## Updated at UTC 2026-06-28T12:29:02.800307

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-13486 7.3 0.00% 2 0 2026-06-28T10:16:27.150000 A vulnerability was determined in SourceCodester Class and Exam Timetabling Syst
CVE-2026-46331 7.8 0.29% 8 4 2026-06-28T08:16:21.240000 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-13482 3.7 0.00% 2 0 2026-06-28T05:16:21.200000 A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is
CVE-2026-58053 9.9 0.00% 4 0 2026-06-28T03:33:40 Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow
CVE-2026-58056 7.6 0.00% 2 0 2026-06-28T02:16:32.860000 RustDesk gates incoming control messages on per-capability flags rather than on
CVE-2026-58050 7.0 0.00% 2 0 2026-06-28T02:16:32.017000 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from
CVE-2026-58049 8.6 0.00% 2 0 2026-06-28T02:16:30.477000 FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit r
CVE-2026-8095 8.1 0.00% 4 0 2026-06-28T00:16:25.180000 The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authentic
CVE-2026-10643 8.7 0.00% 4 0 2026-06-28T00:16:24.637000 Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet
CVE-2026-9677 0 0.15% 2 0 2026-06-27T06:16:34.783000 The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not s
CVE-2026-12415 9.8 0.66% 4 1 2026-06-27T05:16:41.620000 The Invoice Generator plugin for WordPress is vulnerable to privilege escalation
CVE-2026-11807 9.6 0.37% 1 0 2026-06-27T05:16:41.450000 A missing authorization vulnerability was found in the Event-Driven Ansible (EDA
CVE-2026-57231 7.5 0.26% 2 0 2026-06-27T04:17:52.313000 Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a
CVE-2026-54352 9.6 0.47% 3 0 2026-06-27T04:17:51.583000 Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/pr
CVE-2026-50136 7.4 0.33% 1 0 2026-06-27T04:17:49.740000 Budibase is an open-source low-code platform. Prior to 3.39.3, the application s
CVE-2026-56414 7.2 0.40% 2 0 2026-06-26T23:17:09.137000 A vulnerability exists in H.View IP cameras certificate-related upload interface
CVE-2026-55975 7.2 0.65% 2 0 2026-06-26T23:17:08.997000 A vulnerability exists in H.View IP cameras that could allow an authenticated us
CVE-2026-33560 7.1 0.34% 2 0 2026-06-26T23:17:08.847000 The DMP-5000 file service exposes authenticated arbitrary file upload functional
CVE-2026-31928 8.1 0.45% 4 0 2026-06-26T23:17:08.697000 The DMP-5000 devices are shipped with a default administrative web account with
CVE-2026-28701 9.8 0.84% 4 0 2026-06-26T23:17:08.537000 Various versions of Daktronics Controller Firmware could allow authenticated and
CVE-2026-55069 8.7 0.15% 2 0 2026-06-26T22:16:33.093000 Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24,
CVE-2026-53576 10.0 0.47% 2 0 2026-06-26T22:16:32.840000 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 a
CVE-2026-49984 7.7 0.37% 2 0 2026-06-26T22:16:32.243000 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 a
CVE-2026-49869 10.0 0.69% 2 0 2026-06-26T22:16:32.113000 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 a
CVE-2026-45807 7.7 0.37% 2 0 2026-06-26T22:16:31.973000 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 a
CVE-2026-54353 8.5 0.24% 2 0 2026-06-26T21:16:35.417000 Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated use
CVE-2026-54351 8.2 0.41% 2 0 2026-06-26T21:16:35.170000 Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigg
CVE-2026-54350 10.0 0.43% 2 0 2026-06-26T21:16:35.040000 Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthentica
CVE-2026-48778 7.8 1.37% 3 3 2026-06-26T21:16:34.167000 Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <G
CVE-2026-8797 0 0.12% 1 0 2026-06-26T20:23:02.513000 An access control deficiency vulnerability exists in ExpressUpdate Agent for Win
CVE-2026-55189 7.7 0.20% 1 0 2026-06-26T20:20:22.420000 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1
CVE-2026-52784 8.8 0.16% 1 0 2026-06-26T20:20:22.420000 OpenProject is open-source, web-based project management software. Prior to 17.3
CVE-2026-48933 7.5 0.57% 1 0 2026-06-26T20:19:23.707000 A flaw in Node.js WebCrypto implementation can crash the process if the input of
CVE-2026-48618 6.5 0.61% 1 0 2026-06-26T20:18:43.557000 A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator
CVE-2026-54317 7.6 0.19% 1 0 2026-06-26T20:17:26.380000 Home Assistant is open source home automation software that puts local control a
CVE-2026-9222 8.1 0.24% 1 0 2026-06-26T20:08:23.053000 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior o
CVE-2026-56876 8.1 0.32% 1 0 2026-06-26T20:05:14.220000 extract-zip does not validate symlink targets when extracting zip archives. When
CVE-2026-55454 9.9 0.33% 1 0 2026-06-26T19:50:41.937000 Appsmith is a platform to build admin panels, internal tools, and dashboards. Pr
CVE-2026-57915 7.3 0.26% 1 0 2026-06-26T19:16:45.433000 It is possible to bypass the Kerberos pre-authentication check in Apache Kerby b
CVE-2026-56663 8.5 0.22% 1 0 2026-06-26T19:16:44.880000 AutoGPT is a workflow automation platform for creating, deploying, and managing
CVE-2026-55200 8.1 0.92% 3 1 2026-06-26T19:15:53.083000 libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write
CVE-2026-13311 7.5 0.36% 1 0 2026-06-26T19:03:34.507000 shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.protot
CVE-2026-43503 8.8 0.13% 4 6 2026-06-26T18:57:17.887000 In the Linux kernel, the following vulnerability has been resolved: net: skbuff
CVE-2026-57880 9.8 0.53% 1 0 2026-06-26T18:17:04.987000 An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in G
CVE-2026-57881 9.8 0.38% 1 0 2026-06-26T17:16:35.753000 An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in
CVE-2026-57879 9.8 0.53% 1 0 2026-06-26T17:16:35.653000 An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in G
CVE-2026-8380 6.5 0.34% 1 1 2026-06-26T16:17:26.200000 The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly
CVE-2026-54825 9.3 0.28% 1 0 2026-06-26T15:32:21 Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
CVE-2026-20230 8.6 41.69% 13 3 2026-06-26T14:58:43.440000 A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco U
CVE-2026-12569 9.8 1.11% 7 1 2026-06-26T14:35:41.477000 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-54158 9.9 0.29% 1 0 2026-06-26T00:16:53.823000 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, t
CVE-2026-23879 8.0 0.40% 1 0 2026-06-25T20:21:19.853000 py7zr is a Python-based library and utility to support 7zip archive compression,
CVE-2026-53662 9.6 0.24% 1 0 2026-06-25T20:18:11.603000 immich is a high performance self-hosted photo and video management solution. Fr
CVE-2026-10735 7.5 0.39% 1 2 2026-06-25T19:07:56.657000 Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimoni
CVE-2026-33612 7.5 0.12% 1 0 2026-06-25T16:00:30.783000 A malicious authoritative server can send a crafted zone via the ZoneToCache fun
CVE-2026-50256 7.8 0.15% 1 0 2026-06-25T15:31:44 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland.
CVE-2026-55570 9.0 0.33% 1 0 2026-06-25T15:16:39.423000 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, i
CVE-2026-50551 9.9 0.44% 1 0 2026-06-25T14:16:45.323000 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, S
CVE-2026-50264 7.8 0.14% 2 0 2026-06-25T14:16:45.140000 An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIG
CVE-2026-50263 5.5 0.14% 1 0 2026-06-25T14:16:44.947000 A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSave
CVE-2026-50262 5.5 0.13% 1 0 2026-06-25T14:16:44.750000 An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glX
CVE-2026-50261 7.8 0.14% 1 0 2026-06-25T14:16:44.510000 A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChange
CVE-2026-50260 7.8 0.15% 1 0 2026-06-25T14:16:43.427000 A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounte
CVE-2026-50259 7.8 0.16% 1 0 2026-06-25T14:16:43.267000 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland.
CVE-2026-50258 7.8 0.15% 1 0 2026-06-25T14:16:43.110000 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland.
CVE-2026-50257 7.8 0.14% 1 0 2026-06-25T14:16:42.940000 A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDest
CVE-2026-12416 9.8 0.36% 1 2 2026-06-25T14:16:36.007000 The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via
CVE-2026-12850 9.1 1.72% 1 0 2026-06-25T14:02:35.347000 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct
CVE-2026-12851 9.1 1.68% 1 0 2026-06-25T14:02:35.347000 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct
CVE-2026-9702 7.5 0.21% 1 0 2026-06-25T13:28:35.737000 The InPost PL WordPress plugin before 1.9.1 does not verify that the request ori
CVE-2026-46752 0 0.40% 1 0 2026-06-25T13:27:40.747000 Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This
CVE-2026-41566 0 0.29% 1 0 2026-06-25T13:27:40.747000 Improper Handling of Insufficient Permissions or Privileges vulnerability in Apa
CVE-2026-12417 9.8 0.45% 1 1 2026-06-25T13:26:11.740000 The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass
CVE-2026-56022 5.3 0.31% 1 0 2026-06-24T21:16:58.237000 Webmin accepts basic authentication without session cookies when an attacker pro
CVE-2026-34908 10.0 2.45% 6 1 2026-06-24T14:50:41.720000 A malicious actor with access to the network could exploit an Improper Access Co
CVE-2026-34909 10.0 2.27% 4 0 2026-06-24T14:49:53.287000 A malicious actor with access to the network could exploit a Path Traversal vuln
CVE-2026-34910 10.0 78.55% 4 0 template 2026-06-24T14:49:47.237000 A malicious actor with access to the network could exploit an Improper Input Val
CVE-2025-67038 9.8 1.13% 6 1 2026-06-24T05:17:25.670000 An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module exec
CVE-2025-52465 7.2 0.35% 1 0 2026-06-24T05:17:25.543000 GeoServer is an open source server that allows users to share and edit geospatia
CVE-2026-53753 9.8 0.45% 1 0 2026-06-23T20:16:48.907000 Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, t
CVE-2026-12957 7.8 0.12% 2 0 2026-06-23T19:36:18.347000 Improper trust boundary enforcement in Language Servers for AWS before version 1
CVE-2026-12958 7.8 0.14% 1 0 2026-06-23T19:36:18.347000 Missing symlink validation in Language Servers for AWS may allow an arbitrary fi
CVE-2026-11940 None 0.60% 2 0 2026-06-23T18:31:51 tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a cra
CVE-2026-28496 0 1.89% 1 0 template 2026-06-23T16:16:59.350000 FOSSBilling is a free, open-source billing and client management system. Version
CVE-2026-49494 7.5 0.54% 1 0 2026-06-23T15:16:35.747000 Xcitium Client Security (XCS) before 13.8.2.10019 and Comodo Internet Security (
CVE-2026-8461 8.8 0.39% 19 5 2026-06-22T20:31:03.510000 An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specificall
CVE-2026-41950 6.5 0.33% 1 0 2026-06-22T18:16:37.293000 Dify before version 1.14.0 contains an authorization bypass vulnerability that a
CVE-2026-41948 9.4 0.51% 1 0 2026-06-22T18:16:37.033000 Dify version 1.14.1 and prior contain a path traversal vulnerability that allows
CVE-2026-41947 9.1 0.45% 1 0 2026-06-22T18:16:36.883000 Dify before version 1.14.2 contains an authorization bypass vulnerability that a
CVE-2026-6637 8.8 0.38% 1 0 2026-06-17T11:01:08.343000 Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged datab
CVE-2026-49103 0 0.30% 1 0 2026-06-17T10:55:30.553000 Webmin before 2.640 does not safely construct a filename for saving of an attach
CVE-2026-46243 7.1 0.31% 1 4 2026-06-17T10:53:23.893000 In the Linux kernel, the following vulnerability has been resolved: smb: client
CVE-2026-45504 8.8 0.46% 1 1 2026-06-17T10:52:10.200000 Server-side request forgery (ssrf) in Microsoft Exchange Server allows an author
CVE-2026-42508 9.1 0.37% 1 0 2026-06-17T10:47:57.267000 Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked
CVE-2026-39830 9.1 0.39% 1 0 2026-06-17T10:42:39.483000 A malicious SSH peer could send unsolicited global request responses to fill an
CVE-2026-35373 3.3 0.12% 2 0 2026-06-17T10:40:28.933000 A logic error in the ln utility of uutils coreutils causes the program to reject
CVE-2026-34926 6.7 12.68% 2 1 2026-06-17T10:39:49.727000 A directory traversal vulnerability in the Apex One (on-premise) server could al
CVE-2026-33017 9.8 98.41% 2 11 template 2026-06-17T10:36:47.177000 Langflow is a tool for building and deploying AI-powered agents and workflows. I
CVE-2026-28910 3.3 0.12% 1 0 2026-06-17T10:29:19.940000 This issue was addressed with improved permissions checking. This issue is fixed
CVE-2026-22678 5.4 0.17% 1 0 2026-06-17T10:20:13.247000 Webmin before 2.641 contains a stored cross-site scripting vulnerability in the
CVE-2026-20971 7.8 0.13% 4 0 2026-06-17T10:18:08.213000 Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local atta
CVE-2026-20245 7.8 9.92% 6 3 2026-06-17T10:17:19.370000 A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN
CVE-2026-20175 6.1 0.18% 1 0 2026-06-17T10:17:15.950000 A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker
CVE-2026-20045 8.2 4.31% 1 1 2026-06-17T10:16:58.097000 A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unif
CVE-2024-2658 0 0.41% 1 2 2026-06-17T07:24:59.037000 A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1
CVE-2018-13818 9.8 6.99% 2 0 2026-06-17T01:40:13.793000 Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search se
CVE-2014-0160 7.5 100.00% 1 74 template 2026-06-17T00:02:24.467000 The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not p
CVE-2026-10646 0 0.00% 2 0 N/A
CVE-2026-45408 0 0.23% 2 0 N/A
CVE-2026-47729 0 0.00% 3 1 N/A
CVE-2026-11705 0 0.00% 1 0 N/A
CVE-2026-20896 0 0.00% 1 0 N/A
CVE-2026-8932 0 0.00% 2 1 N/A
CVE-2026-50000 0 0.00% 1 0 N/A
CVE-2026-50160 0 0.00% 1 0 N/A

