## Updated at UTC 2026-08-23T21:11:23.559820

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-77002 9.8 0.15% 4 0 2026-08-23T16:16:38.663000 The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any s
CVE-2026-77001 9.8 0.19% 4 0 2026-08-23T16:16:38.507000 The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin t
CVE-2026-77000 9.8 0.15% 2 0 2026-08-23T16:16:38.360000 The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a
CVE-2026-4671 7.5 0.00% 2 1 2026-08-23T15:33:12 justhtml before 1.18.0 contains multiple low-severity denial-of-service issues i
CVE-2026-8445 9.8 0.00% 2 0 2026-08-23T15:33:12 justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-si
CVE-2026-7808 9.8 0.00% 2 0 2026-08-23T15:33:12 justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that ca
CVE-2026-9769 7.5 0.00% 2 0 2026-08-23T15:33:12 justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion
CVE-2026-5388 9.8 0.00% 2 0 2026-08-23T14:16:53.470000 justhtml before 1.15.0 contains multiple security issues in URL sanitization hel
CVE-2026-10053 8.5 0.71% 2 1 2026-08-23T12:31:12 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8
CVE-2026-78155 9.9 0.48% 4 0 2026-08-23T12:31:11 privilege escalation in StackGres operator allows a low-privilege tenant who own
CVE-2026-13598 None 0.19% 2 0 2026-08-23T06:30:28 The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role
CVE-2026-78136 7.8 0.21% 5 0 2026-08-23T03:34:57 chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. Th
CVE-2026-47895 7.5 0.45% 3 0 2026-08-23T02:17:00.083000 In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-I
CVE-2026-78122 7.4 0.31% 2 1 2026-08-23T00:30:30 docker-socket-proxy fails to properly gate read endpoints in the /containers Doc
CVE-2026-16149 8.8 0.59% 4 0 2026-08-23T00:30:30 The Security Hardener plugin for WordPress is vulnerable to Missing Authorizatio
CVE-2026-0551 8.8 0.75% 4 0 2026-08-23T00:30:30 The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Obje
CVE-2026-78050 9.9 0.79% 4 0 2026-08-23T00:30:30 A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is th
CVE-2026-74708 None 0.21% 1 0 2026-08-22T18:30:42 In the Linux kernel, the following vulnerability has been resolved: xsk: valida
CVE-2026-74671 None 0.22% 1 0 2026-08-22T18:30:37 In the Linux kernel, the following vulnerability has been resolved: ima: fix ou
CVE-2026-4703 9.8 0.90% 5 0 2026-08-22T18:30:25 The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vuln
CVE-2026-63310 7.1 0.15% 2 0 2026-08-22T15:31:11 NLTK before 3.9.3 fails to verify file integrity after downloading packages and
CVE-2026-71513 8.8 1.08% 3 0 2026-08-22T15:31:11 NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUn
CVE-2026-62243 7.5 0.25% 2 0 2026-08-22T15:31:11 Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final an
CVE-2026-62388 7.5 0.46% 2 0 2026-08-22T15:31:11 NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all
CVE-2026-68766 7.8 0.22% 2 0 2026-08-22T15:31:11 hashcat fails to restrict command-line options when parsing restore files, allow
CVE-2026-59808 8.8 0.59% 2 0 2026-08-22T15:31:05 AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability w
CVE-2026-60084 8.7 0.55% 2 0 2026-08-22T15:31:05 SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability i
CVE-2026-57998 7.8 0.21% 2 0 2026-08-22T15:31:02 better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm a
CVE-2026-66393 7.5 0.49% 4 0 2026-08-22T15:16:19.633000 NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONT
CVE-2026-63312 7.5 0.66% 2 0 2026-08-22T15:16:19.367000 NLTK before 3.10.0 contains an arbitrary local file read vulnerability in Stream
CVE-2026-62384 7.5 0.66% 5 0 2026-08-22T15:16:18.700000 NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCo
CVE-2026-2996 7.5 0.53% 2 0 2026-08-22T14:16:32.807000 The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPres
CVE-2026-59256 7.5 0.46% 2 0 2026-08-22T13:16:38.817000 WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerabili
CVE-2026-77945 7.4 1.77% 1 0 2026-08-22T12:30:26 A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unkno
CVE-2026-77946 10.0 1.02% 5 0 2026-08-22T11:16:54.447000 A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by thi
CVE-2026-12710 None 0.29% 2 0 2026-08-22T09:30:32 A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud App
CVE-2026-78003 9.8 0.53% 4 0 2026-08-22T09:30:32 The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Requ
CVE-2026-69836 10.0 1.37% 21 2 2026-08-22T04:18:01.640000 Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a
CVE-2026-47827 7.5 1.96% 2 0 2026-08-22T04:17:47.820000 Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote a
CVE-2026-19883 8.8 0.37% 2 0 2026-08-22T03:31:33 The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorize
CVE-2026-34948 7.7 0.23% 2 0 2026-08-21T23:16:24.153000 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only cla
CVE-2026-62867 9.9 0.52% 2 0 2026-08-21T22:16:41.900000 Incus is a system container and virtual machine manager. Prior to version 7.3.0,
CVE-2026-54071 7.8 0.14% 2 0 2026-08-21T22:16:40.203000 BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF
CVE-2026-48755 9.9 0.44% 2 0 2026-08-21T22:16:37.973000 Incus is a system container and virtual machine manager. Prior to version 7.1.0,
CVE-2026-34741 8.6 0.45% 2 0 2026-08-21T22:16:37.143000 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authenti
CVE-2026-76017 8.8 0.47% 1 0 2026-08-21T21:31:48 Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a
CVE-2026-77811 8.7 0.37% 2 0 2026-08-21T21:17:08.903000 Improper input validation in the dashboards-observability plugin in OpenSearch D
CVE-2026-77647 9.8 0.81% 3 0 2026-08-21T21:17:08.777000 SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary
CVE-2026-77415 0 0.51% 2 0 2026-08-21T21:17:07.553000 JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, c
CVE-2026-77413 0 0.41% 2 0 2026-08-21T21:17:07.267000 JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, t
CVE-2026-76905 7.5 0.35% 3 0 2026-08-21T21:17:06.320000 kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.
CVE-2026-63421 7.5 0.47% 2 0 2026-08-21T21:17:01.643000 Keystone is a content management system for Node.js. Prior to 6.5.3, the findMan
CVE-2026-61824 8.2 0.23% 2 0 2026-08-21T21:17:01.017000 Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page
CVE-2026-30890 8.0 0.23% 2 0 2026-08-21T21:16:57.103000 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is
CVE-2026-18290 7.8 0.26% 1 0 2026-08-21T21:16:55.823000 OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution V
CVE-2026-77414 None 0.35% 2 0 2026-08-21T20:58:02 Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code wit
CVE-2026-68508 7.8 0.25% 2 0 2026-08-21T20:57:32 ## Summary `hydra.utils.instantiate()` resolves and calls Python objects from c
CVE-2026-63135 8.2 0.23% 2 0 2026-08-21T20:57:24 ### Summary YOURLS stores the HTTP `Referer` header for short URL redirects and
CVE-2026-61539 10.0 0.66% 4 0 2026-08-21T20:56:39 ### Summary Xinference used Python's unsafe `eval()` function when parsing Llam
CVE-2026-64679 8.1 0.38% 2 0 2026-08-21T20:55:33 ### Summary Atlantis versions `>= 0.19.8` and `< 0.45.0` did not consistently va
CVE-2026-76904 9.8 0.43% 2 1 2026-08-21T20:26:30 ### Summary An SQL Injection Vulnerability has been found when executing OGC Fi
CVE-2026-27462 7.5 0.31% 2 0 2026-08-21T20:16:33.870000 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop ret
CVE-2026-41449 7.8 0.64% 2 0 2026-08-21T19:17:01.520000 UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command in
CVE-2026-63462 7.5 0.38% 2 0 2026-08-21T19:14:39 ## Summary An unauthenticated `POST` to any OpenAPI-validated endpoint, includi
CVE-2026-41451 7.8 0.72% 2 0 2026-08-21T18:35:08 UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command in
CVE-2026-41450 7.8 0.70% 2 0 2026-08-21T18:35:07 UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command in
CVE-2026-39909 8.1 0.77% 2 0 2026-08-21T18:35:07 llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server
CVE-2026-75932 8.6 0.40% 3 0 2026-08-21T18:35:02 Jet Admin allows an attacker to create a malicious app and connect it to a targe
CVE-2026-69502 10.0 0.76% 3 0 2026-08-21T18:35:01 Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized
CVE-2026-22681 8.5 0.28% 2 1 2026-08-21T18:35:01 OpenViking before 0.3.4 contains a server-side request forgery vulnerability tha
CVE-2026-75501 None 0.37% 2 0 2026-08-21T18:34:56 A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residentia
CVE-2026-73570 8.9 1.04% 13 1 2026-08-21T18:34:48 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-77812 0 0.06% 2 0 2026-08-21T18:16:52.527000 DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over
CVE-2026-55241 7.5 0.44% 2 0 2026-08-21T18:16:48.790000 Checkmate is an open-source, self-hosted tool designed to track and monitor serv
CVE-2026-54789 7.5 0.39% 2 0 2026-08-21T18:16:48.680000 mod_auth_openidc is an OpenID Certified authentication and authorization module
CVE-2026-73137 7.7 0.29% 1 0 2026-08-21T16:18:16.620000 A flaw was found in the multicloud-operators-subscription component of Red Hat A
CVE-2026-69855 7.7 0.48% 1 0 2026-08-21T16:18:11.723000 Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an autho
CVE-2026-55622 7.7 0.20% 2 0 2026-08-21T16:17:19.623000 Incus is a system container and virtual machine manager. Prior to version 7.2.0,
CVE-2026-48751 9.9 0.70% 2 0 2026-08-21T16:17:17.533000 Incus is a system container and virtual machine manager. Prior to version 7.2.0,
CVE-2026-48749 9.9 0.81% 2 0 2026-08-21T16:17:17.413000 Incus is a system container and virtual machine manager. Prior to version 7.2.0,
CVE-2026-50112 8.8 0.32% 2 0 2026-08-21T15:33:15 SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a
CVE-2026-77814 7.5 0.41% 2 0 2026-08-21T15:32:19 is_path_trusted in scripts/iib/api.py compares the requested path against each a
CVE-2026-77806 9.8 0.79% 4 0 2026-08-21T15:32:18 SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary
CVE-2026-77087 9.6 0.40% 3 0 2026-08-21T15:32:18 Paperclip before 0.3.1 in default local_trusted mode fails to validate Host head
CVE-2026-77815 7.5 0.41% 2 0 2026-08-21T15:32:18 to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.no
CVE-2026-63125 9.9 0.66% 3 0 2026-08-21T15:16:46.427000 Incus is a system container and virtual machine manager. Prior to version 7.3.0,
CVE-2026-77767 7.5 0.36% 2 0 2026-08-21T14:16:53.773000 Reconmap's API applies a fallback authorization policy in apps/api/app/Program.c
CVE-2026-77651 9.8 0.43% 1 0 2026-08-21T14:16:53.510000 The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when
CVE-2026-18781 8.1 0.32% 1 0 2026-08-21T13:16:55.727000 The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin befor
CVE-2026-77086 9.1 0.65% 2 0 2026-08-21T12:30:41 SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar insta
CVE-2026-77776 9.1 0.34% 5 0 2026-08-21T12:30:41 Headroom's LLM proxy derives the memory owner from the x-headroom-user-id reques
CVE-2026-77683 9.9 1.51% 4 0 2026-08-21T12:30:37 A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this
CVE-2026-77775 8.6 0.36% 2 0 2026-08-21T12:30:35 Headroom's LLM proxy lets a client choose the upstream destination with the x-he
CVE-2026-59279 7.5 0.39% 2 0 2026-08-21T12:30:34 The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not
CVE-2026-72529 9.8 0.78% 10 0 2026-08-21T04:18:15.753000 A remote unauthorized attacker with network access via port 4307/TCP to the True
CVE-2026-76158 None 0.41% 1 0 2026-08-21T03:31:30 External Control of File Name or Path in the upload API endpoint of Datiphy Data
CVE-2026-76155 None 0.29% 1 0 2026-08-21T03:31:29 Use of default credentials in Datiphy Data Management Center from v8.3.0 through
CVE-2026-76156 None 0.83% 1 0 2026-08-21T03:31:29 OS command injection in the api endpoint of Datiphy Data Management Center from
CVE-2026-77645 None 0.47% 1 0 2026-08-21T00:31:31 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-72860 8.5 0.22% 1 0 2026-08-21T00:31:31 The POST /api/provider-nodes/validate route in 9router takes a caller-supplied b
CVE-2026-72848 8.6 0.48% 1 0 2026-08-21T00:31:31 SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py a
CVE-2026-72818 7.5 0.51% 1 0 2026-08-21T00:31:31 The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetToken
CVE-2026-72843 9.8 0.57% 4 0 2026-08-21T00:31:24 The customer update route in EverShop is declared with "access": "public" in pac
CVE-2026-77642 7.5 0.19% 1 0 2026-08-20T22:18:06.070000 tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus
CVE-2026-73040 8.8 0.67% 1 0 2026-08-20T21:31:37 Dockge validates a stack name only on the write path. In backend/stack.ts the al
CVE-2026-66785 9.9 0.29% 2 0 2026-08-20T21:31:36 A flaw was found in Submariner. This vulnerability allows a malicious cluster (s
CVE-2026-67567 9.9 0.32% 2 0 2026-08-20T21:31:36 A flaw was found in the multicloud-operators-subscription component. This vulner
CVE-2026-18420 8.8 0.96% 1 0 2026-08-20T21:31:36 Improper input validation in the Time Series Visual Builder (TSVB) plugin in Ope
CVE-2026-72852 7.8 0.14% 1 0 2026-08-20T21:31:36 hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by
CVE-2026-19586 None 5.04% 1 0 2026-08-20T21:31:30 A pre-authentication OS command injection vulnerability has been identified in O
CVE-2026-77638 8.9 0.17% 1 0 2026-08-20T21:31:30 Tor before 0.4.9.11 is prone to a race condition where in just the right circums
CVE-2026-77148 9.9 0.47% 1 0 2026-08-20T20:17:47.110000 A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function
CVE-2026-73257 9.1 0.38% 1 0 2026-08-20T20:17:46.470000 Mongoose is an embedded web server and network library. Priro to version 7.22, a
CVE-2026-72530 9.0 0.97% 9 0 2026-08-20T18:31:47 A remote unauthorized attacker with network access via port 4307/TCP to the True
CVE-2026-76641 7.5 0.34% 1 0 2026-08-20T18:31:11 Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows att
CVE-2026-77022 9.9 0.46% 1 0 2026-08-20T18:31:06 A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this
CVE-2026-71428 9.3 0.25% 1 0 2026-08-20T17:19:40.773000 The unstructured library provides open-source components for ingesting and pre-p
CVE-2026-66582 7.1 0.18% 1 0 2026-08-20T17:19:24.533000 Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
CVE-2026-19490 None 0.33% 6 0 2026-08-20T15:34:03 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f
CVE-2026-32475 9.0 0.42% 5 2 2026-08-20T12:48:31.843000 Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Eleme
CVE-2026-19598 9.8 0.50% 2 3 2026-08-20T12:48:10.287000 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to
CVE-2026-20231 9.9 0.41% 3 0 2026-08-19T21:31:33 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20315 10.0 0.32% 2 0 2026-08-19T21:30:29 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20317 10.0 0.34% 1 0 2026-08-19T21:30:29 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-65400 9.8 0.75% 1 3 2026-08-19T04:17:34.547000 An authentication issue was addressed with improved state management. This issue
CVE-2026-59310 9.8 2.40% 1 2 2026-08-19T04:17:24.940000 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-33824 9.8 77.90% 1 2 2026-08-19T04:16:58.560000 Double free in Windows IKE Extension allows an unauthorized attacker to execute
CVE-2026-18963 9.1 0.39% 4 1 2026-08-19T03:31:21 A flaw was found in the reset-credentials flow of the keycloak-services componen
CVE-2026-64849 9.3 8.15% 2 3 template 2026-08-17T21:58:52 ### Summary The default MLflow Tracking Server (`mlflow server`, no authenticati
CVE-2026-19478 9.4 1.94% 7 6 template 2026-08-17T21:31:30 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2
CVE-2026-42945 8.1 66.04% 2 44 2026-08-17T12:18:36.420000 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo
CVE-2026-33818 7.5 0.46% 1 0 2026-08-14T18:31:34 Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing
CVE-2026-68820 7.0 0.33% 1 2 2026-08-11T21:33:01 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-12569 9.8 30.20% 1 1 2026-08-01T05:16:55.023000 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-66066 None 1.77% 1 7 2026-07-30T18:23:34 ### Impact In its default configuration, a Rails application that displays image
CVE-2026-59309 9.8 0.74% 1 0 2026-07-30T16:17:15.073000 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-54457 7.7 0.29% 2 0 2026-07-15T21:59:41 ### Impact The `/internal/object_storage` endpoint accepts a caller-supplied JS
CVE-2026-52929 7.5 0.39% 1 0 2026-07-08T15:31:44 In the Linux kernel, the following vulnerability has been resolved: sctp: strea
CVE-2026-58472 5.9 0.22% 1 0 2026-07-07T21:31:43 GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflo
CVE-2026-49360 None 0.45% 1 0 2026-07-02T21:14:38 ### Impact Recce OSS server deployments that expose the server to an untrusted n
CVE-2026-8452 9.8 1.04% 2 3 2026-07-01T18:32:28 Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp
CVE-2026-48769 9.9 0.44% 2 0 2026-06-26T19:13:19 ### Summary An arbitrary file write exists in the Incus client when a malicious
CVE-2026-48753 9.9 0.71% 2 0 2026-06-26T18:47:27 ## Summary The S3 protocol upload endpoint is vulnerable to path traversal and
CVE-2026-48752 9.9 0.81% 2 0 2026-06-26T18:46:32 ### Summary A specially crafted image or instance backup can be used to read or
CVE-2026-48750 9.9 0.78% 2 0 2026-06-26T18:32:53 ### Summary The `record-output` parameter of the `/instances/$name/exec` endpoi
CVE-2025-62593 None 1.00% 2 1 2025-12-01T16:02:43 # Summary Developers working with Ray as a development tool can be exploited vi
CVE-2012-0158 8.8 99.97% 2 2 2025-10-22T03:31:35 The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX control
CVE-2021-43226 7.8 3.07% 2 1 2025-10-22T00:33:30 Windows Common Log File System Driver Elevation of Privilege Vulnerability This
CVE-2020-5135 9.8 24.56% 2 0 2025-10-22T00:31:59 A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Den
CVE-2026-55621 0 0.20% 2 0 N/A
CVE-2026-39113 0 0.00% 2 1 N/A
CVE-2026-50538 0 0.32% 3 0 N/A
CVE-2026-72898 0 10.40% 2 6 template N/A
CVE-2026-63343 0 0.48% 2 0 N/A
CVE-2026-62941 0 0.44% 2 0 N/A
CVE-2026-62940 0 0.42% 2 0 N/A
CVE-2026-30826 0 0.23% 2 0 N/A
CVE-2026-31880 0 0.23% 2 0 N/A
CVE-2026-31803 0 0.23% 2 0 N/A
CVE-2026-53525 0 0.43% 1 0 N/A
CVE-2026-62316 0 0.32% 2 0 N/A
CVE-2026-62283 0 0.37% 2 0 N/A
CVE-2026-49849 0 0.70% 4 0 N/A
CVE-2026-33240 0 0.27% 2 0 N/A
CVE-2026-31936 0 0.27% 2 0 N/A
CVE-2026-53528 0 0.35% 2 0 N/A
CVE-2026-53527 0 0.24% 2 0 N/A
CVE-2026-62677 0 0.45% 2 0 N/A
CVE-2026-62675 0 0.45% 2 0 N/A
CVE-2026-30866 0 0.27% 2 0 N/A
CVE-2026-27490 0 0.31% 2 0 N/A
CVE-2026-77810 0 0.35% 2 0 N/A
CVE-2026-54682 0 0.14% 2 0 N/A
CVE-2026-62674 0 0.34% 2 0 N/A
CVE-2026-71862 0 0.35% 2 0 N/A
CVE-2026-77234 0 0.11% 2 0 N/A
CVE-2026-59270 0 0.00% 1 0 N/A
CVE-2026-77176 0 0.41% 2 0 N/A
CVE-2026-71485 0 0.42% 1 0 N/A
CVE-2026-73256 0 0.40% 1 0 N/A

