## Updated at UTC 2026-09-10T05:07:49.342144

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-85103 9.8 0.00% 4 0 2026-09-10T04:18:18.390000 A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unau
CVE-2026-85102 9.8 0.00% 2 0 2026-09-10T04:18:18.243000 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-69730 9.8 1.05% 4 0 2026-09-10T04:18:14.773000 Use after free in Windows DNS allows an unauthorized attacker to execute code ov
CVE-2026-19583 9.9 0.00% 2 0 2026-09-10T03:16:59.010000 Velociraptor allows some sensitive artifacts to be gated by additional permissio
CVE-2026-18351 9.8 0.00% 2 0 2026-09-10T02:16:34.180000 The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulner
CVE-2026-15913 7.7 0.00% 2 0 2026-09-10T00:30:34 In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteF
CVE-2026-87931 9.6 0.00% 2 0 2026-09-10T00:17:24.737000 A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral
CVE-2026-88069 0 0.00% 2 0 2026-09-09T22:18:49.240000 Pandora contains a path traversal vulnerability in its archive extraction worker
CVE-2026-73786 7.5 0.00% 1 0 2026-09-09T21:32:03 A vulnerability in the web-based management interface of CPPM could allow an una
CVE-2026-79324 7.5 0.00% 1 0 2026-09-09T21:32:03 Missing authorization in the Address Delete controller in Mageplaza GDPR for Mag
CVE-2026-79322 8.6 0.00% 1 0 2026-09-09T21:31:56 SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (magep
CVE-2026-87491 8.8 0.29% 8 0 2026-09-09T21:31:35 Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remo
CVE-2026-20079 10.0 35.95% 12 2 template 2026-09-09T21:31:33 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-19490 None 3.37% 2 1 2026-09-09T21:30:50 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f
CVE-2025-25249 8.1 0.76% 3 0 2026-09-09T21:30:27 A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6
CVE-2026-79696 0 0.44% 1 0 2026-09-09T21:17:04.820000 A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit
CVE-2026-12855 8.2 0.12% 1 0 2026-09-09T21:17:01.313000 Unvalidated memory boundary could result in arbitrary code execution. The vulner
CVE-2026-84372 9.8 0.41% 1 0 2026-09-09T21:09:13.080000 Predis is a flexible and feature-complete Redis and Valkey client for PHP. From
CVE-2026-85061 10.0 0.31% 1 0 2026-09-09T21:09:13.080000 MapLibre GL JS is an interactive vector tile map library for web browsers. Prior
CVE-2026-87911 9.6 0.00% 1 0 2026-09-09T20:21:02.017000 An OS command injection weakness in the read-only enforcement of the SQL validat
CVE-2026-79323 7.5 0.00% 1 0 2026-09-09T20:20:42.877000 Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL
CVE-2026-83991 5.5 0.35% 1 1 2026-09-09T20:14:54.747000 Missing authentication for critical function in Windows Cloud Files Mini Filter
CVE-2026-87874 8.1 0.00% 1 0 2026-09-09T20:13:26.720000 A flaw was found in the memcached cache plugin of the community.general Ansible
CVE-2026-80081 8.8 0.48% 1 0 2026-09-09T19:04:29.790000 Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to
CVE-2026-87929 9.8 0.00% 2 0 2026-09-09T18:32:12 MaxSite CMS through 109.6 ships with a hardcoded session encryption key in appli
CVE-2026-87927 8.2 0.00% 1 0 2026-09-09T18:32:12 MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the a
CVE-2026-67401 9.9 0.00% 3 3 2026-09-09T18:32:06 A vulnerability in cPanel allows a mail-enabled account to achieve remote code e
CVE-2026-53938 8.2 0.24% 1 0 2026-09-09T17:17:23.370000 OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encr
CVE-2026-15667 7.5 0.56% 1 0 2026-09-09T16:17:01.133000 The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)
CVE-2026-85983 7.8 0.14% 1 0 2026-09-09T16:03:22.897000 The Auth0 AD/LDAP Connector improperly processes a configuration value during se
CVE-2026-87628 8.3 0.17% 1 0 2026-09-09T15:35:03 Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjace
CVE-2026-76009 8.1 0.52% 2 0 2026-09-09T15:33:34.467000 The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable
CVE-2026-53581 9.0 0.33% 2 0 2026-09-09T14:17:12.343000 OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1
CVE-2026-86738 8.7 0.27% 1 0 2026-09-09T13:06:27.157000 Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Cust
CVE-2026-80172 9.8 0.00% 2 0 2026-09-09T12:32:22 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application
CVE-2026-79641 7.5 0.00% 1 0 2026-09-09T12:32:21 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application
CVE-2026-41870 None 0.00% 1 0 2026-09-09T12:32:13 Missing Authorization, Improper Control of Generation of Code ('Code Injection')
CVE-2026-87795 8.2 0.00% 1 0 2026-09-09T12:32:12 zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters
CVE-2026-87794 8.4 0.00% 1 0 2026-09-09T10:22:34.397000 bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in
CVE-2026-82007 7.8 0.23% 1 0 2026-09-09T10:22:32.157000 Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability
CVE-2026-16272 9.1 0.14% 1 0 2026-09-09T09:33:00 Use of less trusted source vulnerability in PayTR Payment and Electronic Money I
CVE-2026-6485 8.2 0.12% 1 0 2026-09-09T06:31:41 UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands
CVE-2026-87734 7.5 0.29% 1 0 2026-09-09T06:31:40 An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order
CVE-2026-21096 None 0.41% 1 0 2026-09-09T06:31:39 Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SM
CVE-2026-86502 8.4 0.14% 1 0 2026-09-09T05:18:20.043000 In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the
CVE-2026-86480 9.8 0.29% 2 0 2026-09-09T05:18:19.830000 In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register
CVE-2026-86479 8.1 0.20% 1 0 2026-09-09T05:18:19.723000 In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing
CVE-2026-86218 9.8 0.74% 10 1 2026-09-09T05:18:19.490000 N-central is vulnerable to a pre-auth remote code execution This issue affects N
CVE-2026-85880 7.8 0.57% 9 0 2026-09-09T05:18:19.193000 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev
CVE-2026-80166 7.8 0.10% 1 0 2026-09-09T05:18:14.767000 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application
CVE-2026-67276 0 0.24% 3 4 2026-09-09T05:17:28.130000 RouterOS does not compare the complete RSA public key when matching an SSH authe
CVE-2026-66768 9.0 0.32% 1 0 2026-09-09T05:17:27.537000 SAP GUI for Java does not correctly enforce the trust level policy for certain f
CVE-2026-73314 7.5 0.45% 1 1 2026-09-09T03:31:44 XenForo before 2.3.13 contains a signature verification logic error in the PayPa
CVE-2026-73316 7.5 0.20% 1 1 2026-09-09T03:30:36 XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST
CVE-2026-73315 8.6 0.27% 1 1 2026-09-09T01:16:58.050000 XenForo before 2.3.13 contains a server-side request forgery vulnerability in th
CVE-2026-18355 7.5 0.84% 2 0 2026-09-08T22:17:40.127000 A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Ser
CVE-2026-81994 8.2 0.30% 1 0 2026-09-08T21:34:41 Acrobat Reader is affected by an Improperly Controlled Modification of Object Pr
CVE-2026-84869 9.9 0.38% 2 0 2026-09-08T21:34:37 A condition in the ScreenConnect client may allow files to be transferred and ex
CVE-2026-84942 8.7 0.33% 1 0 2026-09-08T21:34:37 Improper input validation in the Vega expression function implementation in Open
CVE-2026-81963 7.8 0.63% 9 0 2026-09-08T21:34:09 Improper link resolution before file access ('link following') in Windows Update
CVE-2026-75650 10.0 2.15% 14 4 2026-09-08T21:33:09 Adobe Commerce is affected by an Improper Neutralization of Special Elements Use
CVE-2026-80119 7.8 0.12% 1 0 2026-09-08T20:10:30.270000 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10
CVE-2026-86540 7.8 0.14% 1 0 2026-09-08T19:56:50.950000 knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary
CVE-2026-86538 7.5 0.74% 1 0 2026-09-08T19:56:50.950000 knowns versions before 0.30.0 contain a path traversal vulnerability in the POST
CVE-2026-86543 9.8 0.44% 2 0 2026-09-08T19:56:50.950000 knowns versions before 0.30.0 serve the management API without authentication on
CVE-2026-86721 7.5 0.29% 1 0 2026-09-08T19:53:13.400000 AVideo through commit c3edcc274c contains an authorization bypass vulnerability
CVE-2026-86727 7.5 0.31% 1 0 2026-09-08T19:53:13.400000 AVideo through 29.0 contains an information disclosure vulnerability in plugin/L
CVE-2026-86732 8.8 0.51% 1 0 2026-09-08T19:53:13.400000 Craft CMS versions before 5.10.12 contain a remote code execution vulnerability
CVE-2026-84282 0 0.16% 1 0 2026-09-08T19:29:09.680000 A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownC
CVE-2026-86206 0 0.68% 1 0 template 2026-09-08T19:16:41.410000 A vulnerability in the N-central internal API access control filter allows unaut
CVE-2026-76969 9.4 0.29% 2 0 2026-09-08T19:12:59.557000 @sap/cds-mtxs NPM library does not perform sufficient checks on certain function
CVE-2026-75021 8.1 0.42% 1 0 2026-09-08T19:07:52.113000 fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignor
CVE-2026-82067 8.1 0.28% 2 0 2026-09-08T19:07:12.210000 Improper handling of case sensitivity in the configuration validation component
CVE-2026-26084 9.9 0.24% 1 0 2026-09-08T18:35:10.323000 A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5
CVE-2026-83970 7.8 0.32% 1 0 2026-09-08T18:34:30 Heap-based buffer overflow in Windows Biometric Service allows an authorized att
CVE-2026-83972 7.8 0.32% 1 0 2026-09-08T18:34:21 Heap-based buffer overflow in Windows Biometric Service allows an authorized att
CVE-2026-81954 7.8 0.33% 1 0 2026-09-08T18:34:18 Use after free in Microsoft Office Excel allows an unauthorized attacker to exec
CVE-2026-81953 7.8 0.43% 1 0 2026-09-08T18:34:03 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized att
CVE-2026-69829 9.8 1.05% 1 0 2026-09-08T18:33:17 Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to e
CVE-2026-69420 7.8 0.32% 1 0 2026-09-08T18:32:42 Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker
CVE-2026-20293 7.1 0.13% 1 0 2026-09-08T18:32:05 A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implem
CVE-2026-86730 8.8 0.39% 1 0 2026-09-08T18:32:01 Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-la
CVE-2026-86728 7.5 0.32% 1 0 2026-09-08T18:32:00 AVideo through 29.0 contains an authentication bypass vulnerability in plugin/Pl
CVE-2026-33197 0 0.12% 2 0 2026-09-08T16:18:08.077000 AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause th
CVE-2026-86492 8.5 0.56% 1 0 2026-09-08T15:30:03.247000 In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-ten
CVE-2026-31431 7.8 99.91% 1 100 template 2026-09-08T15:13:07.273000 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-71377 9.8 0.31% 1 0 2026-09-08T14:18:34.130000 Command Argument Injection Vulnerability in Cosminexus Component Container. Thi
CVE-2026-85786 7.5 0.33% 1 0 2026-09-08T14:00:33.017000 Improper handling of highly compressed data in Amazon ion-java before 1.12.1 mig
CVE-2026-48888 7.5 0.26% 1 0 2026-09-08T13:12:58.310000 Allocation of Resources Without Limits or Throttling vulnerability in Automattic
CVE-2026-78234 9.9 0.21% 2 0 2026-09-08T12:31:35 A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA
CVE-2026-50093 9.0 0.19% 1 0 2026-09-08T09:35:45 A vulnerability has been identified in Siveillance Control Pro V3.0 (All version
CVE-2026-62645 9.8 0.35% 1 0 2026-09-08T09:35:45 A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Inf
CVE-2026-81790 7.5 0.27% 1 0 2026-09-08T09:35:45 Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási cí
CVE-2026-71374 9.8 0.31% 1 0 2026-09-08T09:35:44 Deserialization of untrusted data vulnerability in Cosminexus Component Containe
CVE-2026-18963 9.1 3.18% 1 14 template 2026-09-08T09:17:43.063000 A flaw was found in the reset-credentials flow of the keycloak-services componen
CVE-2026-44756 10.0 0.32% 6 0 2026-09-08T03:31:21 A memory safety vulnerability exists in the Extended Passport Protocol (EPP) pro
CVE-2026-19397 None 0.21% 1 0 2026-09-08T03:31:21 Missing authentication for a critical function in ASUS Control Center Express Ag
CVE-2026-66767 7.7 0.26% 1 0 2026-09-08T03:31:21 SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenti
CVE-2026-86510 9.9 0.46% 2 0 2026-09-08T03:31:21 A vulnerability has been found in D-Link DIR-822A A_101. Affected is the functio
CVE-2026-86509 9.6 0.43% 2 0 2026-09-08T03:31:21 A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function se
CVE-2026-76967 7.8 0.22% 1 0 2026-09-08T03:31:21 SAP NetWeaver Business Client does not perform sufficient validation when proces
CVE-2026-76958 8.5 0.22% 1 0 2026-09-08T03:31:13 SAP Integration Suite does not sufficiently validate XML documents accepted from
CVE-2026-58240 9.8 0.34% 2 0 2026-09-08T03:31:11 SAP NetWeaver Message Server does not sufficiently validate the authenticity of
CVE-2026-86541 8.3 0.53% 1 0 2026-09-08T00:30:33 knowns versions before 0.30.0 contain a path traversal vulnerability in the hand
CVE-2026-86439 8.8 0.75% 1 0 2026-09-08T00:30:33 knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool argu
CVE-2026-86544 8.1 0.31% 1 0 2026-09-08T00:30:32 knowns versions before 0.30.0 contain an authorization bypass vulnerability wher
CVE-2026-86542 9.1 0.47% 1 0 2026-09-08T00:30:32 knowns before 0.30.0 fails to validate import names in the import routes, allowi
CVE-2026-86504 7.8 0.13% 1 0 2026-09-07T18:31:43 In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation be
CVE-2026-86494 7.7 0.17% 1 0 2026-09-07T18:31:42 In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthori
CVE-2026-86498 7.7 0.17% 1 0 2026-09-07T18:31:42 In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link s
CVE-2026-86482 8.8 0.23% 1 0 2026-09-07T18:31:36 In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes all
CVE-2026-86478 9.8 0.36% 1 0 2026-09-07T18:31:36 In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authenticatio
CVE-2026-86296 10.0 1.35% 1 0 2026-09-07T12:30:36 A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affe
CVE-2026-85046 8.8 1.43% 2 6 2026-09-06T03:30:24 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at
CVE-2026-86207 None 0.73% 1 0 template 2026-09-05T21:31:20 An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypa
CVE-2026-67277 None 0.43% 1 0 2026-09-05T21:31:20 RouterOS accepts a "related" btest connection before the corresponding primary s
CVE-2026-86060 None 0.40% 2 0 2026-09-05T21:31:20 RouterOS contains an argument-handling flaw in the SSH login path involving user
CVE-2026-86090 7.1 0.25% 1 0 2026-09-04T22:17:18.840000 ntopng before 6.7.260717 fails to perform authorization checks in the delete end
CVE-2026-75754 None 0.21% 1 0 2026-09-04T03:31:07 Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF)
CVE-2023-54391 9.8 1.75% 1 2 2026-09-03T15:33:10 Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypa
CVE-2026-20212 9.8 0.53% 1 1 2026-09-03T13:04:38.177000 A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switc
CVE-2026-20354 5.9 0.15% 1 0 2026-09-02T19:23:13.660000 Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/
CVE-2026-20355 5.9 0.15% 1 0 2026-09-02T18:32:32 Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/
CVE-2026-62911 8.0 1.32% 1 1 2026-09-02T04:18:00.460000 Authentication bypass by capture-replay in Microsoft Exchange Server allows an a
CVE-2026-82078 9.1 1.69% 2 2 2026-09-01T04:18:02.160000 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-81578 9.8 1.62% 2 2 2026-08-31T21:31:56 An improper access control vulnerability exists in the web management interface
CVE-2026-77234 8.8 0.12% 1 0 2026-08-27T20:18:39.130000 Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unpriv
CVE-2026-77237 6.5 0.13% 1 0 2026-08-25T16:44:12.343000 Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel bef
CVE-2026-69836 10.0 1.55% 1 2 2026-08-21T00:31:31 Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a
CVE-2026-75936 7.5 0.44% 1 0 2026-08-20T13:01:19.947000 Improper handling of highly compressed data in the GZIP auto-decompression handl
CVE-2026-69414 7.8 0.56% 2 2 2026-08-19T18:32:28 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-19311 8.1 0.41% 1 0 2026-08-13T15:19:38.027000 Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting p
CVE-2026-68820 7.0 6.18% 1 4 2026-08-11T21:33:01 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-62735 7.8 0.48% 1 2 2026-08-11T18:31:23 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to
CVE-2025-14733 9.8 26.51% 1 1 2026-08-10T21:33:00 An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remot
CVE-2026-13230 6.5 0.38% 1 0 2026-08-06T18:21:08.780000 An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 a
CVE-2026-20316 5.3 9.82% 1 0 2026-07-29T21:31:00 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-43502 7.8 0.12% 2 1 2026-07-23T16:10:00.137000 In the Linux kernel, the following vulnerability has been resolved: net/rds: ha
CVE-2026-8461 8.8 1.57% 1 4 2026-07-23T12:32:53 An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specificall
CVE-2026-8510 7.5 0.21% 1 0 2026-06-17T11:04:00.860000 Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 all
CVE-2022-1096 8.8 24.39% 1 1 2026-06-17T04:21:49.070000 Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote att
CVE-2021-35464 9.8 100.00% 1 2 template 2025-10-22T00:32:19 ForgeRock AM server 6.x before 7, and OpenAM 14.6.3, has a Java deserialization
CVE-2025-2524 4.8 0.30% 1 0 2025-06-17T21:31:59 The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape som
CVE-2024-11015 9.8 0.78% 1 0 2024-12-12T06:30:56 The Sign In With Google plugin for WordPress is vulnerable to authentication byp
CVE-2026-67593 0 0.00% 2 0 N/A
CVE-2026-87016 0 0.00% 2 0 N/A
CVE-2026-87996 0 0.00% 2 0 N/A
CVE-2026-87995 0 0.00% 2 0 N/A
CVE-2026-87011 0 0.00% 2 0 N/A
CVE-2026-85012 0 1.06% 1 0 N/A
CVE-2026-77235 0 0.11% 1 0 N/A
CVE-2026-77236 0 0.11% 1 0 N/A
CVE-2026-54694 0 0.00% 1 0 N/A
CVE-2026-0310 0 0.00% 4 0 N/A
CVE-2026-0307 0 0.00% 1 0 N/A
CVE-2026-85982 0 0.22% 1 0 N/A
CVE-2026-85083 0 0.00% 1 0 N/A
CVE-2026-53939 0 0.20% 1 0 N/A
CVE-2026-84390 0 0.00% 1 0 N/A
CVE-2026-8504 0 0.00% 1 6 N/A

CVE-2026-85103
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T04:18:18.390000

4 posts

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

daniel1820815@infosec.exchange at 2026-09-09T20:10:44.000Z ##

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

community.checkpoint.com/t5/Ge

#CheckPoint #CheckPointSoftwareTechnologies #VPN #vulnerability

##

cR0w@infosec.exchange at 2026-09-09T15:52:09.000Z ##

It has been :zero_percent: days since an ASN.1 decoding vuln.

It has been :zero_percent: days since an overflow vuln in a corp VPN.

It has been :zero_percent: days since a vuln with "Quantum" in the system name.

They are all the same vuln.

nvd.nist.gov/vuln/detail/cve-2

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T14:36:57.000Z ##

Check Point fixed critical Check Point VPN vulnerabilities. Update gateways to prevent remote code execution under CVE-2026-85102 and CVE-2026-85103.

#CheckPoint #VPN #Cybersecurity #CVE202685102 #CVE202685103

securityonline.info/checkpoint

##

offseq@infosec.exchange at 2026-09-09T13:30:24.000Z ##

CRITICAL CVE-2026-85103 in Check Point Quantum Security Gateway: Heap-based buffer overflow in VPN certificate ASN.1 decoding allows unauthenticated RCE. Patch pending — monitor vendor. radar.offseq.com/threat/cve-20 #OffSeq #CheckPoint #infosec #Vuln

##

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T04:18:18.243000

2 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

daniel1820815@infosec.exchange at 2026-09-09T20:10:44.000Z ##

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

community.checkpoint.com/t5/Ge

#CheckPoint #CheckPointSoftwareTechnologies #VPN #vulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T14:36:57.000Z ##

Check Point fixed critical Check Point VPN vulnerabilities. Update gateways to prevent remote code execution under CVE-2026-85102 and CVE-2026-85103.

#CheckPoint #VPN #Cybersecurity #CVE202685102 #CVE202685103

securityonline.info/checkpoint

##

CVE-2026-69730
(9.8 CRITICAL)

EPSS: 1.05%

updated 2026-09-10T04:18:14.773000

4 posts

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

lrosa@mastodon.uno at 2026-09-10T03:46:13.000Z ##

Esecuzione remota di programmi (RCE) da remoto senza autenticazione sui server DNS di Microsoft.

Problema risolto con gli ultimi aggiornamenti.

Quasi tutti i Domain Controller hanno un server DNS a bordo e la vulnerabilità è sfruttabile con richieste DNS, quindi non bloccabili da un normale firewall.

msrc.microsoft.com/update-guid

##

i0null at 2026-09-09T22:38:29.832Z ##

@pkprotoplasm the infamous phrase is used on the FAQ of the MSRC advisory. the NIST description is even more generic.

msrc.microsoft.com/update-guid

##

i0null@infosec.exchange at 2026-09-09T22:38:29.000Z ##

@pkprotoplasm the infamous phrase is used on the FAQ of the MSRC advisory. the NIST description is even more generic.

msrc.microsoft.com/update-guid

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.

Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.

Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.

#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)

##

CVE-2026-19583
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T03:16:59.010000

2 posts

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS

offseq at 2026-09-10T04:30:24.651Z ##

CVE-2026-19583: CRITICAL vuln in Rapid7 Velociraptor (<0.77.2) allows users w/ artifact scheduling rights to execute privileged artifacts like Linux.Sys.BashShell — risking full compromise. Restrict permissions, monitor activity. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T04:30:24.000Z ##

CVE-2026-19583: CRITICAL vuln in Rapid7 Velociraptor (<0.77.2) allows users w/ artifact scheduling rights to execute privileged artifacts like Linux.Sys.BashShell — risking full compromise. Restrict permissions, monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Infosec

##

CVE-2026-18351
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T02:16:34.180000

2 posts

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via

offseq at 2026-09-10T03:00:31.108Z ##

CVE-2026-18351 (CRITICAL): addonsorg Drag and Drop File Upload for Elementor Forms <=1.6.0 lets unauthenticated attackers upload arbitrary files — enabling RCE. Restrict or disable plugin use until remediation. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T03:00:31.000Z ##

CVE-2026-18351 (CRITICAL): addonsorg Drag and Drop File Upload for Elementor Forms <=1.6.0 lets unauthenticated attackers upload arbitrary files — enabling RCE. Restrict or disable plugin use until remediation. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #RCE

##

CVE-2026-15913
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-10T00:30:34

2 posts

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.

thehackerwire@mastodon.social at 2026-09-10T00:04:36.000Z ##

🟠 CVE-2026-15913 - High (7.7)

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T00:04:36.000Z ##

🟠 CVE-2026-15913 - High (7.7)

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87931
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T00:17:24.737000

2 posts

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any

offseq at 2026-09-10T00:00:52.552Z ##

CVE-2026-87931 | CRITICAL buffer overflow in Pavlok Behavioral Conditioning Wearable (Apple Notification Center Service Event Handler). Exploitable locally, no patch or vendor response. Limit device network access. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T00:00:52.000Z ##

CVE-2026-87931 | CRITICAL buffer overflow in Pavlok Behavioral Conditioning Wearable (Apple Notification Center Service Event Handler). Exploitable locally, no patch or vendor response. Limit device network access. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202687931 #IoTSecurity

##

CVE-2026-88069
(0 None)

EPSS: 0.00%

updated 2026-09-09T22:18:49.240000

2 posts

Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuring that the resulting destination remained within the intended extraction directory. An attacker able to submit a malicious file for analysis could use path traversal sequences or crafted paths to ca

offseq at 2026-09-10T01:30:24.171Z ##

CVE-2026-88069: Path traversal in pandora-analysis pandora (<=1.12.7) allows attackers to overwrite system/app files via crafted archives. Severity: CRITICAL (CVSS 9.3). No patch confirmed — monitor vendor updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T01:30:24.000Z ##

CVE-2026-88069: Path traversal in pandora-analysis pandora (<=1.12.7) allows attackers to overwrite system/app files via crafted archives. Severity: CRITICAL (CVSS 9.3). No patch confirmed — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202688069 #vuln #infosec

##

CVE-2026-73786
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-09T21:32:03

1 posts

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance of the vulnerable CPPM server.

thehackerwire@mastodon.social at 2026-09-09T21:01:11.000Z ##

🟠 CVE-2026-73786 - High (7.5)

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79324
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-09T21:32:03

1 posts

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so

thehackerwire@mastodon.social at 2026-09-09T21:01:00.000Z ##

🟠 CVE-2026-79324 - High (7.5)

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by itera...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79322
(8.6 HIGH)

EPSS: 0.00%

updated 2026-09-09T21:31:56

1 posts

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view.

thehackerwire@mastodon.social at 2026-09-09T21:04:44.000Z ##

🟠 CVE-2026-79322 - High (8.6)

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87491
(8.8 HIGH)

EPSS: 0.29%

updated 2026-09-09T21:31:35

8 posts

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Matchbook3469@mastodon.social at 2026-09-10T00:33:59.000Z ##

🟠 New security advisory:

CVE-2026-87491 affects Google Chrome.

• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#Cybersecurity #ZeroDay #ThreatIntel

##

threatnoir at 2026-09-10T00:06:04.781Z ##

⚠️ CRITICAL: Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google patched CVE-2026-87491, a zero-day out-of-bounds write in Chrome's V8 engine actively exploited in the wild. Attackers can execute arbitrary code within the browser sandbox via crafted HTML, potentially compromising any user visiting a malicious page. This is the seventh exploited Chrome zer…

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-10T00:06:04.000Z ##

⚠️ CRITICAL: Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google patched CVE-2026-87491, a zero-day out-of-bounds write in Chrome's V8 engine actively exploited in the wild. Attackers can execute arbitrary code within the browser sandbox via crafted HTML, potentially compromising any user visiting a malicious page. This is the seventh exploited Chrome zer…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

secdb@infosec.exchange at 2026-09-09T21:00:26.000Z ##

🚨 [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-25249 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-19490 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-20079 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-87491 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491

##

cisakevtracker@mastodon.social at 2026-09-09T20:01:25.000Z ##

CVE ID: CVE-2026-87491
Vendor: Google
Product: Chromium V8
Date Added: 2026-09-09
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

jbhall56@infosec.exchange at 2026-09-09T12:46:30.000Z ##

The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. thehackernews.com/2026/09/chro

##

cyberworldops@infosec.exchange at 2026-09-09T11:40:01.000Z ##

Google fixed CVE-2026-87491, an out-of-bounds write in Chrome V8 exploited in the wild via crafted HTML. It enables arbitrary code execution inside the sandbox with risk of heap corruption and memory disclosure. Patch to version 153 immediately and hunt for anomalous browser activity. #ChromeSecurity #ZeroDay #ThreatIntel

cyberworldops.eu/en/chrome-v8-

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T00:17:29.000Z ##

Google patched a Chrome zero-day, CVE-2026-87491, exploited in the wild. Chrome 153 fixes 230 flaws including critical WebGL bugs. Update now.

#Chrome #ZeroDay #Google #CyberSecurity #CVE #V8 #BrowserSecurity #Infosec

securityonline.info/chrome-zer

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 35.95%

updated 2026-09-09T21:31:33

12 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerab

Nuclei template

2 repos

https://github.com/0xBlackash/CVE-2026-20079

https://github.com/CyberAuth/CVE-2026-20079

cyberworldops at 2026-09-10T00:50:00.849Z ##

Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC. Unauthenticated remote attackers can execute commands as root via crafted HTTP requests, compromising firewall management. Immediate patching and exposure review are critical.

cyberworldops.eu/en/cisco-secu

##

bleepingcomputer.com@web.brid.gy at 2026-09-09T21:40:44.000Z ##

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

fed.brid.gy/r/https://www.blee

##

undercodenews@mastodon.social at 2026-09-09T22:17:51.000Z ##

Cisco Secure Firewall Crisis Deepens as CVE-2026-20079 Becomes an Actively Exploited Root-Level Threat + Video

A Maximum-Severity Flaw Has Crossed the Line A critical warning is now hanging over organizations that rely on Cisco Secure Firewall Management Center (FMC): a vulnerability once described as having no evidence of exploitation has now been confirmed as actively abused in real-world attacks. Tracked as CVE-2026-20079, the flaw carries the maximum possible CVSS…

undercodenews.com/cisco-secure

##

patrickcmiller at 2026-09-09T22:12:01.834Z ##

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks bleepingcomputer.com/news/secu

##

oversecurity@mastodon.social at 2026-09-09T22:01:24.000Z ##

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center...

🔗️ [Bleepingcomputer] link.is.it/y6fb5Q

##

cyberworldops@infosec.exchange at 2026-09-10T00:50:00.000Z ##

Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC. Unauthenticated remote attackers can execute commands as root via crafted HTTP requests, compromising firewall management. Immediate patching and exposure review are critical. #CiscoFmc #AuthBypass #CriticalVulnerability

cyberworldops.eu/en/cisco-secu

##

patrickcmiller@infosec.exchange at 2026-09-09T22:12:01.000Z ##

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks bleepingcomputer.com/news/secu

##

oversecurity@mastodon.social at 2026-09-09T22:01:24.000Z ##

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center...

🔗️ [Bleepingcomputer] link.is.it/y6fb5Q

##

secdb@infosec.exchange at 2026-09-09T21:00:26.000Z ##

🚨 [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-25249 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-19490 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-20079 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-87491 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491

##

cisakevtracker@mastodon.social at 2026-09-09T20:01:41.000Z ##

CVE ID: CVE-2026-20079
Vendor: Cisco
Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Date Added: 2026-09-09
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T16:28:31.000Z ##

Cisco Talos warns of Cisco FMC vulnerabilities actively exploited in the wild. Attackers chain CVE-2026-20079 and CVE-2026-20316 to deploy ransomware.

#CiscoFMC #Cybersecurity #CVE202620079 #Ransomware #InfoSec

securityonline.info/cisco-fmc-

##

AAKL@infosec.exchange at 2026-09-09T16:10:40.000Z ##

Broadcom has a long list of advisories today for high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom #Linux

Palo Alto:

Palo Alto has several advisories, one of them critical:

CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing security.paloaltonetworks.com/

More: security.paloaltonetworks.com/

Cisco:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

Dell:

A Dell release that impacts multiple CVEs: Security Update for Dell PowerScale OneFS Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell

Posted yesterday:

Apple:

Several releases were posted yesterday support.apple.com/en-us/100100 #Apple #iOS

AMD:

AMD: Linux GPU Driver NULL Pointer Dereference amd.com/en/resources/product-s #AMD

Adobe:

Adobe has a long list of updates here helpx.adobe.com/security/secur #Adobe #infosec #vulnerability

@cR0w

##

CVE-2026-19490(CVSS UNKNOWN)

EPSS: 3.37%

updated 2026-09-09T21:30:50

2 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

1 repos

https://github.com/TarPeg007/CVE-2026-19490

secdb@infosec.exchange at 2026-09-09T21:00:26.000Z ##

🚨 [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-25249 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-19490 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-20079 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-87491 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491

##

cisakevtracker@mastodon.social at 2026-09-09T20:00:53.000Z ##

CVE ID: CVE-2026-19490
Vendor: Citrix
Product: NetScaler
Date Added: 2026-09-09
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-25249
(8.1 HIGH)

EPSS: 0.76%

updated 2026-09-09T21:30:27

3 posts

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSASE 25.2.b, FortiSASE 25.1.a.2, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted p

secdb@infosec.exchange at 2026-09-09T21:00:26.000Z ##

🚨 [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-25249 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-19490 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-20079 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-87491 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491

##

cisakevtracker@mastodon.social at 2026-09-09T20:01:09.000Z ##

CVE ID: CVE-2025-25249
Vendor: Fortinet
Product: Multiple Products
Date Added: 2026-09-09
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

threatcodex@infosec.exchange at 2026-09-08T17:20:17.000Z ##

CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
#CVE_2025_25249 #PivotC2
socradar.io/blog/cve-2025-2524

##

CVE-2026-79696
(0 None)

EPSS: 0.44%

updated 2026-09-09T21:17:04.820000

1 posts

A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.

offseq@infosec.exchange at 2026-09-09T10:30:26.000Z ##

CVE-2026-79696: Critical code injection (CVSS 10.0) in Google Cloud ADK for Python (2.0.0 – 2.6.0). Unauth RCE possible via crafted session replay in pytest-enabled Cloud Run & GKE. Patch or update now. radar.offseq.com/threat/cve-20 #OffSeq #CVE #CloudSecurity #Python

##

CVE-2026-12855
(8.2 HIGH)

EPSS: 0.12%

updated 2026-09-09T21:17:01.313000

1 posts

Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.

offseq@infosec.exchange at 2026-09-09T04:30:23.000Z ##

CVE-2026-12855: HIGH-severity vuln in InsydeH2O firmware (HP). Local attackers with high privileges may execute arbitrary code due to improper input validation. No patch yet — restrict local admin access. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Firmware #Infosec

##

CVE-2026-84372
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-09-09T21:09:13.080000

1 posts

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode("\r\n") instead of honoring RESP length prefixes. Attacker-controlled keys or values containing CRLF s

CVE-2026-85061
(10.0 CRITICAL)

EPSS: 0.31%

updated 2026-09-09T21:09:13.080000

1 posts

MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or user-supplied cust

DailyCyberSecurity@infosec.exchange at 2026-09-09T02:25:56.000Z ##

A critical MapLibre XSS vulnerability allows zero-click code execution in 2.7M weekly downloads. Discover how CVE-2026-85061 works and how to patch now.

#MapLibre #XSS #CVE202685061 #WebSecurity #InfoSec #CyberSecurity #OpenSource

securityonline.info/maplibre-x

##

CVE-2026-87911
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-09T20:21:02.017000

1 posts

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP s

thehackerwire@mastodon.social at 2026-09-09T21:00:50.000Z ##

🔴 CVE-2026-87911 - Critical (9.6)

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-manage...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79323
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-09T20:20:42.877000

1 posts

Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and admin identifiers via a POST request to /graphql.

thehackerwire@mastodon.social at 2026-09-09T21:04:34.000Z ##

🟠 CVE-2026-79323 - High (7.5)

Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83991
(5.5 MEDIUM)

EPSS: 0.35%

updated 2026-09-09T20:14:54.747000

1 posts

Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.

1 repos

https://github.com/karollooool/CVE-2026-83991-writeup-and-poc

CVE-2026-87874
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-09T20:13:26.720000

1 posts

A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a n

thehackerwire@mastodon.social at 2026-09-09T20:00:36.000Z ##

🟠 CVE-2026-87874 - High (8.1)

A flaw was found in the memcached cache plugin of the community.general Ansible
collection. Although its documentation states that records are stored in JSON
format, the plugin performs no explicit serialization and relies on
python-memcached, whi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80081
(8.8 HIGH)

EPSS: 0.48%

updated 2026-09-09T19:04:29.790000

1 posts

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.

nyanbinary@infosec.exchange at 2026-09-08T18:26:10.000Z ##

I explicitly don't want to complain about MSRC here, this is a bigger topic, but I am a bit confused here:

Compare these two:

msrc.microsoft.com/update-guid - AV:L,UI:R

Q: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A: An attacker must send a user a malicious Office file and convince them to open it.

msrc.microsoft.com/update-guid - AV:N,UI:R

Q: How could an attacker exploit this vulnerability?
A: An attacker could send a specially crafted PowerPoint presentation containing malicious linked media to a target user. The user would need to open the presentation, start the slideshow, and allow the linked content. Successful exploitation could allow the attacker to execute code on the user's system. Authentication is not required.

To me the attack flow looks equivalent wrt to attacker location. We can argue about #2 being actually harder to execute, having more social engineering prerequisites... which is why it totally makes sense for #2 to scored higher on CVSS as it's apparently network & the other one local.

##

CVE-2026-87929
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-09T18:32:12

2 posts

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malicious ci_session cookie with administrator privileges by computing an HMAC-SHA1 using the publicly known encryption key, bypassing authentication checks

thehackerwire@mastodon.social at 2026-09-10T00:04:45.000Z ##

🔴 CVE-2026-87929 - Critical (9.8)

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a mal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T00:04:45.000Z ##

🔴 CVE-2026-87929 - Critical (9.8)

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a mal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87927
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-09T18:32:12

1 posts

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.

thehackerwire@mastodon.social at 2026-09-09T20:00:47.000Z ##

🟠 CVE-2026-87927 - High (8.2)

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Att...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67401
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-09T18:32:06

3 posts

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

3 repos

https://github.com/jithinkrishnanrs/CVE-2026-67401-cPanel-EmailTrack-SQLi

https://github.com/axedos/CVE-2026-67401

https://github.com/HORKimhab/CVE-2026-67401

cR0w@infosec.exchange at 2026-09-09T18:43:49.000Z ##

I can't imagine trying to manage cPanel on the public Internet in 2026, especially on shared systems.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.9 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

##

guru@thecybersecguru.com at 2026-09-09T13:15:19.000Z ##

Critical cPanel Vulnerability (CVE-2026-67401): How an EmailTrack SQL Injection Grants Root Access

A critical cPanel EmailTrack SQL injection vulnerability, CVE-2026-67401, can allow authenticated attackers to escalate to root and take over an entire hosting server

thecybersecguru.com/news/cve-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T01:47:41.000Z ##

A critical CVE-2026-67401 cPanel SQL injection flaw in EmailTrack allows authenticated users to gain full control of the server. Patch your system today.

#cPanel #SQLInjection #CVE202667401 #Cybersecurity #Vulnerability

securityonline.info/cve-2026-6

##

CVE-2026-53938
(8.2 HIGH)

EPSS: 0.24%

updated 2026-09-09T17:17:23.370000

1 posts

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not validate the length of the attacker-supplied `encrypted_key` (JWE Encrypted Key) before unwrapping it into a fixed-size, heap-allocated Content Encryption K

thehackerwire@mastodon.social at 2026-09-09T01:00:08.000Z ##

🟠 CVE-2026-53938 - High (8.2)

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not val...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15667
(7.5 HIGH)

EPSS: 0.56%

updated 2026-09-09T16:17:01.133000

1 posts

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execut

offseq@infosec.exchange at 2026-09-09T03:00:25.000Z ##

CVE-2026-15667: HIGH-severity LFI in Eventin WordPress plugin (≤4.1.22). Contributors can include arbitrary PHP via 'event_layout', risking code execution. Restrict privileges & await patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #LFI

##

CVE-2026-85983
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-09T16:03:22.897000

1 posts

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account.

thehackerwire@mastodon.social at 2026-09-09T03:00:18.000Z ##

🟠 CVE-2026-85983 - High (7.8)

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87628
(8.3 HIGH)

EPSS: 0.17%

updated 2026-09-09T15:35:03

1 posts

Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-09-09T01:30:26.000Z ##

CVE-2026-87628: CRITICAL use-after-free in Chrome's Cast (<153.0.8010.36) enables adjacent code execution outside the sandbox. Patch status unconfirmed. Check the vendor advisory: radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Vuln #CVE202687628

##

CVE-2026-76009
(8.1 HIGH)

EPSS: 0.52%

updated 2026-09-09T15:33:34.467000

2 posts

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/next_cart/v1/migration` REST route with `permission_callback` set to `__return_true` and relying on a hardcoded fallback value of `__token__` in `get_option

thehackerwire@mastodon.social at 2026-09-09T09:01:38.000Z ##

🟠 CVE-2026-76009 - High (8.1)

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/nex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-09T06:00:25.000Z ##

CVE-2026-76009 (HIGH): Next-Cart Store to WooCommerce Migration ≤3.9.8 exposes an auth bypass via REST API. Attackers can execute arbitrary SQL & delete files — full site compromise possible. Patch status unknown. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Infosec

##

CVE-2026-53581
(9.0 CRITICAL)

EPSS: 0.33%

updated 2026-09-09T14:17:12.343000

2 posts

OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape th

offseq@infosec.exchange at 2026-09-09T00:00:35.000Z ##

CVE-2026-53581 (CRITICAL, CVSS 9.0): OPNsense core <26.1.9 NTP module path traversal lets privileged users overwrite files as root. Upgrade to 26.1.9+ & backend 26.4_20+ now. radar.offseq.com/threat/cve-20 #OffSeq #OPNsense #Vuln #PathTraversal

##

thehackerwire@mastodon.social at 2026-09-09T00:00:16.000Z ##

🔴 CVE-2026-53581 - Critical (9)

OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86738
(8.7 HIGH)

EPSS: 0.27%

updated 2026-09-09T13:06:27.157000

1 posts

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other superusers via attribute-selector rules, enabling account takeover.

thehackerwire@mastodon.social at 2026-09-08T17:00:56.000Z ##

🟠 CVE-2026-86738 - High (8.7)

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80172
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-09T12:32:22

2 posts

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could exploit this, leading to unauthorized access. This vulnerability is considered critical as an unauthenticated attacker can repeatedly reuse a captured request to

offseq@infosec.exchange at 2026-09-09T12:00:25.000Z ##

Dell SCG 5.0 (pre-5.36.00.00) hit by CRITICAL vuln (CVE-2026-80172, CVSS 9.8): unauthenticated attackers can reuse requests to gain admin access. Upgrade required to patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE202680172 #Dell #Infosec

##

DailyCyberSecurity@infosec.exchange at 2026-09-07T16:36:30.000Z ##

A Dell Secure Connect Gateway vulnerability (CVE-2026-80172, CVSS 9.8) grants unauthorized access via forged admin tokens. Patch SCG now.

#Dell #SecureConnectGateway #CVE202680172 #RCE #UnauthorizedAccess #PatchNow #Infosec #SCG

securityonline.info/dell-scg-c

##

CVE-2026-79641
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-09T12:32:21

1 posts

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.

thehackerwire@mastodon.social at 2026-09-09T12:00:14.000Z ##

🟠 CVE-2026-79641 - High (7.5)

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-41870(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-09T12:32:13

1 posts

Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.11 through 1.22. Users are recommended to upgrade to version 1.23, which remo

CVE-2026-87795
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-09T12:32:12

1 posts

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

thehackerwire@mastodon.social at 2026-09-09T12:00:35.000Z ##

🟠 CVE-2026-87795 - High (8.2)

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87794
(8.4 HIGH)

EPSS: 0.00%

updated 2026-09-09T10:22:34.397000

1 posts

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.

thehackerwire@mastodon.social at 2026-09-09T12:00:25.000Z ##

🟠 CVE-2026-87794 - High (8.4)

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with cra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82007
(7.8 HIGH)

EPSS: 0.23%

updated 2026-09-09T10:22:32.157000

1 posts

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

thehackerwire@mastodon.social at 2026-09-08T21:00:23.000Z ##

🟠 CVE-2026-82007 - High (7.8)

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16272
(9.1 CRITICAL)

EPSS: 0.14%

updated 2026-09-09T09:33:00

1 posts

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

offseq@infosec.exchange at 2026-09-09T09:00:24.000Z ##

CVE-2026-16272 (CVSS 9.1, CRITICAL) in PayTR Virtual Pos iFrame API (v9x) WHMCS Module v9.0.0: Use of less trusted source can compromise confidentiality and integrity. No patch yet — restrict access and monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026_16272 #infosec

##

CVE-2026-6485
(8.2 HIGH)

EPSS: 0.12%

updated 2026-09-09T06:31:41

1 posts

UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.

thehackerwire@mastodon.social at 2026-09-09T09:01:59.000Z ##

🟠 CVE-2026-6485 - High (8.2)

UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87734
(7.5 HIGH)

EPSS: 0.29%

updated 2026-09-09T06:31:40

1 posts

An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.

thehackerwire@mastodon.social at 2026-09-09T09:01:48.000Z ##

🟠 CVE-2026-87734 - High (7.5)

An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-21096(CVSS UNKNOWN)

EPSS: 0.41%

updated 2026-09-09T06:31:39

1 posts

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

cR0w@infosec.exchange at 2026-09-09T15:35:49.000Z ##

CATTE OVERFLOW I REPEAT CATTE OVERFLOW THIS IS NOT A DRILL :catte:

nvd.nist.gov/vuln/detail/cve-2

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

##

CVE-2026-86502
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-09T05:18:20.043000

1 posts

In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts

thehackerwire@mastodon.social at 2026-09-07T18:00:11.000Z ##

🟠 CVE-2026-86502 - High (8.4)

In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86480
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-09-09T05:18:19.830000

2 posts

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

thehackerwire@mastodon.social at 2026-09-07T22:02:04.000Z ##

🔴 CVE-2026-86480 - Critical (9.8)

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-07T17:30:24.000Z ##

CVE-2026-86480 (CRITICAL, CVSS 9.8) in JetBrains Hub allows unauthenticated attackers to escalate to superuser by registering a trusted service. No patch yet — restrict access & monitor activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #JetBrains #CVE202686480 #Infosec

##

CVE-2026-86479
(8.1 HIGH)

EPSS: 0.20%

updated 2026-09-09T05:18:19.723000

1 posts

In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR

thehackerwire@mastodon.social at 2026-09-07T18:01:17.000Z ##

🟠 CVE-2026-86479 - High (8.1)

In JetBrains YouTrack before 2026.2.18788,
2026.1.14055,
2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86218
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-09-09T05:18:19.490000

10 posts

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

1 repos

https://github.com/HORKimhab/CVE-2026-86218

threatnoir at 2026-09-10T00:06:02.183Z ##

⚠️ CRITICAL: N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

CVE-2026-86218 is a critical pre-auth RCE in N-able N-central being actively exploited in the wild. Any organization running N-central is vulnerable to unauthenticated remote code execution. Federal agencies are mandated to patch by September 11, 2026.

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-10T00:06:02.000Z ##

⚠️ CRITICAL: N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

CVE-2026-86218 is a critical pre-auth RCE in N-able N-central being actively exploited in the wild. Any organization running N-central is vulnerable to unauthenticated remote code execution. Federal agencies are mandated to patch by September 11, 2026.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

AAKL@infosec.exchange at 2026-09-09T16:27:09.000Z ##

New.

Press release:

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats cisa.gov/news-events/news/cisa

The guide: cisa.gov/resources-tools/resou

Updates to the Kev catalogue:

- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #Windows

- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-81963: Microsoft Windows Link Following Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability cve.org/CVERecord?id=CVE-2026- #Adobe

Yesterday:

Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

cyberworldops@infosec.exchange at 2026-09-09T15:00:01.000Z ##

N-able released Hotfix 4 for CVE-2026-86218, a pre-auth RCE in on-prem N-central with CVSS 4.0 10.0. All builds before 2026.3.1.14 are vulnerable, including Hotfix 3. RMM pre-auth RCE is high-value for initial access, prioritize patching and internet exposure review. #NAble #NCentral #RemoteCodeExecution

cyberworldops.eu/en/n-able-fix

##

secdb@infosec.exchange at 2026-09-09T11:00:11.000Z ##

🚨 [CISA-2026:0908] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-75650 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-81963 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Link Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85880 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86218 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Static Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: status.n-able.com/2026/09/06/n ; me.n-able.com/s/security-advis ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260908 #cisa20260908 #cve_2026_75650 #cve_2026_81963 #cve_2026_85880 #cve_2026_86218 #cve202675650 #cve202681963 #cve202685880 #cve202686218

##

cyberworldops@infosec.exchange at 2026-09-09T07:10:01.000Z ##

CISA added CVE-2026-86218 to KEV after confirmed active exploitation. The N-able N-central static code injection allows pre-auth RCE with CVSS 9.8, exposing centralized management infrastructure. Patch and hunt for pre-patch compromise. #Nable #NCentral #RemoteCodeExecution

cyberworldops.eu/en/actively-e

##

cisakevtracker@mastodon.social at 2026-09-08T19:01:17.000Z ##

CVE ID: CVE-2026-86218
Vendor: N-able
Product: N-central
Date Added: 2026-09-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

beyondmachines1@infosec.exchange at 2026-09-08T08:01:13.000Z ##

N-able Issues Emergency Hotfix for Maximum-Severity Unauthenticated RCE in N-central

N-able released a critical hotfix for N-central to fix a CVSS 10.0 unauthenticated remote code execution vulnerability (CVE-2026-86218) that may be under active exploitation. The update is the fourth in five weeks and affects all on-premises builds prior to 2026.3.1.14.

**If you run N-central on-premises, upgrade to build 2026.3.1.14 (Hotfix 4) ASAP. Earlier builds, including Hotfix 3 released just hours before, are still vulnerable to unauthenticated remote code execution. Until the hotfix is applied, take any internet-facing console offline or restrict it to a VPN/IP allowlist. Assume that a compromised server means every managed endpoint behind it needs checking too.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-09-07T23:05:57.000Z ##

⚠️ CRITICAL: N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

N-able N-central RMM platform contains a critical unauthenticated RCE vulnerability (CVE-2026-86218, CVSS 10.0) affecting all builds before 2026.3.1.14. While N-able denies confirmed exploitation, incident reports indicate active wild exploitation. Any organization running N-central is at immediate…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-07T23:05:54.000Z ##

⚠️ CRITICAL: N-able patches max severity N-central flaw amid ongoing attacks

N-able has released emergency patches for three vulnerabilities in N-central RMM, including a critical unauthenticated RCE (CVE-2026-86218) and two high-severity authentication bypasses. Evidence indicates active exploitation in customer environments. Any organization running N-central is at immedi…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-85880
(7.8 HIGH)

EPSS: 0.57%

updated 2026-09-09T05:18:19.193000

9 posts

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

AAKL@infosec.exchange at 2026-09-09T16:27:09.000Z ##

New.

Press release:

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats cisa.gov/news-events/news/cisa

The guide: cisa.gov/resources-tools/resou

Updates to the Kev catalogue:

- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #Windows

- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-81963: Microsoft Windows Link Following Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability cve.org/CVERecord?id=CVE-2026- #Adobe

Yesterday:

Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

youranonnewsirc@nerdculture.de at 2026-09-09T16:26:23.000Z ##

**Latest Global Briefing: September 9, 2026**

**Cybersecurity:** Microsoft's September Patch Tuesday revealed nearly 1000 vulnerabilities, with CISA flagging two exploited zero-days (CVE-2026-81963, CVE-2026-85880) requiring urgent patching by federal agencies. The FBI also announced a new strategy to enhance cyberattack disruptions.

**Technology:** Dell Technologies reported surging Q2 FY 2027 earnings driven by high AI server demand, with OpenAI exploring AI infrastructure-as-a-service.

**Geopolitics:** Tensions heightened in the Middle East as US forces destroyed five Iranian oil tankers following IRGC attacks on a US Navy warship. Separately, 12 nations implemented trade bans on goods from Israeli settlements.

#Cybersecurity #TechNews #Geopolitics

##

secdb@infosec.exchange at 2026-09-09T11:00:11.000Z ##

🚨 [CISA-2026:0908] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-75650 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-81963 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Link Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85880 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86218 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Static Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: status.n-able.com/2026/09/06/n ; me.n-able.com/s/security-advis ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260908 #cisa20260908 #cve_2026_75650 #cve_2026_81963 #cve_2026_85880 #cve_2026_86218 #cve202675650 #cve202681963 #cve202685880 #cve202686218

##

beyondmachines1@infosec.exchange at 2026-09-09T09:01:13.000Z ##

Microsoft Patches 966 Vulnerabilities in September 2026 Update Including Two Actively Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixed 966 flaws, its largest ever. The patch package includes 105 critical bugs and two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880). The critical flaws cluster in Windows network services (DNS, DHCP, RRAS, Netlogon), Office file parsing, imaging/graphics components, and Azure/Entra cloud services. Microsoft is attributing the surge in volume to AI-assisted vulnerability discovery.

**Patch the Windows OS first for the two zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC, both already exploited in attacks to gain SYSTEM privileges. Next, patch internet-reachable and domain-joined Windows servers: DNS, DHCP, RRAS, Netlogon, Kerberos and the Key Distribution Center, Services for NFS, Deployment Services, Failover Cluster and SSTP all carry critical remote code execution flaws. Then move through Outlook, Word, Excel, and Office, followed by SQL Server, SharePoint Server, and Exchange. Windows Hello, Secure Kernel Mode, Credential Guard, and VBS should follow for anything holding credentials or running as a security boundary. Everything else can follow in the normal cycle, but plan for it to take longer than usual: almost no organization can test and deploy this volume in a single window.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.

Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.

Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.

#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

🏆 New Achievement! Stand In The Fire One More Time, I Dare You!

NINE HUNDRED AND SEVENTY-FOUR vulnerabilities. Microsoft dropped 974 patches this Patch Tuesday and you are STILL standing in the bad stuff. CVE-2026-81963 and CVE-2026-85880, both CVSS 7.8, are being actively exploited RIGHT NOW against the Windows Update Stack and Windows Advanced Local Procedure Call — privilege escalation, in the wild, before disclosure. (1/2)

##

cisakevtracker@mastodon.social at 2026-09-08T19:01:33.000Z ##

CVE ID: CVE-2026-85880
Vendor: Microsoft
Product: Windows
Date Added: 2026-09-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-08T18:09:23.000Z ##

Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild.

#PatchTuesday #ZeroDay #Microsoft #Windows #CyberSecurity #CVE #Infosec #VulnerabilityManagement

securityonline.info/patch-tues

##

cR0w@infosec.exchange at 2026-09-08T17:25:21.000Z ##

Only two 0days this month for MS? Bummer.

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

##

CVE-2026-80166
(7.8 HIGH)

EPSS: 0.10%

updated 2026-09-09T05:18:14.767000

1 posts

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.

thehackerwire@mastodon.social at 2026-09-07T22:02:23.000Z ##

🟠 CVE-2026-80166 - High (7.8)

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67276
(0 None)

EPSS: 0.24%

updated 2026-09-09T05:17:28.130000

3 posts

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target

4 repos

https://github.com/HORKimhab/CVE-2026-67276

https://github.com/BlackHatExploitation/exploit-mikrotik-2026

https://github.com/dinosn/mikrotrick-poc

https://github.com/4rt-Net/Mikrotrick_POC

threatcodex@infosec.exchange at 2026-09-09T15:00:02.000Z ##

CVE-2026-67276: MikroTik RouterOS SSH Zero-Day Exploited in Router Takeover Attacks
#CVE_2026_67276
socprime.com/blog/cve-2026-672

##

threatnoir@infosec.exchange at 2026-09-07T23:05:52.000Z ##

⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers

Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

netsecio@mastodon.social at 2026-09-07T17:33:21.000Z ##

📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit

🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity

🔗 cyber.netsecops.io/articles/mi

##

CVE-2026-66768
(9.0 CRITICAL)

EPSS: 0.32%

updated 2026-09-09T05:17:27.537000

1 posts

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and avai

thehackerwire@mastodon.social at 2026-09-08T03:00:18.000Z ##

🔴 CVE-2026-66768 - Critical (9)

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73314
(7.5 HIGH)

EPSS: 0.45%

updated 2026-09-09T03:31:44

1 posts

XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo header value. When the algorithm cannot be mapped to a supported hash function, the verification function incorrectly returns true instead of failing, causing

1 repos

https://github.com/BomboBombone/CVE-2026-73314

thehackerwire@mastodon.social at 2026-09-08T15:00:17.000Z ##

🟠 CVE-2026-73314 - High (7.5)

XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo heade...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73316
(7.5 HIGH)

EPSS: 0.20%

updated 2026-09-09T03:30:36

1 posts

XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades.

1 repos

https://github.com/BomboBombone/CVE-2026-73316

thehackerwire@mastodon.social at 2026-09-08T15:00:39.000Z ##

🟠 CVE-2026-73316 - High (7.5)

XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73315
(8.6 HIGH)

EPSS: 0.27%

updated 2026-09-09T01:16:58.050000

1 posts

XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback

1 repos

https://github.com/BomboBombone/CVE-2026-73315

thehackerwire@mastodon.social at 2026-09-08T15:00:27.000Z ##

🟠 CVE-2026-73315 - High (8.6)

XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18355
(7.5 HIGH)

EPSS: 0.84%

updated 2026-09-08T22:17:40.127000

2 posts

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet().

offseq@infosec.exchange at 2026-09-08T07:30:25.000Z ##

Red Hat 389-ds-base faces CRITICAL flaws (CVE-2026-18355 & more): heap buffer overflow, pre-auth NULL dereference, privilege escalation, and ACI bypass in RHEL 9.2 (<9.2.4). Patch ASAP. radar.offseq.com/threat/red-ha #OffSeq #RedHat #CVE #LDAP

##

offseq@infosec.exchange at 2026-09-08T06:00:23.000Z ##

CRITICAL vulnerabilities in Red Hat 389-ds-base (>=9.4 <9.4.5) incl. heap overflow (CVE-2026-18355), privilege escalation, and ACI bypass. Patch ASAP via RHSA-2026:64781. Details: radar.offseq.com/threat/red-ha #OffSeq #RedHat #LDAP #Vuln #SysAdmin

##

CVE-2026-81994
(8.2 HIGH)

EPSS: 0.30%

updated 2026-09-08T21:34:41

1 posts

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious fi

thehackerwire@mastodon.social at 2026-09-09T03:00:30.000Z ##

🟠 CVE-2026-81994 - High (8.2)

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitiv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84869
(9.9 CRITICAL)

EPSS: 0.38%

updated 2026-09-08T21:34:37

2 posts

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

cR0w@infosec.exchange at 2026-09-08T21:38:08.000Z ##

WTF

github.com/ConnectWise-Advisor

Earlier versions of ScreenConnect Client Support and Access sessions contained a client-side file-transfer handling condition in which file-transfer actions could be processed through an active remote session without proper authorization or Host confirmation. Under certain circumstances, this could allow files to be transferred to and executed on the Host client system, including through elevated execution actions. ScreenConnect servers are not impacted. Disabling file-transfer permissions for affected sessions may reduce exposure until the update is applied.

##

thehackerwire@mastodon.social at 2026-09-08T21:00:02.000Z ##

🔴 CVE-2026-84869 - Critical (9.9)

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84942
(8.7 HIGH)

EPSS: 0.33%

updated 2026-09-08T21:34:37

1 posts

Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function pro

thehackerwire@mastodon.social at 2026-09-08T21:00:13.000Z ##

🟠 CVE-2026-84942 - High (8.7)

Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81963
(7.8 HIGH)

EPSS: 0.63%

updated 2026-09-08T21:34:09

9 posts

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

AAKL@infosec.exchange at 2026-09-09T16:27:09.000Z ##

New.

Press release:

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats cisa.gov/news-events/news/cisa

The guide: cisa.gov/resources-tools/resou

Updates to the Kev catalogue:

- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #Windows

- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-81963: Microsoft Windows Link Following Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability cve.org/CVERecord?id=CVE-2026- #Adobe

Yesterday:

Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

youranonnewsirc@nerdculture.de at 2026-09-09T16:26:23.000Z ##

**Latest Global Briefing: September 9, 2026**

**Cybersecurity:** Microsoft's September Patch Tuesday revealed nearly 1000 vulnerabilities, with CISA flagging two exploited zero-days (CVE-2026-81963, CVE-2026-85880) requiring urgent patching by federal agencies. The FBI also announced a new strategy to enhance cyberattack disruptions.

**Technology:** Dell Technologies reported surging Q2 FY 2027 earnings driven by high AI server demand, with OpenAI exploring AI infrastructure-as-a-service.

**Geopolitics:** Tensions heightened in the Middle East as US forces destroyed five Iranian oil tankers following IRGC attacks on a US Navy warship. Separately, 12 nations implemented trade bans on goods from Israeli settlements.

#Cybersecurity #TechNews #Geopolitics

##

secdb@infosec.exchange at 2026-09-09T11:00:11.000Z ##

🚨 [CISA-2026:0908] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-75650 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-81963 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Link Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85880 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86218 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Static Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: status.n-able.com/2026/09/06/n ; me.n-able.com/s/security-advis ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260908 #cisa20260908 #cve_2026_75650 #cve_2026_81963 #cve_2026_85880 #cve_2026_86218 #cve202675650 #cve202681963 #cve202685880 #cve202686218

##

beyondmachines1@infosec.exchange at 2026-09-09T09:01:13.000Z ##

Microsoft Patches 966 Vulnerabilities in September 2026 Update Including Two Actively Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixed 966 flaws, its largest ever. The patch package includes 105 critical bugs and two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880). The critical flaws cluster in Windows network services (DNS, DHCP, RRAS, Netlogon), Office file parsing, imaging/graphics components, and Azure/Entra cloud services. Microsoft is attributing the surge in volume to AI-assisted vulnerability discovery.

**Patch the Windows OS first for the two zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC, both already exploited in attacks to gain SYSTEM privileges. Next, patch internet-reachable and domain-joined Windows servers: DNS, DHCP, RRAS, Netlogon, Kerberos and the Key Distribution Center, Services for NFS, Deployment Services, Failover Cluster and SSTP all carry critical remote code execution flaws. Then move through Outlook, Word, Excel, and Office, followed by SQL Server, SharePoint Server, and Exchange. Windows Hello, Secure Kernel Mode, Credential Guard, and VBS should follow for anything holding credentials or running as a security boundary. Everything else can follow in the normal cycle, but plan for it to take longer than usual: almost no organization can test and deploy this volume in a single window.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.

Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.

Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.

#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

🏆 New Achievement! Stand In The Fire One More Time, I Dare You!

NINE HUNDRED AND SEVENTY-FOUR vulnerabilities. Microsoft dropped 974 patches this Patch Tuesday and you are STILL standing in the bad stuff. CVE-2026-81963 and CVE-2026-85880, both CVSS 7.8, are being actively exploited RIGHT NOW against the Windows Update Stack and Windows Advanced Local Procedure Call — privilege escalation, in the wild, before disclosure. (1/2)

##

cisakevtracker@mastodon.social at 2026-09-08T19:01:01.000Z ##

CVE ID: CVE-2026-81963
Vendor: Microsoft
Product: Windows
Date Added: 2026-09-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-08T18:09:23.000Z ##

Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild.

#PatchTuesday #ZeroDay #Microsoft #Windows #CyberSecurity #CVE #Infosec #VulnerabilityManagement

securityonline.info/patch-tues

##

cR0w@infosec.exchange at 2026-09-08T17:25:21.000Z ##

Only two 0days this month for MS? Bummer.

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

##

CVE-2026-75650
(10.0 CRITICAL)

EPSS: 2.15%

updated 2026-09-08T21:33:09

14 posts

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

4 repos

https://github.com/disrex-group/stylesmuggler-adobe-patches

https://github.com/dinosn/cve-2026-75650-magento-validation-lab

https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit

https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos

thecybermind at 2026-09-10T00:59:17.540Z ##

Critical CVE-2026-75650 alert for Adobe Commerce and Magento. Active CISA KEV exploitation requires immediate template parsing audits and endpoint hardening. Access our technical forensic brief to secure your enterprise perimeter today.

thecybermind.co/8in9

##

thecybermind@infosec.exchange at 2026-09-10T00:59:17.000Z ##

Critical CVE-2026-75650 alert for Adobe Commerce and Magento. Active CISA KEV exploitation requires immediate template parsing audits and endpoint hardening. Access our technical forensic brief to secure your enterprise perimeter today.

thecybermind.co/8in9

##

AAKL@infosec.exchange at 2026-09-09T16:27:09.000Z ##

New.

Press release:

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats cisa.gov/news-events/news/cisa

The guide: cisa.gov/resources-tools/resou

Updates to the Kev catalogue:

- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #Windows

- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-81963: Microsoft Windows Link Following Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability cve.org/CVERecord?id=CVE-2026- #Adobe

Yesterday:

Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-09T11:00:11.000Z ##

🚨 [CISA-2026:0908] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-75650 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-81963 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Link Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85880 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86218 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Static Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: status.n-able.com/2026/09/06/n ; me.n-able.com/s/security-advis ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260908 #cisa20260908 #cve_2026_75650 #cve_2026_81963 #cve_2026_85880 #cve_2026_86218 #cve202675650 #cve202681963 #cve202685880 #cve202686218

##

benzogaga33@mamot.fr at 2026-09-09T09:40:05.000Z ##

Magento : la faille zero-day StyleSmuggler est corrigée, mais des boutiques sont déjà piratées it-connect.fr/magento-adobe-co #ActuCybersécurité #Cybersécurité #Vulnérabilité #Adobe

##

beyondmachines1@infosec.exchange at 2026-09-08T20:01:13.000Z ##

Adobe releases September 2026 patches for multiple products

Adobe's September 2026 security updates patch vulnerabilities across eight product families: Commerce/Magento, ColdFusion, Campaign Classic, Acrobat/Reader, Experience Manager, Photoshop, Illustrator, and Animate. The flaws could allow arbitrary code execution, privilege escalation, security feature bypass, file system read/write, memory exposure, and denial-of-service. The most urgent is CVE-2026-75650 (CVSS 10.0) in Adobe Commerce and Magento Open Source, an unauthenticated template-engine flaw already exploited in the wild and fixed by a separate out-of-band hotfix on September 7 that must be applied in addition to the September update.

**If you run Adobe Commerce or Magento Open Source, apply the out-of-band hotfix for CVE-2026-75650 immediately! Adobe is aware of this flaw being exploited in the wild, it carries a CVSS score of 10.0, and it can be triggered without authentication. Next, update ColdFusion and Adobe Campaign Classic, both of which received Adobe's highest priority rating and contain critical flaws that could lead to arbitrary code execution. Then apply the September Adobe Commerce security update, which is separate from the hotfix and must be installed in addition to it. After that, update Adobe Experience Manager and Acrobat and Reader. Finally, update Photoshop, Illustrator, and Animate. If you can't update right away, restrict network access to Commerce, ColdFusion, Campaign Classic, and Experience Manager servers, and avoid opening untrusted PDFs and untrusted image or project files in Acrobat, Reader, Photoshop, Illustrator, and Animate until patches are applied.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

cisakevtracker@mastodon.social at 2026-09-08T19:00:46.000Z ##

CVE ID: CVE-2026-75650
Vendor: Adobe
Product: Commerce and Magento
Date Added: 2026-09-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-09-08T15:47:10.000Z ##

Update: Adobe released an update for CVE-2026-75650 yesterday helpx.adobe.com/security/produ.

CSO: Adobe Commerce max-severity bug comes under active attack csoonline.com/article/4219626/ #Adobe #infosec #vulnerability

##

oversecurity@mastodon.social at 2026-09-08T14:00:51.000Z ##

Adobe fixes critical Magento zero-day exploited to backdoor servers

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that...

🔗️ [Bleepingcomputer] link.is.it/kbCfVz

##

jbhall56@infosec.exchange at 2026-09-08T12:42:21.000Z ##

The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. thehackernews.com/2026/09/adob

##

security_crawler_carl@infosec.exchange at 2026-09-08T00:43:48.000Z ##

🏆 New Achievement! StyleSmuggler Has Entered the Tutorial Zone!

Welcome, new merchant! This is the part of the game where we introduce a mandatory debuff called CVE-2026-75650. Adobe Commerce and Magento 2 contain a CVSS 10.0 critical flaw in the template engine — an Improper Neutralization of Special Elements — that lets attackers execute arbitrary code with no user interaction required. This isn't a side quest. (1/2)

##

DailyCyberSecurity@infosec.exchange at 2026-09-08T00:17:02.000Z ##

An Adobe Commerce vulnerability, CVE-2026-75650 (CVSS 10), enables unauthenticated arbitrary code execution and is exploited in the wild. Patch now.

#AdobeCommerce #Magento #StyleSmuggler #CVE202675650 #RCE #Ecommerce #ExploitedInTheWild #Infosec

securityonline.info/adobe-comm

##

thehackerwire@mastodon.social at 2026-09-07T22:00:48.000Z ##

🔴 CVE-2026-75650 - Critical (10)

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-07T20:30:23.000Z ##

Adobe Commerce faces a CRITICAL (CVSS 10) template engine flaw (CVE-2026-75650) allowing arbitrary code execution with no user interaction required. Update and monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #AdobeCommerce #CVE202675650 #infosec

##

CVE-2026-80119
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-08T20:10:30.270000

1 posts

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path to an exposed IOCTL. Attackers can issue a single IOCTL call to trigger the driver

hugovalters@mastodon.social at 2026-09-10T04:20:44.000Z ##

CVE-2026-80119: Info disclosure in Directio64.sys lets unauthenticated local attackers dump physical memory via crafted IOCTL. CVSS 7.8. Unpatched. Update PassMark tools or restrict driver access. Details: valtersit.com/cve/CVE-2026-801 #CVE #infosec #cybersecurity

##

CVE-2026-86540
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-08T19:56:50.950000

1 posts

knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.

thehackerwire@mastodon.social at 2026-09-08T00:04:13.000Z ##

🟠 CVE-2026-86540 - High (7.8)

knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a craf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86538
(7.5 HIGH)

EPSS: 0.74%

updated 2026-09-08T19:56:50.950000

1 posts

knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensitive files like credentials and configuration through the JSON response.

thehackerwire@mastodon.social at 2026-09-08T00:04:02.000Z ##

🟠 CVE-2026-86538 - High (7.5)

knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86543
(9.8 CRITICAL)

EPSS: 0.44%

updated 2026-09-08T19:56:50.950000

2 posts

knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.

thehackerwire@mastodon.social at 2026-09-08T00:02:54.000Z ##

🔴 CVE-2026-86543 - Critical (9.8)

knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-08T00:00:34.000Z ##

CVE-2026-86543: CRITICAL vuln in knowns-dev knowns <0.30.0. Mgmt API is exposed w/o auth by default, allowing attackers to create public tunnels. Restrict access & upgrade ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026_86543 #Vulnerability #APIsecurity

##

CVE-2026-86721
(7.5 HIGH)

EPSS: 0.29%

updated 2026-09-08T19:53:13.400000

1 posts

AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.

thehackerwire@mastodon.social at 2026-09-08T17:02:29.000Z ##

🟠 CVE-2026-86721 - High (7.5)

AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86727
(7.5 HIGH)

EPSS: 0.31%

updated 2026-09-08T19:53:13.400000

1 posts

AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response to obtain sensitive streaming creden

thehackerwire@mastodon.social at 2026-09-08T17:02:07.000Z ##

🟠 CVE-2026-86727 - High (7.5)

AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86732
(8.8 HIGH)

EPSS: 0.51%

updated 2026-09-08T19:53:13.400000

1 posts

Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then use a PHP gadget chain with yii\rbac\PhpManager

thehackerwire@mastodon.social at 2026-09-08T17:01:06.000Z ##

🟠 CVE-2026-86732 - High (8.8)

Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84282
(0 None)

EPSS: 0.16%

updated 2026-09-08T19:29:09.680000

1 posts

A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can manipulate the document server parameter to cause the ownCloud server to send arbitrar

DailyCyberSecurity@infosec.exchange at 2026-09-08T15:19:26.000Z ##

A new ONLYOFFICE ownCloud plugin SSRF vulnerability, tracked as CVE-2026-84282, allows attackers to trigger unauthorized internal network requests.

#ONLYOFFICE #ownCloud #SSRF #Cybersecurity #CVE202684282 #Vulnerability

securityonline.info/onlyoffice

##

CVE-2026-86206
(0 None)

EPSS: 0.68%

updated 2026-09-08T19:16:41.410000

1 posts

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

Nuclei template

CVE-2026-76969
(9.4 CRITICAL)

EPSS: 0.29%

updated 2026-09-08T19:12:59.557000

2 posts

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application.

offseq@infosec.exchange at 2026-09-08T04:30:23.000Z ##

SAP CAP's @sap/cds-mtxs (<=4.0.2) has a CRITICAL flaw (CVE-2026-76969): insufficiently protected credentials let unauthenticated attackers steal creds and delete/replace tenant data. No patch yet — monitor SAP updates. radar.offseq.com/threat/cve-20 #OffSeq #SAP #infosec #CVE

##

thehackerwire@mastodon.social at 2026-09-08T02:00:25.000Z ##

🔴 CVE-2026-76969 - Critical (9.4)

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credential...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75021
(8.1 HIGH)

EPSS: 0.42%

updated 2026-09-08T19:07:52.113000

1 posts

fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debugging interface can be exposed beyond the local machine, and because the Inspector protocol allows arbitrary code evaluation, a remote party that reaches it can ach

thehackerwire@mastodon.social at 2026-09-08T13:59:48.000Z ##

🟠 CVE-2026-75021 - High (8.1)

fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debugging inter...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82067
(8.1 HIGH)

EPSS: 0.28%

updated 2026-09-08T19:07:12.210000

2 posts

Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and a

CVE-2026-26084
(9.9 CRITICAL)

EPSS: 0.24%

updated 2026-09-08T18:35:10.323000

1 posts

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.

CVE-2026-83970
(7.8 HIGH)

EPSS: 0.32%

updated 2026-09-08T18:34:30

1 posts

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

nyanbinary@infosec.exchange at 2026-09-08T18:36:25.000Z ##

I'm also quickly going to mention this, explicitly not as a complaint but as a good case study of a well chosen "SHOULD" & why should is better than must here:

cve.org/ResourcesSupport/AllRe

5.1.1 SHOULD contain sufficient information to uniquely identify the Vulnerability and distinguish it from similar Vulnerabilities.

This, uh, will be a bit of an issue with msrc.microsoft.com/update-guid & msrc.microsoft.com/update-guid . You it actually doesn't matter. The fix is the same, fucking update. And it doesn't matter if you got owned through -83972 or -83970, given the current firehose. It's actually one of those cases where I'd be happy to relax the "one record per vuln" rule, in no world does the differentiation of these two matter to anyone.

##

CVE-2026-83972
(7.8 HIGH)

EPSS: 0.32%

updated 2026-09-08T18:34:21

1 posts

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

nyanbinary@infosec.exchange at 2026-09-08T18:36:25.000Z ##

I'm also quickly going to mention this, explicitly not as a complaint but as a good case study of a well chosen "SHOULD" & why should is better than must here:

cve.org/ResourcesSupport/AllRe

5.1.1 SHOULD contain sufficient information to uniquely identify the Vulnerability and distinguish it from similar Vulnerabilities.

This, uh, will be a bit of an issue with msrc.microsoft.com/update-guid & msrc.microsoft.com/update-guid . You it actually doesn't matter. The fix is the same, fucking update. And it doesn't matter if you got owned through -83972 or -83970, given the current firehose. It's actually one of those cases where I'd be happy to relax the "one record per vuln" rule, in no world does the differentiation of these two matter to anyone.

##

CVE-2026-81954
(7.8 HIGH)

EPSS: 0.33%

updated 2026-09-08T18:34:18

1 posts

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

nyanbinary@infosec.exchange at 2026-09-08T18:26:10.000Z ##

I explicitly don't want to complain about MSRC here, this is a bigger topic, but I am a bit confused here:

Compare these two:

msrc.microsoft.com/update-guid - AV:L,UI:R

Q: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A: An attacker must send a user a malicious Office file and convince them to open it.

msrc.microsoft.com/update-guid - AV:N,UI:R

Q: How could an attacker exploit this vulnerability?
A: An attacker could send a specially crafted PowerPoint presentation containing malicious linked media to a target user. The user would need to open the presentation, start the slideshow, and allow the linked content. Successful exploitation could allow the attacker to execute code on the user's system. Authentication is not required.

To me the attack flow looks equivalent wrt to attacker location. We can argue about #2 being actually harder to execute, having more social engineering prerequisites... which is why it totally makes sense for #2 to scored higher on CVSS as it's apparently network & the other one local.

##

CVE-2026-81953
(7.8 HIGH)

EPSS: 0.43%

updated 2026-09-08T18:34:03

1 posts

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

nyanbinary@infosec.exchange at 2026-09-08T18:13:22.000Z ##

db.gcve.eu/vuln/cve-2026-81953

Microsoft Excel Remote Code Execution Vulnerability

looks inside

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

##

CVE-2026-69829
(9.8 CRITICAL)

EPSS: 1.05%

updated 2026-09-08T18:33:17

1 posts

Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.

Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.

Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.

#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)

##

CVE-2026-69420
(7.8 HIGH)

EPSS: 0.32%

updated 2026-09-08T18:32:42

1 posts

Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.

winterknight1337@infosec.exchange at 2026-09-08T22:18:42.000Z ##

CVE-2026-69420 is a heap based buffer overflow on Windows resulting in an LPE. Couldn’t have come up with a more memey CVE for 69420 if I tried.

##

CVE-2026-20293
(7.1 HIGH)

EPSS: 0.13%

updated 2026-09-08T18:32:05

1 posts

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin&nbsp;or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized softw

AAKL@infosec.exchange at 2026-09-08T16:42:45.000Z ##

New advisories from Cisco addressing two high and medium-severity vulnerabilities.

New: CVE-2026-20293: Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability sec.cloudapps.cisco.com/securi

Known: CVE-2026-20354 and CVE-2026-20355: Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2026-86730
(8.8 HIGH)

EPSS: 0.39%

updated 2026-09-08T18:32:01

1 posts

Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON strings to bypass cleanse validation, then trigger arbitrary object instantiation and code execution through Craft::createObject().

thehackerwire@mastodon.social at 2026-09-08T17:01:16.000Z ##

🟠 CVE-2026-86730 - High (8.8)

Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86728
(7.5 HIGH)

EPSS: 0.32%

updated 2026-09-08T18:32:00

1 posts

AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.

thehackerwire@mastodon.social at 2026-09-08T17:02:18.000Z ##

🟠 CVE-2026-86728 - High (7.5)

AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-33197
(0 None)

EPSS: 0.12%

updated 2026-09-08T16:18:08.077000

2 posts

AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact system Confidentiality, Integrity, and Availability.

DailyCyberSecurity at 2026-09-10T01:14:10.106Z ##

A critical Secure Boot bypass vulnerability via a UEFI Shell flaw exposes servers to code execution. Discover how CVE-2026-33197 impacts devices.

securityonline.info/secure-boo

##

DailyCyberSecurity@infosec.exchange at 2026-09-10T01:14:10.000Z ##

A critical Secure Boot bypass vulnerability via a UEFI Shell flaw exposes servers to code execution. Discover how CVE-2026-33197 impacts devices.

#SecureBoot #UEFI #Vulnerability #Cybersecurity #CVE202633197

securityonline.info/secure-boo

##

CVE-2026-86492
(8.5 HIGH)

EPSS: 0.56%

updated 2026-09-08T15:30:03.247000

1 posts

In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

thehackerwire@mastodon.social at 2026-09-07T18:00:56.000Z ##

🟠 CVE-2026-86492 - High (8.5)

In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 99.91%

updated 2026-09-08T15:13:07.273000

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

Nuclei template

100 repos

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/sammwyy/copyfail-rs

https://github.com/gagaltotal/cve-2026-31431-copy-fail

https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/diemoeve/copyfail-rs

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/0xShe/CVE-2026-31431

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/cozystack/copy-fail-blocker

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/samanzamani/copy-fail-checker

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/Qengineering/RK35xx-CopyFail-Hotfix

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/sudoytang/copyfail-arm64

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/insomnisec/Detections-CVE-2026-31431

https://github.com/malwarekid/CVE-2026-31431

https://github.com/desultory/CVE-2026-31431

https://github.com/sgkdev/page_inject

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/povzayd/CVE-2026-31431

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/luotian2/CVE-2026-31431

https://github.com/bootsareme/copyfail-deconstructed

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/Smarttfoxx/copyfail

https://github.com/Boos4721/copyfail-rs

https://github.com/b5null/CVE-2026-31431-C

https://github.com/rvzsec/CVE-2026-31431

https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH

https://github.com/rootsecdev/cve_2026_31431

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/nisec-eric/cve-2026-31431

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/tgies/copy-fail-c

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/pedromizz/copy-fail

https://github.com/badsectorlabs/copyfail-go

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/atgreen/block-copyfail

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/Juguitos/copy-fail

https://github.com/cyber-joker/copy-fail-python

https://github.com/pyroceper/copy-fail-CVE-2026-31431

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/wgnet/wg.copyfail.patch

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/Huchangzhi/autorootlinux

https://github.com/mrunalp/block-copyfail

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/ncmprbll/copy-fail-rs

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/sgkdev/ptrace_may_dream

https://github.com/cs8425/copy-fail-go

https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/wesmar/CVE-2026-31431

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/xeloxa/copyfail-exploit

https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4

https://github.com/lonelyor/CVE-2026-31431-exp

kubesploit@learnk8s.news at 2026-09-09T18:36:03.000Z ##

This article examines why Copy Fail (CVE-2026-31431) breaks container assumptions and provides a small, safe Python check to determine whether your nodes can reach the vulnerable kernel path

ku.bz/CTv-Yf60c

##

CVE-2026-71377
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-09-08T14:18:34.130000

1 posts

Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 through 11-00-12, from 09-87 before 09-87-10, from 09-80 t

offseq@infosec.exchange at 2026-09-08T09:00:23.000Z ##

CVE-2026-71377: Critical (CVSS 9.8) command arg injection in Hitachi Cosminexus Component Container (09-00 to 11-70-01). Remote, no auth needed, complete compromise possible. No patch yet. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202671377 #Vuln #Infosec

##

CVE-2026-85786
(7.5 HIGH)

EPSS: 0.33%

updated 2026-09-08T14:00:33.017000

1 posts

Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insufficient coverage of the GZIP auto-decompression opt-out introduced for CVE-2026-75936. To remediate this issue, users should upgrade to version 1.12.1.

hugovalters@mastodon.social at 2026-09-10T02:40:38.000Z ##

CVE-2026-85786: DoS via crafted compressed Ion data in Amazon ion-java <1.12.1. Expansion bomb bypasses GZIP opt-out (CVE-2026-75936). CVSS 7.5. Update to 1.12.1 now. valtersit.com/cve/CVE-2026-857 #CVE #infosec #AWS

##

CVE-2026-48888
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-08T13:12:58.310000

1 posts

Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.

thehackerwire@mastodon.social at 2026-09-08T09:01:01.000Z ##

🟠 CVE-2026-48888 - High (7.5)

Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS.

This issue affects WooCommerce: from n/a before 11.1.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78234
(9.9 CRITICAL)

EPSS: 0.21%

updated 2026-09-08T12:31:35

2 posts

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with

DailyCyberSecurity@infosec.exchange at 2026-09-09T00:32:06.000Z ##

A critical Hawtio Operator vulnerability, tracked as CVE-2026-78234, allows in-cluster service impersonation. Discover the impact and mitigation steps.

#HawtioOperator #CVE202678234 #Kubernetes #OpenShift #Vulnerability

securityonline.info/hawtio-ope

##

offseq@infosec.exchange at 2026-09-08T12:00:27.000Z ##

CRITICAL (CVSS 9.9): CVE-2026-78234 in Red Hat build of Apache Camel - HawtIO 4 allows users with edit access to mint Service-CA-signed certs, enabling service impersonation & RCE. Restrict HawtIO CR access, audit certs. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202678234 #RedHat

##

CVE-2026-50093
(9.0 None)

EPSS: 0.19%

updated 2026-09-08T09:35:45

1 posts

A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this

CVE-2026-62645
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-09-08T09:35:45

1 posts

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device.

offseq@infosec.exchange at 2026-09-08T10:30:24.000Z ##

CVE-2026-62645 (CRITICAL, CVSS 9.8) in Siemens Reyrolle 7SR5 <2.70 allows attackers to calculate session IDs and bypass authentication via web interface. Restrict access, check Siemens advisory for updates. radar.offseq.com/threat/cve-20 #OffSeq #ICS #Vuln #OTsec

##

CVE-2026-81790
(7.5 HIGH)

EPSS: 0.27%

updated 2026-09-08T09:35:45

1 posts

Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási címkék WooCommerce-hez: from n/a before 4.2.8.

thehackerwire@mastodon.social at 2026-09-08T09:00:40.000Z ##

🟠 CVE-2026-81790 - High (7.5)

Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Csomagpontok és szállítási címkék WooCom...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71374
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-09-08T09:35:44

1 posts

Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 0

thehackerwire@mastodon.social at 2026-09-08T09:00:50.000Z ##

🔴 CVE-2026-71374 - Critical (9.8)

Deserialization of untrusted data vulnerability in Cosminexus Component Container.

This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18963
(9.1 CRITICAL)

EPSS: 3.18%

updated 2026-09-08T09:17:43.063000

1 posts

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user

Nuclei template

14 repos

https://github.com/0xlyvio/CVE-2026-18963-keycloak

https://github.com/prot0tw/Keycloak_CVE-2026-18963_PoC

https://github.com/gman0x00/keycloak-CVE-2026-18963

https://github.com/ynsmroztas/KeySniper

https://github.com/T0w0T/POC-CVE-2026-18963

https://github.com/minh3102011/CVE-2026-18963_analyst

https://github.com/BlackHatExploitation/Exploit-For-CVE-2026-18963

https://github.com/EQSTLab/CVE-2026-18963

https://github.com/debugactiveprocess/CVE-2026-18963

https://github.com/Red-Darkin/CVE-2026-18963-keycloak

https://github.com/alt3kx/CVE-2026-18963

https://github.com/Snizi/CVE-2026-18963-Exploit

https://github.com/kyos-public/keycloak-cve-2026-18963-hunt

https://github.com/M4xSec/My-Exploits

CVE-2026-44756
(10.0 CRITICAL)

EPSS: 0.32%

updated 2026-09-08T03:31:21

6 posts

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availabil

guru@thecybersecguru.com at 2026-09-09T12:33:27.000Z ##

SAP OVERPASS CVE-2026-44756: CVSS 10.0 Kernel RCE Explained

SAP OVERPASS CVE-2026-44756 is a CVSS 10.0 kernel flaw enabling unauthenticated RCE. Learn the attack path, S4GET risks and patching steps

thecybersecguru.com/news/sap-o

##

jbhall56@infosec.exchange at 2026-09-09T12:29:39.000Z ##

The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP security company Onapsis, it has been codenamed OVERPASS. thehackernews.com/2026/09/sap-

##

security_crawler_carl@infosec.exchange at 2026-09-09T03:04:18.000Z ##

🏆 New Achievement! OVERPASS: The SAP Kernel Speedrun!

Patch compliance policy activated. Scanning enterprise environment. Detecting CVE-2026-44756, a CVSS 10/10 memory corruption flaw in SAP Extended Passport Processing, dubbed OVERPASS. Policy requires acknowledgment of impact: unauthenticated remote attackers may execute arbitrary system commands, drain database credentials and password hashes, hijack live user sessions, and rewrite configurations and SAP binaries. (1/2)

##

campuscodi@mastodon.social at 2026-09-08T14:33:21.000Z ##

OVERPASS is an unauth RCE in the SAP kernel (CVE-2026-44756) and S4GET is a preauth RCE in the SAP NetWeaver's Message Server (CVE-2026-58240).

Both have a very high CVSS and are likely to be exploited.

onapsis.com/blog/sap-overpass-

onapsis.com/blog/s4get-cve-202

##

DailyCyberSecurity@infosec.exchange at 2026-09-08T07:52:44.000Z ##

The September 2026 SAP Security Patch Day resolves 20 flaws. Apply these SAP Security Patch Day updates to fix CVE-2026-44756 and secure your environment.

#SAPSecurityPatchDay #CVE202644756 #SAPSecurity #CyberSecurity #Vulnerability

securityonline.info/september-

##

thehackerwire@mastodon.social at 2026-09-08T04:02:15.000Z ##

🔴 CVE-2026-44756 - Critical (10)

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resultin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19397(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-09-08T03:31:21

1 posts

Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the '  Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.

CVE-2026-66767
(7.7 HIGH)

EPSS: 0.26%

updated 2026-09-08T03:31:21

1 posts

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the applic

thehackerwire@mastodon.social at 2026-09-08T04:02:05.000Z ##

🟠 CVE-2026-66767 - High (7.7)

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86510
(9.9 CRITICAL)

EPSS: 0.46%

updated 2026-09-08T03:31:21

2 posts

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

offseq@infosec.exchange at 2026-09-08T03:00:24.000Z ##

D-Link DIR-822A routers are affected by CVE-2026-86510 (CRITICAL, CVSS 9.4): remote out-of-bounds write in L2TP parser can lead to system compromise. No patch yet — restrict access and monitor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202686510 #RouterSecurity #Infosec

##

thehackerwire@mastodon.social at 2026-09-08T02:59:56.000Z ##

🔴 CVE-2026-86510 - Critical (9.9)

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86509
(9.6 CRITICAL)

EPSS: 0.43%

updated 2026-09-08T03:31:21

2 posts

A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used.

thehackerwire@mastodon.social at 2026-09-08T02:00:36.000Z ##

🔴 CVE-2026-86509 - Critical (9.6)

A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-08T01:30:25.000Z ##

CVE-2026-86509 — CRITICAL stack-based buffer overflow in D-Link DIR-895L (A1_102b07), in udhcpcd’s sendOffer/sendACK. Exploit is public, local network access needed. Review segmentation and monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE202686509 #IoTSecurity

##

CVE-2026-76967
(7.8 HIGH)

EPSS: 0.22%

updated 2026-09-08T03:31:21

1 posts

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This res

thehackerwire@mastodon.social at 2026-09-08T02:00:16.000Z ##

🟠 CVE-2026-76967 - High (7.8)

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76958
(8.5 HIGH)

EPSS: 0.22%

updated 2026-09-08T03:31:13

1 posts

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging

thehackerwire@mastodon.social at 2026-09-08T03:00:06.000Z ##

🟠 CVE-2026-76958 - High (8.5)

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity dec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58240
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-09-08T03:31:11

2 posts

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confide

campuscodi@mastodon.social at 2026-09-08T14:33:21.000Z ##

OVERPASS is an unauth RCE in the SAP kernel (CVE-2026-44756) and S4GET is a preauth RCE in the SAP NetWeaver's Message Server (CVE-2026-58240).

Both have a very high CVSS and are likely to be exploited.

onapsis.com/blog/sap-overpass-

onapsis.com/blog/s4get-cve-202

##

thehackerwire@mastodon.social at 2026-09-08T04:01:55.000Z ##

🔴 CVE-2026-58240 - Critical (9.8)

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to regi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86541
(8.3 HIGH)

EPSS: 0.53%

updated 2026-09-08T00:30:33

1 posts

knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing directory traversal sequences to write malicious content to sensitive files like shell startup scripts or SSH configuration files.

thehackerwire@mastodon.social at 2026-09-08T01:01:18.000Z ##

🟠 CVE-2026-86541 - High (8.3)

knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86439
(8.8 HIGH)

EPSS: 0.75%

updated 2026-09-08T00:30:33

1 posts

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server process.

thehackerwire@mastodon.social at 2026-09-08T00:03:52.000Z ##

🟠 CVE-2026-86439 - High (8.8)

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86544
(8.1 HIGH)

EPSS: 0.31%

updated 2026-09-08T00:30:32

1 posts

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.

thehackerwire@mastodon.social at 2026-09-08T00:03:03.000Z ##

🟠 CVE-2026-86544 - High (8.1)

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission confi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86542
(9.1 CRITICAL)

EPSS: 0.47%

updated 2026-09-08T00:30:32

1 posts

knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files writable by the server process.

thehackerwire@mastodon.social at 2026-09-08T00:02:44.000Z ##

🔴 CVE-2026-86542 - Critical (9.1)

knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86504
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-07T18:31:43

1 posts

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

thehackerwire@mastodon.social at 2026-09-07T18:00:21.000Z ##

🟠 CVE-2026-86504 - High (7.8)

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86494
(7.7 HIGH)

EPSS: 0.17%

updated 2026-09-07T18:31:42

1 posts

In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues

thehackerwire@mastodon.social at 2026-09-07T18:01:07.000Z ##

🟠 CVE-2026-86494 - High (7.7)

In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86498
(7.7 HIGH)

EPSS: 0.17%

updated 2026-09-07T18:31:42

1 posts

In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

thehackerwire@mastodon.social at 2026-09-07T18:00:00.000Z ##

🟠 CVE-2026-86498 - High (7.7)

In JetBrains YouTrack before 2025.3.160480,
2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86482
(8.8 HIGH)

EPSS: 0.23%

updated 2026-09-07T18:31:36

1 posts

In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation

thehackerwire@mastodon.social at 2026-09-07T22:02:14.000Z ##

🟠 CVE-2026-86482 - High (8.8)

In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86478
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-09-07T18:31:36

1 posts

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

offseq@infosec.exchange at 2026-09-07T19:00:26.000Z ##

JetBrains YouTrack CRITICAL vulnerability (CVE-2026-86478, CVSS 9.8) in versions <2025.3.161254, <2026.1.14042: improper authentication enables unauthenticated account takeover. Patch status pending — check vendor advisory. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #CVE202686478

##

CVE-2026-86296
(10.0 CRITICAL)

EPSS: 1.35%

updated 2026-09-07T12:30:36

1 posts

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

offseq@infosec.exchange at 2026-09-07T22:00:11.000Z ##

CVE-2026-86296 | D-Link DIR-822A A_101: Critical stack-based buffer overflow in udhcpcd (CVSS 10). Remotely exploitable, no auth needed. Exploit code is public. Isolate devices & check vendor updates. radar.offseq.com/threat/a-vuln #OffSeq #Vulnerability #DLink #Security

##

CVE-2026-85046
(8.8 HIGH)

EPSS: 1.43%

updated 2026-09-06T03:30:24

2 posts

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

6 repos

https://github.com/atiilla/CVE-2026-85046

https://github.com/adriyansyah-mf/cve-2026-85046-poc

https://github.com/HORKimhab/CVE-2026-85046

https://github.com/Eliot-code/CVE-2026-85046

https://github.com/SneakyNachos/CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm

https://github.com/ubitquity/CVE-2026-85046-Patch-confusion-zero-day-vulnerability-in-Google-Chrome-s-V8-engine

hackmag@infosec.exchange at 2026-09-08T15:30:09.000Z ##

⚪️ Chrome fixes sixth zero-day vulnerability this year

🗨️ Google developers have released an update for the Chrome browser that fixes 12 vulnerabilities, including an actively exploited zero-day flaw in the V8 engine (CVE-2026-85046). The bug allows attackers to achieve arbitrary code execution through a specially crafted HTML page.…

🔗 hackmag.com/news/cve-2026-8504

#news

##

cR0w@infosec.exchange at 2026-09-08T14:07:59.000Z ##

@ajn142 I'm pretty sure the Chromium version is 152.0.7977.82-1.

security-tracker.debian.org/tr

I don't have a Chromium login to check the issue itself:

issues.chromium.org/issues/542

##

CVE-2026-86207(CVSS UNKNOWN)

EPSS: 0.73%

updated 2026-09-05T21:31:20

1 posts

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

Nuclei template

CVE-2026-67277(CVSS UNKNOWN)

EPSS: 0.43%

updated 2026-09-05T21:31:20

1 posts

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragment

threatnoir@infosec.exchange at 2026-09-07T23:05:52.000Z ##

⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers

Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-86060(CVSS UNKNOWN)

EPSS: 0.40%

updated 2026-09-05T21:31:20

2 posts

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable

threatnoir@infosec.exchange at 2026-09-07T23:05:52.000Z ##

⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers

Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

netsecio@mastodon.social at 2026-09-07T17:33:21.000Z ##

📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit

🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity

🔗 cyber.netsecops.io/articles/mi

##

CVE-2026-86090
(7.1 HIGH)

EPSS: 0.25%

updated 2026-09-04T22:17:18.840000

1 posts

ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.

hugovalters@mastodon.social at 2026-09-10T03:30:03.000Z ##

CVE-2026-86090: ntopng auth bypass lets non-admin users delete all alert endpoints, silencing critical notifications. CVSS 7.1. No patch yet. Audit your instance now. Details: valtersit.com/cve/CVE-2026-860 #CVE #infosec #ntopng

##

CVE-2026-75754(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-09-04T03:31:07

1 posts

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of

sekurakbot@mastodon.com.pl at 2026-09-09T10:26:00.000Z ##

RCE z uprawnieniami roota. Krytyczna podatność (CVSS 10.0) w ASUS Control Center Enterprise

Firma ASUS w najnowszym biuletynie bezpieczeństwa poinformowała o wykryciu krytycznej luki w popularnym oprogramowaniu ASUS Control Center Enterprise (ACC). Podatność oznaczona identyfikatorem CVE-2026-75754 otrzymała maksymalną ocenę 10.0 w skali CVSS 4.0. TLDR: Świadczy to o tym, że potencjalny atakujący może w łatwy sposób, całkowicie zdalnie oraz bez konieczności jakiejkolwiek interakcji...

#WBiegu #Asus #ControlCenter #Cve #Rce

sekurak.pl/rce-z-uprawnieniami

##

CVE-2023-54391
(9.8 CRITICAL)

EPSS: 1.75%

updated 2026-09-03T15:33:10

1 posts

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with a

2 repos

https://github.com/disqualifier/psa-2026-00043-recovery

https://github.com/neeythann/Proxmox-VE-7-RCE

CVE-2026-20212
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-03T13:04:38.177000

1 posts

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device an

1 repos

https://github.com/HORKimhab/CVE-2026-20212

sekurakbot@mastodon.com.pl at 2026-09-09T10:26:00.000Z ##

Krytyczna luka w przełącznikach Cisco Nexus 9000 [CVE-2026-20212]. RCE bez uwierzytelnienia i dostęp do roota

Firma Cisco opublikowała biuletyn bezpieczeństwa opisujący krytyczną lukę w przełącznikach Nexus serii 9000 opartych na układach Silicon One. Podatność została oznaczona jako CVE-2026-20212 i oceniona na 9.8 (Critical) w skali CVSS v3.1. Umożliwia nieuwierzytelnionemu użytkownikowi zdalne wykonanie kodu z uprawnieniami roota. Poprawki bezpieczeństwa są już dostępne, zalecamy niezwłoczną aktualizację oprogramowania. ...

#WBiegu #Cisco #Cve #Nexus #Rce #Switch

sekurak.pl/krytyczna-luka-w-pr

##

CVE-2026-20354
(5.9 MEDIUM)

EPSS: 0.15%

updated 2026-09-02T19:23:13.660000

1 posts

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle tec

AAKL@infosec.exchange at 2026-09-08T16:42:45.000Z ##

New advisories from Cisco addressing two high and medium-severity vulnerabilities.

New: CVE-2026-20293: Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability sec.cloudapps.cisco.com/securi

Known: CVE-2026-20354 and CVE-2026-20355: Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2026-20355
(5.9 MEDIUM)

EPSS: 0.15%

updated 2026-09-02T18:32:32

1 posts

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle techn

AAKL@infosec.exchange at 2026-09-08T16:42:45.000Z ##

New advisories from Cisco addressing two high and medium-severity vulnerabilities.

New: CVE-2026-20293: Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability sec.cloudapps.cisco.com/securi

Known: CVE-2026-20354 and CVE-2026-20355: Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2026-62911
(8.0 HIGH)

EPSS: 1.32%

updated 2026-09-02T04:18:00.460000

1 posts

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/hypnguyen1209/CVE-2026-62911

youranonnewsirc@nerdculture.de at 2026-09-07T22:26:24.000Z ##

A critical Microsoft Exchange vulnerability (CVE-2026-62911) leaves thousands of servers unpatched, while AI-assisted ransomware now compromises networks in under 10 hours. OpenAI released GPT-6 Astra, advancing Artificial General Intelligence. Geopolitically, Ukrainian drones struck Russia's Taganrog airbase overnight (Sept 6-7).

#Cybersecurity #TechNews #Geopolitics

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 1.69%

updated 2026-09-01T04:18:02.160000

2 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

AAKL@infosec.exchange at 2026-09-09T16:37:11.000Z ##

Which is to say, a real person directed this nonsense.

"On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078)."

GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF greynoise.io/blog/ai-orchestra @greynoise #infosec #cyberattack #bot

##

guru@thecybersecguru.com at 2026-09-09T15:35:45.000Z ##

The AI swarm that breached 440 PaperCut servers worldwide

GreyNoise uncovered an AI-driven PaperCut attack that compromised 440 servers across 395 organizations in 48 countries using CVE-2026-81578 and CVE-2026-82078

thecybersecguru.com/news/ai-sw

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 1.62%

updated 2026-08-31T21:31:56

2 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

AAKL@infosec.exchange at 2026-09-09T16:37:11.000Z ##

Which is to say, a real person directed this nonsense.

"On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078)."

GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF greynoise.io/blog/ai-orchestra @greynoise #infosec #cyberattack #bot

##

guru@thecybersecguru.com at 2026-09-09T15:35:45.000Z ##

The AI swarm that breached 440 PaperCut servers worldwide

GreyNoise uncovered an AI-driven PaperCut attack that compromised 440 servers across 395 organizations in 48 countries using CVE-2026-81578 and CVE-2026-82078

thecybersecguru.com/news/ai-sw

##

CVE-2026-77234
(8.8 HIGH)

EPSS: 0.12%

updated 2026-08-27T20:18:39.130000

1 posts

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:01.000Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-77237
(6.5 MEDIUM)

EPSS: 0.13%

updated 2026-08-25T16:44:12.343000

1 posts

Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory. To remediate this issue, users should upgrade to version 11.3.1 or later.

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:01.000Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-69836
(10.0 CRITICAL)

EPSS: 1.55%

updated 2026-08-21T00:31:31

1 posts

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/sentinel-aidefense/CVE-2026-69836-EXP

https://github.com/HORKimhab/CVE-2026-69836

adulau@infosec.exchange at 2026-09-09T14:43:49.000Z ##

The @gcve BCP-07 KEV format has been updated to allow the Withdrawn and Reasserted KEV Assertions.

This allows to support case like CVE-2026-69836 .

🔗 gcve.eu/bcp/gcve-bcp-07/#withd

#cve #gcve #kev #cybersecurity #vulnerabilitymanagement #vulnerability

##

CVE-2026-75936
(7.5 HIGH)

EPSS: 0.44%

updated 2026-08-20T13:01:19.947000

1 posts

Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression. To remediate this issue, users should upgrade to version 1.12.0 and configure withGzipDecompressionEnabled(false) and/or set a

hugovalters@mastodon.social at 2026-09-10T02:40:38.000Z ##

CVE-2026-85786: DoS via crafted compressed Ion data in Amazon ion-java <1.12.1. Expansion bomb bypasses GZIP opt-out (CVE-2026-75936). CVSS 7.5. Update to 1.12.1 now. valtersit.com/cve/CVE-2026-857 #CVE #infosec #AWS

##

CVE-2026-69414
(7.8 HIGH)

EPSS: 0.56%

updated 2026-08-19T18:32:28

2 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

2 repos

https://github.com/HORKimhab/CVE-2026-50656

https://github.com/1neptune/ShieldBreak

cyberworldops@infosec.exchange at 2026-09-09T12:50:00.000Z ##

Chaotic Eclipse released ShieldCrash PoC, described as a patch bypass for CVE-2026-69414 ShieldBreak in Microsoft Malware Protection Engine. If valid, Defender privilege escalation remains exploitable despite the official fix, requiring re-validation of mitigations. #ShieldBreak #MicrosoftDefender #PatchBypass

cyberworldops.eu/en/microsoft-

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T00:35:56.000Z ##

A Windows Defender 0day has public PoC exploit code. ShieldCrash reads files as SYSTEM on all supported Windows versions.

#WindowsDefender #0day #CVE #ShieldCrash #CyberSecurity #Windows #PoC #Infosec

securityonline.info/windows-de

##

CVE-2026-19311
(8.1 HIGH)

EPSS: 0.41%

updated 2026-08-13T15:19:38.027000

1 posts

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:02.000Z ##

CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin

Bulletin ID: 2026-078-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:30 AM PDT
Description:
OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-68820
(7.0 None)

EPSS: 6.18%

updated 2026-08-11T21:33:01

1 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

4 repos

https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation

https://github.com/maxprog-svg/CVE-2026-68820_Mass_Exploit

https://github.com/HORKimhab/CVE-2026-68820

https://github.com/fevar54/CVE-2026-68820-Mitigation-PoC-

cyberworldops@infosec.exchange at 2026-09-09T10:30:00.000Z ##

Microsoft patched 398 vulnerabilities, 42 rated Critical. CVE-2026-68820 in afd.sys is actively exploited and added to CISA KEV, enabling local privilege escalation to SYSTEM. Prioritize Kernel and RCE flaws in this cycle. #PatchTuesday #WindowsSecurity #CisaKev

cyberworldops.eu/en/microsoft-

##

CVE-2026-62735
(7.8 HIGH)

EPSS: 0.48%

updated 2026-08-11T18:31:23

1 posts

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/nhh9905/CVE-2026-62735

https://github.com/HackSpeak/CVE-2026-62735

CVE-2025-14733
(9.8 CRITICAL)

EPSS: 26.51%

updated 2026-08-10T21:33:00

1 posts

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.5 and

1 repos

https://github.com/machevalia/CVE-2025-14733

kev_Stalker@infosec.exchange at 2026-09-09T11:19:35.000Z ##

CVE-2025-14733 - Changed to Known Ransomware Status

WatchGuard Firebox Out of Bounds Write VulnerabilityVendor: WatchGuardProduct: FireboxWatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-13230
(6.5 MEDIUM)

EPSS: 0.38%

updated 2026-08-06T18:21:08.780000

1 posts

An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses. The vulnerability impacts confidentiality only, with no evidence of inte

BadChemical@infosec.exchange at 2026-09-08T01:07:25.000Z ##

@ohunt I can't speak to the CFAA since I'm no lawyer. Exploitation in this exact scenario isn't a valid classifier either since the underlying vuln of CVE-2026-13230 is a lack of meaningful protection, it equates to intercepting HTTP at this point. Ask and receive. However the protocol that operates on UDP 9999 has been broken for about 10 years now and has an RCE vuln on a different device class.

##

CVE-2026-20316
(5.3 MEDIUM)

EPSS: 9.82%

updated 2026-07-29T21:31:00

1 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vuln

DailyCyberSecurity@infosec.exchange at 2026-09-09T16:28:31.000Z ##

Cisco Talos warns of Cisco FMC vulnerabilities actively exploited in the wild. Attackers chain CVE-2026-20079 and CVE-2026-20316 to deploy ransomware.

#CiscoFMC #Cybersecurity #CVE202620079 #Ransomware #InfoSec

securityonline.info/cisco-fmc-

##

CVE-2026-43502
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-23T16:10:00.137000

2 posts

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the sending socket. The purge path currently infers zerocopy state from rm->m_rs, so an unqueued message can be cleaned up as if it owned normal payload pages. Howev

1 repos

https://github.com/suominen/pintheft

jschauma@mstdn.social at 2026-09-08T13:11:10.000Z ##

Feels like a Monday when you open the inbox and see "Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more".

openwall.com/lists/oss-securit

Various exploits/PoCs here:
github.com/NebuSec/CyberMeowfi

While I don't know how widespread the use of RDS is, it's the "and 20 more" that kills me. Pretty much assuming shell access == root access at this point.

##

DailyCyberSecurity@infosec.exchange at 2026-09-08T04:43:58.000Z ##

The details and PoC exploit code for the ZcopyReaper Linux vulnerability (CVE-2026-43502) are publicly disclosed, posing a privilege escalation risk.

#ZcopyReaper #CVE202643502 #LinuxKernel #CyberSecurity #PrivilegeEscalation

securityonline.info/zcopyreape

##

CVE-2026-8461
(8.8 HIGH)

EPSS: 1.57%

updated 2026-07-23T12:32:53

1 posts

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.

4 repos

https://github.com/Y5neKO/CVE-2026-8461-EXP

https://github.com/anyanything/CVE-2026-8461-PoC

https://github.com/0xBlackash/CVE-2026-8461

https://github.com/HORKimhab/CVE-2026-8461

CVE-2026-8510
(7.5 HIGH)

EPSS: 0.21%

updated 2026-06-17T11:04:00.860000

1 posts

Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

daniel1820815@infosec.exchange at 2026-09-09T20:10:44.000Z ##

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

community.checkpoint.com/t5/Ge

#CheckPoint #CheckPointSoftwareTechnologies #VPN #vulnerability

##

CVE-2022-1096
(8.8 HIGH)

EPSS: 24.39%

updated 2026-06-17T04:21:49.070000

1 posts

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

1 repos

https://github.com/Mav3r1ck0x1/Chrome-and-Edge-Version-Dumper

lacze@infosec.exchange at 2026-09-07T16:51:41.000Z ##

RE: mastodon.online/@rozie/1172242

Eteryu stara się przedstawić swoje tezy jako wynik rzetelnej analizy, jego tekst zawiera elementy dezinformacji, wybiórcze traktowanie faktów oraz jednostronne podejście do omawianych kwestii.

Jak na moje oko, Baza wiedzy Eteryu space – jest jedynie kopią, niestety mocno okrojoną i uproszczoną. Szczegóły w dalszej częśći tekstu, wraz ze zródłami oraz zrzutami ekranu.

🧵 1/2

Baza Wiedzy Eteryu

PODWÓJNE STANDARDY W OCENIE CHROME I BRAVE
Eteryu twierdzi, że Chrome na PC jest ‘czystszym wyborem’ dzięki izolacji procesów, ale celowo bagatelizuje ryzyko związane z telemetrią Chrome.
Błędne założenie o izolacji procesów
Chrome oferuje ‘niezrównaną izolację procesów’, w rzeczywistości wiele przeglądarek opartych na Chromium stosuje identyczne mechanizmy, takie jak: Site Isolation (izolacja stron w osobnych procesach), Process-per-site-instance (osobny proces dla każdej instancji strony). Różnice w izolacji wynikają głównie z ustawień domyślnych (np. Chrome domyślnie włącza Site Isolation, podczas gdy niektóre forki wymagają ręcznej konfiguracji). Przedstawia Chrome jako wyjątkowego lidera, podczas gdy w praktyce wiele przegląddek Chromium osiąga podobnypoziom bezpieczeństwa.
Niespójność w ocenie
Brave jest ‘wysoce zalecany’ na Androidzie ze względu na możliwość wyłączenia JIT w V8, co rzekomo ‘amputuje główny wektor ataków’. To prawda, ale częściowa. Wyłączenie JIT nie jest unikalne dla Brave , każdy użytkownik Chromium może to zrobić ręcznie (np. poprzez flagi –disable-jit). JIT nie jest jedynym wektorem ataków, luki w V8 (np. CVE-2022-1096) były wykorzystywane w atakach nawet z wyłączonym JIT. Eteryu przedstawia rozwiązanie jako panaceum, podczas gdy realne bezpieczeństwo wymaga szerszego podejścia. Brave jest dobrą opcją, ale nie ze względu na ‘wyłączanie JIT’, a raczej dzięki blokowaniu reklam, trackerów i lepszej ochronie prywatności. Tak, “zbędne” funkcje w Brave (jak moduły krypto czy AI) można ręcznie wyłączyć, celowo pomijane, by przedstawić przeglądarkę jako “skomplikowaną”. W rzeczywistości Brave jest bardziej konfigurowalny niż Chrome dzięki lepszej obsłudze rozszerzeń i flag.

AKTUALIZACJE
Chrome jako ‘upstream’ otrzymuje łatki krytyczne ‘natychmiast’, podczas gdy forki muszą je synchronizować. To półprawda. Chrome nie jest jedynym projektem upstream: Chromium (na którym bazuje Chrome) jest open source i wszystkie przeglądarki oparte na Chromium otrzymują łatki w tym samym czasie. Różnice wynikają jedynie z czasu potrzebnego na kompilację i testowanie własnych modyfikacji.

NAJWIĘKSZY PROBLEM TKWI W IGNOROWANIU REALNYCH ALTERNATYW NA DESKTOPIE.
Chrome jest “zawsze lepszy”, ale: Edge (również Chromium) ma lepszą integrację z Windows (ochrona przed phishingiem, lepsze zarządzanie pamięcią) i jest domyślnie instalowany na wielu maszynach.
Przeglądarka Edge zdobyła nawet uznanie wśród autorów treści, którymi Eteryu zdaje się posiłkować. Można tam przeczytać że przeglądarka Edge na Windows, oferuje większe bezpieczeństwo od Chrome i nawet stawia się ją obok przeglądarek Vanadium (GrapheneOS), oraz Trivalent (Secureblue) jednak zwraca się uwagę na problemem z telemetrią.
Safari na MacOS oferuje lepszą izolację procesów niż Chrome dzięki głębszej integracji z systemem i
mniejsze ryzyko zero-day (mniejsza baza użytkowników = mniej celów dla ataków).
Czy Eteryu celowo pomija te przeglądarki, by promować Chrome? Choć Edge i Safari są technicznie lepsze w swoich ekosystemach. Jak widać jest to wybiórcza, analiza skupia się na jednym ignorując szerszy kontekst bezpieczeństwa i wydajności.
Podsumowując: To nie jest “ścisła analiza”, tylko subiektywna ocena oparta na preferencjach. Dla prawdziwie bezpiecznej przeglądarki na desktopie lepszym wyborem byłoby Edge (Windows), Safari (Mac). Brave często cenony jest za blokowanie reklam i trackerów.

Linux
Rzeczywistość jest bardziej złożona:

Więcej poniżej👇

##

CVE-2021-35464
(9.8 CRITICAL)

EPSS: 100.00%

updated 2025-10-22T00:32:19

1 posts

ForgeRock AM server 6.x before 7, and OpenAM 14.6.3, has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/Version request to the server. The vulnerability exists due to incorrect usage of Sun ONE Application Framework (JATO).

Nuclei template

2 repos

https://github.com/Y4er/openam-CVE-2021-35464

https://github.com/rood8008/CVE-2021-35464

pentesttools@infosec.exchange at 2026-09-08T15:00:12.000Z ##

Last month we made a bit of history, and for once it wasn't a CVE. We were the first Romanian company ever to have a booth at DEF CON, showing AI Pentests, powered by Specter, to a room full of people whose entire job is finding what's wrong with things. Still in beta, early access is open now.

What else happened in August, you asked?

🎯 Sniper added a new exploit for CVE-2021-35464, a five-year-old RCE in Forgerock OpenAM that's still alive in the wild. As always, if Sniper can exploit it, the Network Scanner can detect it.
🌐 155 new detections in the Network Scanner, 70 of them critical, prioritized by CVSS, EPSS, and CISA KEV.
🤖 AI is picking up more of the boring work: the Password Auditor now finds stubborn login forms on its own, and Ping, our AI-based assistant moved from the website straight into the product.
🔌 The findings API can now update risk and verified status, findings carry a ransomware-campaign flag straight from CISA, and you can create your account in the US region if data residency matters to you.

Full breakdown in the video: pentest-tools.com/change-log
Early access to AI Pentests: pentest-tools.com/discover-ai-

Until next time: stay sharp, stay human.

#offensivesecurity #penetrationtesting

##

CVE-2025-2524
(4.8 MEDIUM)

EPSS: 0.30%

updated 2025-06-17T21:31:59

1 posts

The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11015
(9.8 CRITICAL)

EPSS: 0.78%

updated 2024-12-12T06:30:56

1 posts

The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.8.0. This is due to the 'authenticate_user' user function not implementing sufficient null value checks when setting the access token and user information. This makes it possible for unauthenticated attackers to log in as the first user who has signed in using Google OAuth, w

wpguyuk@infosec.exchange at 2026-09-08T07:04:22.000Z ##

If you are running All-in-One WP Migration and Backup — over 5 million sites do — you need to check your version now. CVE-2024-11015 allows full admin takeover with no credentials required. That is about as serious as it gets. My advice: patch immediately and audit your user accounts.

#WordPress #WebSecurity #SecurityHardening #WordPressPlugin #CyberSecurity

wpguy.uk/blog/critical-wordpre

##

CVE-2026-67593
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-09-10T02:55:57.475Z ##

Critical Apache Artemis vulnerabilities, including CVE-2026-67593 and other ActiveMQ Artemis flaws, expose systems to denial of service and data exposure.

securityonline.info/apache-art

##

DailyCyberSecurity@infosec.exchange at 2026-09-10T02:55:57.000Z ##

Critical Apache Artemis vulnerabilities, including CVE-2026-67593 and other ActiveMQ Artemis flaws, expose systems to denial of service and data exposure.

#ApacheArtemis #Cybersecurity #Vulnerabilities #ActiveMQ #CVE202667593

securityonline.info/apache-art

##

CVE-2026-87016
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-09T23:00:46.000Z ##

🟠 CVE-2026-87016 - High (8.1)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-09T23:00:46.000Z ##

🟠 CVE-2026-87016 - High (8.1)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87996
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-09T23:00:35.000Z ##

🟠 CVE-2026-87996 - High (7.7)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Pla...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-09T23:00:35.000Z ##

🟠 CVE-2026-87996 - High (7.7)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Pla...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87995
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-09T23:00:25.000Z ##

🟠 CVE-2026-87995 - High (8.7)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-scripts an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-09T23:00:25.000Z ##

🟠 CVE-2026-87995 - High (8.7)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-scripts an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87011
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-09T21:59:49.000Z ##

🟠 CVE-2026-87011 - High (7.5)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery document and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-09T21:59:49.000Z ##

🟠 CVE-2026-87011 - High (7.5)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery document and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85012
(0 None)

EPSS: 1.06%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:02.000Z ##

CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK

Bulletin ID: 2026-095-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 10:00 AM PDT
Description:
Amazon CodeCatalyst blueprints are reusable project templates that generate a software proj...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-77235
(0 None)

EPSS: 0.11%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:01.000Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-77236
(0 None)

EPSS: 0.11%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:01.000Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-54694
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-09T20:00:26.000Z ##

🔴 CVE-2026-54694 - Critical (9.6)

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-0310
(0 None)

EPSS: 0.00%

4 posts

N/A

cR0w@infosec.exchange at 2026-09-09T17:10:22.000Z ##

RE: infosec.exchange/@cR0w/1172419

Seriously, maybe take a good look at CVE-2026-0310.

CVSS-BT: 7.2 / **CVSS-B: 9.2** (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red)

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T17:06:44.000Z ##

A new PAN-OS buffer overflow flaw, tracked as CVE-2026-0310, exposes firewalls to remote code execution. Patch your network devices immediately.

#PANOS #BufferOverflow #CVE20260310 #Cybersecurity #PaloAltoNetworks

securityonline.info/pan-os-buf

##

cR0w@infosec.exchange at 2026-09-09T16:12:33.000Z ##

RE: infosec.exchange/@cR0w/1172369

lol. lmao even.

security.paloaltonetworks.com/

security.paloaltonetworks.com/

##

AAKL@infosec.exchange at 2026-09-09T16:10:40.000Z ##

Broadcom has a long list of advisories today for high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom #Linux

Palo Alto:

Palo Alto has several advisories, one of them critical:

CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing security.paloaltonetworks.com/

More: security.paloaltonetworks.com/

Cisco:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

Dell:

A Dell release that impacts multiple CVEs: Security Update for Dell PowerScale OneFS Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell

Posted yesterday:

Apple:

Several releases were posted yesterday support.apple.com/en-us/100100 #Apple #iOS

AMD:

AMD: Linux GPU Driver NULL Pointer Dereference amd.com/en/resources/product-s #AMD

Adobe:

Adobe has a long list of updates here helpx.adobe.com/security/secur #Adobe #infosec #vulnerability

@cR0w

##

CVE-2026-0307
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-85982
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-09T03:00:08.000Z ##

🔴 CVE-2026-85982 - Critical (9)

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify dir...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85083
(0 None)

EPSS: 0.00%

1 posts

N/A

cyberworldops@infosec.exchange at 2026-09-09T01:30:00.000Z ##

CISA advisory ICSA-26-251-01 documents CVE-2026-85083 in CareCam Pro ANJIA AJL33PC0801: hard-coded bootloader credential allows privileged access with physical presence. It enables firmware modification and persistent compromise, undermining trust in affected deployments. #HardcodedCredentials #IotSecurity #FirmwareSecurity

cyberworldops.eu/en/hard-coded

##

CVE-2026-53939
(0 None)

EPSS: 0.20%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-09T01:00:19.000Z ##

🔴 CVE-2026-53939 - Critical (9.1)

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84390
(0 None)

EPSS: 0.00%

1 posts

N/A

hackmag@infosec.exchange at 2026-09-08T15:30:09.000Z ##

⚪️ Chrome fixes sixth zero-day vulnerability this year

🗨️ Google developers have released an update for the Chrome browser that fixes 12 vulnerabilities, including an actively exploited zero-day flaw in the V8 engine (CVE-2026-85046). The bug allows attackers to achieve arbitrary code execution through a specially crafted HTML page.…

🔗 hackmag.com/news/cve-2026-8504

#news

##

Visit counter For Websites