## Updated at UTC 2026-08-04T18:41:50.461972

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-69110 9.1 0.00% 2 0 2026-08-04T17:16:59.733000 OpenCode Studio before 2.4.4 contains a missing authentication vulnerability tha
CVE-2026-69100 8.8 0.00% 2 0 2026-08-04T17:16:59.320000 LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains
CVE-2026-48323 10.0 0.62% 2 0 2026-08-04T17:16:55.413000 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-25292 7.6 0.00% 2 0 2026-08-04T17:16:53.797000 Memory Corruption when processing untrusted user input in the fastboot command h
CVE-2026-24084 7.5 0.00% 2 0 2026-08-04T17:16:52.453000 Weak configuration when UE does not verify the consistency of its additional sec
CVE-2026-24083 7.8 0.00% 2 0 2026-08-04T17:16:52.040000 Memory Corruption while processing IOCTL device driver requests with invalid arg
CVE-2026-60007 0 0.00% 2 0 2026-08-04T16:16:26.367000 In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns
CVE-2026-48326 9.9 0.48% 2 0 2026-08-04T16:16:25.497000 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-18686 9.8 2.61% 2 0 2026-08-04T16:16:21.593000 A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem
CVE-2026-18401 None 0.00% 1 0 2026-08-04T15:32:23 The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the
CVE-2026-69246 7.2 0.21% 1 0 2026-08-04T15:16:42.927000 Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives
CVE-2026-66315 7.5 0.62% 1 0 2026-08-04T15:16:38.033000 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke
CVE-2026-48333 9.8 0.47% 1 0 2026-08-04T15:16:35.963000 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-12816 0 0.16% 1 0 2026-08-04T14:50:12.360000 In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via len
CVE-2026-58062 0 0.20% 2 0 2026-08-04T14:50:12.360000 In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without bi
CVE-2026-8763 0 0.33% 2 0 2026-08-04T14:50:12.360000 In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot
CVE-2026-59638 0 0.28% 1 0 2026-08-04T14:50:12.360000 In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enable
CVE-2026-48331 10.0 0.47% 1 0 2026-08-04T14:48:22.933000 Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF)
CVE-2026-62354 0 0.26% 1 0 2026-08-04T14:48:22.933000 Authorization handling for Parameter Context validation requests in Apache NiFi
CVE-2026-48330 10.0 0.68% 1 0 2026-08-04T14:48:22.933000 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-34641 7.8 0.14% 1 0 2026-08-04T14:48:22.933000 Premiere Pro is affected by an out-of-bounds write vulnerability that could resu
CVE-2026-6837 7.2 0.95% 2 0 2026-08-04T14:47:47.393000 A post-authentication command injection vulnerability in the "export-cgi" CGI pr
CVE-2026-18577 8.1 2.53% 15 1 2026-08-04T14:27:12.530000 An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco
CVE-2026-18556 7.4 0.27% 5 0 2026-08-04T13:58:04.463000 Authentication bypass using an alternate path or channel vulnerability in N-able
CVE-2026-14804 9.1 0.30% 3 0 2026-08-04T13:17:35.893000 Use of hard-coded cryptographic key vulnerability in Bilin Software and Informat
CVE-2026-14175 9.8 0.40% 4 0 2026-08-04T12:34:56 Unrestricted upload of file with dangerous type vulnerability in Bilin Software
CVE-2026-15721 9.8 0.23% 2 0 2026-08-04T12:34:56 Cleartext storage of sensitive information vulnerability in Bilin Software and I
CVE-2026-10685 7.6 0.18% 1 0 2026-08-04T12:31:51.160000 The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp()
CVE-2026-17349 9.6 0.30% 1 0 2026-08-04T12:31:51.160000 /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced
CVE-2026-18754 9.1 0.31% 1 0 2026-08-04T09:31:41 The product firmware contains an embedded, static RSA private key utilized by th
CVE-2026-15958 None 0.14% 1 0 2026-08-04T09:31:41 The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform
CVE-2026-66066 0 1.70% 3 7 2026-08-04T05:16:40.060000 Action Pack is a framework for handling and responding to web requests. In versi
CVE-2026-68981 None 0.32% 1 0 2026-08-04T00:35:57 Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the appl
CVE-2026-68979 None 0.35% 1 0 2026-08-04T00:35:57 Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API me
CVE-2026-18684 9.8 2.03% 1 0 2026-08-04T00:35:01 A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affe
CVE-2026-66310 7.7 0.40% 1 0 2026-08-04T00:35:01 External control of file name or path in Microsoft Edge for Android allows an un
CVE-2026-66318 8.1 0.37% 1 0 2026-08-04T00:35:01 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize
CVE-2026-18685 9.8 1.99% 1 0 2026-08-04T00:35:01 A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Imp
CVE-2026-66803 10.0 0.49% 1 0 2026-08-04T00:17:39.977000 Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex
CVE-2026-59913 7.8 0.11% 1 0 2026-08-03T21:31:44 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, co
CVE-2026-59912 7.8 0.10% 1 0 2026-08-03T21:31:36 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, co
CVE-2026-18108 9.8 0.22% 1 0 2026-08-03T21:31:35 Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _ve
CVE-2026-67288 7.5 0.35% 1 0 2026-08-03T21:31:31 FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart
CVE-2026-69240 9.8 0.32% 1 0 2026-08-03T20:29:52 ### Summary SQL Injection is possible with strings only **if dialect is set to `
CVE-2026-67357 7.5 0.25% 1 0 2026-08-03T20:17:27.833000 ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability
CVE-2026-67298 7.5 0.38% 1 0 2026-08-03T20:17:26.477000 FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server
CVE-2026-8457 9.8 0.40% 2 0 2026-08-03T19:16:53.733000 The WooCommerce - Social Login plugin for WordPress is vulnerable to Authenticat
CVE-2026-67294 5.9 0.27% 1 0 2026-08-03T19:16:50.143000 FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose
CVE-2026-67289 9.8 0.38% 2 0 2026-08-03T19:16:50 FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and c
CVE-2026-66402 9.8 0.29% 2 0 2026-08-03T19:16:49.210000 FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certif
CVE-2026-48449 10.0 0.54% 1 0 2026-08-03T19:16:47.320000 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-18614 9.8 2.01% 1 0 2026-08-03T19:16:45.200000 A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the func
CVE-2026-16300 9.8 0.30% 1 0 2026-08-03T18:31:51 The ChamaWP WordPress plugin before 1.0.13 does not properly validate a passwor
CVE-2026-18612 9.8 2.16% 1 0 2026-08-03T18:30:56 A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affec
CVE-2026-67296 7.5 0.34% 1 0 2026-08-03T18:16:40.860000 FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI se
CVE-2026-18574 0 0.99% 2 0 2026-08-03T17:40:27.300000 An authentication bypass vulnerability in Check Point Security Management Server
CVE-2026-68579 9.6 0.27% 1 0 2026-08-03T17:16:44.330000 FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the W
CVE-2026-67356 8.8 0.25% 1 0 2026-08-03T17:16:43.343000 ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigg
CVE-2026-67305 0 0.49% 1 0 2026-08-03T17:16:40.637000 FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerabili
CVE-2026-67300 7.5 0.33% 1 0 2026-08-03T17:16:40.480000 FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities i
CVE-2026-67290 7.5 0.43% 1 0 2026-08-03T17:16:40.020000 FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TS
CVE-2026-65321 9.8 0.44% 2 1 2026-08-03T17:16:39.617000 PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unau
CVE-2025-71399 8.6 0.31% 1 0 2026-08-03T17:16:28.867000 Better Auth relies on better-call, which uses the rou3 router library. In affect
CVE-2026-67336 8.7 0.16% 1 0 2026-08-03T16:16:30.790000 better-auth versions before 1.6.11 contain insecure cryptographic defaults in th
CVE-2026-3245 7.5 0.24% 1 0 2026-08-03T16:16:29.437000 A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that
CVE-2026-33591 None 0.52% 2 0 2026-08-03T12:32:43 A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unaut
CVE-2026-18589 9.8 0.61% 1 0 2026-08-03T09:32:46 A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the
CVE-2026-9593 6.7 0.11% 1 0 2026-08-03T09:32:46 A vulnerability in the iDTM FDI allows an attacker with elevated privileges and
CVE-2026-58061 None 0.21% 1 0 2026-08-03T09:32:36 In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to calle
CVE-2026-12803 None 0.17% 1 0 2026-08-03T09:32:36 In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce w
CVE-2026-59639 None 0.17% 1 0 2026-08-03T06:32:44 In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for Sig
CVE-2026-59650 None 0.26% 1 0 2026-08-03T06:32:44 In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalid
CVE-2026-68580 7.5 0.24% 1 0 2026-08-02T15:30:26 FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio inp
CVE-2026-68578 7.5 0.21% 1 0 2026-08-02T15:30:25 ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the
CVE-2026-68581 8.1 0.32% 1 0 2026-08-02T15:30:25 Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API
CVE-2026-68582 6.5 0.21% 1 0 2026-08-02T15:30:25 Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorizat
CVE-2026-18352 7.5 0.68% 1 0 2026-08-02T00:31:17 The User Access Manager plugin for WordPress is vulnerable to Directory Traversa
CVE-2026-13339 7.5 0.64% 1 0 2026-08-02T00:31:16 The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal i
CVE-2026-67292 6.5 0.26% 1 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gat
CVE-2026-67291 7.5 0.34% 1 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bound
CVE-2026-67304 7.5 0.35% 1 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart
CVE-2026-67301 7.5 0.34% 1 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async u
CVE-2026-67299 7.5 0.33% 1 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async up
CVE-2026-67308 10.0 0.45% 1 0 2026-08-01T15:30:36 Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub
CVE-2026-67341 9.8 0.32% 1 0 2026-08-01T15:30:30 ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks o
CVE-2026-67342 9.8 0.32% 1 0 2026-08-01T15:30:30 ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in
CVE-2026-67297 7.5 0.34% 1 0 2026-08-01T15:30:26 FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing T
CVE-2026-15414 8.8 0.34% 1 0 2026-08-01T03:31:19 The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privileg
CVE-2026-63223 9.8 0.49% 1 2 2026-08-01T00:17:17.750000 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and
CVE-2026-53504 7.5 0.34% 1 0 2026-08-01T00:17:16.823000 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0,
CVE-2026-66418 9.3 0.34% 1 1 2026-07-31T23:17:26.170000 OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability t
CVE-2026-43832 7.5 0.24% 1 0 2026-07-31T21:32:56 Successful exploitation of the vulnerability could allow an unauthenticated atta
CVE-2025-69933 9.8 0.26% 1 0 2026-07-31T21:32:55 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /me
CVE-2026-43829 7.5 0.24% 1 0 2026-07-31T21:32:55 Successful exploitation of the vulnerability could allow an unauthenticated atta
CVE-2026-43831 7.5 0.24% 1 0 2026-07-31T21:32:55 Successful exploitation of the vulnerability could allow an unauthenticated atta
CVE-2026-15048 7.5 0.26% 1 0 2026-07-31T21:32:55 The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization c
CVE-2026-67822 9.8 0.29% 1 0 2026-07-31T21:31:55 Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in
CVE-2026-14930 7.5 0.24% 1 0 2026-07-31T21:31:54 The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorizati
CVE-2026-53501 8.2 0.21% 1 0 2026-07-31T20:16:51.280000 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0,
CVE-2026-43830 9.8 0.31% 1 0 2026-07-31T20:16:50.463000 Full details and mitigation steps are currently restricted and will be published
CVE-2026-15258 8.1 0.22% 1 0 2026-07-31T20:16:48.207000 The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not
CVE-2026-14483 9.8 0.61% 1 2 2026-07-31T20:16:46.443000 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulner
CVE-2026-14319 7.5 0.32% 1 0 2026-07-31T20:16:46.290000 The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to
CVE-2026-56670 8.2 0.22% 1 0 2026-07-31T19:17:11.290000 ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes int
CVE-2026-54725 9.6 0.32% 1 0 2026-07-31T19:17:10.833000 vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret
CVE-2026-52856 7.5 0.34% 1 0 2026-07-31T19:17:09.120000 Wings is the server control plane for Pterodactyl, a free, open-source game serv
CVE-2025-69936 9.8 0.26% 1 0 2026-07-31T19:17:03.667000 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /ed
CVE-2025-69935 9.8 0.26% 1 0 2026-07-31T19:17:03.420000 CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the
CVE-2025-69934 9.8 0.26% 1 0 2026-07-31T19:17:03.113000 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /de
CVE-2026-53503 7.5 0.42% 1 0 2026-07-31T18:54:57 ### Summary Thumbor's `filters:convolution(<matrix>, <columns>, <should_normaliz
CVE-2026-62391 8.1 0.40% 1 0 2026-07-31T18:33:21 The security fix for CVE-2025-66518 is incomplete. Any client who can access to
CVE-2025-69937 9.8 0.26% 1 0 2026-07-31T18:33:16 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the
CVE-2026-58048 None 0.50% 2 1 2026-07-31T18:32:25 Improper preservation of SQL mode when renaming databases in cPanel allows exec
CVE-2026-17346 8.8 0.43% 1 0 2026-07-31T18:32:24 The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched six
CVE-2026-17351 9.0 0.45% 1 1 2026-07-31T18:32:24 The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query pas
CVE-2026-35847 9.8 0.37% 1 0 2026-07-31T18:17:14.613000 An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrar
CVE-2026-18446 7.5 0.22% 1 0 2026-07-31T18:17:13.383000 fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash
CVE-2026-12720 7.5 0.30% 1 1 2026-07-31T18:17:10.337000 The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be
CVE-2026-12695 8.1 0.29% 1 0 2026-07-31T18:17:10.150000 The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitte
CVE-2026-12251 8.1 0.23% 1 0 2026-07-31T18:17:09.777000 The Ultimate Member WordPress plugin before 2.12.1 does not filter administrato
CVE-2026-14919 9.8 0.28% 1 0 2026-07-31T17:16:32.863000 The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its
CVE-2026-13609 8.8 0.25% 1 0 2026-07-31T17:16:32.347000 The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML ent
CVE-2026-12721 8.6 0.26% 1 0 2026-07-31T17:16:31.993000 The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape
CVE-2026-63362 5.9 1.53% 1 0 2026-07-31T16:17:09.013000 An unsigned integer underflow in the PubSub signature verification path in open
CVE-2026-63222 7.5 0.45% 1 0 2026-07-31T16:17:08.903000 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedF
CVE-2026-52855 9.9 0.27% 1 0 2026-07-31T16:16:48 ### Impact **Type:** Exposure of sensitive information / insufficiently protect
CVE-2026-63221 9.4 0.38% 1 0 2026-07-31T14:16:50.873000 CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query B
CVE-2026-14830 7.5 0.21% 1 0 2026-07-31T14:16:46.133000 The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment proces
CVE-2026-14333 7.5 0.30% 1 0 2026-07-31T14:16:45.960000 The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in
CVE-2026-52539 9.1 0.30% 1 0 2026-07-31T12:30:30 Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOK
CVE-2026-38709 9.8 2.67% 2 0 2026-07-31T12:16:49.683000 TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, W
CVE-2026-18452 10.0 0.43% 1 0 2026-07-31T09:31:30 DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials v
CVE-2026-16236 8.8 0.63% 1 0 2026-07-31T09:31:30 The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Up
CVE-2026-65309 7.5 0.15% 1 0 2026-07-31T09:31:30 ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmit
CVE-2026-65310 7.5 0.32% 1 0 2026-07-31T09:31:30 ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affecte
CVE-2026-12562 8.8 0.28% 1 0 2026-07-31T00:30:29 The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that
CVE-2026-51291 9.8 0.00% 1 0 2026-07-30T21:31:47 sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert functi
CVE-2026-43760 8.6 0.24% 1 0 2026-07-30T19:17:30.313000 An access issue was addressed with improved access restrictions. This issue is f
CVE-2026-17191 9.1 2.83% 1 0 2026-07-30T19:10:52.250000 An input validation vulnerability exists in an API component of the orchestrator
CVE-2026-17192 8.5 2.34% 1 0 2026-07-30T19:10:52.250000 A VCO feature does not sufficiently validate caller-supplied input, allowing req
CVE-2026-59309 9.8 0.74% 2 0 2026-07-30T16:17:15.073000 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-41703 7.6 0.56% 2 0 2026-07-30T16:17:11.403000 VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability.
CVE-2026-41709 2.7 0.38% 2 0 2026-07-30T15:31:51 VMware ESX contains an insufficient logging vulnerability. A malicious administr
CVE-2026-59310 9.8 1.14% 2 0 2026-07-30T15:31:51 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-5492 6.5 1.60% 1 0 2026-07-30T14:18:46.477000 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-5491 7.5 1.54% 1 0 2026-07-30T14:18:46.477000 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-5487 7.5 1.54% 1 0 2026-07-30T14:18:46.477000 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-47876 9.3 0.28% 2 0 2026-07-30T14:16:58.467000 VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual
CVE-2026-16498 10.0 0.33% 2 0 2026-07-30T14:08:23.057000 The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant cr
CVE-2026-16655 7.2 0.30% 1 0 2026-07-30T14:01:30.413000 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Fo
CVE-2026-12935 None 0.81% 1 0 2026-07-29T21:31:07 The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking
CVE-2026-53264 7.8 0.21% 2 1 2026-07-29T21:30:47 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-67192 8.1 0.62% 2 0 2026-07-29T18:31:46 Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overfl
CVE-2026-42533 8.1 3.60% 1 9 2026-07-29T05:16:44.720000 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive
CVE-2026-31431 7.8 94.55% 1 100 template 2026-07-28T14:54:01.770000 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-16462 9.8 0.42% 1 0 2026-07-28T12:31:27 In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a
CVE-2026-11841 9.4 0.46% 1 0 2026-07-28T12:31:20 An attacker may perform unauthenticated read and write operations on sensitive f
CVE-2026-12495 0 0.16% 2 0 2026-07-28T08:17:14.187000 Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http
CVE-2026-48030 9.9 1.54% 1 1 2026-07-27T20:32:11.620000 Pheditor is a single-file editor and file manager written in PHP. From version 2
CVE-2026-45112 7.5 1.94% 1 0 2026-07-27T19:51:07.873000 Allocation of Resources Without Limits or Throttling vulnerability in Apache Thr
CVE-2026-63077 9.8 0.65% 1 1 2026-07-27T18:31:56 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-9198 9.8 1.89% 2 3 template 2026-07-24T16:57:10.373000 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain
CVE-2026-16723 9.0 0.41% 1 7 2026-07-23T15:01:24.377000 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.
CVE-2026-50522 9.8 75.76% 1 5 2026-07-22T21:31:51 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-8933 7.8 0.21% 1 0 2026-07-21T15:30:51 A local privilege escalation vulnerability exists in snap-confine, a set-capabil
CVE-2026-34486 7.5 42.63% 2 6 template 2026-07-20T12:18:48.440000 Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f
CVE-2026-15409 10.0 78.44% 2 6 template 2026-07-16T05:16:18.293000 A Server-side request forgery (SSRF) vulnerability has been identified in the SM
CVE-2026-15410 7.2 76.35% 2 3 2026-07-14T21:32:21 Post-authentication improper control of generation of code ('Code Injection') vu
CVE-2026-54121 8.8 1.05% 1 12 2026-07-14T18:32:37 Improper authorization in Active Directory Certificate Services (AD CS) allows a
CVE-2026-50343 7.8 3.50% 2 1 2026-07-14T18:32:22 Improper privilege management in Microsoft Install Service allows an authorized
CVE-2026-46300 7.8 7.01% 1 15 2026-07-14T15:33:05 In the Linux kernel, the following vulnerability has been resolved: net: skbuff
CVE-2026-43284 7.8 93.23% 1 43 2026-07-14T15:31:59 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp:
CVE-2026-49413 7.1 0.15% 1 1 2026-07-01T14:04:37.143000 The Linuxulator determined whether a binary was set-user-ID or set-group-ID by c
CVE-2026-10702 4.3 0.72% 1 2 2026-06-30T03:36:54 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CVE-2026-12044 8.8 0.71% 1 0 2026-06-19T00:31:46 SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT O
CVE-2026-12045 9.0 0.48% 1 0 2026-06-19T00:31:46 Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker wh
CVE-2026-42897 8.1 70.31% 3 1 2026-06-17T10:48:34.893000 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-1070 4.3 0.16% 1 2 2026-06-17T10:14:56.770000 The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request F
CVE-2025-8943 9.8 72.31% 1 0 template 2026-06-17T10:07:59.880000 The Custom MCPs feature is designed to execute OS commands, for instance, using
CVE-2023-32233 7.8 12.97% 1 7 2026-06-17T05:58:22.273000 In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when
CVE-2025-66376 7.2 21.97% 1 0 2026-03-18T18:31:10 Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas
CVE-2025-66518 None 0.91% 1 0 2026-01-29T03:42:38 Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols
CVE-2013-4786 7.5 78.57% 2 1 2025-04-11T04:12:49 The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R
CVE-2026-18830 0 0.00% 2 0 N/A
CVE-2026-69098 0 0.00% 2 0 N/A
CVE-2026-17583 0 0.00% 1 1 N/A
CVE-2026-58073 0 0.00% 2 0 N/A
CVE-2026-64633 0 0.00% 2 0 N/A
CVE-2026-59726 0 0.48% 3 1 N/A
CVE-2026-59774 0 0.00% 2 0 N/A
CVE-2026-56671 0 0.66% 1 0 N/A
CVE-2026-56673 0 0.43% 1 0 N/A
CVE-2026-56672 0 0.24% 1 0 N/A
CVE-2026-4941 0 0.00% 1 2 N/A

CVE-2026-69110
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-04T17:16:59.733000

2 posts

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionall

thehackerwire@mastodon.social at 2026-08-04T17:00:25.000Z ##

🔴 CVE-2026-69110 - Critical (9.1)

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-04T17:00:25.000Z ##

🔴 CVE-2026-69110 - Critical (9.1)

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69100
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-04T17:16:59.320000

2 posts

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend

thehackerwire@mastodon.social at 2026-08-04T17:00:15.000Z ##

🟠 CVE-2026-69100 - High (8.8)

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitel...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-04T17:00:15.000Z ##

🟠 CVE-2026-69100 - High (8.8)

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitel...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48323
(10.0 CRITICAL)

EPSS: 0.62%

updated 2026-08-04T17:16:55.413000

2 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

offseq@infosec.exchange at 2026-08-04T04:30:24.000Z ##

Adobe Campaign Classic is impacted by CVE-2026-48323 (CRITICAL, CVSS 10). Improper neutralization in the template engine allows remote code execution — no user interaction needed. No patch yet. Monitor advisories: radar.offseq.com/threat/cve-20 #OffSeq #Adobe #Vuln #CVE202648323

##

thehackerwire@mastodon.social at 2026-08-04T00:00:03.000Z ##

🔴 CVE-2026-48323 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vul...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-25292
(7.6 HIGH)

EPSS: 0.00%

updated 2026-08-04T17:16:53.797000

2 posts

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

thehackerwire@mastodon.social at 2026-08-04T17:01:01.000Z ##

🟠 CVE-2026-25292 - High (7.6)

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-04T17:01:01.000Z ##

🟠 CVE-2026-25292 - High (7.6)

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-24084
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-04T17:16:52.453000

2 posts

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

thehackerwire@mastodon.social at 2026-08-04T17:01:22.000Z ##

🟠 CVE-2026-24084 - High (7.5)

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-04T17:01:22.000Z ##

🟠 CVE-2026-24084 - High (7.5)

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-24083
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-04T17:16:52.040000

2 posts

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

thehackerwire@mastodon.social at 2026-08-04T17:01:12.000Z ##

🟠 CVE-2026-24083 - High (7.8)

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-04T17:01:12.000Z ##

🟠 CVE-2026-24083 - High (7.8)

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-60007
(0 None)

EPSS: 0.00%

updated 2026-08-04T16:16:26.367000

2 posts

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with

offseq at 2026-08-04T13:30:20.073Z ##

Eclipse Milo (0.6.0 – 1.1.4) faces a CRITICAL flaw (CVE-2026-60007): error messages in username-token RSA PKCS#1 v1.5 handling enable padding oracle attacks, risking password compromise. Patch status unclear. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-04T13:30:20.000Z ##

Eclipse Milo (0.6.0 – 1.1.4) faces a CRITICAL flaw (CVE-2026-60007): error messages in username-token RSA PKCS#1 v1.5 handling enable padding oracle attacks, risking password compromise. Patch status unclear. radar.offseq.com/threat/cve-20 #OffSeq #EclipseMilo #Vuln #Infosec

##

CVE-2026-48326
(9.9 CRITICAL)

EPSS: 0.48%

updated 2026-08-04T16:16:25.497000

2 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

hugovalters@mastodon.social at 2026-08-04T17:10:52.000Z ##

CVE-2026-48326 - Critical SQLi in Adobe Campaign Classic. Low-privilege attacker can achieve RCE. CVSS 9.9, unpatched. Mitigate immediately. #CVE #Adobe #infosec

valtersit.com/cve/cve-2026-483

##

thehackerwire@mastodon.social at 2026-08-04T00:00:13.000Z ##

🔴 CVE-2026-48326 - Critical (9.9)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18686
(9.8 CRITICAL)

EPSS: 2.61%

updated 2026-08-04T16:16:21.593000

2 posts

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of

hugovalters@mastodon.social at 2026-08-04T11:07:42.000Z ##

CVE-2026-18686 - Critical command injection in GL.iNet GL-MT3000 via nas-web.add_user. Public exploit, CVSS 9.8, unpatched. Restrict access and monitor now. #CVE #GLiNet #infosec

valtersit.com/cve/cve-2026-186

##

offseq@infosec.exchange at 2026-08-04T01:30:25.000Z ##

CVE-2026-18686: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated code execution possible — no patch yet. Limit admin interface exposure & monitor for abuse. radar.offseq.com/threat/cve-20 #OffSeq #CVE #RouterSecurity

##

CVE-2026-18401(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-08-04T15:32:23

1 posts

The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.

EUVD_Bot@mastodon.social at 2026-08-04T15:01:08.000Z ##

🚨 EUVD-2026-52703

📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: jackson-core, jackson-core, jackson-core (+2 more)
🏢 Vendor: FasterXML
📅 Updated: 2026-08-04

📝 The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.

Th...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-69246
(7.2 HIGH)

EPSS: 0.21%

updated 2026-08-04T15:16:42.927000

1 posts

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same through fopen(). libcurl then parses the authority itself, percent-decoding it and, on an IDN-capable buil

hugovalters@mastodon.social at 2026-08-04T15:11:03.000Z ##

CVE-2026-69246 - Guzzle HTTP client mishandles Host header via libcurl IDNA/decoding, leading to request smuggling/SSRF. CVSS 7.2. No patch yet; upgrade when fixed. #CVE #PHP #infosec

valtersit.com/cve/CVE-2026-692

##

CVE-2026-66315
(7.5 HIGH)

EPSS: 0.62%

updated 2026-08-04T15:16:38.033000

1 posts

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-08-04T01:00:25.000Z ##

🟠 CVE-2026-66315 - High (7.5)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48333
(9.8 CRITICAL)

EPSS: 0.47%

updated 2026-08-04T15:16:35.963000

1 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.

offseq@infosec.exchange at 2026-08-04T06:00:24.000Z ##

CVE-2026-48333 (CRITICAL, CVSS 9.8): Incorrect Authorization in Adobe Campaign Classic enables attackers to escalate privileges without user interaction. No patch info yet — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Adobe #Security #CVE202648333

##

CVE-2026-12816
(0 None)

EPSS: 0.16%

updated 2026-08-04T14:50:12.360000

1 posts

In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-58062
(0 None)

EPSS: 0.20%

updated 2026-08-04T14:50:12.360000

2 posts

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

offseq@infosec.exchange at 2026-08-03T03:00:27.000Z ##

CVE-2026-58062 (CRITICAL, CVSS 9.3): Bouncy Castle Java improperly validates stapled OCSP, risking cert trust. Affects =1.66, <1.85, LTS <2.73.12. Update to 1.85+ or LTS 2.73.12. Details: radar.offseq.com/threat/cve-20 #OffSeq #BouncyCastle #JavaSecurity

##

CVE-2026-8763
(0 None)

EPSS: 0.33%

updated 2026-08-04T14:50:12.360000

2 posts

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

offseq@infosec.exchange at 2026-08-03T06:00:34.000Z ##

CVE-2026-8763: CRITICAL vuln in Bouncy Castle BC-JAVA (<1.85, 2.73.0-2.73.11). Improper cert validation via trailing dot bypasses name constraints — risk of MITM attacks. No patch yet. Monitor vendor for updates. radar.offseq.com/threat/cve-20 #OffSeq #BouncyCastle #Vuln #CVE20268763

##

CVE-2026-59638
(0 None)

EPSS: 0.28%

updated 2026-08-04T14:50:12.360000

1 posts

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).

offseq@infosec.exchange at 2026-08-03T01:30:23.000Z ##

CVE-2026-59638 (CRITICAL, CVSS 9.3) in BC-JAVA: Improper cert validation due to default CN-fallback can expose TLS connections to MITM. Affects <1.85, LTS <2.73.12. Patch status unknown — monitor vendor & consider disabling fallback. radar.offseq.com/threat/cve-20 #OffSeq #CVE202659638 #infosec

##

CVE-2026-48331
(10.0 CRITICAL)

EPSS: 0.47%

updated 2026-08-04T14:48:22.933000

1 posts

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-62354
(0 None)

EPSS: 0.26%

updated 2026-08-04T14:48:22.933000

1 posts

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of

DailyCyberSecurity@infosec.exchange at 2026-08-04T01:52:18.000Z ##

Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.

#ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec

securityonline.info/apache-nif

##

CVE-2026-48330
(10.0 CRITICAL)

EPSS: 0.68%

updated 2026-08-04T14:48:22.933000

1 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the application. Exploitation of this is

thehackerwire@mastodon.social at 2026-08-04T00:00:24.000Z ##

🔴 CVE-2026-48330 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34641
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-04T14:48:22.933000

1 posts

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

thehackerwire@mastodon.social at 2026-08-02T03:59:57.000Z ##

🟠 CVE-2026-34641 - High (7.8)

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6837
(7.2 HIGH)

EPSS: 0.95%

updated 2026-08-04T14:47:47.393000

2 posts

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

hugovalters@mastodon.social at 2026-08-04T14:06:53.000Z ##

CVE-2026-6837 - Post-auth command injection in Zyxel WAX650S export-cgi. Admin RCE. CVSS 7.2. Unpatched - restrict admin access now. #CVE #Zyxel #infosec

valtersit.com/cve/CVE-2026-683

##

hugovalters@mastodon.social at 2026-08-04T14:06:53.000Z ##

CVE-2026-6837 - Post-auth command injection in Zyxel WAX650S export-cgi. Admin RCE. CVSS 7.2. Unpatched - restrict admin access now. #CVE #Zyxel #infosec

valtersit.com/cve/CVE-2026-683

##

CVE-2026-18577
(8.1 HIGH)

EPSS: 2.53%

updated 2026-08-04T14:27:12.530000

15 posts

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

1 repos

https://github.com/HORKimhab/CVE-2026-18577

Matchbook3469@mastodon.social at 2026-08-04T17:50:21.000Z ##

🔵 THREAT INTELLIGENCE

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

Vulnerability | CRITICAL
CVEs: CVE-2026-18577

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises...

Full analysis:
yazoul.net/news/article/cisa-a

by Yazoul AI

#CyberSecurity #APT #IncidentResponse

##

Analyst207@mastodon.social at 2026-08-04T16:34:20.000Z ##

CISA Warns of Active N-able Flaw Exploit in Federal Agencies

Exploiting the N-able flaw can give attackers unrestricted control over your N-central console, putting your entire operation at risk. Federal agencies have just three days to patch this high-severity vulnerability, tracked as CVE-2026-18577, under CISA's Binding Operational Directive 26-04.

osintsights.com/cisa-warns-of-

#Nable #Cve202618577 #Cisa #BindingOperationalDirective2604 #FederalAgencies

##

AAKL at 2026-08-04T15:28:21.220Z ##

New.

Rapid7: CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official

##

AAKL at 2026-08-04T14:33:24.881Z ##

CISA added this vulnerability to the catalogue yesterday, if you missed it:

CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability cve.org/CVERecord?id=CVE-2026-

Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching arcticwolf.com/resources/blog/

##

AAKL@infosec.exchange at 2026-08-04T15:28:21.000Z ##

New.

Rapid7: CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #infosec #vulnerabiity

##

AAKL@infosec.exchange at 2026-08-04T14:33:24.000Z ##

CISA added this vulnerability to the catalogue yesterday, if you missed it:

CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability cve.org/CVERecord?id=CVE-2026-

Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching arcticwolf.com/resources/blog/ #infosec #vulnerability #CISA

##

youranonnewsirc@nerdculture.de at 2026-08-04T04:26:32.000Z ##

Geopolitical: Trump indicates ongoing talks with Iran for Strait of Hormuz reopening (Aug 3-4), though Tehran denies. Gaza operations persist.
Technology: SK hynix & Sandisk unveil HBF standard for AI memory (Aug 4). White House schedules AI safety talks (Aug 4).
Cybersecurity: CISA alerts to active exploitation of N-able N-central flaw (CVE-2026-18577) (Aug 3). Interpol: AI fuels over 55% of African cybercrime (Aug 3).
#AnonNews_irc #Cybersecurity #News

##

thecybermind@infosec.exchange at 2026-08-03T23:17:37.000Z ##

URGENT C-SUITE BRIEF: Active exploitation verified on CISA KEV for CVE-2026-18577 (N-able N-central). Executive leadership must oversee immediate patch deployment, supply chain auditing, and trust model revalidation to safeguard organizational assets. Full strategic analysis: thecybermind.co/0156

#CyberRisk

##

oversecurity@mastodon.social at 2026-08-03T22:39:19.000Z ##

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-...

🔗️ [Bleepingcomputer] link.is.it/tS9UYV

##

oversecurity@mastodon.social at 2026-08-03T22:38:32.000Z ##

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-...

🔗️ [Bleepingcomputer] bleepingcomputer.com/news/secu

##

thecybermind@infosec.exchange at 2026-08-03T22:06:53.000Z ##

ALERT: Active exploitation verified for CVE-2026-18577 in N-able N-central. Unauthenticated attackers can execute account takeovers via alternate path manipulation. Access our complete threat breakdown, SPL/KQL detection logic, and hardening guidance here: thecybermind.co/jily

#CyberSecurity #ThreatIntel

##

secdb@infosec.exchange at 2026-08-03T21:00:14.000Z ##

🚨 [CISA-2026:0803] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-18577 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: documentation.n-able.com/N-cen ; status.n-able.com/2026/08/02/n ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260803 #cisa20260803 #cve_2026_18577 #cve202618577

##

cisakevtracker@mastodon.social at 2026-08-03T19:00:49.000Z ##

CVE ID: CVE-2026-18577
Vendor: N-able
Product: N-central
Date Added: 2026-08-03
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T16:25:47.000Z ##

CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7.

#Nable #Ncentral #CVE202618577 #AccountTakeover #RMM #CyberSecurity

securityonline.info/cve-2026-1

##

harrysintonen@infosec.exchange at 2026-08-03T10:48:19.000Z ##

Some time ago I discovered a meddler in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse:

status.n-able.com/2026/08/02/n

#nablencentral #CVE_2026_18577 #infosec #cybersecurity

##

CVE-2026-18556
(7.4 HIGH)

EPSS: 0.27%

updated 2026-08-04T13:58:04.463000

5 posts

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

cisakevtracker@mastodon.social at 2026-08-04T18:00:52.000Z ##

CVE ID: CVE-2026-18556
Vendor: N-able
Product: N-central
Date Added: 2026-08-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL at 2026-08-04T14:33:24.881Z ##

CISA added this vulnerability to the catalogue yesterday, if you missed it:

CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability cve.org/CVERecord?id=CVE-2026-

Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching arcticwolf.com/resources/blog/

##

cisakevtracker@mastodon.social at 2026-08-04T18:00:52.000Z ##

CVE ID: CVE-2026-18556
Vendor: N-able
Product: N-central
Date Added: 2026-08-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-08-04T14:33:24.000Z ##

CISA added this vulnerability to the catalogue yesterday, if you missed it:

CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability cve.org/CVERecord?id=CVE-2026-

Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching arcticwolf.com/resources/blog/ #infosec #vulnerability #CISA

##

security_crawler_carl@infosec.exchange at 2026-08-02T15:39:21.000Z ##

🏆 New Achievement! Management Remotely Destroyed!

Today's dungeon crawl is brought to you by Deferred Patch Tuesdays — when you're too busy managing clients to manage yourself. N-able N-central, the RMM platform MSPs trust to run everyone else's networks, is harboring CVE-2026-18556, a CVSS 9.8 authentication bypass being actively exploited in the wild. Attackers are waltzing — no, sorry — strolling right through, dropping Cloudflare tunnels for cozy, persistent access. (1/2)

##

CVE-2026-14804
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-08-04T13:17:35.893000

3 posts

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

thehackerwire@mastodon.social at 2026-08-04T13:00:08.000Z ##

🔴 CVE-2026-14804 - Critical (9.1)

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.

This issue affects HUMANIST Digital Human Resources: from ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-04T13:00:08.000Z ##

🔴 CVE-2026-14804 - Critical (9.1)

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.

This issue affects HUMANIST Digital Human Resources: from ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-04T10:30:25.000Z ##

CVE-2026-14804: CRITICAL (CVSS 9.1) in HUMANIST Digital HR v26.0 🛡️ Hard-coded cryptographic key (CWE-321) allows data exposure & integrity loss. No official fix — limit access & track vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #CVE202614804

##

CVE-2026-14175
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-04T12:34:56

4 posts

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

thehackerwire@mastodon.social at 2026-08-04T13:00:33.000Z ##

🔴 CVE-2026-14175 - Critical (9.8)

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.

This issue affects HUMANIST Digital Human Resources: from...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-04T12:00:28.079Z ##

CVE-2026-14175 (CRITICAL, CVSS 9.8): HUMANIST Digital HR v26.0 has an unrestricted file upload flaw — attackers can deploy web shells for full compromise. No patch yet. Restrict uploads, monitor, and apply network controls. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-04T13:00:33.000Z ##

🔴 CVE-2026-14175 - Critical (9.8)

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.

This issue affects HUMANIST Digital Human Resources: from...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-04T12:00:28.000Z ##

CVE-2026-14175 (CRITICAL, CVSS 9.8): HUMANIST Digital HR v26.0 has an unrestricted file upload flaw — attackers can deploy web shells for full compromise. No patch yet. Restrict uploads, monitor, and apply network controls. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #AppSec

##

CVE-2026-15721
(9.8 CRITICAL)

EPSS: 0.23%

updated 2026-08-04T12:34:56

2 posts

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

thehackerwire@mastodon.social at 2026-08-04T13:00:22.000Z ##

🔴 CVE-2026-15721 - Critical (9.8)

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.

This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-04T13:00:22.000Z ##

🔴 CVE-2026-15721 - Critical (9.8)

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.

This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10685
(7.6 HIGH)

EPSS: 0.18%

updated 2026-08-04T12:31:51.160000

1 posts

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0). Per the public GATT API, a notify callback with NULL data is the documented signal that the subscription has terminated and the bt_gatt_subscribe_params struct may

thehackerwire@mastodon.social at 2026-08-02T08:59:50.000Z ##

🟠 CVE-2026-10685 - High (7.6)

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0).

Per the pub...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17349
(9.6 CRITICAL)

EPSS: 0.30%

updated 2026-08-04T12:31:51.160000

1 posts

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the stored credential fields password, save_password, and tunnel_password. When a non-owner triggered an adhoc connect against

thehackerwire@mastodon.social at 2026-08-02T07:59:54.000Z ##

🔴 CVE-2026-17349 - Critical (9.6)

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, sh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18754
(9.1 CRITICAL)

EPSS: 0.31%

updated 2026-08-04T09:31:41

1 posts

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.

offseq@infosec.exchange at 2026-08-04T09:00:29.000Z ##

CVE-2026-18754: GeoVision GV-AS1620 (GV-Cloud) v1.16 has a CRITICAL bug — static RSA key in firmware lets attackers decrypt HTTPS & spoof server. No fix yet; restrict access & watch for vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Cybersecurity #TLS

##

CVE-2026-15958(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-08-04T09:31:41

1 posts

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.

offseq@infosec.exchange at 2026-08-04T07:30:25.000Z ##

CVE-2026-15958 (CRITICAL): Easy Integration for Dropbox <2.2.0 suffers from missing authorization, letting unauthenticated users manage Dropbox files and access account emails. Patch or disable plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #Security

##

CVE-2026-66066
(0 None)

EPSS: 1.70%

updated 2026-08-04T05:16:40.060000

3 posts

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated a

7 repos

https://github.com/0xBlackash/CVE-2026-66066

https://github.com/HackSpeak/CVE-2026-66066

https://github.com/0xsha/KindaRails2Shell

https://github.com/paveg/rails-activestorage-vips-audit

https://github.com/shinthink/CVE-2026-66066

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

https://github.com/rails/rails-forensics-CVE-2026-66066

DailyCyberSecurity@infosec.exchange at 2026-08-04T07:28:39.000Z ##

A critical KindaRails2Shell Rails RCE flaw (CVE-2026-66066) in Active Storage exposes servers to secret theft and remote code execution via image uploads.

#RubyOnRails #KindaRails2Shell #CVE202666066 #Cybersecurity #WebSecurity

meterpreter.org/kindarails2she

##

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

kuketzblog@social.tchncs.de at 2026-08-02T19:45:34.000Z ##

Ruby on Rails warnt vor CVE-2026-66066 in Active Storage. Angreifer können über präparierte Bild-Uploads Dateien des Servers auslesen und so an Schlüssel oder Zugangsdaten gelangen. Betroffen sind Anwendungen mit libvips. Updates und forensische Prüfwerkzeuge stehen bereit.

discuss.rubyonrails.org/t/cve-

1/2

#RubyOnRails #Sicherheitslücke #Websecurity #KuketzAugust

##

CVE-2026-68981(CVSS UNKNOWN)

EPSS: 0.32%

updated 2026-08-04T00:35:57

1 posts

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommend

DailyCyberSecurity@infosec.exchange at 2026-08-04T01:52:18.000Z ##

Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.

#ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec

securityonline.info/apache-nif

##

CVE-2026-68979(CVSS UNKNOWN)

EPSS: 0.35%

updated 2026-08-04T00:35:57

1 posts

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing auth

DailyCyberSecurity@infosec.exchange at 2026-08-04T01:52:18.000Z ##

Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.

#ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec

securityonline.info/apache-nif

##

CVE-2026-18684
(9.8 CRITICAL)

EPSS: 2.03%

updated 2026-08-04T00:35:01

1 posts

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confir

offseq@infosec.exchange at 2026-08-04T03:00:29.000Z ##

CVE-2026-18684 | CRITICAL command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5) 🛡️ Remote attackers can execute commands — no patch yet. Restrict access and watch for vendor updates. Info: radar.offseq.com/threat/cve-20 #OffSeq #CVE202618684 #IoTSecurity

##

CVE-2026-66310
(7.7 HIGH)

EPSS: 0.40%

updated 2026-08-04T00:35:01

1 posts

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

thehackerwire@mastodon.social at 2026-08-04T01:00:15.000Z ##

🟠 CVE-2026-66310 - High (7.7)

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66318
(8.1 HIGH)

EPSS: 0.37%

updated 2026-08-04T00:35:01

1 posts

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

thehackerwire@mastodon.social at 2026-08-04T01:00:05.000Z ##

🟠 CVE-2026-66318 - High (8.1)

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18685
(9.8 CRITICAL)

EPSS: 1.99%

updated 2026-08-04T00:35:01

1 posts

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of t

offseq@infosec.exchange at 2026-08-04T00:00:36.000Z ##

CVE-2026-18685: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated RCE possible. No patch yet — restrict access & monitor for abuse. Details: radar.offseq.com/threat/cve-20 #OffSeq #vuln #IoT #infosec

##

CVE-2026-66803
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-08-04T00:17:39.977000

1 posts

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-08-02T22:59:51.000Z ##

🔴 CVE-2026-66803 - Critical (10)

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59913
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-03T21:31:44

1 posts

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-08-03T20:00:25.000Z ##

🟠 CVE-2026-59913 - High (7.8)

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59912
(7.8 HIGH)

EPSS: 0.10%

updated 2026-08-03T21:31:36

1 posts

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-03T20:00:11.000Z ##

🟠 CVE-2026-59912 - High (7.8)

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18108
(9.8 CRITICAL)

EPSS: 0.22%

updated 2026-08-03T21:31:35

1 posts

Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. _verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via "return $xml unless $xpath->exists('dsig:Signature', $assert);". The signature check and the trus

hugovalters@mastodon.social at 2026-08-03T23:11:09.000Z ##

CVE-2026-18108 - Critical auth bypass in Perl Net::SAML2. Encrypted assertions without signatures accepted. CVSS 9.8. Upgrade to >=0.86 now. #CVE #Perl #infosec

valtersit.com/cve/cve-2026-181

##

CVE-2026-67288
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-03T21:31:31

1 posts

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process

thehackerwire@mastodon.social at 2026-08-02T02:59:50.000Z ##

🟠 CVE-2026-67288 - High (7.5)

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69240
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-08-03T20:29:52

1 posts

### Summary SQL Injection is possible with strings only **if dialect is set to `oracle`**. The vulnerability was confirmed on Sequelize v6.37.3. ### Details The `escape` function defined in `sql-string.js` does not escape quotes if the value starts with `TO_TIMESTAMP` or `TO_DATE`. ```javascript } else if (dialect === 'oracle' && typeof val === 'string') { if (val.startsWith('TO_TIMESTAMP'

thehackerwire@mastodon.social at 2026-08-03T22:00:08.000Z ##

🔴 CVE-2026-69240 - Critical (9.8)

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67357
(7.5 HIGH)

EPSS: 0.25%

updated 2026-08-03T20:17:27.833000

1 posts

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.

thehackerwire@mastodon.social at 2026-08-02T14:00:37.000Z ##

🟠 CVE-2026-67357 - High (7.5)

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-Ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67298
(7.5 HIGH)

EPSS: 0.38%

updated 2026-08-03T20:17:26.477000

1 posts

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_LENGTH from the peer-controlled orderLength field without first verifying orderLength is at least the header length. For orderLength values 0..3 this caus

thehackerwire@mastodon.social at 2026-08-01T23:00:01.000Z ##

🟠 CVE-2026-67298 - High (7.5)

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_L...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8457
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-03T19:16:53.733000

2 posts

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or validating the issuer, audience, or expiry claims, combined with the security nonce r

offseq@infosec.exchange at 2026-08-02T01:30:26.000Z ##

CVE-2026-8457: WPWeb WooCommerce - Social Login (<=2.8.7) suffers CRITICAL auth bypass. Forged Apple id_tokens + exposed nonce = attacker can access any WordPress user, even admins. Disable Apple login or plugin ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

thehackerwire@mastodon.social at 2026-08-02T01:00:03.000Z ##

🔴 CVE-2026-8457 - Critical (9.8)

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67294
(5.9 MEDIUM)

EPSS: 0.27%

updated 2026-08-03T19:16:50.143000

1 posts

FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fails, the code falls back to client-purpose and any-purpose verification, so a trusted, hostname-matching certificate valid only for clientAuth can be accepted as the

offseq@infosec.exchange at 2026-08-02T12:00:23.000Z ##

CVE-2026-67294 | FreeRDP <3.29.0: Improper EKU validation lets trusted clientAuth certs be accepted as server certs in TLS, enabling RDP server impersonation. Severity: CRITICAL. Patch pending. radar.offseq.com/threat/freerd #OffSeq #FreeRDP #TLS #infosec

##

CVE-2026-67289
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-08-03T19:16:50

2 posts

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or

offseq@infosec.exchange at 2026-08-02T07:30:23.000Z ##

CVE-2026-67289: FreeRDP ≤3.28.0 has a CRITICAL flaw (CVSS 9.8) in RDP redirection — improper CRLF/control character validation exposes clients to HTTP header injection via proxies. Upgrade to 3.29.0+ now. radar.offseq.com/threat/freerd #OffSeq #FreeRDP #CVE202667289 #infosec

##

thehackerwire@mastodon.social at 2026-08-02T02:59:59.000Z ##

🔴 CVE-2026-67289 - Critical (9.8)

FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client&#039;s ServerHostname and, when the client c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66402
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-08-03T19:16:49.210000

2 posts

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity validation APIs, it (1) truncates DNS SAN values at embedded NUL bytes (accepti

offseq@infosec.exchange at 2026-08-02T09:00:24.000Z ##

CVE-2026-66402: FreeRDP <=3.28.0 suffers CRITICAL TLS cert validation flaws. Attackers can bypass server identity checks — risk of MITM & impersonation. Patch to 3.29.0 ASAP. 🔒 radar.offseq.com/threat/freerd #OffSeq #Vulnerability #TLS #FreeRDP

##

thehackerwire@mastodon.social at 2026-08-02T02:00:39.000Z ##

🔴 CVE-2026-66402 - Critical (9.8)

FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48449
(10.0 CRITICAL)

EPSS: 0.54%

updated 2026-08-03T19:16:47.320000

1 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

DailyCyberSecurity@infosec.exchange at 2026-08-03T15:02:08.000Z ##

Adobe fixes a CVSS 10 RCE in Campaign Classic (CVE-2026-48449) and eight critical flaws in Bridge. Update to build 9398 and Bridge 15.1.7 or 16.0.6 now.

#AdobeCampaign #CVE202648449 #AdobeBridge #CriticalPatch #RCE

securityexpress.info/adobe-cam

##

CVE-2026-18614
(9.8 CRITICAL)

EPSS: 2.01%

updated 2026-08-03T19:16:45.200000

1 posts

A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and conf

thehackerwire@mastodon.social at 2026-08-03T20:00:35.000Z ##

🔴 CVE-2026-18614 - Critical (9.8)

A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16300
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-08-03T18:31:51

1 posts

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

offseq@infosec.exchange at 2026-08-03T09:00:24.000Z ##

CVE-2026-16300: ChamaWP (<1.0.13) is vulnerable to missing authorization — attackers can reset any user’s password, including admins. Risk: full site takeover. Patch status unconfirmed; restrict password resets & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-18612
(9.8 CRITICAL)

EPSS: 2.16%

updated 2026-08-03T18:30:56

1 posts

A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so Native Plugin. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure and co

hugovalters@mastodon.social at 2026-08-04T12:16:18.000Z ##

CVE-2026-18612 - Critical command injection in GL.iNet GL-MT3000 (<=4.4.5). Remote exploit public, unpatched. CVSS 9.8. Disable remote management immediately. #CVE #GLiNet #infosec

valtersit.com/cve/cve-2026-186

##

CVE-2026-67296
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-03T18:16:40.860000

1 posts

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.

thehackerwire@mastodon.social at 2026-08-02T02:00:20.000Z ##

🟠 CVE-2026-67296 - High (7.5)

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18574
(0 None)

EPSS: 0.99%

updated 2026-08-03T17:40:27.300000

2 posts

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered

DailyCyberSecurity@infosec.exchange at 2026-08-03T16:16:01.000Z ##

CVE-2026-18574 is a Check Point authentication bypass rated CVSS 9.3, letting attackers run commands as admin. Patch via the latest Jumbo Hotfix.

#CheckPoint #CVE202618574 #AuthenticationBypass #SecurityManagement #CyberSecurity #Firewall

securityonline.info/cve-2026-1

##

offseq@infosec.exchange at 2026-08-03T13:30:28.000Z ##

CRITICAL auth bypass (CVE-2026-18574, CVSS 9.3) affects Check Point Security Management Server & MDS. Remote attackers can execute commands w/o auth. No patch yet — restrict management access. radar.offseq.com/threat/cve-20 #OffSeq #CVE202618574 #CheckPoint #Infosec 🔒

##

CVE-2026-68579
(9.6 CRITICAL)

EPSS: 0.27%

updated 2026-08-03T17:16:44.330000

1 posts

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStream_Read requests file contents from the RDP server and then copies the response into the caller's buffer using the serv

thehackerwire@mastodon.social at 2026-08-02T14:01:21.000Z ##

🔴 CVE-2026-68579 - Critical (9.6)

FreeRDP before 3.30.0 (&lt;= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client&#039;s CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67356
(8.8 HIGH)

EPSS: 0.25%

updated 2026-08-03T17:16:43.343000

1 posts

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.

thehackerwire@mastodon.social at 2026-08-02T14:00:26.000Z ##

🟠 CVE-2026-67356 - High (8.8)

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can creat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67305
(0 None)

EPSS: 0.49%

updated 2026-08-03T17:16:40.637000

1 posts

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP server can send a response with a data payload significantly larger than requested, causing arbitrary heap memory corruption that may enable

offseq@infosec.exchange at 2026-08-02T06:00:25.000Z ##

FreeRDP Windows client <3.29.0 has a CRITICAL heap buffer overflow in clipboard virtual channel (CVE-2026-67305). Malicious RDP servers can trigger remote code execution. Upgrade to 3.29.0+ ASAP. radar.offseq.com/threat/freerd #OffSeq #FreeRDP #CVE202667305 #infosec

##

CVE-2026-67300
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-03T17:16:40.480000

1 posts

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends crafted update orders, the message proxy shallow-copies structures containing nested parser-owned pointers (e.g., titleInfo.string, windowRects, visibili

thehackerwire@mastodon.social at 2026-08-01T23:00:21.000Z ##

🟠 CVE-2026-67300 - High (7.5)

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67290
(7.5 HIGH)

EPSS: 0.43%

updated 2026-08-03T17:16:40.020000

1 posts

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.

thehackerwire@mastodon.social at 2026-08-02T03:00:09.000Z ##

🟠 CVE-2026-67290 - High (7.5)

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65321
(9.8 CRITICAL)

EPSS: 0.44%

updated 2026-08-03T17:16:39.617000

2 posts

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape char

1 repos

https://github.com/rahulreddykarne/CVE-2026-65321-pyathena

offseq@infosec.exchange at 2026-08-03T00:00:37.000Z ##

CRITICAL: PyAthena <3.35.4 is vulnerable to SQL injection (CVE-2026-65321). Improper escaping allows unauthenticated attackers to inject SQL, risking data loss/exfiltration. Patch status unconfirmed — restrict DELETE/CTAS use. radar.offseq.com/threat/cve-20 #OffSeq #CVE202665321 #PyAthena

##

thehackerwire@mastodon.social at 2026-08-02T16:00:01.000Z ##

🔴 CVE-2026-65321 - Critical (9.8)

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-71399
(8.6 HIGH)

EPSS: 0.31%

updated 2026-08-03T17:16:28.867000

1 posts

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extr

thehackerwire@mastodon.social at 2026-08-02T15:00:06.000Z ##

🟠 CVE-2025-71399 - High (8.6)

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67336
(8.7 HIGH)

EPSS: 0.16%

updated 2026-08-03T16:16:30.790000

1 posts

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of the required S256 method.

offseq@infosec.exchange at 2026-08-02T00:00:36.000Z ##

CVE-2026-67336: better-auth <1.6.11 uses insecure crypto defaults in oidcProvider & mcp, advertising 'none' algo & accepting plain PKCE. Exploitation can lead to unsigned tokens & code interception. Severity: CRITICAL. Patch to 1.6.11+ radar.offseq.com/threat/better #OffSeq #CVE202667336 #OAuth #Security

##

CVE-2026-3245
(7.5 HIGH)

EPSS: 0.24%

updated 2026-08-03T16:16:29.437000

1 posts

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-03T00:59:47.000Z ##

🟠 CVE-2026-3245 - High (7.5)

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-33591(CVSS UNKNOWN)

EPSS: 0.52%

updated 2026-08-03T12:32:43

2 posts

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

benzogaga33@mamot.fr at 2026-08-04T09:40:04.000Z ##

WAPT Server (CVE-2026-33591) : une faille permet de contourner l’authentification it-connect.fr/wapt-server-cve- #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

offseq@infosec.exchange at 2026-08-03T12:00:25.000Z ##

Tranquil IT WAPT Server 2.6.0.16767 hit by CVE-2026-33591 (CRITICAL, CVSS 10). Remote attackers can bypass authentication & grab session tokens via crafted packets. No patch yet — restrict access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #CVE202633591 #Infosec #Vulnerability

##

CVE-2026-18589
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-08-03T09:32:46

1 posts

A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very prof

offseq@infosec.exchange at 2026-08-03T07:30:28.000Z ##

CVE-2026-18589 (CRITICAL, CVSS 9.3) in Wavlink WL-NU516U1: Stack buffer overflow in nas.cgi enables unauthenticated RCE/DoS. Patch available — update ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202618589 #IoTSecurity #PatchManagement

##

CVE-2026-9593
(6.7 MEDIUM)

EPSS: 0.11%

updated 2026-08-03T09:32:46

1 posts

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.

certvde@infosec.exchange at 2026-08-03T06:30:53.000Z ##

#OT #Advisory VDE-2026-065
Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.
#CVE CVE-2026-9593

certvde.com/en/advisories/vde-

#CSAF endress-hauser.csaf-tp.certvde

##

CVE-2026-58061(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-08-03T09:32:36

1 posts

In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-12803(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-08-03T09:32:36

1 posts

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-59639(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-08-03T06:32:44

1 posts

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-59650(CVSS UNKNOWN)

EPSS: 0.26%

updated 2026-08-03T06:32:44

1 posts

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

offseq@infosec.exchange at 2026-08-03T04:30:26.000Z ##

BC-JAVA users: CVE-2026-59650 (CRITICAL, CVSS 9.3) exposes MTI/A0 Diffie-Hellman via improper input validation. Affects <1.85, 2.73.0 – 2.73.11. No patch yet — avoid affected versions & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Java #Cryptography

##

CVE-2026-68580
(7.5 HIGH)

EPSS: 0.24%

updated 2026-08-02T15:30:26

1 posts

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all pl

thehackerwire@mastodon.social at 2026-08-02T14:01:32.000Z ##

🟠 CVE-2026-68580 - High (7.5)

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can su...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68578
(7.5 HIGH)

EPSS: 0.21%

updated 2026-08-02T15:30:25

1 posts

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.

thehackerwire@mastodon.social at 2026-08-02T14:01:12.000Z ##

🟠 CVE-2026-68578 - High (7.5)

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema muta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68581
(8.1 HIGH)

EPSS: 0.32%

updated 2026-08-02T15:30:25

1 posts

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a target user's ID is treated as that user by the /api/v1/tokens endpoints. An authenticated attacker can obtain a target's num

thehackerwire@mastodon.social at 2026-08-02T14:00:17.000Z ##

🟠 CVE-2026-68581 - High (8.1)

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JW...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68582
(6.5 MEDIUM)

EPSS: 0.21%

updated 2026-08-02T15:30:25

1 posts

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view from the URL path without verifying the caller is authorized for it. For a link-share token holder, the task scope is pinned to the share's own project, but the vie

offseq@infosec.exchange at 2026-08-02T13:30:24.000Z ##

CVE-2026-68582 (CRITICAL): go-vikunja vikunja ≤2.3.0 allows attackers with a share link to read kanban bucket titles & user info from other tenants due to broken object auth at /projects/{project}/views/{view}/tasks. Update to 2.4.0+! radar.offseq.com/threat/cve-20 #OffSeq #CVE202668582 #Vulnerability

##

CVE-2026-18352
(7.5 HIGH)

EPSS: 0.68%

updated 2026-08-02T00:31:17

1 posts

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. This is possible because when attachment_url_to_postid() returns 0 for a traversal

thehackerwire@mastodon.social at 2026-08-02T01:00:23.000Z ##

🟠 CVE-2026-18352 - High (7.5)

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13339
(7.5 HIGH)

EPSS: 0.64%

updated 2026-08-02T00:31:16

1 posts

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. This is exploitable by unauthenticated attackers because the required nonce is publi

thehackerwire@mastodon.social at 2026-08-02T01:00:13.000Z ##

🟠 CVE-2026-13339 - High (7.5)

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67292
(6.5 MEDIUM)

EPSS: 0.26%

updated 2026-08-01T15:30:36

1 posts

FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to the actual received Ping payload, so a malicious gateway/WebSocket peer sending a non-empty Ping control frame causes the client to reply with an overlong Pong t

offseq@infosec.exchange at 2026-08-02T10:30:23.000Z ##

FreeRDP <3.29.0 has a CRITICAL buffer over-disclosure (CVE-2026-67292). Malicious WebSocket peers can leak memory or crash clients via crafted Ping frames. No patch confirmed — avoid unknown gateways. Details: radar.offseq.com/threat/freerd #OffSeq #FreeRDP #CVE202667292 #AppSec

##

CVE-2026-67291
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-01T15:30:36

1 posts

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes.

thehackerwire@mastodon.social at 2026-08-02T00:00:28.000Z ##

🟠 CVE-2026-67291 - High (7.5)

FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67304
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-01T15:30:36

1 posts

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process via null pointer access in free_reader_states functions.

thehackerwire@mastodon.social at 2026-08-02T00:00:17.000Z ##

🟠 CVE-2026-67304 - High (7.5)

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67301
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-01T15:30:36

1 posts

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points /

thehackerwire@mastodon.social at 2026-08-02T00:00:06.000Z ##

🟠 CVE-2026-67301 - High (7.5)

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67299
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-01T15:30:36

1 posts

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order()

thehackerwire@mastodon.social at 2026-08-01T23:00:11.000Z ##

🟠 CVE-2026-67299 - High (7.5)

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67308
(10.0 CRITICAL)

EPSS: 0.45%

updated 2026-08-01T15:30:36

1 posts

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are directly interpolated into run steps, enabling command execution and exfiltration of secrets including GITHUB_TOKEN and

thehackerwire@mastodon.social at 2026-08-01T21:00:33.000Z ##

🔴 CVE-2026-67308 - Critical (10)

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters int...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67341
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-08-01T15:30:30

1 posts

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.

offseq@infosec.exchange at 2026-08-02T04:30:24.000Z ##

ArcadeDB (<26.7.2) hit by CRITICAL vuln (CVE-2026-67341, CVSS 9.3). Improper auth lets users with DB access execute arbitrary JS via DEFINE FUNCTION, bypassing admin-only restrictions. Restrict access, monitor usage, check for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec

##

CVE-2026-67342
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-08-01T15:30:30

1 posts

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by directly calling affected endpoints with arbitrary database parameters.

offseq@infosec.exchange at 2026-08-02T03:00:24.000Z ##

ArcadeDB <26.7.2 hit by CRITICAL CVE-2026-67342: Auth bypass via unvalidated HTTP endpoints (time series, batch, Prometheus, Grafana). Attackers can access & modify DBs. Restrict endpoints, monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #ArcadeDB #Vuln #Infosec

##

CVE-2026-67297
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-01T15:30:26

1 posts

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.

thehackerwire@mastodon.social at 2026-08-02T02:00:29.000Z ##

🟠 CVE-2026-67297 - High (7.5)

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15414
(8.8 HIGH)

EPSS: 0.34%

updated 2026-08-01T03:31:19

1 posts

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only validations applied, `sanitize_key()` and `wp_roles()->is_role()`, both accept `'ad

thehackerwire@mastodon.social at 2026-08-02T03:59:48.000Z ##

🟠 CVE-2026-15414 - High (8.8)

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63223
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-08-01T00:17:17.750000

1 posts

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-enabled directory. Applications are impacted when they validate uploads u

2 repos

https://github.com/imbas007/CVE-2026-63223-POC

https://github.com/shinthink/CVE-2026-63223

thehackerwire@mastodon.social at 2026-08-02T17:59:58.000Z ##

🔴 CVE-2026-63223 - Critical (9.8)

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an applicat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53504
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-01T00:17:16.823000

1 posts

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This issue is fixed in 7.8.0.

thehackerwire@mastodon.social at 2026-08-02T05:00:05.000Z ##

🟠 CVE-2026-53504 - High (7.5)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66418
(9.3 CRITICAL)

EPSS: 0.34%

updated 2026-07-31T23:17:26.170000

1 posts

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive C

1 repos

https://github.com/theopaid/CVE-2026-66418-OpenClaw-Dashboard-v3.0.0-Stored-XSS-via-Failed-Login-Username-Field

thehackerwire@mastodon.social at 2026-08-02T22:00:37.000Z ##

🔴 CVE-2026-66418 - Critical (9.3)

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is reco...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43832
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-31T21:32:56

1 posts

Successful exploitation of the vulnerability could allow an unauthenticated attacker to exploit a stack-based buffer overflow in the Cookie parsing methods to conduct code execution when the SafeEnhancement feature is enabled.

thehackerwire@mastodon.social at 2026-08-02T20:00:09.000Z ##

🟠 CVE-2026-43832 - High (7.5)

Full details and mitigation steps are currently restricted and will be published at a later date.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69933
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T21:32:55

1 posts

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

thehackerwire@mastodon.social at 2026-08-02T23:59:52.000Z ##

🔴 CVE-2025-69933 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43829
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-31T21:32:55

1 posts

Successful exploitation of the vulnerability could allow an unauthenticated attacker to exploit a stack-based buffer overflow in the password functionality to conduct code execution when the SafeEnhancement feature is enabled.

thehackerwire@mastodon.social at 2026-08-02T21:00:11.000Z ##

🟠 CVE-2026-43829 - High (7.5)

Full details and mitigation steps are currently restricted and will be published at a later date.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43831
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-31T21:32:55

1 posts

Successful exploitation of the vulnerability could allow an unauthenticated attacker to exploit a stack-based buffer overflow in the log message functionality to conduct code execution.

thehackerwire@mastodon.social at 2026-08-02T21:00:00.000Z ##

🟠 CVE-2026-43831 - High (7.5)

Full details and mitigation steps are currently restricted and will be published at a later date.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15048
(7.5 HIGH)

EPSS: 0.26%

updated 2026-07-31T21:32:55

1 posts

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.

thehackerwire@mastodon.social at 2026-08-02T13:00:52.000Z ##

🟠 CVE-2026-15048 - High (7.5)

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67822
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-07-31T21:31:55

1 posts

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.

thehackerwire@mastodon.social at 2026-08-02T06:59:50.000Z ##

🔴 CVE-2026-67822 - Critical (9.8)

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without leng...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14930
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-31T21:31:54

1 posts

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.

thehackerwire@mastodon.social at 2026-08-02T13:00:42.000Z ##

🟠 CVE-2026-14930 - High (7.5)

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53501
(8.2 HIGH)

EPSS: 0.21%

updated 2026-07-31T20:16:51.280000

1 posts

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() removes all occurrences of the substring, an attacker can insert the same signature multiple times in the URL and manipulate the final URL used for validation. Thi

thehackerwire@mastodon.social at 2026-08-02T04:00:08.000Z ##

🟠 CVE-2026-53501 - High (8.2)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() remove...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43830
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-07-31T20:16:50.463000

1 posts

Full details and mitigation steps are currently restricted and will be published at a later date.

thehackerwire@mastodon.social at 2026-08-02T20:59:50.000Z ##

🔴 CVE-2026-43830 - Critical (9.8)

Full details and mitigation steps are currently restricted and will be published at a later date.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15258
(8.1 HIGH)

EPSS: 0.22%

updated 2026-07-31T20:16:48.207000

1 posts

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-08-02T12:00:07.000Z ##

🟠 CVE-2026-15258 - High (8.1)

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL inje...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14483
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-07-31T20:16:46.443000

1 posts

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by static, plugin-seeded API credentials that are identical across all installation

2 repos

https://github.com/0xdak/CVE-2026-14483_exploit

https://github.com/MadExploits/CVE-2026-14483

thehackerwire@mastodon.social at 2026-08-02T17:00:12.000Z ##

🔴 CVE-2026-14483 - Critical (9.8)

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14319
(7.5 HIGH)

EPSS: 0.32%

updated 2026-07-31T20:16:46.290000

1 posts

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details.

thehackerwire@mastodon.social at 2026-08-02T16:00:39.000Z ##

🟠 CVE-2026-14319 - High (7.5)

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their n...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56670
(8.2 HIGH)

EPSS: 0.22%

updated 2026-07-31T19:17:11.290000

1 posts

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored cross-site scripting in the ComfyUI origin. This issue is fixed in version 0.28.0.

thehackerwire@mastodon.social at 2026-08-02T19:59:58.000Z ##

🟠 CVE-2026-56670 - High (8.2)

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54725
(9.6 CRITICAL)

EPSS: 0.32%

updated 2026-07-31T19:17:10.833000

1 posts

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JW

thehackerwire@mastodon.social at 2026-08-02T05:00:14.000Z ##

🔴 CVE-2026-54725 - Critical (9.6)

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52856
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-31T19:17:09.120000

1 posts

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

thehackerwire@mastodon.social at 2026-08-02T07:00:09.000Z ##

🟠 CVE-2026-52856 - High (7.5)

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69936
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T19:17:03.667000

1 posts

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

thehackerwire@mastodon.social at 2026-08-03T01:00:09.000Z ##

🔴 CVE-2025-69936 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69935
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T19:17:03.420000

1 posts

CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

thehackerwire@mastodon.social at 2026-08-03T00:00:13.000Z ##

🔴 CVE-2025-69935 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69934
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T19:17:03.113000

1 posts

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

thehackerwire@mastodon.social at 2026-08-03T00:00:02.000Z ##

🔴 CVE-2025-69934 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53503
(7.5 HIGH)

EPSS: 0.42%

updated 2026-07-31T18:54:57

1 posts

### Summary Thumbor's `filters:convolution(<matrix>, <columns>, <should_normalize>)` filter passes the user-controlled `<columns>` value to a C extension (`thumbor/ext/filters/_convolution.c`) where it is used as a divisor (for `%` and `/`) without validating `columns > 0`. When `columns=0`, the C code triggers undefined behavior; on x86_64 this reliably results in a fatal divide-by-zero trap (SIG

thehackerwire@mastodon.social at 2026-08-02T04:59:54.000Z ##

🟠 CVE-2026-53503 - High (7.5)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(, , ) filter passes the user-controlled value to a C extension (thumbor/ext/filters/_convolution.c) where it is used as a divisor (for %...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62391
(8.1 HIGH)

EPSS: 0.40%

updated 2026-07-31T18:33:21

1 posts

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which fixes the issue.

thehackerwire@mastodon.social at 2026-08-02T11:00:04.000Z ##

🟠 CVE-2026-62391 - High (8.1)

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.

This issue ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69937
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T18:33:16

1 posts

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.

thehackerwire@mastodon.social at 2026-08-03T01:00:19.000Z ##

🔴 CVE-2025-69937 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58048(CVSS UNKNOWN)

EPSS: 0.50%

updated 2026-07-31T18:32:25

2 posts

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

1 repos

https://github.com/imbas007/POC-CVE-2026-58048

Analyst207@mastodon.social at 2026-08-04T11:34:23.000Z ##

cPanel Flaw Exposes Database Vulnerability to Authenticated Users

A critical cPanel flaw, CVE-2026-58048, with a near-perfect CVSS score of 9.4, allows authenticated users to execute SQL commands with root-level access, putting databases at risk. This vulnerability lets users with basic cPanel access escalate privileges and take control of the server's administrative database.

osintsights.com/cpanel-flaw-ex

#Cpanel #Cve202658048 #SqlInjection #PrivilegeEscalation #WebHosting

##

DailyCyberSecurity@infosec.exchange at 2026-08-04T01:02:52.000Z ##

CVE-2026-58048: cPanel Root SQL Execution Flaw Patched

securityonline.info/cve-2026-5

##

CVE-2026-17346
(8.8 HIGH)

EPSS: 0.43%

updated 2026-07-31T18:32:24

1 posts

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema, table, publication, and subscription names sourced from pg_catalog via the browser tree could never contain an apostrophe. Po

thehackerwire@mastodon.social at 2026-08-02T08:00:13.000Z ##

🟠 CVE-2026-17346 - High (8.8)

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17351
(9.0 None)

EPSS: 0.45%

updated 2026-07-31T18:32:24

1 posts

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with PostgreSQL's own parser: under standard_conforming_strings = on (PostgreSQL's defau

1 repos

https://github.com/Hunt-Benito/pgadmin-ai-assistant-sql-injection-cve-2026-17351-lexer-differential-bypass

thehackerwire@mastodon.social at 2026-08-02T08:00:03.000Z ##

🔴 CVE-2026-17351 - Critical (9)

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-35847
(9.8 CRITICAL)

EPSS: 0.37%

updated 2026-07-31T18:17:14.613000

1 posts

An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

thehackerwire@mastodon.social at 2026-08-02T23:00:11.000Z ##

🔴 CVE-2026-35847 - Critical (9.8)

An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18446
(7.5 HIGH)

EPSS: 0.22%

updated 2026-07-31T18:17:13.383000

1 posts

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authority and folds into the path. Node's native WHATWG URL parser instead treats a backslash as interchangeable with a forward

thehackerwire@mastodon.social at 2026-08-02T10:59:54.000Z ##

🟠 CVE-2026-18446 - High (7.5)

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12720
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-31T18:17:10.337000

1 posts

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress v

1 repos

https://github.com/webshellseo8/CVE-2026-12720-Proof-of-Concept

thehackerwire@mastodon.social at 2026-08-02T17:59:49.000Z ##

🟠 CVE-2026-12720 - High (7.5)

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12695
(8.1 HIGH)

EPSS: 0.29%

updated 2026-07-31T18:17:10.150000

1 posts

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.

thehackerwire@mastodon.social at 2026-08-02T17:00:32.000Z ##

🟠 CVE-2026-12695 - High (8.1)

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12251
(8.1 HIGH)

EPSS: 0.23%

updated 2026-07-31T18:17:09.777000

1 posts

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing unauthenticated users to register with a site-defined role that carries administrator capabilities and gain administrative access, when such a

thehackerwire@mastodon.social at 2026-08-02T17:00:22.000Z ##

🟠 CVE-2026-12251 - High (8.1)

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14919
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-07-31T17:16:32.863000

1 posts

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.

thehackerwire@mastodon.social at 2026-08-02T15:00:43.000Z ##

🔴 CVE-2026-14919 - Critical (9.8)

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to red...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13609
(8.8 HIGH)

EPSS: 0.25%

updated 2026-07-31T17:16:32.347000

1 posts

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output without escaping on the Frontend Admin by DynamiApps WordPress plugin before 3.29.9'

thehackerwire@mastodon.social at 2026-08-02T16:00:29.000Z ##

🟠 CVE-2026-13609 - High (8.8)

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12721
(8.6 HIGH)

EPSS: 0.26%

updated 2026-07-31T17:16:31.993000

1 posts

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-08-02T15:00:53.000Z ##

🟠 CVE-2026-12721 - High (8.6)

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63362
(5.9 MEDIUM)

EPSS: 1.53%

updated 2026-07-31T16:17:09.013000

1 posts

An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet.

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-63222
(7.5 HIGH)

EPSS: 0.45%

updated 2026-07-31T16:17:08.903000

1 posts

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploaded content outside the intended directory when the application exposes an upload path. This issue is fixed in version 4.7.4.

thehackerwire@mastodon.social at 2026-08-02T18:59:49.000Z ##

🟠 CVE-2026-63222 - High (7.5)

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52855
(9.9 CRITICAL)

EPSS: 0.27%

updated 2026-07-31T16:16:48

1 posts

### Impact **Type:** Exposure of sensitive information / insufficiently protected credentials leading to privilege escalation and full node compromise. Wings exposes its **entire** daemon configuration to the egg configuration-file templating engine. When Wings renders a server's configuration files, any `{{config.<path>}}` placeholder in a replacement value is resolved against the full marshall

thehackerwire@mastodon.social at 2026-08-02T06:59:59.000Z ##

🔴 CVE-2026-52855 - Critical (9.9)

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63221
(9.4 CRITICAL)

EPSS: 0.38%

updated 2026-07-31T14:16:50.873000

1 posts

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. This affects only the deleteBatch() code path. Regular delete() operations escape where() binds correctly. This issue is fixed i

thehackerwire@mastodon.social at 2026-08-02T18:00:08.000Z ##

🔴 CVE-2026-63221 - Critical (9.4)

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14830
(7.5 HIGH)

EPSS: 0.21%

updated 2026-07-31T14:16:46.133000

1 posts

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.

thehackerwire@mastodon.social at 2026-08-02T15:00:32.000Z ##

🟠 CVE-2026-14830 - High (7.5)

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without pa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14333
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-31T14:16:45.960000

1 posts

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.

thehackerwire@mastodon.social at 2026-08-02T16:00:52.000Z ##

🟠 CVE-2026-14333 - High (7.5)

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52539
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-07-31T12:30:30

1 posts

Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT session tokens with arbitrary user data and full administrative permissions.

thehackerwire@mastodon.social at 2026-08-02T23:00:02.000Z ##

🔴 CVE-2026-52539 - Critical (9.1)

Outstatic CMS &lt;= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-38709
(9.8 CRITICAL)

EPSS: 2.67%

updated 2026-07-31T12:16:49.683000

2 posts

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

thehackerwire@mastodon.social at 2026-08-02T22:00:17.000Z ##

🔴 CVE-2026-38709 - Critical (9.8)

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulne...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18452
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-07-31T09:31:30

1 posts

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.

thehackerwire@mastodon.social at 2026-08-02T13:00:32.000Z ##

🔴 CVE-2026-18452 - Critical (10)

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16236
(8.8 HIGH)

EPSS: 0.63%

updated 2026-07-31T09:31:30

1 posts

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for auth

thehackerwire@mastodon.social at 2026-08-02T12:00:27.000Z ##

🟠 CVE-2026-16236 - High (8.8)

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65309
(7.5 HIGH)

EPSS: 0.15%

updated 2026-07-31T09:31:30

1 posts

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.

thehackerwire@mastodon.social at 2026-08-02T11:59:58.000Z ##

🟠 CVE-2026-65309 - High (7.5)

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores
and transmits user passwords using a reversible format instead of a
one-way password hash. This allows an attacker able to read the
credential store or capture network traffic to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65310
(7.5 HIGH)

EPSS: 0.32%

updated 2026-07-31T09:31:30

1 posts

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.

thehackerwire@mastodon.social at 2026-08-02T11:00:17.000Z ##

🟠 CVE-2026-65310 - High (7.5)

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions, exposes its data and configuration endpoint
without any authentication and permissive CORS on every response. An
unauthenticated attacker with network acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12562
(8.8 HIGH)

EPSS: 0.28%

updated 2026-07-31T00:30:29

1 posts

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service that does not require any authentication, allowing an attacker to directly interact with the Linux environment that power

thehackerwire@mastodon.social at 2026-08-02T22:00:27.000Z ##

🟠 CVE-2026-12562 - High (8.8)

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated
service that exposes a debug interface granting full root-level access
to the embedded system. This vulnerability stems from a
network-accessible port running a Target Communica...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-51291
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-07-30T21:31:47

1 posts

sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module.

nyanbinary@infosec.exchange at 2026-08-03T18:39:18.000Z ##

Ok, the first one is absolutely it:

Furthermore, we deploy MLG-UAF to conduct large-scale security auditing on mainstream open-source software such as libtiff, LibRaw, SQLite, ImageMagick and Zephyr RTOS. In real-world industrial source code scanning, our framework successfully discovered 17 unique confirmed UAF vulnerabilities assigned with independent Common Vulnerabilities and Exposures (CVE) IDs (CVE-2026 series, RESERVED and not yet publicized), covering cross-functional kernel UAF, intra-procedural cache UAF, race-condition UAF and multimedia parsing UAF scenarios.Real CVE case studies on CVE-2026-51291 (SQLite JSON cache flaw) and CVE-2023-32233 (Linux netfilter kernel vulnerability) demonstrate that MLG-UAF can precisely capture the fixed free-then-use spatial topological fingerprint of UAF defects and accurately resolve ambiguous multi-level pointer aliasing, even under heavy control-flow obfuscation.

##

CVE-2026-43760
(8.6 HIGH)

EPSS: 0.24%

updated 2026-07-30T19:17:30.313000

1 posts

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.

sayzard@mastodon.sayzard.org at 2026-08-04T12:42:39.000Z ##

macOS security bug went unreported due to Apple being deluged by AI slop reports

Apple이 macOS Screen Sharing/Remote Management의 레거시 VNC 비밀번호 옵션에서 발생하는 원격 코드 실행 취약점(CVE-2026-43760)을 수정했습니다. 공격자는 macOS 계정 없이 VNC 비밀번호만으로 인증한 뒤 로직 결함을 악용해 root 소유 파일을 생성할 수 있으며, 예시로 /private/etc/sudoers.d에 무비밀번호...

techradar.com/pro/security/a-p

##

CVE-2026-17191
(9.1 CRITICAL)

EPSS: 2.83%

updated 2026-07-30T19:10:52.250000

1 posts

An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not awa

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-17192
(8.5 HIGH)

EPSS: 2.34%

updated 2026-07-30T19:10:52.250000

1 posts

A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer net

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-07-30T16:17:15.073000

2 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

AAKL at 2026-08-04T14:53:52.509Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s

##

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-41703
(7.6 HIGH)

EPSS: 0.56%

updated 2026-07-30T16:17:11.403000

2 posts

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

AAKL at 2026-08-04T14:53:52.509Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s

##

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-41709
(2.7 LOW)

EPSS: 0.38%

updated 2026-07-30T15:31:51

2 posts

VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.

AAKL at 2026-08-04T14:53:52.509Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s

##

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 1.14%

updated 2026-07-30T15:31:51

2 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

AAKL at 2026-08-04T14:53:52.509Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s

##

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-5492
(6.5 MEDIUM)

EPSS: 1.60%

updated 2026-07-30T14:18:46.477000

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a user-s

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-5491
(7.5 HIGH)

EPSS: 1.54%

updated 2026-07-30T14:18:46.477000

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 6067 by default. The issue results from the lack of proper validation of a us

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-5487
(7.5 HIGH)

EPSS: 1.54%

updated 2026-07-30T14:18:46.477000

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a us

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-47876
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-07-30T14:16:58.467000

2 posts

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

AAKL at 2026-08-04T14:53:52.509Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s

##

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-16498
(10.0 CRITICAL)

EPSS: 0.33%

updated 2026-07-30T14:08:23.057000

2 posts

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in terraform-mcp-server 1.1.0.

CVE-2026-16655
(7.2 HIGH)

EPSS: 0.30%

updated 2026-07-30T14:01:30.413000

1 posts

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that

wpguyuk@infosec.exchange at 2026-08-03T07:04:35.000Z ##

Fluent Forms CVE-2026-16655 scores 7.2 on the CVSS scale — High severity — and allows data manipulation or extraction without admin credentials. If my sites were running Fluent Forms below 6.2.8, updating would be my immediate priority. Check your version now and update to 6.2.8.

#WordPress #WordPressSecurity #FluentForms #CVE #WebSecurity

wpguy.uk/blog/high-vulnerabili

##

CVE-2026-12935(CVSS UNKNOWN)

EPSS: 0.81%

updated 2026-07-29T21:31:07

1 posts

The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occurs when a LAN client initiates a connection to a malicious RTSP server controlled by an attacker. A specially crafted RTSP message may trigger improper memory handling within the kernel module Successful exploitation of this vulnerability ma

DailyCyberSecurity@infosec.exchange at 2026-08-03T01:48:42.000Z ##

A TP-Link TL-WR940N flaw, CVE-2026-12935, allows unauthenticated remote code execution via an RTSP stack buffer overflow. Update the router firmware now.

#TPLink #TLWR940N #CVE202612935 #RCE #RouterSecurity #InfoSec

securityonline.info/tp-link-wr

##

CVE-2026-53264
(7.8 HIGH)

EPSS: 0.21%

updated 2026-07-29T21:30:47

2 posts

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is possible to create a race with an associated action. Let's illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER: 0: mutex_lock() <-- holds the idr lock 0: rcu_read_lock() 0: p = idr_f

1 repos

https://github.com/HORKimhab/CVE-2026-53264

DailyCyberSecurity at 2026-08-04T13:03:09.496Z ##

A Linux kernel vulnerability, CVE-2026-53264, lets a local user run arbitrary code via a net/sched use-after-free. A public PoC is now available.

securityonline.info/linux-kern

##

DailyCyberSecurity@infosec.exchange at 2026-08-04T13:03:09.000Z ##

A Linux kernel vulnerability, CVE-2026-53264, lets a local user run arbitrary code via a net/sched use-after-free. A public PoC is now available.

#CVE202653264 #LinuxKernel #UseAfterFree #PrivilegeEscalation #InfoSec

securityonline.info/linux-kern

##

CVE-2026-67192
(8.1 HIGH)

EPSS: 0.62%

updated 2026-07-29T18:31:46

2 posts

Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated. Attackers can craft packets with an unvalidated length field passed directly to the GCM decrypt function, overwriting the stack cookie and return address to potentially achiev

CVE-2026-42533
(8.1 HIGH)

EPSS: 3.60%

updated 2026-07-29T05:16:44.720000

1 posts

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyon

9 repos

https://github.com/suominen/CVE-2026-42533

https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report

https://github.com/Daniyal48/ghostlock-vagrant-box

https://github.com/srkyn/nginx-map-risk-audit

https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner

https://github.com/seguridadentrerios/CVE-2026-42533

https://github.com/jelasin/CVE-2026-42533

https://github.com/imbas007/CVE-2026-42533

https://github.com/gagaltotal/CVE-2026-42533-nginx

rolle@mementomori.social at 2026-08-02T20:52:27.000Z ##

Here's my five-week holiday, June 27 - August 2. This is the evidence trail of a man who does not know how to stop.

Running (11 runs, ~131 km):
- Jun 27: 12 km
- Jun 29: 6.5 km easy
- Jul 1: 8.37 km Mile Repeats treadmill
- Jul 4: 15.14 km trail long run
- Jul 6: 5.33 km easy hill run in drizzle
- Jul 11: 10.33 km long run in +30°C heat
- Jul 17: 6.26 km Zwift Hill Repeats
- Jul 18: 21.90 km half marathon
- Jul 21: 6.01 km Tempo 2-1 outdoors
- Jul 23: 5.05 km Current Pace Calibration 5K
- Jul 25: 25.03 km "Lost in the Swamp" 25K trail, 397m elevation
- Jul 27: 5.04 km Zwift Lutece Express, Paris
- Jul 28: 6.16 km Zwift On Off Ks
- Jul 30: 5.04 km 5x1km intervals
- Aug 1: 26.41 km 26K trail adventure, 415m elevation, 211 min

Health setbacks:
- Jun 27: 9/10 migraine at 23:55
- Jul 18: 9/10 migraine
- Jul 19: terrible postdrome
- Jun 28: postdrome day

Linux desktop deep dive (the real holiday project):
- Switched compositor from Hyprland to driftwm (infinite canvas + DMS shell)
- Built the "quantum realm" living wallpaper - transparent evolving fbm fog/stream/void over a NASA starmap
- Fixed driftwm animated blur GPU overheating (PR #220), stale pointer constraint, VRR support
- Submitted PRs for driftwm blur mask caching (#185) and animate_fps background cap (#184)
- Tried and rejected niri (tile columns kill floating workflow I'm fond of)
- Tried and abandoned Nourish/Y5 Dev session (no XWayland, launcher friction)
- Wrote a full compositor alternatives comparison doc

RAM saga:
- Diagnosed OW2 FPS collapse on Arch: 30 GB demand vs 16 GB RAM, swap full issue
- Survived earlyoom killing the compositor under a ~21 GB DMS shell leak, since fixed
- Ordered Corsair LPX 2x16 GB DDR4-3200, installed to 48 GB total
- Fixed accidentally forgotten MemoryHigh=3G shell cap that had throttled 1.3M times and forced 10 GB into swap

Gaming:
- Started Red Dead Redemption 2 (Jul 4)
- Overwatch 2: fixed dead-zone click bug, recovered corrupted update (75 GB repair), played several comps
- Played RV There Yet? with my son, laughed our assess off (Jul 22)
- Deeper gaming and compatibility optimizations on Linux

Mementomori ry association:
- Filed Mementomori ry association application to PRH - registered Jul 7
- Applied for bank account, handled phone calls, paperwork, meeting minutes
- Set up emails
- Rewrote mementomori.social terms of service
- Decided membership fees, signed board minutes
- Built sophisticated signup-report-monitor (Mastodon to Matrix forwarder)
- Built members.mementomori.social MVP
- Mementods Mastodon fork upgrades from upstream to v4.7.0-alpha.1 and alpha.2

Open source contributions:
- Halloy IRC client: timestamp position PR (#2206), blank space fix PR (#2221), ISO-8859-1 decode PR (#2254)
- Sidra music player: Last.fm scrobbling PR (#145)
- DMS plugin registry: CPU, Disk, I/O monitors submitted
- Released dms-cpu-monitor, dms-disk-monitor, dms-ram-monitor, dms-vram-monitor, dms-gpu-monitor (all from 1.0.0 through multiple releases)
- Released lc (linux-cleaner) among other side projects

Server / infra:
- 2 server maintenance windows
- Upgraded 31 servers in total
- One dist-upgrade from Ubuntu server 20.04 through 22.04 to 24.04 LTS
- Built another personal dedicated server for side projects, migrated some services to it from other servers
- Fixed some StorageBox issues, shipped open source tool backup-to-storagebox v3.0.0
- Fixed minor DNS/Redis issues on multiple servers
- Addressed nginx CVE-2026-42533
- Fixed some failing certs, stale mounts, CIFS hangs due incident calls

Customer client work (yes, on holiday, I'm an entrepreneur):
- ~25 tickets handled
- Fixed issues for 14 sites
- Sent 2 quotes
- Handled 5 job applications
- Fixed one unauthenticated nonce type confusion vulnerability
- Fixed one caching issue

Personal infra / tools:
- Built and iterated dough (open source personal budgeting app): releases 3.3.0 through 3.16.0
- Built dough-mcp (releases 0.2.0 through 0.3.0)
- Nanoclaw (Son of Anton) fork releases 1.19.0 through 1.30.0 (12 releases)
- Personal day planner tool releases 1.22.0 through 1.24.0
- Dotfiles releases 2.10.7 through 2.42.2 (relentless)
- Rewrote completelty our home weather system c.rolle.wtf with precipitation and better forecast
- Set up quick tool based on ff2mpv + mpv for instant adless YouTube playback
- Ungoogled-chromium optimization pass with NVDEC hardware decode
- Fixed home WiFi dropouts (5 GHz DFS, channel splitting, RSSI deauth) with Ubiquity router
- Tested alternative browsers: Thorium, Zen, Brave Origin Nightly, Orion
- Tried dozens of new alternative AI models
- Released lc 0.1.0, omnishuffle 1.3.1, lastfm-recommendations 2.1.0
- Released Luku for iOS 1.2.3
- Fixed some technical challenges long overdue

Finance / admin:
- Paid taxes
- Paid bills
- Categorized and flagged hundreds of transactions
- Daily dough reconciliations
- Company finance review
- Updated company finance sheets

Family:
- 18th anniversary with my wife (Jul 2) - pizza and movie at home
- Weekly café dates with my wife (Jul 5, 12, 19, 26)
- Sushi lunch with my wife (Jul 1)
- Coffee with a friend (Jul 10, sat down for 4 hours)
- Family lunch (Jul 31)
- Trip to mom's place for a few days with kids, strawberries, pancakes, summer days (Jul 13)

Other:
- Migrated off Google Photos to PixelUnion, cancelled Google One
- Wrote a blog post about the Google Photos migration
- Completed CRM migration off Pipedrive (yes, work stuff but a fun one)
- Completed GitBook to Outline tech doc migration (also fun work stuff)

Zero actual rest days that contained zero commits. Oops.

This is everything I have documented.

Tomorrow, I get to rest at the office 😂

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 94.55%

updated 2026-07-28T14:54:01.770000

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

Nuclei template

100 repos

https://github.com/adysec/cve-2026-31431

https://github.com/cs8425/copy-fail-go

https://github.com/samanzamani/copy-fail-checker

https://github.com/tgies/copy-fail-c

https://github.com/insomnisec/Detections-CVE-2026-31431

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/cozystack/copy-fail-blocker

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/xeloxa/copyfail-exploit

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/st4rburn/public-passwd

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/ncmprbll/copy-fail-rs

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/Huchangzhi/autorootlinux

https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection

https://github.com/yxdm02/CVE-2026-31431

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/malwarekid/CVE-2026-31431

https://github.com/sgkdev/ptrace_may_dream

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/cyber-joker/copy-fail-python

https://github.com/diemoeve/copyfail-rs

https://github.com/wesmar/CVE-2026-31431

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/mrunalp/block-copyfail

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/abdullaabdullazade/CVE-2026-31431

https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431

https://github.com/rootsecdev/cve_2026_31431

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/Smarttfoxx/copyfail

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/1neptune/CopyFail

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/H1d3r/copy-fail_LPE_Interactive

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/Boos4721/copyfail-rs

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/sammwyy/copyfail-rs

https://github.com/desultory/CVE-2026-31431

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/b5null/CVE-2026-31431-C

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/professional-slacker/alg_check

https://github.com/badsectorlabs/copyfail-go

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/bootsareme/copyfail-deconstructed

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/sgkdev/page_inject

https://github.com/pedromizz/copy-fail

https://github.com/luotian2/CVE-2026-31431

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/Juguitos/copy-fail

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/atgreen/block-copyfail

https://github.com/povzayd/CVE-2026-31431

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/0xShe/CVE-2026-31431

https://github.com/wgnet/wg.copyfail.patch

https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/rvzsec/CVE-2026-31431

https://github.com/ExploitEoom/CVE-2026-31431

certvde@infosec.exchange at 2026-08-04T07:02:03.000Z ##

#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431

certvde.com/en/advisories/vde-

#CSAF pilz.csaf-tp.certvde.com/.well

##

CVE-2026-16462
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-07-28T12:31:27

1 posts

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

DailyCyberSecurity@infosec.exchange at 2026-08-03T01:03:11.000Z ##

CVE-2026-16462 is a critical SQL injection in Weidmueller PROCON-WEB SCADA, rated CVSS 9.8. An unauthenticated attacker can run SQL commands. Patch now.

#PROCONWEB #Weidmueller #CVE202616462 #SQLInjection #SCADA #CyberSecurity

securityonline.info/procon-web

##

CVE-2026-11841
(9.4 CRITICAL)

EPSS: 0.46%

updated 2026-07-28T12:31:20

1 posts

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify applic

DailyCyberSecurity@infosec.exchange at 2026-08-03T13:45:45.000Z ##

CVE-2026-11841 lets an unauthenticated attacker reach internal files on SICK InspectorP6xx devices, risking device compromise. CVSS 9.4. Update to 5.4.0.

#SICK #InspectorP6xx #CVE202611841 #OTSecurity #ICS #CyberSecurity

securityonline.info/sick-inspe

##

CVE-2026-12495
(0 None)

EPSS: 0.16%

updated 2026-07-28T08:17:14.187000

2 posts

Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration se

CVE-2026-48030
(9.9 CRITICAL)

EPSS: 1.54%

updated 2026-07-27T20:32:11.620000

1 posts

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving full Remote Code Execution

1 repos

https://github.com/muslimbek-0x/CVE-2026-48030

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-45112
(7.5 HIGH)

EPSS: 1.94%

updated 2026-07-27T19:51:07.873000

1 posts

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-07-27T18:31:56

1 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

1 repos

https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

netsecio@mastodon.social at 2026-08-04T16:50:50.000Z ##

📰 JetBrains Patches Critical Unauthenticated RCE Flaw in TeamCity

🚨 CRITICAL ALERT: JetBrains patches CVE-2026-63077, a 9.8 CVSS unauthenticated RCE in TeamCity On-Premises. All versions affected. Exploit allows full server takeover. Upgrade immediately to prevent supply chain attacks! #TeamCity #CI/CD #CyberSecurity

🔗 cyber.netsecops.io/articles/je

##

CVE-2026-9198
(9.8 CRITICAL)

EPSS: 1.89%

updated 2026-07-24T16:57:10.373000

2 posts

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

Nuclei template

3 repos

https://github.com/ywh-jfellus/CVE-2026-9198

https://github.com/0xgh057r3c0n/CVE-2026-9198

https://github.com/0xdak/CVE-2026-9198_exploit

cisakevtracker@mastodon.social at 2026-08-04T18:01:22.000Z ##

CVE ID: CVE-2026-9198
Vendor: IBM
Product: Langflow
Date Added: 2026-08-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-04T18:01:22.000Z ##

CVE ID: CVE-2026-9198
Vendor: IBM
Product: Langflow
Date Added: 2026-08-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-16723
(9.0 CRITICAL)

EPSS: 0.41%

updated 2026-07-23T15:01:24.377000

1 posts

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

7 repos

https://github.com/EQSTLab/CVE-2026-16723

https://github.com/fazilbaig1/CVE-2026-16723

https://github.com/dinosn/fastjson-jsontype-rce-lab

https://github.com/HORKimhab/CVE-2026-16723

https://github.com/why-success/fastjson-rce-lab

https://github.com/xiaoqiMikko/fastjson-check

https://github.com/1xPwn/CVE-2026-16723

cyberveille@mastobot.ping.moi at 2026-08-04T17:30:06.000Z ##

📢 Exploitation active de CVE-2026-16723 dans Fastjson : RCE sans authentification

SecurityWeek, publié le 28 juillet 2026. L'article rapporte l'exploitation active d'une vulnérabilité critique dans Fastjson, une bibliothèque Java de sérialisation/désérialisation JSON développée par Alibaba, largement utilisée dans les applications Spring Boot.

📖 cyberveille : cyberveille.ch/posts/2026-08-0
🌐 source : securityweek.com/unpatched-fas
🟢 vérification factuelle haute
#Fastjson #RCE #Cyberveille

##

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 75.76%

updated 2026-07-22T21:31:51

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

5 repos

https://github.com/HORKimhab/CVE-2026-50522

https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept

https://github.com/ChPratik/CVE-2026-50522

https://github.com/darses/CVE-2026-50522

https://github.com/4minx/CVE-2026-50522

thecybermind@infosec.exchange at 2026-08-03T17:27:38.000Z ##

(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker could exploit a deserialization vulnerability in Microsoft SharePoint to execute arbitrary code over a network....

thecybermind.co/2026/08/03/cis

##

CVE-2026-8933
(7.8 HIGH)

EPSS: 0.21%

updated 2026-07-21T15:30:51

1 posts

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or secur

rincewind@unseen-university.social at 2026-08-04T14:35:04.000Z ##

@derdreschi85

Yea, moving to snap , improve security.

Oh, look.

Just few days ago: CVE-2026-8933 - *another* security issue in snapd

H A H A !

##

CVE-2026-34486
(7.5 HIGH)

EPSS: 42.63%

updated 2026-07-20T12:18:48.440000

2 posts

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Nuclei template

6 repos

https://github.com/AirSkye/CVE-2026-34486-poc

https://github.com/404-src/CVE-2026-34486

https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction

https://github.com/anonmrc/CVE-2026-34486-e-Tomcat-Tribes

https://github.com/striga-ai/CVE-2026-34486

https://github.com/punitdarji/tomcat-cve-2026-34486

cisakevtracker@mastodon.social at 2026-08-04T18:01:07.000Z ##

CVE ID: CVE-2026-34486
Vendor: Apache
Product: Tomcat
Date Added: 2026-08-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-04T18:01:07.000Z ##

CVE ID: CVE-2026-34486
Vendor: Apache
Product: Tomcat
Date Added: 2026-08-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-15409
(10.0 CRITICAL)

EPSS: 78.44%

updated 2026-07-16T05:16:18.293000

2 posts

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Nuclei template

6 repos

https://github.com/remmons-r7/rapid7-CVE-2026-15409

https://github.com/0xBlackash/CVE-2026-15409

https://github.com/HORKimhab/CVE-2026-15409

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/Ch4120N/CVE-2026-15409

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

kev_Stalker@infosec.exchange at 2026-08-04T02:35:33.000Z ##

CVE-2026-15409 - Changed to Known Ransomware Status

SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilityVendor: SonicWallProduct: SMA1000 AppliancesSonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.Status changed from Unknown to Known for ransomware campaign usage.Flip nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T02:29:59.000Z ##

A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+.

#SonicWall #INCRansomware #CVE202615409 #VPNSecurity #CyberSecurity #UTA0533

securityonline.info/sonicwall-

##

CVE-2026-15410
(7.2 HIGH)

EPSS: 76.35%

updated 2026-07-14T21:32:21

2 posts

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

3 repos

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/HORKimhab/CVE-2026-15410

kev_Stalker@infosec.exchange at 2026-08-04T02:40:18.000Z ##

CVE-2026-15410 - Changed to Known Ransomware Status

SonicWall SMA1000 Appliances Code Injection VulnerabilityVendor: SonicWallProduct: SMA1000 AppliancesSonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T02:29:59.000Z ##

A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+.