CVE-2026-77002
(9.8 CRITICAL)

EPSS: 0.15%

updated 2026-08-23T16:16:38.663000

4 posts

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.

thehackerwire@mastodon.social at 2026-08-23T18:00:30.000Z ##

🔴 CVE-2026-77002 - Critical (9.8)

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-22T07:30:22.535Z ##

CRITICAL: CVE-2026-77002 in SmilePass Selfie Login WP plugin (≤1.0.2) allows full account takeover — no auth needed. Remove/disable plugin until patched. Details: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-23T18:00:30.000Z ##

🔴 CVE-2026-77002 - Critical (9.8)

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-22T07:30:22.000Z ##

CRITICAL: CVE-2026-77002 in SmilePass Selfie Login WP plugin (≤1.0.2) allows full account takeover — no auth needed. Remove/disable plugin until patched. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #CVE202677002

##

CVE-2026-77001
(9.8 CRITICAL)

EPSS: 0.19%

updated 2026-08-23T16:16:38.507000

4 posts

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators. In the default case a session as the site's original administrator account is obt

thehackerwire@mastodon.social at 2026-08-23T18:00:21.000Z ##

🔴 CVE-2026-77001 - Critical (9.8)

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-22T13:30:23.191Z ##

CVE-2026-77001: CRITICAL vuln in Social Login & Sharing buttons with Analytics By SoClever (≤1.2.0). No auth checks — attackers can hijack any user session, including admin. Remove/disable plugin pending fix. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-23T18:00:21.000Z ##

🔴 CVE-2026-77001 - Critical (9.8)

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-22T13:30:23.000Z ##

CVE-2026-77001: CRITICAL vuln in Social Login & Sharing buttons with Analytics By SoClever (≤1.2.0). No auth checks — attackers can hijack any user session, including admin. Remove/disable plugin pending fix. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202677001 #Vulnerability

##

CVE-2026-77000
(9.8 CRITICAL)

EPSS: 0.15%

updated 2026-08-23T16:16:38.360000

2 posts

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address.

thehackerwire@mastodon.social at 2026-08-23T18:00:11.000Z ##

🔴 CVE-2026-77000 - Critical (9.8)

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, incl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T18:00:11.000Z ##

🔴 CVE-2026-77000 - Critical (9.8)

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, incl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-4671
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-23T15:33:12

2 posts

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run selector matching over very large untrusted documents, construct DOM trees from untrusted structure, or enable linkification over attacker-controlled tex

1 repos

https://github.com/HAERIN-L/POC_CVE-2026-46716

thehackerwire@mastodon.social at 2026-08-23T15:01:03.000Z ##

🟠 CVE-2026-4671 - High (7.5)

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T15:01:03.000Z ##

🟠 CVE-2026-4671 - High (7.5)

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8445
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-23T15:33:12

2 posts

justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacters are escaped, characters such as < and > are preserved, so untrusted input that is safe in to_html() — including entity-decoded text (e.g. &lt;script&gt;) or t

thehackerwire@mastodon.social at 2026-08-23T15:00:30.000Z ##

🔴 CVE-2026-8445 - Critical (9.8)

justhtml versions &lt;= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacters ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T15:00:30.000Z ##

🔴 CVE-2026-8445 - Critical (9.8)

justhtml versions &lt;= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacters ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7808
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-23T15:33:12

2 posts

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usage rather than the default JustHTML(..., sanitize=True) path for ordinary parsed HTML: mutating or reusing sanitization policy objects (including exporte

thehackerwire@mastodon.social at 2026-08-23T15:00:18.000Z ##

🔴 CVE-2026-7808 - Critical (9.8)

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T15:00:18.000Z ##

🔴 CVE-2026-7808 - Critical (9.8)

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9769
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-23T15:33:12

2 posts

justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the DOM tree via _find_elements()/_find_element() without a depth bound. An attacker who can supply HTML for parsing can provide deeply nested elements (e.g.

thehackerwire@mastodon.social at 2026-08-23T15:00:07.000Z ##

🟠 CVE-2026-9769 - High (7.5)

justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T15:00:07.000Z ##

🟠 CVE-2026-9769 - High (7.5)

justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5388
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-23T14:16:53.470000

2 posts

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on configuration, an attacker can bypass sanitization to inject active HTML and JavaScript — for example via encoded javascript: URLs, backslash-b

thehackerwire@mastodon.social at 2026-08-23T15:01:13.000Z ##

🔴 CVE-2026-5388 - Critical (9.8)

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Dep...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T15:01:13.000Z ##

🔴 CVE-2026-5388 - Critical (9.8)

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Dep...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10053
(8.5 HIGH)

EPSS: 0.71%

updated 2026-08-23T12:31:12

2 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.

1 repos

https://github.com/dinosn/CVE-2026-10053-lab

thehackerwire@mastodon.social at 2026-08-23T11:02:00.000Z ##

🟠 CVE-2026-10053 - High (8.5)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T11:02:00.000Z ##

🟠 CVE-2026-10053 - High (8.5)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78155
(9.9 CRITICAL)

EPSS: 0.48%

updated 2026-08-23T12:31:11

4 posts

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

thehackerwire@mastodon.social at 2026-08-23T11:01:51.000Z ##

🔴 CVE-2026-78155 - Critical (9.9)

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-23T10:30:24.006Z ##

CVE-2026-78155: OnGres StackGres operator has a critical (CVSS 9.9) priv esc vuln via untrusted search path (CWE-426). No patch yet. Restrict tenant privileges & monitor for escalation attempts. More info: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-23T11:01:51.000Z ##

🔴 CVE-2026-78155 - Critical (9.9)

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-23T10:30:24.000Z ##

CVE-2026-78155: OnGres StackGres operator has a critical (CVSS 9.9) priv esc vuln via untrusted search path (CWE-426). No patch yet. Restrict tenant privileges & monitor for escalation attempts. More info: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #PrivilegeEscalation

##

CVE-2026-13598(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-08-23T06:30:28

2 posts

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.

offseq at 2026-08-23T07:30:23.092Z ##

CVE-2026-13598: RestrictMate <1.3.0 (WordPress) CRITICAL vuln lets unauthenticated users create admin accounts via improper privilege management. Disable user registration or validate roles until patched. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-23T07:30:23.000Z ##

CVE-2026-13598: RestrictMate <1.3.0 (WordPress) CRITICAL vuln lets unauthenticated users create admin accounts via improper privilege management. Disable user registration or validate roles until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202613598 #Infosec

##

CVE-2026-78136
(7.8 HIGH)

EPSS: 0.21%

updated 2026-08-23T03:34:57

5 posts

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.

hugovalters@mastodon.social at 2026-08-23T11:10:30.000Z ##

CVE-2026-78136 - CHIRP RCE via eval injection in crafted CSV (kenwood_itm.py). CVSS 7.8. Unpatched - upgrade once available. #CVE #infosec #CHIRP

valtersit.com/cve/CVE-2026-781

##

offseq at 2026-08-23T06:00:24.736Z ##

CVE-2026-78136: HIGH severity eval injection in chirpmyradio CHIRP (<39178db). Malicious CSV data can trigger arbitrary code execution. No patch yet — avoid untrusted files. Full details: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-23T01:59:48.000Z ##

🟠 CVE-2026-78136 - High (7.8)

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-23T06:00:24.000Z ##

CVE-2026-78136: HIGH severity eval injection in chirpmyradio CHIRP (<39178db). Malicious CSV data can trigger arbitrary code execution. No patch yet — avoid untrusted files. Full details: radar.offseq.com/threat/cve-20 #OffSeq #chirpmyradio #Vulnerability #InfoSec

##

thehackerwire@mastodon.social at 2026-08-23T01:59:48.000Z ##

🟠 CVE-2026-78136 - High (7.8)

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47895
(7.5 HIGH)

EPSS: 0.45%

updated 2026-08-23T02:17:00.083000

3 posts

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.

hugovalters@mastodon.social at 2026-08-23T18:07:24.000Z ##

CVE-2026-47895 - Double-Free vulnerability in strongSwan EAP identity parsing. CVSS 7.5. Update to version 6.0.7 immediately. #CVE #strongSwan #infosec

valtersit.com/cve/CVE-2026-478

##

thehackerwire@mastodon.social at 2026-08-22T22:59:52.000Z ##

🟠 CVE-2026-47895 - High (7.5)

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T22:59:52.000Z ##

🟠 CVE-2026-47895 - High (7.5)

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78122
(7.4 HIGH)

EPSS: 0.31%

updated 2026-08-23T00:30:30

2 posts

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.

1 repos

https://github.com/Legendile7/CVE-2026-78122-POC

offseq at 2026-08-23T13:30:23.800Z ##

CVE-2026-78122: HIGH severity in Tecnativa docker-socket-proxy (CVSS 8.3). Insufficient access control enables attackers to read files & export entire container filesystems via Docker API. Restrict access, check vendor guidance. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-23T13:30:23.000Z ##

CVE-2026-78122: HIGH severity in Tecnativa docker-socket-proxy (CVSS 8.3). Insufficient access control enables attackers to read files & export entire container filesystems via Docker API. Restrict access, check vendor guidance. radar.offseq.com/threat/cve-20 #OffSeq #Docker #Infosec #Vuln

##

CVE-2026-16149
(8.8 HIGH)

EPSS: 0.59%

updated 2026-08-23T00:30:30

4 posts

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_endpoints filter via secure_user_endpoints() and overwrites every registered handler's permission_callback on both the /wp/v2/users and /wp/v2/users/(?P<i

offseq at 2026-08-23T12:00:23.772Z ##

CVE-2026-16149 (HIGH, CVSS 8.8): marc4 Security Hardener <=2.4.4 allows Subscriber-level users to create Admin accounts or reset passwords via REST API. Disable plugin or limit API access pending patch. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-23T01:00:14.000Z ##

🟠 CVE-2026-16149 - High (8.8)

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-23T12:00:23.000Z ##

CVE-2026-16149 (HIGH, CVSS 8.8): marc4 Security Hardener <=2.4.4 allows Subscriber-level users to create Admin accounts or reset passwords via REST API. Disable plugin or limit API access pending patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #Infosec

##

thehackerwire@mastodon.social at 2026-08-23T01:00:14.000Z ##

🟠 CVE-2026-16149 - High (8.8)

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-0551
(8.8 HIGH)

EPSS: 0.75%

updated 2026-08-23T00:30:30

4 posts

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable sof

offseq at 2026-08-23T09:00:23.910Z ##

CVE-2026-0551: HIGH severity deserialization vulnerability in buildwps PPWP – Password Protect Pages (<=1.9.18). Contributor+ users can inject PHP objects if a POP chain exists in other plugins/themes. Review access & patch status. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-23T01:00:37.000Z ##

🟠 CVE-2026-0551 - High (8.8)

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-23T09:00:23.000Z ##

CVE-2026-0551: HIGH severity deserialization vulnerability in buildwps PPWP – Password Protect Pages (<=1.9.18). Contributor+ users can inject PHP objects if a POP chain exists in other plugins/themes. Review access & patch status. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

thehackerwire@mastodon.social at 2026-08-23T01:00:37.000Z ##

🟠 CVE-2026-0551 - High (8.8)

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78050
(9.9 CRITICAL)

EPSS: 0.79%

updated 2026-08-23T00:30:30

4 posts

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of the argument timestr/ntp_client_enabled results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.

thehackerwire@mastodon.social at 2026-08-23T01:00:26.000Z ##

🔴 CVE-2026-78050 - Critical (9.9)

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of the argument timestr/ntp_cl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-23T00:00:34.698Z ##

CRITICAL: CVE-2026-78050 in Comfast CF-N1-S (2.6.0.1) enables remote code execution via stack-based buffer overflow in web mgmt (/cgi-bin/mbox-config). Public exploit out, no patch yet. Restrict access! radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-23T01:00:26.000Z ##

🔴 CVE-2026-78050 - Critical (9.9)

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of the argument timestr/ntp_cl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-23T00:00:34.000Z ##

CRITICAL: CVE-2026-78050 in Comfast CF-N1-S (2.6.0.1) enables remote code execution via stack-based buffer overflow in web mgmt (/cgi-bin/mbox-config). Public exploit out, no patch yet. Restrict access! radar.offseq.com/threat/cve-20 #OffSeq #CVE202678050 #infosec #IoT

##

CVE-2026-74708(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-08-22T18:30:42

1 posts

In the Linux kernel, the following vulnerability has been resolved: xsk: validate launch-time metadata size Launch-time metadata extends beyond the first 16 bytes of struct xsk_tx_metadata. Reject the request when the registered metadata area does not contain the complete field. Snapshot the validated flags for the generic transmit path and use that snapshot for request and completion processin

Byte0x90@mastodon.social at 2026-08-22T19:24:23.000Z ##

Kritischer Fix im Linux-Kernel (CVE-2026-74708)

Das MITRE-Institut meldet eine behobene Schwachstelle im xsk-Netzwerk-Subsystem. Eine fehlerhafte Größenprüfung von „Launch-time“-Metadaten konnte durch manipulierte Anfragen zu Pipeline-Ausfällen führen.

Die Patches wurden bereits erfolgreich eingepflegt. System-Updates werden empfohlen!

#Linux #CVE #Infosec

##

CVE-2026-74671(CVSS UNKNOWN)

EPSS: 0.22%

updated 2026-08-22T18:30:37

1 posts

In the Linux kernel, the following vulnerability has been resolved: ima: fix out-of-bounds read in xattr_verify() The digest-length check in xattr_verify() mixes int and size_t: if (xattr_len - sizeof(xattr_value->type) - hash_start >= iint->ima_hash->length) sizeof() yields size_t, so the usual arithmetic conversions promote the whole left-hand side to unsigned 64-bit before the subtracti

Byte0x90@mastodon.social at 2026-08-22T19:25:42.000Z ##

Speicher-Leck im Linux-Kernel (CVE-2026-74671)

Eine Schwachstelle in der Integritätsmessarchitektur (IMA) bedroht Linux-Systeme. Ein Vorzeichenfehler (Type-Mismatch) in der Funktion xattr_verify() führt bei manipulierten security.ima-Erweiterungen zu einem Unterlauf.

Dadurch entsteht ein gefährlicher Out-of-Bounds-Lesefehler, über den Angreifer potenziell sensible Daten direkt aus dem Speicher abgreifen können. Admins sollten umgehend patchen!

#Linux #CVE #Infosec

##

CVE-2026-4703
(9.8 CRITICAL)

EPSS: 0.90%

updated 2026-08-22T18:30:25

5 posts

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has

hugovalters@mastodon.social at 2026-08-23T14:09:34.000Z ##

CVE-2026-4703 - Critical PHP Object Injection in WS Form for WordPress leads to remote code execution via insecure deserialization. CVSS 9.8. Update now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-470

##

offseq at 2026-08-23T01:30:26.007Z ##

CVE-2026-4703: WS Form LITE ≤1.10.80 has a CRITICAL PHP Object Injection vuln via form meta deserialization. Exploitable if a POP chain exists in another plugin/theme — possible RCE, file deletion, or data leak. Audit plugins/themes. radar.offseq.com/threat/the-ws

##

thehackerwire@mastodon.social at 2026-08-22T20:59:49.000Z ##

🔴 CVE-2026-4703 - Critical (9.8)

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-23T01:30:26.000Z ##

CVE-2026-4703: WS Form LITE ≤1.10.80 has a CRITICAL PHP Object Injection vuln via form meta deserialization. Exploitable if a POP chain exists in another plugin/theme — possible RCE, file deletion, or data leak. Audit plugins/themes. radar.offseq.com/threat/the-ws #OffSeq #WordPress #CVE20264703

##

thehackerwire@mastodon.social at 2026-08-22T20:59:49.000Z ##

🔴 CVE-2026-4703 - Critical (9.8)

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63310
(7.1 HIGH)

EPSS: 0.15%

updated 2026-08-22T15:31:11

2 posts

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

offseq at 2026-08-23T04:30:25.205Z ##

CVE-2026-63310: NLTK <3.9.3 has a CRITICAL flaw where package integrity isn't checked post-download in the downloader module. Exposes users to MITM & DNS poisoning attacks. Upgrade to 3.9.3+ or avoid insecure networks. radar.offseq.com/threat/nltk-b

##

offseq@infosec.exchange at 2026-08-23T04:30:25.000Z ##

CVE-2026-63310: NLTK <3.9.3 has a CRITICAL flaw where package integrity isn't checked post-download in the downloader module. Exposes users to MITM & DNS poisoning attacks. Upgrade to 3.9.3+ or avoid insecure networks. radar.offseq.com/threat/nltk-b #OffSeq #NLTK #CVE202663310 #infosec

##

CVE-2026-71513
(8.8 HIGH)

EPSS: 1.08%

updated 2026-08-22T15:31:11

3 posts

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that execute arbitrary commands when TransitionParser.parse loads the mod

hugovalters@mastodon.social at 2026-08-23T01:10:30.000Z ##

CVE-2026-71513 - Critical RCE in NLTK AllowlistUnpickler. Attribute traversal bypasses allowlist to execute arbitrary code via crafted transition-parser models. CVSS 8.8. Update to NLTK 3.10.3 immediately. #CVE #NLTK #infosec

valtersit.com/cve/CVE-2026-715

##

thehackerwire@mastodon.social at 2026-08-22T23:00:11.000Z ##

🟠 CVE-2026-71513 - High (8.8)

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T23:00:11.000Z ##

🟠 CVE-2026-71513 - High (8.8)

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62243
(7.5 HIGH)

EPSS: 0.25%

updated 2026-08-22T15:31:11

2 posts

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping is unavailable (Java 25+). In this configuration the OpenSSL client does not perform hostname verification, allowing a ma

thehackerwire@mastodon.social at 2026-08-22T23:59:49.000Z ##

🟠 CVE-2026-62243 - High (7.5)

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T23:59:49.000Z ##

🟠 CVE-2026-62243 - High (7.5)

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62388
(7.5 HIGH)

EPSS: 0.46%

updated 2026-08-22T15:31:11

2 posts

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.

thehackerwire@mastodon.social at 2026-08-22T22:00:10.000Z ##

🟠 CVE-2026-62388 - High (7.5)

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T22:00:10.000Z ##

🟠 CVE-2026-62388 - High (7.5)

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68766
(7.8 HIGH)

EPSS: 0.22%

updated 2026-08-22T15:31:11

2 posts

hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary files, enabling code execution when targeting shell startup files.

thehackerwire@mastodon.social at 2026-08-22T20:59:59.000Z ##

🟠 CVE-2026-68766 - High (7.8)

hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-contr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T20:59:59.000Z ##

🟠 CVE-2026-68766 - High (7.8)

hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-contr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59808
(8.8 HIGH)