CVE-2026-13486
(7.3 HIGH)

EPSS: 0.00%

updated 2026-06-28T10:16:27.150000

2 posts

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.php. Executing a manipulation of the argument course_year_section can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

offseq at 2026-06-28T10:30:26.325Z ##

CVE-2026-13486 | SQL injection in SourceCodester Class and Exam Timetabling System (v1.0/6.php). MEDIUM severity. Exploit public for /preview6.php — remote attackers can target course_year_section param. Monitor & mitigate. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-28T10:30:26.000Z ##

CVE-2026-13486 | SQL injection in SourceCodester Class and Exam Timetabling System (v1.0/6.php). MEDIUM severity. Exploit public for /preview6.php — remote attackers can target course_year_section param. Monitor & mitigate. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #SQLi #AppSec

##

CVE-2026-46331
(7.8 HIGH)

EPSS: 0.29%

updated 2026-06-28T08:16:21.240000

8 posts

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb

4 repos

https://github.com/sgkdev/packet_edit_meme

https://github.com/HORKimhab/CVE-2026-46331

https://github.com/douglasmun/pagecache-lpe-containment-kit

https://github.com/0xBlackash/CVE-2026-46331

beyondmachines1 at 2026-06-28T09:01:21.316Z ##

Linux Kernel Pedit COW Vulnerability Grants Root Access via Page Cache Poisoning

The Linux kernel "pedit COW" vulnerability (CVE-2026-46331) allows local attackers to gain root access by poisoning the in-memory page cache of privileged binaries.

**This flaw lets attackers hide in your server memory without ever touching the files on your disk. You should patch and reboot your Linux systems ASAP to clear any potential memory poisoning. If you can't patch right away, disable the act_pedit module or restrict unprivileged user namespaces as a temporary fix.**

beyondmachines.net/event_detai

##

raul@mastodon.in4matics.cat at 2026-06-27T07:05:12.000Z ##

Linux té un exploit que dona root mentre els file-integrity checks diuen "tot bé" ✨

**pedit COW** (CVE-2026-46331): OOB write a `act_pedit` que enverina la page cache de binaris setuid. PoC en 24h. RHEL 10 i Debian 13 afectats.

Mitigació: `echo 'install act_pedit /bin/true' > /etc/modprobe.d/disable.conf`

thehackernews.com/2026/06/new-
#Linux #CVE #seguridad #sysadmin

##

tugatech@masto.pt at 2026-06-27T06:54:09.000Z ##

Uma nova vulnerabilidade no kernel do Linux, a pedit COW (CVE-2026-46331), permite a um utilizador local sem privilégios obter acesso root em máquinas afetadas. O exploit público está disponível desde junho de 2026. 🚨

🔗 tugatech.com.pt/t86365-protege

#falha #linux #sistema 

##

beyondmachines1@infosec.exchange at 2026-06-28T09:01:21.000Z ##

Linux Kernel Pedit COW Vulnerability Grants Root Access via Page Cache Poisoning

The Linux kernel "pedit COW" vulnerability (CVE-2026-46331) allows local attackers to gain root access by poisoning the in-memory page cache of privileged binaries.

**This flaw lets attackers hide in your server memory without ever touching the files on your disk. You should patch and reboot your Linux systems ASAP to clear any potential memory poisoning. If you can't patch right away, disable the act_pedit module or restrict unprivileged user namespaces as a temporary fix.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

raul@mastodon.in4matics.cat at 2026-06-27T07:05:12.000Z ##

Linux té un exploit que dona root mentre els file-integrity checks diuen "tot bé" ✨

**pedit COW** (CVE-2026-46331): OOB write a `act_pedit` que enverina la page cache de binaris setuid. PoC en 24h. RHEL 10 i Debian 13 afectats.

Mitigació: `echo 'install act_pedit /bin/true' > /etc/modprobe.d/disable.conf`

thehackernews.com/2026/06/new-
#Linux #CVE #seguridad #sysadmin

##

tugatech@masto.pt at 2026-06-27T06:54:09.000Z ##

Uma nova vulnerabilidade no kernel do Linux, a pedit COW (CVE-2026-46331), permite a um utilizador local sem privilégios obter acesso root em máquinas afetadas. O exploit público está disponível desde junho de 2026. 🚨

🔗 tugatech.com.pt/t86365-protege

#falha #linux #sistema 

##

linux@activitypub.awakari.com at 2026-06-26T13:00:41.000Z ## New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries TheHackerNews CVE-2026-46331 lets local users gain root on affected Linux systems by corrupting page-cache memory throug...

#Security #News

Origin | Interest | Match ##

guru@thecybersecguru.com at 2026-06-26T17:40:04.000Z ##

Two new Linux LPEs hit page cache from opposite ends of the kernel

Two new Linux kernel LPEs, CVE-2026-46331 (pedit COW) and CVE-2026-43503 (DirtyClone), corrupt page-cache memory to gain root without touching disk. Working exploits are public

thecybersecguru.com/news/linux

##

CVE-2026-13482
(3.7 LOW)

EPSS: 0.00%

updated 2026-06-28T05:16:21.200000

2 posts

A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the component User ID Handler. The manipulation results in use of weak hash. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit is now public and may be used. Th

offseq at 2026-06-28T07:30:25.077Z ##

CVE-2026-13482 affects skypilot-org skypilot ≤0.12.0: MEDIUM severity due to weak hash in username.encode (User ID Handler). Remote attack possible, exploit is public, but complex. Review exposure. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-28T07:30:25.000Z ##

CVE-2026-13482 affects skypilot-org skypilot ≤0.12.0: MEDIUM severity due to weak hash in username.encode (User ID Handler). Remote attack possible, exploit is public, but complex. Review exposure. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #AppSec #CVE202613482

##

CVE-2026-58053
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-06-28T03:33:40

4 posts

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with

thehackerwire@mastodon.social at 2026-06-28T06:00:10.000Z ##

🔴 CVE-2026-58053 - Critical (9.9)

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging opt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-06-28T03:00:24.974Z ##

CVE-2026-58053 (CRITICAL, CVSS 9.9) in Gitea act_runner: Improper privilege management lets workflow users escape Docker containers to host as root. Restrict workflow rights & watch for patches. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-06-28T06:00:10.000Z ##

🔴 CVE-2026-58053 - Critical (9.9)

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging opt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-06-28T03:00:24.000Z ##

CVE-2026-58053 (CRITICAL, CVSS 9.9) in Gitea act_runner: Improper privilege management lets workflow users escape Docker containers to host as root. Restrict workflow rights & watch for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE202658053 #Gitea #containers #security

##

CVE-2026-58056
(7.6 HIGH)

EPSS: 0.00%

updated 2026-06-28T02:16:32.860000

2 posts

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach the unguarded screenshot and display-capture handlers, acting outside its granted scope.

thehackerwire@mastodon.social at 2026-06-28T06:00:24.000Z ##

🟠 CVE-2026-58056 - High (7.6)

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject key...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-28T06:00:24.000Z ##

🟠 CVE-2026-58056 - High (7.6)

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject key...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58050
(7.0 HIGH)

EPSS: 0.00%

updated 2026-06-28T02:16:32.017000

2 posts

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap

DailyCyberSecurity at 2026-06-28T08:30:14.439Z ##

Researchers publicly disclosed a libssh2 vulnerability, CVE-2026-58050, with PoC code. A malicious SSH server can corrupt a client's heap. Patch now.

securityonline.info/libssh2-vu

##

DailyCyberSecurity@infosec.exchange at 2026-06-28T08:30:14.000Z ##

Researchers publicly disclosed a libssh2 vulnerability, CVE-2026-58050, with PoC code. A malicious SSH server can corrupt a client's heap. Patch now.

#libssh2 #CVE202658050 #SSH #HeapOverflow #PoC #Cybersecurity #Infosec

securityonline.info/libssh2-vu

##

CVE-2026-58049
(8.6 HIGH)

EPSS: 0.00%

updated 2026-06-28T02:16:30.477000

2 posts

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled ou

thehackerwire@mastodon.social at 2026-06-28T06:00:34.000Z ##

🟠 CVE-2026-58049 - High (8.6)

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-28T06:00:34.000Z ##

🟠 CVE-2026-58049 - High (8.6)

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8095
(8.1 HIGH)

EPSS: 0.00%

updated 2026-06-28T00:16:25.180000

4 posts

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase evades the unset check and is normalized to wpfm_dir_path by sanitize_key() during u

thehackerwire@mastodon.social at 2026-06-28T06:01:17.000Z ##

🟠 CVE-2026-8095 - High (8.1)

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-06-28T00:00:35.779Z ##

CVE-2026-8095: nmedia Frontend File Manager Plugin (WordPress) HIGH severity vuln (CVSS 8.1) allows Subscriber+ users to delete arbitrary files 🛡️. Patch ASAP and monitor for unauthorized deletions. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-06-28T06:01:17.000Z ##

🟠 CVE-2026-8095 - High (8.1)

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-06-28T00:00:35.000Z ##

CVE-2026-8095: nmedia Frontend File Manager Plugin (WordPress) HIGH severity vuln (CVSS 8.1) allows Subscriber+ users to delete arbitrary files 🛡️. Patch ASAP and monitor for unauthorized deletions. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Infosec

##

CVE-2026-10643
(8.7 HIGH)

EPSS: 0.00%

updated 2026-06-28T00:16:24.637000

4 posts

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg-msg_controllen < pktinfo_len) before writing a full control message consisting of an aligned cmsg header plus the payload. Because the check omitted the cmsg header size, a control buffer whose length fal

thehackerwire@mastodon.social at 2026-06-28T06:01:28.000Z ##

🟠 CVE-2026-10643 - High (8.7)

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg-msg_controllen &lt; pktinfo_len) before writing a f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-06-28T01:30:24.885Z ##

CVE-2026-10643: Zephyr (3.6.0 – 4.4.0) HIGH severity bug enables out-of-bounds kernel heap writes via recvmsg() with IP_PKTINFO. Local users can exploit for memory corruption or escalation. Patch pending — check advisories. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-06-28T06:01:28.000Z ##

🟠 CVE-2026-10643 - High (8.7)

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg-msg_controllen &lt; pktinfo_len) before writing a f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-06-28T01:30:24.000Z ##

CVE-2026-10643: Zephyr (3.6.0 – 4.4.0) HIGH severity bug enables out-of-bounds kernel heap writes via recvmsg() with IP_PKTINFO. Local users can exploit for memory corruption or escalation. Patch pending — check advisories. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #CVE202610643 #infosec

##

CVE-2026-9677
(0 None)

EPSS: 0.15%

updated 2026-06-27T06:16:34.783000

2 posts

The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML via the generateshariff() function, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

offseq at 2026-06-27T07:30:24.103Z ##

CVE-2026-9677: HIGH severity stored XSS in Shariff for WordPress (<=1.0.11). Unsanitized shariff_infourl allows high privilege users to inject persistent scripts — risk increases in multisite setups. Restrict admin access. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-27T07:30:24.000Z ##

CVE-2026-9677: HIGH severity stored XSS in Shariff for WordPress (<=1.0.11). Unsanitized shariff_infourl allows high privilege users to inject persistent scripts — risk increases in multisite setups. Restrict admin access. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #XSS #Infosec

##

CVE-2026-12415
(9.8 CRITICAL)

EPSS: 0.66%

updated 2026-06-27T05:16:41.620000

4 posts

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account, accepts an attacker-controlled user_id and user_email from POST data, and calls wp_update_user() without verifying authentic

1 repos

https://github.com/xxconi/CVE-2026-12415-or-CVE-2026-12416.py

thehackerwire@mastodon.social at 2026-06-27T15:00:12.000Z ##

🔴 CVE-2026-12415 - Critical (9.8)

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-06-27T06:00:23.611Z ##

CVE-2026-12415: pravel Invoice Generator ≤1.0.0 suffers CRITICAL privilege escalation — unauthenticated users can reset any account, incl. admins, via exposed AJAX handler. Disable plugin or restrict access ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-06-27T15:00:12.000Z ##

🔴 CVE-2026-12415 - Critical (9.8)

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-06-27T06:00:23.000Z ##

CVE-2026-12415: pravel Invoice Generator ≤1.0.0 suffers CRITICAL privilege escalation — unauthenticated users can reset any account, incl. admins, via exposed AJAX handler. Disable plugin or restrict access ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Infosec

##

CVE-2026-11807
(9.6 CRITICAL)

EPSS: 0.37%

updated 2026-06-27T05:16:41.450000

1 posts

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive plaintext credentials associated with that activation, including OAuth tokens, vault passwords, and SSH

offseq@infosec.exchange at 2026-06-24T00:00:36.000Z ##

CVE-2026-11807 (CRITICAL, CVSS 9.6) affects Red Hat Ansible Automation Platform 2.5: missing authorization in EDA websocket API lets any authenticated user access plaintext credentials. Patch immediately. radar.offseq.com/threat/cve-20 #OffSeq #RedHat #Ansible #Vuln

##

CVE-2026-57231
(7.5 HIGH)

EPSS: 0.26%

updated 2026-06-27T04:17:52.313000

2 posts

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can

canartuc@mastodon.social at 2026-06-27T11:43:00.000Z ##

We treat containers as a boundary: the image runs, the host stays private. CVE-2026-57231 punched through that for Podman before 5.8.4, letting a crafted image read the host's own environment variables by shipping malformed Env entries, even via glob patterns. Environments are where registry tokens and CI secrets usually sit. Now that 5.8.4 is out, how fast can you roll it across your build fleet?
#containers #security

##

canartuc@mastodon.social at 2026-06-27T10:55:00.000Z ##

Podman 5.8.4 closes CVE-2026-57231. A malicious image could ship malformed Env entries that, when the container started, leaked the host's environment variables into it, including through glob operators that grab multiple variables without knowing their names. The release also updates golang.org/x/crypto to v0.53.0 for CVE-2026-39830 and CVE-2026-42508. When you pull a public image, do you think about what its metadata can read from your host?
#containers #security

##

CVE-2026-54352
(9.6 CRITICAL)

EPSS: 0.47%

updated 2026-06-27T04:17:51.583000

3 posts

Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with extract-zip@2.0.1 into a temp directory, then for each entry listed in icons.json validates the icon path, opens it, and streams the bytes into MinIO. The resulting object is served back via GET /api/assets/{appI

thehackerwire@mastodon.social at 2026-06-28T11:00:17.000Z ##

🔴 CVE-2026-54352 - Critical (9.6)

Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with extract-zip@2.0.1 into a temp directory, then for each entr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

hugovalters@mastodon.social at 2026-06-28T09:07:07.000Z ##

CVE-2026-54352 - Critical Path Traversal in Budibase. Symlink extraction allows reading arbitrary files. CVSS 9.6. Unpatched - limit builder access immediately. #CVE #Budibase #infosec

valtersit.com/cve/CVE-2026-543

##

thehackerwire@mastodon.social at 2026-06-28T11:00:17.000Z ##

🔴 CVE-2026-54352 - Critical (9.6)

Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with extract-zip@2.0.1 into a temp directory, then for each entr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50136
(7.4 HIGH)

EPSS: 0.33%

updated 2026-06-27T04:17:49.740000

1 posts

Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject presigned URLs using credentials stored in a workspace datasource. The route is protected only by the recaptcha middleware and does not require authentication, table permission, datasource permission, or builder access. A public caller who knows a wo

hugovalters@mastodon.social at 2026-06-27T12:13:31.000Z ##

CVE-2026-50136 - Supply Chain Attack in Budibase. Unauthenticated endpoint exposes S3 presigned URLs. CVSS 7.4. No known patch. Mitigate immediately. #CVE #Budibase #infosec

valtersit.com/cve/CVE-2026-501

##

CVE-2026-56414
(7.2 HIGH)

EPSS: 0.40%

updated 2026-06-26T23:17:09.137000

2 posts

A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations intended for trusted certificate material, which could affect system integrity o

offseq at 2026-06-27T01:30:27.955Z ##

CVE-2026-56414: H.VIEW HV-500S6 IP Camera has a HIGH-severity vuln (CVSS 7.2) allowing authenticated users to upload arbitrary files via certificate upload, risking persistent compromise. Restrict admin access & monitor uploads. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-27T01:30:27.000Z ##

CVE-2026-56414: H.VIEW HV-500S6 IP Camera has a HIGH-severity vuln (CVSS 7.2) allowing authenticated users to upload arbitrary files via certificate upload, risking persistent compromise. Restrict admin access & monitor uploads. radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #CVE #Vulnerability

##

CVE-2026-55975
(7.2 HIGH)

EPSS: 0.65%

updated 2026-06-26T23:17:08.997000

2 posts

A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate creation command without proper input validation. This may allow for command execution with elevated privileges during certificate generation.

offseq at 2026-06-27T03:00:23.955Z ##

H.VIEW HV-500S6 IP Camera has a HIGH severity bug (CVE-2026-55975, CVSS 7.2): Authenticated users may inject commands using unsanitized XML in cert generation. Restrict access, monitor activity, and check for patches. radar.offseq.com/threat/cve-20 🔒

##

offseq@infosec.exchange at 2026-06-27T03:00:23.000Z ##

H.VIEW HV-500S6 IP Camera has a HIGH severity bug (CVE-2026-55975, CVSS 7.2): Authenticated users may inject commands using unsanitized XML in cert generation. Restrict access, monitor activity, and check for patches. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity 🔒

##

CVE-2026-33560
(7.1 HIGH)

EPSS: 0.34%

updated 2026-06-26T23:17:08.847000

2 posts

The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.

offseq at 2026-06-27T10:30:25.026Z ##

Daktronics VFC-DMP-5000 is affected by CVE-2026-33560 (HIGH, CVSS 7.1) — authenticated users can upload any file type, risking code execution. No patch yet; restrict permissions, monitor uploads. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-27T10:30:25.000Z ##

Daktronics VFC-DMP-5000 is affected by CVE-2026-33560 (HIGH, CVSS 7.1) — authenticated users can upload any file type, risking code execution. No patch yet; restrict permissions, monitor uploads. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Daktronics #CVE202633560

##

CVE-2026-31928
(8.1 HIGH)

EPSS: 0.45%

updated 2026-06-26T23:17:08.697000

4 posts

The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.

thehackerwire@mastodon.social at 2026-06-27T15:00:32.000Z ##

🟠 CVE-2026-31928 - High (8.1)

The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-06-27T09:00:26.227Z ##

CVE-2026-31928 (HIGH, CVSS 8.1) affects Daktronics VFC-DMP-5000: default admin creds + weak auth allow full device takeover via web interface. No patch yet — change creds & restrict access now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-06-27T15:00:32.000Z ##

🟠 CVE-2026-31928 - High (8.1)

The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-06-27T09:00:26.000Z ##

CVE-2026-31928 (HIGH, CVSS 8.1) affects Daktronics VFC-DMP-5000: default admin creds + weak auth allow full device takeover via web interface. No patch yet — change creds & restrict access now. radar.offseq.com/threat/cve-20
#OffSeq #Cybersecurity #Vulnerability #CVE202631928

##

CVE-2026-28701
(9.8 CRITICAL)

EPSS: 0.84%

updated 2026-06-26T23:17:08.537000

4 posts

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.

thehackerwire@mastodon.social at 2026-06-27T15:00:22.000Z ##

🔴 CVE-2026-28701 - Critical (9.8)

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-06-27T00:00:40.082Z ##

Daktronics VFC-DMP-5000 firmware has a CRITICAL vuln (CVE-2026-28701, CVSS 9.8): remote attackers can traverse directories & enumerate file paths — no auth needed. No patch yet. Restrict network access & monitor closely. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-06-27T15:00:22.000Z ##

🔴 CVE-2026-28701 - Critical (9.8)

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-06-27T00:00:40.000Z ##

Daktronics VFC-DMP-5000 firmware has a CRITICAL vuln (CVE-2026-28701, CVSS 9.8): remote attackers can traverse directories & enumerate file paths — no auth needed. No patch yet. Restrict network access & monitor closely. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #IoT

##

CVE-2026-55069
(8.7 HIGH)

EPSS: 0.15%

updated 2026-06-26T22:16:33.093000

2 posts

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS workflow orchestration platform. An attacker who gains read access to the PostgreSQL database can exploit SHA-512's high computation speed to recover the administrator password offline. In Kubernetes deployments, a successful crack fu

thehackerwire@mastodon.social at 2026-06-27T17:00:23.000Z ##

🟠 CVE-2026-55069 - High (8.7)

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS workflow orchestration platform. An attacker who gains read access to the Postgre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-27T17:00:23.000Z ##

🟠 CVE-2026-55069 - High (8.7)

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS workflow orchestration platform. An attacker who gains read access to the Postgre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53576
(10.0 CRITICAL)

EPSS: 0.47%

updated 2026-06-26T22:16:32.840000

2 posts

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a credential check. kestra addresses its resources by URL path segments that the caller chooses (/api/v1/{tenant}/flows/{namespace},

thehackerwire@mastodon.social at 2026-06-27T20:00:15.000Z ##

🔴 CVE-2026-53576 - Critical (10)

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-27T20:00:15.000Z ##

🔴 CVE-2026-53576 - Critical (10)

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49984
(7.7 HIGH)

EPSS: 0.37%

updated 2026-06-26T22:16:32.243000

2 posts

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied paths for .. traversal before it converts Windows-style backslashes to forward slashes. An attacker can therefore smuggle a traversal sequence past the guard using backslashes (..\..\..\); the guard sees a harmless string, and the path is only rewrit

thehackerwire@mastodon.social at 2026-06-27T17:00:44.000Z ##

🟠 CVE-2026-49984 - High (7.7)

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied paths for .. traversal before it converts Windows-style backslashes to forward slashes. An attack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-27T17:00:44.000Z ##

🟠 CVE-2026-49984 - High (7.7)

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied paths for .. traversal before it converts Windows-style backslashes to forward slashes. An attack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49869
(10.0 CRITICAL)

EPSS: 0.69%

updated 2026-06-26T22:16:32.113000

2 posts

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated r

thehackerwire@mastodon.social at 2026-06-27T17:00:33.000Z ##

🔴 CVE-2026-49869 - Critical (10)

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-27T17:00:33.000Z ##

🔴 CVE-2026-49869 - Critical (10)

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45807
(7.7 HIGH)

EPSS: 0.37%

updated 2026-06-26T22:16:31.973000

2 posts

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints accept a kestra:// URI from the client and pass it through StorageInterface.parentTraversalGuard before reading the underlying file from the local storage backend. The guard only inspects the literal URI.toString(), so a URL-encoded .. written as %2E%2E slips through. The downstr

thehackerwire@mastodon.social at 2026-06-27T20:00:26.000Z ##

🟠 CVE-2026-45807 - High (7.7)

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints accept a kestra:// URI from the client and pass it through StorageInterface.parentTraversalGuard before reading the underlying ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-27T20:00:26.000Z ##

🟠 CVE-2026-45807 - High (7.7)

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints accept a kestra:// URI from the client and pass it through StorageInterface.parentTraversalGuard before reading the underlying ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54353
(8.5 HIGH)

EPSS: 0.24%

updated 2026-06-26T21:16:35.417000

2 posts

Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding. The outbound fetch flow validates a hostname against the blacklist before the request is sent, but the actual socket connection later performs a separate DNS lookup through node-fetch. Since the validated IPs are never pinned to

thehackerwire@mastodon.social at 2026-06-28T11:00:27.000Z ##

🟠 CVE-2026-54353 - High (8.5)

Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding. The outbound fetch flow validates a hostname against the blacklist before th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-28T11:00:27.000Z ##

🟠 CVE-2026-54353 - High (8.5)

Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding. The outbound fetch flow validates a hostname against the blacklist before th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54351
(8.2 HIGH)

EPSS: 0.41%

updated 2026-06-26T21:16:35.170000

2 posts

Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automation execution parameters. A mass assignment vulnerability in externalTrigger() allows an attacker to overwrite the internal appId property by including it in the webhook POST body. When the automation is processed asynchron

thehackerwire@mastodon.social at 2026-06-28T06:01:39.000Z ##

🟠 CVE-2026-54351 - High (8.2)

Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automation execution parameters. A mass assignment vulnerability in externalT...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-28T06:01:39.000Z ##

🟠 CVE-2026-54351 - High (8.2)

Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automation execution parameters. A mass assignment vulnerability in externalT...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54350
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-06-26T21:16:35.040000

2 posts

Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with-JSON-body collection and, where the builder has published a PUBLIC write query, modifies every document of that collection with one HTTP request. enrichContext at packages/server

thehackerwire@mastodon.social at 2026-06-27T20:00:36.000Z ##

🔴 CVE-2026-54350 - Critical (10)

Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with-JSON-body collection and,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-27T20:00:36.000Z ##

🔴 CVE-2026-54350 - Critical (10)

Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with-JSON-body collection and,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48778
(7.8 HIGH)

EPSS: 1.37%

updated 2026-06-26T21:16:34.167000

3 posts

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter"> tag in config.xml is read by NppXml::value() (Parameters.cpp:6430) and stored in _nppGUI._commandLineInterpreter without any validation, whitelist, or digital signature check. When the user triggers IDM_FILE_OPEN_CMD (File → Open Containing Folder → cmd), NppCommands.cpp:228 crea

3 repos

https://github.com/kavin-jindal/CVE-2026-48778-PoC

https://github.com/atiilla/Notepad-8.9.6-PoC

https://github.com/XK3NF4/CVE-2026-48778

thehackerwire@mastodon.social at 2026-06-28T11:00:39.000Z ##

🟠 CVE-2026-48778 - High (7.8)

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the tag in config.xml is read by NppXml::value() (Parameters.cpp:6430) and stored in _nppGUI._commandLineInterpreter without any validation, whitelist, or digital signature...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

hugovalters@mastodon.social at 2026-06-27T17:13:34.000Z ##

CVE-2026-48778 - Supply chain attack in Notepad++ pre-8.9.6.1. Unsanitized config.xml input leads to arbitrary command execution via File > Open Containing Folder > cmd. CVSS 7.8. No patch available. Disable feature or isolate. #CVE #Notepad #infosec

valtersit.com/cve/CVE-2026-487

##

thehackerwire@mastodon.social at 2026-06-28T11:00:39.000Z ##

🟠 CVE-2026-48778 - High (7.8)

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the tag in config.xml is read by NppXml::value() (Parameters.cpp:6430) and stored in _nppGUI._commandLineInterpreter without any validation, whitelist, or digital signature...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8797
(0 None)

EPSS: 0.12%

updated 2026-06-26T20:23:02.513000

1 posts

An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.

offseq@infosec.exchange at 2026-06-26T06:00:25.000Z ##

HIGH severity: CVE-2026-8797 impacts NEC ExpressUpdate Agent for Windows. Exposed IOCTL enables local privilege escalation to SYSTEM. No patch yet — restrict local access, monitor activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Windows #PrivilegeEscalation

##

CVE-2026-55189
(7.7 HIGH)

EPSS: 0.20%

updated 2026-06-26T20:20:22.420000

1 posts

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read and probe handlers dispatch directly to the storage backend without ever calling the IAM authorization function that the FTP write/list handlers (and the entire HTTP S3 path) use. As a result, any user who can authenticate to the FTP listener — includin

hugovalters@mastodon.social at 2026-06-27T14:06:48.000Z ##

CVE-2026-55189 - Unauthorized data access in Rustfs FTP frontend. IAM bypass allows read/stat operations on restricted objects. CVSS 7.7. Unpatched - disable FTP or restrict network access immediately. #CVE #rustfs #infosec

valtersit.com/cve/CVE-2026-551

##

CVE-2026-52784
(8.8 HIGH)

EPSS: 0.16%

updated 2026-06-26T20:20:22.420000

1 posts

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via POST parameter "user[admin]". This vulnerability is fixed in 17.3.3 and 17.4.1.

hugovalters@mastodon.social at 2026-06-26T23:13:15.000Z ##

CVE-2026-52784 - Critical CSRF in OpenProject. Attackers can escalate privileges via /users/:id. CVSS 8.8. Update to 17.3.3 or 17.4.1 immediately. #CVE #OpenProject #infosec

valtersit.com/cve/CVE-2026-527

##

CVE-2026-48933
(7.5 HIGH)

EPSS: 0.57%

updated 2026-06-26T20:19:23.707000

1 posts

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

offseq@infosec.exchange at 2026-06-26T04:30:25.000Z ##

Node.js WebCrypto in v22.22.3, v24.16.0, v26.3.0 is affected by CVE-2026-48933 (HIGH). Integer overflow in subtle.encrypt() can crash processes with inputs ≥ 2 GiB, causing DoS. Avoid large inputs while awaiting a fix. 🔐 radar.offseq.com/threat/cve-20 #OffSeq #Nodejs #Vuln

##

CVE-2026-48618
(6.5 MEDIUM)

EPSS: 0.61%

updated 2026-06-26T20:18:43.557000

1 posts

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Nod

offseq@infosec.exchange at 2026-06-26T03:00:24.000Z ##

CVE-2026-48618: Node.js HIGH severity vuln in TLS hostname handling (Unicode dot normalization flaw). Affects 22.22.3, 24.16.0, 26.3.0. No patch yet — restrict use & monitor vendor advisory. radar.offseq.com/threat/cve-20 #OffSeq #NodeJS #Vulnerability #TLS #Security

##

CVE-2026-54317
(7.6 HIGH)

EPSS: 0.19%

updated 2026-06-26T20:17:26.380000

1 posts

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked as not requiring authentication (requires_auth = False). A comment next to that line says auth is instead handled "via the access token from configura

hugovalters@mastodon.social at 2026-06-24T12:14:14.000Z ##

CVE-2026-54317 - Authentication Bypass in Home Assistant. Konnected integration exposes an unauthenticated HTTP endpoint allowing unauthorized write requests. CVSS 7.6. Update to 2026.6.0 immediately. #CVE #HomeAssistant #infosec

valtersit.com/cve/CVE-2026-543

##

CVE-2026-9222
(8.1 HIGH)

EPSS: 0.24%

updated 2026-06-26T20:08:23.053000

1 posts

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.

offseq@infosec.exchange at 2026-06-26T00:00:40.000Z ##

Setracker2 Android app (com.tgelec.setracker) hit by CRITICAL vuln (CVE-2026-9222, CVSS 9.2): uses password hash for authentication. Anyone with the hash can access backend services. Update guidance pending. radar.offseq.com/threat/cve-20 #OffSeq #AndroidSec #CVE20269222

##

CVE-2026-56876
(8.1 HIGH)

EPSS: 0.32%

updated 2026-06-26T20:05:14.220000

1 posts

extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.

hugovalters@mastodon.social at 2026-06-27T09:01:05.000Z ##

CVE-2026-56876 - Path Traversal in Extract-zip. Symlink handling flaw allows arbitrary file read/write via malicious zip. CVSS 8.1. No patch available. Avoid untrusted archives. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-568

##

CVE-2026-55454
(9.9 CRITICAL)

EPSS: 0.33%

updated 2026-06-26T19:50:41.937000

1 posts

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by default — is bound on 0.0.0.0:2019 inside the container. While this listener is not directly published to the host by docker-compose.yml, it is reachable from the Appsmith server process itself or a SSRF vulnerability. An authentic

offseq@infosec.exchange at 2026-06-25T00:00:36.000Z ##

CVE-2026-55454: CRITICAL (CVSS 9.9) vuln in appsmithorg Appsmith <2.1. Unauth Caddy admin API inside container can be exploited via SSRF by low-priv users to control reverse proxy. Upgrade to 2.1+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202655454 #appsmith

##

CVE-2026-57915
(7.3 HIGH)

EPSS: 0.26%

updated 2026-06-26T19:16:45.433000

1 posts

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

canartuc@mastodon.social at 2026-06-27T19:33:00.000Z ##

Apache Kerby, the Java implementation of Kerberos, shipped a fix for CVE-2026-57915: an authentication bypass where an attacker could skip pre-authentication by sending PA-DATA with an unrecognized or unsupported type. The severity is rated important, and the fix is in Kerby 2.1.2. How many Kerberos stacks silently accept PA-DATA types they do not understand, and how many of those are known to operators?
#Kerberos #security

##

CVE-2026-56663
(8.5 HIGH)

EPSS: 0.22%

updated 2026-06-26T19:16:44.880000

1 posts

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.52, an authenticated user can bypass the SSRF / private-IP protections in SendWebRequestBlock and reach internal network services. _is_ip_blocked() in backend/backend/util/request.py does not normalize IPv4-mapped IPv6 addresses before checking resolved IPs agains

hugovalters@mastodon.social at 2026-06-27T05:06:50.000Z ##

CVE-2026-56663 - SSRF bypass in AutoGPT allows authenticated users to access internal networks. CVSS 8.5. No patch available. Block special-use IPs and restrict access immediately. #CVE #AutoGPT #infosec

valtersit.com/cve/CVE-2026-566

##

CVE-2026-55200
(8.1 HIGH)

EPSS: 0.92%

updated 2026-06-26T19:15:53.083000

3 posts

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.

1 repos

https://github.com/0xBlackash/CVE-2026-55200

Sempf@infosec.exchange at 2026-06-26T00:53:38.000Z ##

Just saw there is an exploit example for that libssh2 vuln. Has anyone given it a try yet? I might be too lazy to get my laptop out.

github.com/0xBlackash/CVE-2026

##

xeiaso.net@bsky.brid.gy at 2026-06-24T17:31:32.235Z ##

"No way to prevent this" say users of only language where this regularly happens https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-55200/

"No way to prevent this" say u...

##

cadey@pony.social at 2026-06-24T17:31:32.000Z ##

"No way to prevent this" say users of only language where this regularly happens

xeiaso.net/shitposts/no-way-to

##

CVE-2026-13311
(7.5 HIGH)

EPSS: 0.36%

updated 2026-06-26T19:03:34.507000

1 posts

shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacker who can supply an attacker-controlled string to any code path that calls parse() (no shell metacharacters are required

offseq@infosec.exchange at 2026-06-25T06:00:27.000Z ##

ljharb shell-quote <=1.8.4 is impacted by CVE-2026-13311 (HIGH). Inefficient parsing can let attackers trigger DoS by blocking the Node.js event loop. Patch to 1.8.5+ now! 🛡️ radar.offseq.com/threat/cve-20 #OffSeq #InfoSec #NodeJS #CVE202613311

##

CVE-2026-43503
(8.8 HIGH)

EPSS: 0.13%

updated 2026-06-26T18:57:17.887000

4 posts

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when moving frags from source to destination. __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header(

6 repos

https://github.com/sec0x/CVE-2026-43503

https://github.com/0xBlackash/CVE-2026-43503

https://github.com/gl1tch0x1/DirtyClone

https://github.com/aexdyhaxor/CVE-2026-43503-DirtyClone

https://github.com/douglasmun/pagecache-lpe-containment-kit

https://github.com/mooder1/dirtyclone-CVE-2026-43503

tugatech@masto.pt at 2026-06-27T06:53:31.000Z ##

Nova vulnerabilidade DirtyClone no Linux permite controlo total do sistema. A falha, conhecida como CVE-2026-43503, permite a um utilizador local com poucos privilégios corromper a memória suportada por ficheiros através de um pacote de rede clonado, obtendo acesso de administrador. 🛡️

🔗 tugatech.com.pt/t86364-nova-vu

#controlo #linux #sistema #vulnerabilidade 

##

linux@activitypub.awakari.com at 2026-06-28T06:43:52.000Z ## DirtyClone Is the Fourth ‘Dirty’ Linux Kernel Exploit in Six Weeks CVE-2026-43503 DirtyClone is the fourth DirtyFrag-family privilege escalation in six weeks. JFrog's public PoC raises the ...

#Latest #Cyber #Security #News #| #Network #Security #Hacking #CVE-2026-43503 #DirtyClone #DirtyFrag

Origin | Interest | Match ##

tugatech@masto.pt at 2026-06-27T06:53:31.000Z ##

Nova vulnerabilidade DirtyClone no Linux permite controlo total do sistema. A falha, conhecida como CVE-2026-43503, permite a um utilizador local com poucos privilégios corromper a memória suportada por ficheiros através de um pacote de rede clonado, obtendo acesso de administrador. 🛡️

🔗 tugatech.com.pt/t86364-nova-vu

#controlo #linux #sistema #vulnerabilidade 

##

guru@thecybersecguru.com at 2026-06-26T17:40:04.000Z ##

Two new Linux LPEs hit page cache from opposite ends of the kernel

Two new Linux kernel LPEs, CVE-2026-46331 (pedit COW) and CVE-2026-43503 (DirtyClone), corrupt page-cache memory to gain root without touching disk. Working exploits are public

thecybersecguru.com/news/linux

##

CVE-2026-57880
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-06-26T18:17:04.987000

1 posts

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest authentication fields. A remote attacker may exploit this vulnerability by sending a crafted RTSP request containing overly long authentication data, resulting in memory corruption,

offseq@infosec.exchange at 2026-06-26T12:00:28.000Z ##

GeoVision GV-LPC2011/2211 devices (≤1.12) face CRITICAL CVE-2026-57880: stack-based buffer overflow in RTSP auth enables remote, unauthenticated DoS or code execution. Restrict RTSP access, monitor traffic. Patch status unknown. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #CVE

##

CVE-2026-57881
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-26T17:16:35.753000

1 posts

An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation when processing remote login data. A remote attacker may exploit this vulnerability by sending crafted login data with overly long input, resulting in memory corruption, denial of service, or potentially

offseq@infosec.exchange at 2026-06-26T10:30:26.000Z ##

GeoVision GV-LPC2011/2211 (<=1.12) hit by CVE-2026-57881: CRITICAL stack-based buffer overflow in vlsvr enables unauthenticated RCE or DoS. No patch yet — restrict access & monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #CVE202657881

##

CVE-2026-57879
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-06-26T17:16:35.653000

1 posts

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing RTSP custom authentication data. A remote attacker may exploit this vulnerability by sending a crafted RTSP request, resulting in memory corruption, denial of service, or potentially arbitra

offseq@infosec.exchange at 2026-06-26T13:30:35.000Z ##

GeoVision GV-LPC2011/2211 (≤v1.12) affected by CVE-2026-57879: CRITICAL stack-based buffer overflow in ssvr (CVSS 9.8). Remote, unauthenticated code execution possible via crafted RTSP. Restrict RTSP & monitor. radar.offseq.com/threat/cve-20 #OffSeq #CVE202657879 #infosec #IoT

##

CVE-2026-8380
(6.5 MEDIUM)

EPSS: 0.34%

updated 2026-06-26T16:17:26.200000

1 posts

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin through 23.6's "Allow guest uploads" setting is enabled by an administrator, the sam

1 repos

https://github.com/tiagob0b/CVE-2026-8380

offseq@infosec.exchange at 2026-06-26T07:30:25.000Z ##

CVE-2026-8380: HIGH severity in Frontend File Manager Plugin (≤23.6) for WordPress. Author+ users can delete any post/page; guest deletion possible if enabled. Disable 'Allow guest uploads' until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #BlueTeam

##

CVE-2026-54825
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-06-26T15:32:21

1 posts

Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.

hugovalters@mastodon.social at 2026-06-27T23:02:30.000Z ##

CVE-2026-54825 - SQL Injection in wpDataTables <=7.4. Unauthenticated exploit. CVSS 9.3. No patch yet. Disable plugin or restrict access immediately. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-548

##

CVE-2026-20230
(8.6 HIGH)

EPSS: 41.69%

updated 2026-06-26T14:58:43.440000

13 posts

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this

3 repos

https://github.com/W5M1n9/Cisco-Unified-Communications-Manager-Server-Side-Forgery-Request-Vulnerability-CVE-2026-20230

https://github.com/HORKimhab/CVE-2026-20230

https://github.com/HalilDeniz/CVE-2026-20230-Scanner

thecybermind at 2026-06-28T09:31:43.977Z ##

🛡️ The patch window has collapsed. This week's Cyber Mind Brief breaks down CISA's emergency Cisco SSRF (CVE-2026-20230) mandate, the 2026 Verizon DBIR shift to machine-speed exploits, and tactical moves to harden your Zero Trust perimeter. Read the full operational intel: thecybermind.co/5ee6

##

CapTechGroup@mastodon.social at 2026-06-27T14:38:32.000Z ##

CVE-2026-20230 (Cisco UCM) and CVE-2026-12569 (PTC Windchill/FlexPLM) are actively exploited. The Cisco flaw is unauthenticated SSRF enabling arbitrary file writes; PTC involves unsafe deserialization leading to RCE....

captechgroup.com/threat-intell

##

thecybermind at 2026-06-27T05:45:26.256Z ##

CISA confirms active zero-day exploitation of Cisco Unified CM (CVE-2026-20230), introducing a critical SSRF vector that allows threat actors to bypass internal security boundaries. Access our complete executive risk mitigation framework and boardroom governance strategy: thecybermind.co/ptus

##

thecybermind@infosec.exchange at 2026-06-28T09:31:43.000Z ##

🛡️ The patch window has collapsed. This week's Cyber Mind Brief breaks down CISA's emergency Cisco SSRF (CVE-2026-20230) mandate, the 2026 Verizon DBIR shift to machine-speed exploits, and tactical moves to harden your Zero Trust perimeter. Read the full operational intel: thecybermind.co/5ee6

##

thecybermind@infosec.exchange at 2026-06-27T05:45:26.000Z ##

CISA confirms active zero-day exploitation of Cisco Unified CM (CVE-2026-20230), introducing a critical SSRF vector that allows threat actors to bypass internal security boundaries. Access our complete executive risk mitigation framework and boardroom governance strategy: thecybermind.co/ptus