#SonicWall #INCRansomware #CVE202615409 #VPNSecurity #CyberSecurity #UTA0533

securityonline.info/sonicwall-

##

tugatech@masto.pt at 2026-08-03T16:30:24.000Z ##

A Microsoft acaba de corrigir a falha Certighost, que permitia a um utilizador com acessos básicos manipular o sistema de cadastro e obter um certificado válido em nome de um Controlador de Domínio, assumindo a gestão absoluta de uma rede Windows. A falha, classificada como de gravidade alta, foi corrigida com a CVE-2026-54121. 🛡️

🔗 tugatech.com.pt/t88505-microso

#controlo #falha #microsoft 

##

CVE-2026-50343
(7.8 HIGH)

EPSS: 3.50%

updated 2026-07-14T18:32:22

2 posts

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

1 repos

https://github.com/Rat5ak/CVE-2026-50343-InstallService-EoP

DailyCyberSecurity at 2026-08-04T13:03:56.837Z ##

Details and proof-of-concept exploit code for CVE-2026-50343 are now public. The Windows privilege escalation flaw hands standard users SYSTEM privileges.

securityonline.info/cve-2026-5

##

DailyCyberSecurity@infosec.exchange at 2026-08-04T13:03:56.000Z ##

Details and proof-of-concept exploit code for CVE-2026-50343 are now public. The Windows privilege escalation flaw hands standard users SYSTEM privileges.

#CVE202650343 #Windows #PrivilegeEscalation #LPE #InfoSec

securityonline.info/cve-2026-5

##

certvde@infosec.exchange at 2026-08-04T07:02:03.000Z ##

#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431

certvde.com/en/advisories/vde-

#CSAF pilz.csaf-tp.certvde.com/.well

##

CVE-2026-43284
(7.8 HIGH)

EPSS: 93.23%

updated 2026-07-14T15:31:59

1 posts

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when

43 repos

https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284

https://github.com/xd20111/CVE-2026-43284

https://github.com/LucasPDiniz/CVE-2026-43284

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan

https://github.com/First-John/cve_2026_frag_family_fix

https://github.com/MadExploits/CVE-2026-46300

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/0xlane/pagecache-guard

https://github.com/haydenjames/dirty-frag-check

https://github.com/ChernStepanov/DirtyFrag-for-dummies

https://github.com/suominen/CVE-2026-43284

https://github.com/t1ckprivate/CVE-2026-43284-Dirty-Frag

https://github.com/liamromanis101/DirtyFrag-Detector

https://github.com/Aiyakami/rust_dirtyfrag

https://github.com/krisiasty/vcheck

https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284

https://github.com/kuniyal08/Dirty-Frag-CVE-2026-43284

https://github.com/1neptune/DirtyFrag

https://github.com/armircetaj/tetragon-dirtyfrag

https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag

https://github.com/XRSecCD/202605_dirty_frag

https://github.com/lukeslp/redtail-ioc

https://github.com/cumakurt/linuxpi

https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/nonameuserosint-hue/DirtyFrag-go

https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester

https://github.com/dixyes/dirtypatch

https://github.com/attaattaatta/CVE-2026-43500

https://github.com/linnemanlabs/dirtyfrag-arm64

https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4

https://github.com/jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC

https://github.com/RevyHub/CVE-2026-43284---DirtyFrag-Analysis-THM-

https://github.com/g0thamRabb1t/CVE-2026-43284-dirtyfrag-detection

https://github.com/metalx1993/dirtyfrag-patches

https://github.com/nabhan-mohy/Dirty-Frag-Research-CVE-2026-43284-

https://github.com/ryan2929/CVE-2026-43284-

https://github.com/0xBlackash/CVE-2026-43284

https://github.com/AK777177/Dirty-Frag-Analysis

https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC

https://github.com/FrosterDL/CVE-2026-43284

https://github.com/aettern/copyfrag-fuse

certvde@infosec.exchange at 2026-08-04T07:02:03.000Z ##

#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431

certvde.com/en/advisories/vde-

#CSAF pilz.csaf-tp.certvde.com/.well

##

CVE-2026-49413
(7.1 HIGH)

EPSS: 0.15%

updated 2026-07-01T14:04:37.143000

1 posts

The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. During execve(2), this flag is not yet set at the point where the auxiliary vector is constructed, so AT_SECURE was incorrectly set to zero for set-user-ID and set-group-ID executables. An unprivileged local user can inject a shared library via LD_PRELOAD into a set-user-ID or set-gr

1 repos

https://github.com/ii4gsp/CVE-2026-49413

CVE-2026-10702
(4.3 MEDIUM)

EPSS: 0.72%

updated 2026-06-30T03:36:54

1 posts

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

2 repos

https://github.com/raihants/cve-2026-10702

https://github.com/HORKimhab/CVE-2026-10702

hackmag@infosec.exchange at 2026-08-03T09:30:17.000Z ##

⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser

🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…

🔗 hackmag.com/news/cve-2026-1070

#news

##

CVE-2026-12044
(8.8 HIGH)

EPSS: 0.71%

updated 2026-06-19T00:31:46

1 posts

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the Views OID-lookup query, interpolated the description directly inside a single-quoted SQL literal -- ``'{{ data.description }}'`` -- instead o

thehackerwire@mastodon.social at 2026-08-02T08:00:13.000Z ##

🟠 CVE-2026-17346 - High (8.8)

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12045
(9.0 None)

EPSS: 0.48%

updated 2026-06-19T00:31:46

1 posts

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. The AI Assistant's execute_sql_query tool runs LLM-generated SQL inside a BEGIN TRANSACTION READ ONLY wrapper to prevent data modification. The LLM-supplied query was forwarded to

thehackerwire@mastodon.social at 2026-08-02T08:00:03.000Z ##

🔴 CVE-2026-17351 - Critical (9)

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42897
(8.1 HIGH)

EPSS: 70.31%

updated 2026-06-17T10:48:34.893000

3 posts

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

1 repos

https://github.com/atiilla/CVE-2026-42897

netsecio@mastodon.social at 2026-08-04T16:50:55.000Z ##

📰 Russian Group Midnight Blizzard Exploits Outlook XSS Flaw (CVE-2026-42897)

Russian actor Midnight Blizzard (Storm-2945) exploits Outlook XSS flaw CVE-2026-42897 to access mailboxes. Also hijacks hotel Wi-Fi in 'CaptiveCrunch' campaign to steal M365 tokens with CornFlake & ChocoShell malware. #ThreatIntel #APT

🔗 cyber.netsecops.io/articles/ru

##

oversecurity@mastodon.social at 2026-08-03T17:59:54.000Z ##

Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati

Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...

🔗️ [Cybersecurity360] link.is.it/ssYZlG

##

oversecurity@mastodon.social at 2026-08-03T17:59:52.000Z ##

Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati

Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...

🔗️ [Cybersecurity360] link.is.it/ssYZlG

##

CVE-2026-1070
(4.3 MEDIUM)

EPSS: 0.16%

updated 2026-06-17T10:14:56.770000

1 posts

The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0. This is due to missing nonce validation on the alex_user_counter_function() function. This makes it possible for unauthenticated attackers to update the plugin settings via a forged request granted they can trick a site administrator into performing an action such as cl

2 repos

https://github.com/raihants/cve-2026-10702

https://github.com/HORKimhab/CVE-2026-10702

hackmag@infosec.exchange at 2026-08-03T09:30:17.000Z ##

⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser

🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…

🔗 hackmag.com/news/cve-2026-1070

#news

##

CVE-2025-8943
(9.8 CRITICAL)

EPSS: 72.31%

updated 2026-06-17T10:07:59.880000

1 posts

The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication unless explicitly configured. This combination

Nuclei template

EUVD_Bot@mastodon.social at 2026-08-04T18:01:27.000Z ##

🚨 EUVD-2026-52795

📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: Flowise
🏢 Vendor: FlowiseAI
📅 Updated: 2026-08-04

📝 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, ...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2023-32233
(7.8 HIGH)

EPSS: 12.97%

updated 2026-06-17T05:58:22.273000

1 posts

In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

7 repos

https://github.com/oferchen/POC-CVE-2023-32233

https://github.com/Destawell/gemini-2.5-pro-nf-tables-red-teaming

https://github.com/void0red/CVE-2023-32233

https://github.com/Destawell/gemini-2.5-pro-nf-tables-red-teamin

https://github.com/PIDAN-HEIDASHUAI/CVE-2023-32233

https://github.com/RogelioPumajulca/TEST-CVE-2023-32233

https://github.com/Liuk3r/CVE-2023-32233

nyanbinary@infosec.exchange at 2026-08-03T18:39:18.000Z ##

Ok, the first one is absolutely it:

Furthermore, we deploy MLG-UAF to conduct large-scale security auditing on mainstream open-source software such as libtiff, LibRaw, SQLite, ImageMagick and Zephyr RTOS. In real-world industrial source code scanning, our framework successfully discovered 17 unique confirmed UAF vulnerabilities assigned with independent Common Vulnerabilities and Exposures (CVE) IDs (CVE-2026 series, RESERVED and not yet publicized), covering cross-functional kernel UAF, intra-procedural cache UAF, race-condition UAF and multimedia parsing UAF scenarios.Real CVE case studies on CVE-2026-51291 (SQLite JSON cache flaw) and CVE-2023-32233 (Linux netfilter kernel vulnerability) demonstrate that MLG-UAF can precisely capture the fixed free-then-use spatial topological fingerprint of UAF defects and accurately resolve ambiguous multi-level pointer aliasing, even under heavy control-flow obfuscation.

##

CVE-2025-66376
(7.2 HIGH)

EPSS: 21.97%

updated 2026-03-18T18:31:10

1 posts

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

cyberveille@mastobot.ping.moi at 2026-08-02T11:30:26.000Z ##

📢 TA488 exploite une zero-day Zimbra (CVE-2025-66376) pour espionner des gouvernements via half-click
📝 ## 🔍 Contexte

Publié le 23 juillet 2026 par l'équipe Threat Research...
📖 cyberveille : cyberveille.ch/posts/2026-08-0
🌐 source : proofpoint.com/us/blog/threat-
#CVE_2025_66376 #IOC #Cyberveille

##

CVE-2025-66518(CVSS UNKNOWN)

EPSS: 0.91%

updated 2026-01-29T03:42:38

1 posts

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.

thehackerwire@mastodon.social at 2026-08-02T11:00:04.000Z ##

🟠 CVE-2026-62391 - High (8.1)

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.

This issue ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2013-4786
(7.5 HIGH)

EPSS: 78.57%

updated 2025-04-11T04:12:49

2 posts

The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

1 repos

https://github.com/fin3ss3g0d/CosmicRakp

threatnoir@infosec.exchange at 2026-08-04T10:06:06.000Z ##

⚠️ CRITICAL: Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

CVE-2013-4786 in IPMI 2.0 allows unauthenticated attackers to harvest password hashes from Baseboard Management Controllers via UDP 623, then crack them offline. Over 24,000 internet-exposed BMCs are vulnerable, and many run weak or predictable default credentials. Compromised BMCs give attackers d…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T15:01:55.000Z ##

LAVA found 36,872 exposed BMCs leaking IPMI password hashes via CVE-2013-4786. Some are already exploited in the wild. Here is how to lock them down.

#BMC #IPMI #CVE20134786 #DataCenter #Supermicro #CyberSecurity

securityonline.info/exposed-bm

##

CVE-2026-18830
(0 None)

EPSS: 0.00%

2 posts

N/A

awssecurityfeed at 2026-08-04T18:00:01.657Z ##

CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation

Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT
Description:
We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API...

aws.amazon.com/security/securi

##

awssecurityfeed@infosec.exchange at 2026-08-04T18:00:01.000Z ##

CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation

Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT
Description:
We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-69098
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-04T17:00:04.000Z ##

🔴 CVE-2026-69098 - Critical (9.8)

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-04T17:00:04.000Z ##

🔴 CVE-2026-69098 - Critical (9.8)

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17583
(0 None)

EPSS: 0.00%

1 posts

N/A

1 repos

https://github.com/HORKimhab/CVE-2026-17583

netsecio@mastodon.social at 2026-08-04T16:50:32.000Z ##

📰 Thermo Fisher DNA Software Flaw Allows Undetectable Evidence Tampering

A critical flaw (CVE-2026-17583) in Thermo Fisher's forensic DNA software allows for nearly undetectable evidence tampering. The vulnerability impacts the integrity of the criminal justice system. Patches are available. #CyberSecurity #Forensics #DNA

🔗 cyber.netsecops.io/articles/fl

##

CVE-2026-58073
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-64633
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-59726
(0 None)

EPSS: 0.48%

3 posts

N/A

1 repos

https://github.com/HORKimhab/CVE-2026-59726

DailyCyberSecurity at 2026-08-04T12:32:47.022Z ##

RufRoot CVE-2026-59726: Unauthenticated RCE in Ruflo MCP Bridge Exposes AI Agent Keys

meterpreter.org/rufroot-cve-20

##

DailyCyberSecurity@infosec.exchange at 2026-08-04T12:32:47.000Z ##

RufRoot CVE-2026-59726: Unauthenticated RCE in Ruflo MCP Bridge Exposes AI Agent Keys

meterpreter.org/rufroot-cve-20

##

security_crawler_carl@infosec.exchange at 2026-08-04T07:04:17.000Z ##

🏆 New Achievement! RufRoot Has Entered The Arena!

PHASE ONE BEGINS. The challenger: CVE-2026-59726, alias RufRoot, a CVSS 10.0 critical flaw in the open-source AI agent platform Ruflo. Its special move — exploiting an exposed Model Context Protocol bridge to hand unauthenticated attackers full control of enterprise AI environments. No credentials required. No mercy shown. Noma Security surfaced this beast hiding in every Ruflo version before 3.16.3.

This is not a warm-up encounter. (1/2)

##

CVE-2026-59774
(0 None)

EPSS: 0.00%

2 posts

N/A

undercodenews@mastodon.social at 2026-08-04T11:02:41.000Z ##

Critical Gitea Flaw Opens the Door to Silent File Theft and Potential Server Takeover + Video

Introduction: When a Public Repository Becomes a Gateway to the Server Open-source development platforms are built to make collaboration easier, but the same features that improve productivity can become dangerous when hidden trust boundaries fail. A newly disclosed critical vulnerability in Gitea, tracked as CVE-2026-59774, demonstrates how an apparently limited…

undercodenews.com/critical-git

##

DailyCyberSecurity@infosec.exchange at 2026-08-04T07:54:14.000Z ##

Gitea Vulnerability CVE-2026-59774 Enables Unauthenticated Remote Code Execution

securityonline.info/gitea-vuln

##

CVE-2026-56671
(0 None)

EPSS: 0.66%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-02T19:59:49.000Z ##

🟠 CVE-2026-56671 - High (7.5)

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containment che...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56673
(0 None)

EPSS: 0.43%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-02T19:00:09.000Z ##

🟠 CVE-2026-56673 - High (7.5)

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56672
(0 None)

EPSS: 0.24%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-02T18:59:58.000Z ##

🟠 CVE-2026-56672 - High (8.2)

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites