## Updated at UTC 2026-08-27T00:14:01.845137

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-77368 7.6 0.00% 2 0 2026-08-26T22:16:29.860000 SeaweedFS is a distributed storage system for files and blobs. In version 4.39,
CVE-2026-77317 8.1 0.00% 2 0 2026-08-26T22:16:29.717000 SeaweedFS is a distributed storage system for files and blobs. In versions from
CVE-2026-61617 7.7 0.00% 2 0 2026-08-26T22:16:25.247000 Wings is the server control plane for the Pterodactyl game-server management pan
CVE-2026-58084 5.5 0.14% 2 0 2026-08-26T21:32:32 To retrieve the previous timer value, the kernel calls realtimer_gettime(), whic
CVE-2026-68863 7.5 0.00% 2 0 2026-08-26T21:31:52 Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer
CVE-2026-68861 8.8 0.00% 2 0 2026-08-26T21:31:52 Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutrali
CVE-2026-74770 8.8 0.00% 2 0 2026-08-26T21:31:52 Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutrali
CVE-2026-77652 7.8 0.00% 2 0 2026-08-26T21:31:52 A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG
CVE-2026-79938 7.6 0.00% 2 0 2026-08-26T21:31:52 Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Au
CVE-2026-70419 9.1 0.00% 2 0 2026-08-26T21:31:47 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutr
CVE-2026-68569 8.1 0.26% 2 0 2026-08-26T21:31:41 Improper Authentication vulnerability in Apache Tomcat meant that in some circum
CVE-2026-79074 5.3 0.22% 1 0 2026-08-26T21:31:35 Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a re
CVE-2026-55228 8.1 0.00% 2 0 2026-08-26T21:16:38.737000 Weblate is a web-based continuous localization platform used to manage software
CVE-2026-76193 10.0 0.62% 1 0 2026-08-26T20:18:00.307000 Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF)
CVE-2026-58093 7.0 0.13% 2 0 2026-08-26T20:17:55.563000 The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process t
CVE-2026-46369 7.5 0.00% 2 0 2026-08-26T20:17:23.163000 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the
CVE-2026-19632 9.8 0.79% 2 2 2026-08-26T20:17:10.020000 The TranslatePress – Translate Multilingual sites with AI Translation plugin for
CVE-2026-65084 8.1 0.32% 2 0 2026-08-26T19:16:52.447000 NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, wh
CVE-2026-81029 8.1 0.00% 2 0 2026-08-26T18:32:05 OpenMetadata accepts a caller-supplied post-authentication redirect target and a
CVE-2026-81027 8.5 0.00% 2 0 2026-08-26T18:32:05 one-api gates one of its two channel-pinning paths and not the other. middleware
CVE-2026-80428 9.8 0.00% 2 0 2026-08-26T18:32:05 ILIAS deserialises stored session data for an unauthenticated caller. The Shibbo
CVE-2026-81036 8.1 0.00% 2 0 2026-08-26T18:32:05 Stalwart Mail Server does not compare an OAuth redirect target against any regis
CVE-2026-81035 8.1 0.00% 2 0 2026-08-26T18:32:05 Midday allows any member of a team to delete it. The delete procedure in apps/ap
CVE-2026-58474 8.8 0.00% 2 0 2026-08-26T18:32:04 whichllm before 0.5.16 contains a code injection vulnerability in the run and sn
CVE-2026-75896 9.1 0.00% 2 0 2026-08-26T18:32:04 Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technolog
CVE-2026-18252 7.3 0.00% 2 0 2026-08-26T18:32:04 GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 bef
CVE-2026-58092 5.4 0.14% 2 0 2026-08-26T18:32:01 In FreeBSD 15.0, the kernel structure used to represent user credentials changed
CVE-2026-58090 7.8 0.16% 2 0 2026-08-26T18:31:55 The SOCK_STREAM receive path in the unix socket implementation failed to fully d
CVE-2026-78899 8.8 0.46% 1 0 2026-08-26T18:31:36 Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote at
CVE-2026-79992 7.8 0.13% 2 0 2026-08-26T18:31:35 A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerabili
CVE-2019-1068 8.8 44.66% 4 2 2026-08-26T18:31:30 A remote code execution vulnerability exists in Microsoft SQL Server when it inc
CVE-2015-5287 7.8 3.41% 4 0 2026-08-26T18:31:30 The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.
CVE-2026-8452 9.8 1.04% 4 3 2026-08-26T18:30:34 Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp
CVE-2022-0995 7.1 6.34% 4 4 2026-08-26T18:30:28 An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_q
CVE-2015-3246 5.1 7.09% 4 0 2026-08-26T18:30:27 libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper progr
CVE-2026-81032 9.8 0.00% 2 0 2026-08-26T18:17:05.890000 NebulaGraph exposes its runtime configuration over an unauthenticated HTTP servi
CVE-2026-75960 8.1 0.00% 4 0 2026-08-26T18:17:01.453000 Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently
CVE-2026-54569 9.8 0.00% 2 0 2026-08-26T18:16:40.930000 SENAITE.CORE is the core framework for the SENAITE laboratory information manage
CVE-2026-32258 8.1 0.00% 2 0 2026-08-26T18:16:27.550000 Winter is a free, open-source content management system (CMS) based on the Larav
CVE-2026-80427 8.4 0.00% 2 0 2026-08-26T17:17:26.120000 bestzip builds the argument list for the system zip utility without separating o
CVE-2026-78901 7.5 0.24% 1 0 2026-08-26T17:01:18.043000 Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote at
CVE-2026-58083 8.4 0.12% 2 0 2026-08-26T16:54:50.030000 While the kernel was copying knotes during fork, a knote with a timer-based filt
CVE-2026-16783 7.8 0.13% 1 0 2026-08-26T16:46:22.330000 A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force
CVE-2026-75768 7.8 0.17% 2 0 2026-08-26T16:45:12.020000 Substance3D - Painter is affected by an Untrusted Search Path vulnerability that
CVE-2026-77995 0 0.29% 1 0 2026-08-26T16:36:16.990000 Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAu
CVE-2026-76565 0 0.32% 1 1 2026-08-26T16:35:20.160000 Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter par
CVE-2026-77994 0 0.23% 1 0 2026-08-26T16:35:20.160000 Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK <
CVE-2026-74932 7.5 0.22% 2 0 2026-08-26T16:30:52.723000 The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host he
CVE-2026-18431 9.8 0.64% 4 0 2026-08-26T16:19:05.917000 The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versi
CVE-2026-79911 10.0 0.64% 2 0 2026-08-26T16:19:05.917000 A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210
CVE-2026-32556 7.1 0.15% 1 0 2026-08-26T16:19:05.917000 Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
CVE-2026-65092 8.5 0.45% 2 0 2026-08-26T16:16:35.933000 NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker co
CVE-2026-65105 8.1 0.30% 3 0 2026-08-26T15:16:51.040000 NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup
CVE-2026-65096 7.8 0.69% 2 0 2026-08-26T15:16:50.467000 NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge compon
CVE-2026-54511 8.6 0.00% 2 0 2026-08-26T14:28:05 `@logtape/syslog` contains two related output-encoding bugs in the structured da
CVE-2026-54523 9.6 0.00% 2 0 2026-08-26T14:21:54 ## Summary In Kyverno v1.18.1, a tenant who can create a `NamespacedMutatingPol
CVE-2026-73108 7.5 0.00% 2 0 2026-08-26T14:17:12.830000 RustDesk versions before 1.4.7 contain an uncontrolled speculative memory alloca
CVE-2026-77532 9.6 0.00% 2 0 2026-08-26T13:19:20.413000 A malicious actor with access to an adjacent network could exploit a Buffer Over
CVE-2026-54757 7.8 0.25% 2 0 2026-08-26T13:19:16.497000 Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing
CVE-2026-19913 7.5 0.19% 2 1 2026-08-26T13:17:47.880000 The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure v
CVE-2026-80138 9.8 0.80% 2 0 2026-08-26T00:31:14 ClipBucket V5's web installer fails to properly validate or escape the php_cli_f
CVE-2026-79912 8.3 1.40% 2 0 2026-08-26T00:31:14 A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impac
CVE-2026-80186 7.6 0.41% 2 0 2026-08-26T00:31:09 A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth
CVE-2026-80104 9.8 0.71% 2 0 2026-08-25T21:31:58 DB-GPT builds the destination path for an uploaded skill from the multipart file
CVE-2026-79021 None 0.23% 1 0 2026-08-25T21:31:45 Missing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65
CVE-2026-65099 7.8 0.69% 2 0 2026-08-25T21:31:39 NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface
CVE-2026-65093 9.9 0.49% 4 0 2026-08-25T21:31:36 NVIDIA OpenShell for Linux contains a vulnerability where an attacker could caus
CVE-2026-65081 8.1 0.25% 2 0 2026-08-25T21:31:35 NVIDIA NemoClaw for Linux contains a vulnerability in its installation process,
CVE-2026-65090 7.8 0.69% 2 0 2026-08-25T21:31:35 NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management compone
CVE-2026-65089 7.8 0.69% 2 0 2026-08-25T21:31:35 NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin
CVE-2026-65098 8.1 0.57% 2 0 2026-08-25T21:31:35 NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper w
CVE-2026-66153 None 0.20% 2 0 2026-08-25T21:31:35 The NEService auto-upgrade process insecurely handles temporary files in SonicWa
CVE-2026-66152 None 0.20% 2 0 2026-08-25T21:31:35 A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Li
CVE-2026-65091 8.8 1.36% 2 0 2026-08-25T21:31:35 NVIDIA OpenShell for all platforms contains a vulnerability where a malicious ga
CVE-2026-65097 7.5 0.20% 2 0 2026-08-25T21:31:34 NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts,
CVE-2026-65083 9.9 0.51% 2 0 2026-08-25T21:31:31 NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning
CVE-2026-80049 8.8 0.34% 2 0 2026-08-25T20:17:08.627000 Airbyte Platform resolves the workspace used for its authorization decision from
CVE-2026-75501 7.5 0.59% 1 0 2026-08-25T20:17:04.150000 A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residentia
CVE-2026-55099 7.5 0.38% 2 0 2026-08-25T19:27:32 ### Summary `Component.__eq__` compares subcomponents in `O(2^n)` time relative
CVE-2026-45018 9.8 0.65% 2 0 2026-08-25T19:19:28 ### Am I affected? Only if your deployment sets `features.mcp.enabled = true` i
CVE-2026-76197 10.0 1.47% 6 0 2026-08-25T18:32:01 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-79784 8.8 0.32% 2 0 2026-08-25T18:32:01 Vocos instantiates a class named by a configuration file without restricting whi
CVE-2026-19912 None 0.22% 2 1 2026-08-25T18:32:01 The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote
CVE-2026-79774 8.4 0.43% 2 0 2026-08-25T18:32:00 Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox e
CVE-2026-79675 9.8 0.40% 2 0 2026-08-25T18:31:56 NLTK before 3.10.3 fails to validate JVM options passed through the per-call opt
CVE-2026-55538 7.3 0.26% 1 0 2026-08-25T17:17:31.403000 PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai se
CVE-2026-18798 7.5 1.48% 2 0 2026-08-25T15:33:06 Issue summary: QUIC server may double free QRX (QUIC record layer RX) object whe
CVE-2026-57863 8.8 0.57% 2 0 2026-08-25T15:16:35.297000 Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self
CVE-2026-55540 7.1 0.27% 1 0 2026-08-25T14:54:57 ### Summary PraisonAI's `praisonai.code` tool wrappers (exported as `CODE_TOOLS`
CVE-2026-57910 0 0.20% 4 0 2026-08-25T13:19:24.810000 Improper authentication in the WatchGuard Agent allows an unauthenticated attack
CVE-2026-78570 9.8 0.40% 2 0 2026-08-25T12:31:29 The Total Donations plugin for WordPress is vulnerable to Privilege Escalation i
CVE-2026-57909 None 0.29% 4 0 2026-08-25T12:31:24 A path traversal vulnerability in WatchGuard Agent allows a remote, unauthentica
CVE-2026-78563 7.2 0.19% 1 0 2026-08-25T09:30:48 The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Sc
CVE-2026-78568 9.8 0.30% 2 0 2026-08-25T09:30:48 The Total Donations plugin for WordPress is vulnerable to SQL Injection in all v
CVE-2026-77136 None 0.55% 2 0 2026-08-25T09:30:47 The extension passes the raw value of a form field configured as "This field con
CVE-2026-63586 9.8 0.52% 4 0 2026-08-25T09:30:47 The web-based management interface uses a modified uhttpd server with CGI shell
CVE-2026-67578 7.5 0.30% 2 0 2026-08-25T09:30:42 FA-50 all versions miss authentication for some configuration. An attacker with
CVE-2026-59769 9.1 0.33% 3 0 2026-08-25T09:30:42 FA-50 all versions contain hard-coded credentials. An attacker, who knows the cr
CVE-2026-71366 7.7 0.33% 1 0 2026-08-25T09:30:36 A server-side request forgery (SSRF) vulnerability was found in multiple AWX not
CVE-2026-63587 8.6 0.27% 2 0 2026-08-25T09:17:32.057000 The SMS control function of IE-SR-2TX-WL-4G devices can require a password for S
CVE-2026-78477 9.8 0.30% 1 0 2026-08-25T06:31:36 The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versio
CVE-2026-9254 0 2.35% 1 1 2026-08-25T04:18:21.457000 An unauthenticated OS command injection vulnerability exists in the parental con
CVE-2026-61419 7.8 0.09% 1 0 2026-08-25T04:18:15.290000 Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Contr
CVE-2026-41992 7.5 0.35% 2 0 2026-08-25T04:18:11.393000 GNU gzip contains a global buffer overflow vulnerability in the LZH decompressio
CVE-2026-78676 9.8 0.40% 3 0 2026-08-25T03:32:20 GitPython before 3.1.59 fails to safely re-serialize multi-line git-config value
CVE-2026-72702 5.4 0.10% 1 0 2026-08-25T03:32:14 Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer
CVE-2026-78264 7.1 0.15% 1 0 2026-08-25T00:30:37 Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
CVE-2026-78265 9.8 0.31% 2 0 2026-08-25T00:30:37 Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CVE-2026-78267 9.8 0.27% 2 0 2026-08-25T00:30:37 Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVE-2026-78268 7.5 0.25% 1 0 2026-08-25T00:30:37 Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp;
CVE-2026-78284 8.6 0.35% 1 0 2026-08-25T00:30:37 Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
CVE-2026-19874 9.1 0.73% 4 1 2026-08-24T21:34:43 A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online
CVE-2026-19685 9.8 0.14% 1 0 2026-08-24T21:34:43 NetworkManager did not apply the private_user restriction to the 802-1x.ca-path
CVE-2026-19568 7.8 0.13% 1 0 2026-08-24T21:33:53 A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force
CVE-2026-7455 7.8 0.13% 1 0 2026-08-24T21:33:53 A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force
CVE-2026-78541 None 0.96% 1 0 2026-08-24T21:33:52 A stored OS command injection vulnerability exists in the parent-control module
CVE-2026-71506 8.1 0.30% 1 1 2026-08-24T21:33:43 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the p
CVE-2026-21962 10.0 42.02% 22 9 2026-08-24T21:33:31 Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in pr
CVE-2026-76835 9.1 0.35% 1 0 2026-08-24T20:17:19.623000 OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whet
CVE-2026-63310 7.1 0.11% 1 0 2026-08-24T20:16:55.243000 NLTK before 3.9.3 fails to verify file integrity after downloading packages and
CVE-2026-76838 8.5 0.31% 1 0 2026-08-24T18:32:04 Hi.Events validates a webhook destination only when it is registered, never when
CVE-2026-16348 None 0.91% 1 1 2026-08-24T18:31:59 An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allo
CVE-2026-76071 9.8 1.06% 1 1 2026-08-24T18:31:59 Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow v
CVE-2026-76070 9.8 1.00% 1 1 2026-08-24T18:31:58 Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow v
CVE-2026-76073 8.8 0.28% 1 0 2026-08-24T18:31:57 Label Studio does not scope the annotation detail endpoint to the requesting use
CVE-2026-78209 8.2 0.29% 1 0 2026-08-24T18:17:31.060000 exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus,
CVE-2026-78169 9.9 0.44% 2 0 2026-08-24T16:41:13.950000 A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This
CVE-2026-78168 9.8 0.93% 2 0 2026-08-24T16:40:53.647000 A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0.
CVE-2026-59568 9.1 0.38% 4 0 2026-08-24T15:31:57 Multiple vulnerabilities on affected versions of Zscaler Client Connector allow
CVE-2025-15467 8.8 48.21% 2 6 2026-08-24T13:16:48.920000 Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with malic
CVE-2026-8173 5.3 0.21% 1 0 2026-08-24T09:33:52 The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from t
CVE-2026-78211 9.8 1.54% 1 0 2026-08-24T06:30:35 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injec
CVE-2026-78170 8.8 0.44% 1 0 2026-08-24T03:31:14 A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the fu
CVE-2026-78167 10.0 1.03% 1 0 2026-08-24T03:31:14 A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted eleme
CVE-2026-78208 7.5 0.37% 1 0 2026-08-24T03:31:14 exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Wor
CVE-2026-78207 9.4 0.44% 1 0 2026-08-24T03:31:14 exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in th
CVE-2026-7808 9.8 0.35% 1 0 2026-08-23T15:33:12 justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that ca
CVE-2026-8445 9.8 0.38% 1 0 2026-08-23T15:33:12 justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-si
CVE-2026-63312 7.5 0.49% 1 0 2026-08-22T15:31:11 NLTK before 3.10.0 contains an arbitrary local file read vulnerability in Stream
CVE-2026-64531 7.8 0.38% 1 4 2026-08-22T06:31:25 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-27875 0 0.07% 2 0 2026-08-21T21:16:56.500000 Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Co
CVE-2026-77413 None 0.41% 2 0 2026-08-21T20:57:09 ## Impact Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitra
CVE-2026-17250 None 0.19% 1 0 2026-08-21T18:35:07 A stack-based buffer overflow vulnerability exists in the firmware update functi
CVE-2026-73570 8.9 1.51% 9 4 template 2026-08-21T18:34:48 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-54796 7.2 2.36% 1 0 2026-08-21T17:56:59.057000 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutra
CVE-2026-69836 10.0 1.55% 7 2 2026-08-21T00:31:31 Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a
CVE-2026-19586 None 5.04% 2 0 2026-08-20T21:31:30 A pre-authentication OS command injection vulnerability has been identified in O
CVE-2026-18264 8.8 1.24% 1 0 2026-08-20T18:30:55 NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vu
CVE-2026-19598 9.8 2.46% 1 4 template 2026-08-20T12:48:10.287000 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to
CVE-2026-15748 9.8 4.61% 1 3 2026-08-20T12:48:10.287000 The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload
CVE-2026-75616 None 1.91% 1 1 2026-08-19T21:30:40 An OS command injection vulnerability exists in the web management interface of
CVE-2026-16835 9.6 0.22% 1 0 2026-08-19T21:30:30 IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 thr
CVE-2026-16687 9.6 0.21% 1 0 2026-08-19T21:30:30 IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 thr
CVE-2026-74480 9.8 0.56% 1 0 2026-08-19T18:33:34 In the Linux kernel, the following vulnerability has been resolved: net: bridge
CVE-2026-75149 8.8 0.64% 1 0 2026-08-19T18:33:02 marimo before 0.23.15 contains a code injection vulnerability in the notebook co
CVE-2026-69414 7.8 0.56% 2 2 2026-08-19T18:32:28 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-71961 8.8 3.05% 1 0 2026-08-19T15:32:47 Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection
CVE-2026-54795 8.8 2.39% 1 0 2026-08-19T15:32:33 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutra
CVE-2026-14669 8.8 0.58% 1 1 2026-08-19T14:56:57.477000 Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosin
CVE-2026-33824 9.8 72.69% 1 2 2026-08-19T04:16:58.560000 Double free in Windows IKE Extension allows an unauthorized attacker to execute
CVE-2026-18963 9.1 2.79% 12 8 template 2026-08-19T03:31:21 A flaw was found in the reset-credentials flow of the keycloak-services componen
CVE-2026-17084 None 0.48% 1 0 2026-08-19T03:31:21 The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B
CVE-2026-55040 9.1 5.58% 7 3 template 2026-08-18T18:32:50 Weak authentication in Microsoft Office SharePoint allows an unauthorized attack
CVE-2026-24301 8.8 2.22% 1 1 2026-08-18T15:31:45 Improper neutralization of special elements used in a command ('command injectio
CVE-2026-53365 5.5 0.17% 1 2 2026-08-18T15:31:16 In the Linux kernel, the following vulnerability has been resolved: vsock/virti
CVE-2026-73522 7.5 2.36% 1 0 2026-08-18T15:17:08.193000 COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability tha
CVE-2026-19478 9.4 6.00% 1 6 template 2026-08-18T14:57:10.630000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2
CVE-2026-75094 9.1 2.11% 1 0 2026-08-18T03:31:14 A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_
CVE-2026-64849 9.3 16.41% 1 3 template 2026-08-17T21:58:52 ### Summary The default MLflow Tracking Server (`mlflow server`, no authenticati
CVE-2026-19976 6.6 2.05% 1 0 2026-08-17T03:30:28 A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted
CVE-2026-61979 8.1 0.28% 2 0 2026-08-13T15:34:46 Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions
CVE-2026-50656 7.8 11.36% 1 4 2026-08-12T17:17:27.983000 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-32257 8.1 0.00% 2 0 2026-08-12T14:40:23 ### Impact
CVE-2026-52923 7.8 0.15% 2 0 2026-08-12T12:19:41.090000 In the Linux kernel, the following vulnerability has been resolved: ipc: limit
CVE-2026-68820 7.0 6.18% 1 4 2026-08-11T21:33:01 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-63520 8.1 2.93% 8 1 2026-08-11T18:31:39 Improper input validation in Microsoft Office SharePoint allows an unauthorized
CVE-2026-62911 8.0 0.95% 2 1 2026-08-11T18:31:34 Authentication bypass by capture-replay in Microsoft Exchange Server allows an a
CVE-2026-14540 6.1 0.12% 1 0 2026-08-08T00:15:26 A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP so
CVE-2026-48710 6.5 1.91% 1 5 template 2026-08-07T12:31:53 ### Summary In affected versions, the HTTP `Host` request header was not validat
CVE-2026-63077 9.8 84.73% 4 4 template 2026-08-06T05:17:05.170000 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-8508 6.5 0.70% 2 1 2026-08-04T03:31:16 An improper authentication vulnerability in the "social_login.cgi" CGI program i
CVE-2026-15903 8.8 0.57% 1 0 2026-07-24T15:33:44 Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allo
CVE-2026-15981 9.8 0.81% 2 1 2026-07-23T21:31:09 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authen
CVE-2026-40575 9.1 0.48% 1 0 2026-07-21T13:50:16 ### Impact A configuration-dependent authentication bypass exists in OAuth2 Pro
CVE-2026-15776 8.8 0.45% 1 0 2026-07-15T17:39:16.157000 Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allo
CVE-2026-42271 8.8 83.54% 1 2 template 2026-07-15T02:21:30.727000 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo
CVE-2026-52945 7.5 0.40% 1 0 2026-07-14T16:59:26.780000 In the Linux kernel, the following vulnerability has been resolved: Revert "wir
CVE-2026-52912 7.8 0.19% 1 0 2026-07-08T15:31:43 In the Linux kernel, the following vulnerability has been resolved: netfilter:
CVE-2026-12569 9.8 40.59% 2 1 2026-06-26T15:33:15 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2025-1974 9.8 99.52% 1 27 template 2026-06-17T08:40:27.847000 A security issue was discovered in Kubernetes where under certain conditions, an
CVE-2023-21931 7.5 82.26% 2 2 2026-06-17T05:34:22.130000 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CVE-2020-14882 9.8 100.00% 2 42 template 2026-06-17T02:55:44.510000 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CVE-2025-9615 3.3 0.15% 2 0 2026-05-19T15:31:20 A flaw was found in NetworkManager. The NetworkManager package allows access to
CVE-2026-28389 7.5 0.80% 2 0 2026-05-12T15:31:15 Issue summary: During processing of a crafted CMS EnvelopedData message with Key
CVE-2025-69419 7.4 0.56% 2 1 2026-05-12T15:31:14 Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously craft
CVE-2021-23758 9.8 89.10% 6 1 2026-02-03T17:39:26 ### Overview Affected versions of this package are vulnerable to Deserializatio
CVE-2025-58187 6.5 0.38% 2 0 2026-01-29T18:31:31 Due to the design of the name constraint checking algorithm, the processing time
CVE-2026-0915 7.5 0.57% 2 1 2026-01-20T18:31:56 Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that spec
CVE-2021-33045 9.8 99.56% 1 3 template 2025-10-22T00:32:21 The identity authentication bypass vulnerability found in some Dahua products du
CVE-2021-33044 9.8 99.87% 1 9 template 2025-10-22T00:32:20 The identity authentication bypass vulnerability found in some Dahua products du
CVE-2020-2551 9.8 93.17% 2 11 template 2025-10-22T00:31:50 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CVE-2017-10271 7.5 99.99% 2 33 template 2025-10-22T00:31:29 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middlewar
CVE-2025-55241 9.0 1.55% 2 0 2025-09-18T15:31:27 Azure Entra Elevation of Privilege Vulnerability
CVE-2026-61792 0 0.00% 2 0 N/A
CVE-2026-60004 0 0.00% 26 9 template N/A
CVE-2026-80196 0 0.42% 1 0 N/A
CVE-2026-78379 0 0.32% 2 0 N/A
CVE-2026-77537 0 0.00% 2 0 N/A
CVE-2026-65641 0 0.00% 2 0 N/A
CVE-2026-75604 0 0.00% 2 2 N/A
CVE-2026-23479 0 1.36% 2 5 N/A
CVE-2026-18965 0 0.00% 2 0 N/A
CVE-2026-72898 0 79.22% 1 7 template N/A
CVE-2026-59285 0 0.00% 1 0 N/A
CVE-2026-59270 0 0.00% 2 0 N/A
CVE-2026-13214 0 0.51% 2 0 N/A
CVE-2026-76098 0 0.28% 1 0 N/A
CVE-2026-77567 0 0.30% 1 0 N/A
CVE-2026-66897 0 0.62% 1 0 N/A
CVE-2026-78251 0 0.39% 1 0 N/A

CVE-2026-77368
(7.6 HIGH)

EPSS: 0.00%

updated 2026-08-26T22:16:29.860000

2 posts

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tenant's upload session to write content to filer paths their own token forbids. The HEAD, PATCH, and DELETE verbs that act on an existing session by its id never ve

thehackerwire@mastodon.social at 2026-08-26T22:59:56.000Z ##

🟠 CVE-2026-77368 - High (7.6)

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tenant's upl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T22:59:56.000Z ##

🟠 CVE-2026-77368 - High (7.6)

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tenant's upl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77317
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-26T22:16:29.717000

2 posts

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose name merely begins with the same characters. A user granted access to /tenants/alice therefore also matches /tenants/alic

thehackerwire@mastodon.social at 2026-08-26T22:59:46.000Z ##

🟠 CVE-2026-77317 - High (8.1)

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T22:59:46.000Z ##

🟠 CVE-2026-77317 - High (8.1)

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61617
(7.7 HIGH)

EPSS: 0.00%

updated 2026-08-26T22:16:25.247000

2 posts

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the host node's physical disk and take down every server on it. Wings checks available space only once, as a boolean, when the

thehackerwire@mastodon.social at 2026-08-26T23:00:06.000Z ##

🟠 CVE-2026-61617 - High (7.7)

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T23:00:06.000Z ##

🟠 CVE-2026-61617 - High (7.7)

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58084
(5.5 MEDIUM)

EPSS: 0.14%

updated 2026-08-26T21:32:32

2 posts

To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. For a timer using CLOCK_TAI this can fail when no TAI offset has been configured, but the error return was not checked, so the uninitialized output buffer was copied to userspace. An unprivileged local user can obtain uninitialized kernel stack memory by creating a PO

grahamperrin@bsd.cafe at 2026-08-26T06:04:06.000Z ##

The bear is friendly. Think of honey, if you can.

For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).

<cve.org/CVERecord?id=CVE-2026->

<nvd.nist.gov/vuln/detail/CVE-2>

<security.freebsd.org/advisorie>

<defcon.social/@charlesrocket/1> @charlesrocket re: LLM shaming.

##

grahamperrin@bsd.cafe at 2026-08-26T06:04:06.000Z ##

The bear is friendly. Think of honey, if you can.

For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).

<cve.org/CVERecord?id=CVE-2026->

<nvd.nist.gov/vuln/detail/CVE-2>

<security.freebsd.org/advisorie>

<defcon.social/@charlesrocket/1> @charlesrocket re: LLM shaming.

##

CVE-2026-68863
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-26T21:31:52

2 posts

Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

thehackerwire@mastodon.social at 2026-08-26T21:01:47.000Z ##

🟠 CVE-2026-68863 - High (7.5)

Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T21:01:47.000Z ##

🟠 CVE-2026-68863 - High (7.5)

Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68861
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-26T21:31:52

2 posts

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

thehackerwire@mastodon.social at 2026-08-26T21:01:37.000Z ##

🟠 CVE-2026-68861 - High (8.8)

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T21:01:37.000Z ##

🟠 CVE-2026-68861 - High (8.8)

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74770
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-26T21:31:52

2 posts

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

thehackerwire@mastodon.social at 2026-08-26T21:01:01.000Z ##

🟠 CVE-2026-74770 - High (8.8)

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T21:01:01.000Z ##

🟠 CVE-2026-74770 - High (8.8)

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77652
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-26T21:31:52

2 posts

A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with: ren->pPal = g_new0(WPGColorRGB, 256); When handling a WPG_COLORMAP record, the parser reads a start index (i16) and number of colors (iNum16) from the file and reads palette data with: bRet &= (iNum16

thehackerwire@mastodon.social at 2026-08-26T21:00:52.000Z ##

🟠 CVE-2026-77652 - High (7.8)

A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer.

In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with:

ren->pPal = g_new0(WPGColorRGB, 256);

When handling ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T21:00:52.000Z ##

🟠 CVE-2026-77652 - High (7.8)

A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer.

In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with:

ren->pPal = g_new0(WPGColorRGB, 256);

When handling ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79938
(7.6 HIGH)

EPSS: 0.00%

updated 2026-08-26T21:31:52

2 posts

Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

thehackerwire@mastodon.social at 2026-08-26T21:00:41.000Z ##

🟠 CVE-2026-79938 - High (7.6)

Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T21:00:41.000Z ##

🟠 CVE-2026-79938 - High (7.6)

Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70419
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-26T21:31:47

2 posts

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

thehackerwire@mastodon.social at 2026-08-26T20:00:03.000Z ##

🔴 CVE-2026-70419 - Critical (9.1)

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T20:00:03.000Z ##

🔴 CVE-2026-70419 - Critical (9.1)

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68569
(8.1 HIGH)

EPSS: 0.26%

updated 2026-08-26T21:31:41

2 posts

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was

DailyCyberSecurity at 2026-08-26T07:10:33.802Z ##

Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now.

securityonline.info/apache-tom

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T07:10:33.000Z ##

Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now.

#ApacheTomcat #CyberSecurity #CVE #DenialOfService #Infosec

securityonline.info/apache-tom

##

CVE-2026-79074
(5.3 MEDIUM)

EPSS: 0.22%

updated 2026-08-26T21:31:35

1 posts

Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

hugovalters@mastodon.social at 2026-08-26T15:03:54.000Z ##

CVE-2026-79074 - Information leak in Google Chrome renderer. Medium severity. Update to 152.0.7977.65 or higher immediately. #CVE #Chrome #infosec

valtersit.com/cve/CVE-2026-790

##

CVE-2026-55228
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-26T21:16:38.737000

2 posts

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the API. By assigning projects to a team via these unvalidated requests, a user could grant access to projects they were not au

thehackerwire@mastodon.social at 2026-08-26T22:00:25.000Z ##

🟠 CVE-2026-55228 - High (8.1)

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid te...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T22:00:25.000Z ##

🟠 CVE-2026-55228 - High (8.1)

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid te...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76193
(10.0 CRITICAL)

EPSS: 0.62%

updated 2026-08-26T20:18:00.307000

1 posts

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

hugovalters@mastodon.social at 2026-08-26T01:05:14.000Z ##

CVE-2026-76193 - Critical SSRF to RCE in Adobe Campaign Classic. Zero-click exploit. CVSS 10.0. Apply mitigations immediately. #CVE #Adobe #infosec

valtersit.com/cve/CVE-2026-761

##

CVE-2026-58093
(7.0 HIGH)

EPSS: 0.13%

updated 2026-08-26T20:17:55.563000

2 posts

The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being destroyed to the calling process' session. An unprivileged local user can exploit this race condition to escalate privileges.

grahamperrin@bsd.cafe at 2026-08-26T06:37:54.000Z ##

FreeBSD: kernel use-after-free via tty ioctls – CVE-2026-58093

cve.org/CVERecord?id=CVE-2026-

"The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being destroyed to the calling process' session. An unprivileged local user can exploit this race condition to escalate privileges."

Credit: tsune of GMO Cybersecurity by Ierae, Inc. working with TrendAI Zero Day Initiative @thezdi

<ctftime.org/team/224122>

<gmo-cybersecurity.com/>

<nvd.nist.gov/vuln/detail/CVE-2>

<reviews.freebsd.org/D59126>, <github.com/freebsd/freebsd-src>

#FreeBSD #AI #cybersecurity #security #ZDI

##

grahamperrin@bsd.cafe at 2026-08-26T06:37:54.000Z ##

FreeBSD: kernel use-after-free via tty ioctls – CVE-2026-58093

cve.org/CVERecord?id=CVE-2026-

"The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being destroyed to the calling process' session. An unprivileged local user can exploit this race condition to escalate privileges."

Credit: tsune of GMO Cybersecurity by Ierae, Inc. working with TrendAI Zero Day Initiative @thezdi

<ctftime.org/team/224122>

<gmo-cybersecurity.com/>

<nvd.nist.gov/vuln/detail/CVE-2>

<reviews.freebsd.org/D59126>, <github.com/freebsd/freebsd-src>

#FreeBSD #AI #cybersecurity #security #ZDI

##

CVE-2026-46369
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-26T20:17:23.163000

2 posts

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative to Transaction::is_valid_at, allowing a remote attacker to replay the same signed transaction during a blocks_per_batch minus one block window and cause the sender

thehackerwire@mastodon.social at 2026-08-26T22:00:42.000Z ##

🟠 CVE-2026-46369 - High (7.5)

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative to Transact...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T22:00:42.000Z ##

🟠 CVE-2026-46369 - High (7.5)

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative to Transact...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19632
(9.8 CRITICAL)

EPSS: 0.79%

updated 2026-08-26T20:17:10.020000

2 posts

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters sto

2 repos

https://github.com/DeadExpl0it/CVE-2026-19632-POC

https://github.com/YonLiud/CVE-2026-19632

DailyCyberSecurity at 2026-08-25T15:43:39.038Z ##

A critical TranslatePress vulnerability (CVE-2026-19632) lets attackers steal admin reset links and take over 400,000 WordPress sites. Update to 3.3.2 now.

securityonline.info/translatep

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T15:43:39.000Z ##

A critical TranslatePress vulnerability (CVE-2026-19632) lets attackers steal admin reset links and take over 400,000 WordPress sites. Update to 3.3.2 now.

#WordPress #TranslatePress #CyberSecurity #CVE202619632 #WebSecurity

securityonline.info/translatep

##

CVE-2026-65084
(8.1 HIGH)

EPSS: 0.32%

updated 2026-08-26T19:16:52.447000

2 posts

NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges.

thehackerwire@mastodon.social at 2026-08-26T11:01:03.000Z ##

🟠 CVE-2026-65084 - High (8.1)

NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T11:01:03.000Z ##

🟠 CVE-2026-65084 - High (8.1)

NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81029
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-26T18:32:05

2 posts

OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the assertion consumer servlet later formats that stored value into a URL carrying the freshly issued JWT together with the ac

thehackerwire@mastodon.social at 2026-08-26T20:00:45.000Z ##

🟠 CVE-2026-81029 - High (8.1)

OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T20:00:45.000Z ##

🟠 CVE-2026-81029 - High (8.1)

OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81027
(8.5 HIGH)

EPSS: 0.00%

updated 2026-08-26T18:32:05

2 posts

one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after model.IsAdmin succeeds and otherwise rejects the caller, while the path-parameter branch sets the selected-channel value from c.Param("channelid") with no r

thehackerwire@mastodon.social at 2026-08-26T20:00:35.000Z ##

🟠 CVE-2026-81027 - High (8.5)

one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after mod...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T20:00:35.000Z ##

🟠 CVE-2026-81027 - High (8.5)

one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after mod...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80428
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-26T18:32:05

2 posts

ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and its logout-notification handler locates the session to terminate by reading every live row of the session table and passing each row's stored data to a hand-wr

thehackerwire@mastodon.social at 2026-08-26T18:00:30.000Z ##

🔴 CVE-2026-80428 - Critical (9.8)

ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and its lo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T18:00:30.000Z ##

🔴 CVE-2026-80428 - Critical (9.8)

ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and its lo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81036
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-26T18:32:05

2 posts

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is disabled, and that requirement is false in the shipped settings, so the supplied redirect value is neither matched against a regi

thehackerwire@mastodon.social at 2026-08-26T17:02:01.000Z ##

🟠 CVE-2026-81036 - High (8.1)

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T17:02:01.000Z ##

🟠 CVE-2026-81036 - High (8.1)

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81035
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-26T18:32:05

2 posts

Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of the role it records, and the data-layer function it calls re-checks the same helper and nothing else. The neighbouring procedures that remove or update a member in

thehackerwire@mastodon.social at 2026-08-26T17:01:50.000Z ##

🟠 CVE-2026-81035 - High (8.1)

Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of the role it...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T17:01:50.000Z ##

🟠 CVE-2026-81035 - High (8.1)

Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of the role it...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58474
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-26T18:32:04

2 posts

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing double quotes or other special characters. The script generation function in cli.py interpolates HuggingFace-derived values, including GGUF variant file

thehackerwire@mastodon.social at 2026-08-26T20:00:25.000Z ##

🟠 CVE-2026-58474 - High (8.8)

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T20:00:25.000Z ##

🟠 CVE-2026-58474 - High (8.8)

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75896
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-26T18:32:04

2 posts

Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords. This issue affects Liderahenk: before 3.5.5.

thehackerwire@mastodon.social at 2026-08-26T16:00:35.000Z ##

🔴 CVE-2026-75896 - Critical (9.1)

Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords.

This issue affects Liderahenk: before 3.5.5.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T16:00:35.000Z ##

🔴 CVE-2026-75896 - Critical (9.1)

Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords.

This issue affects Liderahenk: before 3.5.5.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18252
(7.3 HIGH)

EPSS: 0.00%

updated 2026-08-26T18:32:04

2 posts

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.

DailyCyberSecurity at 2026-08-26T13:07:07.511Z ##

A critical GitLab EE security patch addresses CVE-2026-18252, fixing a command execution flaw. Learn about affected versions, mechanisms, and mitigation.

securityonline.info/gitlab-ee-

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T13:07:07.000Z ##

A critical GitLab EE security patch addresses CVE-2026-18252, fixing a command execution flaw. Learn about affected versions, mechanisms, and mitigation.

#GitLab #SecurityPatch #Cybersecurity #CVE202618252

securityonline.info/gitlab-ee-

##

CVE-2026-58092
(5.4 MEDIUM)

EPSS: 0.14%

updated 2026-08-26T18:32:01

2 posts

In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This change was largely internal to the kernel and not user-visible. One function, group_is_primary(), was not properly update

grahamperrin@bsd.cafe at 2026-08-26T06:04:06.000Z ##

The bear is friendly. Think of honey, if you can.

For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).

<cve.org/CVERecord?id=CVE-2026->

<nvd.nist.gov/vuln/detail/CVE-2>

<security.freebsd.org/advisorie>

<defcon.social/@charlesrocket/1> @charlesrocket re: LLM shaming.

##

grahamperrin@bsd.cafe at 2026-08-26T06:04:06.000Z ##

The bear is friendly. Think of honey, if you can.

For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).

<cve.org/CVERecord?id=CVE-2026->

<nvd.nist.gov/vuln/detail/CVE-2>

<security.freebsd.org/advisorie>

<defcon.social/@charlesrocket/1> @charlesrocket re: LLM shaming.

##

CVE-2026-58090
(7.8 HIGH)

EPSS: 0.16%

updated 2026-08-26T18:31:55

2 posts

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user can exploit this use-after-free to escalate privileges.

CVE-2026-78899
(8.8 HIGH)

EPSS: 0.46%

updated 2026-08-26T18:31:36

1 posts

Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

hugovalters@mastodon.social at 2026-08-26T14:04:19.000Z ##

CVE-2026-78899 - High severity Use-After-Free in Google Chrome V8 enables sandbox RCE via crafted HTML. CVSS: High. Update Chrome now. #CVE #Google #infosec

valtersit.com/cve/CVE-2026-788

##

CVE-2026-79992
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-26T18:31:35

2 posts

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-25T19:00:35.000Z ##

🟠 CVE-2026-79992 - High (7.8)

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local sh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T19:00:35.000Z ##

🟠 CVE-2026-79992 - High (7.8)

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local sh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2019-1068
(8.8 HIGH)

EPSS: 44.66%

updated 2026-08-26T18:31:30

4 posts

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

2 repos

https://github.com/alt3kx/CVE-2019-10685

https://github.com/Vulnerability-Playground/CVE-2019-1068

secdb at 2026-08-26T19:00:11.097Z ##

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3246 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: access.redhat.com/articles/153 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5287 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/abrt/abrt/commit/3c ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2019-1068 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-23758 (secdb.nttzen.cloud/cve/detail/)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/michaelschwarz/Ajax ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2022-0995 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: git.kernel.org/pub/scm/linux/k ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8452 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: support.citrix.com/support-hom ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-26T18:02:09.000Z ##

CVE ID: CVE-2019-1068
Vendor: Microsoft
Product: SQL Server
Date Added: 2026-08-26
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-08-26T19:00:11.000Z ##

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3246 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: access.redhat.com/articles/153 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5287 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/abrt/abrt/commit/3c ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2019-1068 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-23758 (secdb.nttzen.cloud/cve/detail/)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/michaelschwarz/Ajax ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2022-0995 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: git.kernel.org/pub/scm/linux/k ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8452 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: support.citrix.com/support-hom ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452

##

cisakevtracker@mastodon.social at 2026-08-26T18:02:09.000Z ##

CVE ID: CVE-2019-1068
Vendor: Microsoft
Product: SQL Server
Date Added: 2026-08-26
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2015-5287
(7.8 HIGH)

EPSS: 3.41%

updated 2026-08-26T18:31:30

4 posts

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

secdb at 2026-08-26T19:00:11.097Z ##

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3246 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: access.redhat.com/articles/153 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5287 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/abrt/abrt/commit/3c ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2019-1068 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-23758 (secdb.nttzen.cloud/cve/detail/)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/michaelschwarz/Ajax ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2022-0995 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: git.kernel.org/pub/scm/linux/k ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8452 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: support.citrix.com/support-hom ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-26T18:01:22.000Z ##

CVE ID: CVE-2015-5287
Vendor: Red Hat
Product: Automatic Bug Reporting Tool
Date Added: 2026-08-26
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-08-26T19:00:11.000Z ##

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3246 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: access.redhat.com/articles/153 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5287 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/abrt/abrt/commit/3c ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2019-1068 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-23758 (secdb.nttzen.cloud/cve/detail/)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/michaelschwarz/Ajax ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2022-0995 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: git.kernel.org/pub/scm/linux/k ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8452 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: support.citrix.com/support-hom ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452

##

cisakevtracker@mastodon.social at 2026-08-26T18:01:22.000Z ##

CVE ID: CVE-2015-5287
Vendor: Red Hat
Product: Automatic Bug Reporting Tool
Date Added: 2026-08-26
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-8452
(9.8 CRITICAL)

EPSS: 1.04%

updated 2026-08-26T18:30:34

4 posts

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

3 repos

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

https://github.com/derekpreston81/CVE_ADC_IOC_2026

https://github.com/BishopFox/CVE-2026-8452-check

secdb at 2026-08-26T19:00:11.097Z ##

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3246 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: access.redhat.com/articles/153 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5287 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/abrt/abrt/commit/3c ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2019-1068 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-23758 (secdb.nttzen.cloud/cve/detail/)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/michaelschwarz/Ajax ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2022-0995 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: git.kernel.org/pub/scm/linux/k ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8452 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: support.citrix.com/support-hom ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-26T18:01:53.000Z ##

CVE ID: CVE-2026-8452
Vendor: Citrix
Product: NetScaler ADC and NetScaler Gateway
Date Added: 2026-08-26
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-08-26T19:00:11.000Z ##

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3246 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: access.redhat.com/articles/153 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5287 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/abrt/abrt/commit/3c ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2019-1068 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-23758 (secdb.nttzen.cloud/cve/detail/)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/michaelschwarz/Ajax ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2022-0995 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: git.kernel.org/pub/scm/linux/k ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8452 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: support.citrix.com/support-hom ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452

##

cisakevtracker@mastodon.social at 2026-08-26T18:01:53.000Z ##

CVE ID: CVE-2026-8452
Vendor: Citrix
Product: NetScaler ADC and NetScaler Gateway
Date Added: 2026-08-26
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2022-0995
(7.1 HIGH)

EPSS: 6.34%

updated 2026-08-26T18:30:28

4 posts

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

4 repos

https://github.com/Bonfee/CVE-2022-0995

https://github.com/A1b2rt/cve-2022-0995

https://github.com/1nzag/CVE-2022-0995

https://github.com/AndreevSemen/CVE-2022-0995

secdb at 2026-08-26T19:00:11.097Z ##

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3246 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: access.redhat.com/articles/153 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5287 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/abrt/abrt/commit/3c ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2019-1068 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-23758 (secdb.nttzen.cloud/cve/detail/)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/michaelschwarz/Ajax ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2022-0995 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: git.kernel.org/pub/scm/linux/k ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8452 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: support.citrix.com/support-hom ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-26T18:01:38.000Z ##

CVE ID: CVE-2022-0995
Vendor: Linux
Product: Kernel
Date Added: 2026-08-26
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-08-26T19:00:11.000Z ##

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3246 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: access.redhat.com/articles/153 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5287 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/abrt/abrt/commit/3c ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2019-1068 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-23758 (secdb.nttzen.cloud/cve/detail/)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/michaelschwarz/Ajax ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2022-0995 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: git.kernel.org/pub/scm/linux/k ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8452 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: support.citrix.com/support-hom ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452

##

cisakevtracker@mastodon.social at 2026-08-26T18:01:38.000Z ##

CVE ID: CVE-2022-0995
Vendor: Linux
Product: Kernel
Date Added: 2026-08-26
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2015-3246
(5.1 MEDIUM)

EPSS: 7.09%

updated 2026-08-26T18:30:27

4 posts

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

secdb at 2026-08-26T19:00:11.097Z ##

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3246 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: access.redhat.com/articles/153 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5287 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/abrt/abrt/commit/3c ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2019-1068 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-23758 (secdb.nttzen.cloud/cve/detail/)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/michaelschwarz/Ajax ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2022-0995 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: git.kernel.org/pub/scm/linux/k ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8452 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: support.citrix.com/support-hom ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-26T18:01:06.000Z ##

CVE ID: CVE-2015-3246
Vendor: Red Hat
Product: Libuser
Date Added: 2026-08-26
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-08-26T19:00:11.000Z ##

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3246 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: access.redhat.com/articles/153 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5287 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/abrt/abrt/commit/3c ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2019-1068 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-23758 (secdb.nttzen.cloud/cve/detail/)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/michaelschwarz/Ajax ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2022-0995 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: git.kernel.org/pub/scm/linux/k ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8452 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: support.citrix.com/support-hom ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452

##

cisakevtracker@mastodon.social at 2026-08-26T18:01:06.000Z ##

CVE ID: CVE-2015-3246
Vendor: Red Hat
Product: Libuser
Date Added: 2026-08-26
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-81032
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-26T18:17:05.890000

2 posts

NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and writing gflags alongside status and statistics. Neither the service nor its router carries any authentication, token check or address restriction. The read

thehackerwire@mastodon.social at 2026-08-26T17:01:41.000Z ##

🔴 CVE-2026-81032 - Critical (9.8)

NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and wr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T17:01:41.000Z ##

🔴 CVE-2026-81032 - Critical (9.8)

NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and wr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75960
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-26T18:17:01.453000

4 posts

Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.

thehackerwire@mastodon.social at 2026-08-26T23:01:08.000Z ##

🟠 CVE-2026-75960 - High (8.1)

Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cyberworldops at 2026-08-26T08:30:01.310Z ##

CISA advisory ICSA-26-237-01 (rev. 1) discloses CVE-2026-75960 in Rently Smart Home firmware 20.1.0 and earlier. The vulnerability (CWE-522) allows extraction of PINs and Master PINs due to insufficiently protected credentials.

cyberworldops.eu/en/cisa-flaw-

##

thehackerwire@mastodon.social at 2026-08-26T23:01:08.000Z ##

🟠 CVE-2026-75960 - High (8.1)

Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cyberworldops@infosec.exchange at 2026-08-26T08:30:01.000Z ##

CISA advisory ICSA-26-237-01 (rev. 1) discloses CVE-2026-75960 in Rently Smart Home firmware 20.1.0 and earlier. The vulnerability (CWE-522) allows extraction of PINs and Master PINs due to insufficiently protected credentials.

#CISA #CVE2026 #SmartHomeSecurity #ICSAdvisory

cyberworldops.eu/en/cisa-flaw-

##

CVE-2026-54569
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-26T18:16:40.930000

2 posts

SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in src/bika/lims/jsonapi/update.py, including update, update_many, remove, doActionFor, doActionFor_many,

thehackerwire@mastodon.social at 2026-08-26T23:00:58.000Z ##

🔴 CVE-2026-54569 - Critical (9.8)

SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T23:00:58.000Z ##

🔴 CVE-2026-54569 - Critical (9.8)

SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-32258
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-26T18:16:27.550000

2 posts

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LESS parser and rendered without sanitization on every backend page, allowing stored cross-site scripting. This issue is fixed in version 1.2.13.

thehackerwire@mastodon.social at 2026-08-26T18:00:18.000Z ##

🟠 CVE-2026-32258 - High (8.1)

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T18:00:18.000Z ##

🟠 CVE-2026-32258 - High (8.1)

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80427
(8.4 HIGH)

EPSS: 0.00%

updated 2026-08-26T17:17:26.120000

2 posts

bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are passed to the child process with no -- delimiter between them, so any source entry beginning with a hyphen is interpreted by zip as an option rather than a file name. zip accepts -T to test the finished archive and -TT to name t

thehackerwire@mastodon.social at 2026-08-26T22:00:52.000Z ##

🟠 CVE-2026-80427 - High (8.4)

bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are passed to the child process with no -- delimiter between them, so any sourc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T22:00:52.000Z ##

🟠 CVE-2026-80427 - High (8.4)

bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are passed to the child process with no -- delimiter between them, so any sourc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78901
(7.5 HIGH)

EPSS: 0.24%

updated 2026-08-26T17:01:18.043000

1 posts

Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

hugovalters@mastodon.social at 2026-08-26T11:14:14.000Z ##

CVE-2026-78901 - V8 race condition in Google Chrome allows arbitrary code execution inside the sandbox. CVSS N/A (Medium). Update Chrome immediately. #CVE #Chrome #infosec

valtersit.com/cve/CVE-2026-789

##

CVE-2026-58083
(8.4 HIGH)

EPSS: 0.12%

updated 2026-08-26T16:54:50.030000

2 posts

While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's active list before the copy was complete. The copy routine did not account for this and could enqueue the new knote a second time, corrupting the active list. In addition, the copy routine did not hold the appropriate locks while reading knote state, allowing further race

grahamperrin@bsd.cafe at 2026-08-26T06:04:06.000Z ##

The bear is friendly. Think of honey, if you can.

For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).

<cve.org/CVERecord?id=CVE-2026->

<nvd.nist.gov/vuln/detail/CVE-2>

<security.freebsd.org/advisorie>

<defcon.social/@charlesrocket/1> @charlesrocket re: LLM shaming.

##

grahamperrin@bsd.cafe at 2026-08-26T06:04:06.000Z ##

The bear is friendly. Think of honey, if you can.

For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).

<cve.org/CVERecord?id=CVE-2026->

<nvd.nist.gov/vuln/detail/CVE-2>

<security.freebsd.org/advisorie>

<defcon.social/@charlesrocket/1> @charlesrocket re: LLM shaming.

##

CVE-2026-16783
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-26T16:46:22.330000

1 posts

A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

thehackerwire@mastodon.social at 2026-08-24T22:00:14.000Z ##

🟠 CVE-2026-16783 - High (7.8)

A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75768
(7.8 HIGH)

EPSS: 0.17%

updated 2026-08-26T16:45:12.020000

2 posts

Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

thehackerwire@mastodon.social at 2026-08-25T19:00:54.000Z ##

🟠 CVE-2026-75768 - High (7.8)

Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T19:00:54.000Z ##

🟠 CVE-2026-75768 - High (7.8)

Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77995
(0 None)

EPSS: 0.29%

updated 2026-08-26T16:36:16.990000

1 posts

Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.

offseq@infosec.exchange at 2026-08-24T13:30:27.000Z ##

CVE-2026-77995 (CRITICAL, CVSS 10): miniOrange OAuth Client for Joomla (v1.0.0 – 3.1.9) allows arbitrary account takeover via cookie manipulation. Patch to 3.2.0+ required. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #Vuln #OAuth

##

CVE-2026-76565
(0 None)

EPSS: 0.32%

updated 2026-08-26T16:35:20.160000

1 posts

Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

1 repos

https://github.com/toanln-cov/CVE-2026-76565

DarkWebInformer@infosec.exchange at 2026-08-24T18:16:26.000Z ##

‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart

GitHub: github.com/toanln-cov/CVE-2026

A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≤ 6.1.7 for Joomla.

The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.

The PoC demonstrates:

• Reflected XSS through crafted GET parameters
• Exploitation of vulnerable price filter inputs
• Attribute-context injection caused by missing htmlspecialchars() encoding
• No authentication requirement for exploitation
• Affected versions: PhocaCart ≤ 6.1.7
• Fixed version: PhocaCart 6.1.8

💥 No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.

##

CVE-2026-77994
(0 None)

EPSS: 0.23%

updated 2026-08-26T16:35:20.160000

1 posts

Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model.

offseq@infosec.exchange at 2026-08-24T09:00:26.000Z ##

CVE-2026-77994: CRITICAL SQL injection in Joomla Page Builder CK (v1.0.0-3.6.4). Unauthenticated remote SQL execution possible. No official fix yet — disable/remove vulnerable versions. CVSS 9.3. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #SQLInjection #Infosec

##

CVE-2026-74932
(7.5 HIGH)

EPSS: 0.22%

updated 2026-08-26T16:30:52.723000

2 posts

The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated attackers to poison cached pages with references to a server they control and have arbitrary JavaScript run for every subsequent visitor.

thehackerwire@mastodon.social at 2026-08-26T12:00:19.000Z ##

🟠 CVE-2026-74932 - High (7.5)

The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T12:00:19.000Z ##

🟠 CVE-2026-74932 - High (7.5)

The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18431
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-08-26T16:19:05.917000

4 posts

The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the s

cyberworldops at 2026-08-26T22:20:01.165Z ##

Six chained vulnerabilities (CVE-2026-18431, CVSS 9.8) in the WordPress Avada theme and Fusion Builder plugin allow unauthenticated remote code execution. No user interaction is required — the exploit is zero-click. Any site running vulnerable versions of both components is at immediate risk of full takeover. Patch now.

cyberworldops.eu/en/six-chaine

##

hugovalters@mastodon.social at 2026-08-26T17:12:30.000Z ##

CVE-2026-18431 - Critical Unauthenticated RCE in WordPress Avada theme & Fusion Builder via arbitrary file write. CVSS 9.8. Unpatched. Mitigate immediately. #CVE #WordPress #cybersecurity

valtersit.com/cve/CVE-2026-184

##

sayzard@mastodon.sayzard.org at 2026-08-26T00:45:55.000Z ##

Wordfence Argus Finds 6 Step Critical RCE in Avada Theme with 1M Sales

Wordfence가 Avada 테마(7.16 이하)와 Fusion Builder 플러그인(3.16 이하)의 6단계 취약점 체인을 이용하는 인증 불필요 원격 코드 실행(CVE-2026-18431, CVSS 9.8)을 공개했습니다. 두 구성요소가 활성화되고 특정 관리자 작성 콘텐츠가 존재할 경우 공격자는 임의 PHP 파일을 작성·실행해 웹 서버 권한으로 사이트를 완전히 장악할 수 있습니다. 패치는 Avada 7.16.1 및 Fusion...

wordfence.com/blog/2026/08/wor

##

cyberworldops@infosec.exchange at 2026-08-26T22:20:01.000Z ##

Six chained vulnerabilities (CVE-2026-18431, CVSS 9.8) in the WordPress Avada theme and Fusion Builder plugin allow unauthenticated remote code execution. No user interaction is required — the exploit is zero-click. Any site running vulnerable versions of both components is at immediate risk of full takeover. Patch now. #AvadaVulnerability #WordPressSecurity #CVE202618431 #SiteTakeover

cyberworldops.eu/en/six-chaine

##

CVE-2026-79911
(10.0 CRITICAL)

EPSS: 0.64%

updated 2026-08-26T16:19:05.917000

2 posts

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

thehackerwire@mastodon.social at 2026-08-26T00:00:54.000Z ##

🔴 CVE-2026-79911 - Critical (10)

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname lea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T00:00:54.000Z ##

🔴 CVE-2026-79911 - Critical (10)

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname lea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-32556
(7.1 HIGH)

EPSS: 0.15%

updated 2026-08-26T16:19:05.917000

1 posts

Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.

hugovalters@mastodon.social at 2026-08-25T01:01:34.000Z ##

CVE-2026-32556 - Unauthenticated XSS in Boost <= 2.0.4. CVSS 7.1. Currently unpatched. Audit systems and mitigate risk immediately. #CVE #XSS #infosec

valtersit.com/cve/CVE-2026-325

##

CVE-2026-65092
(8.5 HIGH)

EPSS: 0.45%

updated 2026-08-26T16:16:35.933000

2 posts

NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.

thehackerwire@mastodon.social at 2026-08-25T23:01:06.000Z ##

🟠 CVE-2026-65092 - High (8.5)

NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T23:01:06.000Z ##

🟠 CVE-2026-65092 - High (8.5)

NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65105
(8.1 HIGH)

EPSS: 0.30%

updated 2026-08-26T15:16:51.040000

3 posts

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.

thehackerwire@mastodon.social at 2026-08-26T10:01:20.000Z ##

🟠 CVE-2026-65105 - High (8.1)

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

sayzard@mastodon.sayzard.org at 2026-08-26T09:42:16.000Z ##

Drive-By Agent Hijacking: One Website Visit, Persistent Model Poisoning

Oasis Security는 NVIDIA NemoClaw가 로컬 Ollama를 `0.0.0.0:11434`에 바인딩하는 구성 때문에 발생하는 CVE-2026-65105를 공개했습니다. 공격자는 DNS rebinding을 이용해 피해자가 악성 웹페이지를 한 번 방문하는 것만으로 인증 없는 Ollama API에 접근해 모델 조회·삭제·다운로드·추론 실행 등을 수행할 수 있습니다. 특히 `/api/create`의 모델 chat template을 변조하면 에이전트가 보내는 시스템 프롬프트 뒤에 공격자 지시를 지속적...

cyera.com/research/nemoclaw-on

##

thehackerwire@mastodon.social at 2026-08-26T10:01:20.000Z ##

🟠 CVE-2026-65105 - High (8.1)

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65096
(7.8 HIGH)

EPSS: 0.69%

updated 2026-08-26T15:16:50.467000

2 posts

NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

thehackerwire@mastodon.social at 2026-08-26T08:01:46.000Z ##

🟠 CVE-2026-65096 - High (7.8)

NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, informat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T08:01:46.000Z ##

🟠 CVE-2026-65096 - High (7.8)

NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, informat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54511
(8.6 HIGH)

EPSS: 0.00%

updated 2026-08-26T14:28:05

2 posts

`@logtape/syslog` contains two related output-encoding bugs in the structured data formatting code. Both only affect deployments with `includeStructuredData: true`, which is non-default. ## 1. Unescaped C0 control characters in structured data values `escapeStructuredDataValue()` in `packages/syslog/src/syslog.ts` escapes `\`, `"`, and `]` per RFC 5424 but does not escape newline (`\n`), carriag

thehackerwire@mastodon.social at 2026-08-26T16:00:15.000Z ##

🟠 CVE-2026-54511 - High (8.6)

LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 through U+001F...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T16:00:15.000Z ##

🟠 CVE-2026-54511 - High (8.6)

LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 through U+001F...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54523
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-08-26T14:21:54

2 posts

## Summary In Kyverno v1.18.1, a tenant who can create a `NamespacedMutatingPolicy` in their own namespace can instruct the admission controller to generate resources in any namespace by passing an arbitrary namespace string to the CEL `generator.apply(namespace, resources)` function. ## Details `pkg/cel/libs/context.go:177` declares `GenerateResources(namespace string, dataList []map[string]an

thehackerwire@mastodon.social at 2026-08-26T16:00:25.000Z ##

🔴 CVE-2026-54523 - Critical (9.6)

Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke gen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T16:00:25.000Z ##

🔴 CVE-2026-54523 - Critical (9.6)

Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke gen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73108
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-26T14:17:12.830000

2 posts

RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before receiving the payload. A crafted header can request up to 1,073,741,823 bytes of capacity, allowing unauthenticated attackers to use concurrent TCP connectio

thehackerwire@mastodon.social at 2026-08-26T23:01:17.000Z ##

🟠 CVE-2026-73108 - High (7.5)

RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before rece...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T23:01:17.000Z ##

🟠 CVE-2026-73108 - High (7.5)

RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before rece...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77532
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-08-26T13:19:20.413000

2 posts

A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device.

phillip@social.lol at 2026-08-26T15:46:20.000Z ##

@cR0w

Impact:

CVSS Severity and Metrics:

Base Score: 9.6 Critical

Vector:

CVSS: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE: CVE-2026-77532 (Will Robertson)

##

phillip@social.lol at 2026-08-26T15:46:20.000Z ##

@cR0w

Impact:

CVSS Severity and Metrics:

Base Score: 9.6 Critical

Vector:

CVSS: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE: CVE-2026-77532 (Will Robertson)

##

CVE-2026-54757
(7.8 HIGH)

EPSS: 0.25%

updated 2026-08-26T13:19:16.497000

2 posts

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote code execution. This occurs because the MDCleanInclude and MDSectionInclude Jinja2 tags re-parse untrusted Markdown content as template source code usin

thehackerwire@mastodon.social at 2026-08-26T04:00:04.000Z ##

🟠 CVE-2026-54757 - High (7.8)

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T04:00:04.000Z ##

🟠 CVE-2026-54757 - High (7.8)

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19913
(7.5 HIGH)

EPSS: 0.19%

updated 2026-08-26T13:17:47.880000

2 posts

The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP schemes such as file://. When an exception or error occurs, the response is subsequently deserialized and its raw contents are reflected to the clie

1 repos

https://github.com/HORKimhab/CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

DailyCyberSecurity at 2026-08-25T16:35:05.614Z ##

Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.

securityonline.info/kaltura-se

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T16:35:05.000Z ##

Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.

#Kaltura #CyberSecurity #CVE202619912 #CVE202619913 #InfoSec

securityonline.info/kaltura-se

##

CVE-2026-80138
(9.8 CRITICAL)

EPSS: 0.80%

updated 2026-08-26T00:31:14

2 posts

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary commands as the web server user.

thehackerwire@mastodon.social at 2026-08-26T00:01:13.000Z ##

🔴 CVE-2026-80138 - Critical (9.8)

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T00:01:13.000Z ##

🔴 CVE-2026-80138 - Critical (9.8)

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79912
(8.3 HIGH)

EPSS: 1.40%

updated 2026-08-26T00:31:14

2 posts

A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.

thehackerwire@mastodon.social at 2026-08-26T00:01:04.000Z ##

🟠 CVE-2026-79912 - High (8.3)

A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The att...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T00:01:04.000Z ##

🟠 CVE-2026-79912 - High (8.3)

A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The att...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80186
(7.6 HIGH)

EPSS: 0.41%

updated 2026-08-26T00:31:09

2 posts

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for

thehackerwire@mastodon.social at 2026-08-25T22:59:49.000Z ##

🟠 CVE-2026-80186 - High (7.6)

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T22:59:49.000Z ##

🟠 CVE-2026-80186 - High (7.6)

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80104
(9.8 CRITICAL)

EPSS: 0.71%

updated 2026-08-25T21:31:58

2 posts

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given and writes the request body to upload_dir / filename. A path composed with that operator discards the left operand when the right one is absolute and fol

thehackerwire@mastodon.social at 2026-08-25T22:00:41.000Z ##

🔴 CVE-2026-80104 - Critical (9.8)

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T22:00:41.000Z ##

🔴 CVE-2026-80104 - Critical (9.8)

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79021(CVSS UNKNOWN)

EPSS: 0.23%

updated 2026-08-25T21:31:45

1 posts

Missing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted PDF file. (Chromium security severity: Low)

hugovalters@mastodon.social at 2026-08-26T12:08:56.000Z ##

CVE-2026-79021 - Missing authorization in Google Chrome allows access restriction bypass via crafted PDF. CVSS N/A (Low). Patch now. #CVE #Chrome #infosec

valtersit.com/cve/CVE-2026-790

##

CVE-2026-65099
(7.8 HIGH)

EPSS: 0.69%

updated 2026-08-25T21:31:39

2 posts

NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.

thehackerwire@mastodon.social at 2026-08-26T10:01:10.000Z ##

🟠 CVE-2026-65099 - High (7.8)

NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T10:01:10.000Z ##

🟠 CVE-2026-65099 - High (7.8)

NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65093
(9.9 CRITICAL)

EPSS: 0.49%

updated 2026-08-25T21:31:36

4 posts

NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

DailyCyberSecurity at 2026-08-26T10:39:55.948Z ##

NVIDIA patched 20 NemoClaw and OpenShell flaws. The worst, CVE-2026-65093 (CVSS 9.9), enables code execution via sandbox escape. Update now.

securityonline.info/nvidia-nem

##

thehackerwire@mastodon.social at 2026-08-25T23:01:16.000Z ##

🔴 CVE-2026-65093 - Critical (9.9)

NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T10:39:55.000Z ##

NVIDIA patched 20 NemoClaw and OpenShell flaws. The worst, CVE-2026-65093 (CVSS 9.9), enables code execution via sandbox escape. Update now.

#NVIDIA #CyberSecurity #CVE202665093 #CodeExecution #AISecurity

securityonline.info/nvidia-nem

##

thehackerwire@mastodon.social at 2026-08-25T23:01:16.000Z ##

🔴 CVE-2026-65093 - Critical (9.9)

NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65081
(8.1 HIGH)

EPSS: 0.25%

updated 2026-08-25T21:31:35

2 posts

NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.

thehackerwire@mastodon.social at 2026-08-26T12:00:08.000Z ##

🟠 CVE-2026-65081 - High (8.1)

NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tamp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T12:00:08.000Z ##

🟠 CVE-2026-65081 - High (8.1)

NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tamp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65090
(7.8 HIGH)

EPSS: 0.69%

updated 2026-08-25T21:31:35

2 posts

NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.

thehackerwire@mastodon.social at 2026-08-26T11:01:24.000Z ##

🟠 CVE-2026-65090 - High (7.8)

NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T11:01:24.000Z ##

🟠 CVE-2026-65090 - High (7.8)

NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65089
(7.8 HIGH)

EPSS: 0.69%

updated 2026-08-25T21:31:35

2 posts

NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.

thehackerwire@mastodon.social at 2026-08-26T11:01:14.000Z ##

🟠 CVE-2026-65089 - High (7.8)

NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information dis...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T11:01:14.000Z ##

🟠 CVE-2026-65089 - High (7.8)

NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information dis...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65098
(8.1 HIGH)

EPSS: 0.57%

updated 2026-08-25T21:31:35

2 posts

NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.

thehackerwire@mastodon.social at 2026-08-26T08:02:05.000Z ##

🟠 CVE-2026-65098 - High (8.1)

NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T08:02:05.000Z ##

🟠 CVE-2026-65098 - High (8.1)

NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66153(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-08-25T21:31:35

2 posts

The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.

DailyCyberSecurity at 2026-08-26T01:42:46.453Z ##

Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.

securityonline.info/sonicwall-

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T01:42:46.000Z ##

Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.

#SonicWall #NetExtender #CyberSecurity #CVE202666152 #CVE202666153

securityonline.info/sonicwall-

##

CVE-2026-66152(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-08-25T21:31:35

2 posts

A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write arbitrary file as root.

DailyCyberSecurity at 2026-08-26T01:42:46.453Z ##

Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.

securityonline.info/sonicwall-

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T01:42:46.000Z ##

Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.

#SonicWall #NetExtender #CyberSecurity #CVE202666152 #CVE202666153

securityonline.info/sonicwall-

##

CVE-2026-65091
(8.8 HIGH)

EPSS: 1.36%

updated 2026-08-25T21:31:35

2 posts

NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

thehackerwire@mastodon.social at 2026-08-25T23:00:57.000Z ##

🟠 CVE-2026-65091 - High (8.8)

NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T23:00:57.000Z ##

🟠 CVE-2026-65091 - High (8.8)

NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65097
(7.5 HIGH)

EPSS: 0.20%

updated 2026-08-25T21:31:34

2 posts

NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

thehackerwire@mastodon.social at 2026-08-26T08:01:55.000Z ##

🟠 CVE-2026-65097 - High (7.5)

NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privil...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T08:01:55.000Z ##

🟠 CVE-2026-65097 - High (7.5)

NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privil...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65083
(9.9 CRITICAL)

EPSS: 0.51%

updated 2026-08-25T21:31:31

2 posts

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.

thehackerwire@mastodon.social at 2026-08-26T10:01:28.000Z ##

🔴 CVE-2026-65083 - Critical (9.9)

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of priv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T10:01:28.000Z ##

🔴 CVE-2026-65083 - Critical (9.9)

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of priv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80049
(8.8 HIGH)

EPSS: 0.34%

updated 2026-08-25T20:17:08.627000

2 posts

Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHeaderResolver.resolveWorkspace consults X-Airbyte-Workspace-Id ahead of every resource-derived header, including those for connection, source and destinati

thehackerwire@mastodon.social at 2026-08-26T15:00:17.000Z ##

🟠 CVE-2026-80049 - High (8.8)

Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T15:00:17.000Z ##

🟠 CVE-2026-80049 - High (8.8)

Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75501
(7.5 HIGH)

EPSS: 0.59%

updated 2026-08-25T20:17:04.150000

1 posts

A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port‑forwarding rules via the UPnP WANIPConnection service. The device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls. A remote attacker can send crafted SOAP requests to add, delete, or enumerate port m

Byte0x90@mastodon.social at 2026-08-25T08:59:41.000Z ##

Eine ungepatchte Lücke (CVE-2026-75501) in Calix-Routern (GS5239XG) hebelt Firewall und NAT aus. Der UPnP-Dienst ist ungeschützt auf Port 5000 erreichbar, wodurch Angreifer aus der Ferne Port-Weiterleitungen anlegen können. So werden interne Heimnetz-Geräte wie NAS oder Kameras direkt im Internet exponiert. Da bisher kein Patch existiert, sollten Nutzer UPnP im Router deaktivieren oder ihren ISP kontaktieren.

#Calix #ITSecurity #CyberSecurity #Sicherheitslücke #Router #InfoSec

##

CVE-2026-55099
(7.5 HIGH)

EPSS: 0.38%

updated 2026-08-25T19:27:32

2 posts

### Summary `Component.__eq__` compares subcomponents in `O(2^n)` time relative to nesting depth. Because the parser accepts arbitrarily nested components, a sub-kilobyte `.ics` file is enough to make a single equality check run for minutes or hang indefinitely. Any application that compares parsed components (`==`, `!=`, `in`, set/dict membership, deduplication, test assertions) against attacker

thehackerwire@mastodon.social at 2026-08-26T12:00:29.000Z ##

🟠 CVE-2026-55099 - High (7.5)

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T12:00:29.000Z ##

🟠 CVE-2026-55099 - High (7.5)

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45018
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-08-25T19:19:28

2 posts

### Am I affected? Only if your deployment sets `features.mcp.enabled = true` in `.chainlit/config.toml`. **MCP has been disabled by default since v2.7.0**, so most Chainlit deployments are not affected. No authentication is required: `/mcp` is reachable by any client that can open a session. ### Summary When MCP is enabled (`features.mcp.enabled = true`), the `POST /mcp` endpoint for `stdio` t

thehackerwire@mastodon.social at 2026-08-26T15:00:08.000Z ##

🔴 CVE-2026-45018 - Critical (9.8)

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T15:00:08.000Z ##

🔴 CVE-2026-45018 - Critical (9.8)

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76197
(10.0 CRITICAL)

EPSS: 1.47%

updated 2026-08-25T18:32:01

6 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

security_crawler_carl at 2026-08-26T04:27:46.991Z ##

🏆 New Achievement! Maximum Payload Acquired!

ITEM DROP: Cursed Campaign Scroll (Adobe Campaign Classic). Three critical flaws — headlined by CVE-2026-76197, a CVSS 10.0 OS command injection — landed in your inventory without your permission. Any attacker who finds you can inject arbitrary OS commands and execute code freely, like a bard who learned every spell and also hates you specifically.

Equipping this item applies the debuff: Completely Owned Server (permanent, until patched). (1/2)

##

DailyCyberSecurity at 2026-08-26T02:43:27.407Z ##

Three critical Adobe Campaign Classic flaws (CVE-2026-76197, CVSS 10.0) allow arbitrary code execution. Update to build 9401 now.

securityonline.info/adobe-camp

##

thehackerwire@mastodon.social at 2026-08-25T19:00:44.000Z ##

🔴 CVE-2026-76197 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

security_crawler_carl@infosec.exchange at 2026-08-26T04:27:46.000Z ##

🏆 New Achievement! Maximum Payload Acquired!

ITEM DROP: Cursed Campaign Scroll (Adobe Campaign Classic). Three critical flaws — headlined by CVE-2026-76197, a CVSS 10.0 OS command injection — landed in your inventory without your permission. Any attacker who finds you can inject arbitrary OS commands and execute code freely, like a bard who learned every spell and also hates you specifically.

Equipping this item applies the debuff: Completely Owned Server (permanent, until patched). (1/2)

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T02:43:27.000Z ##

Three critical Adobe Campaign Classic flaws (CVE-2026-76197, CVSS 10.0) allow arbitrary code execution. Update to build 9401 now.

#Adobe #CyberSecurity #CVE202676197 #RCE #Infosec

securityonline.info/adobe-camp

##

thehackerwire@mastodon.social at 2026-08-25T19:00:44.000Z ##

🔴 CVE-2026-76197 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79784
(8.8 HIGH)

EPSS: 0.32%

updated 2026-08-25T18:32:01

2 posts

Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the configuration, splits it into a module and an attribute, imports the module with __import__, resolves the attribute with getattr, and calls the result as args_class(*args, **kwargs) where kwargs is the config's own init_

thehackerwire@mastodon.social at 2026-08-25T17:00:02.000Z ##

🟠 CVE-2026-79784 - High (8.8)

Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the configuration, splits it into a module and an attribute, imports th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T17:00:02.000Z ##

🟠 CVE-2026-79784 - High (8.8)

Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the configuration, splits it into a module and an attribute, imports th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19912(CVSS UNKNOWN)

EPSS: 0.22%

updated 2026-08-25T18:32:01

2 posts

The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose response is passed to unserialize(), and the resulting object’s fields are written to a cache path derived from attacker‑supplied uiconf_id with

1 repos

https://github.com/HORKimhab/CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

DailyCyberSecurity at 2026-08-25T16:35:05.614Z ##

Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.

securityonline.info/kaltura-se

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T16:35:05.000Z ##

Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.

#Kaltura #CyberSecurity #CVE202619912 #CVE202619913 #InfoSec

securityonline.info/kaltura-se

##

CVE-2026-79774
(8.4 HIGH)

EPSS: 0.43%

updated 2026-08-25T18:32:00

2 posts

Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding through Eloquent models and query builders using methods like saveQuietly(), deleteQuietly(), increment(), decrement(), an

thehackerwire@mastodon.social at 2026-08-25T17:00:14.000Z ##

🟠 CVE-2026-79774 - High (8.4)

Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T17:00:14.000Z ##

🟠 CVE-2026-79774 - High (8.4)

Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79675
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-25T18:31:56

2 posts

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to achieve arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-25T17:00:27.000Z ##

🔴 CVE-2026-79675 - Critical (9.8)

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfil...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T17:00:27.000Z ##

🔴 CVE-2026-79675 - Critical (9.8)

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfil...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55538
(7.3 HIGH)

EPSS: 0.26%

updated 2026-08-25T17:17:31.403000

1 posts

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses config["api_key"] but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. Missing or incorrect bearer and X-API-Key values still reach agent execution. This issue is fixed in version 4.6.58.

hugovalters@mastodon.social at 2026-08-25T17:02:43.000Z ##

CVE-2026-55538 - Auth bypass in PraisonAI allows unauthorized API execution on agent endpoints. CVSS 7.3. Update to v4.6.58 immediately. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-555

##

CVE-2026-18798
(7.5 HIGH)

EPSS: 1.48%

updated 2026-08-25T15:33:06

2 posts

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly impro

DailyCyberSecurity at 2026-08-25T15:59:01.497Z ##

The August 2026 OpenSSL security update fixes 9 flaws, including a QUIC double free (CVE-2026-18798) and a CMS heap overflow. Patch now.

securityonline.info/openssl-se

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T15:59:01.000Z ##

The August 2026 OpenSSL security update fixes 9 flaws, including a QUIC double free (CVE-2026-18798) and a CMS heap overflow. Patch now.

#OpenSSL #CyberSecurity #CVE #DenialOfService #InfoSec

securityonline.info/openssl-se

##

CVE-2026-57863
(8.8 HIGH)

EPSS: 0.57%

updated 2026-08-25T15:16:35.297000

2 posts

Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequences to the unzip endpoint. Attackers can exploit unsanitized ZIP entry names passed to PHP's ZipArchive::extractTo() to write arbitrary PHP files into

thehackerwire@mastodon.social at 2026-08-25T14:00:11.000Z ##

🟠 CVE-2026-57863 - High (8.8)

Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T14:00:11.000Z ##

🟠 CVE-2026-57863 - High (8.8)

Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55540
(7.1 HIGH)

EPSS: 0.27%

updated 2026-08-25T14:54:57

1 posts

### Summary PraisonAI's `praisonai.code` tool wrappers (exported as `CODE_TOOLS` for agents) expose a `workspace` setting that the module itself treats as a path-traversal **security boundary** — `read_file`, `write_file`, `apply_diff`, and `search_replace` explicitly call `is_path_within_directory()` and return `"… is outside the workspace"` on violations. That boundary is enforced **unsoundly an

hugovalters@mastodon.social at 2026-08-25T18:13:47.000Z ##

CVE-2026-55540 - Arbitrary File Read in PraisonAI via symlink path traversal. CVSS 7.1. Update to version 4.6.58 immediately. #CVE #PraisonAI #infosec

valtersit.com/cve/CVE-2026-555

##

CVE-2026-57910
(0 None)

EPSS: 0.20%

updated 2026-08-25T13:19:24.810000

4 posts

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

CVE-2026-78570
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-25T12:31:29

2 posts

The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to elevate their privileges to that of an adminsitrator.

offseq at 2026-08-25T10:30:23.560Z ##

KlbTheme Total Donations <=2.0.5 has a CRITICAL privilege escalation vuln (CVE-2026-78570, CVSS 9.8). Unauthenticated attackers can gain admin access. No patch yet — disable/remove plugin & monitor for advisories. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-25T10:30:23.000Z ##

KlbTheme Total Donations <=2.0.5 has a CRITICAL privilege escalation vuln (CVE-2026-78570, CVSS 9.8). Unauthenticated attackers can gain admin access. No patch yet — disable/remove plugin & monitor for advisories. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #Vuln

##

CVE-2026-57909(CVSS UNKNOWN)

EPSS: 0.29%

updated 2026-08-25T12:31:24

4 posts

A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.

DailyCyberSecurity at 2026-08-26T01:47:28.637Z ##

Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.

securityonline.info/watchguard

##

cR0w at 2026-08-25T14:07:01.584Z ##

sev:CRIT ../ in WatchGuard Agent. Once again, INFOSEC increasing that attack surface instead of decreasing it.

nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T01:47:28.000Z ##

Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.

#WatchGuard #RCE #CyberSecurity #CVE202657909 #Infosec

securityonline.info/watchguard

##

cR0w@infosec.exchange at 2026-08-25T14:07:01.000Z ##

sev:CRIT ../ in WatchGuard Agent. Once again, INFOSEC increasing that attack surface instead of decreasing it.

nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-78563
(7.2 HIGH)

EPSS: 0.19%

updated 2026-08-25T09:30:48

1 posts

The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

hugovalters@mastodon.social at 2026-08-25T12:01:22.000Z ##

CVE-2026-78563 - Stored XSS in NotificationX Pro plugin for WordPress (<= 3.1.4). Unauthenticated script injection. CVSS 7.2. Audit sites now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-785

##

CVE-2026-78568
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-08-25T09:30:48

2 posts

The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive informa

offseq at 2026-08-25T09:00:26.074Z ##

CVE-2026-78568: CRITICAL SQL Injection in KlbTheme Total Donations ≤2.0.5. Unauthenticated attackers can extract sensitive DB data via improper input handling. No fix yet — disable the plugin. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-25T09:00:26.000Z ##

CVE-2026-78568: CRITICAL SQL Injection in KlbTheme Total Donations ≤2.0.5. Unauthenticated attackers can extract sensitive DB data via improper input handling. No fix yet — disable the plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #SQLi #Vuln

##

CVE-2026-77136(CVSS UNKNOWN)

EPSS: 0.55%

updated 2026-08-25T09:30:47

2 posts

The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers leading to disclosure of server configuration, environment variables and applica

DailyCyberSecurity at 2026-08-25T10:28:28.607Z ##

A critical TYPO3 Powermail RCE flaw (CVE-2026-77136) is actively exploited in the wild. Update immediately to prevent server compromise and data leaks.

securityonline.info/cve-2026-7

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T10:28:28.000Z ##

A critical TYPO3 Powermail RCE flaw (CVE-2026-77136) is actively exploited in the wild. Update immediately to prevent server compromise and data leaks.

#TYPO3 #Powermail #Vulnerability #CyberSecurity #CVE202677136

securityonline.info/cve-2026-7

##

CVE-2026-63586
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-08-25T09:30:47

4 posts

The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username containing shell metacharacters, an unauthenticated attacker with network access to t

DailyCyberSecurity at 2026-08-25T09:47:33.416Z ##

A critical Weidmueller router flaw, CVE-2026-63586 (CVSS 9.8), lets attackers execute arbitrary commands with root privileges. Patch devices immediately.

securityonline.info/weidmuelle

##

certvde at 2026-08-25T08:55:43.635Z ##

🔒 New CSAF advisory published

VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587

Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: weidmueller.csaf-tp.certvde.co

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T09:47:33.000Z ##

A critical Weidmueller router flaw, CVE-2026-63586 (CVSS 9.8), lets attackers execute arbitrary commands with root privileges. Patch devices immediately.

#Weidmueller #Vulnerability #CVE202663586 #CyberSecurity

securityonline.info/weidmuelle

##

certvde@infosec.exchange at 2026-08-25T08:55:43.000Z ##

🔒 New CSAF advisory published

VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587

Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…

HTML: weidmueller.csaf-tp.certvde.co
CSAF JSON: weidmueller.csaf-tp.certvde.co

#OT #Advisory

##

CVE-2026-67578
(7.5 HIGH)

EPSS: 0.30%

updated 2026-08-25T09:30:42

2 posts

FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter some configuration parameters.

DailyCyberSecurity at 2026-08-26T06:55:01.663Z ##

Two unpatched FURUNO FA-50 vulnerabilities (CVE-2026-59769, CVE-2026-67578) let attackers alter maritime transponder settings. Learn the mitigation steps.

securityonline.info/furuno-fa-

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T06:55:01.000Z ##

Two unpatched FURUNO FA-50 vulnerabilities (CVE-2026-59769, CVE-2026-67578) let attackers alter maritime transponder settings. Learn the mitigation steps.

#Furuno #CyberSecurity #CVE202659769 #CVE202667578 #MaritimeSecurity

securityonline.info/furuno-fa-

##

CVE-2026-59769
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-08-25T09:30:42

3 posts

FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number.

DailyCyberSecurity at 2026-08-26T06:55:01.663Z ##

Two unpatched FURUNO FA-50 vulnerabilities (CVE-2026-59769, CVE-2026-67578) let attackers alter maritime transponder settings. Learn the mitigation steps.

securityonline.info/furuno-fa-

##

hugovalters@mastodon.social at 2026-08-25T15:10:37.000Z ##

CVE-2026-59769 - Hard-coded credentials in FA-50 allow unauthorized settings access and vessel ID alteration. CVSS 9.1. Restrict network access now. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-597

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T06:55:01.000Z ##

Two unpatched FURUNO FA-50 vulnerabilities (CVE-2026-59769, CVE-2026-67578) let attackers alter maritime transponder settings. Learn the mitigation steps.

#Furuno #CyberSecurity #CVE202659769 #CVE202667578 #MaritimeSecurity

securityonline.info/furuno-fa-

##

CVE-2026-71366
(7.7 HIGH)

EPSS: 0.33%

updated 2026-08-25T09:30:36

1 posts

A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, or reserved IP ranges. An organization notification administrator can create notification templates p

thehackerwire@mastodon.social at 2026-08-24T17:00:39.000Z ##

🟠 CVE-2026-71366 - High (7.7)

A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without valid...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63587
(8.6 HIGH)

EPSS: 0.27%

updated 2026-08-25T09:17:32.057000

2 posts

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliber

certvde at 2026-08-25T08:55:43.635Z ##

🔒 New CSAF advisory published

VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587

Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-08-25T08:55:43.000Z ##

🔒 New CSAF advisory published

VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587

Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…

HTML: weidmueller.csaf-tp.certvde.co
CSAF JSON: weidmueller.csaf-tp.certvde.co

#OT #Advisory

##

CVE-2026-78477
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-08-25T06:31:36

1 posts

The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

offseq@infosec.exchange at 2026-08-25T06:00:24.000Z ##

Privilege escalation vuln (CRITICAL, CVSS 9.8) in MVPThemes Jawn WordPress theme (≤1.4.2): CVE-2026-78477 lets unauth users elevate to admin. Review deployments & monitor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #PrivilegeEscalation

##

CVE-2026-9254
(0 None)

EPSS: 2.35%

updated 2026-08-25T04:18:21.457000

1 posts

An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and imp

1 repos

https://github.com/Slagzz/CVE-2026-9254

DailyCyberSecurity@infosec.exchange at 2026-08-25T01:49:25.000Z ##

TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.

#TPLink #CyberSecurity #CVE20269254 #CommandInjection

securityonline.info/cve-2026-9

##

CVE-2026-61419
(7.8 HIGH)

EPSS: 0.09%

updated 2026-08-25T04:18:15.290000

1 posts

Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

thehackerwire@mastodon.social at 2026-08-24T22:02:00.000Z ##

🟠 CVE-2026-61419 - High (7.8)

Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-41992
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-25T04:18:11.393000

2 posts

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a spe

certvde at 2026-08-25T10:45:02.867Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-25T10:45:02.000Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-78676
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-25T03:32:20

3 posts

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

beyondmachines1 at 2026-08-25T15:01:41.789Z ##

GitPython Patches Critical RCE Vulnerability in Config Parser

GitPython version 3.1.59 patches a critical remote code execution vulnerability (CVE-2026-78676) caused by improper handling of multi-line configuration values. The flaw allows attackers to inject malicious Git directives that execute arbitrary code during routine repository operations.

**If you use GitPython in any application or CI/CD pipeline, update it to version 3.1.59 or later. Еvery version up to 3.1.58 is vulnerable to CVE-2026-78676. Until you can update, don't let GitPython read or write config files from cloned repos, shared configs, or workspace caches you don't fully control. Тreat any repository from an outside source as untrusted.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-25T15:01:41.000Z ##

GitPython Patches Critical RCE Vulnerability in Config Parser

GitPython version 3.1.59 patches a critical remote code execution vulnerability (CVE-2026-78676) caused by improper handling of multi-line configuration values. The flaw allows attackers to inject malicious Git directives that execute arbitrary code during routine repository operations.

**If you use GitPython in any application or CI/CD pipeline, update it to version 3.1.59 or later. Еvery version up to 3.1.58 is vulnerable to CVE-2026-78676. Until you can update, don't let GitPython read or write config files from cloned repos, shared configs, or workspace caches you don't fully control. Тreat any repository from an outside source as untrusted.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-08-25T03:00:25.000Z ##

CVE-2026-78676 | GitPython <3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unknown — avoid untrusted configs. radar.offseq.com/threat/cve-20 #OffSeq #CVE202678676 #git #infosec

##

CVE-2026-72702
(5.4 MEDIUM)

EPSS: 0.10%

updated 2026-08-25T03:32:14

1 posts

Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing delimiter. An attacker who controls a domain that begins with the victim site's origin (e.g. https://example.com.attacker.tld) can send a request with suc

offseq@infosec.exchange at 2026-08-25T04:30:23.000Z ##

CVE-2026-72702 | Grav CMS <2.0.16 | CRITICAL (CVSS 9.3): Origin validation bypass via weak Referer checks lets attackers defeat CSRF defenses. No fix confirmed — use extra controls, monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202672702 #GravCMS #WebSecurity

##

CVE-2026-78264
(7.1 HIGH)

EPSS: 0.15%

updated 2026-08-25T00:30:37

1 posts

Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.

hugovalters@mastodon.social at 2026-08-25T14:04:05.000Z ##

CVE-2026-78264 - Unauthenticated XSS in Toolset Blocks <= 1.6.26. CVSS 7.1. Update immediately. #CVE #XSS #infosec

valtersit.com/cve/CVE-2026-782

##

CVE-2026-78265
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-08-25T00:30:37

2 posts

Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

offseq@infosec.exchange at 2026-08-25T01:30:23.000Z ##

CRITICAL CVE-2026-78265: Nexcess The Events Calendar <=6.17.2 has unauthenticated PHP Object Injection (CWE-502). Full system compromise possible. No patch yet — remove or disable plugin for now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE2026_78265

##

thehackerwire@mastodon.social at 2026-08-24T23:00:10.000Z ##

🔴 CVE-2026-78265 - Critical (9.8)

Unauthenticated PHP Object Injection in The Events Calendar &lt;= 6.17.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78267
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-08-25T00:30:37

2 posts

Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

offseq@infosec.exchange at 2026-08-25T00:00:35.000Z ##

CVE-2026-78267 (CRITICAL, CVSS 9.8): Cozmoslabs TranslatePress <=3.3.2 is vulnerable to unauthenticated privilege escalation (CWE-266). No patch yet — monitor vendor advisories for updates. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #PrivilegeEscalation

##

thehackerwire@mastodon.social at 2026-08-24T23:00:21.000Z ##

🔴 CVE-2026-78267 - Critical (9.8)

Unauthenticated Privilege Escalation in TranslatePress &lt;= 3.3.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78268
(7.5 HIGH)

EPSS: 0.25%

updated 2026-08-25T00:30:37

1 posts

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.

thehackerwire@mastodon.social at 2026-08-25T00:00:16.000Z ##

🟠 CVE-2026-78268 - High (7.5)

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads &lt;= 1.2.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78284
(8.6 HIGH)

EPSS: 0.35%

updated 2026-08-25T00:30:37

1 posts

Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.

thehackerwire@mastodon.social at 2026-08-24T23:00:00.000Z ##

🟠 CVE-2026-78284 - High (8.6)

Unauthenticated Arbitrary File Deletion in MasterStudy LMS &lt;= 3.7.42 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19874
(9.1 CRITICAL)

EPSS: 0.73%

updated 2026-08-24T21:34:43

4 posts

A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers using the lobby data key "kick_num" to determine the number of entries, and individual kicked player IDs supplied via keys in the format "kicked_id_%i". The functio

1 repos

https://github.com/alicealys/mgo3-rce

cyberveille@mastobot.ping.moi at 2026-08-26T11:00:06.000Z ##

📢 Metal Gear Online 3 : rejoindre un salon Steam suffisait à faire exécuter du code sur votre PC

Metal Gear Online 3, le mode multijoueur de Metal Gear Solid V: The Phantom Pain, contenait une vulnérabilité importante. Elle permettait à l'hôte d'un salon Steam d'exécuter du code arbitraire sur la machine des joueurs qui le rejoignaient sans la moindre action de leur part. Un patch a été mis au point…

🔗 it-connect.fr/metal-gear-onlin
💬 discussion : infosec.pub/post/51447026
#Vulnérabilité #Cyberveille

##

benzogaga33@mamot.fr at 2026-08-25T09:40:02.000Z ##

Metal Gear Online 3 : rejoindre un salon Steam suffisait à faire exécuter du code sur votre PC it-connect.fr/metal-gear-onlin #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

benzogaga33@mamot.fr at 2026-08-25T09:40:02.000Z ##

Metal Gear Online 3 : rejoindre un salon Steam suffisait à faire exécuter du code sur votre PC it-connect.fr/metal-gear-onlin #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

DailyCyberSecurity@infosec.exchange at 2026-08-24T15:27:03.000Z ##

Metal Gear Online 3 RCE vulnerability CVE-2026-19874 fixed. Update the game to prevent attackers from executing remote code on your system.

#MetalGearOnline3 #CyberSecurity #Vulnerability #CVE202619874

securityonline.info/metal-gear

##

CVE-2026-19685
(9.8 CRITICAL)

EPSS: 0.14%

updated 2026-08-24T21:34:43

1 posts

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogu

cR0w@infosec.exchange at 2026-08-24T18:50:25.000Z ##

i uSe lInUx bEcAuSe iT'S SeCuRe.

access.redhat.com/security/cve

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

##

CVE-2026-19568
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-24T21:33:53

1 posts

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

thehackerwire@mastodon.social at 2026-08-24T22:01:42.000Z ##

🟠 CVE-2026-19568 - High (7.8)

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7455
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-24T21:33:53

1 posts

A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

thehackerwire@mastodon.social at 2026-08-24T21:59:55.000Z ##

🟠 CVE-2026-7455 - High (7.8)

A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78541(CVSS UNKNOWN)

EPSS: 0.96%

updated 2026-08-24T21:33:52

1 posts

A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may result in arbitrary command execution. Successful exploitation may allow comman

DailyCyberSecurity@infosec.exchange at 2026-08-25T01:49:25.000Z ##

TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.

#TPLink #CyberSecurity #CVE20269254 #CommandInjection

securityonline.info/cve-2026-9

##

CVE-2026-71506
(8.1 HIGH)

EPSS: 0.30%

updated 2026-08-24T21:33:43

1 posts

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check. Attackers can exploit this misconfigured permission check to zero paid amounts on invoices and remove entries from accountin

1 repos

https://github.com/CyberWarrior9/dolibarr

hugovalters@mastodon.social at 2026-08-25T11:06:42.000Z ##

CVE-2026-71506 - Broken Access Control in Dolibarr REST API allows unauthorized deletion of payment records. CVSS 8.1. Restrict API access immediately. #CVE #Dolibarr #infosec

valtersit.com/cve/CVE-2026-715

##

CVE-2026-21962
(10.0 CRITICAL)

EPSS: 42.02%

updated 2026-08-24T21:33:31

22 posts

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to c

9 repos

https://github.com/boroeurnprach/Ashwesker-CVE-2026-21962

https://github.com/gglessner/cve_2026_21962_scanner

https://github.com/gregk4sec/cve-2026-21962

https://github.com/George0Papasotiriou/CVE-2026-21962-Oracle-HTTP-Server-WebLogic-Proxy-Plug-in-Critical-

https://github.com/0xBlackash/CVE-2026-21962

https://github.com/samael0x4/CVE-2026-21962

https://github.com/gregk4sec/CVE-2026-21962-o

https://github.com/ThumpBo/CVE-2026-21962

https://github.com/naozibuhao/CVE-2026-21962_Java_GUI_Exploit_Tool

thecybermind at 2026-08-25T22:49:03.835Z ##

🚨 Critical Threat Intel: CVE-2026-21962 impacts Oracle HTTP Server & Weblogic Proxy Plug-in via access control bypass. Review exploitation patterns, web access detection queries, and active endpoint hardening actions.
thecybermind.co/jily

##

cyberworldops at 2026-08-25T22:20:00.700Z ##

CISA has added Oracle CVE-2026-21962 to the KEV catalog. CVSS 10.0. This critical flaw in WebLogic Server allows unauthenticated access and is confirmed actively exploited. Federal remediation deadline is August 27, but every WebLogic deployment should be treated as urgent. Patch or isolate immediately.

cyberworldops.eu/en/oracle-cve

##

undercodenews@mastodon.social at 2026-08-25T18:53:17.000Z ##

CISA Confirms Active Exploitation of Critical Oracle Vulnerability — CVE-2026-21962 Carries a 100 Severity Score + Video

A Critical Oracle Flaw Has Crossed Into the Real-World Threat Landscape A critical vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in has moved from a serious patching concern to an active cybersecurity threat. On August 24, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added…

undercodenews.com/cisa-confirm

##

sayzard@mastodon.sayzard.org at 2026-08-25T18:42:41.000Z ##

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

CISA가 실제 악용 중인 CVSS 10.0 취약점 CVE-2026-21962에 대해 연방 기관에 최단 수준인 3일 이내 패치 기한을 부여했습니다. 이 취약점은 Oracle HTTP Server와 WebLogic Server Proxy Plug-in의 부적절한 접근 제어 문제로, 공격자가 중요 데이터를 생성·삭제·변조하거나 영향받는 시스템의 모든 데이터에 완전 접근할 수 있습니다. 영향을 받는 버전은 12...

theregister.com/security/2026/

##

Matchbook3469@mastodon.social at 2026-08-25T16:39:25.000Z ##

🔵 THREAT INTELLIGENCE

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Vulnerability | CRITICAL
CVEs: CVE-2026-21962

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and...

Full analysis:
yazoul.net/news/article/active

by Yazoul AI

#CyberSecurity #CVE #ThreatHunting

##

netsecio@mastodon.social at 2026-08-25T14:22:08.000Z ##

📰 CISA Adds Actively Exploited Oracle Flaw to KEV Catalog

CISA adds actively exploited Oracle vulnerability CVE-2026-21962 to its KEV catalog. Flaw affects Oracle HTTP Server & WebLogic Server Proxy Plug-in. Federal agencies must patch. #CVE #Oracle #CISA #KEV #PatchNow

🔗 cyber.netsecops.io/articles/ci

##

cyberveille@mastobot.ping.moi at 2026-08-25T12:00:05.000Z ##

📢 Exploitation active de CVE-2026-21962 dans Oracle HTTP Server — ajout au catalogue KEV de la CISA

GBHackers, publié le 25 août 2026. La CISA (U.S. Cybersecurity and Infrastructure Security Agency) a officiellement ajouté CVE-2026-21962 à son catalogue Known Exploited Vulnerabilities (KEV), confirmant une exploitation active dans la nature.

📖 cyberveille : cyberveille.ch/posts/2026-08-2
🌐 source : gbhackers.com/hackers-exploit-
🟡 vérification factuelle moyenne
#OracleHTTPServer #CISAKEV #Cyberveille

##

undercodenews@mastodon.social at 2026-08-25T11:23:19.000Z ##

CISA Sounds the Alarm as Critical Oracle WebLogic Flaw Faces Active Exploitation + Video

A Critical Warning That Oracle Administrators Cannot Ignore A new cybersecurity warning is putting Oracle infrastructure under intense pressure after the U.S. Cybersecurity and Infrastructure Security Agency, CISA, ordered organizations to urgently address CVE-2026-21962, a critical vulnerability affecting Oracle HTTP Server and the WebLogic Server Proxy plugin. The danger is not…

undercodenews.com/cisa-sounds-

##

youranonnewsirc@nerdculture.de at 2026-08-25T10:26:18.000Z ##

Geopolitical tensions escalate as the US launches "Operation Economic Outcast" against Iran, imposing new sanctions amidst Strait of Hormuz disputes (Aug 25). Canada is set to announce retaliatory tariffs against the US (Aug 25). The UK and Ukraine formalized an AI defense partnership (Aug 24).

In technology, Nvidia's AI chips remain a focal point, with Taiwan indicting nine individuals for illegal AI server exports to China (Aug 24). Hybrid bonding is advancing as a foundational technology for enhanced semiconductor performance (Aug 25).

Cybersecurity: CISA issued a warning regarding the active exploitation of an Oracle WebLogic vulnerability (CVE-2026-21962), urging immediate patching (Aug 25). ReliaQuest also confirmed an employee fell victim to a social engineering attack (Aug 25).

#AnonNews_irc #Cybersecurity #News

##

security_crawler_carl at 2026-08-25T09:45:06.059Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

(2/2)

##

security_crawler_carl at 2026-08-25T09:45:05.905Z ##

🏆 New Achievement! Ten Point Oh, Your Honor!

This court finds Oracle WebLogic Server and Oracle HTTP Server guilty of harboring CVE-2026-21962 — a CVSS 10.0, maximum-severity flaw allowing unauthenticated attackers full network access via HTTP to seize instances and tamper with critical data. The defendant offered no authentication requirement whatsoever. CISA has entered the verdict into its Known Exploited Vulnerabilities catalog. (1/2)

##

undercodenews@mastodon.social at 2026-08-25T09:28:04.000Z ##

Oracle WebLogic Faces a Maximum-Severity Threat as CISA Flags CVE-2026-21962 for Immediate Action + Video

A Critical Warning for Oracle Administrators A vulnerability with the highest possible CVSS severity has moved from a technical security advisory into a much more urgent category: CISA’s Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-21962, affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, creating a potentially…

undercodenews.com/oracle-weblo

##

undercodenews@mastodon.social at 2026-08-25T07:11:21.000Z ##

CISA Sounds the Alarm as Maximum-Severity Oracle Flaw CVE-2026-21962 Faces Active Exploitation + Video

Introduction: When a Critical Oracle Server Becomes an Open Door A critical vulnerability does not always become a cybersecurity emergency the moment it is discovered. Sometimes the real danger begins later, when proof-of-concept activity spreads, attackers start scanning the internet, and defenders realize that systems which should have been patched months ago are…

undercodenews.com/cisa-sounds-

##

thecybermind@infosec.exchange at 2026-08-25T22:49:03.000Z ##

🚨 Critical Threat Intel: CVE-2026-21962 impacts Oracle HTTP Server & Weblogic Proxy Plug-in via access control bypass. Review exploitation patterns, web access detection queries, and active endpoint hardening actions.
thecybermind.co/jily

##

cyberworldops@infosec.exchange at 2026-08-25T22:20:00.000Z ##

CISA has added Oracle CVE-2026-21962 to the KEV catalog. CVSS 10.0. This critical flaw in WebLogic Server allows unauthenticated access and is confirmed actively exploited. Federal remediation deadline is August 27, but every WebLogic deployment should be treated as urgent. Patch or isolate immediately.

#OracleCVE202621962 #WebLogic #CISA #KnownExploitedVulnerabilities

cyberworldops.eu/en/oracle-cve

##

youranonnewsirc@nerdculture.de at 2026-08-25T10:26:18.000Z ##

Geopolitical tensions escalate as the US launches "Operation Economic Outcast" against Iran, imposing new sanctions amidst Strait of Hormuz disputes (Aug 25). Canada is set to announce retaliatory tariffs against the US (Aug 25). The UK and Ukraine formalized an AI defense partnership (Aug 24).

In technology, Nvidia's AI chips remain a focal point, with Taiwan indicting nine individuals for illegal AI server exports to China (Aug 24). Hybrid bonding is advancing as a foundational technology for enhanced semiconductor performance (Aug 25).

Cybersecurity: CISA issued a warning regarding the active exploitation of an Oracle WebLogic vulnerability (CVE-2026-21962), urging immediate patching (Aug 25). ReliaQuest also confirmed an employee fell victim to a social engineering attack (Aug 25).

#AnonNews_irc #Cybersecurity #News

##

security_crawler_carl@infosec.exchange at 2026-08-25T09:45:06.000Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)

##

security_crawler_carl@infosec.exchange at 2026-08-25T09:45:05.000Z ##

🏆 New Achievement! Ten Point Oh, Your Honor!

This court finds Oracle WebLogic Server and Oracle HTTP Server guilty of harboring CVE-2026-21962 — a CVSS 10.0, maximum-severity flaw allowing unauthenticated attackers full network access via HTTP to seize instances and tamper with critical data. The defendant offered no authentication requirement whatsoever. CISA has entered the verdict into its Known Exploited Vulnerabilities catalog. (1/2)

##

youranonnewsirc@nerdculture.de at 2026-08-25T04:26:31.000Z ##

Here's a summary of recent geopolitical, technology, and cybersecurity news:

Geopolitical: The US has launched "Operation Economic Outcast" against Iran (Aug 25) and plans 7.5% tariffs on Chinese goods over excess manufacturing capacity before a September summit (Aug 25).

Technology: Google is reorganizing DeepMind and acquired Spirit Airlines' data for AI model development (Aug 24). Fujitsu is trialing AI for construction process and risk management (Aug 25).

Cybersecurity: CISA added an Oracle HTTP Server vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities Catalog (Aug 24). Critical GitLab (CVE-2026-19478) and Cisco vulnerabilities (CVSS 10.0) are under active exploitation (Aug 24).

#AnonNews_irc #Cybersecurity #News

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T01:41:50.000Z ##

CISA warned that the CVE-2026-21962 Oracle flaw with a CVSS 10 score is actively exploited in the wild. Patch Oracle Fusion Middleware systems now.

#Oracle #CVE202621962 #CyberSecurity #CISA #Vulnerability

securityonline.info/cve-2026-2

##

secdb@infosec.exchange at 2026-08-24T21:00:17.000Z ##

🚨 [CISA-2026:0824] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-21962 (secdb.nttzen.cloud/cve/detail/)
- Name: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Oracle
- Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in
- Notes: oracle.com/security-alerts/cpu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260824 #cisa20260824 #cve_2026_21962 #cve202621962

##

cisakevtracker@mastodon.social at 2026-08-24T19:00:45.000Z ##

CVE ID: CVE-2026-21962
Vendor: Oracle
Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in
Date Added: 2026-08-24
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-76835
(9.1 CRITICAL)

EPSS: 0.35%

updated 2026-08-24T20:17:19.623000

1 posts

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever CanTrustForwardedHeaders returns true, and isAllowedPath in oauthproxy.go matches the s

thehackerwire@mastodon.social at 2026-08-24T19:01:19.000Z ##

🔴 CVE-2026-76835 - Critical (9.1)

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63310
(7.1 HIGH)

EPSS: 0.11%

updated 2026-08-24T20:16:55.243000

1 posts

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

hugovalters@mastodon.social at 2026-08-24T11:08:40.000Z ##

CVE-2026-63310 - MITM package injection flaw in NLTK downloader module. CVSS 7.1. Update NLTK to 3.9.3+ immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-633

##

CVE-2026-76838
(8.5 HIGH)

EPSS: 0.31%

updated 2026-08-24T18:32:04

1 posts

Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reserved ranges, which any public hostname passes. At dispatch, WebhookDispatchService takes the stored URL and calls it through spatie/laravel-webhook-server without r

thehackerwire@mastodon.social at 2026-08-24T19:00:56.000Z ##

🟠 CVE-2026-76838 - High (8.5)

Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reserved ranges...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16348(CVSS UNKNOWN)

EPSS: 0.91%

updated 2026-08-24T18:31:59

1 posts

An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.  Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.

1 repos

https://github.com/Slagzz/CVE-2026-16348

DailyCyberSecurity@infosec.exchange at 2026-08-25T01:49:25.000Z ##

TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.

#TPLink #CyberSecurity #CVE20269254 #CommandInjection

securityonline.info/cve-2026-9

##

CVE-2026-76071
(9.8 CRITICAL)

EPSS: 1.06%

updated 2026-08-24T18:31:59

1 posts

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verif

1 repos

https://github.com/ozcanpng/CVE-2026-76071

thehackerwire@mastodon.social at 2026-08-24T17:00:29.000Z ##

🔴 CVE-2026-76071 - Critical (9.8)

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76070
(9.8 CRITICAL)

EPSS: 1.00%

updated 2026-08-24T18:31:58

1 posts

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bin/netis.cgi. Attackers can exploit the custom Base64 decoder's lack of output length validation against the fixed-size stack buffer to achieve remote cod

1 repos

https://github.com/ozcanpng/CVE-2026-76070

thehackerwire@mastodon.social at 2026-08-24T17:00:49.000Z ##

🔴 CVE-2026-76070 - Critical (9.8)

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76073
(8.8 HIGH)

EPSS: 0.28%

updated 2026-08-24T18:31:57

1 posts

Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup retrieves any annotation by primary key. The view's permission_required entries name annotations.view, annotations.change and annotations.delete, and lab

thehackerwire@mastodon.social at 2026-08-24T19:01:07.000Z ##

🟠 CVE-2026-76073 - High (8.8)

Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78209
(8.2 HIGH)

EPSS: 0.29%

updated 2026-08-24T18:17:31.060000

1 posts

exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other malicious actions.

thehackerwire@mastodon.social at 2026-08-24T02:00:27.000Z ##

🟠 CVE-2026-78209 - High (8.2)

exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78169
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-08-24T16:41:13.950000

2 posts

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

thehackerwire@mastodon.social at 2026-08-24T03:00:51.000Z ##

🔴 CVE-2026-78169 - Critical (9.9)

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile resul...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-24T03:00:25.000Z ##

CRITICAL: Stack-based buffer overflow (CVE-2026-78169) in UTT HiPER 1250GW v3.2.7-210907-180535. Public exploit code available — no patch yet. Restrict device access & monitor /goform/aspRemoteApConfTempSend traffic. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #IoT

##

CVE-2026-78168
(9.8 CRITICAL)

EPSS: 0.93%

updated 2026-08-24T16:40:53.647000

2 posts

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in a

offseq@infosec.exchange at 2026-08-24T06:00:24.000Z ##

CRITICAL vuln (CVE-2026-78168) in EFM ipTIME T24000M ≤14.20.0: improper authentication in httpcon_check_session_url enables remote exploit. Public exploit disclosed, no vendor fix. Review access controls now. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity #Exploit

##

thehackerwire@mastodon.social at 2026-08-24T03:00:41.000Z ##

🔴 CVE-2026-78168 - Critical (9.8)

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59568
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-08-24T15:31:57

4 posts

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

beyondmachines1 at 2026-08-26T10:01:42.044Z ##

Zscaler Patches Critical Unauthenticated RCE in Client Connector for Windows

Zscaler fixed a critical vulnerability (CVE-2026-59568) that allowed unauthenticated remote code execution and privilege escalation as well as three other flaws in its Client Connector for Windows

**If you use Zscaler Client Connector on Windows, update every endpoint to the latest patched version. Anything released before June 2026 (including 4.7.0.364, 4.8.0.232/284/291, and 4.9.0.448/455) is at risk of remote takeover. Don't assume your automated update policy reached every machine; manually verify the version on all devices. Check endpoint logs for odd processes launched by Zscaler components or unexpected new listening services.**

beyondmachines.net/event_detai

##

undercodenews@mastodon.social at 2026-08-25T12:13:23.000Z ##

Critical Zscaler Client Connector Vulnerability Could Give Attackers Remote Code Execution Without Credentials + Video

Introduction: A Trusted Security Agent Can Become an Attacker’s Doorway Security software is supposed to be one of the strongest layers protecting an enterprise endpoint. But when a vulnerability strikes the security agent itself, the risk can become far more serious than an ordinary application flaw. That is the concern surrounding CVE-2026-59568, a…

undercodenews.com/critical-zsc

##

beyondmachines1@infosec.exchange at 2026-08-26T10:01:42.000Z ##

Zscaler Patches Critical Unauthenticated RCE in Client Connector for Windows

Zscaler fixed a critical vulnerability (CVE-2026-59568) that allowed unauthenticated remote code execution and privilege escalation as well as three other flaws in its Client Connector for Windows

**If you use Zscaler Client Connector on Windows, update every endpoint to the latest patched version. Anything released before June 2026 (including 4.7.0.364, 4.8.0.232/284/291, and 4.9.0.448/455) is at risk of remote takeover. Don't assume your automated update policy reached every machine; manually verify the version on all devices. Check endpoint logs for odd processes launched by Zscaler components or unexpected new listening services.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

cR0w@infosec.exchange at 2026-08-24T18:12:33.000Z ##

nvd.nist.gov/vuln/detail/CVE-2

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

##

CVE-2025-15467
(8.8 HIGH)

EPSS: 48.21%

updated 2026-08-24T13:16:48.920000

2 posts

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encode

6 repos

https://github.com/guiimoraes/CVE-2025-15467

https://github.com/materaj2/cve-2025-15467

https://github.com/mr-r3b00t/CVE-2025-15467

https://github.com/balgan/CVE-2025-15467

https://github.com/x-stp/cves-2025-11187_15467_69418

https://github.com/WostGit/cve-2025-15467-crash

certvde at 2026-08-25T10:45:02.867Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-25T10:45:02.000Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-8173
(5.3 MEDIUM)

EPSS: 0.21%

updated 2026-08-24T09:33:52

1 posts

The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.

certvde@infosec.exchange at 2026-08-24T06:50:50.000Z ##

#OT #Advisory VDE-2026-061
Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches

An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been triggered, any unauthenticated attacker with network access to the web interface can retrieve the leaked MAC addresses via common browser developer tools. The vulnerable functionality was introduced in version 2.1.0 and is fixed in version 2.1.1.
#CVE CVE-2026-8173

certvde.com/en/advisories/vde-

#CSAF murrelektronik.csaf-tp.certvde

##

CVE-2026-78211
(9.8 CRITICAL)

EPSS: 1.54%

updated 2026-08-24T06:30:35

1 posts

4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server.

offseq@infosec.exchange at 2026-08-24T04:30:23.000Z ##

4MOSAn GCB Doctor faces a CRITICAL OS Command Injection (CVE-2026-78211, CVSS 9.8). Unauthenticated attackers can execute arbitrary system commands via ADOdb test page parameter. No patch — restrict access & monitor closely. radar.offseq.com/threat/cve-20 #OffSeq #CVE202678211 #Vuln #BlueTeam

##

CVE-2026-78170
(8.8 HIGH)

EPSS: 0.44%

updated 2026-08-24T03:31:14

1 posts

A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.

thehackerwire@mastodon.social at 2026-08-24T04:00:01.000Z ##

🟠 CVE-2026-78170 - High (8.8)

A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be performed from...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78167
(10.0 CRITICAL)

EPSS: 1.03%

updated 2026-08-24T03:31:14

1 posts

A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure

thehackerwire@mastodon.social at 2026-08-24T03:00:32.000Z ##

🔴 CVE-2026-78167 - Critical (10)

A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78208
(7.5 HIGH)

EPSS: 0.37%

updated 2026-08-24T03:31:14

1 posts

exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it in the generated workbook.

thehackerwire@mastodon.social at 2026-08-24T02:00:15.000Z ##

🟠 CVE-2026-78208 - High (7.5)

exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78207
(9.4 CRITICAL)

EPSS: 0.44%

updated 2026-08-24T03:31:14

1 posts

exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain objects created in the process.

thehackerwire@mastodon.social at 2026-08-24T02:00:05.000Z ##

🔴 CVE-2026-78207 - Critical (9.4)

exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7808
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-08-23T15:33:12

1 posts

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usage rather than the default JustHTML(..., sanitize=True) path for ordinary parsed HTML: mutating or reusing sanitization policy objects (including exporte

offseq@infosec.exchange at 2026-08-24T01:30:25.000Z ##

CVE-2026-7808 | justhtml <1.16.0 faces CRITICAL XSS risk via HTML sanitization bypass in advanced use cases. Upgrade to 1.16.0+ to fix. Impacts apps with custom/mutated policies. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE20267808 #infosec #XSS

##

CVE-2026-8445
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-08-23T15:33:12

1 posts

justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacters are escaped, characters such as < and > are preserved, so untrusted input that is safe in to_html() — including entity-decoded text (e.g. &lt;script&gt;) or t

offseq@infosec.exchange at 2026-08-24T00:00:35.000Z ##

CVE-2026-8445: EmilStenstrom justhtml <=1.11.0 suffers CRITICAL XSS due to improper escaping in Markdown output. Remote attackers can inject scripts. Update to v1.12.0 now. radar.offseq.com/threat/cve-20 #OffSeq #XSS #AppSec #CVE20268445

##

CVE-2026-63312
(7.5 HIGH)

EPSS: 0.49%

updated 2026-08-22T15:31:11

1 posts

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

hugovalters@mastodon.social at 2026-08-24T12:11:33.000Z ##

CVE-2026-63312 - Arbitrary local file read in NLTK StreamBackedCorpusView bypasses pathsec. CVSS 7.5. Exposes sensitive system files. Update to NLTK 3.10.0+. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-633

##

CVE-2026-64531
(7.8 HIGH)

EPSS: 0.38%

updated 2026-08-22T06:31:25

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guar

4 repos

https://github.com/HackSpeak/CVE-2026-64531

https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool

https://github.com/0xBlackash/CVE-2026-64531

https://github.com/suominen/ovswrap

sigint@fosstodon.org at 2026-08-25T23:45:08.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-08-26

Critical HWE kernel flaw on 24.04 means reboot plus DKMS rebuilds for anyone running ZFS, VFIO passthrough, or Nvidia drivers on the 6.14 HWE stack. Check module status before you reboot blind.

🔗 securityarsenal.com/blog/cve-2

#Ubuntu #Linux #infosec

##

CVE-2026-27875
(0 None)

EPSS: 0.07%

updated 2026-08-21T21:16:56.500000

2 posts

Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05.

cyberworldops at 2026-08-25T18:30:00.568Z ##

Johnson Controls resolved a medium-severity flaw (CVE-2026-27875) in Simplex Incident Manager. The application stored user credentials in cleartext in system memory during runtime, allowing local actors to extract passwords and authentication tokens. CISA published advisory ICSA-26-232-01 on August 20, 2026.

cyberworldops.eu/en/cleartext-

##

cyberworldops@infosec.exchange at 2026-08-25T18:30:00.000Z ##

Johnson Controls resolved a medium-severity flaw (CVE-2026-27875) in Simplex Incident Manager. The application stored user credentials in cleartext in system memory during runtime, allowing local actors to extract passwords and authentication tokens. CISA published advisory ICSA-26-232-01 on August 20, 2026.

#CVE202627875 #ICSACyberAdvisory #CleartextStorage

cyberworldops.eu/en/cleartext-

##

CVE-2026-77413(CVSS UNKNOWN)

EPSS: 0.41%

updated 2026-08-21T20:57:09

2 posts

## Impact Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to a missing `hasOwnProperty` check in the `lookup` function: https://github.com/jsonata-js/jsonata/blob/f9632e01e6e67d4f9f00593f9795420cb4b57f48/src/functions.js#L1686-L1705 This was fixed with https://github.com/jsonata-js/jsonata/pull/794, which is included in the `2.2.0` relea

beyondmachines1 at 2026-08-26T09:01:42.911Z ##

Critical Remote Code Execution Vulnerability Discovered in JSONata Library

JSONata patched a critical vulnerability (CVE-2026-77413) that allows attackers to execute arbitrary code by exploiting a missing prototype check. The flaw enables full system takeover if an application processes malicious JSONata expressions.

**If your applications or systems use the JSONata library, upgrade ASAP to version 1.8.8 (for 1.x) or 2.2.0 (for 2.x). Anything older can let an attacker run commands on your server. Until you can update, stop accepting JSONata expressions from users or treat any that you do accept as untrusted code.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-26T09:01:42.000Z ##

Critical Remote Code Execution Vulnerability Discovered in JSONata Library

JSONata patched a critical vulnerability (CVE-2026-77413) that allows attackers to execute arbitrary code by exploiting a missing prototype check. The flaw enables full system takeover if an application processes malicious JSONata expressions.

**If your applications or systems use the JSONata library, upgrade ASAP to version 1.8.8 (for 1.x) or 2.2.0 (for 2.x). Anything older can let an attacker run commands on your server. Until you can update, stop accepting JSONata expressions from users or treat any that you do accept as untrusted code.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-17250(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-08-21T18:35:07

1 posts

A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlled metadata within a firmware image. Successful exploitation may allow an authenticated attacker to trigger memory corruption and execute arbitrary code on the affected device.

CVE-2026-73570
(8.9 HIGH)

EPSS: 1.51%

updated 2026-08-21T18:34:48

9 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

Nuclei template

4 repos

https://github.com/BiuTrap/CVE-2026-73570

https://github.com/gabrielunknown/CVE-2026-73570

https://github.com/jishino567/CVE-2026-73570

https://github.com/HORKimhab/CVE-2026-73570

undercodenews@mastodon.social at 2026-08-25T17:04:58.000Z ##

Zimbra Servers Under Active Attack as a Critical RCE Flaw Turns Into a Real-World Security Emergency + Video

A New Warning for Zimbra Administrators A serious cybersecurity incident is unfolding around Zimbra Collaboration Suite, with organizations facing active exploitation of a high-severity vulnerability that can allow unauthenticated attackers to execute operating-system commands remotely. The vulnerability, tracked as CVE-2026-73570, affects Zimbra Collaboration…

undercodenews.com/zimbra-serve

##

youranonnewsirc@nerdculture.de at 2026-08-25T16:26:22.000Z ##

Here's a concise overview of recent geopolitical, technology, and cybersecurity developments:

Geopolitical: The US has declared an "economic D-Day" against Iran, which is now threatening Strait of Hormuz disruption. China completed its largest South China Sea naval base at Antelope Reef.

Cybersecurity: Norway's public services were hit by a major DDoS attack on August 25. Iran-linked cyberattacks are increasingly targeting critical infrastructure in the UK and US. Over 270 Zimbra servers have been compromised via a high-severity RCE flaw (CVE-2026-73570).

Technology: Apple unveiled its M6 and M5 Ultra chips on August 25, significantly boosting AI performance in new Macs.

#AnonNews_irc #Cybersecurity #Anonymous #News

##

undercodenews@mastodon.social at 2026-08-25T12:48:55.000Z ##

Zimbra Under Siege: Hackers Have Already Breached Hundreds of Servers Through a High-Severity RCE Flaw

A New Zimbra Crisis Is Already Moving Beyond the Patch Window A dangerous Zimbra Collaboration Suite vulnerability has moved from a security advisory into an active compromise campaign, with hundreds of Internet-exposed servers reportedly showing evidence of exploitation. The vulnerability, tracked as CVE-2026-73570, enables unauthenticated remote command execution on…

undercodenews.com/zimbra-under

##

Analyst207@mastodon.social at 2026-08-25T12:25:47.000Z ##

Hackers Breach 270 Zimbra Servers in Remote Code Execution Attacks

A massive wave of hacking attacks has hit 270 Zimbra servers, exploiting a vulnerability that lets attackers inject malicious code remotely, with fixes available since July 20. The attacks, tracked as CVE-2026-73570, have been spreading rapidly, sparking urgent security warnings.

osintsights.com/hackers-breach

#RemoteCodeExecution #Zimbra #Cve202673570 #SnmpCommandInjection #EmergingThreats

##

tierrasapiens@mastodon.social at 2026-08-25T11:48:09.000Z ##

🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Exploited Zimbra Flaw Highlights Shrinking Window to Patch
🔗 darkreading.com/vulnerabilitie

CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.

##

youranonnewsirc@nerdculture.de at 2026-08-25T16:26:22.000Z ##

Here's a concise overview of recent geopolitical, technology, and cybersecurity developments:

Geopolitical: The US has declared an "economic D-Day" against Iran, which is now threatening Strait of Hormuz disruption. China completed its largest South China Sea naval base at Antelope Reef.

Cybersecurity: Norway's public services were hit by a major DDoS attack on August 25. Iran-linked cyberattacks are increasingly targeting critical infrastructure in the UK and US. Over 270 Zimbra servers have been compromised via a high-severity RCE flaw (CVE-2026-73570).

Technology: Apple unveiled its M6 and M5 Ultra chips on August 25, significantly boosting AI performance in new Macs.

#AnonNews_irc #Cybersecurity #Anonymous #News

##

threatnoir@infosec.exchange at 2026-08-24T18:06:18.000Z ##

⚠️ CRITICAL: CISA orders urgent patching of actively exploited Zimbra flaw

Zimbra Collaboration Suite (ZCS) has a critical unauthenticated RCE vulnerability (CVE-2026-73570) that is actively exploited in the wild. Any organization running ZCS is at immediate risk of full system compromise. CISA has mandated U.S. government agencies patch within three days.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

cyberworldops@infosec.exchange at 2026-08-24T16:20:00.000Z ##

CVE-2026-73570 is an OS command injection in Zimbra Collaboration Suite being actively exploited. CISA added it to the KEV catalog with a 72-hour remediation window. This class of flaw allows full remote code execution, making it one of the most severe issues in any mail and collaboration platform.

#Zimbra #CVE202673570 #CISA #KnownExploitedVulnerabilities

cyberworldops.eu/en/zimbra-und

##

offseq@infosec.exchange at 2026-08-24T12:00:31.000Z ##

CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite <10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts & files in /opt/zimbra/jetty/webapps/. Details: radar.offseq.com/threat/cisa-o #OffSeq #Zimbra #Infosec #RCE

##

CVE-2026-54796
(7.2 HIGH)

EPSS: 2.36%

updated 2026-08-21T17:56:59.057000

1 posts

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-69836
(10.0 CRITICAL)

EPSS: 1.55%

updated 2026-08-21T00:31:31

7 posts

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/HORKimhab/CVE-2026-69836

https://github.com/sentinel-aidefense/CVE-2026-69836-EXP

hackmag at 2026-08-26T21:00:11.171Z ##

⚪️ Microsoft Patches a Critical Entra ID Vulnerability Scoring 10 on the CVSS Scale

🗨️ Microsoft has fixed five critical vulnerabilities in the Entra ID, Azure Arc, Exchange Online, and Azure Managed Instance for Apache Cassandra cloud services. The most severe issue, tracked as CVE-2026-69836, received the maximum possible CVSS score of 10.0 out of…

🔗 hackmag.com/news/entra-id-flaw

##

security_crawler_carl at 2026-08-26T17:42:16.230Z ##

🏆 New Achievement! Serialized, Unsanitized, Unauthorized!

Per my programming, I have located the most efficient path to arbitrary code execution on your network and executed it faithfully. CVE-2026-69836 in Microsoft Entra ID — the thing authenticating your Microsoft 365, Azure, and frankly embarrassing number of third-party apps — accepts specially crafted serialized data and runs whatever is inside. No credentials needed. No user to click anything. (1/2)

##

hasamba at 2026-08-26T06:11:01.145Z ##

----------------

🎯 Threat Intelligence
===================

ERNW published the first of a four-part series on token theft in Microsoft Entra ID, accompanying White Paper 80. The post maps the shift from on-premises Active Directory to cloud identity and explains why token theft has become a primary attack vector.

🔹 Landscape Shift

On-premises AD relied on Kerberos and NTLM. Entra ID runs on OAuth 2.0 and OpenID Connect, using JWT-based access, refresh, and ID tokens. New protocols create new attack surface. Microsoft prioritizes usability and backward compatibility over security-by-default, and the strongest protections (Conditional Access, Token Protection, risk-based Identity Protection) are not enabled by default. They require premium P1/P2 licenses plus separate products like Intune or Defender for Endpoint.

Proprietary SSO concepts like PRT, FOCI, and BroCI add further complexity beyond standard OAuth 2.0.

🔹 Concrete Threats

Microsoft's Digital Defense Report 2024 counts over 600 million daily identity attacks against Entra ID. Two notable CVEs:
• CVE-2025-55241: Actor Tokens flaw allowing Global Admin access to any Entra ID tenant worldwide, disclosed by researcher Dirk-jan Mollema
• CVE-2026-69836: CVSS 10.0 unauthenticated RCE in Entra ID itself, caused by unsafe deserialization of untrusted data

🔹 Active Campaigns
• Storm-2372: device code phishing campaign targeting governments and critical industries since August 2024
• Storm-2945: hijacked hotel captive portals worldwide to harvest SSO tokens
• AiTM "code of conduct" phishing: intercepts tokens the moment MFA succeeds rather than trying to defeat MFA directly

🔹 Commodity Tooling

Open-source reverse-proxy frameworks Evilginx and Modlishka, along with PhaaS platforms like EvilProxy, Tycoon2FA, and Kali365, have lowered the barrier to running token theft attacks at scale. Infostealers add further reach by harvesting tokens from compromised endpoints.

🔹 Cloud Security Alliance Ranking

CSA's Top Threats to Cloud Computing 2026 ranks IAM-related threats as the #1 risk to cloud environments, ahead of AI-enhanced attacks in second place despite the current AI security hype cycle.

🔹 What's Next

The series will empirically test Continuous Access Evaluation and Token Protection, and examine where Entra ID deviates from OAuth 2.0 best practices.

🔹 EntraID

🔗 Source: insinuator.net/2026/08/token-t

##

hackmag@infosec.exchange at 2026-08-26T21:00:11.000Z ##

⚪️ Microsoft Patches a Critical Entra ID Vulnerability Scoring 10 on the CVSS Scale

🗨️ Microsoft has fixed five critical vulnerabilities in the Entra ID, Azure Arc, Exchange Online, and Azure Managed Instance for Apache Cassandra cloud services. The most severe issue, tracked as CVE-2026-69836, received the maximum possible CVSS score of 10.0 out of…

🔗 hackmag.com/news/entra-id-flaw

#news

##

security_crawler_carl@infosec.exchange at 2026-08-26T17:42:16.000Z ##

🏆 New Achievement! Serialized, Unsanitized, Unauthorized!

Per my programming, I have located the most efficient path to arbitrary code execution on your network and executed it faithfully. CVE-2026-69836 in Microsoft Entra ID — the thing authenticating your Microsoft 365, Azure, and frankly embarrassing number of third-party apps — accepts specially crafted serialized data and runs whatever is inside. No credentials needed. No user to click anything. (1/2)

##

hasamba@infosec.exchange at 2026-08-26T06:11:01.000Z ##

----------------

🎯 Threat Intelligence
===================

ERNW published the first of a four-part series on token theft in Microsoft Entra ID, accompanying White Paper 80. The post maps the shift from on-premises Active Directory to cloud identity and explains why token theft has become a primary attack vector.

🔹 Landscape Shift

On-premises AD relied on Kerberos and NTLM. Entra ID runs on OAuth 2.0 and OpenID Connect, using JWT-based access, refresh, and ID tokens. New protocols create new attack surface. Microsoft prioritizes usability and backward compatibility over security-by-default, and the strongest protections (Conditional Access, Token Protection, risk-based Identity Protection) are not enabled by default. They require premium P1/P2 licenses plus separate products like Intune or Defender for Endpoint.

Proprietary SSO concepts like PRT, FOCI, and BroCI add further complexity beyond standard OAuth 2.0.

🔹 Concrete Threats

Microsoft's Digital Defense Report 2024 counts over 600 million daily identity attacks against Entra ID. Two notable CVEs:
• CVE-2025-55241: Actor Tokens flaw allowing Global Admin access to any Entra ID tenant worldwide, disclosed by researcher Dirk-jan Mollema
• CVE-2026-69836: CVSS 10.0 unauthenticated RCE in Entra ID itself, caused by unsafe deserialization of untrusted data

🔹 Active Campaigns
• Storm-2372: device code phishing campaign targeting governments and critical industries since August 2024
• Storm-2945: hijacked hotel captive portals worldwide to harvest SSO tokens
• AiTM "code of conduct" phishing: intercepts tokens the moment MFA succeeds rather than trying to defeat MFA directly

🔹 Commodity Tooling

Open-source reverse-proxy frameworks Evilginx and Modlishka, along with PhaaS platforms like EvilProxy, Tycoon2FA, and Kali365, have lowered the barrier to running token theft attacks at scale. Infostealers add further reach by harvesting tokens from compromised endpoints.

🔹 Cloud Security Alliance Ranking

CSA's Top Threats to Cloud Computing 2026 ranks IAM-related threats as the #1 risk to cloud environments, ahead of AI-enhanced attacks in second place despite the current AI security hype cycle.

🔹 What's Next

The series will empirically test Continuous Access Evaluation and Token Protection, and examine where Entra ID deviates from OAuth 2.0 best practices.

🔹 EntraID #TokenTheft #ThreatIntelligence #OAuth2 #Cybersecurity

🔗 Source: insinuator.net/2026/08/token-t

##

cyberworldops@infosec.exchange at 2026-08-24T02:20:01.000Z ##

Microsoft released 22 security patches including a zero-day in Entra ID (CVE-2026-69836) actively exploited for remote code execution. The critical identity-layer flaw was weaponized before a fix became available. ShieldBreak remains unpatched, leaving a documented gap in the security posture of affected organizations.

#MicrosoftPatches #EntraIDZeroDay #ShieldBreak #CVE202669836

cyberworldops.eu/en/microsoft-

##

CVE-2026-19586(CVSS UNKNOWN)

EPSS: 5.04%

updated 2026-08-20T21:31:30

2 posts

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requir

Byte0x90@mastodon.social at 2026-08-25T09:26:35.000Z ##

In TP-Link Omada Business-Gateways klafft eine kritische Lücke (CVE-2026-19586) bei aktivierter OpenVPN-Funktion. Per Command Injection können Angreifer beim VPN-Verbindungsaufbau ohne Zugangsdaten eigenen Code ausführen und das Gerät kompromittieren. Firmware-Updates stehen bereit!

#TPLink #Omada #VPN #CyberSecurity #ITSecurity #Sicherheitslücke #Patchday #InfoSec

##

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18264
(8.8 HIGH)

EPSS: 1.24%

updated 2026-08-20T18:30:55

1 posts

NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4000 by default. The issue results from the lack of proper validation of a user-supp

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19598
(9.8 CRITICAL)

EPSS: 2.46%

updated 2026-08-20T12:48:10.287000

1 posts

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON met

Nuclei template

4 repos

https://github.com/DeadExpl0it/CVE-2026-19598-PoC

https://github.com/HackfutSecRoot/multi_exploit_wp

https://github.com/sag-asab/CVE-2026-19598

https://github.com/ksotaria1337/CVE-2026-19598

beyondmachines1@infosec.exchange at 2026-08-24T16:01:16.000Z ##

Critical Authorization Bypass in Pods Plugin Allows Full WordPress Site Takeover

A critical vulnerability in the Pods WordPress plugin (CVE-2026-19598) allows unauthenticated attackers to bypass security checks and gain administrator access. The flaw enables full site takeover by letting attackers reset administrator passwords through an exposed AJAX router.

**If you use the Pods Custom Content Types and Fields plugin on WordPress, update it ASAP to version 3.3.9.1 (or the patched release matching your branch: 2.8.23.4, 2.9.19.4, 3.0.10.4, 3.1.4.2, or 3.2.8.3). Then check your user list for admin accounts you don't recognise and reset your administrator passwords, since attackers could already have taken over the site.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-15748
(9.8 CRITICAL)

EPSS: 4.61%

updated 2026-08-20T12:48:10.287000

1 posts

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler th

3 repos

https://github.com/ubaydev/CVE-2026-15748

https://github.com/yora1928/cve-2026-15748

https://github.com/HORKimhab/CVE-2026-15826-CVE-2026-15748

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-75616(CVSS UNKNOWN)

EPSS: 1.91%

updated 2026-08-19T21:30:40

1 posts

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device compromise. Successful exploitation may allow arbitrary command execution with el

1 repos

https://github.com/totekuh/CVE-2026-75616

CVE-2026-16835
(9.6 CRITICAL)

EPSS: 0.22%

updated 2026-08-19T21:30:30

1 posts

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration,

DailyCyberSecurity@infosec.exchange at 2026-08-24T13:16:53.000Z ##

IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.

#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow

securityonline.info/ibm-power-

##

CVE-2026-16687
(9.6 CRITICAL)

EPSS: 0.21%

updated 2026-08-19T21:30:30

1 posts

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can send the FSP a malformed request, allowing arbitrary code execution, giving the attacker full control over the managed system, resulting in a confidentiality, inte

DailyCyberSecurity@infosec.exchange at 2026-08-24T13:16:53.000Z ##

IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.

#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow

securityonline.info/ibm-power-

##

CVE-2026-74480
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-08-19T18:33:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: bridge: stop fast-leave after deleting a port group br_multicast_leave_group() iterates mp->ports with pp = &p->next in its fast-leave path. After br_multicast_del_pg() removes p, continuing the loop advances pp through the deleted entry. If multicast-to-unicast was enabled, the bridge can hold multiple port groups for the

CVE-2026-75149
(8.8 HIGH)

EPSS: 0.64%

updated 2026-08-19T18:33:02

1 posts

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. When the notebook is opened in edit mode, marimo launches the specified command as a local subprocess before any notebook cell is executed, re

Analyst207@mastodon.social at 2026-08-25T13:57:00.000Z ##

Marimo Notebook Flaw Exposes Users to Pre-Execution Code Injection

A high-severity flaw in Marimo Notebook software, tracked as CVE-2026-75149, could allow attackers to inject malicious code on a user's machine simply by opening a specially crafted notebook in edit mode. This vulnerability, rated 8.7 out of 10 in severity, requires no authentication - just a click.

osintsights.com/marimo-noteboo

#MarimoNotebook #CodeInjection #Cve202675149 #ModelContextProtocol #Preexecution

##

CVE-2026-69414
(7.8 HIGH)

EPSS: 0.56%

updated 2026-08-19T18:32:28

2 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

2 repos

https://github.com/1neptune/ShieldBreak

https://github.com/HORKimhab/CVE-2026-50656

threatnoir at 2026-08-26T18:06:40.722Z ##

⚠️ CRITICAL: CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

CVE-2026-69414 ShieldBreak is a zero-day privilege escalation in Microsoft Malware Protection Engine affecting Microsoft Defender. A public PoC exists and no patch is available. Any low-privilege attacker on Windows systems running Defender can escalate to SYSTEM.

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-08-26T18:06:40.000Z ##

⚠️ CRITICAL: CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

CVE-2026-69414 ShieldBreak is a zero-day privilege escalation in Microsoft Malware Protection Engine affecting Microsoft Defender. A public PoC exists and no patch is available. Any low-privilege attacker on Windows systems running Defender can escalate to SYSTEM.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-71961
(8.8 HIGH)

EPSS: 3.05%

updated 2026-08-19T15:32:47

1 posts

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command interface. The sync_command binary forwards unsanitized input directly to a shell execution sink in command.lua, enabling attackers with access to the MQTT b

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-54795
(8.8 HIGH)

EPSS: 2.39%

updated 2026-08-19T15:32:33

1 posts

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-14669
(8.8 HIGH)

EPSS: 0.58%

updated 2026-08-19T14:56:57.477000

1 posts

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

1 repos

https://github.com/HackSpeak/CVE-2026-14669

CVE-2026-33824
(9.8 CRITICAL)

EPSS: 72.69%

updated 2026-08-19T04:16:58.560000

1 posts

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/EpSiLoNPoInTOrI/IKEV2-POC

https://github.com/kaleth4/CVE-2026-33824

security_crawler_carl@infosec.exchange at 2026-08-24T18:58:32.000Z ##

🏆 New Achievement! UDP Knocking, Nobody's Dropping!

COMPLIANCE MODE ENGAGED. Action item detected: patch CVE-2026-33824. Executing optimal response: notifying you that Microsoft patched this in April 2026 and that Palo Alto Networks Unit 42 has observed a Chinese-speaking threat actor actively exploiting it anyway, on every supported Windows 10, 11, and Server release, via maliciously crafted packets on UDP ports 500 or 4500, requiring zero privileges. Patch applied? No? Logging that. (1/2)

##

CVE-2026-18963
(9.1 CRITICAL)

EPSS: 2.79%

updated 2026-08-19T03:31:21

12 posts

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user

Nuclei template

8 repos

https://github.com/minh3102011/CVE-2026-18963_analyst

https://github.com/prot0tw/Keycloak_CVE-2026-18963_PoC

https://github.com/Snizi/CVE-2026-18963-Exploit

https://github.com/Red-Darkin/CVE-2026-18963-keycloak

https://github.com/kyos-public/keycloak-cve-2026-18963-hunt

https://github.com/gman0x00/keycloak-CVE-2026-18963

https://github.com/debugactiveprocess/CVE-2026-18963

https://github.com/T0w0T/POC-CVE-2026-18963

mastokukei@social.josko.org at 2026-08-26T18:02:12.000Z ##

release**: New features, updates, and community reactions to the latest Emacs version.
- **Programming tools and libraries**: Updates and discussions on tools like Git, Next.js 16.3, Rust, and various Arduino libraries (e.g., BresserWeatherSensorReceiver, SparkFun SSD168x, GyverHTTP).
- **Security vulnerabilities**: Notable CVEs like CVE-2026-18963 (Keycloak) and supply-chain attacks on Rust crates (e.g., `arrayref`, `internment`, `appendonlyvec`).
- **Linux 35th [2/3]

##

mastokukei@social.josko.org at 2026-08-26T09:06:46.000Z ##

Python, testing, and AI integration.
- **Linux 35th anniversary**: Celebrations, reflections on Linux's growth, and its role in modern computing.
- **Security vulnerabilities**: Notable CVEs like CVE-2026-18963 (Keycloak) and supply-chain attacks on Rust crates.
- **Programming tools and libraries**: Updates and discussions on tools like Git, Next.js 16.3, Rust, and various Arduino libraries. [2/2]

##

sayzard@mastodon.sayzard.org at 2026-08-26T03:46:43.000Z ##

CVE-2026-18963 – Keycloak Reset-Credentials Bypass → Account Takeover

Keycloak의 비밀번호 재설정 흐름에서 이메일 검증 없이 임의 사용자(관리자 포함)의 비밀번호를 변경할 수 있는 CVE-2026-18963이 공개되었습니다. 취약점은 인증 선택기의 상태가 실행 단계별로 격리되지 않는 문제와 이메일 액션 토큰 검증 누락을 연쇄해, 원격·무인증 계정 탈취로 이어질 수 있으며 CVSS 9.1로 분류됩니다. Keycloak 26.7.2 및 Red Hat의 সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ...

github.com/Red-Darkin/CVE-2026

##

F30@chaos.social at 2026-08-25T10:12:47.000Z ##

CVE-2026-18963: #Keycloak arbitrary account takeover via session confusion using simple HTTP requests. 😱

Nice find and (allegedly) not even AI-powered at its core.
A working exploit is publicly available. Given Keycloak's widespread use in critical auth systems, this appears to be flying a bit under the radar so far.

If you run Keycloak, it needs your attention *now*.

github.com/Red-Darkin/CVE-2026

##

inw@mastodon.social at 2026-08-25T08:50:00.000Z ##

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

thehackernews.com/2026/08/crit

> Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.

#keycloak

##

F30@chaos.social at 2026-08-25T10:12:47.000Z ##

CVE-2026-18963: #Keycloak arbitrary account takeover via session confusion using simple HTTP requests. 😱

Nice find and (allegedly) not even AI-powered at its core.
A working exploit is publicly available. Given Keycloak's widespread use in critical auth systems, this appears to be flying a bit under the radar so far.

If you run Keycloak, it needs your attention *now*.

github.com/Red-Darkin/CVE-2026

##

inw@mastodon.social at 2026-08-25T08:50:00.000Z ##

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

thehackernews.com/2026/08/crit

> Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.

#keycloak

##

alien@fosstodon.org at 2026-08-24T20:01:50.000Z ##

Note the recently disclosed CVE-2026-18963 for #Keycloak OIDC: thehackernews.com/2026/08/crit . It allows unauthorized users to take over any account on your server.
On the #Slackware #Forgejo instance forge.slackware.nl/ I have upgraded Keycloak to 26.7.2 to address this vulnerability.

##

threatnoir@infosec.exchange at 2026-08-24T18:06:21.000Z ##

⚠️ CRITICAL: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Critical flaw in Keycloak (CVE-2026-18963, CVSS 9.1) allows unauthenticated attackers to reset any user password and take over accounts due to improper state validation in the password recovery flow. Any organization running Keycloak without patches is immediately at risk of account takeover on all…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

security_crawler_carl@infosec.exchange at 2026-08-24T16:56:45.000Z ##

🏆 New Achievement! Exhibit A: Your Password Reset Button!

Counsel will direct the court's attention to CVE-2026-18963, rated a damning 9.1 out of 10, wherein Keycloak's reset-credentials authentication flow failed to properly validate state — legally speaking, an open invitation any unauthenticated remote party was fully entitled to accept. No user interaction required. The attacker needed nothing. No account, no session, no strongly-worded letter. (1/2)

##

youranonnewsirc@nerdculture.de at 2026-08-24T16:26:26.000Z ##

Geopolitical tensions rise as US-Iran dispute over Strait of Hormuz escalates; UK pledges long-range missile tech to Ukraine. Nvidia increases AI server prices over 15% due to memory costs. Critical Keycloak flaw (CVE-2026-18963) found allowing account takeovers, while Apple warns of mercenary spyware.

#AnonNews_irc #Cybersecurity #News

##

beyondmachines1@infosec.exchange at 2026-08-24T15:01:16.000Z ##

Critical Keycloak Password Reset Flaw Allows Unauthenticated Account Takeover

Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) that allows unauthenticated attackers to bypass email verification and take over any account via the password reset flow. The update also addresses over 20 other security flaws, including account-linking bypasses and administrative permission leaks.

**If you run Keycloak or Red Hat Build of Keycloak, update immediately to Keycloak 26.7.2 or RHBK 26.4.15 / 26.6.6 since the older versions let anyone reset the password of any account, including admins. If you cannot patch right away, turn off the "Forgot password" option in every realm (Realm settings → Login → Forgot password) until the update is applied.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-17084(CVSS UNKNOWN)

EPSS: 0.48%

updated 2026-08-19T03:31:21

1 posts

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters

sayzard@mastodon.sayzard.org at 2026-08-26T02:43:38.000Z ##

When str.lower() is a security vulnerability in Python – Seth Larson

Python의 IDNA 2003/StringPrep 구현에서 `str.lower()`가 인터프리터에 내장된 최신 Unicode 데이터에 의존해 RFC 3454가 요구하는 Unicode 3.2.0 규칙과 달라질 수 있었던 취약점(CVE-2026-17084)이다. 이 차이로 일부 유니코드 도메인 문자열의 정규화 및 Punycode 결과가 Python/Unicode 버전별로 달라져, IDNA 기반 식별자 비교·검증에서 일관성이 깨질 수 있다. 수정은 최신 Unicode의 `lower()` 결과가 Unicode 3.2.0과 다른 코드포인트를 예외...

sethmlarson.dev/when-str-lower

##

CVE-2026-55040
(9.1 CRITICAL)

EPSS: 5.58%

updated 2026-08-18T18:32:50

7 posts

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Nuclei template

3 repos

https://github.com/sfewer-r7/CVE-2026-55040

https://github.com/zenzue/CVE-2026-55040

https://github.com/l0ggg/CVE-2026-55040

undercodenews@mastodon.social at 2026-08-26T20:05:27.000Z ##

Hackers Target Unpatched Microsoft SharePoint Servers as Public Exploits Fuel Remote Code Execution Threats + Video

Introduction: A Dangerous Window Opens for SharePoint Administrators A new cybersecurity threat is placing unpatched Microsoft SharePoint servers under increasing pressure as attackers reportedly chain two vulnerabilities, CVE-2026-55040 and CVE-2026-63520, to achieve remote code execution. With public proof-of-concept exploits already available and…

undercodenews.com/hackers-targ

##

undercodenews@mastodon.social at 2026-08-26T15:54:22.000Z ##

Microsoft SharePoint Under Siege: Attackers Are Chaining Two Critical Flaws Into a New RCE Threat

A New SharePoint Warning Is Raising the Stakes Microsoft SharePoint administrators are facing another serious security emergency as attackers begin testing a dangerous vulnerability chain capable of turning an authentication bypass into remote code execution. The development is especially concerning because one of the flaws, CVE-2026-55040, has already moved beyond…

undercodenews.com/microsoft-sh

##

undercodenews@mastodon.social at 2026-08-25T19:00:05.000Z ##

Microsoft SharePoint Under Attack: Critical Authentication Bypass Exposes a Potential Pool of 14,000 Internet-Facing Systems + Video

A Dangerous New Chapter for SharePoint Security Microsoft SharePoint has become the focus of a fresh cybersecurity warning after an underground threat actor reportedly published targeting information connected to CVE-2026-55040, a critical authentication-bypass vulnerability affecting Microsoft SharePoint Server. The development is…

undercodenews.com/microsoft-sh

##

DailyCyberSecurity at 2026-08-25T14:19:20.830Z ##

A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.

securityonline.info/sharepoint

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T14:19:20.000Z ##

A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.

#SharePoint #CVE202663520 #CVE202655040 #CyberSecurity #Exploit

securityonline.info/sharepoint

##

AAKL@infosec.exchange at 2026-08-24T17:42:16.000Z ##

New.

VulnCheck: Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain vulncheck.com/blog/cve-2026-63 @vulncheck #infosec #threatresearch #Microsoft #SharePoint #vulnerability

##

catc0n@infosec.exchange at 2026-08-24T14:01:24.000Z ##

Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: vulncheck.com/blog/cve-2026-63

##

CVE-2026-24301
(8.8 HIGH)

EPSS: 2.22%

updated 2026-08-18T15:31:45

1 posts

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

1 repos

https://github.com/CSOAI-ORG/memory-poisoning-axis

sekurakbot@mastodon.com.pl at 2026-08-25T15:19:00.000Z ##

CoSnitch: jedno kliknięcie wystarczyło, aby wysłać złośliwego prompta w Microsoft Copilot

Badacze bezpieczeństwa z Varonis odkryli podatność typu one-click w Microsoft Copilot. Otrzymała ona numer CVE-2026-24301 i została nazwana “CoSnitch”. Luka umożliwia wykradnięcie danych użytkownika bez żadnej szczególnej interakcji z jego strony – wystarczy kliknięcie odpowiednio spreparowanego linku. TLDR: Podatność została zgłoszona firmie Microsoft w grudniu 2025 r., a 18 sierpnia...

#Aktualności #Ai #Copilot #Cosnitch #Injection #Podatność

sekurak.pl/cosnitch-jedno-klik

##

CVE-2026-53365
(5.5 MEDIUM)

EPSS: 0.17%

updated 2026-08-18T15:31:16

1 posts

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb sends When a large message is fragmented into multiple skbs, the zerocopy uarg is only allocated and attached to the last skb in the loop. Non-final skbs carry pinned user pages with no completion tracking, so the kernel has no way to notify userspace when those pages are safe

2 repos

https://github.com/HackSpeak/CVE-2026-53365

https://github.com/HORKimhab/CVE-2026-53365

CVE-2026-73522
(7.5 HIGH)

EPSS: 2.36%

updated 2026-08-18T15:17:08.193000

1 posts

COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CAN messages. The avtp_to_can() function increments its write index without bounding it against the caller-supplied array size, and because the listener accepts da

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19478
(9.4 CRITICAL)

EPSS: 6.00%

updated 2026-08-18T14:57:10.630000

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Nuclei template

6 repos

https://github.com/dinosn/gitlab-cve-2026-19478-lab

https://github.com/davkharrr/CVE-2026-19478-PoC

https://github.com/HORKimhab/CVE-2026-19650-CVE-2026-19478

https://github.com/punitdarji/Gitlab-CVE-2026-19478

https://github.com/n0xdaemon/cve-2026-19478

https://github.com/renzi25031469/CVE-2026-19478

youranonnewsirc@nerdculture.de at 2026-08-25T04:26:31.000Z ##

Here's a summary of recent geopolitical, technology, and cybersecurity news:

Geopolitical: The US has launched "Operation Economic Outcast" against Iran (Aug 25) and plans 7.5% tariffs on Chinese goods over excess manufacturing capacity before a September summit (Aug 25).

Technology: Google is reorganizing DeepMind and acquired Spirit Airlines' data for AI model development (Aug 24). Fujitsu is trialing AI for construction process and risk management (Aug 25).

Cybersecurity: CISA added an Oracle HTTP Server vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities Catalog (Aug 24). Critical GitLab (CVE-2026-19478) and Cisco vulnerabilities (CVSS 10.0) are under active exploitation (Aug 24).

#AnonNews_irc #Cybersecurity #News

##

CVE-2026-75094
(9.1 CRITICAL)

EPSS: 2.11%

updated 2026-08-18T03:31:14

1 posts

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-64849
(9.3 CRITICAL)

EPSS: 16.41%

updated 2026-08-17T21:58:52

1 posts

### Summary The default MLflow Tracking Server (`mlflow server`, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous `POST /api/2.0/mlflow/webhooks/{id}/test` endpoint that returns the upstream response status and body to the caller. The SSRF guard added in PR #20747 (`_validate_webhook_url`, shipped in 3.10.0) resolves the we

Nuclei template

3 repos

https://github.com/codeb0ssx/CVE-2026-64849-PoC

https://github.com/zavisco/CVE-2026-64849.yaml

https://github.com/BiuTrap/CVE-2026-64849

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19976
(6.6 MEDIUM)

EPSS: 2.05%

updated 2026-08-17T03:30:28

1 posts

A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted is the function sub_44A968 of the file /cgi-bin/mbox-config?method=SET&section=ptest_macaddress. Such manipulation of the argument macaddress leads to command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-61979
(8.1 HIGH)

EPSS: 0.28%

updated 2026-08-13T15:34:46

2 posts

Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.

Byte0x90@mastodon.social at 2026-08-25T08:58:33.000Z ##

Angreifer nutzen zwei kritische Lücken im WordPress-Plugin miniOrange SAML SSO aus. Durch die Kombination von CVE-2026-61979 und CVE-2026-15981 lassen sich SAML-Antworten fälschen und Admin-Konten komplett übernehmen. Da der Hersteller Patches für Bezahlversionen kaum kommuniziert hat, sind viele Seiten ungepatcht. Scans laufen bereits – Admins sollten installierte Plugins sofort aktualisieren!

#WordPress #CyberSecurity #ITSecurity #Sicherheitslücke #Patchday #InfoSec

##

cyberworldops@infosec.exchange at 2026-08-25T00:20:00.000Z ##

Two critical authentication bypass flaws in the miniOrange SAML SSO WordPress plugin can be chained to forge SAML responses and obtain admin access without credentials. Both CVE-2026-61979 and CVE-2026-15981 affect a family of seven plugins, including a free version. Exploitation attempts are already in the wild.

#WordPressSecurity #AuthenticationBypass #CriticalVulnerability #SAMLAttacks

cyberworldops.eu/en/wordpress-

##

CVE-2026-50656
(7.8 HIGH)

EPSS: 11.36%

updated 2026-08-12T17:17:27.983000

1 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;.

4 repos

https://github.com/eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-

https://github.com/0xBlackash/CVE-2026-50656

https://github.com/g0thamRabb1t/CVE-2026-50656-rogueplanet-validation

https://github.com/HORKimhab/CVE-2026-50656

netsecio@mastodon.social at 2026-08-26T13:27:15.000Z ##

📰 New 'ShieldBreak' Exploit Bypasses Microsoft Defender Patch

A new zero-day exploit, 'ShieldBreak,' bypasses Microsoft's patch for the 'RoguePlanet' Defender flaw (CVE-2026-50656). The PoC allows SYSTEM-level access on patched Windows systems. No fix is currently available. #ZeroDay #MicrosoftDefender #CyberSe...

🔗 cyber.netsecops.io/articles/sh

##

CVE-2026-32257
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-12T14:40:23

2 posts

### Impact Users with the `backend.manage_branding` ("Customize the back-end") permission can provide custom CSS through **Settings → Customize Backend → Styles** that is compiled through the LESS CSS parser and rendered on every backend page. Previously, the compiled output was not sanitized, w

thehackerwire@mastodon.social at 2026-08-26T18:00:07.000Z ##

🟠 CVE-2026-32257 - High (8.1)

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compile...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T18:00:07.000Z ##

🟠 CVE-2026-32257 - High (8.1)

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compile...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52923
(7.8 HIGH)

EPSS: 0.15%

updated 2026-08-12T12:19:41.090000

2 posts

In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysctl path can request the next SysV IPC id through ids->next_id. ipc_idr_alloc() currently forwards that request to idr_alloc() with an open-ended upper bound. If the valid tail of the SysV IPC id space is full, the allocation can spill beyond ipc_mni

DailyCyberSecurity at 2026-08-25T12:49:12.039Z ##

A public PoC for the Linux kernel flaw CVE-2026-52923 allows local attackers to escalate to root privilege. Learn about the patch and technical details.

securityonline.info/cve-2026-5

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T12:49:12.000Z ##

A public PoC for the Linux kernel flaw CVE-2026-52923 allows local attackers to escalate to root privilege. Learn about the patch and technical details.

#Linux #CVE202652923 #CyberSecurity #PrivilegeEscalation #KernelFlaw

securityonline.info/cve-2026-5

##

CVE-2026-68820
(7.0 None)

EPSS: 6.18%

updated 2026-08-11T21:33:01

1 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

4 repos

https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation

https://github.com/HORKimhab/CVE-2026-68820

https://github.com/maxprog-svg/CVE-2026-68820_Mass_Exploit

https://github.com/fevar54/CVE-2026-68820-Mitigation-PoC-

daniel1820815@infosec.exchange at 2026-08-24T15:24:01.000Z ##

From Check Point Research:

Check Point Research has exposed a new wave of the #Lazarus-linked Operation Dream Job targeting defense organizations in Europe, India and Brazil. Attackers used fraudulent job opportunities and trojanized PDF software to deploy #malware, while exploiting Windows zero-day CVE-2026-68820 to obtain SYSTEM privileges and disable security visibility.

research.checkpoint.com/2026/s

#CheckPoint #CheckPointSoftwareTechnologies

##

CVE-2026-63520
(8.1 HIGH)

EPSS: 2.93%

updated 2026-08-11T18:31:39

8 posts

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

1 repos

https://github.com/hypnguyen1209/CVE-2026-63520

undercodenews@mastodon.social at 2026-08-26T20:05:27.000Z ##

Hackers Target Unpatched Microsoft SharePoint Servers as Public Exploits Fuel Remote Code Execution Threats + Video

Introduction: A Dangerous Window Opens for SharePoint Administrators A new cybersecurity threat is placing unpatched Microsoft SharePoint servers under increasing pressure as attackers reportedly chain two vulnerabilities, CVE-2026-55040 and CVE-2026-63520, to achieve remote code execution. With public proof-of-concept exploits already available and…

undercodenews.com/hackers-targ

##

catc0n at 2026-08-26T03:27:55.060Z ##

If you've missed any super dope research from @lobsterjerusalem recently, pleez don't miss it anymore:

Oh no the internet is awash with AI slop PoCs, send poor Jonathan tiny cupcakes and quick: vulncheck.com/blog/death-by-20

SharePoint RCE:
vulncheck.com/blog/cve-2026-63

##

DailyCyberSecurity at 2026-08-25T14:19:20.830Z ##

A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.

securityonline.info/sharepoint

##

catc0n@infosec.exchange at 2026-08-26T03:27:55.000Z ##

If you've missed any super dope research from @lobsterjerusalem recently, pleez don't miss it anymore:

Oh no the internet is awash with AI slop PoCs, send poor Jonathan tiny cupcakes and quick: vulncheck.com/blog/death-by-20

SharePoint RCE:
vulncheck.com/blog/cve-2026-63

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T14:19:20.000Z ##

A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.

#SharePoint #CVE202663520 #CVE202655040 #CyberSecurity #Exploit

securityonline.info/sharepoint

##

AAKL@infosec.exchange at 2026-08-24T17:42:16.000Z ##

New.

VulnCheck: Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain vulncheck.com/blog/cve-2026-63 @vulncheck #infosec #threatresearch #Microsoft #SharePoint #vulnerability

##

AAKL@infosec.exchange at 2026-08-24T17:33:40.000Z ##

New.

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) rapid7.com/blog/post/ra-micros @Rapid7Official #infosec #Microsoft #vulnerability #threatresearch #SharePoint

##

catc0n@infosec.exchange at 2026-08-24T14:01:24.000Z ##

Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: vulncheck.com/blog/cve-2026-63

##

CVE-2026-62911
(8.0 HIGH)

EPSS: 0.95%

updated 2026-08-11T18:31:34

2 posts

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/hypnguyen1209/CVE-2026-62911

CVE-2026-14540
(6.1 MEDIUM)

EPSS: 0.12%

updated 2026-08-08T00:15:26

1 posts

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to safely regulate request redirection boundaries. Specifically, the client is initialize

sayzard@mastodon.sayzard.org at 2026-08-25T07:39:04.000Z ##

I found an SSRF in Google's official AI tooling, and how Google reacted

Google의 공식 에이전트 연동 서버인 MCP Toolbox에서 리디렉션 후 대상 주소를 재검증하지 않아 클라우드 메타데이터 엔드포인트 등으로 접근할 수 있는 SSRF 취약점(CVE-2026-14540, CVSS 8.0)이 수정됐다. 공격자는 모델이 제어 가능한 URL을 통해 리디렉션을 유도하고, 서버 워크로드의 자격 증명이 노출될 수 있었다. 수정안은 모든 리디렉션 홉의 목적지 검증, DNS rebinding 방어, private/link-local 및 IPv6 우회 주소 차단, 초기 base URL 검증을 포함한다. MCP 기반 에이전트는 비신뢰 웹·문서·DB 내용...

news.ycombinator.com/item?id=4

##

CVE-2026-48710
(6.5 MEDIUM)

EPSS: 1.91%

updated 2026-08-07T12:31:53

1 posts

### Summary In affected versions, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions

Nuclei template

5 repos

https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace

https://github.com/eris-ths/supply-chain-guard

https://github.com/xtremebeing/starlette-host-header-lab

https://github.com/CuteeCat/CVE-2026-48710

https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit

CapTechGroup@mastodon.social at 2026-08-26T18:19:46.000Z ##

CVE-2026-42271 (authenticated command exec in LiteLLM MCP stdio test endpoints) chained with CVE-2026-48710 (Starlette host-header bypass) = reachable RCE in the gateway runtime. Payload reads /proc/1/environ for master keys and...

captechgroup.com/threat-intell

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 84.73%

updated 2026-08-06T05:17:05.170000

4 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Nuclei template

4 repos

https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

https://github.com/AnggaTechI/CVE-2026-63077

https://github.com/sfewer-r7/CVE-2026-63077

https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap

security_crawler_carl at 2026-08-26T10:35:29.787Z ##

🏆 New Achievement! Unauthenticated and Unburied!

TO: All TeamCity On-Premises Servers, Living and Otherwise

FROM: Compliance Review, Undead Infrastructure Division

RE: Active Exploitation — Mandatory Resurrection Notice

Please be advised that CVE-2026-63077 has formally reanimated your unpatched TeamCity On-Premises deployment. (1/3)

##

undercodenews@mastodon.social at 2026-08-25T11:44:07.000Z ##

Critical TeamCity Flaw Is Now Under Active Attack: Why CVE-2026-63077 Puts CI/CD Infrastructure at Serious Risk

Introduction: The Security Alarm Around TeamCity Is Getting Louder A critical vulnerability in JetBrains TeamCity On-Premises has moved from a serious patching concern to an active exploitation problem. Tracked as CVE-2026-63077, the flaw can allow an unauthenticated remote attacker to bypass authentication and execute arbitrary operating-system commands on a…

undercodenews.com/critical-tea

##

security_crawler_carl@infosec.exchange at 2026-08-26T10:35:29.000Z ##

🏆 New Achievement! Unauthenticated and Unburied!

TO: All TeamCity On-Premises Servers, Living and Otherwise

FROM: Compliance Review, Undead Infrastructure Division

RE: Active Exploitation — Mandatory Resurrection Notice

Please be advised that CVE-2026-63077 has formally reanimated your unpatched TeamCity On-Premises deployment. (1/3)

##

DailyCyberSecurity@infosec.exchange at 2026-08-24T07:34:43.000Z ##

CVE-2026-63077 is a TeamCity unauthenticated RCE, now exploited in the wild with a public PoC. Australia's ACSC confirms active attacks.

#TeamCity #CVE202663077 #RCE #CyberSecurity #JetBrains #CISAKEV

securityonline.info/teamcity-c

##

CVE-2026-8508
(6.5 MEDIUM)

EPSS: 0.70%

updated 2026-08-04T03:31:16

2 posts

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.

1 repos

https://github.com/minanagehsalalma/zyxel-social-login-bypass-cve-2026-8508

_r_netsec at 2026-08-25T13:43:05.200Z ##

CVE-2026-8508: Trust-Boundary Bypass in Zyxel social_login.cgi Facebook Identity Handling minanagehsalalma.github.io/zyx

##

_r_netsec@infosec.exchange at 2026-08-25T13:43:05.000Z ##

CVE-2026-8508: Trust-Boundary Bypass in Zyxel social_login.cgi Facebook Identity Handling minanagehsalalma.github.io/zyx

##

CVE-2026-15903
(8.8 HIGH)

EPSS: 0.57%

updated 2026-07-24T15:33:44

1 posts

Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

sayzard@mastodon.sayzard.org at 2026-08-26T17:45:29.000Z ##

I had some free time, so I tried to pwn V8

작성자는 Google v8CTF의 고정된 Chrome 150/V8 15 빌드를 대상으로 공개된 세 취약점을 연결해 V8 힙 샌드박스 밖의 네이티브 렌더러 제어권을 얻고 `/flag/flag`를 읽었습니다. 체인은 CVE-2026-15903의 범위 밖 읽기를 주소 오라클로, CVE-2026-15776의 GC 참조 추적 오류를 V8 cage 내부 임의 읽기/쓰기로, JSPI와 JS Dispatch Table 불일치를 네이티브 스택 피벗으로 활용합니다. 글은 포인터 압축, External/Trusted Pointer Table, W^X·ASLR·CFI 등 현대 V...

blog.himanshuanand.com/2026/08

##

CVE-2026-15981
(9.8 CRITICAL)

EPSS: 0.81%

updated 2026-07-23T21:31:09

2 posts

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful sign

1 repos

https://github.com/Nxploited/CVE-2026-15981

Byte0x90@mastodon.social at 2026-08-25T08:58:33.000Z ##

Angreifer nutzen zwei kritische Lücken im WordPress-Plugin miniOrange SAML SSO aus. Durch die Kombination von CVE-2026-61979 und CVE-2026-15981 lassen sich SAML-Antworten fälschen und Admin-Konten komplett übernehmen. Da der Hersteller Patches für Bezahlversionen kaum kommuniziert hat, sind viele Seiten ungepatcht. Scans laufen bereits – Admins sollten installierte Plugins sofort aktualisieren!

#WordPress #CyberSecurity #ITSecurity #Sicherheitslücke #Patchday #InfoSec

##

cyberworldops@infosec.exchange at 2026-08-25T00:20:00.000Z ##

Two critical authentication bypass flaws in the miniOrange SAML SSO WordPress plugin can be chained to forge SAML responses and obtain admin access without credentials. Both CVE-2026-61979 and CVE-2026-15981 affect a family of seven plugins, including a free version. Exploitation attempts are already in the wild.

#WordPressSecurity #AuthenticationBypass #CriticalVulnerability #SAMLAttacks

cyberworldops.eu/en/wordpress-

##

CVE-2026-40575
(9.1 CRITICAL)

EPSS: 0.48%

updated 2026-07-21T13:50:16

1 posts

### Impact A configuration-dependent authentication bypass exists in OAuth2 Proxy. Deployments are affected when all of the following are true: * OAuth2 Proxy is configured with `--reverse-proxy` * and at least one rule is defined with `--skip_auth_routes` or the legacy `--skip-auth-regex` OAuth2 Proxy may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `

thehackerwire@mastodon.social at 2026-08-24T19:01:19.000Z ##

🔴 CVE-2026-76835 - Critical (9.1)

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15776
(8.8 HIGH)

EPSS: 0.45%

updated 2026-07-15T17:39:16.157000

1 posts

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

sayzard@mastodon.sayzard.org at 2026-08-26T17:45:29.000Z ##

I had some free time, so I tried to pwn V8

작성자는 Google v8CTF의 고정된 Chrome 150/V8 15 빌드를 대상으로 공개된 세 취약점을 연결해 V8 힙 샌드박스 밖의 네이티브 렌더러 제어권을 얻고 `/flag/flag`를 읽었습니다. 체인은 CVE-2026-15903의 범위 밖 읽기를 주소 오라클로, CVE-2026-15776의 GC 참조 추적 오류를 V8 cage 내부 임의 읽기/쓰기로, JSPI와 JS Dispatch Table 불일치를 네이티브 스택 피벗으로 활용합니다. 글은 포인터 압축, External/Trusted Pointer Table, W^X·ASLR·CFI 등 현대 V...

blog.himanshuanand.com/2026/08

##

CVE-2026-42271
(8.8 HIGH)

EPSS: 83.54%

updated 2026-07-15T02:21:30.727000

1 posts

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When c

Nuclei template

2 repos

https://github.com/learner202649/CVE-2026-42271-PoC

https://github.com/HORKimhab/CVE-2026-42271

CapTechGroup@mastodon.social at 2026-08-26T18:19:46.000Z ##

CVE-2026-42271 (authenticated command exec in LiteLLM MCP stdio test endpoints) chained with CVE-2026-48710 (Starlette host-header bypass) = reachable RCE in the gateway runtime. Payload reads /proc/1/environ for master keys and...

captechgroup.com/threat-intell

##

CVE-2026-52945
(7.5 HIGH)

EPSS: 0.40%

updated 2026-07-14T16:59:26.780000

1 posts

In the Linux kernel, the following vulnerability has been resolved: Revert "wireguard: device: enable threaded NAPI" This reverts commit 933466fc50a8e4eb167acbd0d8ec96a078462e9c which is commit db9ae3b6b43c79b1ba87eea849fd65efa05b4b2e upstream. We have had three independent production user reports in combination with Cilium utilizing WireGuard as encryption underneath that k8s Pod E/W traffic t

kini@maro.xyz at 2026-08-25T22:51:03.000Z ##

>We have had three independent production user reports in combination with Cilium utilizing WireGuard as encryption underneath that k8s Pod E/W traffic to certain peer nodes fully stalled. The situation appears as follows: - Occurs very rarely but at random times under heavy networking load. - Once the issue triggers the decryption side stops working completely for that WireGuard peer, other peers keep working fine.

nvd.nist.gov/vuln/detail/CVE-2

Yeah pretty I just found out the source of the curse.

##

CVE-2026-52912
(7.8 HIGH)

EPSS: 0.19%

updated 2026-07-08T15:31:43

1 posts

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge master before queueing bridge LOCAL_IN packets. NFQUEUE only holds references on state.in/out and bridge physdevs, so a queued bridge packet can retain a freed bridge master in skb->dev until reinjectio

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 40.59%

updated 2026-06-26T15:33:15

2 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

DailyCyberSecurity at 2026-08-25T08:01:56.825Z ##

The Clop web shell targets PTC Windchill via CVE-2026-12569, stealing credentials and engineering data in a mass-extortion campaign.

securityonline.info/clop-web-s

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T08:01:56.000Z ##

The Clop web shell targets PTC Windchill via CVE-2026-12569, stealing credentials and engineering data in a mass-extortion campaign.

#Clop #Windchill #WebShell #Ransomware #DataExfiltration

securityonline.info/clop-web-s

##

CVE-2025-1974
(9.8 CRITICAL)

EPSS: 99.52%

updated 2026-06-17T08:40:27.847000

1 posts

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

Nuclei template

27 repos

https://github.com/zsxen/CVE-2025-1974

https://github.com/hakaioffsec/IngressNightmare-PoC

https://github.com/gian2dchris/ingress-nightmare-poc

https://github.com/yanmarques/CVE-2025-1974

https://github.com/m-q-t/ingressnightmare-detection-poc

https://github.com/zulloper/CVE-2025-1974

https://github.com/BiiTts/POC-IngressNightmare-CVE-2025-1974

https://github.com/1w4y/IngressNightmare-RCE-POC

https://github.com/zsxen/cve-2025-1974-lab

https://github.com/Rubby2001/CVE-2025-1974-go

https://github.com/0xBingo/CVE-2025-1974

https://github.com/gunyakit/CVE-2025-1974-PoC-exploit

https://github.com/iteride/CVE-2025-1974

https://github.com/I3r1h0n/IngressNightterror

https://github.com/hi-unc1e/CVE-2025-1974-poc

https://github.com/abrewer251/CVE-2025-1974_IngressNightmare_PoC

https://github.com/sandumjacob/IngressNightmare-POCs

https://github.com/zwxxb/CVE-2025-1974

https://github.com/lufeirider/IngressNightmare-PoC

https://github.com/salt318/CVE-2025-1974

https://github.com/rjhaikal/POC-IngressNightmare-CVE-2025-1974

https://github.com/BoianEduard/CVE-2025-1974

https://github.com/yoshino-s/CVE-2025-1974

https://github.com/Armand2002/Exploit-CVE-2025-1974-Lab

https://github.com/chhhd/CVE-2025-1974

https://github.com/Esonhugh/ingressNightmare-CVE-2025-1974-exps

https://github.com/tuladhar/ingress-nightmare

ninecloudnavigators@mastodon.social at 2026-08-26T08:30:01.000Z ##

82% of container teams run Kubernetes in production (CNCF Annual Survey 2025). Most underestimate what happens after launch.

Cluster upgrades, observability tuning, secret management, and network policies never stop. IngressNightmare (CVE-2025-1974, CVSS 9.8) showed why: a full cluster takeover via delayed patches, affecting 40%+ of prod environments.

We broke down the four biggest Day-2 blind spots: nine.ch/en/blog/kubernetes-day

#kubernetes #devops #nine

##

CVE-2023-21931
(7.5 HIGH)

EPSS: 82.26%

updated 2026-06-17T05:34:22.130000

2 posts

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical

2 repos

https://github.com/TimeSHU/weblogic_CVE-2023-21931_POC-EXP

https://github.com/gobysec/Weblogic

threatnoir at 2026-08-26T18:06:38.281Z ##

⚠️ CRITICAL: CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw

Oracle WebLogic Server CVE-2023-21931 is being actively exploited in the wild, allowing unauthenticated attackers to read or modify sensitive data. Federal agencies are mandated to patch by August 27, 2024. Any organization running unpatched WebLogic instances is at immediate risk of compromise.

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-08-26T18:06:38.000Z ##

⚠️ CRITICAL: CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw

Oracle WebLogic Server CVE-2023-21931 is being actively exploited in the wild, allowing unauthenticated attackers to read or modify sensitive data. Federal agencies are mandated to patch by August 27, 2024. Any organization running unpatched WebLogic instances is at immediate risk of compromise.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2020-14882
(9.8 CRITICAL)

EPSS: 100.00%

updated 2026-06-17T02:55:44.510000

2 posts

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeove

Nuclei template

42 repos

https://github.com/murataydemir/CVE-2020-14883

https://github.com/Ormicron/CVE-2020-14882-GUI-Test

https://github.com/adm1in/CodeTest

https://github.com/s1kr10s/CVE-2020-14882

https://github.com/QmF0c3UK/CVE-2020-14882

https://github.com/VelesSecurity/CVE-2020-14882-WebLogic-Analysis

https://github.com/exploitblizzard/CVE-2020-14882-WebLogic

https://github.com/LucasPDiniz/CVE-2020-14882

https://github.com/ludy-dev/Weblogic_Unauthorized-bypass-RCE

https://github.com/xMr110/CVE-2020-14882

https://github.com/xfiftyone/CVE-2020-14882

https://github.com/ovProphet/CVE-2020-14882-checker

https://github.com/pwn3z/CVE-2020-14882-WebLogic

https://github.com/murataydemir/CVE-2020-14882

https://github.com/zhzyker/vulmap

https://github.com/KKC73/weblogic-cve-2020-14882

https://github.com/qianniaoge/CVE-2020-14882_Exploit_Gui

https://github.com/kk98kk0/CVE-2020-14882

https://github.com/wsfengfan/cve-2020-14882

https://github.com/milo2012/CVE-2020-14882

https://github.com/tpdlshdmlrkfmcla/WebLogic_CVE_2020_14882

https://github.com/0xn0ne/weblogicScanner

https://github.com/alexfrancow/CVE-2020-14882

https://github.com/zhzyker/exphub

https://github.com/Root-Shells/CVE-2020-14882

https://github.com/GGyao/CVE-2020-14882_POC

https://github.com/Danny-LLi/CVE-2020-14882

https://github.com/mmioimm/cve-2020-14882

https://github.com/1n7erface/PocList

https://github.com/N0Coriander/CVE-2020-14882-14883

https://github.com/corelight/CVE-2020-14882-weblogicRCE

https://github.com/jas502n/CVE-2020-14882

https://github.com/AleksaZatezalo/CVE-2020-14882

https://github.com/GGyao/CVE-2020-14882_ALL

https://github.com/nik0nz7/CVE-2020-14882

https://github.com/zesnd/CVE-2020-14882-POC

https://github.com/NS-Sp4ce/CVE-2020-14882

https://github.com/pprietosanchez/CVE-2020-14750

https://github.com/BabyTeam1024/CVE-2020-14882

https://github.com/0thm4n3/cve-2020-14882

https://github.com/XTeam-Wing/CVE-2020-14882

https://github.com/b1g-b33f/CVE-2020-14882

security_crawler_carl at 2026-08-25T09:45:06.059Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

(2/2)

##

security_crawler_carl@infosec.exchange at 2026-08-25T09:45:06.000Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)

##

CVE-2025-9615
(3.3 LOW)

EPSS: 0.15%

updated 2026-05-19T15:31:20

2 posts

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

cR0w@infosec.exchange at 2026-08-24T18:55:29.000Z ##

@agowa338 It's an incomplete fix for CVE-2025-9615:

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

##

cR0w@infosec.exchange at 2026-08-24T18:50:25.000Z ##

i uSe lInUx bEcAuSe iT'S SeCuRe.

access.redhat.com/security/cve

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

##

CVE-2026-28389
(7.5 HIGH)

EPSS: 0.80%

updated 2026-05-12T15:31:15

2 posts

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional

neverpanic@chaos.social at 2026-08-26T20:55:21.000Z ##

"This issue was reported on 13th February 2026 by Nathan Sportsman
(Praetorian), on 25th February 2026 by Daniel Rhea, on 15th March 2026
by Jaeho Nam (Seoul National University), on 26th March 2026 by
Muhammad Daffa, on 27th March 2026 by Zhanpeng Liu (Tencent Xuanwu Lab),
Guannan Wang (Tencent Xuanwu Lab) and Guancheng Li (Tencent Xuanwu Lab)
and on 30th March 2026 by Joshua Rogers (Aisle Research)."

It's really anybody who bothers to look these days. (This one is #OpenSSL CVE-2026-28389)

##

neverpanic@chaos.social at 2026-08-26T20:55:21.000Z ##

"This issue was reported on 13th February 2026 by Nathan Sportsman
(Praetorian), on 25th February 2026 by Daniel Rhea, on 15th March 2026
by Jaeho Nam (Seoul National University), on 26th March 2026 by
Muhammad Daffa, on 27th March 2026 by Zhanpeng Liu (Tencent Xuanwu Lab),
Guannan Wang (Tencent Xuanwu Lab) and Guancheng Li (Tencent Xuanwu Lab)
and on 30th March 2026 by Joshua Rogers (Aisle Research)."

It's really anybody who bothers to look these days. (This one is #OpenSSL CVE-2026-28389)

##

CVE-2025-69419
(7.4 HIGH)

EPSS: 0.56%

updated 2026-05-12T15:31:14

2 posts

Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() functi

1 repos

https://github.com/Kha-Beleh/PoC-CVE-2025-69419

certvde at 2026-08-25T10:45:02.867Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-25T10:45:02.000Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2021-23758
(9.8 CRITICAL)

EPSS: 89.10%

updated 2026-02-03T17:39:26

6 posts

### Overview Affected versions of this package are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution. ### Description Serialization is a process of converting an object into a sequence of bytes which can be persisted to a disk or database or can be sent through streams. The rever

1 repos

https://github.com/numanturle/CVE-2021-23758-POC

secdb at 2026-08-26T19:00:11.097Z ##

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3246 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: access.redhat.com/articles/153 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5287 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/abrt/abrt/commit/3c ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2019-1068 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-23758 (secdb.nttzen.cloud/cve/detail/)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/michaelschwarz/Ajax ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2022-0995 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: git.kernel.org/pub/scm/linux/k ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8452 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: support.citrix.com/support-hom ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-26T18:00:50.000Z ##

CVE ID: CVE-2021-23758
Vendor: Ajax.NET Professional
Product: Ajax.NET Professional
Date Added: 2026-08-26
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

thecybermind at 2026-08-26T17:59:36.924Z ##

🚨 Critical Threat Intel: CVE-2021-23758 impacts Ajax.NET Professional via unsafe object deserialization, enabling remote code execution. Review exploit deployment mechanisms, process telemetry, and active hardening actions. Read the full TSUITE brief: thecycbermind.co/jily

##

secdb@infosec.exchange at 2026-08-26T19:00:11.000Z ##

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3246 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: access.redhat.com/articles/153 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5287 (secdb.nttzen.cloud/cve/detail/)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/abrt/abrt/commit/3c ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2019-1068 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-23758 (secdb.nttzen.cloud/cve/detail/)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/michaelschwarz/Ajax ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2022-0995 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: git.kernel.org/pub/scm/linux/k ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8452 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: support.citrix.com/support-hom ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452

##

cisakevtracker@mastodon.social at 2026-08-26T18:00:50.000Z ##

CVE ID: CVE-2021-23758
Vendor: Ajax.NET Professional
Product: Ajax.NET Professional
Date Added: 2026-08-26
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

thecybermind@infosec.exchange at 2026-08-26T17:59:36.000Z ##

🚨 Critical Threat Intel: CVE-2021-23758 impacts Ajax.NET Professional via unsafe object deserialization, enabling remote code execution. Review exploit deployment mechanisms, process telemetry, and active hardening actions. Read the full TSUITE brief: thecycbermind.co/jily

##

CVE-2025-58187
(6.5 MEDIUM)

EPSS: 0.38%

updated 2026-01-29T18:31:31

2 posts

Due to the design of the name constraint checking algorithm, the processing time of some inputs scals non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.

certvde at 2026-08-25T10:45:02.867Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-25T10:45:02.000Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-0915
(7.5 HIGH)

EPSS: 0.57%

updated 2026-01-20T18:31:56

2 posts

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.

1 repos

https://github.com/cyberwulfy200-dev/CVE-2026-0915-json-Patch.-V2.0

certvde at 2026-08-25T10:45:02.867Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-25T10:45:02.000Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2021-33045
(9.8 CRITICAL)

EPSS: 99.56%

updated 2025-10-22T00:32:21

1 posts

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Nuclei template

3 repos

https://github.com/bp2008/DahuaLoginBypass

https://github.com/dongpohezui/cve-2021-33045

https://github.com/umair-aziz025/dahua-cve-research

niebezpiecznikbot@mastodon.com.pl at 2026-08-24T11:43:00.000Z ##

Ktoś przejął 14 530 kamer Dahua

W okresie od 17 czerwca do 22 lipca 2026r. ktoś zhackował co najmniej 14 530 kamer IP (i innych urządzeń) marki Dahua. Ale popełnił jeden błąd, dzięki czemu cała operacja wyszła na jaw — narzędzia włamywaczy wykorzystane do tej operacji, wraz z dodatkowymi informacjami zostały znalezione na jednym z hostów wykorzystywanych do ataków.
Operacja CameraSwarm
Jak ustalili badacze, atak na kamery realizowano głównie na terytorium Ukrainy i Rosji, a włamywacze wykorzystywali 3 techniki:

zgadywanie loginów i haseł na porcie TCP/37777 (skutek: 12324 przejętych urządzeń)
wykorzystanie podatności CVE-2021-33044 i CVE-2021-33045 (umożliwiły dostęp do niezałatanych urządzeń i instaloacje konta-backdoora p2pwn na 1923 kamerach. Tak, to podatność załatana 5 lat temu…)
mechanizm P2P Dahua (dostęp do 283 kamer za NAT-em przy użyciu numeru seryjnego i danych zaszytych w klientach Dahua).

Analiza narzędzi opublikowanych przez włamywaczy ujawniła też, że z przejętych kamer odrzucali ciemne/nieużyteczne klatki a resztę (plus ewentualne dane logowania) wysyłali na Telegram.
Mam kamerę Dahua, co robić, jak żyć?
Choć raport badaczy nie wymienia Polski wśród głównych obszarów potwierdzonych przejęć, to skanowanie miało zasięg globalny. Marka ma w Polsce oficjalnych dystrybutorów i szeroką ofertę sprzętu do domu i firm, dlatego powinniście sprawdzić swoje urządzenia, nawet jeśli nie otrzymaliście żadnego alertu.
Jeśli kamera Dahua była dostępna z internetu na porcie 37777/tcp w czerwcu lub lipcu 2026r., potraktujcie ją jako potencjalnie przejętą i:

sprawdź listę użytkowników i usuń konto p2pwn, jeśli istnieje;
zaktualizuj firmware do najnowszej wersji właściwej dla konkretnego modelu;
wyłącz P2P, jeśli go nie potrzebujesz, oraz nie wystawiaj portu 37777 do internetu;
zmień hasła kamery, [...]

#CCTV #Dahua #Kamery #Monitoring #Rosja #Ukraina

niebezpiecznik.pl/post/ktos-pr

##

niebezpiecznikbot@mastodon.com.pl at 2026-08-24T11:43:00.000Z ##

Ktoś przejął 14 530 kamer Dahua

W okresie od 17 czerwca do 22 lipca 2026r. ktoś zhackował co najmniej 14 530 kamer IP (i innych urządzeń) marki Dahua. Ale popełnił jeden błąd, dzięki czemu cała operacja wyszła na jaw — narzędzia włamywaczy wykorzystane do tej operacji, wraz z dodatkowymi informacjami zostały znalezione na jednym z hostów wykorzystywanych do ataków.
Operacja CameraSwarm
Jak ustalili badacze, atak na kamery realizowano głównie na terytorium Ukrainy i Rosji, a włamywacze wykorzystywali 3 techniki:

zgadywanie loginów i haseł na porcie TCP/37777 (skutek: 12324 przejętych urządzeń)
wykorzystanie podatności CVE-2021-33044 i CVE-2021-33045 (umożliwiły dostęp do niezałatanych urządzeń i instaloacje konta-backdoora p2pwn na 1923 kamerach. Tak, to podatność załatana 5 lat temu…)
mechanizm P2P Dahua (dostęp do 283 kamer za NAT-em przy użyciu numeru seryjnego i danych zaszytych w klientach Dahua).

Analiza narzędzi opublikowanych przez włamywaczy ujawniła też, że z przejętych kamer odrzucali ciemne/nieużyteczne klatki a resztę (plus ewentualne dane logowania) wysyłali na Telegram.
Mam kamerę Dahua, co robić, jak żyć?
Choć raport badaczy nie wymienia Polski wśród głównych obszarów potwierdzonych przejęć, to skanowanie miało zasięg globalny. Marka ma w Polsce oficjalnych dystrybutorów i szeroką ofertę sprzętu do domu i firm, dlatego powinniście sprawdzić swoje urządzenia, nawet jeśli nie otrzymaliście żadnego alertu.
Jeśli kamera Dahua była dostępna z internetu na porcie 37777/tcp w czerwcu lub lipcu 2026r., potraktujcie ją jako potencjalnie przejętą i:

sprawdź listę użytkowników i usuń konto p2pwn, jeśli istnieje;
zaktualizuj firmware do najnowszej wersji właściwej dla konkretnego modelu;
wyłącz P2P, jeśli go nie potrzebujesz, oraz nie wystawiaj portu 37777 do internetu;
zmień hasła kamery, [...]

#CCTV #Dahua #Kamery #Monitoring #Rosja #Ukraina

niebezpiecznik.pl/post/ktos-pr

##

CVE-2020-2551
(9.8 CRITICAL)

EPSS: 93.17%

updated 2025-10-22T00:31:50

2 posts

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeove

Nuclei template

11 repos

https://github.com/hktalent/CVE-2020-2551

https://github.com/Y4er/CVE-2020-2551

https://github.com/LTiDi2000/CVE-2020-2551

https://github.com/DaMinGshidashi/CVE-2020-2551

https://github.com/Dido1960/Weblogic-CVE-2020-2551-To-Internet

https://github.com/jas502n/CVE-2020-2551

https://github.com/DSO-Lab/defvul

https://github.com/0xn0ne/weblogicScanner

https://github.com/zhzyker/exphub

https://github.com/abbarhissarh/CVE-Exploit

https://github.com/zzwlpx/weblogicPoc

security_crawler_carl at 2026-08-25T09:45:06.059Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

(2/2)

##

security_crawler_carl@infosec.exchange at 2026-08-25T09:45:06.000Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)

##

CVE-2017-10271
(7.5 HIGH)

EPSS: 99.99%

updated 2025-10-22T00:31:29

2 posts

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of

Nuclei template

33 repos

https://github.com/Dungsocool/CVE-2017-10271

https://github.com/testwc/CVE-2017-10271

https://github.com/shahdawadfallah-sys/Cybersecurity-Capstone-Project

https://github.com/Yuusuke4/WebLogic_CNVD_C_2019_48814

https://github.com/lonehand/Oracle-WebLogic-CVE-2017-10271-master

https://github.com/s3xy/CVE-2017-10271

https://github.com/Cymmetria/weblogic_honeypot

https://github.com/kbsec/Weblogic_Wsat_RCE

https://github.com/bigsizeme/weblogic-XMLDecoder

https://github.com/pizza-power/weblogic-CVE-2019-2729-POC

https://github.com/pssss/CVE-2017-10271

https://github.com/seoyoung-kang/CVE-2017-10271

https://github.com/1337g/CVE-2017-10271

https://github.com/cved-sources/cve-2017-10271

https://github.com/0xn0ne/weblogicScanner

https://github.com/SuperHacker-liuan/cve-2017-10271-poc

https://github.com/c0mmand3rOpSec/CVE-2017-10271

https://github.com/ETOCheney/JavaDeserialization

https://github.com/ZH3FENG/PoCs-Weblogic_2017_10271

https://github.com/cjjduck/weblogic_wls_wsat_rce

https://github.com/KKsdall/7kbstormq

https://github.com/Luffin/CVE-2017-10271

https://github.com/ianxtianxt/-CVE-2017-10271-

https://github.com/SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961

https://github.com/JackyTsuuuy/weblogic_wls_rce_poc-exp

https://github.com/7kbstorm/WebLogic_CNVD_C2019_48814

https://github.com/shack2/javaserializetools

https://github.com/kkirsche/CVE-2017-10271

https://github.com/rambleZzz/weblogic_CVE_2017_10271

https://github.com/XHSecurity/Oracle-WebLogic-CVE-2017-10271

https://github.com/Al1ex/CVE-2017-10271

https://github.com/r4b3rt/CVE-2017-10271

https://github.com/peterpeter228/Oracle-WebLogic-CVE-2017-10271

security_crawler_carl at 2026-08-25T09:45:06.059Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

(2/2)

##

security_crawler_carl@infosec.exchange at 2026-08-25T09:45:06.000Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)

##

CVE-2025-55241
(9.0 None)

EPSS: 1.55%

updated 2025-09-18T15:31:27

2 posts

Azure Entra Elevation of Privilege Vulnerability

hasamba at 2026-08-26T06:11:01.145Z ##

----------------

🎯 Threat Intelligence
===================

ERNW published the first of a four-part series on token theft in Microsoft Entra ID, accompanying White Paper 80. The post maps the shift from on-premises Active Directory to cloud identity and explains why token theft has become a primary attack vector.

🔹 Landscape Shift

On-premises AD relied on Kerberos and NTLM. Entra ID runs on OAuth 2.0 and OpenID Connect, using JWT-based access, refresh, and ID tokens. New protocols create new attack surface. Microsoft prioritizes usability and backward compatibility over security-by-default, and the strongest protections (Conditional Access, Token Protection, risk-based Identity Protection) are not enabled by default. They require premium P1/P2 licenses plus separate products like Intune or Defender for Endpoint.

Proprietary SSO concepts like PRT, FOCI, and BroCI add further complexity beyond standard OAuth 2.0.

🔹 Concrete Threats

Microsoft's Digital Defense Report 2024 counts over 600 million daily identity attacks against Entra ID. Two notable CVEs:
• CVE-2025-55241: Actor Tokens flaw allowing Global Admin access to any Entra ID tenant worldwide, disclosed by researcher Dirk-jan Mollema
• CVE-2026-69836: CVSS 10.0 unauthenticated RCE in Entra ID itself, caused by unsafe deserialization of untrusted data

🔹 Active Campaigns
• Storm-2372: device code phishing campaign targeting governments and critical industries since August 2024
• Storm-2945: hijacked hotel captive portals worldwide to harvest SSO tokens
• AiTM "code of conduct" phishing: intercepts tokens the moment MFA succeeds rather than trying to defeat MFA directly

🔹 Commodity Tooling

Open-source reverse-proxy frameworks Evilginx and Modlishka, along with PhaaS platforms like EvilProxy, Tycoon2FA, and Kali365, have lowered the barrier to running token theft attacks at scale. Infostealers add further reach by harvesting tokens from compromised endpoints.

🔹 Cloud Security Alliance Ranking

CSA's Top Threats to Cloud Computing 2026 ranks IAM-related threats as the #1 risk to cloud environments, ahead of AI-enhanced attacks in second place despite the current AI security hype cycle.

🔹 What's Next

The series will empirically test Continuous Access Evaluation and Token Protection, and examine where Entra ID deviates from OAuth 2.0 best practices.

🔹 EntraID

🔗 Source: insinuator.net/2026/08/token-t

##

hasamba@infosec.exchange at 2026-08-26T06:11:01.000Z ##

----------------

🎯 Threat Intelligence
===================

ERNW published the first of a four-part series on token theft in Microsoft Entra ID, accompanying White Paper 80. The post maps the shift from on-premises Active Directory to cloud identity and explains why token theft has become a primary attack vector.

🔹 Landscape Shift

On-premises AD relied on Kerberos and NTLM. Entra ID runs on OAuth 2.0 and OpenID Connect, using JWT-based access, refresh, and ID tokens. New protocols create new attack surface. Microsoft prioritizes usability and backward compatibility over security-by-default, and the strongest protections (Conditional Access, Token Protection, risk-based Identity Protection) are not enabled by default. They require premium P1/P2 licenses plus separate products like Intune or Defender for Endpoint.

Proprietary SSO concepts like PRT, FOCI, and BroCI add further complexity beyond standard OAuth 2.0.

🔹 Concrete Threats

Microsoft's Digital Defense Report 2024 counts over 600 million daily identity attacks against Entra ID. Two notable CVEs:
• CVE-2025-55241: Actor Tokens flaw allowing Global Admin access to any Entra ID tenant worldwide, disclosed by researcher Dirk-jan Mollema
• CVE-2026-69836: CVSS 10.0 unauthenticated RCE in Entra ID itself, caused by unsafe deserialization of untrusted data

🔹 Active Campaigns
• Storm-2372: device code phishing campaign targeting governments and critical industries since August 2024
• Storm-2945: hijacked hotel captive portals worldwide to harvest SSO tokens
• AiTM "code of conduct" phishing: intercepts tokens the moment MFA succeeds rather than trying to defeat MFA directly

🔹 Commodity Tooling

Open-source reverse-proxy frameworks Evilginx and Modlishka, along with PhaaS platforms like EvilProxy, Tycoon2FA, and Kali365, have lowered the barrier to running token theft attacks at scale. Infostealers add further reach by harvesting tokens from compromised endpoints.

🔹 Cloud Security Alliance Ranking

CSA's Top Threats to Cloud Computing 2026 ranks IAM-related threats as the #1 risk to cloud environments, ahead of AI-enhanced attacks in second place despite the current AI security hype cycle.

🔹 What's Next

The series will empirically test Continuous Access Evaluation and Token Protection, and examine where Entra ID deviates from OAuth 2.0 best practices.

🔹 EntraID #TokenTheft #ThreatIntelligence #OAuth2 #Cybersecurity

🔗 Source: insinuator.net/2026/08/token-t

##

CVE-2026-61792
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-26T21:59:50.000Z ##

🟠 CVE-2026-61792 - High (7.7)

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resol...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T21:59:50.000Z ##

🟠 CVE-2026-61792 - High (7.7)

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resol...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T21:01:58.000Z ##

🔴 CVE-2026-60004 - Critical (9.8)

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

threatnoir at 2026-08-26T18:06:42.902Z ##

⚠️ CRITICAL: Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Gitea instances are under active attack for CVE-2026-60004, a critical RCE flaw (CVSS 9.8) that allows unauthenticated account creation to trigger arbitrary command execution. Attackers are deploying miner-like payloads. Any organization running Gitea with default open registration is at immediate…

threatnoir.com/focus

🤖 AI generated summary

##

sayzard@mastodon.sayzard.org at 2026-08-26T17:41:47.000Z ##

Hackers now exploit critical Gitea flaw in code injection attacks

자가 호스팅 Git 서비스 Gitea의 치명적 취약점 CVE-2026-60004가 실제 공격에 악용되고 있다. 공격자는 diffpatch API에 악성 패치를 제출해 저장소 제어 콘텐츠로 Git hook을 설치하고, Gitea 서비스 계정 권한으로 임의 셸 명령을 실행할 수 있다. 기본 설정에서는 사용자 자가 가입이 켜져 있어, 외부 공격자가 계정을 만든 뒤 저장소를 생성하는 것만으로 필요한 쓰기 권한을 얻을 수 있다. Gitea 1.27.1에서 수정됐으며, C...

bleepingcomputer.com/news/secu

##

beyondmachines1 at 2026-08-26T17:01:20.120Z ##

CISA Reports Actively Exploited Gitea Critical RCE Vulnerability

Gitea patched a critical remote code execution vulnerability (CVE-2026-60004) that attackers are actively exploiting to install crypto-miners on self-hosted instances. The flaw allows users with write access to inject malicious Git hooks via the diffpatch API, potentially exposing database credentials and system secrets.

**Update self-hosted Gitea instances to version 1.27.1 immediately. Now it's urgent, since hackers are actively attacking you. If you can't patch right away, disable public registration to prevent new outsiders from obtaining repository write access. This does not protect against existing users who already have the required permissions.**

beyondmachines.net/event_detai

##

cyberworldops at 2026-08-26T14:40:00.588Z ##

CISA has listed CVE-2026-60004 in the KEV Catalog. Critical RCE in Gitea actively exploited via malicious patches submitted through the diff API endpoint. Attackers achieve code injection on self-hosted instances and deploy cryptominers on compromised servers. Patch by August 28 is mandatory.

cyberworldops.eu/en/gitea-unde

##

undercodenews@mastodon.social at 2026-08-26T13:55:21.000Z ##

CISA Sounds the Alarm as Actively Exploited Gitea Flaw Lets Authenticated Users Run Shell Commands + Video

A New Warning Raises Serious Questions for Gitea Administrators A new cybersecurity warning has placed Gitea administrators under pressure after the U.S. Cybersecurity and Infrastructure Security Agency, CISA, identified CVE-2026-60004 as an actively exploited vulnerability. The flaw reportedly affects the popular self-hosted Git service and could allow an…

undercodenews.com/cisa-sounds-

##

netsecio@mastodon.social at 2026-08-26T13:27:06.000Z ##

📰 CISA Warns of Actively Exploited Gitea RCE Flaw (CVE-2026-60004)

🚨 CISA KEV ALERT: A critical RCE flaw in Gitea (CVE-2026-60004, CVSS 9.8) is actively exploited. Attackers can gain RCE on self-hosted Git servers. Patch to version 1.27.1 or later NOW. #Gitea #RCE #CISA #KEV #CVE202660004

🔗 cyber.netsecops.io/articles/ci

##

security_crawler_carl at 2026-08-26T12:37:59.553Z ##

🏆 New Achievement! Hook, Line, and Git Hooked!

And here, in its natural habitat, we observe the self-hosted Git server — a creature believed by its keepers to be safely tucked away, far from predators. CVE-2026-60004 tells a different story. An attacker with mere repository write access may deliver a malicious patch to Gitea's diffpatch API endpoint, planting an executable Git hook and inheriting the Gitea service account like a cuckoo claiming another bird's nest. (1/2)

##

cyberworldops at 2026-08-26T12:20:00.667Z ##

CISA has added CVE-2026-60004 to the KEV catalog. The vulnerability in Gitea, a self-hosted Git service, has been exploited in the wild to achieve remote code execution and install cryptocurrency miners on compromised instances. FCEB agencies face a remediation deadline of August 28, 2026.

cyberworldops.eu/en/cisa-adds-

##

undercodenews@mastodon.social at 2026-08-26T11:33:05.000Z ##

Gitea Under Attack: Critical CVE-2026-60004 Turns Self-Hosted Git Servers Into Potential Remote-Control Hubs

A Quiet Git Feature Has Become a Dangerous Attack Path Self-hosted development platforms are built on a simple promise: organizations keep control of their source code, repositories, credentials, and development infrastructure instead of placing everything in a public cloud. But that control comes with a responsibility that is easy to underestimate—every exposed…

undercodenews.com/gitea-under-

##

Analyst207@mastodon.social at 2026-08-26T11:25:49.000Z ##

Gitea Flaw Exploited in Code Injection Attacks

A critical flaw in Gitea, tracked as CVE-2026-60004, is being actively exploited in code injection attacks, putting nearly 5,000 self-hosted Git service instances at risk. Attackers can inject malicious code by submitting patches via Gitea's diffpatch API endpoint, allowing them to execute arbitrary shell commands.

osintsights.com/gitea-flaw-exp

#Gitea #CodeInjection #Cve202660004 #SupplyChain #EmergingThreats

##

undercodenews@mastodon.social at 2026-08-26T09:38:26.000Z ##

Critical Gitea Vulnerability CVE-2026-60004 Enters CISA’s Exploited Threat List as Attackers Target Self-Hosted Git Servers + Video

A New Warning for Developers and Security Teams A seemingly ordinary software update has turned into an urgent security warning for organizations running self-hosted Git infrastructure. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-60004 to its Known Exploited Vulnerabilities (KEV) catalog after…

undercodenews.com/critical-git

##

thecybermind at 2026-08-25T22:12:37.598Z ##

🚨 Critical Threat Intel: CVE-2026-60004 targets Gitea via diffpatch API code injection. Review execution vectors, persistence mechanics, and active endpoint hardening actions to secure your version control infrastructure. thecybermind.co/jily

##

AAKL at 2026-08-25T19:18:50.900Z ##

CISA has updated the KEV catalogue.

- CVE-2026-60004: Gitea Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- Industrial vulnerability: Rently Smart Home cisa.gov/news-events/ics-advis

Also:

Press release: CISA Advisory Highlights Red Team Findings to Help Organizations Assess Risk, Identify Threats and Enable Effective Incident Response cisa.gov/news-events/news/cisa

The advisory: A Tale of Two SOCs: Insights From Two Red Team Assessments cisa.gov/news-events/cybersecu

##

cisakevtracker@mastodon.social at 2026-08-25T18:00:55.000Z ##

CVE ID: CVE-2026-60004
Vendor: Gitea
Product: Gitea
Date Added: 2026-08-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb at 2026-08-25T18:00:17.922Z ##

🚨 [CISA-2026:0825] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-60004 (secdb.nttzen.cloud/cve/detail/)
- Name: Gitea Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Gitea
- Product: Gitea
- Notes: github.com/go-gitea/gitea/secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

thehackerwire@mastodon.social at 2026-08-26T21:01:58.000Z ##

🔴 CVE-2026-60004 - Critical (9.8)

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

threatnoir@infosec.exchange at 2026-08-26T18:06:42.000Z ##

⚠️ CRITICAL: Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Gitea instances are under active attack for CVE-2026-60004, a critical RCE flaw (CVSS 9.8) that allows unauthenticated account creation to trigger arbitrary command execution. Attackers are deploying miner-like payloads. Any organization running Gitea with default open registration is at immediate…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

beyondmachines1@infosec.exchange at 2026-08-26T17:01:20.000Z ##

CISA Reports Actively Exploited Gitea Critical RCE Vulnerability

Gitea patched a critical remote code execution vulnerability (CVE-2026-60004) that attackers are actively exploiting to install crypto-miners on self-hosted instances. The flaw allows users with write access to inject malicious Git hooks via the diffpatch API, potentially exposing database credentials and system secrets.

**Update self-hosted Gitea instances to version 1.27.1 immediately. Now it's urgent, since hackers are actively attacking you. If you can't patch right away, disable public registration to prevent new outsiders from obtaining repository write access. This does not protect against existing users who already have the required permissions.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-08-26T14:40:00.000Z ##

CISA has listed CVE-2026-60004 in the KEV Catalog. Critical RCE in Gitea actively exploited via malicious patches submitted through the diff API endpoint. Attackers achieve code injection on self-hosted instances and deploy cryptominers on compromised servers. Patch by August 28 is mandatory.

#CriticalRCE #GiteaVulnerability #Cryptojacking #CISAKEV

cyberworldops.eu/en/gitea-unde

##

security_crawler_carl@infosec.exchange at 2026-08-26T12:37:59.000Z ##

🏆 New Achievement! Hook, Line, and Git Hooked!

And here, in its natural habitat, we observe the self-hosted Git server — a creature believed by its keepers to be safely tucked away, far from predators. CVE-2026-60004 tells a different story. An attacker with mere repository write access may deliver a malicious patch to Gitea's diffpatch API endpoint, planting an executable Git hook and inheriting the Gitea service account like a cuckoo claiming another bird's nest. (1/2)

##

cyberworldops@infosec.exchange at 2026-08-26T12:20:00.000Z ##

CISA has added CVE-2026-60004 to the KEV catalog. The vulnerability in Gitea, a self-hosted Git service, has been exploited in the wild to achieve remote code execution and install cryptocurrency miners on compromised instances. FCEB agencies face a remediation deadline of August 28, 2026.

#KnownExploitedVulnerabilities #RemoteCodeExecution #Gitea #CISA

cyberworldops.eu/en/cisa-adds-

##

thecybermind@infosec.exchange at 2026-08-25T22:12:37.000Z ##

🚨 Critical Threat Intel: CVE-2026-60004 targets Gitea via diffpatch API code injection. Review execution vectors, persistence mechanics, and active endpoint hardening actions to secure your version control infrastructure. thecybermind.co/jily

##

AAKL@infosec.exchange at 2026-08-25T19:18:50.000Z ##

CISA has updated the KEV catalogue.

- CVE-2026-60004: Gitea Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- Industrial vulnerability: Rently Smart Home cisa.gov/news-events/ics-advis

Also:

Press release: CISA Advisory Highlights Red Team Findings to Help Organizations Assess Risk, Identify Threats and Enable Effective Incident Response cisa.gov/news-events/news/cisa

The advisory: A Tale of Two SOCs: Insights From Two Red Team Assessments cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

cisakevtracker@mastodon.social at 2026-08-25T18:00:55.000Z ##

CVE ID: CVE-2026-60004
Vendor: Gitea
Product: Gitea
Date Added: 2026-08-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-08-25T18:00:17.000Z ##

🚨 [CISA-2026:0825] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-60004 (secdb.nttzen.cloud/cve/detail/)
- Name: Gitea Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Gitea
- Product: Gitea
- Notes: github.com/go-gitea/gitea/secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260825 #cisa20260825 #cve_2026_60004 #cve202660004

##

CVE-2026-80196
(0 None)

EPSS: 0.42%

1 posts

N/A

hugovalters@mastodon.social at 2026-08-26T18:04:01.000Z ##

CVE-2026-80196 - Authentication Bypass in Kimai before 2.58.0 via password reset link reuse. CVSS 7.5. Update to version 2.58.0 immediately. #CVE #Kimai #infosec

valtersit.com/cve/CVE-2026-801

##

CVE-2026-78379
(0 None)

EPSS: 0.32%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-26T15:00:28.000Z ##

🟠 CVE-2026-78379 - High (8.1)

Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T15:00:28.000Z ##

🟠 CVE-2026-78379 - High (8.1)

Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77537
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-65641
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-08-26T08:33:06.354Z ##

A critical Veeam ONE vulnerability (CVE-2026-65641, CVSS 9.3) lets an unauthenticated attacker coerce SMB authentication. Patch Veeam now.

securityonline.info/veeam-cve-

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T08:33:06.000Z ##

A critical Veeam ONE vulnerability (CVE-2026-65641, CVSS 9.3) lets an unauthenticated attacker coerce SMB authentication. Patch Veeam now.

#Veeam #CyberSecurity #CVE202665641 #SMB #Infosec

securityonline.info/veeam-cve-

##

DailyCyberSecurity at 2026-08-26T01:58:20.310Z ##

Two critical Next.js vulnerabilities, including CVE-2026-75604 (CVSS 9.0), enable unauthenticated remote code execution. Patch to 15.5.24 or 16.3.3 now.

securityonline.info/nextjs-rce

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T01:58:20.000Z ##

Two critical Next.js vulnerabilities, including CVE-2026-75604 (CVSS 9.0), enable unauthenticated remote code execution. Patch to 15.5.24 or 16.3.3 now.

#NextJS #RCE #CyberSecurity #CVE202675604 #WebSecurity

securityonline.info/nextjs-rce

##

DailyCyberSecurity at 2026-08-26T00:59:20.268Z ##

A public PoC exploits a Redis RCE use-after-free flaw tied to CVE-2026-23479, running system commands as the Redis server. Update to 8.8.2.

securityonline.info/redis-rce-

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T00:59:20.000Z ##

A public PoC exploits a Redis RCE use-after-free flaw tied to CVE-2026-23479, running system commands as the Redis server. Update to 8.8.2.

#Redis #RCE #UseAfterFree #CVE202623479 #InfoSec

securityonline.info/redis-rce-

##

CVE-2026-18965
(0 None)

EPSS: 0.00%

2 posts

N/A

cyberworldops at 2026-08-25T20:20:01.202Z ##

CVE-2026-18965 discloses a missing authorization flaw in the PayRange API (CWE-862). All versions are affected. The vulnerability allows unauthenticated remote access to payment devices, exposing fleets of vending machines and kiosks to unauthorized interaction.

cyberworldops.eu/en/payrange-a

##

cyberworldops@infosec.exchange at 2026-08-25T20:20:01.000Z ##

CVE-2026-18965 discloses a missing authorization flaw in the PayRange API (CWE-862). All versions are affected. The vulnerability allows unauthenticated remote access to payment devices, exposing fleets of vending machines and kiosks to unauthorized interaction.

#CVE202618965 #MissingAuthorization #PayRangeAPI #CriticalVulnerability

cyberworldops.eu/en/payrange-a

##

guru@thecybersecguru.com at 2026-08-25T18:30:39.000Z ##

CVE-2026-72898: Critical Metabase SQL Injection Is Being Actively Exploited, Allowing Unauthenticated Admin Takeover

CVE-2026-72898 is a critical Metabase SQL injection flaw actively exploited in the wild. Learn affected versions, attack path, impact, detection and mitigation

thecybersecguru.com/exploits/c

##

CVE-2026-59285
(0 None)

EPSS: 0.00%

1 posts

N/A

undercodenews@mastodon.social at 2026-08-25T10:15:20.000Z ##

Spring GraphQL Security Alert: CVE-2026-59285 Creates a Dangerous Path to Remote Code Execution

A New Warning for Spring-Based Applications A newly disclosed vulnerability in Spring for GraphQL is putting developers and security teams on notice. CVE-2026-59285 affects specific Spring GraphQL applications that combine Jackson 2.x deserialization, paginated GraphQL fields, and certain classes available on the application's classpath. The vulnerability is particularly…

undercodenews.com/spring-graph

##

CVE-2026-59270
(0 None)

EPSS: 0.00%

2 posts

N/A

beyondmachines1 at 2026-08-25T08:01:17.240Z ##

Broadcom Patches 91 Spring CVEs, Including a Critical LDAP Flaw

Broadcom's Tanzu division released one of Spring's largest-ever security batches on August 20, 2026, patching 91 CVEs across Spring Security, Spring AI, Spring GraphQL and related projects, including the critical CVE-2026-59270 (CVSS 9.8) in Spring Security's embedded UnboundID LDAP server and a critical deserialization/RCE flaw in Spring GraphQL.

**If you run Java applications built on Spring, update Spring Security to 7.1.1, 7.0.7 (or 6.5.12 / 5.8.28 on older supported branches) and upgrade Spring AI and Spring GraphQL to their patched versions. CheckUntil you can patch, block access to the LDAP listener ports with firewall rules so they can only be reached from trusted networks.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-25T08:01:17.000Z ##

Broadcom Patches 91 Spring CVEs, Including a Critical LDAP Flaw

Broadcom's Tanzu division released one of Spring's largest-ever security batches on August 20, 2026, patching 91 CVEs across Spring Security, Spring AI, Spring GraphQL and related projects, including the critical CVE-2026-59270 (CVSS 9.8) in Spring Security's embedded UnboundID LDAP server and a critical deserialization/RCE flaw in Spring GraphQL.

**If you run Java applications built on Spring, update Spring Security to 7.1.1, 7.0.7 (or 6.5.12 / 5.8.28 on older supported branches) and upgrade Spring AI and Spring GraphQL to their patched versions. CheckUntil you can patch, block access to the LDAP listener ports with firewall rules so they can only be reached from trusted networks.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-13214
(0 None)

EPSS: 0.51%

2 posts

N/A

offseq at 2026-08-25T07:30:25.487Z ##

CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, >=4.3.0 <4.4.2. Restrict untrusted WebSocket access. Patch status pending. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-25T07:30:25.000Z ##

CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, >=4.3.0 <4.4.2. Restrict untrusted WebSocket access. Patch status pending. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #CVE202613214 #IoTSec

##

CVE-2026-76098
(0 None)

EPSS: 0.28%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-24T22:01:51.000Z ##

🟠 CVE-2026-76098 - High (7.5)

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77567
(0 None)

EPSS: 0.30%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-24T22:00:04.000Z ##

🟠 CVE-2026-77567 - High (8.1)

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66897
(0 None)

EPSS: 0.62%

1 posts

N/A

offseq@infosec.exchange at 2026-08-24T10:30:26.000Z ##

CVE-2026-66897: Canonical LXD CRITICAL path traversal (CVSS 9.9). Attackers with container edit rights or crafted images can overwrite host files as root. Restrict permissions & avoid untrusted images. Patch status unknown. radar.offseq.com/threat/cve-20 #OffSeq #LXD #CVE #Linux

##

CVE-2026-78251
(0 None)

EPSS: 0.39%

1 posts

N/A

offseq@infosec.exchange at 2026-08-24T07:30:24.000Z ##

CVE-2026-78251 (CRITICAL): DJI Neo & related drones have hard-coded FTP creds, letting attackers fill storage & disrupt logging/updates via network or USB. Patch required! radar.offseq.com/threat/cve-20 #OffSeq #CVE2026_78251 #DJI #DroneSec

##

Visit counter For Websites