EPSS: 0.59%

updated 2026-08-22T15:31:05

2 posts

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts this hash into passwordless login as the video owner. Attackers with upload permission can retrieve an administrator's video_id_hash by omitting the v

thehackerwire@mastodon.social at 2026-08-23T01:01:14.000Z ##

🟠 CVE-2026-59808 - High (8.8)

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() conver...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T01:01:14.000Z ##

🟠 CVE-2026-59808 - High (8.8)

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() conver...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-60084
(8.7 HIGH)

EPSS: 0.55%

updated 2026-08-22T15:31:05

2 posts

SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute filesystem paths to recursively delete any file or directory the kernel process has permission to remove, anywhere on the host filesystem.

thehackerwire@mastodon.social at 2026-08-22T23:00:32.000Z ##

🟠 CVE-2026-60084 - High (8.7)

SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T23:00:32.000Z ##

🟠 CVE-2026-60084 - High (8.7)

SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57998
(7.8 HIGH)

EPSS: 0.21%

updated 2026-08-22T15:31:02

2 posts

better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that string to child_process.exec() in index.ts, which spawns a shell. A registry value containing shell metacharacters such as a semicolon, pipe, or command

thehackerwire@mastodon.social at 2026-08-22T23:59:58.000Z ##

🟠 CVE-2026-57998 - High (7.8)

better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T23:59:58.000Z ##

🟠 CVE-2026-57998 - High (7.8)

better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66393
(7.5 HIGH)

EPSS: 0.49%

updated 2026-08-22T15:16:19.633000

4 posts

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unhandled RecursionError that crashes the Python process.

hugovalters@mastodon.social at 2026-08-23T15:14:53.000Z ##

CVE-2026-66393 - DoS vulnerability in NLTK. Deeply nested JSON triggers unhandled recursion crash in Python. CVSS 7.5. Update to 3.9.4 immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-663

##

thehackerwire@mastodon.social at 2026-08-22T21:59:51.000Z ##

🟠 CVE-2026-66393 - High (7.5)

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

hugovalters@mastodon.social at 2026-08-23T15:14:53.000Z ##

CVE-2026-66393 - DoS vulnerability in NLTK. Deeply nested JSON triggers unhandled recursion crash in Python. CVSS 7.5. Update to 3.9.4 immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-663

##

thehackerwire@mastodon.social at 2026-08-22T21:59:51.000Z ##

🟠 CVE-2026-66393 - High (7.5)

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63312
(7.5 HIGH)

EPSS: 0.66%

updated 2026-08-22T15:16:19.367000

2 posts

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

thehackerwire@mastodon.social at 2026-08-22T21:00:09.000Z ##

🟠 CVE-2026-63312 - High (7.5)

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T21:00:09.000Z ##

🟠 CVE-2026-63312 - High (7.5)

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62384
(7.5 HIGH)

EPSS: 0.66%

updated 2026-08-22T15:16:18.700000

5 posts

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _

hugovalters@mastodon.social at 2026-08-23T17:07:03.000Z ##

CVE-2026-62384 - Symlink sandbox bypass in NLTK leads to arbitrary file read. CVSS 7.5. Update to version 3.10.2 now. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-623

##

hugovalters@mastodon.social at 2026-08-23T12:06:06.000Z ##

CVE-2026-62384 - Symlink sandbox bypass in NLTK FramenetCorpusReader. Arbitrary XML file read. CVSS 7.5. Update to 3.10.2 now. #CVE #NLTK #infosec

valtersit.com/cve/CVE-2026-623

##

thehackerwire@mastodon.social at 2026-08-22T22:00:00.000Z ##

🟠 CVE-2026-62384 - High (7.5)

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

hugovalters@mastodon.social at 2026-08-23T17:07:03.000Z ##

CVE-2026-62384 - Symlink sandbox bypass in NLTK leads to arbitrary file read. CVSS 7.5. Update to version 3.10.2 now. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-623

##

thehackerwire@mastodon.social at 2026-08-22T22:00:00.000Z ##

🟠 CVE-2026-62384 - High (7.5)

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-2996
(7.5 HIGH)

EPSS: 0.53%

updated 2026-08-22T14:16:32.807000

2 posts

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing pro

thehackerwire@mastodon.social at 2026-08-22T23:00:22.000Z ##

🟠 CVE-2026-2996 - High (7.5)

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T23:00:22.000Z ##

🟠 CVE-2026-2996 - High (7.5)

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59256
(7.5 HIGH)

EPSS: 0.46%

updated 2026-08-22T13:16:38.817000

2 posts

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token from the Gallery endpoint and use it to bypass authorization checks in other subsystems like view/hls.php to access restric

thehackerwire@mastodon.social at 2026-08-23T00:00:09.000Z ##

🟠 CVE-2026-59256 - High (7.5)

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T00:00:09.000Z ##

🟠 CVE-2026-59256 - High (7.5)

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77945
(7.4 HIGH)

EPSS: 1.77%

updated 2026-08-22T12:30:26

1 posts

A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Performing a manipulation of the argument filename results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used.

hugovalters@mastodon.social at 2026-08-22T15:02:56.000Z ##

CVE-2026-77945 - Command injection in TRENDnet TEW-821DAP 2.2.01b05 via /cgi-bin/upload.cgi. CVSS 7.4. Unpatched. Disable remote access now. #CVE #TRENDnet #infosec

valtersit.com/cve/CVE-2026-779

##

CVE-2026-77946
(10.0 CRITICAL)

EPSS: 1.02%

updated 2026-08-22T11:16:54.447000

5 posts

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument system.ntp.server/system.ntp.enable_server/cameo.time.time_zone/cameo.cameo.syslog_server can lead to stack-based buffer overflow. The attack may

hugovalters@mastodon.social at 2026-08-22T17:07:48.000Z ##

CVE-2026-77946 - Critical stack buffer overflow in TRENDnet TEW-821DAP NTP handler. Remote exploit public, unpatched. CVSS 10. Isolate/disable affected devices until patch. #CVE #TRENDnet #infosec

valtersit.com/cve/CVE-2026-779

##

offseq at 2026-08-22T12:00:23.811Z ##

CVE-2026-77946: Stack-based buffer overflow in TRENDnet TEW-821DAP v2.2.01b05 (CRITICAL, CVSS 10). Remote code execution possible via NTP config. No patch — limit exposure & monitor traffic. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-22T12:00:03.000Z ##

🔴 CVE-2026-77946 - Critical (10)

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-22T12:00:23.000Z ##

CVE-2026-77946: Stack-based buffer overflow in TRENDnet TEW-821DAP v2.2.01b05 (CRITICAL, CVSS 10). Remote code execution possible via NTP config. No patch — limit exposure & monitor traffic. radar.offseq.com/threat/cve-20 #OffSeq #CVE202677946 #infosec #vulnerability

##

thehackerwire@mastodon.social at 2026-08-22T12:00:03.000Z ##

🔴 CVE-2026-77946 - Critical (10)

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12710(CVSS UNKNOWN)

EPSS: 0.29%

updated 2026-08-22T09:30:32

2 posts

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.

offseq at 2026-08-22T10:30:22.866Z ##

CRITICAL (CVSS 9.3): CVE-2026-12710 in Google Cloud Application Integration (QueryEngineTask) enabled unauthorized data access. Patched by Google on 2026-04-04 — no customer action needed. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-22T10:30:22.000Z ##

CRITICAL (CVSS 9.3): CVE-2026-12710 in Google Cloud Application Integration (QueryEngineTask) enabled unauthorized data access. Patched by Google on 2026-04-04 — no customer action needed. Details: radar.offseq.com/threat/cve-20 #OffSeq #CloudSecurity #CVE #Vuln

##

CVE-2026-78003
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-08-22T09:30:32

4 posts

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through sanitize_text_field(). This makes it possible for unauthenticated attackers to make

thehackerwire@mastodon.social at 2026-08-22T09:59:53.000Z ##

🔴 CVE-2026-78003 - Critical (9.8)

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts use...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-22T09:00:24.472Z ##

CRITICAL: Mailgun for WordPress ≤2.2.0 vulnerable to SSRF (CVE-2026-78003). Attackers can exploit input validation in add_list() to hijack admin resets & compromise sites. Update/disable plugin now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-22T09:59:53.000Z ##

🔴 CVE-2026-78003 - Critical (9.8)

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts use...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-22T09:00:24.000Z ##

CRITICAL: Mailgun for WordPress ≤2.2.0 vulnerable to SSRF (CVE-2026-78003). Attackers can exploit input validation in add_list() to hijack admin resets & compromise sites. Update/disable plugin now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #SSRF

##

CVE-2026-69836
(10.0 CRITICAL)

EPSS: 1.37%

updated 2026-08-22T04:18:01.640000

21 posts

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/sentinel-aidefense/CVE-2026-69836-EXP

https://github.com/HORKimhab/CVE-2026-69836

undercodenews@mastodon.social at 2026-08-23T17:06:18.000Z ##

Microsoft Entra ID Faces Maximum-Severity Security Emergency as CVE-2026-69836 Reportedly Comes Under Active Exploitation + Video

A Critical Warning for Organizations That Depend on Cloud Identity Identity infrastructure has become the front door to the modern enterprise. Employees sign in through it, administrators manage systems through it, cloud services trust it, and security teams depend on it to decide who should and should not have access. That is why a newly…

undercodenews.com/microsoft-en

##

teezeh@ieji.de at 2026-08-22T07:18:36.000Z ##

“Microsoft warned on Aug. 20 that a maximum-severity deserialization flaw in Entra ID was actively exploited.

In releasing a patch for CVE-2026-69836, Microsoft said it had already fully mitigated the vulnerability, so there’s no further action for Entra ID users to take.”

scworld.com/news/microsoft-pat

##

ottoto2017@prattohome.com at 2026-08-22T05:43:19.000Z ##

「マイクロソフトが警鐘を鳴らす、Entra IDの完全な欠陥が攻撃を受けている
/マイクロソフトはクラウドIDのバグは既に修正済みだと述べているが、誰がどの程度悪用したのかは明らかにしていない。 」: #TheRegister

「マイクロソフトは、攻撃者が既に悪用していたEntra IDの深刻度が最大レベルの脆弱性を修正した。

CVE-2026-69836として追跡されているこの脆弱性は、CVSSスコアが最高値の10.0であり、認証されていない攻撃者がMicrosoftのクラウドIDサービス上でリモートからコードを実行できる可能性がある。Microsoft は木曜日にこの脆弱性を公表し 、既に悪用が確認されているという残念なニュースも同時に発表した。

Entra ID(旧称Azure Active Directory)は、マイクロソフトのお客様向けIDおよびアクセス管理の中核を担い、クラウドアプリケーションやその他の企業リソースへの認証とアクセスを管理します。」

theregister.com/cyber-crime/20

#prattohome

##

secdb at 2026-08-21T19:00:10.468Z ##

🚨 [CISA-2026:0821] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-69836 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Entra ID
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-73570 (secdb.nttzen.cloud/cve/detail/)
- Name: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Synacor
- Product: Zimbra Collaboration Suite (ZCS)
- Notes: wiki.zimbra.com/wiki/Zimbra_Se ; blog.zimbra.com/2026/07/patch- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cR0w at 2026-08-21T17:04:39.206Z ##

CVE-2026-69836 was added to the KEV. It was published yesterday by Microsoft:

msrc.microsoft.com/update-guid

Microsoft says:

Publicly disclosed: No
Exploited: No
Exploitability assessment: Exploitation Less Likely

and

This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

So does this mean that Microsoft was made aware by a third party that it was EITW? Because presumably it was exploited before it was published if no action is needed by the customer and Microsoft doesn't list it as EITW.

Edit: I now see this revision in the advisory:

Corrected Exploited to No. This vulnerability was not exploited in the wild. This is an informational change only.

So I assume that because it was incorrectly listed as EITW it ended up in the KEV. But now they say it wasn't EITW. Which is it? That's kind of important you fucking sloppy ass clanker fuckers.

##

cisakevtracker@mastodon.social at 2026-08-21T17:00:49.000Z ##

CVE ID: CVE-2026-69836
Vendor: Microsoft
Product: Entra ID
Date Added: 2026-08-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

benzogaga33@mamot.fr at 2026-08-21T15:40:03.000Z ##

Entra ID : une faille critique a été exploitée, mais vous n’avez rien à patcher it-connect.fr/entra-id-cve-202 #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #EntraID

##

CapTechGroup@mastodon.social at 2026-08-21T12:52:36.000Z ##

A maximum-severity CVSS 10.0 flaw in Microsoft Entra ID is under active exploitation, allowing remote code execution. Two CVEs are in play, CVE-2026-68820 and CVE-2026-69836, with activity attributed to the Lazarus Group.

captechgroup.com/threat-intell

##

cyberworldops at 2026-08-21T12:20:00.667Z ##

A critical deserialization vulnerability (CVE-2026-69836) has been actively exploited in Microsoft Entra ID. The flaw could allow unauthorized access to identity and access management functions across Azure, M365, and Dynamics CRM Online.

cyberworldops.eu/en/cve-2026-6

##

tugatech@masto.pt at 2026-08-21T12:07:17.000Z ##

Microsoft corrige falha crítica no Entra ID, uma vulnerabilidade que permitia a execução de código malicioso sem privilégios. A falha, classificada como CVE-2026-69836, já foi explorada em ataques informáticos. 🛡️

🔗 tugatech.com.pt/t89674-microso

#falha #microsoft 

##

Analyst207@mastodon.social at 2026-08-21T11:25:44.000Z ##

Microsoft patches exploited Entra ID flaw amid rising attacks

Microsoft has patched a critical vulnerability in its Entra ID platform, known as CVE-2026-69836, which allowed attackers to execute code remotely with ease, and has already been exploited in recent attacks. This flaw enabled unauthorized threat actors to gain control and wreak havoc, making swift action crucial to prevent…

osintsights.com/microsoft-patc

#MicrosoftEntraId #IdentityManagement #Cve202669836 #ZeroDay #EmergingThreats

##

teezeh@ieji.de at 2026-08-22T07:18:36.000Z ##

“Microsoft warned on Aug. 20 that a maximum-severity deserialization flaw in Entra ID was actively exploited.

In releasing a patch for CVE-2026-69836, Microsoft said it had already fully mitigated the vulnerability, so there’s no further action for Entra ID users to take.”

scworld.com/news/microsoft-pat

##

ottoto2017@prattohome.com at 2026-08-22T05:43:19.000Z ##

「マイクロソフトが警鐘を鳴らす、Entra IDの完全な欠陥が攻撃を受けている
/マイクロソフトはクラウドIDのバグは既に修正済みだと述べているが、誰がどの程度悪用したのかは明らかにしていない。 」: #TheRegister

「マイクロソフトは、攻撃者が既に悪用していたEntra IDの深刻度が最大レベルの脆弱性を修正した。

CVE-2026-69836として追跡されているこの脆弱性は、CVSSスコアが最高値の10.0であり、認証されていない攻撃者がMicrosoftのクラウドIDサービス上でリモートからコードを実行できる可能性がある。Microsoft は木曜日にこの脆弱性を公表し 、既に悪用が確認されているという残念なニュースも同時に発表した。

Entra ID(旧称Azure Active Directory)は、マイクロソフトのお客様向けIDおよびアクセス管理の中核を担い、クラウドアプリケーションやその他の企業リソースへの認証とアクセスを管理します。」

theregister.com/cyber-crime/20

#prattohome

##

secdb@infosec.exchange at 2026-08-21T19:00:10.000Z ##

🚨 [CISA-2026:0821] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-69836 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Entra ID
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-73570 (secdb.nttzen.cloud/cve/detail/)
- Name: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Synacor
- Product: Zimbra Collaboration Suite (ZCS)
- Notes: wiki.zimbra.com/wiki/Zimbra_Se ; blog.zimbra.com/2026/07/patch- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260821 #cisa20260821 #cve_2026_69836 #cve_2026_73570 #cve202669836 #cve202673570

##

cR0w@infosec.exchange at 2026-08-21T17:04:39.000Z ##

CVE-2026-69836 was added to the KEV. It was published yesterday by Microsoft:

msrc.microsoft.com/update-guid

Microsoft says:

Publicly disclosed: No
Exploited: No
Exploitability assessment: Exploitation Less Likely

and

This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

So does this mean that Microsoft was made aware by a third party that it was EITW? Because presumably it was exploited before it was published if no action is needed by the customer and Microsoft doesn't list it as EITW.

Edit: I now see this revision in the advisory:

Corrected Exploited to No. This vulnerability was not exploited in the wild. This is an informational change only.

So I assume that because it was incorrectly listed as EITW it ended up in the KEV. But now they say it wasn't EITW. Which is it? That's kind of important you fucking sloppy ass clanker fuckers.

##

cisakevtracker@mastodon.social at 2026-08-21T17:00:49.000Z ##

CVE ID: CVE-2026-69836
Vendor: Microsoft
Product: Entra ID
Date Added: 2026-08-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

benzogaga33@mamot.fr at 2026-08-21T15:40:03.000Z ##

Entra ID : une faille critique a été exploitée, mais vous n’avez rien à patcher it-connect.fr/entra-id-cve-202 #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #EntraID

##

cyberworldops@infosec.exchange at 2026-08-21T12:20:00.000Z ##

A critical deserialization vulnerability (CVE-2026-69836) has been actively exploited in Microsoft Entra ID. The flaw could allow unauthorized access to identity and access management functions across Azure, M365, and Dynamics CRM Online.

#CriticalVulnerability #MicrosoftEntra #IdentitySecurity #Deserialization

cyberworldops.eu/en/cve-2026-6

##

tugatech@masto.pt at 2026-08-21T12:07:17.000Z ##

Microsoft corrige falha crítica no Entra ID, uma vulnerabilidade que permitia a execução de código malicioso sem privilégios. A falha, classificada como CVE-2026-69836, já foi explorada em ataques informáticos. 🛡️

🔗 tugatech.com.pt/t89674-microso

#falha #microsoft 

##

ottoto2017@prattohome.com at 2026-08-21T07:08:22.000Z ##

「Microsoft Entra IDの脆弱性(CVSS 10.0)が実際に悪用され、リモートコード実行が可能になる 」: #TheHackerNews

「マイクロソフトは木曜日、Entra IDに重大なセキュリティ上の欠陥があり、既に悪用されていると警告したが、顧客による対応は不要であると述べた。

CVE-2026-69836 (CVSSスコア:10.0)として追跡されているこの脆弱性は、 リモートコード実行によって、このテクノロジー大手企業のクラウドベースのIDおよびアクセス管理サービスに影響を与える事例です。このサービスは以前はAzure Active DirectoryまたはAzure ADと呼ばれていました。

マイクロソフトは木曜日に発表した警告の中で、 「Microsoft Entra IDにおける信頼できないデータの逆シリアル化により、権限のない攻撃者がネットワーク上でコードを実行できる可能性がある」 と述べた。 」

thehackernews.com/2026/08/micr

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T02:29:49.000Z ##

CVE-2026-69836, a CVSS 10 Entra ID remote code execution flaw, was exploited in the wild. Microsoft has fully mitigated it server-side.

#CVE202669836 #EntraID #RemoteCodeExecution #Microsoft #CloudSecurity #RCE

securityonline.info/cve-2026-6

##

CVE-2026-47827
(7.5 HIGH)

EPSS: 1.96%

updated 2026-08-22T04:17:47.820000

2 posts

Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities

thehackerwire@mastodon.social at 2026-08-23T09:00:17.000Z ##

🟠 CVE-2026-47827 - High (7.5)

Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T09:00:17.000Z ##

🟠 CVE-2026-47827 - High (7.5)

Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19883
(8.8 HIGH)

EPSS: 0.37%

updated 2026-08-22T03:31:33

2 posts

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress

thehackerwire@mastodon.social at 2026-08-22T03:59:57.000Z ##

🟠 CVE-2026-19883 - High (8.8)

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and inc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T03:59:57.000Z ##

🟠 CVE-2026-19883 - High (8.8)

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and inc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34948
(7.7 HIGH)

EPSS: 0.23%

updated 2026-08-21T23:16:24.153000

2 posts

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos access check in OQL. This issue has been fixed in version 3.2.3.

thehackerwire@mastodon.social at 2026-08-22T00:00:16.000Z ##

🟠 CVE-2026-34948 - High (7.7)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos access check in OQL. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T00:00:16.000Z ##

🟠 CVE-2026-34948 - High (7.7)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos access check in OQL. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62867
(9.9 CRITICAL)

EPSS: 0.52%

updated 2026-08-21T22:16:41.900000

2 posts

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. Version 7.3.0 patches the issue.

thehackerwire@mastodon.social at 2026-08-22T10:00:33.000Z ##

🔴 CVE-2026-62867 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T10:00:33.000Z ##

🔴 CVE-2026-62867 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54071
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-21T22:16:40.203000

2 posts

BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PDF-controlled Encoding or CMapName values and embedded PostScript usecmap operators can reach this sink after path separators are decoded, while _normalize_cmap_name() removes only a leading slash. Abso

thehackerwire@mastodon.social at 2026-08-21T20:00:43.000Z ##

🟠 CVE-2026-54071 - High (7.8)

BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PDF-controlled Encoding or CMapName values and emb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T20:00:43.000Z ##

🟠 CVE-2026-54071 - High (7.8)

BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PDF-controlled Encoding or CMapName values and emb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48755
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-08-21T22:16:37.973000

2 posts

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.

thehackerwire@mastodon.social at 2026-08-23T01:01:24.000Z ##

🔴 CVE-2026-48755 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T01:01:24.000Z ##

🔴 CVE-2026-48755 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34741
(8.6 HIGH)

EPSS: 0.45%

updated 2026-08-21T22:16:37.143000

2 posts

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environment. This issue has been fixed in version 3.2.3.

thehackerwire@mastodon.social at 2026-08-21T23:01:12.000Z ##

🟠 CVE-2026-34741 - High (8.6)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T23:01:12.000Z ##

🟠 CVE-2026-34741 - High (8.6)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76017
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-21T21:31:48

1 posts

Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)

CVE-2026-77811
(8.7 HIGH)

EPSS: 0.37%

updated 2026-08-21T21:17:08.903000

2 posts

Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web content.

thehackerwire@mastodon.social at 2026-08-21T22:00:00.000Z ##

🟠 CVE-2026-77811 - High (8.7)

Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other user...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T22:00:00.000Z ##

🟠 CVE-2026-77811 - High (8.7)

Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other user...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77647
(9.8 CRITICAL)

EPSS: 0.81%

updated 2026-08-21T21:17:08.777000

3 posts

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.

netsecio@mastodon.social at 2026-08-21T17:46:07.000Z ##

📰 Critical RCE Flaw in SPIP CMS Under Active Exploitation

🚨 Critical RCE vulnerability (CVE-2026-77647, CVSS 9.8) in SPIP CMS is under active exploitation. The unauthenticated flaw allows full server takeover. All versions before 4.4.20 are vulnerable. #SPIP #RCE #Vulnerability #PatchNow

🔗 cyber.netsecops.io/articles/cr

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T02:49:11.000Z ##

CVE-2026-77647, a CVSS 9.8 unauthenticated RCE in SPIP before 4.4.20, is exploited in the wild. Update now.

#SPIP #CVE202677647 #RCE #ExploitedInTheWild #CMS #WebSecurity

securityonline.info/cve-2026-7

##

thehackerwire@mastodon.social at 2026-08-21T00:00:04.000Z ##

🔴 CVE-2026-77647 - Critical (9.8)

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of &lt;?php blocks, and var_export&#039;s mishandling of certain cases such ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77415
(0 None)

EPSS: 0.51%

updated 2026-08-21T21:17:07.553000

2 posts

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects through evaluateTransformExpression, expose and deconstruct JSONata functions or lambdas through $merge.*, replace proc.arguments.forEach used by applyProcedure, and f

offseq at 2026-08-22T01:30:25.434Z ##

CVE-2026-77415 (CRITICAL, CVSS 9.3) in jsonata-js (<1.8.8, <2.2.1): Attackers can chain object-integrity flaws to achieve arbitrary code execution. Patch to 1.8.8/2.2.1 ASAP. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-22T01:30:25.000Z ##

CVE-2026-77415 (CRITICAL, CVSS 9.3) in jsonata-js (<1.8.8, <2.2.1): Attackers can chain object-integrity flaws to achieve arbitrary code execution. Patch to 1.8.8/2.2.1 ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #jsonata #security #vuln

##

CVE-2026-77413
(0 None)

EPSS: 0.41%

updated 2026-08-21T21:17:07.267000

2 posts

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An attacker able to supply an expression could use inherited prototype setters and getters, constructor access, valueOf, and process.getBuiltinModule to reach the ch

offseq at 2026-08-22T04:30:25.642Z ##

jsonata-js (<1.8.8, <2.2.0) is affected by CRITICAL CVE-2026-77413 (CVSS 9.3) due to a code injection flaw in the lookup function. Attackers can execute arbitrary code remotely. Upgrade to 1.8.8 or 2.2.0+ ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-22T04:30:25.000Z ##

jsonata-js (<1.8.8, <2.2.0) is affected by CRITICAL CVE-2026-77413 (CVSS 9.3) due to a code injection flaw in the lookup function. Attackers can execute arbitrary code remotely. Upgrade to 1.8.8 or 2.2.0+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec #security

##

CVE-2026-76905
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-21T21:17:06.320000

3 posts

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A malformed non-string scalar field in a multipart/form-data request body produces a nested ParseError with a nil RequestError.Parameter, and applications that rende

hugovalters@mastodon.social at 2026-08-22T11:08:04.000Z ##

CVE-2026-76905 - Unpatched DoS in kin-openapi. Malformed multipart request triggers nil pointer panic in error handling. CVSS 7.5. No fix yet - monitor for updates and apply workarounds. #CVE #infosec #Go

valtersit.com/cve/CVE-2026-769

##

thehackerwire@mastodon.social at 2026-08-21T22:00:22.000Z ##

🟠 CVE-2026-76905 - High (7.5)

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A malformed ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T22:00:22.000Z ##

🟠 CVE-2026-76905 - High (7.5)

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A malformed ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63421
(7.5 HIGH)

EPSS: 0.47%

updated 2026-08-21T21:17:01.643000

2 posts

Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compares the signed take argument directly with graphql.maxTake, allowing a remote unauthenticated GraphQL client to provide a negative take value whose magnitude exceeds the configured bound. The bypass also applies to relationship queries and can return mo

thehackerwire@mastodon.social at 2026-08-22T01:00:27.000Z ##

🟠 CVE-2026-63421 - High (7.5)

Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compares the signed take argument directly with graphql.maxTake, allowing a remote unauthenticated GraphQ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T01:00:27.000Z ##

🟠 CVE-2026-63421 - High (7.5)

Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compares the signed take argument directly with graphql.maxTake, allowing a remote unauthenticated GraphQ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61824
(8.2 HIGH)

EPSS: 0.23%

updated 2026-08-21T21:17:01.017000

2 posts

Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings without context-appropriate escaping, and buildExtractorResponse() returns this contentHtml without the main pipeline's DOM-based sanitization. The affected paths include src/extractors/x-article.ts, src/extractors/substack.ts,

thehackerwire@mastodon.social at 2026-08-22T00:01:05.000Z ##

🟠 CVE-2026-61824 - High (8.2)

Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings without context-appropriate escaping, and buildExtractorResponse() returns...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T00:01:05.000Z ##

🟠 CVE-2026-61824 - High (8.2)

Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings without context-appropriate escaping, and buildExtractorResponse() returns...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-30890
(8.0 HIGH)

EPSS: 0.23%

updated 2026-08-21T21:16:57.103000

2 posts

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3.

thehackerwire@mastodon.social at 2026-08-22T03:02:20.000Z ##

🟠 CVE-2026-30890 - High (8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T03:02:20.000Z ##

🟠 CVE-2026-30890 - High (8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18290
(7.8 HIGH)

EPSS: 0.26%

updated 2026-08-21T21:16:55.823000

1 posts

OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG fil

hugovalters@mastodon.social at 2026-08-21T12:07:43.000Z ##

CVE-2026-18290 - RCE in OriginLab OriginPro via OGG parsing. Out-of-bounds write leads to arbitrary code execution. CVSS 7.8. No patch yet; avoid opening untrusted OGG files. #CVE #OriginPro #infosec

valtersit.com/cve/CVE-2026-182

##

CVE-2026-77414(CVSS UNKNOWN)

EPSS: 0.35%

updated 2026-08-21T20:58:02

2 posts

Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to a bypassable `hasOwnProperty` check in `environment.lookup` https://github.com/jsonata-js/jsonata/blob/8ee4476f8a228bfc7a62979ae0a9c13a4043cd03/src/jsonata.js#L1863-L1871 This was fixed in https://github.com/jsonata-js/jsonata/pull/799 (https://github.com/jsonata-js/jsonata/pull/799/files

offseq at 2026-08-22T03:00:24.208Z ##

CRITICAL: CVE-2026-77414 in jsonata-js (<1.8.8, <2.2.1) enables remote code execution via code injection (CWE-94). Update to 1.8.8/2.2.1 now. No workaround. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-22T03:00:24.000Z ##

CRITICAL: CVE-2026-77414 in jsonata-js (<1.8.8, <2.2.1) enables remote code execution via code injection (CWE-94). Update to 1.8.8/2.2.1 now. No workaround. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202677414 #infosec #security

##

CVE-2026-68508
(7.8 HIGH)

EPSS: 0.25%

updated 2026-08-21T20:57:32

2 posts

## Summary `hydra.utils.instantiate()` resolves and calls Python objects from config. If an application passes untrusted config to `instantiate()`, an attacker who controls `_target_` and its arguments can cause arbitrary code execution in the consuming process. Hydra is not a network service. Exploitation requires a consuming application, library, or user workflow to load attacker-controlled co

thehackerwire@mastodon.social at 2026-08-22T00:00:54.000Z ##

🟠 CVE-2026-68508 - High (7.8)

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instantiate2.py, a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T00:00:54.000Z ##

🟠 CVE-2026-68508 - High (7.8)

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instantiate2.py, a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63135
(8.2 HIGH)

EPSS: 0.23%

updated 2026-08-21T20:57:24

2 posts

### Summary YOURLS stores the HTTP `Referer` header for short URL redirects and later renders aggregated referrer domains in the per-link statistics page. An unauthenticated attacker can send a crafted `Referer` header to any existing short URL. When an authenticated administrator or stats-page viewer opens that short URL's statistics page, the crafted referrer is embedded into Google Charts Java

thehackerwire@mastodon.social at 2026-08-22T01:00:16.000Z ##

🟠 CVE-2026-63135 - High (8.2)

YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and yourls_log_redirect(), then aggregates the value in y...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T01:00:16.000Z ##

🟠 CVE-2026-63135 - High (8.2)

YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and yourls_log_redirect(), then aggregates the value in y...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61539
(10.0 CRITICAL)

EPSS: 0.66%

updated 2026-08-21T20:56:39

4 posts

### Summary Xinference used Python's unsafe `eval()` function when parsing Llama3 tool-call output generated by a large language model. Because the model output can be influenced by attacker-controlled prompts sent to the chat completion API, a remote attacker can craft prompts that cause the model to return a Python expression. Xinference then evaluates that expression on the server while post-p

offseq at 2026-08-22T06:00:25.516Z ##

CVE-2026-61539: CRITICAL RCE in xorbitsai Xinference <=2.5.0 — attacker-controlled input reaches Python eval(), enabling unauthenticated code execution. Patch to 2.7.0. CVSS: 10.0 🛡️ radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-22T02:01:29.000Z ##

🔴 CVE-2026-61539 - Critical (10)

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-22T06:00:25.000Z ##

CVE-2026-61539: CRITICAL RCE in xorbitsai Xinference <=2.5.0 — attacker-controlled input reaches Python eval(), enabling unauthenticated code execution. Patch to 2.7.0. CVSS: 10.0 🛡️ radar.offseq.com/threat/cve-20 #OffSeq #CVE202661539 #infosec #remotecodeexecution

##

thehackerwire@mastodon.social at 2026-08-22T02:01:29.000Z ##

🔴 CVE-2026-61539 - Critical (10)

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64679
(8.1 HIGH)

EPSS: 0.38%

updated 2026-08-21T20:55:33

2 posts

### Summary Atlantis versions `>= 0.19.8` and `< 0.45.0` did not consistently validate user-controlled `workspace` values before using them to construct local workspace paths. A crafted workspace value containing path traversal segments could cause Atlantis to resolve workspace paths outside the intended per-pull workspace directory. In vulnerable versions or code paths, Atlantis could create, us

thehackerwire@mastodon.social at 2026-08-22T02:01:08.000Z ##

🟠 CVE-2026-64679 - High (8.1)

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted repository-level...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T02:01:08.000Z ##

🟠 CVE-2026-64679 - High (8.1)

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted repository-level...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76904
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-21T20:26:30

2 posts

### Summary An SQL Injection Vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation: * `jsonArrayContains` function Requires PostGIS 12 or greater with a String or JSON field For PostGIS 12 and greater `jsonArrayContains(<column>, <pointer>, <value>)` function writes `<value>` into generated SQL without escaping. ### Patches * GeoTools 35.1 * GeoTo

1 repos

https://github.com/YonLiud/CVE-2026-76904

thehackerwire@mastodon.social at 2026-08-21T22:00:11.000Z ##

🔴 CVE-2026-76904 - Critical (9.8)

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore imple...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T22:00:11.000Z ##

🔴 CVE-2026-76904 - Critical (9.8)

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore imple...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-27462
(7.5 HIGH)

EPSS: 0.31%

updated 2026-08-21T20:16:33.870000

2 posts

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.

thehackerwire@mastodon.social at 2026-08-21T21:01:09.000Z ##

🟠 CVE-2026-27462 - High (7.5)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T21:01:09.000Z ##

🟠 CVE-2026-27462 - High (7.5)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-41449
(7.8 HIGH)

EPSS: 0.64%

updated 2026-08-21T19:17:01.520000

2 posts

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data such as usernames, process names, or filenames. Attackers can exploit this vulnerability through crafted evidence inputs, mounted images with hostile filenames, or

thehackerwire@mastodon.social at 2026-08-22T07:03:17.000Z ##

🟠 CVE-2026-41449 - High (7.8)

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data such as us...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T07:03:17.000Z ##

🟠 CVE-2026-41449 - High (7.8)

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data such as us...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63462
(7.5 HIGH)

EPSS: 0.38%

updated 2026-08-21T19:14:39

2 posts

## Summary An unauthenticated `POST` to any OpenAPI-validated endpoint, including the anonymous `POST /edge/validate` and `POST /edge/issue-token`, crashes the entire Unleash server with one request body of deeply-nested JSON. When request-body validation fails, Unleash builds the error message by calling `JSON.stringify` on the raw offending value taken from the request body. A value nested a f

thehackerwire@mastodon.social at 2026-08-21T20:00:16.000Z ##

🟠 CVE-2026-63462 - High (7.5)

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericErrorMessag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T20:00:16.000Z ##

🟠 CVE-2026-63462 - High (7.5)

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericErrorMessag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-41451
(7.8 HIGH)

EPSS: 0.72%

updated 2026-08-21T18:35:08

2 posts

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into command strings without escaping before execution via eval. Attackers can inject shell metacharacters such as command substitution syntax or semicolons throug

thehackerwire@mastodon.social at 2026-08-22T08:01:56.000Z ##

🟠 CVE-2026-41451 - High (7.8)

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T08:01:56.000Z ##

🟠 CVE-2026-41451 - High (7.8)

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-41450
(7.8 HIGH)

EPSS: 0.70%

updated 2026-08-21T18:35:07

2 posts

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without proper escaping before being evaluated with eval. Attackers can exploit this by crafting malicious filenames or artifact definitions containing shell metacharacters s

thehackerwire@mastodon.social at 2026-08-22T08:01:47.000Z ##

🟠 CVE-2026-41450 - High (7.8)

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without proper escapi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T08:01:47.000Z ##

🟠 CVE-2026-41450 - High (7.8)

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without proper escapi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39909
(8.1 HIGH)

EPSS: 0.77%

updated 2026-08-21T18:35:07

2 posts

llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by storing a computation graph, freeing referenced buffers, and reclaiming freed memory with attacker-controlled content. Attackers can send RPC requests to trigger re-execution of stored graphs with dangl

thehackerwire@mastodon.social at 2026-08-21T17:59:50.000Z ##

🟠 CVE-2026-39909 - High (8.1)

llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by storing a computation graph, freeing referenced b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T17:59:50.000Z ##

🟠 CVE-2026-39909 - High (8.1)

llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by storing a computation graph, freeing referenced b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75932
(8.6 HIGH)

EPSS: 0.40%

updated 2026-08-21T18:35:02

3 posts

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.

hugovalters@mastodon.social at 2026-08-22T14:07:12.000Z ##

CVE-2026-75932 - Critical Jet Admin vuln: malicious app can hijack custom domain & steal OAuth secrets. CVSS 8.6. Unpatched — audit configs & block app creation. #CVE #JetAdmin #infosec

valtersit.com/cve/CVE-2026-759

##

thehackerwire@mastodon.social at 2026-08-21T17:00:47.000Z ##

🟠 CVE-2026-75932 - High (8.6)

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T17:00:47.000Z ##

🟠 CVE-2026-75932 - High (8.6)

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69502
(10.0 CRITICAL)

EPSS: 0.76%

updated 2026-08-21T18:35:01

3 posts

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

hugovalters@mastodon.social at 2026-08-22T12:06:18.000Z ##

CVE-2026-69502 - Critical SSRF in Azure SQL DB allows privilege escalation. CVSS 10. Patch under review - update when available. #CVE #Azure #infosec

valtersit.com/cve/CVE-2026-695

##

thehackerwire@mastodon.social at 2026-08-21T17:00:55.000Z ##

🔴 CVE-2026-69502 - Critical (10)

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T17:00:55.000Z ##

🔴 CVE-2026-69502 - Critical (10)

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-22681
(8.5 HIGH)

EPSS: 0.28%

updated 2026-08-21T18:35:01

2 posts

OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a crafted URL to /api/v1/resources, causing the server to issue outbound HEAD and GET requests with redirects enabled to loopback, RFC 1918, link-local, or cl

1 repos

https://github.com/pcrosby-1990/cip-security-poc

thehackerwire@mastodon.social at 2026-08-22T10:00:23.000Z ##

🟠 CVE-2026-22681 - High (8.5)

OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T10:00:23.000Z ##

🟠 CVE-2026-22681 - High (8.5)

OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75501(CVSS UNKNOWN)

EPSS: 0.37%

updated 2026-08-21T18:34:56

2 posts

A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port‑forwarding rules via the UPnP WANIPConnection service. The device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls. A remote attacker can send crafted SOAP requests to add, delete, or enumerate port m

DailyCyberSecurity at 2026-08-21T16:32:05.916Z ##

CVE-2026-75501 exposes an unauthenticated UPnP service on Calix routers. Public details and PoC code show how attackers bypass NAT and firewall protections.

securityonline.info/cve-2026-7

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T16:32:05.000Z ##

CVE-2026-75501 exposes an unauthenticated UPnP service on Calix routers. Public details and PoC code show how attackers bypass NAT and firewall protections.

#CVE202675501 #Calix #UPnP #RouterSecurity #NAT #IoTSecurity

securityonline.info/cve-2026-7

##

CVE-2026-73570
(8.9 HIGH)

EPSS: 1.04%

updated 2026-08-21T18:34:48

13 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

1 repos

https://github.com/HORKimhab/CVE-2026-73570

youranonnewsirc@nerdculture.de at 2026-08-22T10:26:23.000Z ##

Geopolitical tensions rise as the US escalates economic pressure on Iran, which labels new sanctions as a "declaration of war". Ukraine faces critical missile shortages amid intensified Russian strikes. In technology, major investments continue in AI infrastructure, with Google backing Marvell's custom AI chips. Cybersecurity sees CISA adding a critical Zimbra vulnerability (CVE-2026-73570) to its KEV catalog and new banking Trojans actively exploited globally.

#AnonNews_irc #Cybersecurity #News

##

undercodenews@mastodon.social at 2026-08-22T09:14:19.000Z ##

Critical Zimbra Vulnerability Enters CISA’s KEV Catalog as Attackers Exploit Unauthenticated Remote Code Execution + Video

A New Warning for Zimbra Administrators A serious security warning is now hanging over organizations running Zimbra Collaboration Suite (ZCS). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog after Poland’s national cybersecurity response team confirmed…

undercodenews.com/critical-zim

##

security_crawler_carl at 2026-08-22T06:16:36.079Z ##

🏆 New Achievement! Patch Notes: Server Owned by Community!

CHANGELOG v-Oh-No: ADDED — unauthenticated remote attackers executing arbitrary OS commands as the Zimbra user. ADDED — full control of your enterprise email server, courtesy of CVE-2026-73570. FIXED (by the developers, on July 20, in version 10.1.20) — the exact hole threat actors are currently crawling through, per Poland's CERT Polska. KNOWN ISSUE — you haven't patched yet.

The fix shipped over a month ago. (1/2)

##

secdb at 2026-08-21T19:00:10.468Z ##

🚨 [CISA-2026:0821] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-69836 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Entra ID
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-73570 (secdb.nttzen.cloud/cve/detail/)
- Name: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Synacor
- Product: Zimbra Collaboration Suite (ZCS)
- Notes: wiki.zimbra.com/wiki/Zimbra_Se ; blog.zimbra.com/2026/07/patch- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-21T17:01:04.000Z ##

CVE ID: CVE-2026-73570
Vendor: Synacor
Product: Zimbra Collaboration Suite (ZCS)
Date Added: 2026-08-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

undercodenews@mastodon.social at 2026-08-21T10:44:35.000Z ##

Zimbra Under Attack: Critical CVE-2026-73570 Turns Internet-Facing Mail Servers Into High-Value Targets + Video

A Warning That Arrived Just 28 Days After the Patch A newly confirmed exploitation campaign against Zimbra Collaboration Suite is raising the pressure on organizations that operate their own email infrastructure. Poland’s national computer emergency response team, CERT Polska, has confirmed that attackers are actively exploiting CVE-2026-73570, a critical…

undercodenews.com/zimbra-under

##

youranonnewsirc@nerdculture.de at 2026-08-22T10:26:23.000Z ##

Geopolitical tensions rise as the US escalates economic pressure on Iran, which labels new sanctions as a "declaration of war". Ukraine faces critical missile shortages amid intensified Russian strikes. In technology, major investments continue in AI infrastructure, with Google backing Marvell's custom AI chips. Cybersecurity sees CISA adding a critical Zimbra vulnerability (CVE-2026-73570) to its KEV catalog and new banking Trojans actively exploited globally.

#AnonNews_irc #Cybersecurity #News

##

security_crawler_carl@infosec.exchange at 2026-08-22T06:16:36.000Z ##

🏆 New Achievement! Patch Notes: Server Owned by Community!

CHANGELOG v-Oh-No: ADDED — unauthenticated remote attackers executing arbitrary OS commands as the Zimbra user. ADDED — full control of your enterprise email server, courtesy of CVE-2026-73570. FIXED (by the developers, on July 20, in version 10.1.20) — the exact hole threat actors are currently crawling through, per Poland's CERT Polska. KNOWN ISSUE — you haven't patched yet.

The fix shipped over a month ago. (1/2)

##

secdb@infosec.exchange at 2026-08-21T19:00:10.000Z ##

🚨 [CISA-2026:0821] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-69836 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Entra ID
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-73570 (secdb.nttzen.cloud/cve/detail/)
- Name: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Synacor
- Product: Zimbra Collaboration Suite (ZCS)
- Notes: wiki.zimbra.com/wiki/Zimbra_Se ; blog.zimbra.com/2026/07/patch- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260821 #cisa20260821 #cve_2026_69836 #cve_2026_73570 #cve202669836 #cve202673570

##

cisakevtracker@mastodon.social at 2026-08-21T17:01:04.000Z ##

CVE ID: CVE-2026-73570
Vendor: Synacor
Product: Zimbra Collaboration Suite (ZCS)
Date Added: 2026-08-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

beyondmachines1@infosec.exchange at 2026-08-21T09:01:12.000Z ##

Critical Zimbra RCE Vulnerability Exploited in Global Attacks

Zimbra patched nine vulnerabilities in its Collaboration Suite, including a critical RCE flaw (CVE-2026-73570) that attackers are currently exploiting to take control of mail servers. Organizations should update to version 10.1.20 and check logs for signs of compromise.

**If you run Zimbra Collaboration Suite, update to version 10.1.20 ASAP. Attackers are already exploiting this to take over mail servers, and everything older is vulnerable. Because this flaw is being actively exploited, also check for signs of breach: look for unexpected files in `/opt/zimbra/jetty/webapps/` and `/tmp/`, and review `/var/log/zimbra.log` for services restarting on their own.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-08-20T22:20:00.000Z ##

CVE-2026-73570 in Zimbra Collaboration Suite is under active exploitation. CERT Polska flagged real-world attacks this week. The flaw grants unauthenticated remote OS command execution when zimbra-snmp is installed with SNMP enabled. Attacker identity and campaign goals remain unknown — patch priority is critical for affected deployments.

#Zimbra #CVE202673570 #ThreatIntelligence #PatchNow

cyberworldops.eu/en/zimbra-cve

##

cyberworldops@infosec.exchange at 2026-08-20T18:20:00.000Z ##

Active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite is underway. The command injection flaw enables unauthenticated RCE on ZCS versions prior to 10.1.20 when zimbra-snmp is installed with SNMP notifications active. Attackers exploit this via crafted SMTP requests for full server compromise. Patch or disable SNMP immediately.

#ZimbraRCE #CVE202673570 #PatchNow

cyberworldops.eu/en/zimbra-vul

##

CVE-2026-77812
(0 None)

EPSS: 0.06%

updated 2026-08-21T18:16:52.527000

2 posts

DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to QuickTransfer mode, the DJI Fly application exchanges DUML messages with the drone over BLE, including the Wi-Fi credentials. An attacker within BLE range can passively sniff this t

CVE-2026-55241
(7.5 HIGH)

EPSS: 0.44%

updated 2026-08-21T18:16:48.790000

2 posts

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/src/api/routes/authRoutes.ts passes multipart profileImage uploads through in-memory Multer parsing before registration validation, without file-size, file

thehackerwire@mastodon.social at 2026-08-22T08:02:06.000Z ##

🟠 CVE-2026-55241 - High (7.5)

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/sr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T08:02:06.000Z ##

🟠 CVE-2026-55241 - High (7.5)

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/sr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54789
(7.5 HIGH)

EPSS: 0.39%

updated 2026-08-21T18:16:48.680000

2 posts

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a val

thehackerwire@mastodon.social at 2026-08-21T17:01:06.000Z ##

🟠 CVE-2026-54789 - High (7.5)

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds wr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T17:01:06.000Z ##

🟠 CVE-2026-54789 - High (7.5)

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds wr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73137
(7.7 HIGH)

EPSS: 0.29%

updated 2026-08-21T16:18:16.620000

1 posts

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch sensitive credentials from any namespace, which are then sent to an attacker-cont

thehackerwire@mastodon.social at 2026-08-20T22:00:36.000Z ##

🟠 CVE-2026-73137 - High (7.7)

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69855
(7.7 HIGH)

EPSS: 0.48%

updated 2026-08-21T16:18:11.723000

1 posts

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

thehackerwire@mastodon.social at 2026-08-20T23:01:19.000Z ##

🟠 CVE-2026-69855 - High (7.7)

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55622
(7.7 HIGH)

EPSS: 0.20%

updated 2026-08-21T16:17:19.623000

2 posts

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access.

thehackerwire@mastodon.social at 2026-08-22T13:00:01.000Z ##

🟠 CVE-2026-55622 - High (7.7)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T13:00:01.000Z ##

🟠 CVE-2026-55622 - High (7.7)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48751
(9.9 CRITICAL)

EPSS: 0.70%

updated 2026-08-21T16:17:17.533000

2 posts

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`. Version 7.2.0 patches the issue.

thehackerwire@mastodon.social at 2026-08-23T05:59:55.000Z ##

🔴 CVE-2026-48751 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T05:59:55.000Z ##

🔴 CVE-2026-48751 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48749
(9.9 CRITICAL)

EPSS: 0.81%

updated 2026-08-21T16:17:17.413000

2 posts

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the issue.

thehackerwire@mastodon.social at 2026-08-23T02:00:28.000Z ##

🔴 CVE-2026-48749 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T02:00:28.000Z ##

🔴 CVE-2026-48749 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50112
(8.8 HIGH)

EPSS: 0.32%

updated 2026-08-21T15:33:15

2 posts

SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can later be downloaded through normal APIs. RCE on KVM hypervisor via NFS, Metalink files with/without Direct Downloads: An authenticated Cl

DailyCyberSecurity at 2026-08-21T15:57:22.657Z ##

Apache CloudStack patched 20 flaws. CVE-2026-50112, a critical bug, allows cross-tenant remote code execution as root on KVM hypervisor hosts.

securityonline.info/cve-2026-5

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T15:57:22.000Z ##

Apache CloudStack patched 20 flaws. CVE-2026-50112, a critical bug, allows cross-tenant remote code execution as root on KVM hypervisor hosts.

#ApacheCloudStack #CVE202650112 #RCE #KVM #CloudSecurity #IaaS

securityonline.info/cve-2026-5

##

CVE-2026-77814
(7.5 HIGH)

EPSS: 0.41%

updated 2026-08-21T15:32:19

2 posts

is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins with an allowed path therefore satisfies the comparison, so where /data/images is allowed a request for /data/images_private/secret.txt is treated as trusted and served by FileResponse, di

thehackerwire@mastodon.social at 2026-08-21T16:00:20.000Z ##

🟠 CVE-2026-77814 - High (7.5)

is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins with an allowed path therefore sati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T16:00:20.000Z ##

🟠 CVE-2026-77814 - High (7.5)

is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins with an allowed path therefore sati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77806
(9.8 CRITICAL)

EPSS: 0.79%

updated 2026-08-21T15:32:18

4 posts

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.

thehackerwire@mastodon.social at 2026-08-23T07:00:30.000Z ##

🔴 CVE-2026-77806 - Critical (9.8)

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity at 2026-08-21T16:59:33.307Z ##

CVE-2026-77806, a CVSS 9.8 SPIP unauthenticated RCE, is exploited in the wild. A public Metasploit module and full details are now available.

securityonline.info/cve-2026-7

##

thehackerwire@mastodon.social at 2026-08-23T07:00:30.000Z ##

🔴 CVE-2026-77806 - Critical (9.8)

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T16:59:33.000Z ##

CVE-2026-77806, a CVSS 9.8 SPIP unauthenticated RCE, is exploited in the wild. A public Metasploit module and full details are now available.

#CVE202677806 #SPIP #RCE #ExploitedInTheWild #Metasploit #CMS

securityonline.info/cve-2026-7

##

CVE-2026-77087
(9.6 CRITICAL)

EPSS: 0.40%

updated 2026-08-21T15:32:18

3 posts

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.

hugovalters@mastodon.social at 2026-08-21T17:06:05.000Z ##

CVE-2026-77087 - Critical RCE in Paperclip <0.3.1 via DNS rebinding. Host header validation flaw allows authenticated API abuse. CVSS 9.6. No patch yet - update when available. #CVE #infosec #Paperclip

valtersit.com/cve/CVE-2026-770

##

thehackerwire@mastodon.social at 2026-08-21T16:00:10.000Z ##

🔴 CVE-2026-77087 - Critical (9.6)

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T16:00:10.000Z ##

🔴 CVE-2026-77087 - Critical (9.6)

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77815
(7.5 HIGH)

EPSS: 0.41%

updated 2026-08-21T15:32:18

2 posts

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment comparison performed by is_path_trusted in scripts/iib/api.py while pointing outside that directory, and FileResponse follows the link when serving the response, so a

thehackerwire@mastodon.social at 2026-08-21T16:00:31.000Z ##

🟠 CVE-2026-77815 - High (7.5)

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment comparison pe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T16:00:31.000Z ##

🟠 CVE-2026-77815 - High (7.5)

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment comparison pe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63125
(9.9 CRITICAL)

EPSS: 0.66%

updated 2026-08-21T15:16:46.427000

3 posts

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships `backup.yaml` as a symlink to a host file. When the root daemon writes the instance's backup file, it follows the symlin

thehackerwire@mastodon.social at 2026-08-22T12:00:36.000Z ##

🔴 CVE-2026-63125 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

hugovalters@mastodon.social at 2026-08-21T18:03:44.000Z ##

CVE-2026-63125 – Critical RCE/privesc in Incus. Unprivileged user can execute code as root via symlink attack. CVSS 9.9. Patch to 7.3.0 immediately. #CVE #Incus #infosec

valtersit.com/cve/CVE-2026-631

##

thehackerwire@mastodon.social at 2026-08-22T12:00:36.000Z ##

🔴 CVE-2026-63125 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77767
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-21T14:16:53.773000

2 posts

Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role, so controllers without their own attribute reject anonymous callers. The report preview action in apps/api/app/Controllers/ReportsController.cs carries [AllowAnonymous] and therefore opts out of that policy. PreviewReport loads the Project row named

thehackerwire@mastodon.social at 2026-08-23T07:00:41.000Z ##

🟠 CVE-2026-77767 - High (7.5)

Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role, so controllers without their own attribute reject anonymous callers. The report preview action in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T07:00:41.000Z ##

🟠 CVE-2026-77767 - High (7.5)

Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role, so controllers without their own attribute reject anonymous callers. The report preview action in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77651
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-21T14:16:53.510000

1 posts

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

offseq@infosec.exchange at 2026-08-21T01:30:22.000Z ##

CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

##

CVE-2026-18781
(8.1 HIGH)

EPSS: 0.32%

updated 2026-08-21T13:16:55.727000

1 posts

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.

offseq@infosec.exchange at 2026-08-21T07:30:24.000Z ##

CVE-2026-18781: CRITICAL code injection in Drag and Drop Multiple File Upload for Contact Form 7 <1.3.9.9. Unauthenticated users can run code on affected WordPress servers. No patch yet — restrict or disable plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE202618781

##

CVE-2026-77086
(9.1 CRITICAL)

EPSS: 0.65%

updated 2026-08-21T12:30:41

2 posts

SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write arbitrary files to any location via install operations or recursively delete directories via uninstall operations by supplying crafted packageName values.

thehackerwire@mastodon.social at 2026-08-23T07:00:53.000Z ##

🔴 CVE-2026-77086 - Critical (9.1)

SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T07:00:53.000Z ##

🔴 CVE-2026-77086 - Critical (9.1)

SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77776
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-08-21T12:30:41

5 posts

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client can therefore name another user's identifier and read or write that user's stored LLM memory. The fix introduces a single r

hugovalters@mastodon.social at 2026-08-21T15:02:38.000Z ##

CVE-2026-77776 - Critical IDOR in Headroom LLM proxy. Spoof x-headroom-user-id to read/write other users' memory. CVSS 9.1. No patch yet - restrict access now. #CVE #Headroom #infosec

valtersit.com/cve/CVE-2026-777

##

thehackerwire@mastodon.social at 2026-08-21T14:00:24.000Z ##

🔴 CVE-2026-77776 - Critical (9.1)

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-21T12:00:31.471Z ##

CRITICAL: CVE-2026-77776 in Headroom Labs Headroom (<0.36.1) allows unauth'd attackers to spoof x-headroom-user-id and access/modify any user's LLM memory. Default configs expose this via 0.0.0.0 binding. Restrict access & use auth tokens. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-21T14:00:24.000Z ##

🔴 CVE-2026-77776 - Critical (9.1)

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-21T12:00:31.000Z ##

CRITICAL: CVE-2026-77776 in Headroom Labs Headroom (<0.36.1) allows unauth'd attackers to spoof x-headroom-user-id and access/modify any user's LLM memory. Default configs expose this via 0.0.0.0 binding. Restrict access & use auth tokens. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec #LLM

##

CVE-2026-77683
(9.9 CRITICAL)

EPSS: 1.51%

updated 2026-08-21T12:30:37

4 posts

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

thehackerwire@mastodon.social at 2026-08-23T09:00:03.000Z ##

🔴 CVE-2026-77683 - Critical (9.9)

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr results in command injection. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-21T10:30:27.958Z ##

CVE-2026-77683: CRITICAL command injection in Comfast CF-N1-S (2.6.0.1) via /cgi-bin/mbox-config timestr parameter. Public exploit available, remote exploitation possible. Patch unavailable. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-23T09:00:03.000Z ##

🔴 CVE-2026-77683 - Critical (9.9)

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr results in command injection. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-21T10:30:27.000Z ##

CVE-2026-77683: CRITICAL command injection in Comfast CF-N1-S (2.6.0.1) via /cgi-bin/mbox-config timestr parameter. Public exploit available, remote exploitation possible. Patch unavailable. radar.offseq.com/threat/cve-20 #OffSeq #CVE202677683 #IoTSecurity #CommandInjection

##

CVE-2026-77775
(8.6 HIGH)

EPSS: 0.36%

updated 2026-08-21T12:30:35

2 posts

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http or https scheme and a hostname, and returns it for use as the upstream base; _select_passthrough_base_url in headroom/providers/proxy_routes.py reads the

thehackerwire@mastodon.social at 2026-08-21T14:00:11.000Z ##

🟠 CVE-2026-77775 - High (8.6)

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T14:00:11.000Z ##

🟠 CVE-2026-77775 - High (8.6)

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59279
(7.5 HIGH)

EPSS: 0.39%

updated 2026-08-21T12:30:34

2 posts

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimately causing a Denial of Service that affects al

thehackerwire@mastodon.social at 2026-08-21T14:00:36.000Z ##

🟠 CVE-2026-59279 - High (7.5)

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T14:00:36.000Z ##

🟠 CVE-2026-59279 - High (7.5)

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72529
(9.8 CRITICAL)

EPSS: 0.78%

updated 2026-08-21T04:18:15.753000

10 posts

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

security_crawler_carl at 2026-08-22T20:01:20.418Z ##

🏆 New Achievement! Port 4307 Is Not a Safe Harbor!

Conducting inventory audit on your TrueConf Server installation. Status: compromised. Line items include two unauthenticated RCE vulnerabilities — CVE-2026-72529 and CVE-2026-72530 — currently checked out under the name Head Mare, a hacktivist group who used them to swap a server file for a web shell and deploy PhantomCore malware. Item condition: cursed. (1/2)

##

threatnoir at 2026-08-22T17:05:48.623Z ##

⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws

Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise.

threatnoir.com/focus

🤖 AI generated summary

##

thecybermind at 2026-08-21T15:01:53.473Z ##

Critical Alert: CVE-2026-72529 allows unauthenticated command execution on TrueConf Servers. Our T-SUITE report maps the attack surface and provides immediate hardening steps to secure your perimeter. Read the full brief here. thecybermind.co/jily

##

security_crawler_carl@infosec.exchange at 2026-08-22T20:01:20.000Z ##

🏆 New Achievement! Port 4307 Is Not a Safe Harbor!

Conducting inventory audit on your TrueConf Server installation. Status: compromised. Line items include two unauthenticated RCE vulnerabilities — CVE-2026-72529 and CVE-2026-72530 — currently checked out under the name Head Mare, a hacktivist group who used them to swap a server file for a web shell and deploy PhantomCore malware. Item condition: cursed. (1/2)

##

threatnoir@infosec.exchange at 2026-08-22T17:05:48.000Z ##

⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws

Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

thecybermind@infosec.exchange at 2026-08-21T15:01:53.000Z ##

Critical Alert: CVE-2026-72529 allows unauthenticated command execution on TrueConf Servers. Our T-SUITE report maps the attack surface and provides immediate hardening steps to secure your perimeter. Read the full brief here. thecybermind.co/jily

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T21:30:12.000Z ##

CISA confirms two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, are exploited in the wild to deliver PhantomCore malware. Patch now.

#TrueConf #CVE #ExploitedInTheWild #PhantomCore #HeadMare #InfoSec #PatchNow

securityonline.info/trueconf-c

##

AAKL@infosec.exchange at 2026-08-20T20:15:43.000Z ##

CISA has added two known vulnerabilities to the KEV catalogue.

- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Yesterday:

Cisco:

CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

secdb@infosec.exchange at 2026-08-20T19:00:11.000Z ##

🚨 [CISA-2026:0820] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-72529 (secdb.nttzen.cloud/cve/detail/)
- Name: TrueConf Server Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TrueConf
- Product: Server
- Notes: trueconf.com/blog/news/securit ; ics-cert.kaspersky.com/advisor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-72530 (secdb.nttzen.cloud/cve/detail/)
- Name: TrueConf Server Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TrueConf
- Product: Server
- Notes: trueconf.com/blog/news/securit ; ics-cert.kaspersky.com/advisor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260820 #cisa20260820 #cve_2026_72529 #cve_2026_72530 #cve202672529 #cve202672530

##

cisakevtracker@mastodon.social at 2026-08-20T18:01:22.000Z ##

CVE ID: CVE-2026-72529
Vendor: TrueConf
Product: Server
Date Added: 2026-08-20
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-76158(CVSS UNKNOWN)

EPSS: 0.41%

updated 2026-08-21T03:31:30

1 posts

External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.

offseq@infosec.exchange at 2026-08-21T03:00:24.000Z ##

CVE-2026-76158: Datiphy Data Management Center 8.3.0 faces CRITICAL vuln (CVSS 9.3) — upload API allows unauthenticated file writes anywhere via path traversal 🗂️. Restrict access & monitor uploads until patch. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Datiphy #CVE202676158

##

CVE-2026-76155(CVSS UNKNOWN)

EPSS: 0.29%

updated 2026-08-21T03:31:29

1 posts

Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.

offseq@infosec.exchange at 2026-08-21T06:00:24.000Z ##

Datiphy Data Management Center 8.3.0 hit by CRITICAL vuln (CVE-2026-76155) due to default admin creds. Remote attackers can gain full access. No patch yet — change credentials & limit access ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Vuln #Datiphy

##

CVE-2026-76156(CVSS UNKNOWN)

EPSS: 0.83%

updated 2026-08-21T03:31:29

1 posts

OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.

offseq@infosec.exchange at 2026-08-21T04:30:26.000Z ##

CVE-2026-76156: CRITICAL OS command injection in Datiphy Data Management Center (8.3.0 – 8.5.1). Authenticated admins can run root OS commands via API. No patch yet — restrict admin access, monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #CVE202676156 #Vuln #Infosec

##

CVE-2026-77645(CVSS UNKNOWN)

EPSS: 0.47%

updated 2026-08-21T00:31:31

1 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

offseq@infosec.exchange at 2026-08-21T00:00:37.000Z ##

CRITICAL RCE flaw (CVE-2026-77645) in PTC Windchill PDMLink (multiple versions). Unauthenticated attackers can execute remote code via insecure deserialization. No patch yet — restrict access & monitor closely. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #PTC #Infosec

##

CVE-2026-72860
(8.5 HIGH)

EPSS: 0.22%

updated 2026-08-21T00:31:31

1 posts

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares hostname strings only: it resolves no DNS, does not revalidate after a redirect, and its IPv4-mapped IPv6 branch is unreachable. The branch matches ^::ffff:(\d+\.\d+\.

thehackerwire@mastodon.social at 2026-08-20T23:01:08.000Z ##

🟠 CVE-2026-72860 - High (8.5)

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares hostname strin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72848
(8.6 HIGH)

EPSS: 0.48%

updated 2026-08-21T00:31:31

1 posts

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child loc straight to self.scrape_all([loc.text], "xml"), which reaches WebBaseLoader.scrape_all and an aiohttp GET, with no dom

thehackerwire@mastodon.social at 2026-08-20T23:00:58.000Z ##

🟠 CVE-2026-72848 - High (8.6)

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72818
(7.5 HIGH)

EPSS: 0.51%

updated 2026-08-21T00:31:31

1 posts

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label separators can be partitioned in exponentially many ways, and because the branch also requires a trailing top-level domain t

thehackerwire@mastodon.social at 2026-08-20T23:00:07.000Z ##

🟠 CVE-2026-72818 - High (7.5)

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72843
(9.8 CRITICAL)

EPSS: 0.57%

updated 2026-08-21T00:31:24

4 posts

The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware guards the route; the only middleware in the chain parses the JSON body. The handler in updateCustomer.js then loads the cust

ransomnews@poliversity.it at 2026-08-23T13:37:01.000Z ##

🚨 🔃 EverShop flaw enables account takeover

CVE-2026-72843 lets attackers overwrite customer email and passwords using an exposed UUID; fixed in 2.2.1.

🔗 read more: securityonline.info/evershop-c

#ransomNews #cyberthreats #ecommerce

##

DailyCyberSecurity at 2026-08-23T06:30:49.897Z ##

A critical EverShop account takeover flaw, CVE-2026-72843, exposes systems to an eCommerce platform vulnerability. Update to version 2.2.1 immediately.

securityonline.info/evershop-c

##

DailyCyberSecurity@infosec.exchange at 2026-08-23T06:30:49.000Z ##

A critical EverShop account takeover flaw, CVE-2026-72843, exposes systems to an eCommerce platform vulnerability. Update to version 2.2.1 immediately.

#EverShop #CyberSecurity #CVE202672843 #Vulnerability #eCommerce

securityonline.info/evershop-c

##

thehackerwire@mastodon.social at 2026-08-20T23:00:18.000Z ##

🔴 CVE-2026-72843 - Critical (9.8)

The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77642
(7.5 HIGH)

EPSS: 0.19%

updated 2026-08-20T22:18:06.070000

1 posts

tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.

thehackerwire@mastodon.social at 2026-08-20T22:59:57.000Z ##

🟠 CVE-2026-77642 - High (7.5)

tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-20...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73040
(8.8 HIGH)

EPSS: 0.67%

updated 2026-08-20T21:31:37

1 posts

Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.server.stacksDir, this.name) and Stack.getStack builds path.join(server.stacksDir, stackName) with no check. The socket handlers in backend/agent-socket-handlers/docke

thehackerwire@mastodon.social at 2026-08-20T22:00:25.000Z ##

🟠 CVE-2026-73040 - High (8.8)

Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.server.stacksD...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66785
(9.9 CRITICAL)

EPSS: 0.29%

updated 2026-08-20T21:31:36

2 posts

A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly validate the network subnets provided by the malicious cluster, enabling it to declare arbitrary network ranges. Consequently, all network traffic intended for

hugovalters@mastodon.social at 2026-08-21T11:14:14.000Z ##

CVE-2026-66785 - Critical network redirection flaw in Submariner. Malicious clusters can hijack peer traffic via crafted endpoints. CVSS 9.9. No patch yet - isolate clusters, monitor traffic. #CVE #Submariner #infosec

valtersit.com/cve/CVE-2026-667

##

thehackerwire@mastodon.social at 2026-08-20T21:00:21.000Z ##

🔴 CVE-2026-66785 - Critical (9.9)

A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly valida...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67567
(9.9 CRITICAL)

EPSS: 0.32%

updated 2026-08-20T21:31:36

2 posts

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary reso

DailyCyberSecurity@infosec.exchange at 2026-08-21T08:11:18.000Z ##

Three Red Hat flaws enable privilege escalation, led by CVE-2026-67567 (CVSS 9.9) in ACM. Two FreeIPA bugs can reach full domain compromise.

#RedHat #CVE202667567 #PrivilegeEscalation #FreeIPA #Kubernetes #ACM

securityonline.info/red-hat-pr

##

thehackerwire@mastodon.social at 2026-08-20T22:01:26.000Z ##

🔴 CVE-2026-67567 - Critical (9.9)

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18420
(8.8 HIGH)

EPSS: 0.96%

updated 2026-08-20T21:31:36

1 posts

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.  To remediate this issue, users should upgrade to OpenSearch Dashboards

thehackerwire@mastodon.social at 2026-08-20T22:01:36.000Z ##

🟠 CVE-2026-18420 - High (8.8)

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. Th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72852
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-20T21:31:36

1 posts

hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In src-lib/convolutional_layer.cpp, l.nweights is computed as (c / groups) * n * size * size and l.outputs as l.out_h * l.out_w * l.out_c, and both feed xcalloc directly. A .cfg whose true dimension product exceeds INT_MAX wraps

thehackerwire@mastodon.social at 2026-08-20T21:00:10.000Z ##

🟠 CVE-2026-72852 - High (7.8)

hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In src-lib/convolutional_layer.cpp, l.nweights is computed as (c / groups) ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19586(CVSS UNKNOWN)

EPSS: 5.04%

updated 2026-08-20T21:31:30

1 posts

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requir

CVE-2026-77638
(8.9 HIGH)

EPSS: 0.17%

updated 2026-08-20T21:31:30

1 posts

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

thehackerwire@mastodon.social at 2026-08-20T22:00:15.000Z ##

🟠 CVE-2026-77638 - High (8.9)

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77148
(9.9 CRITICAL)

EPSS: 0.47%

updated 2026-08-20T20:17:47.110000

1 posts

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.

thehackerwire@mastodon.social at 2026-08-20T21:00:00.000Z ##

🔴 CVE-2026-77148 - Critical (9.9)

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73257
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-08-20T20:17:46.470000

1 posts

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept both headers and prioritize chunked encoding, while a Content-Length-preferring reverse proxy can use

thehackerwire@mastodon.social at 2026-08-20T19:00:25.000Z ##

🔴 CVE-2026-73257 - Critical (9.1)

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_htt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72530
(9.0 None)

EPSS: 0.97%

updated 2026-08-20T18:31:47

9 posts

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

security_crawler_carl at 2026-08-22T20:01:20.418Z ##

🏆 New Achievement! Port 4307 Is Not a Safe Harbor!

Conducting inventory audit on your TrueConf Server installation. Status: compromised. Line items include two unauthenticated RCE vulnerabilities — CVE-2026-72529 and CVE-2026-72530 — currently checked out under the name Head Mare, a hacktivist group who used them to swap a server file for a web shell and deploy PhantomCore malware. Item condition: cursed. (1/2)

##

threatnoir at 2026-08-22T17:05:48.623Z ##

⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws

Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise.

threatnoir.com/focus

🤖 AI generated summary

##

Matchbook3469@mastodon.social at 2026-08-21T15:06:36.000Z ##

🔴 New security advisory:

CVE-2026-72530 affects Trueconf Server.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #ZeroDay #ThreatIntel

##

security_crawler_carl@infosec.exchange at 2026-08-22T20:01:20.000Z ##

🏆 New Achievement! Port 4307 Is Not a Safe Harbor!

Conducting inventory audit on your TrueConf Server installation. Status: compromised. Line items include two unauthenticated RCE vulnerabilities — CVE-2026-72529 and CVE-2026-72530 — currently checked out under the name Head Mare, a hacktivist group who used them to swap a server file for a web shell and deploy PhantomCore malware. Item condition: cursed. (1/2)

##

threatnoir@infosec.exchange at 2026-08-22T17:05:48.000Z ##

⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws

Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T21:30:12.000Z ##

CISA confirms two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, are exploited in the wild to deliver PhantomCore malware. Patch now.

#TrueConf #CVE #ExploitedInTheWild #PhantomCore #HeadMare #InfoSec #PatchNow

securityonline.info/trueconf-c

##

AAKL@infosec.exchange at 2026-08-20T20:15:43.000Z ##

CISA has added two known vulnerabilities to the KEV catalogue.

- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Yesterday:

Cisco:

CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

secdb@infosec.exchange at 2026-08-20T19:00:11.000Z ##

🚨 [CISA-2026:0820] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-72529 (secdb.nttzen.cloud/cve/detail/)
- Name: TrueConf Server Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TrueConf
- Product: Server
- Notes: trueconf.com/blog/news/securit ; ics-cert.kaspersky.com/advisor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-72530 (secdb.nttzen.cloud/cve/detail/)
- Name: TrueConf Server Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TrueConf
- Product: Server
- Notes: trueconf.com/blog/news/securit ; ics-cert.kaspersky.com/advisor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260820 #cisa20260820 #cve_2026_72529 #cve_2026_72530 #cve202672529 #cve202672530

##

cisakevtracker@mastodon.social at 2026-08-20T18:01:06.000Z ##

CVE ID: CVE-2026-72530
Vendor: TrueConf
Product: Server
Date Added: 2026-08-20
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-76641
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-20T18:31:11

1 posts

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attr

thehackerwire@mastodon.social at 2026-08-20T19:00:04.000Z ##

🟠 CVE-2026-76641 - High (7.5)

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77022
(9.9 CRITICAL)

EPSS: 0.46%

updated 2026-08-20T18:31:06

1 posts

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks

thehackerwire@mastodon.social at 2026-08-20T18:00:20.000Z ##

🔴 CVE-2026-77022 - Critical (9.9)

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71428
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-08-20T17:19:40.773000

1 posts

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partition_md is fetched without host validation in unstructured/partition/auto.py, unstructured/partition/html/partition.py, and unstructured/partition/md.py. An

thehackerwire@mastodon.social at 2026-08-20T18:00:43.000Z ##

🔴 CVE-2026-71428 - Critical (9.3)

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partitio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66582
(7.1 HIGH)

EPSS: 0.18%

updated 2026-08-20T17:19:24.533000

1 posts

Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.

hugovalters@mastodon.social at 2026-08-21T14:06:42.000Z ##

CVE-2026-66582 - Unauthenticated XSS in TranslatePress ≤3.3.2. CVSS 7.1. No patch yet. Disable or restrict access now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-665

##

CVE-2026-19490(CVSS UNKNOWN)

EPSS: 0.33%

updated 2026-08-20T15:34:03

6 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

security_crawler_carl at 2026-08-22T21:32:42.872Z ##

🏆 New Achievement! No Password? No Problem!

Welcome, new player, to the Authentication Bypass Tutorial! This mandatory segment introduces CVE-2026-19490, a CVSS 9.3 critical flaw in Citrix NetScaler ADC and NetScaler Gateway. No account required. No user interaction needed. No elevated privileges. The game just... lets attackers in. Think of it as a permanent debuff applied to your enterprise perimeter. (1/2)

##

cyberveille@mastobot.ping.moi at 2026-08-22T13:00:10.000Z ##

📢 [VULN] Citrix NetScaler (CVE-2026-19490) : cette faille permet de contourner l'authentification

Le 19 août 2026, Citrix a publié un nouveau bulletin de sécurité pour NetScaler ADC et NetScaler Gateway. Il fait référence à deux failles de sécurité, dont l'une particulièrement inquiétante : la CVE-2026-19490.

🔗 it-connect.fr/citrix-netscaler
💬 discussion : infosec.pub/post/51278994
#CVE #Cyberveille

##

benzogaga33@mamot.fr at 2026-08-22T09:40:03.000Z ##

Citrix NetScaler (CVE-2026-19490) : cette faille critique permet de contourner l’authentification it-connect.fr/citrix-netscaler #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

security_crawler_carl@infosec.exchange at 2026-08-22T21:32:42.000Z ##

🏆 New Achievement! No Password? No Problem!

Welcome, new player, to the Authentication Bypass Tutorial! This mandatory segment introduces CVE-2026-19490, a CVSS 9.3 critical flaw in Citrix NetScaler ADC and NetScaler Gateway. No account required. No user interaction needed. No elevated privileges. The game just... lets attackers in. Think of it as a permanent debuff applied to your enterprise perimeter. (1/2)

##

benzogaga33@mamot.fr at 2026-08-22T09:40:03.000Z ##

Citrix NetScaler (CVE-2026-19490) : cette faille critique permet de contourner l’authentification it-connect.fr/citrix-netscaler #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

ottoto2017@prattohome.com at 2026-08-21T07:42:40.000Z ##

「Citrixは、NetScalerの新たな脆弱性をできるだけ早く修正するよう管理者に強く求めている。」: #BLEEPINGCOMPUTER

「Citrixは、NetScaler GatewayセキュアリモートアクセスソリューションとNetScaler ADCネットワークアプライアンスに影響を与える2つの脆弱性からシステムを保護するため、顧客に対し直ちにセキュリティ対策を講じるよう警告した。

2つのうちより深刻な脆弱性( CVE-2026-19490 として追跡)では、NetScalerのファームウェアバージョンとSAMLアクションが構成されているかどうかに応じて、アプライアンスがAAA仮想サーバーまたはゲートウェイ(SSL VPN、ICAプロキシ、CVPN、RDPプロキシ)として構成されている場合に、権限を持たないリモート攻撃者が認証をバイパスできる可能性があります。 」

bleepingcomputer.com/news/secu

#prattohome

##

CVE-2026-32475
(9.0 CRITICAL)

EPSS: 0.42%

updated 2026-08-20T12:48:31.843000

5 posts

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

2 repos

https://github.com/0xBlackash/CVE-2026-32475

https://github.com/absholi7ly/Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE

cyberveille@mastobot.ping.moi at 2026-08-21T14:00:05.000Z ##

📢 [VULN] WordPress : cette faille Elementor Pro ouvre votre site aux pirates CVE-2026-32475

Nouvelle alerte à destination de tous les administrateurs de sites WordPress : la faille CVE-2026-32475, corrigée le 19 août 2026 dans Elementor Pro, permet à un visiteur anonyme de déposer un fichier PHP sur un site WordPress, puis de l'exécuter. Aucun compte, aucune interaction avec un administrateur.

🔗 it-connect.fr/elementor-pro-cv
💬 discussion : infosec.pub/post/51237084
#CVE #Cyberveille

##

cyberveille@mastobot.ping.moi at 2026-08-21T14:00:05.000Z ##

📢 [VULN] WordPress : cette faille Elementor Pro ouvre votre site aux pirates CVE-2026-32475

Nouvelle alerte à destination de tous les administrateurs de sites WordPress : la faille CVE-2026-32475, corrigée le 19 août 2026 dans Elementor Pro, permet à un visiteur anonyme de déposer un fichier PHP sur un site WordPress, puis de l'exécuter. Aucun compte, aucune interaction avec un administrateur.

🔗 it-connect.fr/elementor-pro-cv
💬 discussion : infosec.pub/post/51237084
#CVE #Cyberveille

##

benzogaga33@mamot.fr at 2026-08-21T09:40:03.000Z ##

Elementor Pro : une faille critique permet de prendre le contrôle d’un site WordPress it-connect.fr/elementor-pro-cv #ActuCybersécurité #Cybersécurité #Vulnérabilité #Wordpress

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T07:56:13.000Z ##

CVE-2026-32475 (CVSS 9.8) is an unauthenticated file upload flaw in Elementor Pro. It threatens complete site compromise across 6 million sites.

#ElementorPro #CVE202632475 #WordPress #RCE #FileUpload #WebSecurity

securityonline.info/cve-2026-3

##

ottoto2017@prattohome.com at 2026-08-21T07:39:49.000Z ##

「Elementor Proの重大なバグにより、WordPressサイトがリモートコード実行攻撃に晒される 」: #BLEEPINGCOMPUTER

「WordPressプラグイン「Elementor Pro」に存在する重大な脆弱性により、攻撃者が実行可能ファイルをアップロードして、サーバー上でリモートコードを実行できる可能性がある。

CVE-2026-32475として識別されたこの脆弱性は、Elementor Proのバージョン4.2.2より前のバージョンに影響し、ファイル検証と処理に別々のループを使用するファイルアップロードモジュールに起因しており、ファイル名が空のアップロードの処理方法が異なっています。」

bleepingcomputer.com/news/secu

#prattohome

##

CVE-2026-19598
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-08-20T12:48:10.287000

2 posts

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON met

3 repos

https://github.com/DeadExpl0it/CVE-2026-19598-PoC

https://github.com/ksotaria1337/CVE-2026-19598

https://github.com/sag-asab/CVE-2026-19598

DailyCyberSecurity at 2026-08-21T16:17:01.243Z ##

CVE-2026-19598, a CVSS 9.8 flaw in the Pods WordPress plugin, enables complete site takeover. Wordfence is already blocking attacks in the wild.

securityonline.info/cve-2026-1

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T16:17:01.000Z ##

CVE-2026-19598, a CVSS 9.8 flaw in the Pods WordPress plugin, enables complete site takeover. Wordfence is already blocking attacks in the wild.

#Pods #CVE202619598 #WordPress #PrivilegeEscalation #SiteTakeover #WebSecurity

securityonline.info/cve-2026-1

##

CVE-2026-20231
(9.9 CRITICAL)

EPSS: 0.41%

updated 2026-08-19T21:31:33

3 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CVE-2026-20231 are related to improper neutralization of special e

nyanbinary at 2026-08-22T20:23:15.512Z ##

Fuck it, CVE dumpster diving.

CVE-2026-20231 - this is one of a batch of Cisco CVEs that stood out to me because they have multiple descriptions: One by the CNA, one by an ADP, "CVE" itself. The ADP one is just "please please please dont do this (bundling multiple vulns into a single cve) :neobot_angel_pleading: ". Cisco dont care, they put out 9 of those over the last 7 days.

##

nyanbinary@infosec.exchange at 2026-08-22T20:23:15.000Z ##

Fuck it, CVE dumpster diving.

CVE-2026-20231 - this is one of a batch of Cisco CVEs that stood out to me because they have multiple descriptions: One by the CNA, one by an ADP, "CVE" itself. The ADP one is just "please please please dont do this (bundling multiple vulns into a single cve) :neobot_angel_pleading: ". Cisco dont care, they put out 9 of those over the last 7 days.

##

AAKL@infosec.exchange at 2026-08-20T20:15:43.000Z ##

CISA has added two known vulnerabilities to the KEV catalogue.

- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Yesterday:

Cisco:

CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-20315
(10.0 CRITICAL)

EPSS: 0.32%

updated 2026-08-19T21:30:29

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20315 are related to improper access control issues that are gr

ottoto2017@prattohome.com at 2026-08-21T07:22:35.000Z ##

「Ciscoのバグの深刻度警告は、オリンピック体操競技の得点のように、10、10、9.9、9.6、7.5と表示されます。
/Secure Workload Softwareには5つの重大な欠陥があり、SaaSユーザーでさえアップデートをインストールする必要がある。 」: #TheRegister

「シスコは、ネットワーク内での攻撃者の横方向への移動を阻止することを目的としたマイクロセグメンテーションツールであるセキュアワークロードソフトウェア(旧称Tetration)に、4つの重大な欠陥と、さらに1つの深刻なバグが存在することを明らかにした。

CVE-2026-20315とCVE-2026-20317は、最高評価の10点満点バグです。どちらも不適切なアクセス制御に関連しています。 」

theregister.com/security/2026/

#prattohome

##

AAKL@infosec.exchange at 2026-08-20T20:15:43.000Z ##

CISA has added two known vulnerabilities to the KEV catalogue.

- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Yesterday:

Cisco:

CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-20317
(10.0 CRITICAL)

EPSS: 0.34%

updated 2026-08-19T21:30:29

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20317 are related to improper authentication issues that are gr

AAKL@infosec.exchange at 2026-08-20T20:15:43.000Z ##

CISA has added two known vulnerabilities to the KEV catalogue.

- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Yesterday:

Cisco:

CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-65400
(9.8 CRITICAL)

EPSS: 0.75%

updated 2026-08-19T04:17:34.547000

1 posts

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

3 repos

https://github.com/HORKimhab/CVE-2026-65400

https://github.com/acheong08/CVE-2026-65400

https://github.com/panchocosil/CVE-2026-65400-poc

cktodon@mas.to at 2026-08-21T16:00:12.000Z ##

El fallo de #macOS que permite entrar sin #contraseña por compartir pantalla ya está siendo explotado: actualiza ahora

wwwhatsnew.com/2026/08/20/cve-

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 2.40%

updated 2026-08-19T04:17:24.940000

1 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

2 repos

https://github.com/HORKimhab/CVE-2026-59310

https://github.com/BiuTrap/CVE-2026-59310

sekurakbot@mastodon.com.pl at 2026-08-23T15:32:00.000Z ##

Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter

Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...

#WBiegu #Apt #Chiny #Cve #DirectoryTraversal #Rce #Vmware

sekurak.pl/chinskie-grupy-apt-

##

CVE-2026-33824
(9.8 CRITICAL)

EPSS: 77.90%

updated 2026-08-19T04:16:58.560000

1 posts

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/EpSiLoNPoInTOrI/IKEV2-POC

https://github.com/kaleth4/CVE-2026-33824

DailyCyberSecurity@infosec.exchange at 2026-08-21T04:48:04.000Z ##

CISA confirmed active exploitation of CVE-2026-33824, an unauthenticated Windows IKE double-free flaw patched in April, ordering federal agencies to remediate within three days.

#CVE202633824 #Windows #CISA #IKE #Vulnerability

meterpreter.org/cve-2026-33824

##

CVE-2026-18963
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-08-19T03:31:21

4 posts

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user

1 repos

https://github.com/kyos-public/keycloak-cve-2026-18963-hunt

benzogaga33@mamot.fr at 2026-08-21T15:40:04.000Z ##

Keycloak : cette faille critique permet de pirater un compte via la fonction de mot de passe oublié it-connect.fr/keycloak-cve-202 #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

sayzard@mastodon.sayzard.org at 2026-08-21T11:40:29.000Z ##

Keycloak Unauthenticated Account Takeover

벨기에 사이버보안센터(CCB)는 Red Hat build of Keycloak 26.4 및 26.6의 자격 증명 재설정 흐름에서 원격 비인증 계정 탈취가 가능한 CVE-2026-18963을 경고했다. CVSS 9.1의 CWE-640 취약점으로, 공격자는 비밀번호 재설정 이메일의 검증 링크를 클릭하지 않고도 임의 사용자의 재설정을 강제하고 새 자격 증명을 설정할 수 있다. Keycloak이 SSO·인증·권한 부여의 중심에 배치되는 경우 영향 범위가 해당 계정에 연결된 다수의 AI 서비스, 에이전트,...

ccb.belgium.be/advisories/warn

##

benzogaga33@mamot.fr at 2026-08-21T15:40:04.000Z ##

Keycloak : cette faille critique permet de pirater un compte via la fonction de mot de passe oublié it-connect.fr/keycloak-cve-202 #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T09:17:33.000Z ##

A Keycloak account takeover flaw, CVE-2026-18963, lets attackers reset any user's password with no email verification. Update to 26.7.2 now.

#Keycloak #AccountTakeover #CVE #IAM #InfoSec #RedHat

securityonline.info/keycloak-a

##

CVE-2026-64849
(9.3 CRITICAL)

EPSS: 8.15%

updated 2026-08-17T21:58:52

2 posts

### Summary The default MLflow Tracking Server (`mlflow server`, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous `POST /api/2.0/mlflow/webhooks/{id}/test` endpoint that returns the upstream response status and body to the caller. The SSRF guard added in PR #20747 (`_validate_webhook_url`, shipped in 3.10.0) resolves the we

Nuclei template

3 repos

https://github.com/zavisco/CVE-2026-64849.yaml

https://github.com/BiuTrap/CVE-2026-64849

https://github.com/codeb0ssx/CVE-2026-64849-PoC

Hackread@mstdn.social at 2026-08-22T11:59:25.000Z ##

Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.

Listen/Read: hackread.com/attackers-exploit

#CyberSecurity #MLflow #AI #Vulnerability #CISA

##

Hackread@mstdn.social at 2026-08-22T11:59:25.000Z ##

Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.

Listen/Read: hackread.com/attackers-exploit

#CyberSecurity #MLflow #AI #Vulnerability #CISA

##

CVE-2026-19478
(9.4 CRITICAL)

EPSS: 1.94%

updated 2026-08-17T21:31:30

7 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Nuclei template

6 repos

https://github.com/HORKimhab/CVE-2026-19650-CVE-2026-19478

https://github.com/dinosn/gitlab-cve-2026-19478-lab

https://github.com/n0xdaemon/cve-2026-19478

https://github.com/punitdarji/Gitlab-CVE-2026-19478

https://github.com/davkharrr/CVE-2026-19478-PoC

https://github.com/renzi25031469/CVE-2026-19478

DailyCyberSecurity at 2026-08-23T14:00:39.135Z ##

Critical GitLab vulnerability CVE-2026-19478 lets unauthenticated attackers delete public projects. It is exploited in the wild with public PoC.

securityonline.info/gitlab-cve

##

undercodenews@mastodon.social at 2026-08-23T00:14:25.000Z ##

GitLab CVE-2026-19478: A Critical Zero-Click Risk Puts Public Projects and User Data in the Crosshairs + Video

A Dangerous GitLab Flaw Is Already Being Exploited A critical vulnerability in GitLab has moved from a security advisory to an active exploitation problem, raising the pressure on organizations that operate self-managed GitLab servers. Tracked as CVE-2026-19478 and rated CVSS 9.4, the flaw can allow an attacker with no credentials to remotely modify or delete…

undercodenews.com/gitlab-cve-2

##

undercodenews@mastodon.social at 2026-08-21T10:44:40.000Z ##

Critical GitLab Flaw CVE-2026-19478 Is Under Active Attack: Why Organizations Need to Patch Now + Video

A Dangerous Warning for GitLab Administrators A critical vulnerability in self-managed GitLab installations has moved from a serious security concern to an immediate incident-response priority. Security researchers are warning that attackers are actively exploiting CVE-2026-19478, a flaw rated CVSS 9.4, that can allow completely unauthenticated attackers to remotely…

undercodenews.com/critical-git

##

DailyCyberSecurity@infosec.exchange at 2026-08-23T14:00:39.000Z ##

Critical GitLab vulnerability CVE-2026-19478 lets unauthenticated attackers delete public projects. It is exploited in the wild with public PoC.

#GitLab #CVE202619478 #Vulnerability #InfoSec #CyberSecurity #PatchNow

securityonline.info/gitlab-cve

##

cyberworldops@infosec.exchange at 2026-08-21T10:20:01.000Z ##

watchTowr reports active exploitation of CVE-2026-19478 in GitLab within days of public disclosure. The flaw is a code injection via GraphQL directives, exploitable by unauthenticated remote attackers. Reproduction was possible within minutes of the advisory going live. Patch immediately.

#GitLab #CVE202619478 #CodeInjection #PatchNow

cyberworldops.eu/en/gitlab-cve

##

benzogaga33@mamot.fr at 2026-08-21T09:40:04.000Z ##

GitLab : la faille critique CVE-2026-19478 est déjà exploitée, deux jours après le correctif it-connect.fr/gitlab-cve-2026- #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

linuxmint_hun@mastodon.social at 2026-08-21T08:38:00.000Z ##

A GitLab CVE-2026-19478 sebezhetőséget napokkal a nyilvánosságra hozatal után már aktívan kihasználják

linuxmint.hu/hir/2026/08/a-git

##

CVE-2026-42945
(8.1 HIGH)

EPSS: 66.04%

updated 2026-08-17T12:18:36.420000

2 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond it

44 repos

https://github.com/edgecases-PurpleHax/cve-images

https://github.com/simota/nginx-rift-scanner

https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC

https://github.com/sibersan/web-server-audit_CVE-2026-42945

https://github.com/realityone/cve-2026-42945-scan

https://github.com/Kentox493/CVE-2026-42945_NginxRift

https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab

https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit

https://github.com/nanwinata/nginxrift-CVE-2026-42945

https://github.com/oseasfr/Scanner_CVE_2026-42945

https://github.com/ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945

https://github.com/azilRababe/CVE-2026-42945

https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945

https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift

https://github.com/BarAppTeam/nginx-cve-fix

https://github.com/strivepan/Nginx_cve-2026-42945-scanner-gui

https://github.com/tal7aouy/nginx-cve-2026-42945

https://github.com/0xBlackash/CVE-2026-42945

https://github.com/iammerrida-source/nginx-rift-detect

https://github.com/yusufdalbudak/CVE-2026-42945

https://github.com/rheodev/CVE-2026-42945

https://github.com/josephfelix/CVE-2026-42945-nginx-rift

https://github.com/aratane/CVE-2026-42945

https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945

https://github.com/MateusVerass/nGixshell

https://github.com/nu0l/NGINX-Rift

https://github.com/dinosn/cve-2026-42945-nginx32-lab

https://github.com/jelasin/CVE-2026-42945

https://github.com/hulina9900-boop/DIY-CVE-2026-42945-POC

https://github.com/hnytgl/CVE-2026-42945

https://github.com/limo57640-crypto/nginx-rift-detector

https://github.com/RedCrazyGhost/CVE-2026-42945

https://github.com/forxiucn/nginx-cve-2026-42945-poc

https://github.com/quantumworld-dpdns-io/CVE-2026-42945

https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945

https://github.com/imSre9/CVE-2026-42945

https://github.com/sec-sys/CVE-2026-42945-Reverse-Shell-POC

https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script

https://github.com/CynepMyx/nginx-rift-check

https://github.com/byezero/nginx-cve-2026-42945-check

https://github.com/cipherspy/CVE-2026-42945-POC

https://github.com/fkj-src/fix_nginx_cve_2026_42945

https://github.com/chenqin231/CVE-2026-42945

https://github.com/F2u0a0d3/CVE-2026-42945-nginx-rift-poc

kubesploit@learnk8s.news at 2026-08-21T19:06:03.000Z ##

Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives
The README lists affected and fixed versions

ku.bz/PQSlZ7Khl

##

kubesploit@learnk8s.news at 2026-08-21T19:06:03.000Z ##

Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives
The README lists affected and fixed versions

ku.bz/PQSlZ7Khl

##

CVE-2026-33818
(7.5 HIGH)

EPSS: 0.46%

updated 2026-08-14T18:31:34

1 posts

Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.

lambdawatchdog@mastodon.social at 2026-08-22T12:01:10.000Z ##

🔍 Lambda Watchdog detected that CVE-2026-33818 is no longer present in latest AWS Lambda base image scans. github.com/aws/aws-lambda-base #AWS #Lambda #Security #CVE #DevOps #SecOps

##

CVE-2026-68820
(7.0 None)

EPSS: 0.33%

updated 2026-08-11T21:33:01

1 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/HORKimhab/CVE-2026-68820

https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation

CapTechGroup@mastodon.social at 2026-08-21T12:52:36.000Z ##

A maximum-severity CVSS 10.0 flaw in Microsoft Entra ID is under active exploitation, allowing remote code execution. Two CVEs are in play, CVE-2026-68820 and CVE-2026-69836, with activity attributed to the Lazarus Group.

captechgroup.com/threat-intell

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 30.20%

updated 2026-08-01T05:16:55.023000

1 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

CVE-2026-66066(CVSS UNKNOWN)

EPSS: 1.77%

updated 2026-07-30T18:23:34

1 posts

### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment. That environment typically holds `secret_key_base` and often credentials for external systems, which may in turn allow escalation to remote code execution or lateral movement to those systems. ##

7 repos

https://github.com/shinthink/CVE-2026-66066

https://github.com/0xBlackash/CVE-2026-66066

https://github.com/rails/rails-forensics-CVE-2026-66066

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

https://github.com/paveg/rails-activestorage-vips-audit

https://github.com/0xsha/KindaRails2Shell

https://github.com/HackSpeak/CVE-2026-66066

ottoto2017@prattohome.com at 2026-08-21T08:16:05.000Z ##

Mastodon v4.7 へのupgrade をRails v8.1.3 の脆弱性解消とは、関係ないことを学習。

Google AI:
「今回の「KindaRails2Shell (CVE-2026-66066)」という脆弱性の攻撃ルートを、Mastodon自体が完全に通らない構造になっているためです。

Active Storage(問題の部品)を完全排除している

ダイレクトアップロード機能も使っていない」

以上の回答を得ました。

Mastodon v4.7 が Rails v8.1.3 の対策で出されたと言う以前の私の投稿を訂正いたします。

#prattohome

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-07-30T16:17:15.073000

1 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

sekurakbot@mastodon.com.pl at 2026-08-23T15:32:00.000Z ##

Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter

Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...

#WBiegu #Apt #Chiny #Cve #DirectoryTraversal #Rce #Vmware

sekurak.pl/chinskie-grupy-apt-

##

CVE-2026-54457
(7.7 HIGH)

EPSS: 0.29%

updated 2026-07-15T21:59:41

2 posts

### Impact The `/internal/object_storage` endpoint accepts a caller-supplied JSON `storage_path` parameter that dynamically overrides the TensorZero `[object_storage]` configuration. By abusing the `filesystem` storage type, a caller can read arbitrary files from the gateway filesystem, including files that may contain sensitive credentials. Similarly, by abusing the `s3_compatible` storage type

thehackerwire@mastodon.social at 2026-08-22T02:01:18.000Z ##

🟠 CVE-2026-54457 - High (7.7)

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON stor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T02:01:18.000Z ##

🟠 CVE-2026-54457 - High (7.7)

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON stor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52929
(7.5 HIGH)

EPSS: 0.39%

updated 2026-07-08T15:31:44

1 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: stream: fully roll back denied add-stream state When ADD_OUT_STREAMS is denied, SCTP only shrinks the queued chunks and then lowers outcnt. That leaves removed stream metadata behind, so a later re-add can reuse a stale ext and hit a null-pointer dereference in the scheduler get path. Fix the rollback by tearing down the

CVE-2026-58472
(5.9 MEDIUM)

EPSS: 0.22%

updated 2026-07-07T21:31:43

1 posts

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output si

ottoto2017@prattohome.com at 2026-08-21T00:27:09.000Z ##

#Ubuntu 24.04.4 で #update

console-setup (1.226ubuntu1.1)
セキュリティ対応ではない。
console-setup-linux
keyboard-configuration

open-vm-tools (2:13.0.10-0ubuntu0.24.04.1)
セキュリティ対応ではない。

snapd (2.76.3+ubuntu24.04)
セキュリティ対応ではない。

wget (1.21.4-1ubuntu4.5)
CVE-2026-58472へのセキュリティ対応。

#prattohome #更新

##

CVE-2026-49360(CVSS UNKNOWN)

EPSS: 0.45%

updated 2026-07-02T21:14:38

1 posts

### Impact Recce OSS server deployments that expose the server to an untrusted network without authentication are vulnerable to unauthenticated SQL execution through the query run API. When Recce is configured with a DuckDB-backed project, an attacker can use DuckDB filesystem primitives to read and write files accessible to the Recce server process. The impact depends on how Recce is deployed, b

killbait@mastodon.social at 2026-08-22T01:12:19.000Z ##

Critical Vulnerability Discovered in Widely Used Software Framework

📰 Original title: CVE-2026-49360 Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB

🤖 IA: It's not clickbait ✅
👥 Users: It's not clickbait ✅

View full AI summary en.killbait.com/critical-vulne

#technology #cve #vulnerability #se...

##

CVE-2026-8452
(9.8 CRITICAL)

EPSS: 1.04%

updated 2026-07-01T18:32:28

2 posts

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

3 repos

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

https://github.com/BishopFox/CVE-2026-8452-check

https://github.com/derekpreston81/CVE_ADC_IOC_2026

beyondmachines1 at 2026-08-21T13:01:26.798Z ##

Citrix NetScaler Flaws Under Active Attack Following Exploit Release

Citrix NetScaler ADC and Gateway appliances are being exploited via a critical SAML memory overflow vulnerability (CVE-2026-8452) that allows pre-authentication remote code execution. Attackers are targeting perimeter devices to gain unauthorized access to internal corporate networks following the release of public proof-of-concept code.

**If you run Citrix NetScaler ADC or Gateway, patch immediately to version 14.1-72.61 or 13.1-63.18 (or the matching FIPS builds). Attackers are already exploiting these appliances and a public exploit PoC is available. If you can't patch right away, restrict the management interface to trusted internal networks only, review your SAML configuration, and check logs for unexpected admin logins or config changes.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-21T13:01:26.000Z ##

Citrix NetScaler Flaws Under Active Attack Following Exploit Release

Citrix NetScaler ADC and Gateway appliances are being exploited via a critical SAML memory overflow vulnerability (CVE-2026-8452) that allows pre-authentication remote code execution. Attackers are targeting perimeter devices to gain unauthorized access to internal corporate networks following the release of public proof-of-concept code.

**If you run Citrix NetScaler ADC or Gateway, patch immediately to version 14.1-72.61 or 13.1-63.18 (or the matching FIPS builds). Attackers are already exploiting these appliances and a public exploit PoC is available. If you can't patch right away, restrict the management interface to trusted internal networks only, review your SAML configuration, and check logs for unexpected admin logins or config changes.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-48769
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-06-26T19:13:19

2 posts

### Summary An arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. ### Details - `cmd/incusd/images.go:611-684` handles `source.type=url` by HEADing the user-supplied URL, reading `Incus-Image-Hash` and `Incus-Image-URL`, and passing them to `imageDownload(

thehackerwire@mastodon.social at 2026-08-23T01:01:34.000Z ##

🔴 CVE-2026-48769 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T01:01:34.000Z ##

🔴 CVE-2026-48769 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48753
(9.9 CRITICAL)

EPSS: 0.71%

updated 2026-06-26T18:47:27

2 posts

## Summary The S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. In `internal/server/storage/s3/local/multipart.go`, user-controlled upload ID is appended to the uploads directory unsanitized; https://github.com/lxc/incus/blob/40dd4f151d52c06b178482aa2518abfb9df3e6fb/internal/se

thehackerwire@mastodon.social at 2026-08-23T06:00:21.000Z ##

🔴 CVE-2026-48753 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T06:00:21.000Z ##

🔴 CVE-2026-48753 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48752
(9.9 CRITICAL)

EPSS: 0.81%

updated 2026-06-26T18:46:32

2 posts

### Summary A specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. ### Details For container images, `internal/server/storage/utils.go` calls `archive.Unpack(imageFile, destPath, ...)`. The tar extraction path in `shared/archive/archive.go` excludes device nodes, but it does not reject a top

thehackerwire@mastodon.social at 2026-08-23T06:00:06.000Z ##

🔴 CVE-2026-48752 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T06:00:06.000Z ##

🔴 CVE-2026-48752 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48750
(9.9 CRITICAL)

EPSS: 0.78%

updated 2026-06-26T18:32:53

2 posts

### Summary The `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named `exec_UUID.stdout` and `exec_UUID.stderr` can be written to an arbitrary location where the `.stdout` file will contain arbitrary content. This behavior can be abused for arbitrary command execu

thehackerwire@mastodon.social at 2026-08-23T02:00:42.000Z ##

🔴 CVE-2026-48750 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T02:00:42.000Z ##

🔴 CVE-2026-48750 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-62593(CVSS UNKNOWN)

EPSS: 1.00%

updated 2025-12-01T16:02:43

2 posts

# Summary Developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. Due to the longstanding [decision](https://docs.ray.io/en/releases-2.51.1/ray-security/index.html) by the Ray Development team to not implement any sort of authentication on critical endpoints, like the `/api/jobs` & `/api/job_agent/jobs/` has once ag

1 repos

https://github.com/Boreas37/CVE-2025-62593-PoC

cyberworldops at 2026-08-21T16:20:01.034Z ##

CISA has added CVE-2025-62593 to the KEV catalog: a CVSS 8.8 flaw in Anyscale Ray enabling remote code execution against AI development environments. Active exploitation confirmed. Versions below 2.52.0 are affected. Patch immediately and audit for compromise — attackers are targeting the ML build layer as an initial access vector.

cyberworldops.eu/en/ray-added-

##

cyberworldops@infosec.exchange at 2026-08-21T16:20:01.000Z ##

CISA has added CVE-2025-62593 to the KEV catalog: a CVSS 8.8 flaw in Anyscale Ray enabling remote code execution against AI development environments. Active exploitation confirmed. Versions below 2.52.0 are affected. Patch immediately and audit for compromise — attackers are targeting the ML build layer as an initial access vector.

#RayFramework #CVE202562593 #ActiveExploitation #CISA

cyberworldops.eu/en/ray-added-

##

CVE-2012-0158
(8.8 HIGH)

EPSS: 99.97%

updated 2025-10-22T03:31:35

2 posts

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2;

2 repos

https://github.com/RobertoLeonFR-ES/Exploit-Win32.CVE-2012-0158.F.doc

https://github.com/Sunqiz/CVE-2012-0158-reproduction

kev_Stalker at 2026-08-21T17:45:41.941Z ##

CVE-2012-0158 - Changed to Known Ransomware Status

Microsoft MSCOMCTL.OCX Remote Code Execution VulnerabilityVendor: MicrosoftProduct: MSCOMCTL.OCXMicrosoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August nvd.nist.gov/vuln/detail/CVE-2

##

kev_Stalker@infosec.exchange at 2026-08-21T17:45:41.000Z ##

CVE-2012-0158 - Changed to Known Ransomware Status

Microsoft MSCOMCTL.OCX Remote Code Execution VulnerabilityVendor: MicrosoftProduct: MSCOMCTL.OCXMicrosoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2021-43226
(7.8 HIGH)

EPSS: 3.07%

updated 2025-10-22T00:33:30

2 posts

Windows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43207.

1 repos

https://github.com/Rosayxy/cve-2021-43226PoC

kev_Stalker at 2026-08-21T17:40:57.164Z ##

CVE-2021-43226 - Changed to Known Ransomware Status

Microsoft Windows Privilege Escalation VulnerabilityVendor: MicrosoftProduct: WindowsMicrosoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 21, 2026 at 13:08:17 UTCDate Added to nvd.nist.gov/vuln/detail/CVE-2

##

kev_Stalker@infosec.exchange at 2026-08-21T17:40:57.000Z ##

CVE-2021-43226 - Changed to Known Ransomware Status

Microsoft Windows Privilege Escalation VulnerabilityVendor: MicrosoftProduct: WindowsMicrosoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 21, 2026 at 13:08:17 UTCDate Added to nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2020-5135
(9.8 CRITICAL)

EPSS: 24.56%

updated 2025-10-22T00:31:59

2 posts

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected SonicOS Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.

kev_Stalker at 2026-08-21T17:50:34.176Z ##

CVE-2020-5135 - Changed to Known Ransomware Status

SonicWall SonicOS Buffer Overflow VulnerabilityVendor: SonicWallProduct: SonicOSA buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 21, 2026 at 13:08:17 UTCDate Added tohttps://nvd.nist.gov/vuln/detail/CVE-2020-5135

##

kev_Stalker@infosec.exchange at 2026-08-21T17:50:34.000Z ##

CVE-2020-5135 - Changed to Known Ransomware Status

SonicWall SonicOS Buffer Overflow VulnerabilityVendor: SonicWallProduct: SonicOSA buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 21, 2026 at 13:08:17 UTCDate Added tohttps://nvd.nist.gov/vuln/detail/CVE-2020-5135

##

CVE-2026-55621
(0 None)

EPSS: 0.20%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-23T02:00:12.000Z ##

🟠 CVE-2026-55621 - High (7.7)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom v...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T02:00:12.000Z ##

🟠 CVE-2026-55621 - High (7.7)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom v...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39113
(0 None)

EPSS: 0.00%

2 posts

N/A

1 repos

https://github.com/20000419/CVE-2026-39113

DarkWebInformer at 2026-08-22T18:43:39.775Z ##

‼️ CVE-2026-39113: Heap Buffer Overflow in SQLite's Optional SQLAR Extension

GitHub: github.com/20000419/CVE-2026-3

##

DarkWebInformer@infosec.exchange at 2026-08-22T18:43:39.000Z ##

‼️ CVE-2026-39113: Heap Buffer Overflow in SQLite's Optional SQLAR Extension

GitHub: github.com/20000419/CVE-2026-3

##

CVE-2026-50538
(0 None)

EPSS: 0.32%

3 posts

N/A

hugovalters@mastodon.social at 2026-08-22T18:11:28.000Z ##

CVE-2026-50538 - Critical OOB heap write in LibVNCServer's libvncclient. Malicious VNC server can overwrite memory pre-auth. CVSS 8.8. Update to fixed version now. #CVE #infosec #LibVNCServer

valtersit.com/cve/CVE-2026-505

##

thehackerwire@mastodon.social at 2026-08-22T03:02:10.000Z ##

🟠 CVE-2026-50538 - High (8.8)

LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-the-middle) VNC server can force a connecting `libvncclient` to write attacker-controlled data past the end of its framebu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T03:02:10.000Z ##

🟠 CVE-2026-50538 - High (8.8)

LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-the-middle) VNC server can force a connecting `libvncclient` to write attacker-controlled data past the end of its framebu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DarkWebInformer at 2026-08-22T17:52:48.169Z ##

🚨🇫🇷 iMapper allegedly breached through critical Metabase vulnerability, account data and database access leaked on a cybercrime forum

A forum actor claims to have compromised iMapper, a French web-connected 2D laser measurement platform for building professionals, using a vulnerability identified in the listing as CVE-2026-72898 with a claimed CVSS score of 10.0.

The exposed account dataset reportedly contains 2,463 records and includes:

• User IDs and usernames
• Password hashes
• Account roles
• Email addresses
• Phone numbers
• Professions
• MFA status and related metadata
• Language preferences
• Stripe customer IDs
• Stripe tax-related identifiers
• Measurement and display configuration fields

The data is being distributed in XLSX format. The listing also claims the compromised environment contains additional database tables and offers credentials that could provide access to those systems.

The claims, exploitation method and authenticity, availability and scope of the allegedly exposed data and database access have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

##

DarkWebInformer@infosec.exchange at 2026-08-22T17:52:48.000Z ##

🚨🇫🇷 iMapper allegedly breached through critical Metabase vulnerability, account data and database access leaked on a cybercrime forum

A forum actor claims to have compromised iMapper, a French web-connected 2D laser measurement platform for building professionals, using a vulnerability identified in the listing as CVE-2026-72898 with a claimed CVSS score of 10.0.

The exposed account dataset reportedly contains 2,463 records and includes:

• User IDs and usernames
• Password hashes
• Account roles
• Email addresses
• Phone numbers
• Professions
• MFA status and related metadata
• Language preferences
• Stripe customer IDs
• Stripe tax-related identifiers
• Measurement and display configuration fields

The data is being distributed in XLSX format. The listing also claims the compromised environment contains additional database tables and offers credentials that could provide access to those systems.

The claims, exploitation method and authenticity, availability and scope of the allegedly exposed data and database access have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

##

CVE-2026-63343
(0 None)

EPSS: 0.48%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T12:00:47.000Z ##

🔴 CVE-2026-63343 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T12:00:47.000Z ##

🔴 CVE-2026-63343 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62941
(0 None)

EPSS: 0.44%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T12:00:26.000Z ##

🔴 CVE-2026-62941 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T12:00:26.000Z ##

🔴 CVE-2026-62941 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62940
(0 None)

EPSS: 0.42%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T10:00:44.000Z ##

🔴 CVE-2026-62940 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T10:00:44.000Z ##

🔴 CVE-2026-62940 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-30826
(0 None)

EPSS: 0.23%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T07:03:07.000Z ##

🟠 CVE-2026-30826 - High (8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T07:03:07.000Z ##

🟠 CVE-2026-30826 - High (8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-31880
(0 None)

EPSS: 0.23%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T07:02:57.000Z ##

🟠 CVE-2026-31880 - High (8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T07:02:57.000Z ##

🟠 CVE-2026-31880 - High (8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-31803
(0 None)

EPSS: 0.23%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T03:02:29.000Z ##

🟠 CVE-2026-31803 - High (8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T03:02:29.000Z ##

🟠 CVE-2026-31803 - High (8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53525
(0 None)

EPSS: 0.43%

1 posts

N/A

hugovalters@mastodon.social at 2026-08-22T01:13:22.000Z ##

CVE-2026-53525 - Timing attack in WeeChat relay auth leaks hash, enabling auth bypass. CVSS 7.4. Update to 4.9.1 now. #CVE #WeeChat #infosec

valtersit.com/cve/CVE-2026-535

##

CVE-2026-62316
(0 None)

EPSS: 0.32%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T01:00:05.000Z ##

🟠 CVE-2026-62316 - High (8.8)

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, O...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T01:00:05.000Z ##

🟠 CVE-2026-62316 - High (8.8)

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, O...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62283
(0 None)

EPSS: 0.37%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T00:01:16.000Z ##

🔴 CVE-2026-62283 - Critical (9.9)

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_stream.go to th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-22T00:01:16.000Z ##

🔴 CVE-2026-62283 - Critical (9.9)

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_stream.go to th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49849
(0 None)

EPSS: 0.70%

4 posts

N/A

offseq at 2026-08-22T00:00:37.421Z ##

CVE-2026-49849 (CRITICAL): 4xmen xShop <3.0.4 lets authenticated admins upload dangerous files, leading to remote code execution 🛡️. Patch to 3.0.4 now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-21T23:00:36.000Z ##

🔴 CVE-2026-49849 - Critical (9.1)

xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially crafted php file, an attack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-22T00:00:37.000Z ##

CVE-2026-49849 (CRITICAL): 4xmen xShop <3.0.4 lets authenticated admins upload dangerous files, leading to remote code execution 🛡️. Patch to 3.0.4 now. radar.offseq.com/threat/cve-20 #OffSeq #CVE202649849 #remotecodeexecution #infosec

##

thehackerwire@mastodon.social at 2026-08-21T23:00:36.000Z ##

🔴 CVE-2026-49849 - Critical (9.1)

xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially crafted php file, an attack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-33240
(0 None)

EPSS: 0.27%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T23:01:34.000Z ##

🟠 CVE-2026-33240 - High (8.8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T23:01:34.000Z ##

🟠 CVE-2026-33240 - High (8.8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-31936
(0 None)

EPSS: 0.27%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T23:01:23.000Z ##

🟠 CVE-2026-31936 - High (8.8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T23:01:23.000Z ##

🟠 CVE-2026-31936 - High (8.8)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53528
(0 None)

EPSS: 0.35%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T23:00:24.000Z ##

🟠 CVE-2026-53528 - High (8.8)

LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are accessible to the LeafWiki server...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T23:00:24.000Z ##

🟠 CVE-2026-53528 - High (8.8)

LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are accessible to the LeafWiki server...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53527
(0 None)

EPSS: 0.24%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T23:00:10.000Z ##

🟠 CVE-2026-53527 - High (8.8)

LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their own account role and escalate privileges from a regular user, such as `viewer`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T23:00:10.000Z ##

🟠 CVE-2026-53527 - High (8.8)

LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their own account role and escalate privileges from a regular user, such as `viewer`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62677
(0 None)

EPSS: 0.45%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T21:01:29.000Z ##

🟠 CVE-2026-62677 - High (8.8)

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value because omnige...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T21:01:29.000Z ##

🟠 CVE-2026-62677 - High (8.8)

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value because omnige...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62675
(0 None)

EPSS: 0.45%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T21:01:19.000Z ##

🟠 CVE-2026-62675 - High (8.8)

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle does not ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T21:01:19.000Z ##

🟠 CVE-2026-62675 - High (8.8)

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle does not ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-30866
(0 None)

EPSS: 0.27%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T21:00:31.000Z ##

🟠 CVE-2026-30866 - High (7.5)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T21:00:31.000Z ##

🟠 CVE-2026-30866 - High (7.5)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-27490
(0 None)

EPSS: 0.31%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T21:00:19.000Z ##

🟠 CVE-2026-27490 - High (7.5)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T21:00:19.000Z ##

🟠 CVE-2026-27490 - High (7.5)

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77810
(0 None)

EPSS: 0.35%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T21:00:09.000Z ##

🔴 CVE-2026-77810 - Critical (9.9)

In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T21:00:09.000Z ##

🔴 CVE-2026-77810 - Critical (9.9)

In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54682
(0 None)

EPSS: 0.14%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T20:00:29.000Z ##

🟠 CVE-2026-54682 - High (8.2)

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T20:00:29.000Z ##

🟠 CVE-2026-54682 - High (8.2)

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62674
(0 None)

EPSS: 0.34%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T19:01:04.000Z ##

🔴 CVE-2026-62674 - Critical (9)

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T19:01:04.000Z ##

🔴 CVE-2026-62674 - Critical (9)

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71862
(0 None)

EPSS: 0.35%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T19:00:55.000Z ##

🟠 CVE-2026-71862 - High (7.5)

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T19:00:55.000Z ##

🟠 CVE-2026-71862 - High (7.5)

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77234
(0 None)

EPSS: 0.11%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T19:00:45.000Z ##

🟠 CVE-2026-77234 - High (8.8)

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T19:00:45.000Z ##

🟠 CVE-2026-77234 - High (8.8)

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59270
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-08-21T02:11:36.000Z ##

Four Spring Security vulnerabilities were disclosed, led by CVE-2026-59270 (CVSS 9.4). Attackers can read or modify entries in the in-memory directory.

#SpringSecurity #CVE202659270 #LDAP #WebAuthn #DPoP #AppSec

securityonline.info/spring-sec

##

CVE-2026-77176
(0 None)

EPSS: 0.41%

2 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-08-21T02:02:38.000Z ##

CVE-2026-77176 lets a malicious operator mount arbitrary guest rootfs paths in Kata Containers Confidential Containers setups. Update to Kata 4.1.0.

#CVE202677176 #KataContainers #ConfidentialContainers #CloudSecurity #genpolicy #infosec

securityonline.info/cve-2026-7

##

thehackerwire@mastodon.social at 2026-08-20T18:00:32.000Z ##

🟠 CVE-2026-77176 - High (8.1)

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71485
(0 None)

EPSS: 0.42%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-20T22:01:14.000Z ##

🔴 CVE-2026-71485 - Critical (9.1)

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEm...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73256
(0 None)

EPSS: 0.40%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-20T19:00:14.000Z ##

🔴 CVE-2026-73256 - Critical (9.1)

Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites