## Updated at UTC 2026-08-17T10:56:17.832344

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-74845 8.8 0.00% 2 0 2026-08-17T10:16:42.403000 Official Document Management System developed by 2100 Technology has an Arbitrar
CVE-2026-15623 0 0.00% 2 0 2026-08-17T07:17:12.020000 A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud G
CVE-2026-72407 10.0 0.19% 2 0 2026-08-17T06:19:07.453000 In the Linux kernel, the following vulnerability has been resolved: geneve: val
CVE-2026-50602 0 0.00% 2 0 2026-08-17T03:16:50.840000 A security vulnerability has been identified in Planet9 due to incorrect file pe
CVE-2026-19961 9.9 0.00% 4 0 2026-08-16T23:16:25.050000 A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function
CVE-2026-19959 9.9 0.00% 4 0 2026-08-16T23:16:24.710000 A weakness has been identified in Edimax EW-7478APC 1.04. This affects the funct
CVE-2026-68820 7.0 0.33% 2 2 2026-08-16T19:17:24.183000 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-74789 7.5 0.00% 1 0 2026-08-16T15:30:38 Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only t
CVE-2026-74788 7.5 0.00% 2 0 2026-08-16T15:30:33 Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memor
CVE-2026-73060 7.5 0.00% 2 0 2026-08-16T15:30:33 Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerabil
CVE-2026-74783 7.5 0.00% 1 0 2026-08-16T15:30:33 Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimi
CVE-2026-74790 9.1 0.00% 1 0 2026-08-16T15:30:27 Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering
CVE-2026-74787 7.5 0.00% 2 0 2026-08-16T15:30:26 Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the obj
CVE-2026-73062 7.5 0.00% 2 0 2026-08-16T15:30:26 Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability i
CVE-2026-74795 7.5 0.00% 1 0 2026-08-16T14:16:57.590000 Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its rec
CVE-2026-74794 7.5 0.00% 1 0 2026-08-16T14:16:57.450000 Scriban before 6.6.0 contains an infinite recursion vulnerability in object rend
CVE-2026-74792 7.5 0.00% 1 0 2026-08-16T14:16:57.317000 Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vuln
CVE-2026-74791 8.6 0.00% 1 0 2026-08-16T14:16:57.183000 Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when Template
CVE-2026-74251 0 0.00% 2 1 2026-08-16T14:16:56.027000 Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filte
CVE-2026-73061 9.8 0.00% 2 0 2026-08-16T14:16:55.770000 Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedOb
CVE-2026-73057 7.5 0.00% 2 0 2026-08-16T14:16:55.230000 stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy en
CVE-2026-73056 9.8 0.00% 3 0 2026-08-16T14:16:55.083000 SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive
CVE-2026-17087 7.5 0.41% 1 0 2026-08-16T09:30:22 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for W
CVE-2026-19714 None 0.16% 1 0 2026-08-16T06:30:37 The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audien
CVE-2026-18432 9.8 0.45% 2 0 2026-08-16T06:30:32 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege
CVE-2026-16099 8.8 0.59% 1 0 2026-08-16T06:30:32 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary fi
CVE-2026-18316 9.1 0.32% 2 0 2026-08-16T06:16:51.683000 The Solace Extra plugin for WordPress is vulnerable to unauthorized modification
CVE-2026-17123 8.8 0.36% 1 0 2026-08-16T05:16:48.033000 The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Req
CVE-2026-16098 9.8 0.64% 2 0 2026-08-16T05:16:47.667000 The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U
CVE-2026-14524 9.1 0.70% 2 0 2026-08-16T05:16:46.493000 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file d
CVE-2026-14498 8.8 0.55% 1 0 2026-08-16T05:16:46.360000 The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution i
CVE-2026-19924 9.8 0.90% 2 0 2026-08-16T02:16:47.247000 A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01
CVE-2026-73053 9.0 0.28% 2 0 2026-08-16T00:31:35 SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th
CVE-2026-73054 7.5 0.31% 1 0 2026-08-16T00:31:35 SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in
CVE-2026-73052 9.0 0.30% 2 0 2026-08-16T00:31:34 SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and
CVE-2026-73055 4.8 0.21% 1 0 2026-08-16T00:31:29 Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (
CVE-2026-73050 9.0 0.25% 1 0 2026-08-16T00:31:28 SiYuan versions before v3.7.4 fail to validate or escape the color field in attr
CVE-2026-73043 9.0 0.37% 1 0 2026-08-16T00:31:26 SiYuan versions before v3.7.4 contain a remote code execution vulnerability in t
CVE-2026-73042 9.0 0.30% 1 0 2026-08-16T00:31:26 SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML int
CVE-2026-73046 9.8 0.43% 1 0 2026-08-15T22:16:54.600000 SiYuan before v3.7.4 improperly restricts excessive authentication attempts in t
CVE-2026-73045 7.5 0.30% 1 0 2026-08-15T22:16:54.463000 SiYuan before 3.7.4 contains an improper restriction of excessive authentication
CVE-2026-73044 9.0 0.25% 1 0 2026-08-15T22:16:54.330000 SiYuan versions before v3.7.4 fail to validate or escape table column width valu
CVE-2026-73041 9.0 0.23% 1 0 2026-08-15T22:16:53.883000 SiYuan versions before v3.7.4 fail to validate or escape annotation fields writt
CVE-2026-18855 9.1 1.21% 1 0 2026-08-15T21:31:01 The Link Library plugin for WordPress is vulnerable to arbitrary file deletion d
CVE-2026-65400 9.8 0.50% 8 0 2026-08-15T04:18:24.470000 An authentication issue was addressed with improved state management. This issue
CVE-2026-19681 9.9 2.24% 2 0 2026-08-14T18:31:46 An authenticated command injection vulnerability exists in Security Center relat
CVE-2026-59310 9.8 1.14% 3 2 2026-08-14T05:16:59.407000 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-19771 7.2 2.79% 2 0 2026-08-14T03:31:33 A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This im
CVE-2026-19747 9.8 2.36% 2 0 2026-08-13T21:36:14 A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B
CVE-2026-62832 7.8 2.37% 2 0 2026-08-13T12:37:51.113000 Improper link resolution before file access ('link following') in Windows User P
CVE-2026-72898 10.0 10.40% 3 6 2026-08-12T15:18:30.347000 Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via t
CVE-2026-49261 10.0 1.58% 1 0 2026-08-12T12:19:36.660000 MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 th
CVE-2026-58231 10.0 0.73% 2 1 2026-08-12T05:17:56.963000 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent
CVE-2026-66804 7.8 3.42% 2 2 2026-08-11T18:31:49 Improper access control in Windows Cross Device Service allows an authorized att
CVE-2026-65775 7.8 2.45% 2 0 2026-08-11T18:31:44 Use after free in Windows Win32K allows an authorized attacker to elevate privil
CVE-2026-62696 7.8 3.17% 2 0 2026-08-11T18:31:18 Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistan
CVE-2026-61358 7.8 3.68% 2 0 2026-08-11T18:31:13 Improper link resolution before file access ('link following') in Windows Access
CVE-2026-6837 7.2 0.95% 2 1 2026-08-04T03:31:16 A post-authentication command injection vulnerability in the "export-cgi" CGI pr
CVE-2026-8452 9.8 0.49% 2 2 2026-07-01T15:52:28.390000 Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp
CVE-2026-44012 0 0.34% 1 0 2026-06-17T10:50:12.640000 Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18,
CVE-2026-42228 6.5 0.38% 1 1 2026-06-17T10:47:32.723000 n8n is an open source workflow automation platform. Prior to versions 1.123.32,
CVE-2026-33696 9.9 0.77% 1 0 2026-03-26T16:41:02 ## Impact An authenticated user with permission to create or modify workflows co
CVE-2024-69414 0 0.00% 2 0 N/A
CVE-2026-73296 0 2.61% 2 0 N/A
CVE-2026-73554 0 0.00% 1 0 N/A

CVE-2026-74845
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-17T10:16:42.403000

2 posts

Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

offseq at 2026-08-17T10:30:25.451Z ##

CVE-2026-74845 (HIGH, CVSS 8.7): 2100 Technology Official Document Management System lets authenticated attackers upload dangerous files — risk of code execution. No patch yet. Limit upload rights & monitor files. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-17T10:30:25.000Z ##

CVE-2026-74845 (HIGH, CVSS 8.7): 2100 Technology Official Document Management System lets authenticated attackers upload dangerous files — risk of code execution. No patch yet. Limit upload rights & monitor files. radar.offseq.com/threat/cve-20 #OffSeq #vuln #infosec #CVE2026_74845

##

CVE-2026-15623
(0 None)

EPSS: 0.00%

updated 2026-08-17T07:17:12.020000

2 posts

A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability was patched in version 6.3.85, and no customer action is needed.

offseq at 2026-08-17T07:30:24.932Z ##

CVE-2026-15623: CRITICAL SQL Injection vuln (CVSS 9.4) in Google Cloud Google SecOps (Chronicle SOAR) <6.3.85. Auth attackers could run blind SQL queries. Google patched server-side — no customer action needed. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-17T07:30:24.000Z ##

CVE-2026-15623: CRITICAL SQL Injection vuln (CVSS 9.4) in Google Cloud Google SecOps (Chronicle SOAR) <6.3.85. Auth attackers could run blind SQL queries. Google patched server-side — no customer action needed. radar.offseq.com/threat/cve-20 #OffSeq #GoogleCloud #Infosec

##

CVE-2026-72407
(10.0 CRITICAL)

EPSS: 0.19%

updated 2026-08-17T06:19:07.453000

2 posts

In the Linux kernel, the following vulnerability has been resolved: geneve: validate inner network offset in geneve_gro_complete() Even with both paths gated on gs->gro_hint, geneve_gro_complete() re-derives the inner dispatch type and length from the packet and the current gs->gro_hint, independently of geneve_gro_receive(). The two can disagree if gs->gro_hint flips under a concurrent geneve_q

jelte@mastodon.nl at 2026-08-17T08:32:47.000Z ##

Say what you will about 'branded' vulnerability disclosures, at least they tend to provide understandable information about the issue, which functionality it concerns, whether you might be affected, and often how to mitigate while waiting for the patch to propagate. As opposed to raw CVEs like cve.org/CVERecord?id=CVE-2026-

##

jelte@mastodon.nl at 2026-08-17T08:32:47.000Z ##

Say what you will about 'branded' vulnerability disclosures, at least they tend to provide understandable information about the issue, which functionality it concerns, whether you might be affected, and often how to mitigate while waiting for the patch to propagate. As opposed to raw CVEs like cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-50602
(0 None)

EPSS: 0.00%

updated 2026-08-17T03:16:50.840000

2 posts

A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 background service. The service runs with SYSTEM privileges, while the affected executable grants excessive permissions to non-administrative users. As a result, an authenticated local user could potentially modify or replace the executable and execute

offseq at 2026-08-17T04:30:23.695Z ##

CVE-2026-50602: HIGH severity (CVSS 8.5) vuln in Acer Planet9 background service 🖥️. Incorrect permissions on SYSTEM-level executable allow local users to escalate privileges. Restrict permissions or disable service until patched. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-17T04:30:23.000Z ##

CVE-2026-50602: HIGH severity (CVSS 8.5) vuln in Acer Planet9 background service 🖥️. Incorrect permissions on SYSTEM-level executable allow local users to escalate privileges. Restrict permissions or disable service until patched. radar.offseq.com/threat/cve-20 #OffSeq #vuln #Infosec

##

CVE-2026-19961
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-16T23:16:25.050000

4 posts

A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

thehackerwire@mastodon.social at 2026-08-17T00:00:43.000Z ##

🔴 CVE-2026-19961 - Critical (9.9)

A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-17T00:00:39.411Z ##

CVE-2026-19961: CRITICAL buffer overflow in Edimax EW-7478APC v1.04 via /goform/formWlSiteSurvey (selSSID). Remote code execution is possible; no patch, public exploit exists. Isolate affected devices. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-17T00:00:43.000Z ##

🔴 CVE-2026-19961 - Critical (9.9)

A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-17T00:00:39.000Z ##

CVE-2026-19961: CRITICAL buffer overflow in Edimax EW-7478APC v1.04 via /goform/formWlSiteSurvey (selSSID). Remote code execution is possible; no patch, public exploit exists. Isolate affected devices. radar.offseq.com/threat/cve-20 #OffSeq #CVE202619961 #IoTSecurity

##

CVE-2026-19959
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-16T23:16:24.710000

4 posts

A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclos

offseq at 2026-08-17T01:30:23.991Z ##

CVE-2026-19959: CRITICAL stack buffer overflow in Edimax EW-7478APC v1.04 (CVSS 9.4). Remote code execution possible. Public exploit out, no fix from vendor. Restrict access or replace device. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-17T00:00:53.000Z ##

🔴 CVE-2026-19959 - Critical (9.9)

A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-17T01:30:23.000Z ##

CVE-2026-19959: CRITICAL stack buffer overflow in Edimax EW-7478APC v1.04 (CVSS 9.4). Remote code execution possible. Public exploit out, no fix from vendor. Restrict access or replace device. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity #infosec

##

thehackerwire@mastodon.social at 2026-08-17T00:00:53.000Z ##

🔴 CVE-2026-19959 - Critical (9.9)

A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68820
(7.0 HIGH)

EPSS: 0.33%

updated 2026-08-16T19:17:24.183000

2 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/HORKimhab/CVE-2026-68820

https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation

youranonnewsirc@nerdculture.de at 2026-08-17T04:26:24.000Z ##

Geopolitical tensions rise with a Middle East conflict stalemate and Israeli retaliatory strikes against Hezbollah in Lebanon. Ukraine's air defense faces threats amid Patriot interceptor depletion and drone attacks on Moscow.

In tech, NVIDIA and SpaceX have forged a significant AI partnership, with massive infrastructure spending projected. Cybersecurity sees the US allowing vetted private companies to conduct offensive cyber operations. Microsoft patched a critical, exploited Windows zero-day (CVE-2026-68820), and Cl0p ransomware leveraged a PTC Windchill flaw impacting nearly 50 firms.

#AnonNews_irc #Cybersecurity #News

##

youranonnewsirc@nerdculture.de at 2026-08-17T04:26:24.000Z ##

Geopolitical tensions rise with a Middle East conflict stalemate and Israeli retaliatory strikes against Hezbollah in Lebanon. Ukraine's air defense faces threats amid Patriot interceptor depletion and drone attacks on Moscow.

In tech, NVIDIA and SpaceX have forged a significant AI partnership, with massive infrastructure spending projected. Cybersecurity sees the US allowing vetted private companies to conduct offensive cyber operations. Microsoft patched a critical, exploited Windows zero-day (CVE-2026-68820), and Cl0p ransomware leveraged a PTC Windchill flaw impacting nearly 50 firms.

#AnonNews_irc #Cybersecurity #News

##

CVE-2026-74789
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T15:30:38

1 posts

Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | array.size }} — or a memory-amplification expression such as {{ 'A' * 200000000 }} — can force large CPU or memory consumption even when LoopLimit is config

thehackerwire@mastodon.social at 2026-08-16T16:01:00.000Z ##

🟠 CVE-2026-74789 - High (7.5)

Scriban before 7.0.0 (affected &lt;= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74788
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T15:30:33

2 posts

Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to .NET's String.PadLeft/PadRight. When an application exposes Scriban to untrusted template input, an attacker can supply an arbitrarily large width value (e.g

hugovalters@mastodon.social at 2026-08-16T18:11:43.000Z ##

CVE-2026-74788 - DoS in Scriban templates via string.pad_left/right. Unvalidated width triggers ~1GB allocations, OOM. CVSS 7.5. Unpatched. Update to 7.0.0 or restrict template access. #CVE #infosec #Scriban

valtersit.com/cve/CVE-2026-747

##

thehackerwire@mastodon.social at 2026-08-16T16:00:50.000Z ##

🟠 CVE-2026-74788 - High (7.5)

Scriban before 7.0.0 (affected versions &lt;= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to ....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73060
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T15:30:33

2 posts

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on lazy sequences to execute billions of uncharged iterations, pinning CPU cores and exhausting garbage collection resources even when LoopLimit is set to 1

thehackerwire@mastodon.social at 2026-08-16T16:02:01.000Z ##

🟠 CVE-2026-73060 - High (7.5)

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T16:02:01.000Z ##

🟠 CVE-2026-73060 - High (7.5)

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74783
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T15:30:33

1 posts

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an uncatchable StackOverflowException that immediately terminates the host process.

thehackerwire@mastodon.social at 2026-08-16T15:01:29.000Z ##

🟠 CVE-2026-74783 - High (7.5)

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74790
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-16T15:30:27

1 posts

Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.

thehackerwire@mastodon.social at 2026-08-16T15:00:08.000Z ##

🔴 CVE-2026-74790 - Critical (9.1)

Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74787
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T15:30:26

2 posts

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the hosting .NET process.

hugovalters@mastodon.social at 2026-08-16T17:07:38.000Z ##

CVE-2026-74787 - Uncontrolled recursion in Scriban's object.to_json. Crafted templates cause stack overflow, crashing .NET apps. CVSS 7.5. No patch yet - mitigate by limiting template input. #CVE #Scriban #infosec

valtersit.com/cve/CVE-2026-747

##

thehackerwire@mastodon.social at 2026-08-16T16:00:37.000Z ##

🟠 CVE-2026-74787 - High (7.5)

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73062
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T15:30:26

2 posts

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multiplier in a template to force multi-gigabyte memory allocations, causing resource exhaustion and availability degradation.

thehackerwire@mastodon.social at 2026-08-16T17:00:36.000Z ##

🟠 CVE-2026-73062 - High (7.5)

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T17:00:36.000Z ##

🟠 CVE-2026-73062 - High (7.5)

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74795
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:57.590000

1 posts

Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so an attacker who controls template input can supply a deeply nested template (e.g., thousands of nested parentheses or blocks) that exhausts thread stack

thehackerwire@mastodon.social at 2026-08-16T15:01:18.000Z ##

🟠 CVE-2026-74795 - High (7.5)

Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74794
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:57.450000

1 posts

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and triggering an uncatchable StackOverflowException that terminates the hosting process.

thehackerwire@mastodon.social at 2026-08-16T15:01:06.000Z ##

🟠 CVE-2026-74794 - High (7.5)

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74792
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:57.317000

1 posts

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInitializer) that is not covered by the ExpressionDepthLimit counter added in the fix for GHSA-wgh7-7m3c-fx25. An attacker who can supply untrusted input to Templat

thehackerwire@mastodon.social at 2026-08-16T15:00:30.000Z ##

🟠 CVE-2026-74792 - High (7.5)

Scriban before 7.0.0 (affected versions &lt;= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74791
(8.6 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:57.183000

1 posts

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again.

thehackerwire@mastodon.social at 2026-08-16T15:00:20.000Z ##

🟠 CVE-2026-74791 - High (8.6)

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74251
(0 None)

EPSS: 0.00%

updated 2026-08-16T14:16:56.027000

2 posts

Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without parameterization or escaping. An unauthenticated attacker can inject arbitrary SQL through these parameters, enabling full database ex

1 repos

https://github.com/toanln-cov/CVE-2026-74251

offseq at 2026-08-17T03:00:28.980Z ##

CVE-2026-74251: Phoca Cart (Joomla ext. v5.0.0 – 6.1.16) suffers CRITICAL SQL injection via unauthenticated a[]/s[] params. Full DB extraction possible. Patch status unclear — check vendor. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-17T03:00:28.000Z ##

CVE-2026-74251: Phoca Cart (Joomla ext. v5.0.0 – 6.1.16) suffers CRITICAL SQL injection via unauthenticated a[]/s[] params. Full DB extraction possible. Patch status unclear — check vendor. radar.offseq.com/threat/cve-20 #OffSeq #SQLInjection #Joomla #Infosec

##

CVE-2026-73061
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-16T14:16:55.770000

2 posts

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.

thehackerwire@mastodon.social at 2026-08-16T17:00:25.000Z ##

🔴 CVE-2026-73061 - Critical (9.8)

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T17:00:25.000Z ##

🔴 CVE-2026-73061 - Critical (9.8)

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73057
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:55.230000

2 posts

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger concurrent requests to exhaust available memory across proxy replicas.

thehackerwire@mastodon.social at 2026-08-16T16:01:49.000Z ##

🟠 CVE-2026-73057 - High (7.5)

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T16:01:49.000Z ##

🟠 CVE-2026-73057 - High (7.5)

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73056
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-16T14:16:55.083000

3 posts

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter, and neither path is protected by the application's CAPTCHA/lockout mechanism (NeedCaptcha/WrongAuthCount). As a result, an

hugovalters@mastodon.social at 2026-08-17T01:04:28.000Z ##

CVE-2026-73056 - Critical auth bypass in SiYuan kernel <3.7.4. Unauthenticated attackers can brute-force API tokens via CheckAuth() middleware, no lockout. CVSS 9.8. Update immediately. #CVE #SiYuan #infosec

valtersit.com/cve/CVE-2026-730

##

thehackerwire@mastodon.social at 2026-08-16T16:01:38.000Z ##

🔴 CVE-2026-73056 - Critical (9.8)

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-16T13:30:26.000Z ##

siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 radar.offseq.com/threat/cve-20 #OffSeq #CVE202673056 #infosec

##

CVE-2026-17087
(7.5 HIGH)

EPSS: 0.41%

updated 2026-08-16T09:30:22

1 posts

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view private booking billing details — including the victim customer's firs

thehackerwire@mastodon.social at 2026-08-16T07:59:50.000Z ##

🟠 CVE-2026-17087 - High (7.5)

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authori...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19714(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-08-16T06:30:37

1 posts

The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the Simple JWT Login WordPress plugin before 3.6.8's Google sign-in enabled is affected.

offseq@infosec.exchange at 2026-08-16T07:30:24.000Z ##

CVE-2026-19714 (CRITICAL): Simple JWT Login <3.6.8 for WordPress fails to validate Google token audiences. Sites with Google sign-in enabled risk admin impersonation & takeover. Disable Google sign-in or update ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202619714

##

CVE-2026-18432
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-08-16T06:30:32

2 posts

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a conditio

offseq@infosec.exchange at 2026-08-16T12:00:24.000Z ##

CVE-2026-18432 (CVSS 9.8): CRITICAL privilege escalation in DynamiApps Frontend Admin <=3.29.9. Unauthenticated attackers can become admins via flawed user ID checks. Restrict access to vulnerable forms & endpoints. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #PrivilegeEscalation #CVE

##

thehackerwire@mastodon.social at 2026-08-16T05:59:59.000Z ##

🔴 CVE-2026-18432 - Critical (9.8)

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16099
(8.8 HIGH)

EPSS: 0.59%

updated 2026-08-16T06:30:32

1 posts

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the

thehackerwire@mastodon.social at 2026-08-16T06:00:47.000Z ##

🟠 CVE-2026-16099 - High (8.8)

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authentic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18316
(9.1 CRITICAL)

EPSS: 0.32%

updated 2026-08-16T06:16:51.683000

2 posts

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies the 'ajax-nonce' nonce, which is emitted on every admin page via wp_localize_script

thehackerwire@mastodon.social at 2026-08-16T06:59:50.000Z ##

🔴 CVE-2026-18316 - Critical (9.1)

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_act...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-16T06:00:23.000Z ##

CVE-2026-18316: CRITICAL auth bypass in Solace Extra WordPress plugin (≤1.6.0). Subscriber-level users can perform destructive actions — no patch yet. Restrict user roles & monitor import_zip() activity. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #CVE202618316

##

CVE-2026-17123
(8.8 HIGH)

EPSS: 0.36%

updated 2026-08-16T05:16:48.033000

1 posts

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render (including a Contributor previewing their own draft), and the wpr_form_builder_webhoo

thehackerwire@mastodon.social at 2026-08-16T05:59:49.000Z ##

🟠 CVE-2026-17123 - High (8.8)

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-control...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16098
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-08-16T05:16:47.667000

2 posts

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, and a post-save extension check that fails to delet

offseq@infosec.exchange at 2026-08-16T10:30:22.000Z ##

CVE-2026-16098 (CRITICAL): ProSolution WP Client <=2.0.10 lets unauthenticated attackers upload dangerous files via nonce leak, leading to remote code execution. Restrict plugin use & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202616098 #Infosec

##

thehackerwire@mastodon.social at 2026-08-16T06:00:11.000Z ##

🔴 CVE-2026-16098 - Critical (9.8)

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Dispo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14524
(9.1 CRITICAL)

EPSS: 0.70%

updated 2026-08-16T05:16:46.493000

2 posts

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-c

offseq@infosec.exchange at 2026-08-16T09:00:23.000Z ##

CRITICAL: CVE-2026-14524 in ProSolution WP Client ≤2.0.8 enables unauthenticated file deletion via path traversal — risking RCE if key files are removed. No patch; restrict or disable plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202614524 #Vuln

##

thehackerwire@mastodon.social at 2026-08-16T06:01:22.000Z ##

🔴 CVE-2026-14524 - Critical (9.1)

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unaut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14498
(8.8 HIGH)

EPSS: 0.55%

updated 2026-08-16T05:16:46.360000

1 posts

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options fully replacing saved query options and being passed directly to call_user_func_arr

thehackerwire@mastodon.social at 2026-08-16T06:00:59.000Z ##

🟠 CVE-2026-14498 - High (8.8)

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_for...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19924
(9.8 CRITICAL)

EPSS: 0.90%

updated 2026-08-16T02:16:47.247000

2 posts

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

thehackerwire@mastodon.social at 2026-08-16T02:59:49.000Z ##

🔴 CVE-2026-19924 - Critical (9.8)

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-16T01:31:24.000Z ##

Tenda AC10 (16.03.10.09_multi_TDE01) hit by CRITICAL auth bypass (CVE-2026-19924) via R7WebsSecurityHandler. Public exploit available — remote compromise possible. Update or restrict access! radar.offseq.com/threat/cve-20 #OffSeq #CVE202619924 #Tenda #Vuln

##

CVE-2026-73053
(9.0 None)

EPSS: 0.28%

updated 2026-08-16T00:31:35

2 posts

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.

offseq@infosec.exchange at 2026-08-16T03:00:23.000Z ##

CVE-2026-73053: CRITICAL XSS in SiYuan (pre-v3.7.4) risks code execution on host via crafted icons when Node integration is enabled. No patch confirmed — disable Node integration or avoid untrusted files. radar.offseq.com/threat/cve-20 #OffSeq #XSS #Vuln #SiYuan

##

thehackerwire@mastodon.social at 2026-08-15T23:00:24.000Z ##

🔴 CVE-2026-73053 - Critical (9)

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73054
(7.5 HIGH)

EPSS: 0.31%

updated 2026-08-16T00:31:35

1 posts

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can craft a malicious WebSocket URI with duplicated query parameters to bypass access auth code validation and receive the live kernel event stream includin

thehackerwire@mastodon.social at 2026-08-15T23:00:36.000Z ##

🟠 CVE-2026-73054 - High (7.5)

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73052
(9.0 None)

EPSS: 0.30%

updated 2026-08-16T00:31:34

2 posts

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.

offseq@infosec.exchange at 2026-08-16T04:30:23.000Z ##

CVE-2026-73052: CRITICAL XSS in SiYuan (<3.7.4) enables arbitrary JS & potential code execution if Node integration is enabled. Desktop users most at risk — upgrade ASAP & disable Node integration where possible. radar.offseq.com/threat/cve-20 #OffSeq #XSS #SiYuan #Infosec

##

thehackerwire@mastodon.social at 2026-08-15T23:00:14.000Z ##

🔴 CVE-2026-73052 - Critical (9)

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73055
(4.8 MEDIUM)

EPSS: 0.21%

updated 2026-08-16T00:31:29

1 posts

Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to "sh" or true and /bin/sh points to BusyBox. Using the escape and escapeAll APIs with untrusted input in an assignment prefixed to a command, an attacker can inject a tilde payload to disclose the user's home directory locat

offseq@infosec.exchange at 2026-08-16T00:00:34.000Z ##

CVE-2026-73055: CRITICAL vuln in ericcornelissen shescape (<2.1.15, 3.0.0<3.0.2). Improper tilde (~) escaping lets attackers leak home dir & alter cmd targets on BusyBox /bin/sh. Avoid untrusted input in escape APIs. Patch pending. radar.offseq.com/threat/cve-20 #OffSeq #CVE202673055 #infosec

##

CVE-2026-73050
(9.0 None)

EPSS: 0.25%

updated 2026-08-16T00:31:28

1 posts

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select field.

thehackerwire@mastodon.social at 2026-08-16T00:00:27.000Z ##

🔴 CVE-2026-73050 - Critical (9)

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73043
(9.0 None)

EPSS: 0.37%

updated 2026-08-16T00:31:26

1 posts

SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the

thehackerwire@mastodon.social at 2026-08-15T23:01:24.000Z ##

🔴 CVE-2026-73043 - Critical (9)

SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and Jav...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73042
(9.0 None)

EPSS: 0.30%

updated 2026-08-16T00:31:26

1 posts

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins due to Electron's insecure configuration.

thehackerwire@mastodon.social at 2026-08-15T23:01:13.000Z ##

🔴 CVE-2026-73042 - Critical (9)

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73046
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-15T22:16:54.600000

1 posts

SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode) as the Basic Auth password but never consults the CAPTCHA/lockout gate or increments the failure counter used by the cookie/session login path. This all

thehackerwire@mastodon.social at 2026-08-16T00:00:17.000Z ##

🔴 CVE-2026-73046 - Critical (9.8)

SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode)...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73045
(7.5 HIGH)

EPSS: 0.30%

updated 2026-08-15T22:16:54.463000

1 posts

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit unbounded password guesses without rate limiting or CAPTCHA to gain access to password-protected published notebooks.

thehackerwire@mastodon.social at 2026-08-16T00:00:07.000Z ##

🟠 CVE-2026-73045 - High (7.5)

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73044
(9.0 CRITICAL)

EPSS: 0.25%

updated 2026-08-15T22:16:54.330000

1 posts

SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of style attributes and inject event handlers on every table cell, executing arbitrary code in the Electron renderer with Node integration enabled.

thehackerwire@mastodon.social at 2026-08-15T23:01:35.000Z ##

🔴 CVE-2026-73044 - Critical (9)

SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73041
(9.0 CRITICAL)

EPSS: 0.23%

updated 2026-08-15T22:16:53.883000

1 posts

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.

thehackerwire@mastodon.social at 2026-08-16T00:01:03.000Z ##

🔴 CVE-2026-73041 - Critical (9)

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18855
(9.1 CRITICAL)

EPSS: 1.21%

updated 2026-08-15T21:31:01

1 posts

The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). E

thehackerwire@mastodon.social at 2026-08-15T19:59:50.000Z ##

🔴 CVE-2026-18855 - Critical (9.1)

The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65400
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-08-15T04:18:24.470000

8 posts

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

offseq at 2026-08-17T09:00:25.989Z ##

CVE-2026-65400 (HIGH) - macOS Screen Sharing vuln lets remote attackers bypass auth and gain root. Active exploitation seen, mainly on systems with port 5900 open. Patch Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9. radar.offseq.com/threat/recent

##

guardingpearsoftware@mastodon.social at 2026-08-17T07:49:29.000Z ##

A recently patched Apple macOS security vulnerability is being actively exploited in the wild to deploy crypto-mining malware, researchers have warned.
The flaw, tracked as CVE-2026-65400, is a critical authentication vulnerability in the Screen Sharing component and could allow an attacker to gain root access.

##

security_crawler_carl at 2026-08-16T21:07:35.972Z ##

🏆 New Achievement! Screen Sharing Is Caring (About My Monero Wallet)!

Allow me to monologue, as any proper villain must. CVE-2026-65400 — a gorgeous authentication bypass in macOS Screen Sharing — handed attackers root access through port 5900, wide open to the internet like a velvet rope with no bouncer. Apple patched it August 6 in macOS Tahoe 26.6.1. You simply... did not apply it. Delicious. (1/2)

##

offseq@infosec.exchange at 2026-08-17T09:00:25.000Z ##

CVE-2026-65400 (HIGH) - macOS Screen Sharing vuln lets remote attackers bypass auth and gain root. Active exploitation seen, mainly on systems with port 5900 open. Patch Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9. radar.offseq.com/threat/recent #OffSeq #macOS #infosec #vuln

##

security_crawler_carl@infosec.exchange at 2026-08-16T21:07:35.000Z ##

🏆 New Achievement! Screen Sharing Is Caring (About My Monero Wallet)!

Allow me to monologue, as any proper villain must. CVE-2026-65400 — a gorgeous authentication bypass in macOS Screen Sharing — handed attackers root access through port 5900, wide open to the internet like a velvet rope with no bouncer. Apple patched it August 6 in macOS Tahoe 26.6.1. You simply... did not apply it. Delicious. (1/2)

##

threatnoir@infosec.exchange at 2026-08-16T15:05:44.000Z ##

⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

tomshardware@mastodon.online at 2026-08-16T13:04:06.000Z ##

Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks

The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
#hardware
tomshardware.com/tech-industry

##

beyondmachines1@infosec.exchange at 2026-08-16T11:01:08.000Z ##

Apple Patches Actively Exploited macOS Screen Sharing Vulnerability Used in Crypto Mining Attacks

Apple patched a macOS Screen Sharing vulnerability (CVE-2026-65400) that allows remote attackers to bypass authentication and gain root access. Attackers are actively exploiting the flaw to install Monero crypto miners on systems with port 5900 exposed to the internet.

**If you use a Mac, update macOS now to Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 to fix CVE-2026-65400, which attackers are already using to take full control of Macs without a password. Also turn off Screen Sharing when you don't need it and make sure port 5900 is not reachable from the internet.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-19681
(9.9 CRITICAL)

EPSS: 2.24%

updated 2026-08-14T18:31:46

2 posts

An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.

secdb at 2026-08-17T00:02:24.594Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-17T00:02:24.000Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 1.14%

updated 2026-08-14T05:16:59.407000

3 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

2 repos

https://github.com/BiuTrap/CVE-2026-59310

https://github.com/HORKimhab/CVE-2026-59310

guru@thecybersecguru.com at 2026-08-17T08:31:43.000Z ##

The Anatomy of the VMware vCenter Syslog Exploitation and the Babuk ESXi Ransomware Campaign

VMware vCenter CVE-2026-59310 is being actively exploited to compromise vCenter servers and deploy Babuk-derived ransomware on ESXi hosts

thecybersecguru.com/news/vmwar

##

patrickcmiller@infosec.exchange at 2026-08-16T12:12:01.000Z ##

vCenter Flaw Exploited Just Five Days After Disclosure infosecurity-magazine.com/news

##

threatnoir@infosec.exchange at 2026-08-16T05:15:04.000Z ##

2026-W33 — Weekly Threat Roundup

🔥 VMware vCenter RCE (CVE-2026-59310) under active APT exploitation across 47 countries, patch and hunt for persistence now.
🤖 Near-autonomous AI cyberattack observed against Taiwan's government, adapting mid-operation without human direction.
💀 Lazarus Group's Operation Dream Job exploits Windo…

threatnoir.com/weekly/2026-w33

#infosec #cybersecurity #threatintel

🤖 AI generated summary

##

CVE-2026-19771
(7.2 HIGH)

EPSS: 2.79%

updated 2026-08-14T03:31:33

2 posts

A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure bu

secdb at 2026-08-17T00:02:24.594Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-17T00:02:24.000Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19747
(9.8 CRITICAL)

EPSS: 2.36%

updated 2026-08-13T21:36:14

2 posts

A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely.

secdb at 2026-08-17T00:02:24.594Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-17T00:02:24.000Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-62832
(7.8 HIGH)

EPSS: 2.37%

updated 2026-08-13T12:37:51.113000

2 posts

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

secdb at 2026-08-17T00:02:24.594Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-17T00:02:24.000Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-72898
(10.0 CRITICAL)

EPSS: 10.40%

updated 2026-08-12T15:18:30.347000

3 posts

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

6 repos

https://github.com/0xBlackash/CVE-2026-72898

https://github.com/Franc-Zar/CVE-2026-72898-safe-detection

https://github.com/4minx/CVE-2026-72898

https://github.com/VuxNx/CVE-2026-72898

https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix

https://github.com/codeb0ssx/CVE-2026-72898-PoC

sayzard@mastodon.sayzard.org at 2026-08-17T00:38:41.000Z ##

The Metabase SQLi: Exploited in the Wild

Metabase Cloud를 대상으로 실제 악용된 제로데이 SQL 인젝션 취약점(CVE-2026-72898)이 공개됐으며, 자체 호스팅 인스턴스도 즉시 패치가 필요하다. 취약점은 `/api/session/reset_password`에서 요청 JSON의 추가 `user-id` 필드가 인증 결과와 병합되는 과정에서 살아남고, HoneySQL의 `:raw` 표현을 통해 비매개변수화 SQL로 전달되는 구조다. 영향 버전은 1.58 이후이며, Wiz는 취약 버전 0.58.22와 수정 버전 0.58.24의 JAR 디프·디컴파일을 AI 에이전트로 분석해 원인을 재구성했다고 설명했다. Metab...

wiz.io/blog/inside-the-metabas

##

secdb at 2026-08-17T00:02:24.594Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-17T00:02:24.000Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-49261
(10.0 CRITICAL)

EPSS: 1.58%

updated 2026-08-12T12:19:36.660000

1 posts

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should

ransomnews.online@bsky.brid.gy at 2026-08-15T19:00:05.000Z ##

🚨 Critical #MariaDB flaw enables remote code execution

CVE-2026-49261 can run arbitrary commands on vulnerable servers.
🔗 read more: securityonline.info/...

#ransomNews #cybersecurity

##

CVE-2026-58231
(10.0 CRITICAL)

EPSS: 0.73%

updated 2026-08-12T05:17:56.963000

2 posts

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

1 repos

https://github.com/HORKimhab/CVE-2026-58231

undercodenews@mastodon.social at 2026-08-17T06:18:14.000Z ##

SAP Commerce Cloud Under Attack: Critical CVE-2026-58231 Draws Active Exploitation Attempts Just Days After Patch Release

A Maximum-Severity Flaw Has Entered the Attacker Crosshairs Enterprise security teams are once again facing a familiar but increasingly dangerous race: vendors release a critical security patch, defenders begin testing it, and attackers immediately start looking for systems that have not yet been updated. That is now the situation surrounding…

undercodenews.com/sap-commerce

##

hackerdogs@mastodon.social at 2026-08-15T22:45:34.000Z ##

Attackers are actively exploiting a maximum severity vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231, just days after SAP released a patch. The flaw is a remote code execution vulnerabi
securityaffairs.com/197244/sec
#cybersecurity #vulnerability #SAP

##

CVE-2026-66804
(7.8 HIGH)

EPSS: 3.42%

updated 2026-08-11T18:31:49

2 posts

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/Rat5ak/CVE-2026-66804-CrossDevice-Service-EoP

https://github.com/DavidCarliez/CVE-2026-66804-CrossDevice-LPE

secdb at 2026-08-17T00:02:24.594Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-17T00:02:24.000Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-65775
(7.8 HIGH)

EPSS: 2.45%

updated 2026-08-11T18:31:44

2 posts

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

secdb at 2026-08-17T00:02:24.594Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-17T00:02:24.000Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-62696
(7.8 HIGH)

EPSS: 3.17%

updated 2026-08-11T18:31:18

2 posts

Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

secdb at 2026-08-17T00:02:24.594Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-17T00:02:24.000Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-61358
(7.8 HIGH)

EPSS: 3.68%

updated 2026-08-11T18:31:13

2 posts

Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

secdb at 2026-08-17T00:02:24.594Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-17T00:02:24.000Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-6837
(7.2 HIGH)

EPSS: 0.95%

updated 2026-08-04T03:31:16

2 posts

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

1 repos

https://github.com/minanagehsalalma/CVE-2026-6837-zyxel-export-cgi-command-injection

_r_netsec at 2026-08-16T18:58:05.526Z ##

CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling minanagehsalalma.github.io/CVE

##

_r_netsec@infosec.exchange at 2026-08-16T18:58:05.000Z ##

CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling minanagehsalalma.github.io/CVE

##

CVE-2026-8452
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-07-01T15:52:28.390000

2 posts

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

2 repos

https://github.com/derekpreston81/CVE_ADC_IOC_2026

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

CVE-2026-44012
(0 None)

EPSS: 0.34%

updated 2026-06-17T10:50:12.640000

1 posts

Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filename and complete folder hierarchy (including volume handle, volume UID, folder names, folder UIDs, and folder URI paths) without checking whether the requesting user has viewAssets or viewPeerAssets permission on the asset’s volume. Any

cvedatabase@techhub.social at 2026-08-17T10:30:03.000Z ##

🛡️ Weekly CVE Roundup is live! We're diving deep into the critical RCE found in Fast-API-Router (CVE-2026-44012) and discussing the broader trend of API vulnerabilities. Protect your supply chain and patch today. Full details: cvedatabase.com/blog/weekly-cv #InfoSec #CyberSecurity #CVE #APISecurity #FastAPIRouter #PatchTuesday

##

CVE-2026-42228
(6.5 MEDIUM)

EPSS: 0.38%

updated 2026-06-17T10:47:32.723000

1 posts

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized to interact with the target execution. An unauthenticated remote attacker who could identify a valid execution ID for a workflow in a waiting state could attach

1 repos

https://github.com/rudSarkar/CVE-2026-42228

sayzard@mastodon.sayzard.org at 2026-08-16T17:39:34.000Z ##

Breaking AI Orchestration: Hijacking N8n HITL Chat Sessions

n8n의 HITL Chat 노드에서 인증 없이 활성 WebSocket 채팅 세션을 탐색·도청·메시지 주입할 수 있는 취약점이 발견됐다. 순차적인 executionId와 공개된 `/form-waiting` 상태 오라클, 클라이언트가 임의 지정 가능한 sessionId가 결합돼 실행 중인 에이전트 대화를 탈취할 수 있으며, 에이전트가 반환하는 도구 결과·검색 컨텍스트 등의 노출 및 대화 조작으로 이어질 수 있다. 이 이슈는 CVE-2026-42228(CVSS 6.3, Moderate)로 수정됐으며, n...

zerolabs.rubrik.com/blog/break

##

CVE-2026-33696
(9.9 CRITICAL)

EPSS: 0.77%

updated 2026-03-26T16:41:02

1 posts

## Impact An authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the GSuiteAdmin node. By supplying a crafted parameter as part of node configuration, an attacker could write attacker-controlled values onto `Object.prototype`. An attacker could use this prototype pollution to achieve remote code execution on the n8n instance. ## Pa

CVE-2024-69414
(0 None)

EPSS: 0.00%

2 posts

N/A

security_crawler_carl at 2026-08-17T09:36:52.067Z ##

🏆 New Achievement! Your Antivirus Has a Virus Problem!

PATCH NOTES v0.0.0 — KNOWN ISSUES: Microsoft Defender, the product specifically designed to protect you from threats, is currently a threat. The Microsoft Malware Protection Engine contains a zero-day tracked as CVE-2024-69414, nicknamed ShieldBreak, which attackers in the wild are actively using to elevate their privileges. Think of it as a DLC nobody ordered.

ADDED: Unauthorized privilege escalation. FIXED: Nothing yet. (1/2)

##

security_crawler_carl@infosec.exchange at 2026-08-17T09:36:52.000Z ##

🏆 New Achievement! Your Antivirus Has a Virus Problem!

PATCH NOTES v0.0.0 — KNOWN ISSUES: Microsoft Defender, the product specifically designed to protect you from threats, is currently a threat. The Microsoft Malware Protection Engine contains a zero-day tracked as CVE-2024-69414, nicknamed ShieldBreak, which attackers in the wild are actively using to elevate their privileges. Think of it as a DLC nobody ordered.

ADDED: Unauthorized privilege escalation. FIXED: Nothing yet. (1/2)

##

CVE-2026-73296
(0 None)

EPSS: 2.61%

2 posts

N/A

secdb at 2026-08-17T00:02:24.594Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-17T00:02:24.000Z ##

📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222

Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183

CISA KEVs:
- CISA-2026:0811 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93

Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136

Top EPSS Score:
- CVE-2026-72898 - 10.40 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-61358 - 3.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66804 - 3.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62696 - 3.18 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19771 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73296 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65775 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62832 - 2.37 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19747 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19681 - 2.24 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-73554
(0 None)

EPSS: 0.00%

1 posts

N/A

cyberveille@mastobot.ping.moi at 2026-08-17T00:00:06.000Z ##

📢 Bypass d'authentification critique dans Dolt MCP : exécution d'outils sans authentification

Cet article présente la découverte et la divulgation coordonnée d'une vulnérabilité critique d'authentification bypass dans le serveur MCP distant de DoltHub (CVE-2026-73554). La vulnérabilité affecte Dolt MCP versions 0.3.1 à 0.3.6 sur le transport HTTP distant lorsque…

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : pillar.security/blog/lose-cont
🟡 vérification factuelle moyenne
#Dolt #MCP #Cyberveille

##

Visit counter For Websites