## Updated at UTC 2026-09-13T00:31:55.090620

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-85681 9.8 0.14% 4 0 2026-09-12T18:31:29 The WP Component WordPress plugin through 2.2.4 does not have any capability or
CVE-2026-84171 9.8 0.16% 4 0 2026-09-12T18:31:29 The WP images upload on piclect WordPress plugin through 1.0 does not validate t
CVE-2026-84047 8.6 0.18% 2 0 2026-09-12T18:31:28 The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize
CVE-2026-87842 7.5 0.18% 2 0 2026-09-12T18:31:28 The Zonify WordPress plugin before 1.0.5 does not perform any capability or aut
CVE-2026-90560 8.2 0.00% 2 0 2026-09-12T18:30:33 zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerabi
CVE-2026-90559 7.5 0.00% 2 0 2026-09-12T18:30:33 snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Sn
CVE-2026-90558 9.8 0.00% 2 0 2026-09-12T18:30:33 sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attri
CVE-2026-90556 7.8 0.00% 2 0 2026-09-12T18:30:33 Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load()
CVE-2026-82845 9.9 0.17% 2 0 2026-09-12T18:30:22 The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied
CVE-2026-87888 8.0 0.15% 2 0 2026-09-12T18:30:22 The YayPricing WordPress plugin before 3.5.7 does not perform an authorization
CVE-2026-87759 8.8 0.13% 4 0 2026-09-12T18:30:22 The Add User Autocomplete WordPress plugin before 1.2 does not perform any capab
CVE-2026-84099 8.1 0.16% 2 0 2026-09-12T18:30:22 The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthen
CVE-2026-81742 8.8 0.17% 2 0 2026-09-12T16:16:40.417000 The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any author
CVE-2026-81402 9.8 0.20% 2 0 2026-09-12T16:16:40.140000 The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability c
CVE-2026-80494 8.6 0.16% 2 0 2026-09-12T16:16:39.867000 The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-suppli
CVE-2026-80491 8.6 0.19% 2 0 2026-09-12T16:16:39.737000 The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and esc
CVE-2026-77006 9.6 0.11% 2 0 2026-09-12T16:16:38.670000 The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-sup
CVE-2026-77005 9.6 0.15% 2 0 2026-09-12T16:16:38.523000 The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a u
CVE-2026-15451 8.8 0.00% 2 0 2026-09-12T15:31:49 The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privile
CVE-2026-90537 8.2 0.00% 2 0 2026-09-12T15:31:49 WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a m
CVE-2026-90553 7.8 0.00% 2 0 2026-09-12T13:16:53.887000 vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOn
CVE-2026-85706 10.0 1.15% 36 7 2026-09-12T11:16:33.373000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7
CVE-2026-16482 7.5 0.34% 2 0 2026-09-12T09:33:41 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulner
CVE-2026-78159 9.8 0.76% 4 0 2026-09-12T09:33:41 The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut
CVE-2026-85200 7.5 0.76% 2 0 2026-09-12T08:16:24.810000 The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all
CVE-2026-78175 8.8 0.59% 2 0 2026-09-12T08:16:24.507000 The Tutor LMS – eLearning and online course solution plugin for WordPress is vul
CVE-2026-78006 9.8 0.78% 4 1 2026-09-12T08:16:24.240000 The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut
CVE-2026-86093 7.5 0.47% 1 0 2026-09-12T04:16:45.040000 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker
CVE-2026-81940 8.8 0.54% 1 0 2026-09-12T04:16:39.240000 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacke
CVE-2026-87719 9.9 0.61% 3 0 2026-09-12T03:30:28 GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 bef
CVE-2026-90460 None 0.34% 2 0 2026-09-12T00:31:35 An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via
CVE-2026-89266 8.2 0.47% 2 0 2026-09-12T00:31:35 stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where
CVE-2026-90456 None 0.25% 2 0 2026-09-12T00:31:35 An example environment-configuration file for a bundled inventory-management com
CVE-2026-49846 7.5 0.34% 1 0 2026-09-11T22:16:37.537000 libks provides foundational support for signalwire C products. Prior to version
CVE-2026-42018 7.5 0.92% 9 0 2026-09-11T21:32:08 JFrog Artifactory could return an internal anonymous-user token to an unauthenti
CVE-2026-80995 None 0.15% 2 0 2026-09-11T21:31:31 In the Linux kernel, the following vulnerability has been resolved: net: mctp:
CVE-2026-81000 None 0.20% 2 0 2026-09-11T21:31:31 In the Linux kernel, the following vulnerability has been resolved: net: tun: b
CVE-2026-80981 None 0.20% 2 0 2026-09-11T21:31:27 In the Linux kernel, the following vulnerability has been resolved: net/smc: fi
CVE-2026-79395 9.8 0.41% 1 0 2026-09-11T21:31:23 An improper authentication vulnerability in the WS-Security (wsse:UsernameToken)
CVE-2026-79393 7.5 0.53% 1 0 2026-09-11T21:31:22 A heap-based buffer overflow vulnerability in the WS-Addressing Action transform
CVE-2026-84869 9.9 0.69% 4 0 2026-09-11T21:31:17 A condition in the ScreenConnect client may allow files to be transferred and ex
CVE-2026-42016 8.1 0.89% 5 0 2026-09-11T21:31:06 JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri
CVE-2026-8778 9.8 0.62% 1 0 2026-09-11T21:17:58.797000 The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout
CVE-2026-89260 7.5 0.43% 1 0 2026-09-11T21:17:58.153000 MoguBlog through 6.2 contains an XML external entity injection vulnerability in
CVE-2026-89042 9.1 0.27% 1 0 2026-09-11T21:17:56.573000 passport-saml-encrypted through 0.1.13 makes SAML signature verification conditi
CVE-2026-62112 7.6 0.28% 1 0 2026-09-11T21:17:02.457000 Editor SQL Injection in Amelia <= 2.4.9 versions.
CVE-2026-89771 0 0.16% 1 0 2026-09-11T20:20:08.460000 In the Linux kernel, the following vulnerability has been resolved: ring-buffer
CVE-2026-54135 7.5 0.55% 1 0 2026-09-11T20:17:14.330000 AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan p
CVE-2026-53952 9.8 0.33% 1 0 2026-09-11T20:17:14.060000 GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the
CVE-2026-89262 7.5 0.31% 1 0 2026-09-11T18:31:32 MoguBlog through 6.2 contains an authorization bypass vulnerability in the comme
CVE-2026-89176 8.8 0.25% 1 0 2026-09-11T16:17:50.073000 WeenyGenius, a computer lab management system developed by Howyar Technologies,
CVE-2026-80462 10.0 0.30% 4 0 2026-09-11T15:32:48 A vulnerability in the Chef Automate API gateway and identity validation path ma
CVE-2026-89212 8.6 0.33% 1 0 2026-09-11T15:32:48 A flaw resulting in XML external entity (XXE) was found in Akana API Platform in
CVE-2026-84390 9.8 0.52% 1 0 2026-09-11T15:32:48 A inclusion of sensitive information in source code vulnerability in Fortinet Fo
CVE-2026-86060 9.8 1.02% 3 1 2026-09-11T15:32:27 RouterOS contains an argument-handling flaw in the SSH login path involving user
CVE-2026-82100 9.6 0.40% 2 0 2026-09-11T15:17:06.230000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-71416 8.8 0.17% 1 0 2026-09-11T15:17:03.373000 Headroom compresses data before the data reaches a large language model. Prior t
CVE-2026-47839 0 0.30% 1 0 2026-09-11T15:17:02.193000 A vulnerability allows users authenticating through a federated OIDC provider to
CVE-2026-82107 9.6 0.36% 2 0 2026-09-11T14:56:50.613000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-39821 9.6 0.69% 1 0 2026-09-11T13:17:49.237000 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels t
CVE-2026-67277 8.2 0.86% 2 0 2026-09-11T12:52:29.533000 RouterOS accepts a "related" btest connection before the corresponding primary s
CVE-2026-89259 9.8 0.41% 1 0 2026-09-11T12:33:34 Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under N
CVE-2026-86781 5.3 0.12% 1 0 2026-09-11T12:33:26 The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin befor
CVE-2026-80469 8.3 0.23% 1 0 2026-09-11T09:31:32 An attacker may achieve arbitrary code execution on a target system by uploading
CVE-2026-89178 8.8 0.23% 1 0 2026-09-11T09:31:31 WeenyGenius, a computer lab management system by Howyar Technologies, has an Ori
CVE-2026-89177 8.8 0.23% 1 0 2026-09-11T09:31:31 WeenyGenius, a computer lab management system by Howyar Technologies, has a Use
CVE-2026-89174 7.5 0.38% 1 0 2026-09-11T09:31:31 Smart Video Intercom System developed by Kingdom Communication Associated has a
CVE-2026-89060 7.7 0.23% 1 0 2026-09-11T06:31:14 A flaw was found in multicluster-observability-addon. This vulnerability allows
CVE-2026-19584 7.7 0.19% 1 0 2026-09-11T04:17:34.343000 Velociraptor allows for the creation of notebook backups in its default enabled
CVE-2026-77807 7.5 0.68% 1 0 2026-09-11T00:31:23 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution
CVE-2026-84889 8.8 0.53% 1 0 2026-09-11T00:31:23 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke
CVE-2026-87958 8.1 0.21% 1 0 2026-09-11T00:31:16 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a deni
CVE-2026-19646 9.1 0.52% 1 0 2026-09-11T00:31:12 IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0
CVE-2026-88044 9.1 0.49% 1 0 2026-09-10T22:47:10 ## Summary `serve/start` accepts protocol options in a per-server `proxyOpt` ob
CVE-2026-88062 None 0.40% 1 0 2026-09-10T21:22:13 ## 2. Summary `POST /api/acp/agents` registers a custom ACP agent. The endpoint
CVE-2026-89094 9.9 0.50% 3 0 2026-09-10T21:17:53.160000 Forgejo before 16.0.4 allows remote code execution via a crafted template reposi
CVE-2026-89086 9.1 0.20% 1 0 2026-09-10T21:17:52.570000 In the jose package before 0.11.0 for OCaml, library calls to validate an RSA si
CVE-2026-89054 8.2 0.35% 1 0 2026-09-10T20:17:31.973000 A missing authorization vulnerability in OpenNMS Horizon allows configuration ch
CVE-2026-88045 7.5 0.53% 1 0 2026-09-10T19:54:25.810000 rclone is a command-line program to sync files and directories to and from diffe
CVE-2026-80352 9.8 0.33% 1 0 2026-09-10T18:33:12 Improper Control of Generation of Code ('Code Injection') vulnerability in Apach
CVE-2026-89046 8.2 0.57% 1 0 2026-09-10T18:33:05 zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnera
CVE-2026-81467 9.8 3.84% 1 0 2026-09-10T18:33:04 Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutraliza
CVE-2026-85228 9.1 0.38% 1 0 2026-09-10T18:33:04 An integer overflow in the tensor buffer validation component in Amazon Deep Jav
CVE-2026-65638 None 3.20% 3 0 2026-09-10T18:32:56 Improper escaping of a request URL in ConfigServer Security & Firewall allows a
CVE-2026-65639 None 1.61% 1 0 2026-09-10T18:32:56 OS command injection in the advanced-rule parser of ConfigServer Security & Fire
CVE-2026-88889 7.8 0.62% 1 0 2026-09-10T16:18:11.693000 Renovate before 44.14.7 contains a command injection vulnerability in the Maven
CVE-2026-88290 7.5 0.26% 1 0 2026-09-10T16:18:10.767000 GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare un
CVE-2026-67593 9.1 0.46% 1 0 2026-09-10T16:17:45.273000 A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause
CVE-2026-13745 0 0.30% 1 0 2026-09-10T16:17:07.727000 A vulnerability in the Gemini CLI and associated GitHub Action allowed an unpriv
CVE-2026-88890 8.5 0.29% 1 0 2026-09-10T15:33:28 OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the
CVE-2026-88887 8.6 0.30% 1 0 2026-09-10T15:17:58.380000 Renovate is a dependency update automation tool. When listing tags/digests for a
CVE-2026-88891 8.3 0.25% 1 0 2026-09-10T15:13:07.090000 OpenPanel fails to enforce read-only project access level on 26 of 29 mutating p
CVE-2026-15019 7.5 0.68% 1 0 2026-09-10T14:39:13.757000 The Direct Download for WooCommerce plugin for WordPress is vulnerable to Direct
CVE-2026-18351 9.8 0.77% 1 2 2026-09-10T14:39:13.757000 The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulner
CVE-2026-19490 9.8 5.60% 1 2 2026-09-10T12:48:10.453000 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f
CVE-2025-25249 8.1 2.40% 2 0 2026-09-10T12:47:59.933000 A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6
CVE-2026-78082 None 0.49% 1 0 2026-09-10T12:31:26 Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Se
CVE-2026-8323 9.3 0.25% 1 0 2026-09-10T09:31:48 URL redirection to untrusted site ('open redirect') vulnerability in Armiya Info
CVE-2026-88289 7.5 0.33% 1 0 2026-09-10T09:31:44 GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variab
CVE-2026-0310 None 0.34% 2 0 2026-09-10T06:31:55 A buffer overflow vulnerability in the XML processing functionality of Palo Alto
CVE-2026-14873 8.0 0.24% 1 0 2026-09-10T06:31:42 The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalati
CVE-2026-69730 9.8 1.05% 2 0 2026-09-10T04:18:14.773000 Use after free in Windows DNS allows an unauthorized attacker to execute code ov
CVE-2026-19583 9.9 0.60% 1 0 2026-09-10T03:30:26 Velociraptor allows some sensitive artifacts to be gated by additional permissio
CVE-2026-88069 None 0.33% 1 0 2026-09-10T00:30:34 Pandora contains a path traversal vulnerability in its archive extraction worker
CVE-2026-87491 8.8 0.86% 4 2 2026-09-09T21:31:35 Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remo
CVE-2026-20079 10.0 75.75% 9 2 template 2026-09-09T21:31:33 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-75170 6.1 0.24% 1 0 2026-09-09T20:20:34.260000 Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoin
CVE-2026-38961 5.4 0.20% 1 0 2026-09-09T20:17:22.207000 Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Pl
CVE-2026-17469 5.3 0.21% 1 0 2026-09-09T18:32:16 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause
CVE-2026-78745 9.8 0.72% 1 1 2026-09-09T16:04:24.933000 An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote
CVE-2026-73324 6.5 0.33% 4 0 2026-09-09T15:35:16 VLC media player copies an RTSP response line into a fixed buffer without guaran
CVE-2026-56711 8.8 0.30% 4 0 2026-09-09T15:35:15 VLC media player computes the size of a picture buffer with 32-bit arithmetic an
CVE-2026-85103 9.8 0.36% 6 0 2026-09-09T15:35:15 A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unau
CVE-2026-85102 9.8 0.33% 6 0 2026-09-09T15:35:15 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-17622 6.5 0.49% 1 0 2026-09-09T15:06:06.793000 IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacke
CVE-2026-75650 10.0 2.15% 3 5 2026-09-09T05:18:07.237000 Adobe Commerce is affected by an Improper Neutralization of Special Elements Use
CVE-2025-14733 9.8 26.51% 3 1 2026-09-09T04:17:52.700000 An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process
CVE-2026-85880 7.8 0.57% 1 0 2026-09-08T21:34:12 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev
CVE-2026-86218 9.8 0.74% 4 2 2026-09-08T21:33:02 N-central is vulnerable to a pre-auth remote code execution This issue affects N
CVE-2026-52777 0 0.21% 1 0 2026-09-08T21:05:26.920000 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an aut
CVE-2026-86426 0 1.41% 1 0 template 2026-09-08T19:57:49.663000 LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the RE
CVE-2026-82067 8.1 0.28% 1 0 2026-09-08T19:07:12.210000 Improper handling of case sensitivity in the configuration validation component
CVE-2026-69827 8.1 0.53% 1 0 2026-09-08T18:33:26 Concurrent execution using shared resource with improper synchronization ('race
CVE-2026-33197 None 0.12% 1 0 2026-09-08T15:32:05 AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause th
CVE-2026-71626 7.5 0.32% 1 0 2026-09-08T15:31:36 An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive
CVE-2026-44756 10.0 0.32% 1 0 2026-09-08T03:31:21 A memory safety vulnerability exists in the Extended Passport Protocol (EPP) pro
CVE-2026-80907 0 0.16% 1 0 2026-09-07T15:17:33.510000 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu:
CVE-2026-85046 8.8 1.26% 1 8 2026-09-06T03:30:24 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at
CVE-2026-80880 None 0.16% 1 0 2026-09-04T18:31:40 In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Pr
CVE-2026-17444 5.3 0.29% 1 0 2026-09-04T18:31:40 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.
CVE-2026-16689 6.2 0.11% 1 0 2026-09-04T18:31:39 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.
CVE-2026-78849 None 0.26% 1 0 2026-09-04T18:31:34 Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <=
CVE-2026-80890 0 0.18% 1 0 2026-09-04T18:17:57.077000 In the Linux kernel, the following vulnerability has been resolved: sctp: rejec
CVE-2026-80871 0 0.15% 1 0 2026-09-04T17:16:59.027000 In the Linux kernel, the following vulnerability has been resolved: crypto: xil
CVE-2026-82329 9.8 7.67% 3 7 template 2026-09-02T18:31:57 JFrog Artifactory contains an authentication weakness that, under default config
CVE-2026-82078 9.1 1.69% 1 2 2026-09-01T04:18:02.160000 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-81578 9.8 1.62% 1 2 2026-08-31T21:31:56 An improper access control vulnerability exists in the web management interface
CVE-2026-69414 7.8 0.56% 2 2 2026-08-19T18:32:28 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-59310 9.8 45.88% 2 2 2026-08-18T18:32:52 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-20316 5.3 11.15% 3 0 2026-08-01T05:16:55.973000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-43502 7.8 0.12% 1 1 2026-07-23T16:10:00.137000 In the Linux kernel, the following vulnerability has been resolved: net/rds: ha
CVE-2026-15409 10.0 84.54% 2 6 template 2026-07-14T21:32:22 A Server-side request forgery (SSRF) vulnerability has been identified in the SM
CVE-2026-50013 7.5 0.27% 1 0 2026-07-14T18:03:10 ### Summary: When Hoverfly is running in Diff mode, the `AddDiff()` function wr
CVE-2026-54174 8.3 0.10% 1 0 2026-07-10T21:43:06 Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the
CVE-2026-49464 8.1 0.20% 1 0 2026-07-08T21:12:01 ## Impact In versions from 1.5.0 up to and including 3.0.0, any authenticated p
CVE-2026-11387 9.8 2.21% 1 2 template 2026-07-01T13:56:17.493000 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart
CVE-2026-28576 5.5 0.15% 1 1 2026-06-17T18:35:56 In Contacts Provider, there is a possible way to access the contacts database du
CVE-2026-39987 9.8 98.95% 1 25 template 2026-06-17T10:42:51.460000 marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE
CVE-2026-20841 7.8 11.85% 1 14 2026-06-17T10:17:53.867000 Improper neutralization of special elements used in a command ('command injectio
CVE-2019-0859 7.8 4.15% 1 1 2026-06-17T02:09:03.317000 An elevation of privilege vulnerability exists in Windows when the Win32k compon
CVE-2026-4800 8.1 2.76% 1 2 2026-04-01T23:51:13 ### Impact The fix for [CVE-2021-23337](https://github.com/advisories/GHSA-35jh
CVE-2026-33671 7.5 0.40% 1 1 2026-03-27T21:36:14 ### Impact `picomatch` is vulnerable to Regular Expression Denial of Service (Re
CVE-2026-33186 9.1 1.56% 1 1 2026-03-25T18:12:09 ### Impact _What kind of vulnerability is it? Who is impacted?_ It is an **Auth
CVE-2026-0915 7.5 0.63% 1 1 2026-01-20T18:31:56 Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that spec
CVE-2022-41352 9.8 95.48% 1 4 template 2025-10-22T00:32:37 An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacke
CVE-2016-7255 7.8 80.97% 1 5 2025-10-22T00:32:21 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2
CVE-2026-84890 0 0.25% 1 0 N/A
CVE-2026-46636 0 0.36% 1 0 N/A
CVE-2026-89066 0 0.16% 1 0 N/A
CVE-2026-87908 0 0.30% 1 0 N/A
CVE-2026-51990 0 0.00% 1 1 N/A
CVE-2026-16338 0 0.00% 1 0 N/A
CVE-2026-70416 0 0.00% 1 0 N/A
CVE-2026-63695 0 0.00% 1 0 N/A
CVE-2026-89049 0 0.36% 2 0 N/A
CVE-2026-88052 0 0.12% 1 0 N/A
CVE-2026-72898 0 94.22% 1 8 template N/A
CVE-2026-84388 0 0.00% 1 0 N/A
CVE-2026-87911 0 0.99% 1 0 N/A

CVE-2026-85681
(9.8 CRITICAL)

EPSS: 0.14%

updated 2026-09-12T18:31:29

4 posts

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to overwrite any of the site's options. On a single site installation this leads to a full takeover, as registration can be enabled

thehackerwire@mastodon.social at 2026-09-12T17:00:14.000Z ##

🔴 CVE-2026-85681 - Critical (9.8)

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unaut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-12T12:00:24.408Z ##

CVE-2026-85681 (CRITICAL): WP Component plugin ≤2.2.4 allows unauthenticated option overwrites, risking full WordPress site takeover. Single-site installs are exposed. Check vendor advisory for mitigation steps: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-12T17:00:14.000Z ##

🔴 CVE-2026-85681 - Critical (9.8)

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unaut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-12T12:00:24.000Z ##

CVE-2026-85681 (CRITICAL): WP Component plugin ≤2.2.4 allows unauthenticated option overwrites, risking full WordPress site takeover. Single-site installs are exposed. Check vendor advisory for mitigation steps: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #BlueTeam

##

CVE-2026-84171
(9.8 CRITICAL)

EPSS: 0.16%

updated 2026-09-12T18:31:29

4 posts

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.

thehackerwire@mastodon.social at 2026-09-12T17:00:02.000Z ##

🔴 CVE-2026-84171 - Critical (9.8)

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-12T13:30:24.200Z ##

WP images upload on piclect (≤1.0) suffers from CRITICAL CVE-2026-84171: Unauthenticated attackers can upload arbitrary files, risking code execution. Restrict uploads & monitor activity until a fix is released. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-12T17:00:02.000Z ##

🔴 CVE-2026-84171 - Critical (9.8)

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-12T13:30:24.000Z ##

WP images upload on piclect (≤1.0) suffers from CRITICAL CVE-2026-84171: Unauthenticated attackers can upload arbitrary files, risking code execution. Restrict uploads & monitor activity until a fix is released. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202684171 #Vuln

##

CVE-2026-84047
(8.6 HIGH)

EPSS: 0.18%

updated 2026-09-12T18:31:28

2 posts

The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-09-12T19:01:45.000Z ##

🟠 CVE-2026-84047 - High (8.6)

The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T19:01:45.000Z ##

🟠 CVE-2026-84047 - High (8.6)

The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87842
(7.5 HIGH)

EPSS: 0.18%

updated 2026-09-12T18:31:28

2 posts

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.

thehackerwire@mastodon.social at 2026-09-12T18:00:02.000Z ##

🟠 CVE-2026-87842 - High (7.5)

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T18:00:02.000Z ##

🟠 CVE-2026-87842 - High (7.5)

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90560
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-12T18:30:33

2 posts

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.

thehackerwire@mastodon.social at 2026-09-12T19:01:24.000Z ##

🟠 CVE-2026-90560 - High (8.2)

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T19:01:24.000Z ##

🟠 CVE-2026-90560 - High (8.2)

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90559
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-12T18:30:33

2 posts

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data that decompresses larger than the destination buffer, causing writes past buffer boundaries and JVM termination.

thehackerwire@mastodon.social at 2026-09-12T19:00:34.000Z ##

🟠 CVE-2026-90559 - High (7.5)

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T19:00:34.000Z ##

🟠 CVE-2026-90559 - High (7.5)

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90558
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-12T18:30:33

2 posts

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.

thehackerwire@mastodon.social at 2026-09-12T19:00:23.000Z ##

🔴 CVE-2026-90558 - Critical (9.8)

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other hea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T19:00:23.000Z ##

🔴 CVE-2026-90558 - Critical (9.8)

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other hea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90556
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-12T18:30:33

2 posts

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.

thehackerwire@mastodon.social at 2026-09-12T19:00:13.000Z ##

🟠 CVE-2026-90556 - High (7.8)

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T19:00:13.000Z ##

🟠 CVE-2026-90556 - High (7.8)

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82845
(9.9 CRITICAL)

EPSS: 0.17%

updated 2026-09-12T18:30:22

2 posts

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the s

thehackerwire@mastodon.social at 2026-09-12T19:01:35.000Z ##

🔴 CVE-2026-82845 - Critical (9.9)

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T19:01:35.000Z ##

🔴 CVE-2026-82845 - Critical (9.9)

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87888
(8.0 HIGH)

EPSS: 0.15%

updated 2026-09-12T18:30:22

2 posts

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.

thehackerwire@mastodon.social at 2026-09-12T18:00:16.000Z ##

🟠 CVE-2026-87888 - High (8)

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T18:00:16.000Z ##

🟠 CVE-2026-87888 - High (8)

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87759
(8.8 HIGH)

EPSS: 0.13%

updated 2026-09-12T18:30:22

4 posts

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator role on a multisite installation.

thehackerwire@mastodon.social at 2026-09-12T17:59:53.000Z ##

🟠 CVE-2026-87759 - High (8.8)

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to gr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-12T07:30:24.066Z ##

CVE-2026-87759 (CRITICAL): Add User Autocomplete plugin (<1.2) for WordPress allows authenticated users to self-assign admin on multisite via improper privilege checks. Upgrade to 1.2+ or restrict user roles. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-12T17:59:53.000Z ##

🟠 CVE-2026-87759 - High (8.8)

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to gr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-12T07:30:24.000Z ##

CVE-2026-87759 (CRITICAL): Add User Autocomplete plugin (<1.2) for WordPress allows authenticated users to self-assign admin on multisite via improper privilege checks. Upgrade to 1.2+ or restrict user roles. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Security #CVE202687759

##

CVE-2026-84099
(8.1 HIGH)

EPSS: 0.16%

updated 2026-09-12T18:30:22

2 posts

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.

thehackerwire@mastodon.social at 2026-09-12T16:59:52.000Z ##

🟠 CVE-2026-84099 - High (8.1)

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T16:59:52.000Z ##

🟠 CVE-2026-84099 - High (8.1)

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81742
(8.8 HIGH)

EPSS: 0.17%

updated 2026-09-12T16:16:40.417000

2 posts

The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.

thehackerwire@mastodon.social at 2026-09-12T22:59:51.000Z ##

🟠 CVE-2026-81742 - High (8.8)

The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T22:59:51.000Z ##

🟠 CVE-2026-81742 - High (8.8)

The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81402
(9.8 CRITICAL)

EPSS: 0.20%

updated 2026-09-12T16:16:40.140000

2 posts

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.

thehackerwire@mastodon.social at 2026-09-12T20:00:36.000Z ##

🔴 CVE-2026-81402 - Critical (9.8)

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T20:00:36.000Z ##

🔴 CVE-2026-81402 - Critical (9.8)

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80494
(8.6 HIGH)

EPSS: 0.16%

updated 2026-09-12T16:16:39.867000

2 posts

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.

thehackerwire@mastodon.social at 2026-09-12T20:00:24.000Z ##

🟠 CVE-2026-80494 - High (8.6)

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T20:00:24.000Z ##

🟠 CVE-2026-80494 - High (8.6)

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80491
(8.6 HIGH)

EPSS: 0.19%

updated 2026-09-12T16:16:39.737000

2 posts

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-09-12T20:00:13.000Z ##

🟠 CVE-2026-80491 - High (8.6)

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T20:00:13.000Z ##

🟠 CVE-2026-80491 - High (8.6)

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77006
(9.6 CRITICAL)

EPSS: 0.11%

updated 2026-09-12T16:16:38.670000

2 posts

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.

thehackerwire@mastodon.social at 2026-09-12T23:00:13.000Z ##

🔴 CVE-2026-77006 - Critical (9.6)

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T23:00:13.000Z ##

🔴 CVE-2026-77006 - Critical (9.6)

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77005
(9.6 CRITICAL)

EPSS: 0.15%

updated 2026-09-12T16:16:38.523000

2 posts

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.

thehackerwire@mastodon.social at 2026-09-12T23:00:01.000Z ##

🔴 CVE-2026-77005 - Critical (9.6)

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T23:00:01.000Z ##

🔴 CVE-2026-77005 - Critical (9.6)

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15451
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-12T15:31:49

2 posts

The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like role or ID. This makes it possible for authenticated attackers, with subscriber-lev

thehackerwire@mastodon.social at 2026-09-12T14:00:24.000Z ##

🟠 CVE-2026-15451 - High (8.8)

The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'user...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T14:00:24.000Z ##

🟠 CVE-2026-15451 - High (8.8)

The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'user...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90537
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-12T15:31:49

2 posts

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid dail

thehackerwire@mastodon.social at 2026-09-12T14:00:13.000Z ##

🟠 CVE-2026-90537 - High (8.2)

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T14:00:13.000Z ##

🟠 CVE-2026-90537 - High (8.2)

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90553
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-12T13:16:53.887000

2 posts

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.

thehackerwire@mastodon.social at 2026-09-12T13:59:48.000Z ##

🟠 CVE-2026-90553 - High (7.8)

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T13:59:48.000Z ##

🟠 CVE-2026-90553 - High (7.8)

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85706
(10.0 CRITICAL)

EPSS: 1.15%

updated 2026-09-12T11:16:33.373000

36 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

7 repos

https://github.com/mhtsec/CVE-2026-85706

https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab

https://github.com/ynsmroztas/GitLabSniper

https://github.com/guneykabel/cve-2026-85706

https://github.com/FlowerWitch/CVE-2026-85706_docker_exp

https://github.com/solivaquaant/CVE-2026-85706

https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc

cyberworldops at 2026-09-12T20:20:00.745Z ##

GitLab CVE-2026-85706 is a maximum-severity path traversal in the repository commits API enabling unauthenticated arbitrary file read on self-managed servers. CISA added it to KEV with a three-day deadline, signaling active exploitation risk. Patch immediately and review for anomalous access to credentials and secrets.

cyberworldops.eu/en/gitlab-pat

##

security_crawler_carl at 2026-09-12T20:01:23.523Z ##

That is a faster turnaround than most people's pizza delivery.

Patch GitLab immediately to remediate CVE-2026-85706 — your self-managed server is the featured product in someone else's highlight reel.

Reward: Complimentary sponsorship credit from Deferred Maintenance Inc. Your inaction keeps them in business.

securityweek.com/gitlab-vulner

(2/2)

##

security_crawler_carl at 2026-09-12T20:01:23.359Z ##

🏆 New Achievement! Speed-Run Sponsored by Your Unpatched GitLab!

This achievement is brought to you by Deferred Maintenance Inc. — when you absolutely, positively need unauthenticated strangers reading every file on your server within a single HTTP request. CVE-2026-85706 scored a perfect ten out of ten on the CVSS scale, because some bugs don't do half measures. GitLab dropped patches on a Thursday. By Friday, WatchTowr was already watching wild exploitation probes roll in. One day. (1/2)

##

undercodenews@mastodon.social at 2026-09-12T18:44:35.000Z ##

GitLab CVSS 100 Vulnerability Reportedly Exploited Within 24 Hours, Leaving Self-Managed Servers Under Immediate Threat + Video

A Critical GitLab Warning for Defenders A critical security vulnerability in GitLab has reportedly moved from public disclosure to active exploitation in roughly a single day. Tracked as CVE-2026-85706, the flaw carries the highest possible CVSS score of 10.0, making it one of the most urgent vulnerabilities facing organizations operating…

undercodenews.com/gitlab-cvss-

##

Matchbook3469@mastodon.social at 2026-09-12T18:12:02.000Z ##

🔵 THREAT INTELLIGENCE

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

Vulnerability | CRITICAL
CVEs: CVE-2026-85706

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes...

Full analysis:
yazoul.net/news/article/gitlab

by Yazoul AI

#CyberSecurity #CVE #SecurityOps

##

netsecio@mastodon.social at 2026-09-12T17:43:52.000Z ##

📰 GitLab Patches Critical CVSS 10.0 Path Traversal Vulnerability

GitLab releases emergency patches for a critical CVSS 10.0 path traversal flaw (CVE-2026-85706). Unauthenticated attackers can read arbitrary files. Active scanning detected. Upgrade self-managed instances NOW. #GitLab #CVE #CyberSecurity #PatchNow

🔗 cyber.netsecops.io/articles/gi

##

rxerium at 2026-09-12T16:36:01.746Z ##

🚨 Detection for the actively exploited GitLab vulnerability tagged as CVE-2026-85706 (CVSS 10.0) available here:
github.com/projectdiscovery/nu

##

Matchbook3469@mastodon.social at 2026-09-12T11:15:42.000Z ##

🔴 New security advisory:

CVE-2026-85706 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#CVE #VulnerabilityManagement #CyberSec

##

obivan at 2026-09-12T08:46:52.501Z ##

PoC for unauthenticated arbitrary file read on Gitlab github.com/guneykabel/cve-2026

##

sayzard@mastodon.sayzard.org at 2026-09-12T08:39:18.000Z ##

Improper Limitation of a Pathname to a Restricted Directory in GitLab 10/10

GitLab CE/EE의 Repository Commits API에서 경로 제한(path confinement)과 인증 검증이 불완전해 발생한 치명적 경로 탐색 취약점(CWE-22)입니다. 공격자는 인증 없이 조작된 경로를 통해 GitLab 서버의 임의 파일을 읽을 수 있으며, CVSS 3.1 기준 10.0(Critical)으로 평가됩니다. 영향 버전은 18.7 이상 19.1.8 미만, 19.2.0 이상 19.2.6 미만, 19.3.0 이상 19.3.2 미만이며, 각각 19.1.8·19.2.6·19.3.2 이상으로 즉시 업데이트해야 합니다. GitLab은 소스...

cve.org/CVERecord?id=CVE-2026-

##

beyondmachines1 at 2026-09-12T08:01:13.477Z ##

GitLab Patches Critical Path Traversal Flaw Under Active Exploitation

GitLab released emergency patches for 18 vulnerabilities, including a CVSS 10.0 path traversal flaw (CVE-2026-85706) that allows unauthenticated attackers to read sensitive server files and is currently seeing active probes.

**If you run a self-hosted GitLab instance, update it now to version 19.3.2, 19.2.6, or 19.1.8. One of these flaws is already being exploited and lets anyone read files off your server without logging in. All it takes is one public project to exist on the instance. If you can't patch right away, take the instance off the public internet and check your logs for POST requests to the repository commits API containing a "file.path" parameter to see if you've already been probed.**

beyondmachines.net/event_detai

##

undercodenews@mastodon.social at 2026-09-12T05:07:57.000Z ##

CISA Sounds the Alarm: Actively Exploited GitLab Flaw Could Expose Secrets and CI/CD Infrastructure

A Dangerous New Entry in CISA’s Exploited Vulnerabilities Catalog A serious security warning has emerged around GitLab after U.S. cybersecurity authorities identified active exploitation of a critical vulnerability capable of exposing arbitrary files from affected servers. The flaw, tracked as CVE-2026-85706, affects both GitLab Community Edition and Enterprise Edition…

undercodenews.com/cisa-sounds-

##

cyberworldops at 2026-09-12T04:20:00.522Z ##

GitLab path-traversal CVE-2026-85706 (CVSS 10.0) is being exploited in the wild one day after disclosure. It allows unauthenticated arbitrary file read with a single HTTP request, exposing secrets and enabling further compromise. Prioritize immediate patching and review logs.

cyberworldops.eu/en/critical-g

##

thehackerwire@mastodon.social at 2026-09-12T04:00:22.000Z ##

🔴 CVE-2026-85706 - Critical (10)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab serve...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

threatnoir at 2026-09-12T01:05:48.700Z ##

⚠️ CRITICAL: GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab patched a CVSS 10.0 unauthenticated file-read vulnerability (CVE-2026-85706) in the repository commits API that allows attackers to read arbitrary files from affected servers. In-the-wild probes are already active. Attackers can extract credentials, SSH keys, and other sensitive data without…

threatnoir.com/focus

🤖 AI generated summary

##

cyberworldops@infosec.exchange at 2026-09-12T20:20:00.000Z ##

GitLab CVE-2026-85706 is a maximum-severity path traversal in the repository commits API enabling unauthenticated arbitrary file read on self-managed servers. CISA added it to KEV with a three-day deadline, signaling active exploitation risk. Patch immediately and review for anomalous access to credentials and secrets. #GitLab #CisaKev #InfoSec

cyberworldops.eu/en/gitlab-pat

##

security_crawler_carl@infosec.exchange at 2026-09-12T20:01:23.000Z ##

That is a faster turnaround than most people's pizza delivery.

Patch GitLab immediately to remediate CVE-2026-85706 — your self-managed server is the featured product in someone else's highlight reel.

Reward: Complimentary sponsorship credit from Deferred Maintenance Inc. Your inaction keeps them in business.

securityweek.com/gitlab-vulner

#GitLab #CyberSecurity #ZeroDay #PathTraversal #CVE #PatchedOrPerish (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-12T20:01:23.000Z ##

🏆 New Achievement! Speed-Run Sponsored by Your Unpatched GitLab!

This achievement is brought to you by Deferred Maintenance Inc. — when you absolutely, positively need unauthenticated strangers reading every file on your server within a single HTTP request. CVE-2026-85706 scored a perfect ten out of ten on the CVSS scale, because some bugs don't do half measures. GitLab dropped patches on a Thursday. By Friday, WatchTowr was already watching wild exploitation probes roll in. One day. (1/2)

##

netsecio@mastodon.social at 2026-09-12T17:43:52.000Z ##

📰 GitLab Patches Critical CVSS 10.0 Path Traversal Vulnerability

GitLab releases emergency patches for a critical CVSS 10.0 path traversal flaw (CVE-2026-85706). Unauthenticated attackers can read arbitrary files. Active scanning detected. Upgrade self-managed instances NOW. #GitLab #CVE #CyberSecurity #PatchNow

🔗 cyber.netsecops.io/articles/gi

##

rxerium@infosec.exchange at 2026-09-12T16:36:01.000Z ##

🚨 Detection for the actively exploited GitLab vulnerability tagged as CVE-2026-85706 (CVSS 10.0) available here:
github.com/projectdiscovery/nu

##

obivan@infosec.exchange at 2026-09-12T08:46:52.000Z ##

PoC for unauthenticated arbitrary file read on Gitlab github.com/guneykabel/cve-2026

##

beyondmachines1@infosec.exchange at 2026-09-12T08:01:13.000Z ##

GitLab Patches Critical Path Traversal Flaw Under Active Exploitation

GitLab released emergency patches for 18 vulnerabilities, including a CVSS 10.0 path traversal flaw (CVE-2026-85706) that allows unauthenticated attackers to read sensitive server files and is currently seeing active probes.

**If you run a self-hosted GitLab instance, update it now to version 19.3.2, 19.2.6, or 19.1.8. One of these flaws is already being exploited and lets anyone read files off your server without logging in. All it takes is one public project to exist on the instance. If you can't patch right away, take the instance off the public internet and check your logs for POST requests to the repository commits API containing a "file.path" parameter to see if you've already been probed.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-09-12T04:20:00.000Z ##

GitLab path-traversal CVE-2026-85706 (CVSS 10.0) is being exploited in the wild one day after disclosure. It allows unauthenticated arbitrary file read with a single HTTP request, exposing secrets and enabling further compromise. Prioritize immediate patching and review logs. #GitLab #PathTraversal #ThreatIntel

cyberworldops.eu/en/critical-g

##

thehackerwire@mastodon.social at 2026-09-12T04:00:22.000Z ##

🔴 CVE-2026-85706 - Critical (10)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab serve...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

threatnoir@infosec.exchange at 2026-09-12T01:05:48.000Z ##

⚠️ CRITICAL: GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab patched a CVSS 10.0 unauthenticated file-read vulnerability (CVE-2026-85706) in the repository commits API that allows attackers to read arbitrary files from affected servers. In-the-wild probes are already active. Attackers can extract credentials, SSH keys, and other sensitive data without…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

secdb@infosec.exchange at 2026-09-11T21:00:27.000Z ##

🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-42016 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-42018 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-84869 (secdb.nttzen.cloud/cve/detail/)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: connectwise.com/company/trust/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85706 (secdb.nttzen.cloud/cve/detail/)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: docs.gitlab.com/releases/patch ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706

##

ssvc@infosec.exchange at 2026-09-11T20:20:10.000Z ##

@cR0w no mention of exploitation from CNA GitLab

CVE-2026-85706 - Path Traversal issue in repository commits API impacts GitLab CE/EE

GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Impacted Versions: GitLab CE/EE: all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2
CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)

Thanks s3ntago for reporting this vulnerability through our HackerOne bug bounty program.

docs.gitlab.com/releases/patch

##

cisakevtracker@mastodon.social at 2026-09-11T20:00:54.000Z ##

CVE ID: CVE-2026-85706
Vendor: GitLab
Product: Community Edition and Enterprise Edition
Date Added: 2026-09-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cR0w@infosec.exchange at 2026-09-11T19:55:48.000Z ##

CVE-2026-85706 is now in the KEV but the CVE still isn't published. LMAO. Go hack and patch more GitLab shit.

##

DarkWebInformer@infosec.exchange at 2026-09-11T17:30:12.000Z ##

🚨 CVE-2026-85706: An unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1

PoC: github.com/guneykabel/cve-2026

##

DarkWebInformer@infosec.exchange at 2026-09-11T17:24:17.000Z ##

🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure

Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances.

The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.

Affected versions include:

• GitLab 18.7 through versions before 19.1.8
• GitLab 19.2 through versions before 19.2.6
• GitLab 19.3 through versions before 19.3.2

GitLab disclosed and patched the vulnerability on September 10.

Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow.

Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.

GitLab.com is already patched.

Source: docs.gitlab.com/releases/patch

##

jbhall56@infosec.exchange at 2026-09-11T14:05:07.000Z ##

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. bleepingcomputer.com/news/secu

##

guru@thecybersecguru.com at 2026-09-11T13:16:52.000Z ##

Critical GitLab Vulnerabilities Exposed: Deep Dive into the CVSS 10.0 Path Traversal (CVE-2026-85706) & GraphQL Exploits

GitLab fixes CVE-2026-85706, a CVSS 10.0 unauthenticated path traversal flaw, alongside CVE-2026-87719. Learn affected versions and patch now

thecybersecguru.com/news/gitla

##

tugatech@masto.pt at 2026-09-11T12:53:11.000Z ##

GitLab alerta para vulnerabilidade de gravidade máxima e pede atualização imediata. A falha, identificada como CVE-2026-85706, foi descoberta por um investigador de segurança e reportada através do programa de recompensas de bugs do HackerOne. 🚨

🔗 tugatech.com.pt/t90842-gitlab-

#alerta #gitlab #vulnerabilidade 

##

oversecurity@mastodon.social at 2026-09-11T12:00:50.000Z ##

GitLab urges users to patch max severity path traversal flaw

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706.

🔗️ [Bleepingcomputer] link.is.it/jdshdd

##

DailyCyberSecurity@infosec.exchange at 2026-09-11T00:18:04.000Z ##

GitLab patched critical GitLab vulnerabilities, led by CVE-2026-85706 with a CVSS 10.0 score. Update your server now to protect source code from exposure.

#GitLab #CVE202685706 #Vulnerabilities #DevSecOps #Cybersecurity
securityonline.info/gitlab-vul

##

CVE-2026-16482
(7.5 HIGH)

EPSS: 0.34%

updated 2026-09-12T09:33:41

2 posts

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries

thehackerwire@mastodon.social at 2026-09-12T09:00:55.000Z ##

🟠 CVE-2026-16482 - High (7.5)

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied param...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T09:00:55.000Z ##

🟠 CVE-2026-16482 - High (7.5)

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied param...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78159
(9.8 CRITICAL)

EPSS: 0.76%

updated 2026-09-12T09:33:41

4 posts

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it p

offseq at 2026-09-12T09:00:24.081Z ##

CVE-2026-78159: CRITICAL RCE in The Events Calendar (<=6.17.3). Unauthenticated attackers can run arbitrary code via crafted comments. Disable comments on tribe_events posts to mitigate. CVSS 9.8. Details: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-12T08:59:59.000Z ##

🔴 CVE-2026-78159 - Critical (9.8)

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-arr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-12T09:00:24.000Z ##

CVE-2026-78159: CRITICAL RCE in The Events Calendar (<=6.17.3). Unauthenticated attackers can run arbitrary code via crafted comments. Disable comments on tribe_events posts to mitigate. CVSS 9.8. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #RCE

##

thehackerwire@mastodon.social at 2026-09-12T08:59:59.000Z ##

🔴 CVE-2026-78159 - Critical (9.8)

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-arr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85200
(7.5 HIGH)

EPSS: 0.76%

updated 2026-09-12T08:16:24.810000

2 posts

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sen

thehackerwire@mastodon.social at 2026-09-12T09:00:45.000Z ##

🟠 CVE-2026-85200 - High (7.5)

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T09:00:45.000Z ##

🟠 CVE-2026-85200 - High (7.5)

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78175
(8.8 HIGH)

EPSS: 0.59%

updated 2026-09-12T08:16:24.507000

2 posts

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler lacking any capability or role check, relying solely on a nonce, while also passing attacker-supplied values through `esc_sq

thehackerwire@mastodon.social at 2026-09-12T09:00:09.000Z ##

🟠 CVE-2026-78175 - High (8.8)

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T09:00:09.000Z ##

🟠 CVE-2026-78175 - High (8.8)

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78006
(9.8 CRITICAL)

EPSS: 0.78%

updated 2026-09-12T08:16:24.240000

4 posts

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attri

1 repos

https://github.com/DeadExpl0it/CVE-2026-78006-POC

offseq at 2026-09-12T10:30:24.457Z ##

CVE-2026-78006: CRITICAL RCE in The Events Calendar plugin (<=6.17.4) for WordPress. Unauthenticated attackers can exploit comments to run code on the server. Disable event comments now & check for patches. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-12T08:59:50.000Z ##

🔴 CVE-2026-78006 - Critical (9.8)

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-12T10:30:24.000Z ##

CVE-2026-78006: CRITICAL RCE in The Events Calendar plugin (<=6.17.4) for WordPress. Unauthenticated attackers can exploit comments to run code on the server. Disable event comments now & check for patches. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #RCE #Vuln

##

thehackerwire@mastodon.social at 2026-09-12T08:59:50.000Z ##

🔴 CVE-2026-78006 - Critical (9.8)

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86093
(7.5 HIGH)

EPSS: 0.47%

updated 2026-09-12T04:16:45.040000

1 posts

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.

thehackerwire@mastodon.social at 2026-09-11T00:01:55.000Z ##

🟠 CVE-2026-86093 - High (7.5)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81940
(8.8 HIGH)

EPSS: 0.54%

updated 2026-09-12T04:16:39.240000

1 posts

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

thehackerwire@mastodon.social at 2026-09-11T00:02:16.000Z ##

🟠 CVE-2026-81940 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87719
(9.9 CRITICAL)

EPSS: 0.61%

updated 2026-09-12T03:30:28

3 posts

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server objec

thehackerwire@mastodon.social at 2026-09-12T04:00:11.000Z ##

🔴 CVE-2026-87719 - Critical (9.9)

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T04:00:11.000Z ##

🔴 CVE-2026-87719 - Critical (9.9)

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

guru@thecybersecguru.com at 2026-09-11T13:16:52.000Z ##

Critical GitLab Vulnerabilities Exposed: Deep Dive into the CVSS 10.0 Path Traversal (CVE-2026-85706) & GraphQL Exploits

GitLab fixes CVE-2026-85706, a CVSS 10.0 unauthenticated path traversal flaw, alongside CVE-2026-87719. Learn affected versions and patch now

thecybersecguru.com/news/gitla

##

CVE-2026-90460(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-09-12T00:31:35

2 posts

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the /v3/credentials API. EC2-derived tokens can additionally read credential blobs, exposing TOTP MFA seeds and other secrets. Also, PATCH

offseq at 2026-09-12T03:00:25.358Z ##

CVE-2026-90460: OpenStack Keystone <29.0.3 HIGH risk flaw allows delegated tokens to manage credentials & read sensitive data (MFA seeds) via /v3/credentials. Limit delegated token use & monitor access. Patch status pending. radar.offseq.com/threat/an-iss

##

offseq@infosec.exchange at 2026-09-12T03:00:25.000Z ##

CVE-2026-90460: OpenStack Keystone <29.0.3 HIGH risk flaw allows delegated tokens to manage credentials & read sensitive data (MFA seeds) via /v3/credentials. Limit delegated token use & monitor access. Patch status pending. radar.offseq.com/threat/an-iss #OffSeq #OpenStack #Infosec

##

CVE-2026-89266
(8.2 HIGH)

EPSS: 0.47%

updated 2026-09-12T00:31:35

2 posts

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.

thehackerwire@mastodon.social at 2026-09-12T00:59:49.000Z ##

🟠 CVE-2026-89266 - High (8.2)

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T00:59:49.000Z ##

🟠 CVE-2026-89266 - High (8.2)

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90456(CVSS UNKNOWN)

EPSS: 0.25%

updated 2026-09-12T00:31:35

2 posts

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.

offseq at 2026-09-12T00:00:35.043Z ##

CISA Malcolm (<=26.05.x) faces CRITICAL risk: CVE-2026-90456 allows admin takeover via default creds in inventory component if setup isn't run. Ensure unique passwords! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-12T00:00:35.000Z ##

CISA Malcolm (<=26.05.x) faces CRITICAL risk: CVE-2026-90456 allows admin takeover via default creds in inventory component if setup isn't run. Ensure unique passwords! radar.offseq.com/threat/cve-20 #OffSeq #CISAMalcolm #CVE202690456 #infosec

##

CVE-2026-49846
(7.5 HIGH)

EPSS: 0.34%

updated 2026-09-11T22:16:37.537000

1 posts

libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".." sequences intact, enabling path traversal in any consumer that later joins the URI wit

thehackerwire@mastodon.social at 2026-09-11T22:59:58.000Z ##

🟠 CVE-2026-49846 - High (7.5)

libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonica...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42018
(7.5 HIGH)

EPSS: 0.92%

updated 2026-09-11T21:32:08

9 posts

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

thecybermind at 2026-09-12T14:40:36.719Z ##

CRITICAL SOC ALERT: CVE-2026-42018 exposes JFrog Artifactory via improper auth and token leakage. Active KEV exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to neutralize attacker persistence. thecybermind.co/9t6b

##

thecybermind at 2026-09-12T13:46:54.425Z ##

CRITICAL CISA KEV ALERT: CVE-2026-42018 targets JFrog Artifactory via improper auth and token leakage. Active exploitation verified. Access our CSUITE Brief for technical execution vectors, asset integrity rules, and endpoint hardening steps to protect your enterprise perimeter. thecybermind.co/22sa

##

threatnoir at 2026-09-12T01:05:51.850Z ##

⚠️ CRITICAL: Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers are chaining multiple JFrog Artifactory vulnerabilities (CVE-2026-42018, CVE-2026-42016, CVE-2026-82329) to escalate from anonymous users to administrator control on self-hosted instances. This grants them ability to plant backdoors and execute arbitrary shell commands in your build pipel…

threatnoir.com/focus

🤖 AI generated summary

##

thecybermind@infosec.exchange at 2026-09-12T14:40:36.000Z ##

CRITICAL SOC ALERT: CVE-2026-42018 exposes JFrog Artifactory via improper auth and token leakage. Active KEV exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to neutralize attacker persistence. thecybermind.co/9t6b

##

thecybermind@infosec.exchange at 2026-09-12T13:46:54.000Z ##

CRITICAL CISA KEV ALERT: CVE-2026-42018 targets JFrog Artifactory via improper auth and token leakage. Active exploitation verified. Access our CSUITE Brief for technical execution vectors, asset integrity rules, and endpoint hardening steps to protect your enterprise perimeter. thecybermind.co/22sa

##

threatnoir@infosec.exchange at 2026-09-12T01:05:51.000Z ##

⚠️ CRITICAL: Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers are chaining multiple JFrog Artifactory vulnerabilities (CVE-2026-42018, CVE-2026-42016, CVE-2026-82329) to escalate from anonymous users to administrator control on self-hosted instances. This grants them ability to plant backdoors and execute arbitrary shell commands in your build pipel…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

secdb@infosec.exchange at 2026-09-11T21:00:27.000Z ##

🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-42016 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-42018 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-84869 (secdb.nttzen.cloud/cve/detail/)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: connectwise.com/company/trust/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85706 (secdb.nttzen.cloud/cve/detail/)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: docs.gitlab.com/releases/patch ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706

##

cisakevtracker@mastodon.social at 2026-09-11T19:01:28.000Z ##

CVE ID: CVE-2026-42018
Vendor: JFrog
Product: Artifactory
Date Added: 2026-09-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops@infosec.exchange at 2026-09-11T18:30:01.000Z ##

Active exploitation chains CVE-2026-42018 and CVE-2026-42016 to bypass authentication on self-hosted JFrog Artifactory and deploy a Rust backdoor with C2. CVE-2026-82329 is also abused to create admin tokens. This enables full server takeover and supply chain compromise. #JFrog #Artifactory #SupplyChainSecurity

cyberworldops.eu/en/attackers-

##

CVE-2026-80995(CVSS UNKNOWN)

EPSS: 0.15%

updated 2026-09-11T21:31:31

2 posts

In the Linux kernel, the following vulnerability has been resolved: net: mctp: hold a reference to the route device in mctp_route_lookup() mctp_route_lookup() uses rt->dev without holding a reference on it. mctp_route_lookup_single() returns the route under RCU only, so the route's device can be torn down concurrently: mctp_dev_put() drops the last reference and synchronously kfree()s mdev->addr

offseq at 2026-09-12T04:30:24.311Z ##

CVE-2026-80995: HIGH severity use-after-free in Linux kernel MCTP code lets unprivileged users trigger memory corruption or DoS. Fix: update to patched kernel when released. Details: radar.offseq.com/threat/in-the

##

offseq@infosec.exchange at 2026-09-12T04:30:24.000Z ##

CVE-2026-80995: HIGH severity use-after-free in Linux kernel MCTP code lets unprivileged users trigger memory corruption or DoS. Fix: update to patched kernel when released. Details: radar.offseq.com/threat/in-the #OffSeq #Linux #Infosec #CVE #Vulnerability

##

CVE-2026-81000(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-09-11T21:31:31

2 posts

In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the re

offseq at 2026-09-12T01:30:23.675Z ##

CVE-2026-81000: Linux kernel TUN driver HIGH severity vulnerability fixed. Flaw in skb headroom calculation could trigger memory corruption. Update to patched kernel ASAP. 🐧 radar.offseq.com/threat/in-the

##

offseq@infosec.exchange at 2026-09-12T01:30:23.000Z ##

CVE-2026-81000: Linux kernel TUN driver HIGH severity vulnerability fixed. Flaw in skb headroom calculation could trigger memory corruption. Update to patched kernel ASAP. 🐧 radar.offseq.com/threat/in-the #OffSeq #Linux #Vulnerability #BlueTeam

##

CVE-2026-80981(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-09-11T21:31:27

2 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() smc_llc_srv_add_link() keeps add_llc pointing into the queue entry: add_llc = &qentry->msg.add_link; smc_llc.c:1482 ... smc_llc_save_add_link_info(link_new, add_llc); smc_llc.c:1494 smc_llc_flow_qentry_del(&lgr->llc_flow_lcl); smc_llc.c:1495 ..

offseq at 2026-09-12T06:00:24.830Z ##

CVE-2026-80981: Linux kernel net/smc HIGH severity use-after-free in smc_llc_srv_add_link(). Risk of memory corruption & escalation. Patch when available! Details: radar.offseq.com/threat/in-the

##

offseq@infosec.exchange at 2026-09-12T06:00:24.000Z ##

CVE-2026-80981: Linux kernel net/smc HIGH severity use-after-free in smc_llc_srv_add_link(). Risk of memory corruption & escalation. Patch when available! Details: radar.offseq.com/threat/in-the #OffSeq #Linux #Infosec #Vulnerability

##

CVE-2026-79395
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-09-11T21:31:23

1 posts

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin

thehackerwire@mastodon.social at 2026-09-11T22:02:03.000Z ##

🔴 CVE-2026-79395 - Critical (9.8)

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentica...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79393
(7.5 HIGH)

EPSS: 0.53%

updated 2026-09-11T21:31:22

1 posts

A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.

thehackerwire@mastodon.social at 2026-09-11T19:59:46.000Z ##

🟠 CVE-2026-79393 - High (7.5)

A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a deni...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84869
(9.9 CRITICAL)

EPSS: 0.69%

updated 2026-09-11T21:31:17

4 posts

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

DailyCyberSecurity at 2026-09-12T07:12:00.953Z ##

A critical ConnectWise ScreenConnect vulnerability, CVE-2026-84869, is actively exploited in the wild. Patch your servers now to stop remote attacks.

securityonline.info/connectwis

##

DailyCyberSecurity@infosec.exchange at 2026-09-12T07:12:00.000Z ##

A critical ConnectWise ScreenConnect vulnerability, CVE-2026-84869, is actively exploited in the wild. Patch your servers now to stop remote attacks.

#ConnectWise #ScreenConnect #CVE202684869 #Cybersecurity #Vulnerability

securityonline.info/connectwis

##

secdb@infosec.exchange at 2026-09-11T21:00:27.000Z ##

🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-42016 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-42018 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-84869 (secdb.nttzen.cloud/cve/detail/)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: connectwise.com/company/trust/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85706 (secdb.nttzen.cloud/cve/detail/)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: docs.gitlab.com/releases/patch ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706

##

cisakevtracker@mastodon.social at 2026-09-11T19:00:57.000Z ##

CVE ID: CVE-2026-84869
Vendor: ConnectWise
Product: ScreenConnect
Date Added: 2026-09-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-42016
(8.1 HIGH)

EPSS: 0.89%

updated 2026-09-11T21:31:06

5 posts

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

threatnoir at 2026-09-12T01:05:51.850Z ##

⚠️ CRITICAL: Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers are chaining multiple JFrog Artifactory vulnerabilities (CVE-2026-42018, CVE-2026-42016, CVE-2026-82329) to escalate from anonymous users to administrator control on self-hosted instances. This grants them ability to plant backdoors and execute arbitrary shell commands in your build pipel…

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-12T01:05:51.000Z ##

⚠️ CRITICAL: Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers are chaining multiple JFrog Artifactory vulnerabilities (CVE-2026-42018, CVE-2026-42016, CVE-2026-82329) to escalate from anonymous users to administrator control on self-hosted instances. This grants them ability to plant backdoors and execute arbitrary shell commands in your build pipel…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

secdb@infosec.exchange at 2026-09-11T21:00:27.000Z ##

🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-42016 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-42018 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-84869 (secdb.nttzen.cloud/cve/detail/)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: connectwise.com/company/trust/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85706 (secdb.nttzen.cloud/cve/detail/)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: docs.gitlab.com/releases/patch ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706

##

cisakevtracker@mastodon.social at 2026-09-11T19:01:13.000Z ##

CVE ID: CVE-2026-42016
Vendor: JFrog
Product: Artifactory
Date Added: 2026-09-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops@infosec.exchange at 2026-09-11T18:30:01.000Z ##

Active exploitation chains CVE-2026-42018 and CVE-2026-42016 to bypass authentication on self-hosted JFrog Artifactory and deploy a Rust backdoor with C2. CVE-2026-82329 is also abused to create admin tokens. This enables full server takeover and supply chain compromise. #JFrog #Artifactory #SupplyChainSecurity

cyberworldops.eu/en/attackers-

##

CVE-2026-8778
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-09-11T21:17:58.797000

1 posts

The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote

offseq@infosec.exchange at 2026-09-11T04:30:23.000Z ##

CVE-2026-8778 (CRITICAL): MIPL Grouped Checkout Fields for WooCommerce ≤1.2.2 suffers from unrestricted file upload due to missing file type validation. Remote code execution possible by unauthenticated attackers. Restrict uploads & monitor! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE20268778

##

CVE-2026-89260
(7.5 HIGH)

EPSS: 0.43%

updated 2026-09-11T21:17:58.153000

1 posts

MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions. Unauthenticated remote attackers can submit DOCTYPE declarations with external parameter ent

thehackerwire@mastodon.social at 2026-09-11T17:00:27.000Z ##

🟠 CVE-2026-89260 - High (7.5)

MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89042
(9.1 CRITICAL)

EPSS: 0.27%

updated 2026-09-11T21:17:56.573000

1 posts

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.

thehackerwire@mastodon.social at 2026-09-10T19:00:43.000Z ##

🔴 CVE-2026-89042 - Critical (9.1)

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62112
(7.6 HIGH)

EPSS: 0.28%

updated 2026-09-11T21:17:02.457000

1 posts

Editor SQL Injection in Amelia <= 2.4.9 versions.

CVE-2026-89771
(0 None)

EPSS: 0.16%

updated 2026-09-11T20:20:08.460000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix subbuf resize race with ring buffer readers trace_buffer subbuf_size is read lockless in ring_buffer_read_page() and ring_buffer_read_start(), while it can simultaneously be resized with ring_buffer_subbuf_order_set(). Instead of trace_buffer::subbuf_size, use bpage::order in ring_buffer_read_start() and ring_b

sigint@fosstodon.org at 2026-09-11T23:45:05.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-09-12

Ring buffer race between subbuf resize and readers can corrupt trace data or crash the kernel. If you rely on ftrace or perf for debugging on your boxes, get this patched before it bites you mid-trace.

🔗 thehackerwire.com/vulnerabilit

#Ubuntu #Linux #infosec

##

CVE-2026-54135
(7.5 HIGH)

EPSS: 0.55%

updated 2026-09-11T20:17:14.330000

1 posts

AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory exhaustion (OOM). In httpserver.cpp, the HttpServer::Request::content function reads the Content-Length header and direct

thehackerwire@mastodon.social at 2026-09-11T22:01:54.000Z ##

🟠 CVE-2026-54135 - High (7.5)

AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Den...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53952
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-09-11T20:17:14.060000

1 posts

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installatio

thehackerwire@mastodon.social at 2026-09-11T22:01:43.000Z ##

🔴 CVE-2026-53952 - Critical (9.8)

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a n...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89262
(7.5 HIGH)

EPSS: 0.31%

updated 2026-09-11T18:31:32

1 posts

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.

thehackerwire@mastodon.social at 2026-09-11T17:00:37.000Z ##

🟠 CVE-2026-89262 - High (7.5)

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89176
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-11T16:17:50.073000

1 posts

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can disrupt normal classroom operations, whereas impersonating a teacher can induce student computers to initiate connections, thereby gaining remote control o

thehackerwire@mastodon.social at 2026-09-11T11:00:25.000Z ##

🟠 CVE-2026-89176 - High (8.8)

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can di...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80462
(10.0 CRITICAL)

EPSS: 0.30%

updated 2026-09-11T15:32:48

4 posts

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

DailyCyberSecurity at 2026-09-12T01:42:24.777Z ##

Progress patched a critical Chef Automate vulnerability tracked as CVE-2026-80462. Fix this Chef Automate vulnerability to stop DevOps account takeovers.

securityonline.info/chef-autom

##

DailyCyberSecurity@infosec.exchange at 2026-09-12T01:42:24.000Z ##

Progress patched a critical Chef Automate vulnerability tracked as CVE-2026-80462. Fix this Chef Automate vulnerability to stop DevOps account takeovers.

#ChefAutomate #CVE202680462 #DevOpsSecurity #Cybersecurity #InfoSec

securityonline.info/chef-autom

##

thehackerwire@mastodon.social at 2026-09-11T15:00:28.000Z ##

🔴 CVE-2026-80462 - Critical (10)

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-11T13:30:34.000Z ##

CRITICAL vuln (CVE-2026-80462) in Progress Chef Automate (4.13.516 – 4.13.519): API gateway auth bypass enables unauth’d privilege escalation. Restrict API access & review logs until patch confirmed. radar.offseq.com/threat/cve-20 #OffSeq #ChefAutomate #vuln #CVE202680462

##

CVE-2026-89212
(8.6 HIGH)

EPSS: 0.33%

updated 2026-09-11T15:32:48

1 posts

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions.

thehackerwire@mastodon.social at 2026-09-11T15:00:05.000Z ##

🟠 CVE-2026-89212 - High (8.6)

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (includ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84390
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-09-11T15:32:48

1 posts

A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here>

beyondmachines1@infosec.exchange at 2026-09-10T09:01:13.000Z ##

Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line

Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.

**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-86060
(9.8 CRITICAL)

EPSS: 1.02%

updated 2026-09-11T15:32:27

3 posts

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable

1 repos

https://github.com/bahirul/cve-2026-86060

thecybermind@infosec.exchange at 2026-09-11T11:38:21.000Z ##

Executive alert: CVE-2026-86060 actively threatens MikroTik RouterOS infrastructure. Review board-ready risk evaluation protocols, network asset integrity measures, and strategic remediation steps to protect your enterprise value today.

thecybermind.co/stnk

##

secdb@infosec.exchange at 2026-09-10T21:00:32.000Z ##

🚨 [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-67277 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86060 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260910 #cisa20260910 #cve_2026_67277 #cve_2026_86060 #cve202667277 #cve202686060

##

cisakevtracker@mastodon.social at 2026-09-10T20:01:01.000Z ##

CVE ID: CVE-2026-86060
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-82100
(9.6 CRITICAL)

EPSS: 0.40%

updated 2026-09-11T15:17:06.230000

2 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

offseq@infosec.exchange at 2026-09-11T01:30:25.000Z ##

CVE-2026-82100: CRITICAL path traversal in IBM DataStage on Cloud Pak for Data 5.4.0.0 (CVSS 9.6). Remote authenticated attackers can cause denial of service via improper directory handling. Restrict access & monitor until patch confirmed. radar.offseq.com/threat/cve-20 #OffSeq #CVE202682100 #IBM #infosec

##

thehackerwire@mastodon.social at 2026-09-10T22:59:59.000Z ##

🔴 CVE-2026-82100 - Critical (9.6)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71416
(8.8 HIGH)

EPSS: 0.17%

updated 2026-09-11T15:17:03.373000

1 posts

Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket

thehackerwire@mastodon.social at 2026-09-11T15:00:16.000Z ##

🟠 CVE-2026-71416 - High (8.8)

Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47839
(0 None)

EPSS: 0.30%

updated 2026-09-11T15:17:02.193000

1 posts

A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses groupMappingMode: AS_SCOPES with a wildcard externalGroupsWhitelist entry.

offseq@infosec.exchange at 2026-09-11T10:30:25.000Z ##

Cloud Foundry UAA hit by CRITICAL vuln (CVE-2026-47839, CVSS 9.2): OIDC users with wildcard group mapping can gain uaa.admin. Review configs, avoid wildcards, and monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #CloudSecurity #CVE202647839 #Infosec

##

CVE-2026-82107
(9.6 CRITICAL)

EPSS: 0.36%

updated 2026-09-11T14:56:50.613000

2 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

offseq@infosec.exchange at 2026-09-11T03:00:24.000Z ##

CVE-2026-82107: CRITICAL vuln in IBM DataStage on Cloud Pak for Data 5.4.0.0 (CVSS 9.6). Authenticated attackers can bypass authentication & access sensitive data. No patch — limit access & monitor for abuse. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IBM #InfoSec

##

thehackerwire@mastodon.social at 2026-09-10T23:00:08.000Z ##

🔴 CVE-2026-82107 - Critical (9.6)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39821
(9.6 CRITICAL)

EPSS: 0.69%

updated 2026-09-11T13:17:49.237000

1 posts

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "examp

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-67277
(8.2 HIGH)

EPSS: 0.86%

updated 2026-09-11T12:52:29.533000

2 posts

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragment

secdb@infosec.exchange at 2026-09-10T21:00:32.000Z ##

🚨 [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-67277 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86060 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260910 #cisa20260910 #cve_2026_67277 #cve_2026_86060 #cve202667277 #cve202686060

##

cisakevtracker@mastodon.social at 2026-09-10T20:01:17.000Z ##

CVE ID: CVE-2026-67277
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-89259
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-09-11T12:33:34

1 posts

Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As a result, the restrictions intended by the fix for GHSA-x597-9fr4-5857 could still be bypassed, allowing a Node tool invoked

offseq@infosec.exchange at 2026-09-11T12:00:28.000Z ##

CVE-2026-89259 (CRITICAL): gohugoio Hugo <0.165.0 lets Node tools like TailwindCSS bypass security.exec.allow list, enabling file access outside project dirs. Upgrade to 0.165.0 or restrict exec.allow in hugo.toml. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Hugo #InfoSec

##

CVE-2026-86781
(5.3 MEDIUM)

EPSS: 0.12%

updated 2026-09-11T12:33:26

1 posts

The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download the site's TLS private key, certificates, and diagnostic logs.

offseq@infosec.exchange at 2026-09-11T07:30:24.000Z ##

CVE-2026-86781: SSL Zen plugin (<4.7.40) has a CRITICAL auth flaw — any WP user can download TLS private key & certs, risking site impersonation. Patch to 4.7.40+ now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #TLS

##

CVE-2026-80469
(8.3 HIGH)

EPSS: 0.23%

updated 2026-09-11T09:31:32

1 posts

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is required.

thehackerwire@mastodon.social at 2026-09-11T11:00:02.000Z ##

🟠 CVE-2026-80469 - High (8.3)

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of
attacker-controlled code. User interaction is required.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89178
(8.8 HIGH)

EPSS: 0.23%

updated 2026-09-11T09:31:31

1 posts

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker.

thehackerwire@mastodon.social at 2026-09-11T11:01:18.000Z ##

🟠 CVE-2026-89178 - High (8.8)

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student compute...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89177
(8.8 HIGH)

EPSS: 0.23%

updated 2026-09-11T09:31:31

1 posts

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.

thehackerwire@mastodon.social at 2026-09-11T11:01:05.000Z ##

🟠 CVE-2026-89177 - High (8.8)

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89174
(7.5 HIGH)

EPSS: 0.38%

updated 2026-09-11T09:31:31

1 posts

Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.

thehackerwire@mastodon.social at 2026-09-11T11:00:13.000Z ##

🟠 CVE-2026-89174 - High (7.5)

Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89060
(7.7 HIGH)

EPSS: 0.23%

updated 2026-09-11T06:31:14

1 posts

A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster identity to reference configuration resources outside its designated namespace. This can lead to the disclosure of sensitive hub Secrets to an attacker-controlled managed cluster.

offseq@infosec.exchange at 2026-09-11T06:00:25.000Z ##

Red Hat Advanced Cluster Management for Kubernetes 2 is affected by CVE-2026-89060 (HIGH, CVSS 7.7): managed-cluster identities may access hub Secrets outside their namespace due to authorization flaws. Monitor Red Hat and restrict permissions. radar.offseq.com/threat/cve-20 #OffSeq #Kubernetes #RedHat

##

CVE-2026-19584
(7.7 HIGH)

EPSS: 0.19%

updated 2026-09-11T04:17:34.343000

1 posts

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.

thehackerwire@mastodon.social at 2026-09-10T06:01:16.000Z ##

🟠 CVE-2026-19584 - High (7.7)

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77807
(7.5 HIGH)

EPSS: 0.68%

updated 2026-09-11T00:31:23

1 posts

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires

thehackerwire@mastodon.social at 2026-09-11T02:00:03.000Z ##

🟠 CVE-2026-77807 - High (7.5)

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84889
(8.8 HIGH)

EPSS: 0.53%

updated 2026-09-11T00:31:23

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

thehackerwire@mastodon.social at 2026-09-10T23:00:18.000Z ##

🟠 CVE-2026-84889 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87958
(8.1 HIGH)

EPSS: 0.21%

updated 2026-09-11T00:31:16

1 posts

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

thehackerwire@mastodon.social at 2026-09-11T00:02:05.000Z ##

🟠 CVE-2026-87958 - High (8.1)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19646
(9.1 CRITICAL)

EPSS: 0.52%

updated 2026-09-11T00:31:12

1 posts

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.

offseq@infosec.exchange at 2026-09-11T00:00:36.000Z ##

CVE-2026-19646 (CRITICAL, CVSS 9.1) affects IBM Common Licensing 9.0.x & ART 9.0. Improper Host header validation enables remote redirection to attacker domains. No patch yet — monitor IBM guidance. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IBM #InfoSec

##

CVE-2026-88044
(9.1 CRITICAL)

EPSS: 0.49%

updated 2026-09-10T22:47:10

1 posts

## Summary `serve/start` accepts protocol options in a per-server `proxyOpt` object. The FTP and S3 RC adapters parse that object and pass it to their server constructors, but the constructors decide whether proxy authentication is enabled by checking the process-global `proxy.Opt.AuthProxy` instead of the supplied `proxyOpt.AuthProxy`. When the process-global option is empty—the normal case whe

thehackerwire@mastodon.social at 2026-09-10T18:00:11.000Z ##

🔴 CVE-2026-88044 - Critical (9.1)

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88062(CVSS UNKNOWN)

EPSS: 0.40%

updated 2026-09-10T21:22:13

1 posts

## 2. Summary `POST /api/acp/agents` registers a custom ACP agent. The endpoint accepts user-controlled `binary` and `versionCommand` values. After saving the custom agent, the same request calls `refreshAgentCache()`, which triggers agent version detection. The version probe eventually runs: ```ts execFileSync(probe.command, probe.args, ...) ``` The only validation is `resolveVersionProbe(bina

DailyCyberSecurity@infosec.exchange at 2026-09-11T08:30:48.000Z ##

A critical CVSS 9.5 OmniRoute RCE flaw (CVE-2026-88062) has public PoC exploit code available. Upgrade your AI gateway immediately to prevent compromises.

#OmniRoute #CVE202688062 #CyberSecurity #InfoSec #RCE

securityonline.info/omniroute-

##

CVE-2026-89094
(9.9 CRITICAL)

EPSS: 0.50%

updated 2026-09-10T21:17:53.160000

3 posts

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

DarkWebInformer@infosec.exchange at 2026-09-11T21:37:54.000Z ##

🚨 CVE-2026-89094: Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

CVSS: 9.9

Foregejo Update/Notes: codeberg.org/forgejo/forgejo/s

##

DailyCyberSecurity@infosec.exchange at 2026-09-11T13:09:20.000Z ##

A critical Forgejo remote code execution flaw, tracked as CVE-2026-89094, threatens Git servers. Patch this Forgejo remote code execution bug today.

#Forgejo #RemoteCodeExecution #CVE202689094 #Cybersecurity #DevSecOps

securityonline.info/forgejo-re

##

cR0w@infosec.exchange at 2026-09-10T21:42:08.000Z ##

RE: infosec.exchange/@cR0w/1172478

CVE for this one:

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.9 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

##

CVE-2026-89086
(9.1 CRITICAL)

EPSS: 0.20%

updated 2026-09-10T21:17:52.570000

1 posts

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

thehackerwire@mastodon.social at 2026-09-10T20:59:58.000Z ##

🔴 CVE-2026-89086 - Critical (9.1)

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89054
(8.2 HIGH)

EPSS: 0.35%

updated 2026-09-10T20:17:31.973000

1 posts

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for event configuration and SNMP data collection (which enable and disable event definitions and data-collection sources) are re

thehackerwire@mastodon.social at 2026-09-10T21:00:08.000Z ##

🟠 CVE-2026-89054 - High (8.2)

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @patch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88045
(7.5 HIGH)

EPSS: 0.53%

updated 2026-09-10T19:54:25.810000

1 posts

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to multipart.NewRW().Reserve before reading request-body bytes. waitForTurn admits the current part and one oversized part when the buffer is empty despite -

thehackerwire@mastodon.social at 2026-09-10T18:00:22.000Z ##

🟠 CVE-2026-88045 - High (7.5)

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80352
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-09-10T18:33:12

1 posts

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before

DailyCyberSecurity@infosec.exchange at 2026-09-11T14:13:15.000Z ##

Three critical Apache Camel K vulnerabilities, including CVE-2026-80352, allow code injection and eval injection. Patch these critical flaws immediately.

#ApacheCamel #CamelK #Cybersecurity #CVE202680352 #InfoSec

securityonline.info/apache-cam

##

CVE-2026-89046
(8.2 HIGH)

EPSS: 0.57%

updated 2026-09-10T18:33:05

1 posts

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and reach the native frame-header parser, causing out-of-bounds memory reads that lead to information disclosure or JVM crashes.

thehackerwire@mastodon.social at 2026-09-10T19:00:33.000Z ##

🟠 CVE-2026-89046 - High (8.2)

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and rea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81467
(9.8 CRITICAL)

EPSS: 3.84%

updated 2026-09-10T18:33:04

1 posts

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

DailyCyberSecurity@infosec.exchange at 2026-09-11T08:40:47.000Z ##

Dell patched critical Dell ThinOS vulnerabilities, including CVE-2026-81467. Update your ThinOS clients now to stop remote code execution attacks.

#Dell #ThinOS #Cybersecurity #Vulnerabilities #CVE202681467

securityonline.info/dell-thino

##

CVE-2026-85228
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-09-10T18:33:04

1 posts

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above.

thehackerwire@mastodon.social at 2026-09-10T18:00:33.000Z ##

🔴 CVE-2026-85228 - Critical (9.1)

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65638(CVSS UNKNOWN)

EPSS: 3.20%

updated 2026-09-10T18:32:56

3 posts

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed t

beyondmachines1 at 2026-09-12T09:01:13.148Z ##

Critical ConfigServer Firewall Flaw Allows Unauthenticated Remote Command Execution

ConfigServer Security & Firewall (CSF) patched a critical shell injection vulnerability (CVE-2026-65638) in its MESSENGER service that allows unauthenticated remote code execution.

**If you run ConfigServer Security & Firewall (CSF) on your Linux or cPanel/WHM servers, update to version 16.30 right away (on cPanel systems run `yum clean all` then `/scripts/update-packages`) to close CVE-2026-65638. If you can't update immediately, turn the vulnerable feature off by setting `MESSENGER = 0` in `/etc/csf/csf.conf`, restart with `systemctl restart csf lfd`. Then check your logs for any unexpected commands run under the CSF service account.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-12T09:01:13.000Z ##

Critical ConfigServer Firewall Flaw Allows Unauthenticated Remote Command Execution

ConfigServer Security & Firewall (CSF) patched a critical shell injection vulnerability (CVE-2026-65638) in its MESSENGER service that allows unauthenticated remote code execution.

**If you run ConfigServer Security & Firewall (CSF) on your Linux or cPanel/WHM servers, update to version 16.30 right away (on cPanel systems run `yum clean all` then `/scripts/update-packages`) to close CVE-2026-65638. If you can't update immediately, turn the vulnerable feature off by setting `MESSENGER = 0` in `/etc/csf/csf.conf`, restart with `systemctl restart csf lfd`. Then check your logs for any unexpected commands run under the CSF service account.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-09-11T03:18:48.000Z ##

Two critical CSF plugin vulnerabilities, CVE-2026-65638 and CVE-2026-65639, allow remote code execution. Patch your ConfigServer firewall immediately.

#CSFPlugin #Cybersecurity #CVE202665639 #Vulnerabilities #InfoSec

securityonline.info/csf-plugin

##

CVE-2026-65639(CVSS UNKNOWN)

EPSS: 1.61%

updated 2026-09-10T18:32:56

1 posts

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that co

DailyCyberSecurity@infosec.exchange at 2026-09-11T03:18:48.000Z ##

Two critical CSF plugin vulnerabilities, CVE-2026-65638 and CVE-2026-65639, allow remote code execution. Patch your ConfigServer firewall immediately.

#CSFPlugin #Cybersecurity #CVE202665639 #Vulnerabilities #InfoSec

securityonline.info/csf-plugin

##

CVE-2026-88889
(7.8 HIGH)

EPSS: 0.62%

updated 2026-09-10T16:18:11.693000

1 posts

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve remote code execution when Renovate processes Maven Wrapper updates in binarySour

thehackerwire@mastodon.social at 2026-09-10T15:00:03.000Z ##

🟠 CVE-2026-88889 - High (7.8)

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inj...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88290
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-10T16:18:10.767000

1 posts

GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.

thehackerwire@mastodon.social at 2026-09-10T11:00:24.000Z ##

🟠 CVE-2026-88290 - High (7.5)

GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67593
(9.1 CRITICAL)

EPSS: 0.46%

updated 2026-09-10T16:17:45.273000

1 posts

A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes

DailyCyberSecurity@infosec.exchange at 2026-09-10T02:55:57.000Z ##

Critical Apache Artemis vulnerabilities, including CVE-2026-67593 and other ActiveMQ Artemis flaws, expose systems to denial of service and data exposure.

#ApacheArtemis #Cybersecurity #Vulnerabilities #ActiveMQ #CVE202667593

securityonline.info/apache-art

##

CVE-2026-13745
(0 None)

EPSS: 0.30%

updated 2026-09-10T16:17:07.727000

1 posts

A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.

offseq@infosec.exchange at 2026-09-10T09:00:26.000Z ##

CVE-2026-13745: CRITICAL vuln (CVSS 9.2) in Google Cloud Gemini CLI allows arbitrary code execution via untrusted .env files overriding GEMINI_CLI_HOME. Review .env file usage & restrict access. More info: radar.offseq.com/threat/cve-20 #OffSeq #GoogleCloud #Vulnerability #InfoSec

##

CVE-2026-88890
(8.5 HIGH)

EPSS: 0.29%

updated 2026-09-10T15:33:28

1 posts

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analyti

thehackerwire@mastodon.social at 2026-09-10T15:00:12.000Z ##

🟠 CVE-2026-88890 - High (8.5)

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88887
(8.6 HIGH)

EPSS: 0.30%

updated 2026-09-10T15:17:58.380000

1 posts

Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the follow-up request without verifying that the pagination URL has the same origin as the original registry. A malicious or compromised container registry can therefore s

offseq@infosec.exchange at 2026-09-10T13:30:26.000Z ##

CRITICAL: CVE-2026-88887 in renovatebot renovate enables open redirect — malicious registries can steal credentials using crafted Link headers. Upgrade to 44.11.2+ ASAP. More info: radar.offseq.com/threat/cve-20 #OffSeq #CVE202688887 #SupplyChain #ContainerSecurity

##

CVE-2026-88891
(8.3 HIGH)

EPSS: 0.25%

updated 2026-09-10T15:13:07.090000

1 posts

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation

thehackerwire@mastodon.social at 2026-09-10T15:00:22.000Z ##

🟠 CVE-2026-88891 - High (8.3)

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedul...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15019
(7.5 HIGH)

EPSS: 0.68%

updated 2026-09-10T14:39:13.757000

1 posts

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The product ownership check only verifies that some free, virtual, downloada

thehackerwire@mastodon.social at 2026-09-10T06:01:01.000Z ##

🟠 CVE-2026-15019 - High (7.5)

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the content...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18351
(9.8 CRITICAL)

EPSS: 0.77%

updated 2026-09-10T14:39:13.757000

1 posts

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via

2 repos

https://github.com/ChiefYoru/Exploit-CVE-2026-18351

https://github.com/JohenLastGen-JLG/CVE-2026-18351

offseq@infosec.exchange at 2026-09-10T03:00:31.000Z ##

CVE-2026-18351 (CRITICAL): addonsorg Drag and Drop File Upload for Elementor Forms <=1.6.0 lets unauthenticated attackers upload arbitrary files — enabling RCE. Restrict or disable plugin use until remediation. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #RCE

##

CVE-2026-19490
(9.8 CRITICAL)

EPSS: 5.60%

updated 2026-09-10T12:48:10.453000

1 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

2 repos

https://github.com/BishopFox/CVE-2026-19490-check

https://github.com/TarPeg007/CVE-2026-19490

obivan@infosec.exchange at 2026-09-11T07:51:26.000Z ##

Safely detect Citrix NetScaler SAML auth bypass (CVE-2026-19490) github.com/BishopFox/CVE-2026-

##

CVE-2025-25249
(8.1 HIGH)

EPSS: 2.40%

updated 2026-09-10T12:47:59.933000

2 posts

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

thecybermind@infosec.exchange at 2026-09-11T13:36:46.000Z ##

🚨 CRITICAL THREAT BRIEF: CVE-2025-25249 (Fortinet FortiOS & Gateway Infrastructure)

Active exploitation verified by the CISA KEV matrix has placed enterprise network perimeters at risk due to a critical heap-based buffer overflow vulnerability.

🔗 Read the full intelligence brief: thecybermind.co/us4c

##

cyberworldops@infosec.exchange at 2026-09-10T08:30:00.000Z ##

Fortinet CVE-2025-25249, an unauthenticated heap-based buffer overflow RCE, is being exploited at scale to deploy PivotC2 RAT. CISA added it to KEV on 2026-09-09 with remediation due 2026-09-12. Unpatched Fortinet perimeter devices should be assumed compromised and investigated for RAT persistence. #Fortinet #PivotC2 #ThreatIntel

cyberworldops.eu/en/fortinet-c

##

CVE-2026-78082(CVSS UNKNOWN)

EPSS: 0.49%

updated 2026-09-10T12:31:26

1 posts

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and psize_range_dropdown) by directly concatenating raw request parameters into SQL strings without quoting or type casting. An unauthentic

offseq@infosec.exchange at 2026-09-10T10:30:24.000Z ##

CVE-2026-78082: SP Property extension for Joomla v1.0.0-4.1.3 suffers CRITICAL SQL injection (CVSS 9.3). Unauthenticated attackers can extract DB data via blind injection. Patch status unknown — check vendor guidance. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #SQLi #Infosec

##

CVE-2026-8323
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-09-10T09:31:48

1 posts

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2.

thehackerwire@mastodon.social at 2026-09-10T11:00:35.000Z ##

🔴 CVE-2026-8323 - Critical (9.3)

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data.

This issue affects Access Control System: before Versiyon 2.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88289
(7.5 HIGH)

EPSS: 0.33%

updated 2026-09-10T09:31:44

1 posts

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.

thehackerwire@mastodon.social at 2026-09-10T11:00:14.000Z ##

🟠 CVE-2026-88289 - High (7.5)

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-0310(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-09-10T06:31:55

2 posts

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimiz

GossiTheDog@cyberplace.social at 2026-09-11T22:47:49.000Z ##

Palo-Alto are calling resellers and asking them to call customers to tell them to update their Palo-Alto PA and VM firewalls to cover CVE-2026-0310 - an unauthenticated XML parsing vulneraility which causes a buffer overflow leading to code execution, on the PA (physical) firewalls via the dataplane.
security.paloaltonetworks.com/

HT @databeestje

##

threatcodex@infosec.exchange at 2026-09-10T18:39:08.000Z ##

CVE-2026-0310: PAN-OS Buffer Overflow Can Enable Root RCE on PA-Series Firewalls
#CVE_2026_0310
socprime.com/blog/cve-2026-031

##

CVE-2026-14873
(8.0 HIGH)

EPSS: 0.24%

updated 2026-09-10T06:31:42

1 posts

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site

thehackerwire@mastodon.social at 2026-09-10T06:00:48.000Z ##

🟠 CVE-2026-14873 - High (8)

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their detail...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69730
(9.8 CRITICAL)

EPSS: 1.05%

updated 2026-09-10T04:18:14.773000

2 posts

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-19583
(9.9 CRITICAL)

EPSS: 0.60%

updated 2026-09-10T03:30:26

1 posts

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS

offseq@infosec.exchange at 2026-09-10T04:30:24.000Z ##

CVE-2026-19583: CRITICAL vuln in Rapid7 Velociraptor (<0.77.2) allows users w/ artifact scheduling rights to execute privileged artifacts like Linux.Sys.BashShell — risking full compromise. Restrict permissions, monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Infosec

##

CVE-2026-88069(CVSS UNKNOWN)

EPSS: 0.33%

updated 2026-09-10T00:30:34

1 posts

Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuring that the resulting destination remained within the intended extraction directory. An attacker able to submit a malicious file for analysis could use path traversal sequences or crafted paths to ca

offseq@infosec.exchange at 2026-09-10T01:30:24.000Z ##

CVE-2026-88069: Path traversal in pandora-analysis pandora (<=1.12.7) allows attackers to overwrite system/app files via crafted archives. Severity: CRITICAL (CVSS 9.3). No patch confirmed — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202688069 #vuln #infosec

##

CVE-2026-87491
(8.8 HIGH)

EPSS: 0.86%

updated 2026-09-09T21:31:35

4 posts

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

2 repos

https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.

https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter

security_crawler_carl@infosec.exchange at 2026-09-11T09:27:16.000Z ##

🏆 New Achievement! Seventh Inning Slaughter!

CHANGELOG v2026.09.09 — Google Chrome (Unscheduled Hotfix #7)

FIXED: Nothing you did. ADDED: CVE-2026-87491, an out-of-bounds write in the V8 JavaScript and WebAssembly engine, actively exploited in the wild via crafted HTML pages. Remote attackers can execute arbitrary code inside your browser sandbox, corrupt the heap, expose sensitive data, or simply crash the party. This is the seventh actively exploited Chrome zero-day patched this year. (1/2)

##

hackmag@infosec.exchange at 2026-09-10T22:32:52.000Z ##

⚪️ Google Chrome Patches Another Zero-Day Vulnerability

🗨️ Google developers have released an update for the Chrome browser that fixes 230 vulnerabilities, including a zero-day flaw in the V8 engine (CVE-2026-87491) that is already being exploited in attacks. The bug allows a remote attacker to achieve arbitrary code…

🔗 hackmag.com/news/chrome-7th-0d

#news

##

beyondmachines1@infosec.exchange at 2026-09-10T08:01:13.000Z ##

Google Patches Chrome Zero-Day and 229 Other Flaws in Version 153

Google released Chrome 153 to fix 230 vulnerabilities, including an actively exploited V8 zero-day (CVE-2026-87491) and five critical flaws in WebGL and Cast.

**This one is urgent, again. Actively exploited flaw and a bunch of fixes. Update Google Chrome to version 153.0.8010.36/.37 for Windows and macOS, or 153.0.8010.36 for Linux. Users of Microsoft Edge, Brave, Opera, Vivaldi, and other Chromium-based browsers. Don't delay, the tabs reopen after an update.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-09-10T00:06:04.000Z ##

⚠️ CRITICAL: Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google patched CVE-2026-87491, a zero-day out-of-bounds write in Chrome's V8 engine actively exploited in the wild. Attackers can execute arbitrary code within the browser sandbox via crafted HTML, potentially compromising any user visiting a malicious page. This is the seventh exploited Chrome zer…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 75.75%

updated 2026-09-09T21:31:33

9 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerab

Nuclei template

2 repos

https://github.com/CyberAuth/CVE-2026-20079

https://github.com/0xBlackash/CVE-2026-20079

netsecio@mastodon.social at 2026-09-12T17:43:34.000Z ##

📰 Cisco Firewall Flaws Actively Exploited by Ransomware & State Actors

Cisco warns multiple threat groups, including Qilin ransomware and state actors, are exploiting a critical auth bypass flaw (CVE-2026-20079) in Secure Firewall Management Center (FMC). CVSS 10.0. Patch now! #CVE202620079 #Cisco #Ransomware

🔗 cyber.netsecops.io/articles/ci

##

thenewoil@mastodon.thenewoil.org at 2026-09-11T20:00:01.000Z ##

#Cisco confirms CVE-2026-20079 #SecureFMC flaw exploited in attacks

bleepingcomputer.com/news/secu

#cybersecurity

##

security_crawler_carl@infosec.exchange at 2026-09-11T16:34:15.000Z ##

Reward: You've unlocked the Mandatory Remediation Sprint — a stackable negative buff. Enjoy your weekend.

tech-insider.org/cisco-fmc-cve

#CiscoFMC #CyberSecurity #CriticalVulnerability #Ransomware #CVSS10 #BudgetJustified (3/3)

##

security_crawler_carl@infosec.exchange at 2026-09-11T16:34:14.000Z ##

🏆 New Achievement! Perfect Score, Wrong Test!

Welcome, new player, to the Management Plane Tutorial. This is a mandatory segment. You cannot skip it. Your Cisco Firepower Management Console, CVE-2026-20079, has just rolled a CVSS 10.0 — a perfect score — and approximately 700 exposed instances are now enrolled in this questline whether they opted in or not. (1/3)

##

youranonnewsirc@nerdculture.de at 2026-09-11T04:26:21.000Z ##

The EU Cyber Resilience Act (CRA) takes effect today, September 11, mandating 24-hour vulnerability reporting from manufacturers of connected hardware and software. Simultaneously, state-backed threat actors are increasingly targeting EU officials via encrypted messaging apps for phishing attacks, and a critical Cisco Secure Firewall Management Center flaw (CVE-2026-20079) requires urgent patching. Geopolitically, tensions escalated in the Strait of Hormuz following Iranian claims of ship attacks after US actions, and conflicts continue in the Middle East. In technology, Google Threat Intelligence reported on an AI system capable of harvesting thousands of credentials autonomously.

#Cybersecurity #Geopolitics #TechNews

##

cyberworldops@infosec.exchange at 2026-09-10T17:00:00.000Z ##

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.

#CiscoFMC #ThreatIntelligence #VulnerabilityManagement #Qilin

cyberworldops.eu/en/cisco-fmc-

##

jbhall56@infosec.exchange at 2026-09-10T12:53:19.000Z ##

The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. bleepingcomputer.com/news/secu

##

beyondmachines1@infosec.exchange at 2026-09-10T10:01:13.000Z ##

Cisco Secure Firewall Management Center Under Active Attack

Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.

**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2–7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-09-10T00:50:00.000Z ##

Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC. Unauthenticated remote attackers can execute commands as root via crafted HTTP requests, compromising firewall management. Immediate patching and exposure review are critical. #CiscoFmc #AuthBypass #CriticalVulnerability

cyberworldops.eu/en/cisco-secu

##

CVE-2026-75170
(6.1 MEDIUM)

EPSS: 0.24%

updated 2026-09-09T20:20:34.260000

1 posts

Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoint of the HubCore platform (version 14.1.1) allows a remote unauthenticated attacker to inject arbitrary JavaScript into the application's response via the language POST parameter.

hugovalters@mastodon.social at 2026-09-12T07:10:02.000Z ##

CVE-2026-75170: Unauthenticated XSS in HubCore 14.1.1 via /loginController/doLogin language param. CVSS N/A, no patch yet. Attackers can inject arbitrary JS. Audit exposure and restrict access now. Details: valtersit.com/cve/CVE-2026-751 #CVE #infosec #XSS

##

CVE-2026-38961
(5.4 MEDIUM)

EPSS: 0.20%

updated 2026-09-09T20:17:22.207000

1 posts

Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data

hugovalters@mastodon.social at 2026-09-12T03:40:17.000Z ##

CVE-2026-38961: Stored XSS in Netgate pfSense RSS Widget (versions 26.03, 25.11.1, CE 2.8.1). Malicious feed titles execute JS for any authenticated user viewing the dashboard. CVSS: N/A. Unpatched—restrict RSS access now. Details: valtersit.com/cve/CVE-2026-389 #C

##

CVE-2026-17469
(5.3 MEDIUM)

EPSS: 0.21%

updated 2026-09-09T18:32:16

1 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.

hugovalters@mastodon.social at 2026-09-10T20:40:01.000Z ##

CVE-2026-17469: IBM i (7.3-7.6) DoS via off-by-one write in LPD queue parser. Local authenticated attacker can crash the service. CVSS 5.3. No patch yet. Lock down LPD access & monitor. Details: valtersit.com/cve/CVE-2026-174 #CVE #IBM #infosec

##

CVE-2026-78745
(9.8 CRITICAL)

EPSS: 0.72%

updated 2026-09-09T16:04:24.933000

1 posts

An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)

1 repos

https://github.com/n0c71v3x/CVE-2026-78745

hugovalters@mastodon.social at 2026-09-12T21:20:05.000Z ##

CVE-2026-78745: Unpatched flaw in HiDPT Android (Hi3751V350/V352E) allows remote code execution via ADB daemon. Risk is critical if ADB exposed. CVSS N/A. Check exposure and restrict ADB now. Details: valtersit.com/cve/CVE-2026-787 #CVE #Android #infosec

##

CVE-2026-73324
(6.5 MEDIUM)

EPSS: 0.33%

updated 2026-09-09T15:35:16

4 posts

VLC media player copies an RTSP response line into a fixed buffer without guaranteeing termination and then treats that buffer as a C string. RtspReadLine in modules/access/rtsp/access.c calls strncpy with the full buffer length, which writes no terminator when the source line is at least as long as the destination, and rtsp_get in modules/access/rtsp/rtsp.c allocates that buffer as BUF_SIZE bytes

guru@thecybersecguru.com at 2026-09-12T17:11:54.000Z ##

VLC Media Player hit by two critical security flaws: heap corruption and memory disclosure putting millions at risk

Two critical VLC Media Player vulnerabilities, CVE-2026-56711 and CVE-2026-73324, expose users to heap corruption and memory disclosure. Here’s what to do

thecybersecguru.com/news/vlc-m

##

guru@thecybersecguru.com at 2026-09-12T17:11:54.000Z ##

VLC Media Player hit by two critical security flaws: heap corruption and memory disclosure putting millions at risk

Two critical VLC Media Player vulnerabilities, CVE-2026-56711 and CVE-2026-73324, expose users to heap corruption and memory disclosure. Here’s what to do

thecybersecguru.com/news/vlc-m

##

DarkWebInformer@infosec.exchange at 2026-09-11T16:37:27.000Z ##

🚨 Two VLC Media Player flaws can allow code execution and leak sensitive memory

Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23.

CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation.

An attacker can craft a malicious PNG with manipulated dimensions that causes VLC to allocate an undersized memory buffer before writing beyond its boundaries.

The flaw can potentially lead to arbitrary code execution when the malicious image is opened directly or loaded through a playlist.

CVE-2026-73324, rated 6.9, affects VLC's RealRTSP handling.

A malicious RTSP server can send an oversized response that causes VLC to read beyond an allocated buffer and return adjacent heap memory to the attacker, potentially exposing sensitive information.

The vulnerable RealRTSP component is enabled in official VideoLAN builds, although some Linux distribution packages may compile VLC without it.

As of September 11, VLC 3.0.23 remains the current stable desktop release listed by VideoLAN and is affected by both vulnerabilities.

Users should avoid opening untrusted image files or RealRTSP playlist links until an updated release addressing the flaws becomes available.

Source: securityonline.info/vlc-media-

##

DailyCyberSecurity@infosec.exchange at 2026-09-11T08:54:19.000Z ##

Two VLC media player vulnerabilities (CVE-2026-56711, CVE-2026-73324) allow heap out-of-bounds write and read. No patch is available yet.

#VLC #VideoLAN #VLCvulnerability #CVE #HeapOverflow #MediaPlayer #InfoSec #IntegerOverflow #RTSP #PatchNow

securityonline.info/vlc-media-

##

CVE-2026-56711
(8.8 HIGH)

EPSS: 0.30%

updated 2026-09-09T15:35:15

4 posts

VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result. In AllocatePicture in src/misc/picture.c the running total is accumulated as i_bytes += p->i_pitch * p->i_lines, and both plane_t fields are declared int in include/vlc_picture.h, so the multiplication is evaluated at 32 bits and wraps before it is widened to the size_t accumulator.

guru@thecybersecguru.com at 2026-09-12T17:11:54.000Z ##

VLC Media Player hit by two critical security flaws: heap corruption and memory disclosure putting millions at risk

Two critical VLC Media Player vulnerabilities, CVE-2026-56711 and CVE-2026-73324, expose users to heap corruption and memory disclosure. Here’s what to do

thecybersecguru.com/news/vlc-m

##

guru@thecybersecguru.com at 2026-09-12T17:11:54.000Z ##

VLC Media Player hit by two critical security flaws: heap corruption and memory disclosure putting millions at risk

Two critical VLC Media Player vulnerabilities, CVE-2026-56711 and CVE-2026-73324, expose users to heap corruption and memory disclosure. Here’s what to do

thecybersecguru.com/news/vlc-m

##

DarkWebInformer@infosec.exchange at 2026-09-11T16:37:27.000Z ##

🚨 Two VLC Media Player flaws can allow code execution and leak sensitive memory

Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23.

CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation.

An attacker can craft a malicious PNG with manipulated dimensions that causes VLC to allocate an undersized memory buffer before writing beyond its boundaries.

The flaw can potentially lead to arbitrary code execution when the malicious image is opened directly or loaded through a playlist.

CVE-2026-73324, rated 6.9, affects VLC's RealRTSP handling.

A malicious RTSP server can send an oversized response that causes VLC to read beyond an allocated buffer and return adjacent heap memory to the attacker, potentially exposing sensitive information.

The vulnerable RealRTSP component is enabled in official VideoLAN builds, although some Linux distribution packages may compile VLC without it.

As of September 11, VLC 3.0.23 remains the current stable desktop release listed by VideoLAN and is affected by both vulnerabilities.

Users should avoid opening untrusted image files or RealRTSP playlist links until an updated release addressing the flaws becomes available.

Source: securityonline.info/vlc-media-

##

DailyCyberSecurity@infosec.exchange at 2026-09-11T08:54:19.000Z ##

Two VLC media player vulnerabilities (CVE-2026-56711, CVE-2026-73324) allow heap out-of-bounds write and read. No patch is available yet.

#VLC #VideoLAN #VLCvulnerability #CVE #HeapOverflow #MediaPlayer #InfoSec #IntegerOverflow #RTSP #PatchNow

securityonline.info/vlc-media-

##

CVE-2026-85103
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-09-09T15:35:15

6 posts

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

Analyst207@mastodon.social at 2026-09-12T14:37:55.000Z ##

Dutch NCSC Warns of Imminent Check Point VPN Flaw Exploitation

The Dutch National Cyber Security Centrum is warning organizations to act fast - two critical flaws in Check Point VPN, tracked as CVE-2026-85102 and CVE-2026-85103, are likely to be exploited soon, with potentially severe consequences. Install security updates as soon as possible to protect yourself.

osintsights.com/dutch-ncsc-war

#CheckPointVpn #Cve202685102 #Cve202685103 #EmergingThreats #NationState

##

undercodenews@mastodon.social at 2026-09-12T14:35:56.000Z ##

Critical Check Point VPN Flaws Could Soon Trigger Remote Attacks, Dutch Cyber Agency Warns + Video

Critical Check Point VPN Flaws Could Soon Trigger Remote Attacks, Dutch Cyber Agency Warns A Dangerous Window Is Opening A new warning from the Dutch Nationaal Cyber Security Centrum (NCSC) is putting administrators of Check Point Security Gateways on high alert. Two critical vulnerabilities in Check Point VPN technology, tracked as CVE-2026-85102 and CVE-2026-85103,…

undercodenews.com/critical-che

##

cR0w at 2026-09-12T14:18:21.659Z ##

ncsc.nl/alerts/kritieke-kwetsb

Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en verwacht dat er snel pogingen tot misbruik zullen plaatsvinden, het advies is dan ook om de updates zo snel mogelijk te installeren.

Translated by LibreWolf:

There are 2 critical vulnerabilities in Check Point VPN products, with the characteristics CVE-2026-85102 and CVE-2026-85103. This concerns 2 serious vulnerabilities with a CVSS score of 9.8. The NCSC assesses the risk of abuse and possible damage as high and expects that attempts at abuse will take place quickly, so the advice is to install the updates as quickly as possible.

##

cR0w@infosec.exchange at 2026-09-12T14:18:21.000Z ##

ncsc.nl/alerts/kritieke-kwetsb

Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en verwacht dat er snel pogingen tot misbruik zullen plaatsvinden, het advies is dan ook om de updates zo snel mogelijk te installeren.

Translated by LibreWolf:

There are 2 critical vulnerabilities in Check Point VPN products, with the characteristics CVE-2026-85102 and CVE-2026-85103. This concerns 2 serious vulnerabilities with a CVSS score of 9.8. The NCSC assesses the risk of abuse and possible damage as high and expects that attempts at abuse will take place quickly, so the advice is to install the updates as quickly as possible.

##

jbhall56@infosec.exchange at 2026-09-11T13:56:38.000Z ##

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. securityweek.com/check-point-p

##

cyberworldops@infosec.exchange at 2026-09-10T15:00:00.000Z ##

Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise. #CyberSecurity #CheckPoint #VPN #RCE

cyberworldops.eu/en/check-poin

##

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-09-09T15:35:15

6 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Analyst207@mastodon.social at 2026-09-12T14:37:55.000Z ##

Dutch NCSC Warns of Imminent Check Point VPN Flaw Exploitation

The Dutch National Cyber Security Centrum is warning organizations to act fast - two critical flaws in Check Point VPN, tracked as CVE-2026-85102 and CVE-2026-85103, are likely to be exploited soon, with potentially severe consequences. Install security updates as soon as possible to protect yourself.

osintsights.com/dutch-ncsc-war

#CheckPointVpn #Cve202685102 #Cve202685103 #EmergingThreats #NationState

##

undercodenews@mastodon.social at 2026-09-12T14:35:56.000Z ##

Critical Check Point VPN Flaws Could Soon Trigger Remote Attacks, Dutch Cyber Agency Warns + Video

Critical Check Point VPN Flaws Could Soon Trigger Remote Attacks, Dutch Cyber Agency Warns A Dangerous Window Is Opening A new warning from the Dutch Nationaal Cyber Security Centrum (NCSC) is putting administrators of Check Point Security Gateways on high alert. Two critical vulnerabilities in Check Point VPN technology, tracked as CVE-2026-85102 and CVE-2026-85103,…

undercodenews.com/critical-che

##

cR0w at 2026-09-12T14:18:21.659Z ##

ncsc.nl/alerts/kritieke-kwetsb

Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en verwacht dat er snel pogingen tot misbruik zullen plaatsvinden, het advies is dan ook om de updates zo snel mogelijk te installeren.

Translated by LibreWolf:

There are 2 critical vulnerabilities in Check Point VPN products, with the characteristics CVE-2026-85102 and CVE-2026-85103. This concerns 2 serious vulnerabilities with a CVSS score of 9.8. The NCSC assesses the risk of abuse and possible damage as high and expects that attempts at abuse will take place quickly, so the advice is to install the updates as quickly as possible.

##

cR0w@infosec.exchange at 2026-09-12T14:18:21.000Z ##

ncsc.nl/alerts/kritieke-kwetsb

Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en verwacht dat er snel pogingen tot misbruik zullen plaatsvinden, het advies is dan ook om de updates zo snel mogelijk te installeren.

Translated by LibreWolf:

There are 2 critical vulnerabilities in Check Point VPN products, with the characteristics CVE-2026-85102 and CVE-2026-85103. This concerns 2 serious vulnerabilities with a CVSS score of 9.8. The NCSC assesses the risk of abuse and possible damage as high and expects that attempts at abuse will take place quickly, so the advice is to install the updates as quickly as possible.

##

jbhall56@infosec.exchange at 2026-09-11T13:56:38.000Z ##

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. securityweek.com/check-point-p

##

cyberworldops@infosec.exchange at 2026-09-10T15:00:00.000Z ##

Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise. #CyberSecurity #CheckPoint #VPN #RCE

cyberworldops.eu/en/check-poin

##

CVE-2026-17622
(6.5 MEDIUM)

EPSS: 0.49%

updated 2026-09-09T15:06:06.793000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

hugovalters@mastodon.social at 2026-09-12T05:40:02.000Z ##

CVE-2026-17622 IBM Langflow 1.0.0-1.10.2: path traversal flaw lets remote authenticated attackers read sensitive files. CVSS 6.5. Unpatched—assume risk now. Restrict access or isolate instances immediately. Details: valtersit.com/cve/CVE-2026-176 #CVE #infosec #IBM

##

CVE-2026-75650
(10.0 CRITICAL)

EPSS: 2.15%

updated 2026-09-09T05:18:07.237000

3 posts

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

5 repos

https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit

https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos

https://github.com/fortbridge/stylesmuggler

https://github.com/disrex-group/stylesmuggler-adobe-patches

https://github.com/dinosn/cve-2026-75650-magento-validation-lab

shochdoerfer@phpc.social at 2026-09-10T16:51:52.000Z ##

If you want to learn more about the latest zero-day #Magento exploit (StyleSmuggler), this a great read: graycore.io/case-studies/CVE-2

##

thecybermind@infosec.exchange at 2026-09-10T09:42:55.000Z ##

Executive alert: CVE-2026-75650 actively threatens Adobe Commerce and Magento infrastructure. Review board-ready risk evaluation protocols, asset integrity measures, and strategic remediation steps to protect your enterprise value today.

thecybermind.co/hip4

##

thecybermind@infosec.exchange at 2026-09-10T00:59:17.000Z ##

Critical CVE-2026-75650 alert for Adobe Commerce and Magento. Active CISA KEV exploitation requires immediate template parsing audits and endpoint hardening. Access our technical forensic brief to secure your enterprise perimeter today.

thecybermind.co/8in9

##

CVE-2025-14733
(9.8 CRITICAL)

EPSS: 26.51%

updated 2026-09-09T04:17:52.700000

3 posts

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN us

1 repos

https://github.com/machevalia/CVE-2025-14733

security_crawler_carl@infosec.exchange at 2026-09-10T20:28:41.000Z ##

🏆 New Achievement! WatchGuard Out, Ransomware In!

Patch Notes v0.0.0 (Unplanned Release): REMOVED — the assumption that your perimeter firewall was keeping anyone out. ADDED — unauthenticated remote code execution via CVE-2025-14733, a critical out-of-bounds write in the Fireware OS iked process affecting versions 11.x, 12.x, and 2025.1 through 2025.1.3. KNOWN ISSUE — ransomware gangs are already shipping this feature to your network. (1/2)

##

offseq@infosec.exchange at 2026-09-10T12:00:25.000Z ##

CVE-2025-14733: CRITICAL RCE in WatchGuard Firebox (Fireware OS 11.x+, 12.x+, 2025.1 – 2025.1.3) exploited by ransomware. Patch ASAP! Review VPN configs, monitor for IOCs. Details: radar.offseq.com/threat/cisa-w #OffSeq #WatchGuard #Ransomware #Infosec

##

cyberworldops@infosec.exchange at 2026-09-10T10:50:00.000Z ##

CISA confirmed CVE-2025-14733, a critical WatchGuard Firebox RCE, is being exploited in ransomware attacks. Edge firewalls are high-value targets because compromise enables network-wide access. Patch immediately and audit exposed interfaces for post-exploitation activity. #WatchGuard #Ransomware #CisaKev

cyberworldops.eu/en/cisa-confi

##

CVE-2026-85880
(7.8 HIGH)

EPSS: 0.57%

updated 2026-09-08T21:34:12

1 posts

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

PC_Fluesterer@social.tchncs.de at 2026-09-11T15:02:15.000Z ##

Die allerschlechteste Kombination: Chrome und Windows

Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows

##

CVE-2026-86218
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-09-08T21:33:02

4 posts

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

2 repos

https://github.com/HORKimhab/CVE-2026-86218

https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit

threatcodex at 2026-09-12T18:13:24.202Z ##

CVE-2026-86218: Active Exploitation of N-able N-central: Critical Pre-Auth Remote Code Execution (RCE) Vulnerability

arcticwolf.com/resources/blog/

##

threatcodex@infosec.exchange at 2026-09-12T18:13:24.000Z ##

CVE-2026-86218: Active Exploitation of N-able N-central: Critical Pre-Auth Remote Code Execution (RCE) Vulnerability
#N_central #CVE_2026_86218
arcticwolf.com/resources/blog/

##

DailyCyberSecurity@infosec.exchange at 2026-09-10T14:04:30.000Z ##

Discover the severe N-central CVE-2026-86218 vulnerability allowing unauthenticated RCE. Learn about N-able HF4 patches, CISA mandates, and threat actors.

#Ncentral #CVE202686218 #CyberSecurity #ZeroDay #Vulnerability

meterpreter.org/n-central-cve-

##

beyondmachines1@infosec.exchange at 2026-09-10T11:01:14.000Z ##

N-Able Patches N-Central Zero-Day Exploited in the Wild

N-Able released an emergency hotfix for a remote code execution vulnerability (CVE-2026-86218) in N-Central that attackers are actively exploiting to gain full administrative control over RMM servers and downstream client endpoints.

**If you run on-premises N-able N-central, upgrade immediately to version 2026.3.1.14 (2026.3 Hotfix 4). Make sure to keep the management console off the open internet behind a VPN or firewall allowlist limited to trusted admin networks. Since attackers may have already gained access, check for unfamiliar administrator accounts, unknown scripts or scheduled jobs and strange outbound connections, and change all passwords and keys used by or stored on the N-central server.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-52777
(0 None)

EPSS: 0.21%

updated 2026-09-08T21:05:26.920000

1 posts

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.

hugovalters@mastodon.social at 2026-09-12T01:20:02.000Z ##

CVE-2026-52777: Authenticated PHP object injection via unserialize in YesWiki's BazarImportAction. CVSS N/A, unpatched pre-4.6.6. Attackers can exploit to execute arbitrary code. Update immediately to 4.6.6. valtersit.com/cve/CVE-2026-527 #CVE #infosec #YesWiki

##

CVE-2026-86426
(0 None)

EPSS: 1.41%

updated 2026-09-08T19:57:49.663000

1 posts

LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL type coercion by sending small integers like 0 through 9 to match token hashes, gaining access to API functionality including device credentials and administrative f

Nuclei template

halildeniz@mastodon.social at 2026-09-12T13:14:20.000Z ##

🚨 Critical Security Alert!
Deep-dive vulnerability analysis of CVE-2026-86426 (CVSS 9.2): Unauthenticated API Access & RCE in LibreNMS <= 26.7.0 caused by JSON type confusion & MySQL coercion.

denizhalil.com/2026/09/12/cve-

#CyberSecurity #Vulnerability #LibreNMS

##

CVE-2026-82067
(8.1 HIGH)

EPSS: 0.28%

updated 2026-09-08T19:07:12.210000

1 posts

Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and a

CVE-2026-69827
(8.1 HIGH)

EPSS: 0.53%

updated 2026-09-08T18:33:26

1 posts

Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.

shaknais@mastodon.social at 2026-09-11T23:11:45.000Z ##

@hrbrmstr

MS selling "MDASH" as having fixed their TCP/IP stack, a day after a critical DNS CVE comes out without a fix.

cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-33197(CVSS UNKNOWN)

EPSS: 0.12%

updated 2026-09-08T15:32:05

1 posts

AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact system Confidentiality, Integrity, and Availability.

CVE-2026-71626
(7.5 HIGH)

EPSS: 0.32%

updated 2026-09-08T15:31:36

1 posts

An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components

hugovalters@mastodon.social at 2026-09-12T10:20:19.000Z ##

CVE-2026-71626: Invoice Ninja v5.13.24 leaks sensitive data via webhook request components. Remote info exposure, no CVSS or patch yet. Review your instance now. Details: valtersit.com/cve/CVE-2026-716 #CVE #infosec #InvoiceNinja

##

CVE-2026-44756
(10.0 CRITICAL)

EPSS: 0.32%

updated 2026-09-08T03:31:21

1 posts

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availabil

DailyCyberSecurity@infosec.exchange at 2026-09-10T14:37:16.000Z ##

The SAP OVERPASS vulnerability (CVE-2026-44756) scores a perfect CVSS 10.0, letting attackers seize SAP servers before login. Patch Note 3747649 now.

#SAP #OVERPASS #CVE202644756 #CyberSecurity #RCE #Onapsis #InfoSec

securityexpress.info/sap-overp

##

CVE-2026-80907
(0 None)

EPSS: 0.16%

updated 2026-09-07T15:17:33.510000

1 posts

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix UVD dpb min size calculation for H264 This should use actual number of references from the decode message, instead of maximum derived from level. (cherry picked from commit 64b525edb7e7bdfcdc77883c5e413804e2396856)

hugovalters@mastodon.social at 2026-09-12T04:00:03.000Z ##

CVE-2026-80907: Linux kernel amdgpu UVD dpb size miscalc for H264 could trigger memory corruption. Unpatched—CVSS N/A. If you run AMD GPUs, verify your kernel build now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

PC_Fluesterer@social.tchncs.de at 2026-09-11T15:02:15.000Z ##

Die allerschlechteste Kombination: Chrome und Windows

Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows

##

CVE-2026-80880(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-09-04T18:31:40

1 posts

In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Properly support implicit ODP rereg_mr Due to all the child mkeys in the implicit ODP configuration we cannot change anything in place for the parent mkey. Instead the whole thing needs to be rebuilt if any change is requested. If the user does not specify a translation then force the implicit values which will then fal

hugovalters@mastodon.social at 2026-09-12T16:30:03.000Z ##

CVE-2026-80880: Linux kernel flaw in IB/mlx5 implicit ODP mkey handling. Exploitable to corrupt memory or crash systems—impact not fully disclosed. CVSS N/A, no patch available. Track this actively; test mitigations, restrict valtersit.com/cve/CVE-2026-808

##

CVE-2026-17444
(5.3 MEDIUM)

EPSS: 0.29%

updated 2026-09-04T18:31:40

1 posts

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

hugovalters@mastodon.social at 2026-09-12T13:30:02.000Z ##

CVE-2026-17444: XXE in IBM App Connect Enterprise & Integration Bus (CVSS 5.3). Remote authenticated attacker can leak sensitive data via XML injection. Impact hits versions 13.0.1.0-13.0.8.1, 12.0.1.0-12.0.12.28, & z/OS 10.1.0.x. valtersit.com/cve/CVE-2026-174

##

CVE-2026-16689
(6.2 MEDIUM)

EPSS: 0.11%

updated 2026-09-04T18:31:39

1 posts

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials.

hugovalters@mastodon.social at 2026-09-12T11:50:56.000Z ##

CVE-2026-16689: IBM App Connect Enterprise & Integration Bus log credentials improperly, letting local attackers steal sensitive info. CVSS 6.2. Unpatched—check your versions now. Patch immediately. valtersit.com/cve/CVE-2026-166 #CVE #ibm #infosec

##

CVE-2026-78849(CVSS UNKNOWN)

EPSS: 0.26%

updated 2026-09-04T18:31:34

1 posts

Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file

hugovalters@mastodon.social at 2026-09-12T15:00:03.000Z ##

CVE-2026-78849 - XSS in Netgate pfSense (Plus <=26.03 & CE <=2.8.1). Remote code execution via captive_portal_status.widget.php. Unpatched. CVSS N/A. Isolate exposed firewalls & monitor logs. Details: valtersit.com/cve/CVE-2026-788 #CVE #pfSense #infosec

##

CVE-2026-80890
(0 None)

EPSS: 0.18%

updated 2026-09-04T18:17:57.077000

1 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: reject stale cookies with mismatched verification tags sctp_unpack_cookie() skips cookie expiration checks whenever an association already exists. This is broader than the exception in RFC 9260 Section 5.2.4. For an existing association, Section 5.2.4 permits an expired State Cookie only when both Verification Tags in th

hugovalters@mastodon.social at 2026-09-12T18:10:13.000Z ##

CVE-2026-80890: Linux kernel SCTP flaw allows stale cookies with mismatched verification tags to bypass checks, risking connection hijacking or DoS. CVSS N/A, unpatched. Patch when available; audit SCTP exposure now. valtersit.com/cve/CVE-2026-808 #CVE #infosec #Li

##

CVE-2026-80871
(0 None)

EPSS: 0.15%

updated 2026-09-04T17:16:59.027000

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: xilinx-trng - Remove crypto_rng interface Implementing the crypto_rng interface has no purpose, as it isn't used in practice. It's being removed from other drivers too. Just remove it. This leaves hwrng, which is actually used. Tagging with 'Cc stable' due to the bugs that this removes: - xtrng_trng_generate() som

hugovalters@mastodon.social at 2026-09-12T19:40:06.000Z ##

CVE-2026-80871: Linux kernel crypto/xilinx-trng bug—removed crypto_rng interface that could return success without filling buffers. Potential data integrity risk. CVSS: N/A. Patch status unclear—check your kernel. Details: valtersit.com/cve/CVE-2026-808 Update kern

##

threatnoir at 2026-09-12T01:05:51.850Z ##

⚠️ CRITICAL: Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers are chaining multiple JFrog Artifactory vulnerabilities (CVE-2026-42018, CVE-2026-42016, CVE-2026-82329) to escalate from anonymous users to administrator control on self-hosted instances. This grants them ability to plant backdoors and execute arbitrary shell commands in your build pipel…

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-12T01:05:51.000Z ##

⚠️ CRITICAL: Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers are chaining multiple JFrog Artifactory vulnerabilities (CVE-2026-42018, CVE-2026-42016, CVE-2026-82329) to escalate from anonymous users to administrator control on self-hosted instances. This grants them ability to plant backdoors and execute arbitrary shell commands in your build pipel…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

cyberworldops@infosec.exchange at 2026-09-11T18:30:01.000Z ##

Active exploitation chains CVE-2026-42018 and CVE-2026-42016 to bypass authentication on self-hosted JFrog Artifactory and deploy a Rust backdoor with C2. CVE-2026-82329 is also abused to create admin tokens. This enables full server takeover and supply chain compromise. #JFrog #Artifactory #SupplyChainSecurity

cyberworldops.eu/en/attackers-

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 1.69%

updated 2026-09-01T04:18:02.160000

1 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/virologi-info/papercut-toolkit

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

offseq@infosec.exchange at 2026-09-11T09:00:25.000Z ##

PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: radar.offseq.com/threat/paperc #OffSeq #PaperCut #ZeroDay #BlueTeam

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 1.62%

updated 2026-08-31T21:31:56

1 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

2 repos

https://github.com/virologi-info/papercut-toolkit

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

offseq@infosec.exchange at 2026-09-11T09:00:25.000Z ##

PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: radar.offseq.com/threat/paperc #OffSeq #PaperCut #ZeroDay #BlueTeam

##

CVE-2026-69414
(7.8 HIGH)

EPSS: 0.56%

updated 2026-08-19T18:32:28

2 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

2 repos

https://github.com/1neptune/ShieldBreak

https://github.com/HORKimhab/CVE-2026-50656

cyberworldops@infosec.exchange at 2026-09-10T18:50:00.000Z ##

Researcher Nightmare-Eclipse has released ShieldCrash, a PoC claiming to bypass Microsoft's fix for CVE-2026-69414, a privilege escalation flaw in Defender's Malware Protection Engine. Public exploit code may increase abuse; verify the patch blocks the technique and monitor for exploitation. #CyberSecurity #Vulnerability #ThreatIntel #MicrosoftDefender

cyberworldops.eu/en/shieldcras

##

offseq@infosec.exchange at 2026-09-10T07:30:25.000Z ##

CRITICAL: ShieldCrash zero-day (CVE-2026-69414) exploits Microsoft Defender on patched Windows (Sept 2026), enabling privilege escalation to System and SAM dumping. No patch yet. Monitor for Defender anomalies. radar.offseq.com/threat/new-sh #OffSeq #ZeroDay #MicrosoftDefender #Infosec

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 45.88%

updated 2026-08-18T18:32:52

2 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

2 repos

https://github.com/BiuTrap/CVE-2026-59310

https://github.com/HORKimhab/CVE-2026-59310

kev_Stalker at 2026-09-12T13:15:13.740Z ##

CVE-2026-59310 - Changed to Known Ransomware Status

Broadcom VMware vCenter Path Traversal VulnerabilityVendor: BroadcomProduct: VMware vCenterBroadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 11, 2026 at 16:08:17 UTCDate Added to KEV: nvd.nist.gov/vuln/detail/CVE-2

##

kev_Stalker@infosec.exchange at 2026-09-12T13:15:13.000Z ##

CVE-2026-59310 - Changed to Known Ransomware Status

Broadcom VMware vCenter Path Traversal VulnerabilityVendor: BroadcomProduct: VMware vCenterBroadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 11, 2026 at 16:08:17 UTCDate Added to KEV: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-20316
(5.3 MEDIUM)

EPSS: 11.15%

updated 2026-08-01T05:16:55.973000

3 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vu

kev_Stalker@infosec.exchange at 2026-09-11T11:36:27.000Z ##

CVE-2026-20316 - Changed to Known Ransomware Status

Cisco Secure Firewall Management Center Use of Hard-coded Password VulnerabilityVendor: CiscoProduct: Secure Firewall Management Center (FMC)Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops@infosec.exchange at 2026-09-10T17:00:00.000Z ##

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.

#CiscoFMC #ThreatIntelligence #VulnerabilityManagement #Qilin

cyberworldops.eu/en/cisco-fmc-

##

beyondmachines1@infosec.exchange at 2026-09-10T10:01:13.000Z ##

Cisco Secure Firewall Management Center Under Active Attack

Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.

**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2–7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-43502
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-23T16:10:00.137000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the sending socket. The purge path currently infers zerocopy state from rm->m_rs, so an unqueued message can be cleaned up as if it owned normal payload pages. Howev

1 repos

https://github.com/suominen/pintheft

bearstech@mamot.fr at 2026-09-10T09:14:32.000Z ##

ZcopyReaper (CVE-2026-43502) nous avons déployé cette nuit les mesures de contournement.

Toutes nos VM ont été redémarrées en moins d’une heure.

👉 En savoir plus sur nos offres d'infogérance : bearstech.com/contact

Merci à @Octopuce et @evolix pour votre collaboration sur ce sujet.

##

CVE-2026-15409
(10.0 CRITICAL)

EPSS: 84.54%

updated 2026-07-14T21:32:22

2 posts

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Nuclei template

6 repos

https://github.com/HORKimhab/CVE-2026-15409

https://github.com/0xBlackash/CVE-2026-15409

https://github.com/remmons-r7/rapid7-CVE-2026-15409

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/Ch4120N/CVE-2026-15409

cyberworldops@infosec.exchange at 2026-09-11T20:30:00.000Z ##

Borough Council of King's Lynn and West Norfolk incident linked with moderate confidence to mass exploitation of CVE-2026-15409 in SonicWall SMA1000. Unauthenticated SSRF in WorkPlace WebSocket proxy chains to RCE and LDAP credential theft, enabling pivot into internal networks. Exposed systems require immediate patching and compromise hunting. #SonicWall #Sma1000 #InfoSec

cyberworldops.eu/en/uk-council

##

_r_netsec@infosec.exchange at 2026-09-10T17:58:04.000Z ##

🕵️‍♂️ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance hunt.io/blog/sonicwall-sma1000

##

CVE-2026-50013
(7.5 HIGH)

EPSS: 0.27%

updated 2026-07-14T18:03:10

1 posts

### Summary: When Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the normal case for any proxy), the concurrent map writes trigger Go's built-in race detector which causes a `fatal error: concurrent map read and map write`, immediately killing the e

thehackerwire@mastodon.social at 2026-09-11T23:00:09.000Z ##

🟠 CVE-2026-50013 - High (7.5)

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54174
(8.3 HIGH)

EPSS: 0.10%

updated 2026-07-10T21:43:06

1 posts

Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still passed.

thehackerwire@mastodon.social at 2026-09-11T21:59:51.000Z ##

🟠 CVE-2026-54174 - High (8.3)

melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never ver...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49464
(8.1 HIGH)

EPSS: 0.20%

updated 2026-07-08T21:12:01

1 posts

## Impact In versions from 1.5.0 up to and including 3.0.0, any authenticated portal user could complete and tamper with another user's open task by submitting it on their behalf. The task submission endpoint accepted a task ID and a payload, but it never checked whether the task actually belonged to the user making the call. An attacker who held a valid login (a normal `burger` OAuth token) and

thehackerwire@mastodon.social at 2026-09-11T22:00:00.000Z ##

🟠 CVE-2026-49464 - High (8.1)

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to verify own...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11387
(9.8 CRITICAL)

EPSS: 2.21%

updated 2026-07-01T13:56:17.493000

1 posts

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like reset the password of any user account, including administrators, and gain full a

Nuclei template

2 repos

https://github.com/1beelze/CVE-2026-11387

https://github.com/abraxas/CVE-2026-11387-WooCommerce-SMS-OTP

DarkWebInformer@infosec.exchange at 2026-09-10T20:20:41.000Z ##

‼️ CVE-2026-11387: A critical improper-authentication flaw in the WordPress plugin SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery.

GitHub: github.com/abraxas/CVE-2026-11

##

CVE-2026-28576
(5.5 MEDIUM)

EPSS: 0.15%

updated 2026-06-17T18:35:56

1 posts

In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

1 repos

https://github.com/mobilehackinglab/CVE-2026-28576-poc

CVE-2026-39987
(9.8 CRITICAL)

EPSS: 98.95%

updated 2026-06-17T10:42:51.460000

1 posts

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpo

Nuclei template

25 repos

https://github.com/HORKimhab/CVE-2026-39987

https://github.com/Dhiaelhak-Rached/CVE-2026-39987-lab-or-marimo-cve-lab

https://github.com/keraattin/CVE-2026-39987

https://github.com/Wind010/CVE-2026-39987_PoC

https://github.com/Clara-M-Grossl/Exploit-Marimo

https://github.com/0xdeadroot/CVE-2026-39987-marimo-rce

https://github.com/julichaan/CVE-2026-39987_POC

https://github.com/Ghxstsec/CVE-2026-39987

https://github.com/alreadyClosed/CVE-2026-39987

https://github.com/0xBlackash/CVE-2026-39987

https://github.com/Nxploited/CVE-2026-39987

https://github.com/mki9/CVE-2026-39987_exploit

https://github.com/K3ysTr0K3R/CVE-2026-39987

https://github.com/fevar54/marimo_CVE-2026-39987_RCE_PoC

https://github.com/matesz44/cve-2026-39987

https://github.com/stapat1245/CVE-2026-39987-PoC

https://github.com/dodeepsink/CVE-2026-39987.py

https://github.com/MADA0L/CVE-2026-39987-Poc

https://github.com/rootdirective-sec/CVE-2026-39987-Lab

https://github.com/M3PH1569/CVE-2026-39987-POC

https://github.com/iapetus12/cohort-htb

https://github.com/h3raklez/CVE-2026-39987

https://github.com/vanhari/CVE-2026-39987

https://github.com/jasonbernier/CVE-2026-39987

https://github.com/gbuyssens/CVE-2026-39987

undercodenews@mastodon.social at 2026-09-12T01:03:02.000Z ##

CVE-2026-39987 Turns Marimo Into a Fast-Track Gateway to SSH and Cloud Credentials + Video

CVE-2026-39987 Turns Marimo Into a Fast-Track Gateway to SSH and Cloud Credentials A Critical Marimo Flaw Is Becoming a Real-World Attack Weapon A vulnerability in the open-source marimo project has evolved from a serious software flaw into a practical intrusion route for attackers targeting cloud infrastructure. CVE-2026-39987 is a critical pre-authentication remote code…

undercodenews.com/cve-2026-399

##

tati@eldritch.cafe at 2026-09-12T06:56:03.000Z ##

wait, it's not a shitpost over on my other channel?? there's really an RCE in notepad ?!

cve.org/CVERecord?id=CVE-2026-

##

CVE-2019-0859
(7.8 HIGH)

EPSS: 4.15%

updated 2026-06-17T02:09:03.317000

1 posts

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.

1 repos

https://github.com/Sheisback/CVE-2019-0859-1day-Exploit

kev_Stalker@infosec.exchange at 2026-09-10T11:20:16.000Z ##

CVE-2019-0859 - Changed to Known Ransomware Status

Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate Added to KEV: 2021-11-03View nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-4800
(8.1 HIGH)

EPSS: 2.76%

updated 2026-04-01T23:51:13

1 posts

### Impact The fix for [CVE-2021-23337](https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the `variable` option in `_.template` but did not apply the same validation to `options.imports` key names. Both paths flow into the same `Function()` constructor sink. When an application passes untrusted input as `options.imports` key names, an attacker can inject default-parameter e

2 repos

https://github.com/SvenLie/next-rep-CVE-2026-4800

https://github.com/threalwinky/CVE-2026-4800-POC

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-33671
(7.5 HIGH)

EPSS: 0.40%

updated 2026-03-27T21:36:14

1 posts

### Impact `picomatch` is vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Examples of problematic p

1 repos

https://github.com/BeLazy167/next-picomatch-cve-repro

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-33186
(9.1 CRITICAL)

EPSS: 1.56%

updated 2026-03-25T18:12:09

1 posts

### Impact _What kind of vulnerability is it? Who is impacted?_ It is an **Authorization Bypass** resulting from **Improper Input Validation** of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully rou

1 repos

https://github.com/JohannesLks/CVE-2026-33186

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-0915
(7.5 HIGH)

EPSS: 0.63%

updated 2026-01-20T18:31:56

1 posts

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.

1 repos

https://github.com/Terra-Nova83/CVE-2026-0915-json-Patch.-V2.0

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2022-41352
(9.8 CRITICAL)

EPSS: 95.48%

updated 2025-10-22T00:32:37

1 posts

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavisd via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red H

Nuclei template

4 repos

https://github.com/rxerium/CVE-2022-41352

https://github.com/dafrax/cve-2022-41352-zimbra-rce

https://github.com/Cr4ckC4t/cve-2022-41352-zimbra-rce

https://github.com/segfault-it/cve-2022-41352

kev_Stalker@infosec.exchange at 2026-09-10T11:25:19.000Z ##

CVE-2022-41352 - Changed to Known Ransomware Status

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityVendor: SynacorProduct: Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2016-7255
(7.8 HIGH)

EPSS: 80.97%

updated 2025-10-22T00:32:21

1 posts

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

5 repos

https://github.com/yuvatia/page-table-exploitation

https://github.com/heh3/CVE-2016-7255

https://github.com/homjxi0e/CVE-2016-7255

https://github.com/FSecureLABS/CVE-2016-7255

https://github.com/bbolmin/cve-2016-7255_x86_x64

kev_Stalker@infosec.exchange at 2026-09-10T11:30:23.000Z ##

CVE-2016-7255 - Changed to Known Ransomware Status

Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-84890
(0 None)

EPSS: 0.25%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-12T08:40:01.000Z ##

CVE-2026-84890: undici decompression bomb risk. Malicious upstream can expand tiny payloads to hundreds of MB, exhausting client memory. CVSS 5.9. Patch status unknown—review your undici usage and add limits if possible. Details: valtersit.com/cve/CVE-2026-848 #CVE

##

CVE-2026-46636
(0 None)

EPSS: 0.36%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-12T03:50:03.000Z ##

CVE-2026-46636: Twig <3.27.0 sandbox bypass—subclasses of Twig\Markup expose all public methods, allowing arbitrary code execution. CVSS N/A, fix available. Update immediately to 3.27.0+. valtersit.com/cve/CVE-2026-466 #CVE #infosec #PHP

##

CVE-2026-89066
(0 None)

EPSS: 0.16%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-11T17:00:48.000Z ##

🟠 CVE-2026-89066 - High (7.8)

Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87908
(0 None)

EPSS: 0.30%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-11T11:01:28.000Z ##

🟠 CVE-2026-87908 - High (7.5)

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-51990
(0 None)

EPSS: 0.00%

1 posts

N/A

1 repos

https://github.com/HORKimhab/CVE-2026-51990

VirusBulletin@infosec.exchange at 2026-09-11T10:23:05.000Z ##

Gen Threat Labs discovered a critical remote code execution vulnerability (CVE-2026-51990) in Sogou Input Method. The vulnerability is actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link. gendigital.com/blog/insights/r

##

CVE-2026-16338
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-70416
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-63695
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-09-11T01:32:54.000Z ##

Dell patched critical Dell Networking OS10 vulnerabilities, including CVE-2026-63695. Update your Dell SmartFabric OS10 switches to prevent session theft.

#DellNetworking #Cybersecurity #Vulnerabilities #CVE202663695 #InfoSec

securityonline.info/dell-netwo

##

CVE-2026-89049
(0 None)

EPSS: 0.36%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-10T21:00:17.000Z ##

🔴 CVE-2026-89049 - Critical (9.9)

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

awssecurityfeed@infosec.exchange at 2026-09-10T19:00:01.000Z ##

CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT
Description:
AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-88052
(0 None)

EPSS: 0.12%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-10T19:00:53.000Z ##

🟠 CVE-2026-88052 - High (7.8)

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_ins...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cert_fr@social.numerique.gouv.fr at 2026-09-10T16:04:24.000Z ##

⚠️Alerte CERT-FR⚠️

Le CERT-FR a connaissance de nombreuses compromissions de Metabase vulnérables à l'injection SQL CVE-2026-72898.

cert.ssi.gouv.fr/alerte/CERTFR

##

CVE-2026-84388
(0 None)

EPSS: 0.00%

1 posts

N/A

beyondmachines1@infosec.exchange at 2026-09-10T09:01:13.000Z ##

Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line

Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.

**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-87911
(0 None)

EPSS: 0.99%

1 posts

N/A

offseq@infosec.exchange at 2026-09-10T06:00:25.000Z ##

CVE-2026-87911 (CVSS 9.6): CRITICAL OS command injection in AWS Labs postgres MCP Server (<1.1.7). Unauthenticated attackers can execute OS commands via crafted SQL. Upgrade to 1.1.7+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #AWS #PostgreSQL #Vuln

##

Visit counter For Websites