## Updated at UTC 2026-07-25T19:50:33.452078

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-16766 0 0.67% 2 0 2026-07-25T19:16:51.987000 Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command i
CVE-2026-64374 None 0.22% 1 0 2026-07-25T12:31:39 In the Linux kernel, the following vulnerability has been resolved: sched/rt: H
CVE-2026-64324 None 0.21% 1 0 2026-07-25T12:31:38 In the Linux kernel, the following vulnerability has been resolved: udf: valida
CVE-2026-66012 10.0 0.00% 4 0 2026-07-25T11:17:19.053000 SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST
CVE-2026-64415 0 0.21% 1 0 2026-07-25T10:17:25.343000 In the Linux kernel, the following vulnerability has been resolved: mm/swap: ad
CVE-2026-64399 0 0.21% 1 0 2026-07-25T10:17:23.397000 In the Linux kernel, the following vulnerability has been resolved: ksmbd: add
CVE-2026-64368 0 0.21% 1 0 2026-07-25T10:17:19.613000 In the Linux kernel, the following vulnerability has been resolved: mm/slab: do
CVE-2026-64337 0 0.22% 1 0 2026-07-25T10:17:15.590000 In the Linux kernel, the following vulnerability has been resolved: usb: mtu3:
CVE-2026-64263 0 0.21% 1 0 2026-07-25T10:17:06.460000 In the Linux kernel, the following vulnerability has been resolved: fuse-uring:
CVE-2026-10818 8.1 0.42% 4 0 2026-07-25T07:17:08.880000 The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in a
CVE-2026-66035 7.5 0.32% 1 0 2026-07-25T05:16:42.900000 libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication h
CVE-2026-66034 7.5 0.25% 1 0 2026-07-25T05:16:42.773000 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check
CVE-2026-66032 8.8 0.29% 1 0 2026-07-25T05:16:42.643000 libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerab
CVE-2026-56163 10.0 0.92% 3 0 2026-07-25T05:16:35.420000 Missing authentication for critical function in Microsoft Azure Kubernetes Servi
CVE-2026-66374 8.1 0.39% 2 1 2026-07-25T03:30:55 Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer
CVE-2026-66373 7.5 0.47% 2 0 2026-07-25T01:16:26.277000 Redis before 8.8.0, in the unusual case where an authenticated attacker can exec
CVE-2026-60134 8.8 0.32% 1 0 2026-07-25T00:31:53 Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elev
CVE-2025-71408 7.8 0.16% 1 0 2026-07-25T00:31:53 NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection
CVE-2026-61892 8.8 0.27% 1 0 2026-07-24T23:16:51.333000 Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate p
CVE-2026-61884 9.8 0.66% 4 0 2026-07-24T22:16:50.963000 The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perf
CVE-2026-14603 7.5 0.24% 2 0 2026-07-24T21:33:30 The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have
CVE-2026-45815 7.5 0.37% 2 0 2026-07-24T21:33:30 Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read
CVE-2026-45813 8.8 0.27% 2 0 2026-07-24T21:33:30 Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apa
CVE-2026-66143 7.5 0.33% 2 0 2026-07-24T21:33:30 It is possible to bypass the maximum number of normalized policy alternatives th
CVE-2026-12981 7.5 0.30% 3 0 2026-07-24T21:33:29 The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication
CVE-2026-66142 7.5 0.33% 2 0 2026-07-24T21:33:29 Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that
CVE-2026-62835 9.3 1.03% 4 0 2026-07-24T21:32:28 Improper authorization in Azure Portal allows an unauthorized attacker to disclo
CVE-2026-66039 8.8 0.42% 1 0 2026-07-24T21:32:28 FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflo
CVE-2026-66041 8.8 0.42% 1 0 2026-07-24T21:32:28 FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds
CVE-2026-17107 8.5 0.23% 1 0 2026-07-24T21:32:28 A flaw was found in the cluster-proxy service-proxy component used in Red Hat Ad
CVE-2026-12877 9.1 0.24% 2 0 2026-07-24T20:48:39.923000 The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5
CVE-2026-12497 7.5 0.23% 2 0 2026-07-24T20:48:39.923000 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
CVE-2026-56167 8.5 0.38% 2 0 2026-07-24T20:48:18.380000 Server-side request forgery (ssrf) in Azure AI Search allows an authorized attac
CVE-2026-16804 8.3 0.29% 2 0 2026-07-24T20:47:41.790000 Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remot
CVE-2026-45811 7.5 0.25% 2 0 2026-07-24T20:47:41.790000 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerabi
CVE-2026-45816 7.5 0.38% 2 0 2026-07-24T20:47:41.790000 NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Requ
CVE-2026-66144 7.5 0.33% 2 0 2026-07-24T20:47:41.790000 Although remote policy references are not retrieved during policy normalization,
CVE-2026-8789 8.1 0.22% 1 0 2026-07-24T20:45:45.697000 The Easy Appointments plugin for WordPress is vulnerable to unauthorized modific
CVE-2026-66040 8.8 0.55% 1 0 2026-07-24T20:18:21.063000 FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds wri
CVE-2026-66036 8.8 0.29% 1 0 2026-07-24T20:18:20.433000 FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds wri
CVE-2026-49745 7.8 0.11% 2 0 2026-07-24T18:32:33 Kernel software installed and running inside a Guest VM may post improper comman
CVE-2026-49743 7.8 0.11% 2 0 2026-07-24T18:32:33 Software installed and run as a non-privileged user may conduct improper GPU sys
CVE-2026-49744 7.8 0.11% 2 0 2026-07-24T18:32:32 Kernel software installed and running inside a Guest VM may post improper comman
CVE-2026-16801 8.8 0.29% 2 0 2026-07-24T18:32:32 Improper control of generation of code ('Code Injection') in the variables featu
CVE-2026-65709 8.3 0.22% 1 0 2026-07-24T18:31:41 sysPass through version 3.2.11 contains a missing object-level authorization vul
CVE-2026-66033 7.5 0.39% 1 0 2026-07-24T18:31:41 libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication i
CVE-2026-65708 8.1 0.22% 1 0 2026-07-24T18:31:37 sysPass through version 3.2.11 contains an insecure direct object reference vuln
CVE-2026-66027 8.3 0.26% 1 0 2026-07-24T18:31:37 Suna before 0.9.102 contains a broken access control vulnerability in the messag
CVE-2026-16870 8.8 0.36% 1 0 2026-07-24T18:16:52.770000 Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior
CVE-2026-16800 8.8 0.29% 2 0 2026-07-24T18:16:52.303000 Improper control of generation of code ('Code Injection') in the schedule featur
CVE-2026-16807 8.8 0.29% 2 0 2026-07-24T15:34:00 Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a
CVE-2026-16806 8.8 0.43% 2 0 2026-07-24T15:34:00 Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remo
CVE-2026-16805 8.8 0.34% 2 0 2026-07-24T15:34:00 Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remot
CVE-2026-64600 None 0.72% 7 3 2026-07-24T15:34:00 In the Linux kernel, the following vulnerability has been resolved: xfs: resamp
CVE-2026-58630 10.0 0.81% 4 0 2026-07-24T15:33:09 Improper access control in Azure App Service allows an unauthorized attacker to
CVE-2026-57106 10.0 0.92% 3 0 2026-07-24T15:33:03 Server-side request forgery (ssrf) in Data Quality allows an unauthorized attack
CVE-2026-12503 0 0.14% 2 0 2026-07-24T15:17:10.997000 Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-
CVE-2026-24727 0 0.67% 1 0 2026-07-24T13:17:34.217000 An unrestricted upload of file with dangerous type vulnerability in the e-paper
CVE-2026-14172 7.8 0.11% 1 0 2026-07-24T09:32:22 Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables
CVE-2026-15704 9.8 0.35% 2 0 2026-07-24T09:32:16 In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled
CVE-2026-66140 8.4 0.27% 2 0 2026-07-24T06:34:11 Exim before 4.99.5 allows directory traversal to access files outside of the spo
CVE-2026-35425 8.0 0.48% 2 0 2026-07-24T03:32:01 Improper access control in Azure API Management (APIM) allows an authorized atta
CVE-2026-54120 9.9 0.71% 3 0 2026-07-24T03:31:56 Improper input validation in Microsoft Surface allows an authorized attacker to
CVE-2026-56160 9.1 0.65% 1 0 2026-07-24T03:31:56 Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized att
CVE-2026-50517 9.9 1.25% 2 0 2026-07-24T03:31:55 Deserialization of untrusted data in M365 Copilot allows an authorized attacker
CVE-2026-16232 9.1 12.68% 4 1 2026-07-23T15:44:54.743000 An authentication bypass vulnerability in the Check Point SmartConsole login pro
CVE-2026-50522 9.8 57.10% 4 2 2026-07-23T15:44:10.873000 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-16723 9.0 0.41% 5 1 2026-07-23T15:01:24.377000 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.
CVE-2026-25089 9.8 69.83% 2 2 2026-07-23T08:10:00.137000 A improper neutralization of special elements used in an os command ('os command
CVE-2026-53359 8.8 0.91% 3 6 2026-07-22T21:31:50 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F
CVE-2026-50454 7.8 0.44% 1 0 2026-07-22T16:17:58.990000 Relative path traversal in Windows User Interface Core allows an authorized atta
CVE-2026-49176 7.8 0.40% 2 1 2026-07-22T16:17:28.753000 Improper privilege management in Windows WalletService allows an authorized atta
CVE-2026-60137 5.9 77.97% 1 41 2026-07-22T05:17:11.750000 WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does no
CVE-2026-8933 7.8 0.18% 2 0 2026-07-21T15:30:51 A local privilege escalation vulnerability exists in snap-confine, a set-capabil
CVE-2026-46817 9.8 13.31% 2 2 2026-07-21T10:10:00.103000 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone
CVE-2026-16242 9.4 0.37% 1 0 2026-07-20T09:31:15 A flaw was found in the Konnectivity proxy-server configuration for hosted contr
CVE-2026-39808 9.8 89.69% 2 6 template 2026-07-16T18:32:24 A improper neutralization of special elements used in an os command ('os command
CVE-2026-58644 9.8 5.06% 2 0 2026-07-16T18:31:26 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2023-4346 7.5 0.91% 2 0 2026-07-16T05:16:16.603000 KNX devices that use KNX Connection Authorization and support Option 1 are, dep
CVE-2026-42533 8.1 2.79% 1 6 2026-07-15T15:33:14 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive
CVE-2026-56155 7.8 2.33% 2 0 2026-07-15T14:18:24.010000 Insufficient granularity of access control in Active Directory Federation Servic
CVE-2026-54121 8.8 1.05% 6 4 2026-07-14T18:32:37 Improper authorization in Active Directory Certificate Services (AD CS) allows a
CVE-2026-11405 9.8 1.62% 1 1 2026-07-08T15:32:52 The web server binary /bin/httpd contains a hidden backdoor authentication mecha
CVE-2026-55255 8.4 29.05% 2 1 2026-07-08T13:39:12.593000 Langflow is a tool for building and deploying AI-powered agents and workflows. P
CVE-2026-12569 9.8 2.26% 3 1 2026-06-26T15:33:15 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-32191 9.8 0.56% 2 0 2026-06-17T10:35:18.950000 Improper neutralization of special elements used in an os command ('os command i
CVE-2026-32194 9.8 0.70% 2 1 2026-03-20T00:31:34 Improper neutralization of special elements used in a command ('command injectio
CVE-2025-66376 7.2 21.62% 1 0 2026-03-18T18:31:10 Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas
CVE-2026-0770 None 53.46% 1 7 template 2026-02-19T22:09:33 Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere R
CVE-2025-0679 4.3 0.29% 1 0 2025-05-22T15:35:02 An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 be
CVE-2026-48021 0 0.12% 3 0 N/A
CVE-2026-54342 0 0.12% 1 0 N/A
CVE-2026-63030 0 98.05% 2 67 template N/A

CVE-2026-16766
(0 None)

EPSS: 0.67%

updated 2026-07-25T19:16:51.987000

2 posts

Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly to the wkhtmltopdf command without sanitization. Any web application that passes user-controlled options such as the page_size, orientation or margins without validation allows shell command injection. Version 0.6.0 was released with an incomplete fi

offseq at 2026-07-25T09:00:28.153Z ##

CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-25T09:00:28.000Z ##

CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. radar.offseq.com/threat/cve-20 #OffSeq #infosec #perl #vuln

##

CVE-2026-64374(CVSS UNKNOWN)

EPSS: 0.22%

updated 2026-07-25T12:31:39

1 posts

In the Linux kernel, the following vulnerability has been resolved: sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT RT migration is done aggressively. When a CPU schedules out a high priority RT task for a lower priority task, it will look to see if there's any RT tasks that are waiting to run on another CPU that is of higher priority than the task this CPU is about to run. If it fi

hugovalters@mastodon.social at 2026-07-25T14:12:27.000Z ##

CVE-2026-64374 - DoS in Linux kernel RT scheduler. Fix disabled RT_PUSH_IPI by default for non-PREEMPT_RT. CVSS 0. Update kernel if affected. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-643

##

CVE-2026-64324(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-07-25T12:31:38

1 posts

In the Linux kernel, the following vulnerability has been resolved: udf: validate free block extents against the partition length udf_free_blocks() checks the logical block number and count against the partition length, but drops the extent offset from that final bound. A crafted extent can pass the guard while logicalBlockNum + offset + count points past the partition, which later indexes past

hugovalters@mastodon.social at 2026-07-25T11:09:25.000Z ##

CVE-2026-64324 - Out-of-Bounds Access in Linux kernel UDF. CVSS 0.0. No patch available; monitor for updates. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-643

##

CVE-2026-66012
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-07-25T11:17:19.053000

4 posts

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publis

offseq at 2026-07-25T12:00:26.339Z ##

CVE-2026-66012: CRITICAL flaw in siyuan-note siyuan (<3.7.2). Missing authorization on /mcp lets remote attackers read secrets & plant malicious plugins for admin takeover. Disable anonymous Publish mode & restrict /mcp access. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-07-25T12:00:01.000Z ##

🔴 CVE-2026-66012 - Critical (10)

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-25T12:00:26.000Z ##

CVE-2026-66012: CRITICAL flaw in siyuan-note siyuan (<3.7.2). Missing authorization on /mcp lets remote attackers read secrets & plant malicious plugins for admin takeover. Disable anonymous Publish mode & restrict /mcp access. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec

##

thehackerwire@mastodon.social at 2026-07-25T12:00:01.000Z ##

🔴 CVE-2026-66012 - Critical (10)

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64415
(0 None)

EPSS: 0.21%

updated 2026-07-25T10:17:25.343000

1 posts

In the Linux kernel, the following vulnerability has been resolved: mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup We hit a real softlockup in an internal stress test environment. The workload was LTP memory/swap stress on a large arm64 machine, with 320 CPUs, about 1TB memory and an 8.6GB swap device. The system was under heavy load and the swap device had a l

hugovalters@mastodon.social at 2026-07-25T18:07:01.000Z ##

CVE-2026-64415 - DoS in Linux kernel via softlockup in swap_reclaim_full_clusters. CVSS 0. No patch available. Monitor for updates. #CVE #Linux #DoS

valtersit.com/cve/CVE-2026-644

##

CVE-2026-64399
(0 None)

EPSS: 0.21%

updated 2026-07-25T10:17:23.397000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE The FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() overwrites the destination file's data via vfs_clone_file_range() with neither the share-level KSMBD_TREE_CONN_FLAG_WRITABLE check nor a per-handle fp->daccess check that the other write-bearing arms carry. A

hugovalters@mastodon.social at 2026-07-25T17:09:54.000Z ##

CVE-2026-64399 - Linux ksmbd missing permission checks on FSCTL_DUPLICATE_EXTENTS_TO_FILE. Allows data overwrite on read-only shares. CVSS 0.0. No patch yet; monitor for updates. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-643

##

CVE-2026-64368
(0 None)

EPSS: 0.21%

updated 2026-07-25T10:17:19.613000

1 posts

In the Linux kernel, the following vulnerability has been resolved: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled When init (zeroing) on allocation is requested, for kmalloc() we generally have to zero the full object size even if a smaller size is requested, in order to provide krealloc()'s __GFP_ZERO guarantees. But if we track the requested size, krealloc() uses

hugovalters@mastodon.social at 2026-07-25T15:07:38.000Z ##

CVE-2026-64368 - Information disclosure in Linux kernel mm/slab. Zeroing logic flaw may leak kernel memory. CVSS 0.0. No patch yet; monitor for updates. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-643

##

CVE-2026-64337
(0 None)

EPSS: 0.22%

updated 2026-07-25T10:17:15.590000

1 posts

In the Linux kernel, the following vulnerability has been resolved: usb: mtu3: unmap request DMA on queue failure mtu3_gadget_queue() maps the request before checking whether the QMU GPD ring can accept another transfer. the request is returned with -EAGAIN before it is linked on the endpoint request list if mtu3_prepare_transfer() fails. Normal completion and dequeue paths unmap requests from

earthnewstrending@mastodon.social at 2026-07-25T14:39:45.000Z ##

CVE-2026-64337 | Linux Kernel up to 7.2-rc2 mtu3 mtu3_gadget_queue memory leak A vulnerability classified as very critical was found in Linux Kernel u... #news vuldb.com/vuln/383139

##

CVE-2026-64263
(0 None)

EPSS: 0.21%

updated 2026-07-25T10:17:06.460000

1 posts

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix moving cancelled entry to ent_in_userspace list fuse_uring_cancel() moves entries that are available (these have no reqs attached) to the ent_in_userspace list. ent_list_request_expired() checks the first entry on ent_in_userspace and dereferences ent->fuse_req unconditionally, which will crash on a cancelled ent

hugovalters@mastodon.social at 2026-07-25T12:02:21.000Z ##

CVE-2026-64263 - Null pointer dereference in Linux kernel fuse-uring. CVSS 0.0. No patch yet. Monitor for updates. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-642

##

CVE-2026-10818
(8.1 HIGH)

EPSS: 0.42%

updated 2026-07-25T07:17:08.880000

4 posts

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. This makes it possible for unauthenticated

offseq at 2026-07-25T13:30:10.790Z ##

CVE-2026-10818: WPForms Pro <=1.10.1.1 has a HIGH severity file upload vuln (CVSS 8.1). Unauthenticated RCE possible via ajax_chunk_upload_finalize. Restrict access & monitor uploads until a patch is released. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-07-25T07:59:48.000Z ##

🟠 CVE-2026-10818 - High (8.1)

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-25T13:30:10.000Z ##

CVE-2026-10818: WPForms Pro <=1.10.1.1 has a HIGH severity file upload vuln (CVSS 8.1). Unauthenticated RCE possible via ajax_chunk_upload_finalize. Restrict access & monitor uploads until a patch is released. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE202610818

##

thehackerwire@mastodon.social at 2026-07-25T07:59:48.000Z ##

🟠 CVE-2026-10818 - High (8.1)

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66035
(7.5 HIGH)

EPSS: 0.32%

updated 2026-07-25T05:16:42.900000

1 posts

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffe

thehackerwire@mastodon.social at 2026-07-24T20:00:59.000Z ##

🟠 CVE-2026-66035 - High (7.5)

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66034
(7.5 HIGH)

EPSS: 0.25%

updated 2026-07-25T05:16:42.773000

1 posts

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without

thehackerwire@mastodon.social at 2026-07-24T18:00:34.000Z ##

🟠 CVE-2026-66034 - High (7.5)

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsy...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66032
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-25T05:16:42.643000

1 posts

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call retur

thehackerwire@mastodon.social at 2026-07-24T18:00:10.000Z ##

🟠 CVE-2026-66032 - High (8.8)

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56163
(10.0 CRITICAL)

EPSS: 0.92%

updated 2026-07-25T05:16:35.420000

3 posts

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

offseq at 2026-07-25T04:30:23.579Z ##

CVE-2026-56163: CRITICAL (CVSS 10) in Azure Kubernetes Service — Missing authentication allows remote privilege escalation. Microsoft has released a fix; verify your AKS is updated. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-25T04:30:23.000Z ##

CVE-2026-56163: CRITICAL (CVSS 10) in Azure Kubernetes Service — Missing authentication allows remote privilege escalation. Microsoft has released a fix; verify your AKS is updated. radar.offseq.com/threat/cve-20 #OffSeq #Azure #Kubernetes #CloudSecurity

##

thehackerwire@mastodon.social at 2026-07-24T22:01:21.000Z ##

🔴 CVE-2026-56163 - Critical (10)

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66374
(8.1 HIGH)

EPSS: 0.39%

updated 2026-07-25T03:30:55

2 posts

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

1 repos

https://github.com/venglin/knot-doq

thehackerwire@mastodon.social at 2026-07-25T03:00:16.000Z ##

🟠 CVE-2026-66374 - High (8.1)

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T03:00:16.000Z ##

🟠 CVE-2026-66374 - High (8.1)

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66373
(7.5 HIGH)

EPSS: 0.47%

updated 2026-07-25T01:16:26.277000

2 posts

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.

thehackerwire@mastodon.social at 2026-07-25T03:00:05.000Z ##

🟠 CVE-2026-66373 - High (7.5)

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both cons...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T03:00:05.000Z ##

🟠 CVE-2026-66373 - High (7.5)

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both cons...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-60134
(8.8 HIGH)

EPSS: 0.32%

updated 2026-07-25T00:31:53

1 posts

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

thehackerwire@mastodon.social at 2026-07-25T00:00:13.000Z ##

🟠 CVE-2026-60134 - High (8.8)

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-71408
(7.8 HIGH)

EPSS: 0.16%

updated 2026-07-25T00:31:53

1 posts

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or san

thehackerwire@mastodon.social at 2026-07-24T23:00:01.000Z ##

🟠 CVE-2025-71408 - High (7.8)

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is inv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61892
(8.8 HIGH)

EPSS: 0.27%

updated 2026-07-24T23:16:51.333000

1 posts

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

thehackerwire@mastodon.social at 2026-07-25T00:00:02.000Z ##

🟠 CVE-2026-61892 - High (8.8)

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61884
(9.8 CRITICAL)

EPSS: 0.66%

updated 2026-07-24T22:16:50.963000

4 posts

The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, dev

offseq at 2026-07-25T00:00:40.260Z ##

CVE-2026-61884 (CRITICAL, CVSS 9.8) in Tycon TPDIN-Monitor-WEB2 v2.3.9: Server-side auth validation missing — empty creds grant admin access. Restrict management interface, monitor for unauthorized logins. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-25T00:00:40.000Z ##

CVE-2026-61884 (CRITICAL, CVSS 9.8) in Tycon TPDIN-Monitor-WEB2 v2.3.9: Server-side auth validation missing — empty creds grant admin access. Restrict management interface, monitor for unauthorized logins. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoT #Infosec

##

thehackerwire@mastodon.social at 2026-07-24T23:00:11.000Z ##

🔴 CVE-2026-61884 - Critical (9.8)

The web management interface of Tycon Systems TPDIN-Monitor-WEB2

 does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can byp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-07-24T13:04:35.000Z ##

Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8

securityonline.info/tycon-auth

##

CVE-2026-14603
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-24T21:33:30

2 posts

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.

thehackerwire@mastodon.social at 2026-07-25T10:00:01.000Z ##

🟠 CVE-2026-14603 - High (7.5)

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T10:00:01.000Z ##

🟠 CVE-2026-14603 - High (7.5)

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45815
(7.5 HIGH)

EPSS: 0.37%

updated 2026-07-24T21:33:30

2 posts

Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

thehackerwire@mastodon.social at 2026-07-25T08:00:24.000Z ##

🟠 CVE-2026-45815 - High (7.5)

Reachable Assertion vulnerability in Apache NimBLE.
A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.

Severity is medium as this requires DUT to first send ATT Read Multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T08:00:24.000Z ##

🟠 CVE-2026-45815 - High (7.5)

Reachable Assertion vulnerability in Apache NimBLE.
A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.

Severity is medium as this requires DUT to first send ATT Read Multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45813
(8.8 HIGH)

EPSS: 0.27%

updated 2026-07-24T21:33:30

2 posts

Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read. This can be triggered by nearby devices over Bluetooth connection, however pairing is required prior to accessing BASS service,

thehackerwire@mastodon.social at 2026-07-25T06:00:27.000Z ##

🟠 CVE-2026-45813 - High (8.8)

Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service.
Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T06:00:27.000Z ##

🟠 CVE-2026-45813 - High (8.8)

Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service.
Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66143
(7.5 HIGH)

EPSS: 0.33%

updated 2026-07-24T21:33:30

2 posts

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

thehackerwire@mastodon.social at 2026-07-25T06:00:07.000Z ##

🟠 CVE-2026-66143 - High (7.5)

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T06:00:07.000Z ##

🟠 CVE-2026-66143 - High (7.5)

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12981
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-24T21:33:29

3 posts

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.

thehackerwire@mastodon.social at 2026-07-25T10:59:50.000Z ##

🟠 CVE-2026-12981 - High (7.5)

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T10:59:50.000Z ##

🟠 CVE-2026-12981 - High (7.5)

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-24T07:30:26.000Z ##

CVE-2026-12981: CRITICAL vuln in CAFEHAUS API plugin ≤1.0.0 (WordPress). No authentication on password updates — attackers can reset any user password, including admins. Remove/disable plugin until fixed. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #PrivilegeEscalation

##

CVE-2026-66142
(7.5 HIGH)

EPSS: 0.33%

updated 2026-07-24T21:33:29

2 posts

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

thehackerwire@mastodon.social at 2026-07-25T05:00:24.000Z ##

🟠 CVE-2026-66142 - High (7.5)

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recom...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T05:00:24.000Z ##

🟠 CVE-2026-66142 - High (7.5)

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recom...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62835
(9.3 CRITICAL)

EPSS: 1.03%

updated 2026-07-24T21:32:28

4 posts

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

offseq at 2026-07-25T01:30:24.532Z ##

CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-25T01:30:24.000Z ##

CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at radar.offseq.com/threat/cve-20 #OffSeq #Azure #Vuln #CloudSecurity

##

thehackerwire@mastodon.social at 2026-07-24T22:01:11.000Z ##

🔴 CVE-2026-62835 - Critical (9.3)

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DarkWebInformer@infosec.exchange at 2026-07-24T20:45:57.000Z ##

🚨 CVE-2026-62835: Microsoft Azure Portal Information Disclosure Vulnerability

CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.

CVSS: 9.3

More information: msrc.microsoft.com/update-guid

##

CVE-2026-66039
(8.8 HIGH)

EPSS: 0.42%

updated 2026-07-24T21:32:28

1 posts

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_fra

thehackerwire@mastodon.social at 2026-07-24T22:01:01.000Z ##

🟠 CVE-2026-66039 - High (8.8)

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66041
(8.8 HIGH)

EPSS: 0.42%

updated 2026-07-24T21:32:28

1 posts

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data excee

thehackerwire@mastodon.social at 2026-07-24T22:00:14.000Z ##

🟠 CVE-2026-66041 - High (8.8)

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimension...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17107
(8.5 HIGH)

EPSS: 0.23%

updated 2026-07-24T21:32:28

1 posts

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an

thehackerwire@mastodon.social at 2026-07-24T20:00:24.000Z ##

🟠 CVE-2026-17107 - High (8.5)

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12877
(9.1 CRITICAL)

EPSS: 0.24%

updated 2026-07-24T20:48:39.923000

2 posts

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.

thehackerwire@mastodon.social at 2026-07-25T10:00:21.000Z ##

🔴 CVE-2026-12877 - Critical (9.1)

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is expl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T10:00:21.000Z ##

🔴 CVE-2026-12877 - Critical (9.1)

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is expl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12497
(7.5 HIGH)

EPSS: 0.23%

updated 2026-07-24T20:48:39.923000

2 posts

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some v

thehackerwire@mastodon.social at 2026-07-25T10:00:11.000Z ##

🟠 CVE-2026-12497 - High (7.5)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T10:00:11.000Z ##

🟠 CVE-2026-12497 - High (7.5)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56167
(8.5 HIGH)

EPSS: 0.38%

updated 2026-07-24T20:48:18.380000

2 posts

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-07-25T11:00:10.000Z ##

🟠 CVE-2026-56167 - High (8.5)

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T11:00:10.000Z ##

🟠 CVE-2026-56167 - High (8.5)

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16804
(8.3 HIGH)

EPSS: 0.29%

updated 2026-07-24T20:47:41.790000

2 posts

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T12:59:53.000Z ##

🟠 CVE-2026-16804 - High (8.3)

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T12:59:53.000Z ##

🟠 CVE-2026-16804 - High (8.3)

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45811
(7.5 HIGH)

EPSS: 0.25%

updated 2026-07-24T20:47:41.790000

2 posts

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket l

thehackerwire@mastodon.social at 2026-07-25T08:00:47.000Z ##

🟠 CVE-2026-45811 - High (7.5)

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.
The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer ove...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T08:00:47.000Z ##

🟠 CVE-2026-45811 - High (7.5)

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.
The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer ove...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45816
(7.5 HIGH)

EPSS: 0.38%

updated 2026-07-24T20:47:41.790000

2 posts

NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

thehackerwire@mastodon.social at 2026-07-25T08:00:36.000Z ##

🟠 CVE-2026-45816 - High (7.5)

NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.

This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.

This...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T08:00:36.000Z ##

🟠 CVE-2026-45816 - High (7.5)

NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.

This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.

This...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66144
(7.5 HIGH)

EPSS: 0.33%

updated 2026-07-24T20:47:41.790000

2 posts

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.

thehackerwire@mastodon.social at 2026-07-25T06:00:17.000Z ##

🟠 CVE-2026-66144 - High (7.5)

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T06:00:17.000Z ##

🟠 CVE-2026-66144 - High (7.5)

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8789
(8.1 HIGH)

EPSS: 0.22%

updated 2026-07-24T20:45:45.697000

1 posts

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary connection records from the `

thehackerwire@mastodon.social at 2026-07-24T17:00:27.000Z ##

🟠 CVE-2026-8789 - High (8.1)

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66040
(8.8 HIGH)

EPSS: 0.55%

updated 2026-07-24T20:18:21.063000

1 posts

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output

thehackerwire@mastodon.social at 2026-07-24T22:00:03.000Z ##

🟠 CVE-2026-66040 - High (8.8)

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66036
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-24T20:18:20.433000

1 posts

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() a

thehackerwire@mastodon.social at 2026-07-24T22:00:24.000Z ##

🟠 CVE-2026-66036 - High (8.8)

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49745
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-24T18:32:33

2 posts

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.

thehackerwire@mastodon.social at 2026-07-25T09:00:25.000Z ##

🟠 CVE-2026-49745 - High (7.8)

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.

Software installed and run under a Guest VM can send commands to the G...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T09:00:25.000Z ##

🟠 CVE-2026-49745 - High (7.8)

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.

Software installed and run under a Guest VM can send commands to the G...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49743
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-24T18:32:33

2 posts

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronisation primitive is not properly incremented. This can be exploited, by destroying the ex

thehackerwire@mastodon.social at 2026-07-25T09:00:05.000Z ##

🟠 CVE-2026-49743 - High (7.8)

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs.

During workload submission involving a fence exported by...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T09:00:05.000Z ##

🟠 CVE-2026-49743 - High (7.8)

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs.

During workload submission involving a fence exported by...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49744
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-24T18:32:32

2 posts

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.

thehackerwire@mastodon.social at 2026-07-25T09:00:15.000Z ##

🟠 CVE-2026-49744 - High (7.8)

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.

Out of bounds accesses triggered by malware introduced to a Guest KMD ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T09:00:15.000Z ##

🟠 CVE-2026-49744 - High (7.8)

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.

Out of bounds accesses triggered by malware introduced to a Guest KMD ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16801
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-24T18:32:32

2 posts

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.

thehackerwire@mastodon.social at 2026-07-25T05:00:04.000Z ##

🟠 CVE-2026-16801 - High (8.8)

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a craf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T05:00:04.000Z ##

🟠 CVE-2026-16801 - High (8.8)

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a craf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65709
(8.3 HIGH)

EPSS: 0.22%

updated 2026-07-24T18:31:41

1 posts

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without Account

thehackerwire@mastodon.social at 2026-07-24T20:01:19.000Z ##

🟠 CVE-2026-65709 - High (8.3)

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without pe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66033
(7.5 HIGH)

EPSS: 0.39%

updated 2026-07-24T18:31:41

1 posts

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to

thehackerwire@mastodon.social at 2026-07-24T18:00:20.000Z ##

🟠 CVE-2026-66033 - High (7.5)

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AE...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65708
(8.1 HIGH)

EPSS: 0.22%

updated 2026-07-24T18:31:37

1 posts

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorization checks in AccountFileController. Attackers can supply arbitrary numeric file IDs through the download, view, delete, upload, and list actions

thehackerwire@mastodon.social at 2026-07-24T20:01:09.000Z ##

🟠 CVE-2026-65708 - High (8.1)

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing au...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66027
(8.3 HIGH)

EPSS: 0.26%

updated 2026-07-24T18:31:37

1 posts

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's sess

thehackerwire@mastodon.social at 2026-07-24T16:59:50.000Z ##

🟠 CVE-2026-66027 - High (8.3)

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16870
(8.8 HIGH)

EPSS: 0.36%

updated 2026-07-24T18:16:52.770000

1 posts

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim proces

thehackerwire@mastodon.social at 2026-07-24T12:00:32.000Z ##

🟠 CVE-2026-16870 - High (8.8)

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16800
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-24T18:16:52.303000

2 posts

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.

thehackerwire@mastodon.social at 2026-07-25T05:00:14.000Z ##

🟠 CVE-2026-16800 - High (8.8)

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via craf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T05:00:14.000Z ##

🟠 CVE-2026-16800 - High (8.8)

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via craf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16807
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-24T15:34:00

2 posts

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T13:59:50.000Z ##

🟠 CVE-2026-16807 - High (8.8)

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T13:59:50.000Z ##

🟠 CVE-2026-16807 - High (8.8)

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16806
(8.8 HIGH)

EPSS: 0.43%

updated 2026-07-24T15:34:00

2 posts

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T13:00:13.000Z ##

🟠 CVE-2026-16806 - High (8.8)

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T13:00:13.000Z ##

🟠 CVE-2026-16806 - High (8.8)

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16805
(8.8 HIGH)

EPSS: 0.34%

updated 2026-07-24T15:34:00

2 posts

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T13:00:03.000Z ##

🟠 CVE-2026-16805 - High (8.8)

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T13:00:03.000Z ##

🟠 CVE-2026-16805 - High (8.8)

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64600(CVSS UNKNOWN)

EPSS: 0.72%

updated 2026-07-24T15:34:00

7 posts

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently

3 repos

https://github.com/HORKimhab/CVE-2026-64600

https://github.com/vulnquest58/VQ-RefluxCore

https://github.com/0xBlackash/CVE-2026-64600

secdb at 2026-07-25T12:52:05.798Z ##

🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability.

In the Linux kernel, the following vulnerability has been resolved:

xfs: resample the data fork mapping after cycling ILOCK

RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access.

ℹ️ Additional details on ZEN SecDB secdb.nttzen.cloud/updates/1d2


##

schwerdtfegr.wordpress.com@schwerdtfegr.wordpress.com at 2026-07-25T11:41:44.000Z ##

Aber linux ist doch sicherer als linux…

Sicherheitsforscher von Qualys haben mithilfe von Claude Mythos eine neun Jahre alte und RefluXFS genannte Sicherheitslücke im Linux-Kernel entdeckt, mit der Angreifer durch das überschreiben geschützter Dateien Root-Zugriff erlangen können. Viele Linux-Distributionen sind in der Standardkonfiguration angreifbar, darunter Red Hat Enterprise Linux (RHEL), CentOS, Fedora und Oracle Linux. Admins sollten ihre Systeme absichern […] anfällig sind alle Linux-Kernel ab Version 4.11, welche im April 2017 veröffentlicht wurde. Voraussetzung ist jedoch, dass ein anvisiertes Linux-System über ein XFS-Volume mit aktiver Reflink-Funktion verfügt […] es gebe keinen alternativen Workaround, der zuverlässig vor CVE-2026-64600 schütze

Na, zumindest das kriegen die angelernten neuronalen netzwerke sehr zuverlässig hin: einen haufen uralter fehler in linux aufzufinden. Schön die sicherheitsaktualisierungen einspielen!

#Epic #Fail #Golem #Link #Linux #Security ##

threatnoir at 2026-07-25T07:05:45.677Z ##

⚠️ CRITICAL: New RefluXFS Linux flaw lets attackers gain root privileges

A nine-year-old race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite protected files and escalate to root. Systems running kernel v4.11+ with XFS and reflink enabled are vulnerable. The exploit leaves no kernel logs and persists across reboots, making dete…

threatnoir.com/focus

##

secdb@infosec.exchange at 2026-07-25T12:52:05.000Z ##

🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability.

In the Linux kernel, the following vulnerability has been resolved:

xfs: resample the data fork mapping after cycling ILOCK

RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access.

ℹ️ Additional details on ZEN SecDB secdb.nttzen.cloud/updates/1d2

#infosec #refluxfs #linux #kernel #xfs #lpe
#nttdata #zen #secdb

##

schwerdtfegr.wordpress.com@schwerdtfegr.wordpress.com at 2026-07-25T11:41:44.000Z ##

Aber linux ist doch sicherer als linux…

Sicherheitsforscher von Qualys haben mithilfe von Claude Mythos eine neun Jahre alte und RefluXFS genannte Sicherheitslücke im Linux-Kernel entdeckt, mit der Angreifer durch das überschreiben geschützter Dateien Root-Zugriff erlangen können. Viele Linux-Distributionen sind in der Standardkonfiguration angreifbar, darunter Red Hat Enterprise Linux (RHEL), CentOS, Fedora und Oracle Linux. Admins sollten ihre Systeme absichern […] anfällig sind alle Linux-Kernel ab Version 4.11, welche im April 2017 veröffentlicht wurde. Voraussetzung ist jedoch, dass ein anvisiertes Linux-System über ein XFS-Volume mit aktiver Reflink-Funktion verfügt […] es gebe keinen alternativen Workaround, der zuverlässig vor CVE-2026-64600 schütze

Na, zumindest das kriegen die angelernten neuronalen netzwerke sehr zuverlässig hin: einen haufen uralter fehler in linux aufzufinden. Schön die sicherheitsaktualisierungen einspielen!

#Epic #Fail #Golem #Link #Linux #Security ##

threatnoir@infosec.exchange at 2026-07-25T07:05:45.000Z ##

⚠️ CRITICAL: New RefluXFS Linux flaw lets attackers gain root privileges

A nine-year-old race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite protected files and escalate to root. Systems running kernel v4.11+ with XFS and reflink enabled are vulnerable. The exploit leaves no kernel logs and persists across reboots, making dete…

threatnoir.com/focus

#infosec #cybersecurity

##

DailyCyberSecurity@infosec.exchange at 2026-07-24T13:31:15.000Z ##

Discover the RefluXFS Linux vulnerability (CVE-2026-64600) in XFS that allows local users to overwrite protected files and gain root privileges.

#RefluXFS #CVE202664600 #LinuxKernel #Cybersecurity #XFS

meterpreter.org/refluxfs-linux

##

CVE-2026-58630
(10.0 CRITICAL)

EPSS: 0.81%

updated 2026-07-24T15:33:09

4 posts

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

offseq at 2026-07-25T06:00:25.506Z ##

CVE-2026-58630: Improper access control in Azure App Service for Linux (CVSS 10, CRITICAL) lets remote attackers escalate privileges with no auth or user action. Patched by Microsoft — verify updates. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-25T06:00:25.000Z ##

CVE-2026-58630: Improper access control in Azure App Service for Linux (CVSS 10, CRITICAL) lets remote attackers escalate privileges with no auth or user action. Patched by Microsoft — verify updates. Details: radar.offseq.com/threat/cve-20 #OffSeq #Azure #Infosec #CVE2026_58630

##

DarkWebInformer@infosec.exchange at 2026-07-24T19:09:34.000Z ##

‼️ CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

CVSS: 10

Details: msrc.microsoft.com/update-guid

##

thehackerwire@mastodon.social at 2026-07-24T17:00:38.000Z ##

🔴 CVE-2026-58630 - Critical (10)

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57106
(10.0 CRITICAL)

EPSS: 0.92%

updated 2026-07-24T15:33:03

3 posts

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

offseq at 2026-07-25T07:30:24.250Z ##

Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-25T07:30:24.000Z ##

Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #SSRF #Microsoft #CyberSec

##

thehackerwire@mastodon.social at 2026-07-24T17:00:48.000Z ##

🔴 CVE-2026-57106 - Critical (10)

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12503
(0 None)

EPSS: 0.14%

updated 2026-07-24T15:17:10.997000

2 posts

Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink attack on `/etc/lighttpd/ssl/server.pem`.

offseq at 2026-07-25T10:30:26.709Z ##

CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-25T10:30:26.000Z ##

CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Loytec #CVE2026

##

CVE-2026-24727
(0 None)

EPSS: 0.67%

updated 2026-07-24T13:17:34.217000

1 posts

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.

offseq@infosec.exchange at 2026-07-24T10:30:26.000Z ##

CVE-2026-24727 (CRITICAL, CVSS 9.3): SUNNET Corporate Training Mgmt System v10.3 allows admins to upload ZIP files with executable code, enabling server command execution. No patch yet — restrict admin access & monitor uploads. radar.offseq.com/threat/cve-20 #OffSeq #CVE202624727 #infosec 🛡️

##

CVE-2026-14172
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-24T09:32:22

1 posts

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.

thehackerwire@mastodon.social at 2026-07-24T12:00:22.000Z ##

🟠 CVE-2026-14172 - High (7.8)

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15704
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-07-24T09:32:16

2 posts

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's `middleware.StripSlashes`, so a request such as `GET /shells/` was dispatched to the registered `GET /shells` route. However

thehackerwire@mastodon.social at 2026-07-24T12:00:12.000Z ##

🔴 CVE-2026-15704 - Critical (9.8)

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router.

The shared rou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-24T09:00:31.000Z ##

Eclipse BaSyx Go Components (<=1.0.0) suffer a CRITICAL auth bypass (CVE-2026-15704): ABAC checks can be evaded by adding a trailing slash to API routes. Immediate upgrade to 1.0.1 is required. radar.offseq.com/threat/cve-20 #OffSeq #CVE202615704 #infosec #AppSec

##

CVE-2026-66140
(8.4 HIGH)

EPSS: 0.27%

updated 2026-07-24T06:34:11

2 posts

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

thehackerwire@mastodon.social at 2026-07-25T11:00:00.000Z ##

🟠 CVE-2026-66140 - High (8.4)

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T11:00:00.000Z ##

🟠 CVE-2026-66140 - High (8.4)

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-35425
(8.0 HIGH)

EPSS: 0.48%

updated 2026-07-24T03:32:01

2 posts

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-07-25T12:00:43.000Z ##

🟠 CVE-2026-35425 - High (8)

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T12:00:43.000Z ##

🟠 CVE-2026-35425 - High (8)

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54120
(9.9 CRITICAL)

EPSS: 0.71%

updated 2026-07-24T03:31:56

3 posts

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-07-25T12:00:23.000Z ##

🔴 CVE-2026-54120 - Critical (9.9)

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T12:00:23.000Z ##

🔴 CVE-2026-54120 - Critical (9.9)

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-24T13:30:30.000Z ##

CVE-2026-54120 (CRITICAL, CVSS 9.9): Improper input validation in Microsoft Surface Management Services lets authorized attackers run code remotely. Patch now: radar.offseq.com/threat/cve-20 🖥️ #OffSeq #infosec #Microsoft #CVE202654120

##

CVE-2026-56160
(9.1 CRITICAL)

EPSS: 0.65%

updated 2026-07-24T03:31:56

1 posts

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-07-24T12:00:29.000Z ##

CRITICAL improper authorization vuln (CVE-2026-56160) in Azure Red Hat OpenShift (ARO): privilege escalation risk for authorized users. No active exploits. Microsoft has released a fix — ensure your ARO instances are updated. Details: radar.offseq.com/threat/cve-20 #OffSeq #Azure #CVE202656160

##

CVE-2026-50517
(9.9 CRITICAL)

EPSS: 1.25%

updated 2026-07-24T03:31:55

2 posts

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-07-25T12:00:33.000Z ##

🔴 CVE-2026-50517 - Critical (9.9)

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-25T12:00:33.000Z ##

🔴 CVE-2026-50517 - Critical (9.9)

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16232
(9.1 CRITICAL)

EPSS: 12.68%

updated 2026-07-23T15:44:54.743000

4 posts

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server I

1 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

netsecio@mastodon.social at 2026-07-25T19:15:49.000Z ##

📰 Analysis Highlights Attacks on "Management Layer" Infrastructure

Analysis reveals a trend of attacks on the "management layer." Recent incidents involving an Iranian APT, a Check Point zero-day (CVE-2026-16232), and a SharePoint RCE (CVE-2026-50522) highlight this high-impact strategy. #CyberSecurity #ThreatIntel ...

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/an

##

DarkWebInformer@infosec.exchange at 2026-07-24T19:30:19.000Z ##

‼️ CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

CVSS: 9.1

Scanner: github.com/WadesWeaponShed/Che

Details and Mitigation: support.checkpoint.com/results

##

youranonnewsirc@nerdculture.de at 2026-07-24T10:26:30.000Z ##

Geopolitical tensions escalated as US strikes on Iran continued and Houthi attacks on Saudi tankers raised oil prices. In cybersecurity, a critical Check Point zero-day (CVE-2026-16232) is actively exploited. US agencies warned of Iranian cyber campaigns targeting critical infrastructure PLCs and Russian state-backed phishing on Zimbra Collaboration Suite. AI agents are now a primary attack surface.

#Cybersecurity #Geopolitics #TechNews

##

nyanbinary@infosec.exchange at 2026-07-24T07:04:37.000Z ##

why am I confronted with this crime against language and common sense? discourse.ifin.network/t/cve-2 thats why (eitw vuln)

##

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 57.10%

updated 2026-07-23T15:44:10.873000

4 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/4minx/CVE-2026-50522

https://github.com/HORKimhab/CVE-2026-50522

netsecio@mastodon.social at 2026-07-25T19:15:49.000Z ##

📰 Analysis Highlights Attacks on "Management Layer" Infrastructure

Analysis reveals a trend of attacks on the "management layer." Recent incidents involving an Iranian APT, a Check Point zero-day (CVE-2026-16232), and a SharePoint RCE (CVE-2026-50522) highlight this high-impact strategy. #CyberSecurity #ThreatIntel ...

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/an

##

thecybermind at 2026-07-25T05:35:48.563Z ##

Active exploitation verified for CVE-2026-50522. Microsoft SharePoint's deserialization flaw demands immediate C-Suite oversight, patch prioritization, and strict endpoint hardening. Protect your enterprise assets today. thecybermind.co/kc88

##

thecybermind@infosec.exchange at 2026-07-25T05:35:48.000Z ##

Active exploitation verified for CVE-2026-50522. Microsoft SharePoint's deserialization flaw demands immediate C-Suite oversight, patch prioritization, and strict endpoint hardening. Protect your enterprise assets today. thecybermind.co/kc88

##

thecybermind@infosec.exchange at 2026-07-24T15:22:59.000Z ##

(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data....

thecybermind.co/2026/07/24/cis

##

CVE-2026-16723
(9.0 CRITICAL)

EPSS: 0.41%

updated 2026-07-23T15:01:24.377000

5 posts

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

1 repos

https://github.com/HORKimhab/CVE-2026-16723

CapTechGroup@mastodon.social at 2026-07-25T18:22:23.000Z ##

CVE-2026-16723 in Fastjson 1.2.68–1.2.83 enables unauthenticated RCE in Spring Boot apps. No patched 1.x release exists. Attackers don't need AutoType enabled or gadget chains—just SafeMode at default and a reachable JSON...

captechgroup.com/threat-intell

##

undercodenews@mastodon.social at 2026-07-25T15:11:07.000Z ##

Critical Spring Boot Security Alert: CVE-2026-16723 Exposes Fastjson Applications to Unauthenticated Remote Code Execution + Video

Introduction: A New Java Security Threat Emerges The cybersecurity community is warning developers and organizations about a newly exploited vulnerability affecting Java-based applications built with Spring Boot and Fastjson 1.x. Tracked as CVE-2026-16723, the flaw allows attackers to achieve unauthenticated remote code execution in…

undercodenews.com/critical-spr

##

Analyst207@mastodon.social at 2026-07-25T14:06:30.000Z ##

Fastjson Vulnerability Exploited in Targeted Attacks

A critical vulnerability in Fastjson, tracked as CVE-2026-16723, has been exploited in targeted attacks, with a severity score of 9.0 out of 10. Attackers are actively probing for exposed paths in Fastjson 1.x, commonly used in Spring Boot deployments.

osintsights.com/fastjson-vulne

#FastjsonVulnerability #Cve202616723 #SupplyChain #EmergingThreats #VulnerabilityExploitation

##

DailyCyberSecurity at 2026-07-25T02:24:01.858Z ##

FastJson RCE vulnerability CVE-2026-16723 is exploited in the wild. Details and PoC exploit code are public for this critical remote code execution flaw.

securityonline.info/fastjson-r

##

DailyCyberSecurity@infosec.exchange at 2026-07-25T02:24:01.000Z ##

FastJson RCE vulnerability CVE-2026-16723 is exploited in the wild. Details and PoC exploit code are public for this critical remote code execution flaw.

#FastJson #CVE202616723 #RCE #ZeroDay

securityonline.info/fastjson-r

##

CVE-2026-25089
(9.8 CRITICAL)

EPSS: 69.83%

updated 2026-07-23T08:10:00.137000

2 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP req

2 repos

https://github.com/HORKimhab/CVE-2026-25089

https://github.com/0xBlackash/CVE-2026-25089

thecybermind at 2026-07-25T06:21:34.422Z ##

(CISA TS-SOC) CVE-2026-25089 – Fortinet FortiSandbox OS Command Injection Vulnerability

Severity: CRITICAL Impact Summary: Allows remote, unauthenticated attackers to execute arbitrary operating system commands on affected FortiSandbox products via HTTP....

thecybermind.co/2026/07/25/cis

##

thecybermind@infosec.exchange at 2026-07-25T06:21:34.000Z ##

(CISA TS-SOC) CVE-2026-25089 – Fortinet FortiSandbox OS Command Injection Vulnerability

Severity: CRITICAL Impact Summary: Allows remote, unauthenticated attackers to execute arbitrary operating system commands on affected FortiSandbox products via HTTP....

thecybermind.co/2026/07/25/cis

##

CVE-2026-53359
(8.8 HIGH)

EPSS: 0.91%

updated 2026-07-22T21:31:50

3 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. Th

6 repos

https://github.com/xj2268-TA/KVM-Januscape

https://github.com/ndouglas-cloudsmith/CVE-2026-53359

https://github.com/chuzhongyun/CVE-2026-53359-Kernel-Fix

https://github.com/0xBlackash/CVE-2026-53359

https://github.com/Aoripus-LTD/Januscape-Hotfix

https://github.com/HORKimhab/CVE-2026-53359

benoit@benoit.jp.net at 2026-07-25T12:29:58.000Z ##

I wonder how many hosters are vulnerable to CVE-2026-53359 (Januscape). Probably a lot.

##

benoit@benoit.jp.net at 2026-07-25T12:29:58.000Z ##

I wonder how many hosters are vulnerable to CVE-2026-53359 (Januscape). Probably a lot.

##

tisba@ruby.social at 2026-07-24T09:04:20.000Z ##

@janl @jschauma not all LPE do fully break kernel namespaces ("containers”) - not sure about the quoted one though. While I don't disagree with your assessment, I'd still argue that containers made various security related features much more approachable and still provide value. In the end it always has been about defense in depth.

If we start to see more issues in KVM like CVE-2026-53359, we are really screwed! Then we're basically back to hardware isolation for everything that matters 🫣

##

CVE-2026-50454
(7.8 HIGH)

EPSS: 0.44%

updated 2026-07-22T16:17:58.990000

1 posts

Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

CVE-2026-49176
(7.8 HIGH)

EPSS: 0.40%

updated 2026-07-22T16:17:28.753000

2 posts

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

1 repos

https://github.com/DavidCarliez/CVE-2026-49176_LPE_POC

CVE-2026-60137
(5.9 MEDIUM)

EPSS: 77.97%

updated 2026-07-22T05:17:11.750000

1 posts

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

41 repos

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/0xjessie21/wp2shell-checker

https://github.com/ekomsSavior/wp2shell

https://github.com/shinthink/CVE-2026-63030

https://github.com/bahartanir/wp2shell-scanner

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/ananay/wp2shell-lab

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/h4cd0c/wp2shell

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/Iqbalx7/wp2shell

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/zi3lak/wp2shell_scanner

https://github.com/0xsha/wp2shell

https://github.com/47Cid/wp2shell-lab

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/NULL200OK/WP2Shell

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/Crypto-Cat/wp2shell

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/ikow/wp2shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/0xWhoknows/wp2shell

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/kulichr/wp2shell

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/mcipekci/wp2shell

https://github.com/vulnquest58/PressVector

https://github.com/securelayer7/WordPresShell

https://github.com/Icex0/wp2shell-poc

https://github.com/dinosn/wp2shell-lab

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

thecybermind@infosec.exchange at 2026-07-24T11:29:34.000Z ##

(CISA TS-SOC) CVE-2026-60137 – WordPress Core SQL Injection Vulnerability

Severity: MEDIUM Impact Summary: Allows unauthenticated attackers to perform SQL injection, which can be chained with CVE-2026-63030 to achieve remote code execution on default WordPress installations....

thecybermind.co/2026/07/24/cis

##

CVE-2026-8933
(7.8 HIGH)

EPSS: 0.18%

updated 2026-07-21T15:30:51

2 posts

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or secur

security_crawler_carl at 2026-07-25T11:12:26.134Z ##

CVE-2026-8933, lovingly documented by the Qualys Threat Research Unit, lets a local user squeeze through that gap, drop a malicious AppArmor rules file, prod systemd-udevd into running commands as root, and collect full root access like a door prize. Ubuntu Desktop 24.04, 25.10, and 26.04 ship this by default. It is a trap room with the pressure plate installed by the architect. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-07-25T11:12:26.000Z ##

CVE-2026-8933, lovingly documented by the Qualys Threat Research Unit, lets a local user squeeze through that gap, drop a malicious AppArmor rules file, prod systemd-udevd into running commands as root, and collect full root access like a door prize. Ubuntu Desktop 24.04, 25.10, and 26.04 ship this by default. It is a trap room with the pressure plate installed by the architect. (2/3)

##

CVE-2026-46817
(9.8 CRITICAL)

EPSS: 13.31%

updated 2026-07-21T10:10:00.103000

2 posts

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Con

2 repos

https://github.com/0xBlackash/CVE-2026-46817

https://github.com/HORKimhab/CVE-2026-46817

thecybermind at 2026-07-25T17:07:36.486Z ##

(CISA TS-MAN) CVE-2026-46817 – Oracle E-Business Suite Improper Privilege Management Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attacker to compromise Oracle Payments, potentially resulting in full takeover....

thecybermind.co/2026/07/25/cis

##

thecybermind@infosec.exchange at 2026-07-25T17:07:36.000Z ##

(CISA TS-MAN) CVE-2026-46817 – Oracle E-Business Suite Improper Privilege Management Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attacker to compromise Oracle Payments, potentially resulting in full takeover....

thecybermind.co/2026/07/25/cis

##

CVE-2026-16242
(9.4 CRITICAL)

EPSS: 0.37%

updated 2026-07-20T09:31:15

1 posts

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy,

CVE-2026-39808
(9.8 CRITICAL)

EPSS: 89.69%

updated 2026-07-16T18:32:24

2 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Nuclei template

6 repos

https://github.com/Lechansky/CVE-2026-39808

https://github.com/HORKimhab/CVE-2026-39808

https://github.com/error-inside/CVE-2026-39808

https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808

https://github.com/0xBlackash/CVE-2026-39808

https://github.com/samu-delucas/CVE-2026-39808

thecybermind at 2026-07-25T06:08:41.624Z ##

(CISA TS-SOC) CVE-2026-39808 – Fortinet FortiSandbox OS Command Injection Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to execute unauthorized code or commands on the affected system via crafted HTTP requests....

thecybermind.co/2026/07/25/cis

##

thecybermind@infosec.exchange at 2026-07-25T06:08:41.000Z ##

(CISA TS-SOC) CVE-2026-39808 – Fortinet FortiSandbox OS Command Injection Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to execute unauthorized code or commands on the affected system via crafted HTTP requests....

thecybermind.co/2026/07/25/cis

##

CVE-2026-58644
(9.8 CRITICAL)

EPSS: 5.06%

updated 2026-07-16T18:31:26

2 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

thecybermind at 2026-07-25T06:16:56.866Z ##

(CISA TS-SOC) CVE-2026-58644 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data....

thecybermind.co/2026/07/18/__t

##

thecybermind@infosec.exchange at 2026-07-25T06:16:56.000Z ##

(CISA TS-SOC) CVE-2026-58644 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data....

thecybermind.co/2026/07/18/__t

##

CVE-2023-4346
(7.5 HIGH)

EPSS: 0.91%

updated 2026-07-16T05:16:16.603000

2 posts

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to i

thecybermind at 2026-07-25T17:04:55.394Z ##

(CISA TS-MAN) CVE-2023-4346 – KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

Severity: HIGH Impact Summary: An attacker could purge all devices and set a BCU key to lock the device, potentially resulting in denial of service if additional security options are not enabled....

thecybermind.co/2026/07/25/cis

##

thecybermind@infosec.exchange at 2026-07-25T17:04:55.000Z ##

(CISA TS-MAN) CVE-2023-4346 – KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

Severity: HIGH Impact Summary: An attacker could purge all devices and set a BCU key to lock the device, potentially resulting in denial of service if additional security options are not enabled....

thecybermind.co/2026/07/25/cis

##

CVE-2026-42533
(8.1 HIGH)

EPSS: 2.79%

updated 2026-07-15T15:33:14

1 posts

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyon

6 repos

https://github.com/srkyn/nginx-map-risk-audit

https://github.com/seguridadentrerios/CVE-2026-42533

https://github.com/suominen/CVE-2026-42533

https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner

https://github.com/Daniyal48/ghostlock-vagrant-box

https://github.com/gagaltotal/CVE-2026-42533-nginx

ChrisShort@hachyderm.io at 2026-07-24T15:29:13.000Z ##

15-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533 – cyberstan #devopsish cyberstan.co.uk/nginx-rce/

##

CVE-2026-56155
(7.8 HIGH)

EPSS: 2.33%

updated 2026-07-15T14:18:24.010000

2 posts

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

thecybermind at 2026-07-25T16:43:09.855Z ##

(CISA TS-MAN) CVE-2026-56155 – Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Severity: HIGH Impact Summary: Allows an authorized attacker to locally elevate privileges due to insufficient granularity of access control....

thecybermind.co/2026/07/25/cis

##

thecybermind@infosec.exchange at 2026-07-25T16:43:09.000Z ##

(CISA TS-MAN) CVE-2026-56155 – Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Severity: HIGH Impact Summary: Allows an authorized attacker to locally elevate privileges due to insufficient granularity of access control....

thecybermind.co/2026/07/25/cis

##

CVE-2026-54121
(8.8 HIGH)

EPSS: 1.05%

updated 2026-07-14T18:32:37

6 posts

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

4 repos

https://github.com/0xBlackash/CVE-2026-54121

https://github.com/HORKimhab/CVE-2026-54121

https://github.com/tc4dy/CVE-2026-54121-PoC-Exploit

https://github.com/aniqfakhrul/CVE-2026-54121

benzogaga33@mamot.fr at 2026-07-25T09:40:03.000Z ##

Certighost (CVE-2026-54121) : un compte AD standard suffit pour usurper un contrôleur de domaine it-connect.fr/certighost-cve-2 #ActuCybersécurité #ActiveDirectory #Cybersécurité #Vulnérabilité #Microsoft

##

threatnoir at 2026-07-25T07:05:43.426Z ##

⚠️ CRITICAL: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Certighost (CVE-2026-54121) allows any domain user to obtain a Domain Controller certificate and execute DCSync attacks to steal the krbtgt secret without admin rights. This gives attackers a direct path to full domain compromise. Any organization running unpatched Active Directory is at immediate…

threatnoir.com/focus

##

benzogaga33@mamot.fr at 2026-07-25T09:40:03.000Z ##

Certighost (CVE-2026-54121) : un compte AD standard suffit pour usurper un contrôleur de domaine it-connect.fr/certighost-cve-2 #ActuCybersécurité #ActiveDirectory #Cybersécurité #Vulnérabilité #Microsoft

##

threatnoir@infosec.exchange at 2026-07-25T07:05:43.000Z ##

⚠️ CRITICAL: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Certighost (CVE-2026-54121) allows any domain user to obtain a Domain Controller certificate and execute DCSync attacks to steal the krbtgt secret without admin rights. This gives attackers a direct path to full domain compromise. Any organization running unpatched Active Directory is at immediate…

threatnoir.com/focus

#infosec #cybersecurity

##

DarkWebInformer@infosec.exchange at 2026-07-24T19:55:21.000Z ##

‼️ PoC released for CVE-2026-54121 codenamed Certighost

CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.

GitHub: github.com/aniqfakhrul/cve-202

##

AAKL@infosec.exchange at 2026-07-24T15:49:06.000Z ##

New.

GitHub/H0j3n: Certighost (CVE-2026-54121) gist.github.com/H0j3n/a5ef2609

More:

The Hacker News: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller thehackernews.com/2026/07/cert @thehackernews #infosec #vulnerability #Microsoft #Windows

##

CVE-2026-11405
(9.8 CRITICAL)

EPSS: 1.62%

updated 2026-07-08T15:32:52

1 posts

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuratio

1 repos

https://github.com/HORKimhab/CVE-2026-11405

sekurakbot@mastodon.com.pl at 2026-07-24T09:35:00.000Z ##

Odnaleziono backdoor w routerach Tenda

W oprogramowaniu popularnego – również w naszym kraju – chińskiego producenta sprzętu sieciowego Tenda, odkryto ukrytą funkcjonalność. Pozwala ona na dostęp do interfejsu zarządzania WWW na prawach administratora urządzenia przy pomocy zapisanego na stałe hasła. TLDR: Czyli mamy do czynienia z klasyczną tylną furtką, zwaną powszechnie backdoorem. Podatność została oznaczona identyfikatorem CVE-2026-11405 i polega na modyfikacji...

#WBiegu #Backdoor #Cve #Router #Tenda

sekurak.pl/odnaleziono-backdoo

##

CVE-2026-55255
(8.4 HIGH)

EPSS: 29.05%

updated 2026-07-08T13:39:12.593000

2 posts

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.

1 repos

https://github.com/rootdirective-sec/CVE-2026-55255-Lab

thecybermind at 2026-07-25T17:06:29.770Z ##

(CISA TS-MAN) CVE-2026-55255 – Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Severity: HIGH Impact Summary: An authenticated attacker can execute any flow belonging to another user by specifying the victim's flow ID in the request, bypassing authorization controls....

thecybermind.co/2026/07/25/cis

##

thecybermind@infosec.exchange at 2026-07-25T17:06:29.000Z ##

(CISA TS-MAN) CVE-2026-55255 – Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Severity: HIGH Impact Summary: An authenticated attacker can execute any flow belonging to another user by specifying the victim's flow ID in the request, bypassing authorization controls....

thecybermind.co/2026/07/25/cis

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 2.26%

updated 2026-06-26T15:33:15

3 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

Analyst207@mastodon.social at 2026-07-25T12:07:03.000Z ##

Cl0p Ransomware Gang Exploits PTC Windchill Flaw in Data Extortion Drive

PTC Windchill users are under attack, with threat actors actively exploiting a critical flaw (CVE-2026-12569) that allows for remote code execution, prompting PTC to warn customers of heightened threat activity. This vulnerability, with a CVSS score of 9.3, has already been added to the US government's list of known exploited…

osintsights.com/cl0p-ransomwar

#Cl0pRansomware #PtcWindchill #Cve202612569 #Ransomware #SupplyChain

##

kev_Stalker at 2026-07-25T04:14:10.588Z ##

CVE-2026-12569 - Changed to Known Ransomware Status

PTC Windchill and FlexPLM Improper Input Validation VulnerabilityVendor: PTCProduct: Windchill and FlexPLMPTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: July 24,nvd.nist.gov/vuln/detail/CVE-2

##

kev_Stalker@infosec.exchange at 2026-07-25T04:14:10.000Z ##

CVE-2026-12569 - Changed to Known Ransomware Status

PTC Windchill and FlexPLM Improper Input Validation VulnerabilityVendor: PTCProduct: Windchill and FlexPLMPTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: July 24,nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-32191
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-06-17T10:35:18.950000

2 posts

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

threatnoir at 2026-07-25T06:06:27.136Z ##

⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im…

threatnoir.com/focus

##

threatnoir@infosec.exchange at 2026-07-25T06:06:27.000Z ##

⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-32194
(9.8 CRITICAL)

EPSS: 0.70%

updated 2026-03-20T00:31:34

2 posts

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

1 repos

https://github.com/HORKimhab/CVE-2026-32194

threatnoir at 2026-07-25T06:06:27.136Z ##

⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im…

threatnoir.com/focus

##

threatnoir@infosec.exchange at 2026-07-25T06:06:27.000Z ##

⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2025-66376
(7.2 HIGH)

EPSS: 21.62%

updated 2026-03-18T18:31:10

1 posts

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

VirusBulletin@infosec.exchange at 2026-07-24T09:25:53.000Z ##

Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. proofpoint.com/us/blog/threat-

##

CVE-2026-0770(CVSS UNKNOWN)

EPSS: 53.46%

updated 2026-02-19T22:09:33

1 posts

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The

Nuclei template

7 repos

https://github.com/0xBlackash/CVE-2026-0770

https://github.com/0xgh057r3c0n/CVE-2026-0770

https://github.com/razureink/cve-2026-0770-langflow_rce_reproduction

https://github.com/affix/CVE-2026-0770-PoC

https://github.com/diamorphine666/CVE-2026-0770

https://github.com/Yetazyyy/CVE-2026-0770

https://github.com/Ez4rd1x1/CVE-2026-0770

thecybermind@infosec.exchange at 2026-07-24T11:06:41.000Z ##

(CISA TS-SOC) CVE-2026-0770 – Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Severity: UNKNOWN Impact Summary: Remote attackers can execute arbitrary code on affected installations. Timestamp: 2026-07-24T01:31:37.336Z ATT&CK Mapping…...

thecybermind.co/2026/07/24/cis

##

CVE-2025-0679
(4.3 MEDIUM)

EPSS: 0.29%

updated 2025-05-22T15:35:02

1 posts

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.

security_crawler_carl@infosec.exchange at 2026-07-24T12:21:18.000Z ##

CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

Reward: You've received a hollow Authenticator Token — pre-drained.

#ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)

##

CVE-2026-48021
(0 None)

EPSS: 0.12%

3 posts

N/A

offseq at 2026-07-25T03:00:25.560Z ##

CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-25T03:00:25.000Z ##

CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #HealthcareSecurity #Vuln #CVE202648021

##

thehackerwire@mastodon.social at 2026-07-24T20:00:12.000Z ##

🔴 CVE-2026-48021 - Critical (9.1)

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traff...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54342
(0 None)

EPSS: 0.12%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-24T20:00:02.000Z ##

🟠 CVE-2026-54342 - High (8.1)

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnek...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63030
(0 None)

EPSS: 98.05%

2 posts

N/A

Nuclei template

67 repos

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/0xjessie21/wp2shell-checker

https://github.com/ekomsSavior/wp2shell

https://github.com/shinthink/CVE-2026-63030

https://github.com/bahartanir/wp2shell-scanner

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/ananay/wp2shell-lab

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/h4cd0c/wp2shell

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/Iqbalx7/wp2shell

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/gbrsh/CVE-2026-63030

https://github.com/zi3lak/wp2shell_scanner

https://github.com/0xsha/wp2shell

https://github.com/47Cid/wp2shell-lab

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/4minx/CVE-2026-63030

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/imXur/WordPress-CVE-2026-63030-Analysis

https://github.com/NULL200OK/WP2Shell

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/Crypto-Cat/wp2shell

https://github.com/mhtsec/CVE-2026-63030

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/ikow/wp2shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/fullhunt/wp2shell-scan

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/attackercan/wp2shell-poc2

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/mverschu/CVE-2026-63030

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/0xWhoknows/wp2shell

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/kulichr/wp2shell

https://github.com/c0gnit00/Wp2Shell

https://github.com/mcipekci/wp2shell

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/InstaWP/wp2shell-scan

https://github.com/vulnquest58/PressVector

https://github.com/securelayer7/WordPresShell

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/Icex0/wp2shell-poc

https://github.com/dinosn/wp2shell-lab

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

thecybermind@infosec.exchange at 2026-07-24T11:29:34.000Z ##

(CISA TS-SOC) CVE-2026-60137 – WordPress Core SQL Injection Vulnerability

Severity: MEDIUM Impact Summary: Allows unauthenticated attackers to perform SQL injection, which can be chained with CVE-2026-63030 to achieve remote code execution on default WordPress installations....

thecybermind.co/2026/07/24/cis

##

thecybermind@infosec.exchange at 2026-07-24T11:19:33.000Z ##

(CISA TS-SOC) CVE-2026-63030 – WordPress Core Interpretation Conflict Vulnerability

Severity: CRITICAL Impact Summary: An attacker can exploit an interpretation conflict in WordPress Core to perform SQL Injection, which may be chained to achieve Remote Code Execution....

thecybermind.co/2026/07/24/cis

##

Visit counter For Websites