##

secdb@infosec.exchange at 2026-06-25T21:02:25.000Z ##

🚨 [CISA-2026:0625] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-12569 (secdb.nttzen.cloud/cve/detail/)
- Name: PTC Windchill and FlexPLM Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PTC
- Product: Windchill and FlexPLM
- Notes: ptc.com/en/support/article/CS4 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-20230 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Unified Communications Manager
- Notes: cisco.com/c/en/us/support/docs ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260625 #cisa20260625 #cve_2026_12569 #cve_2026_20230 #cve202612569 #cve202620230

##

cisakevtracker@mastodon.social at 2026-06-25T20:01:06.000Z ##

CVE ID: CVE-2026-20230
Vendor: Cisco
Product: Unified Communications Manager
Date Added: 2026-06-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

PC_Fluesterer@social.tchncs.de at 2026-06-25T16:42:41.000Z ##

Cisco unter Beschuss

Es ist alles nicht so schlimm wie es aussieht, es ist alles viel viel schlimmer. Nicht nur werden in schöner (?) Regelmäßigkeit gefährliche Sicherheitslücken in Cisco-Produkten gefunden, sondern sie werden auch sofort für Angriffe ausgenutzt - manche schon vor der Veröffentlichung (Zero-Day). Eine kleine Historie füge ich unten an. Beginnen wir mit CVE-2026-20230 (8,6 von 10), über die ich noch nicht explizit berichtet hatte. Am Anfang Juni hatte Cisco Flicken gegen diese Sicherheitslücke veröffentlicht. Damals vermeldete die Firma, dass ein PoC Exploit vorläge. Anscheinend haben unbekannte Hacker den PoC gleich in einen

pc-fluesterer.info/wordpress/2

#0day #backdoor #cybercrime #exploits #hersteller #politik #privacy #sicherheit #spionage #UnplugTrump #wissen #zeroday

##

thecybermind@infosec.exchange at 2026-06-25T10:06:07.000Z ##

Critical zero-day alert: Cisco CUCM WebDialer SSRF (CVE-2026-20230) allows unauthenticated remote root file-writes. We map out the Tomcat log baselines, JSP shell indicators, and edge isolation steps in our latest TSUITE Runbook. Protect your voice network: mike@thecybermind.co. #Infosec

##

beyondmachines1@infosec.exchange at 2026-06-25T09:01:30.000Z ##

Active Exploitation of Cisco Unified Communications Manager Vulnerabilities Grants Root Access

Cisco Unified Communications Manager is facing active exploitation of two vulnerabilities, CVE-2026-20230 and CVE-2026-20045, which allow unauthenticated attackers to gain root access and deploy webshells.

**Apply the latest software updates, including Unified CM 14SU6 and 15SU5, immediately. If patching is not possible, disable the Cisco WebDialer Web Service to sever the attack path, and aggressively audit your /platform-services/ directory for unusual .jsp files or unauthorized webshells.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

thenewoil@mastodon.thenewoil.org at 2026-06-24T20:00:03.000Z ##

#Cisco #UnifiedCM flaw CVE-2026-20230 now exploited in attacks

bleepingcomputer.com/news/secu

#cybersecurity

##

tugatech@masto.pt at 2026-06-24T06:45:50.000Z ##

Falha crítica em servidores da Cisco está a ser ativamente explorada. A vulnerabilidade CVE-2026-20230 afeta o Unified Communications Manager e a Session Management Edition, exigindo ação imediata dos administradores de sistemas em Portugal. ⚠️

🔗 tugatech.com.pt/t86118-falha-c

#falha 

##

oversecurity@mastodon.social at 2026-06-23T22:30:19.000Z ##

Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks

A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks.

🔗️ [Bleepingcomputer] link.is.it/Y4BXYl

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 1.11%

updated 2026-06-26T14:35:41.477000

7 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

CapTechGroup@mastodon.social at 2026-06-27T14:38:32.000Z ##

CVE-2026-20230 (Cisco UCM) and CVE-2026-12569 (PTC Windchill/FlexPLM) are actively exploited. The Cisco flaw is unauthenticated SSRF enabling arbitrary file writes; PTC involves unsafe deserialization leading to RCE....

captechgroup.com/threat-intell

##

beyondmachines1 at 2026-06-27T11:01:22.012Z ##

PTC Windchill and FlexPLM Under Active Exploitation via Critical RCE Flaw

PTC issued emergency patches for a critical RCE vulnerability in Windchill and FlexPLM that attackers are actively exploiting to deploy web shells and steal intellectual property. The flaw, tracked as CVE-2026-12569, allows unauthenticated remote code execution and has prompted emergency warnings from international security agencies.

**Consider this as urgent advisory. If possible, make sure all Windchill and FlexPLM servers are isolated from the internet and reachable only from trusted internal networks. Immediately apply PTC's latest patches for your affected version, block IP 5.180.41.35 at your perimeter, and check for compromise by scanning for suspicious 16-character hex-named .jsp files in the codebase/login directory and a flst.txt file in /tmp.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-06-27T11:01:22.000Z ##

PTC Windchill and FlexPLM Under Active Exploitation via Critical RCE Flaw

PTC issued emergency patches for a critical RCE vulnerability in Windchill and FlexPLM that attackers are actively exploiting to deploy web shells and steal intellectual property. The flaw, tracked as CVE-2026-12569, allows unauthenticated remote code execution and has prompted emergency warnings from international security agencies.

**Consider this as urgent advisory. If possible, make sure all Windchill and FlexPLM servers are isolated from the internet and reachable only from trusted internal networks. Immediately apply PTC's latest patches for your affected version, block IP 5.180.41.35 at your perimeter, and check for compromise by scanning for suspicious 16-character hex-named .jsp files in the codebase/login directory and a flst.txt file in /tmp.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-06-26T13:11:01.000Z ##

CISA adds CVE-2026-12569 to the KEV catalog as adversaries actively exploit PTC Windchill & FlexPLM platforms. This is an immediate threat to supply chain integrity and intellectual property. Access our complete executive risk mitigation framework for corporate leadership: thecybermind.co/lacm

##

thecybermind@infosec.exchange at 2026-06-26T12:01:50.000Z ##

CISA adds CVE-2026-12569 to the KEV catalog as adversaries actively exploit PTC Windchill & FlexPLM input validation vulnerabilities. Lock down your supply chain assets. Full forensic indicators, lateral movement tracking, and active endpoint hardening protocols are live: thecybermind.co/y7tn

##

secdb@infosec.exchange at 2026-06-25T21:02:25.000Z ##

🚨 [CISA-2026:0625] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-12569 (secdb.nttzen.cloud/cve/detail/)
- Name: PTC Windchill and FlexPLM Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PTC
- Product: Windchill and FlexPLM
- Notes: ptc.com/en/support/article/CS4 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-20230 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Unified Communications Manager
- Notes: cisco.com/c/en/us/support/docs ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260625 #cisa20260625 #cve_2026_12569 #cve_2026_20230 #cve202612569 #cve202620230

##

cisakevtracker@mastodon.social at 2026-06-25T20:00:51.000Z ##

CVE ID: CVE-2026-12569
Vendor: PTC
Product: Windchill and FlexPLM
Date Added: 2026-06-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-54158
(9.9 CRITICAL)

EPSS: 0.29%

updated 2026-06-26T00:16:53.823000

1 posts

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, url, phone, and mAsset. A cell value like </textarea><img src=x onerror="..."> or "><img src=x onerror="..."> breaks out of its surrounding tag and runs arbitrary JavaScript in the renderer when the vi

offseq@infosec.exchange at 2026-06-25T04:30:26.000Z ##

CVE-2026-54158: CRITICAL XSS in SiYuan (<3.7.0) allows persistent JS injection; on Electron clients, can escalate to RCE. Upgrade to 3.7.0+ ASAP. No active exploits reported. radar.offseq.com/threat/cve-20 #OffSeq #XSS #CVE202654158 #SiYuan

##

CVE-2026-23879
(8.0 HIGH)

EPSS: 0.40%

updated 2026-06-25T20:21:19.853000

1 posts

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious symbolic link chains. When using extractall to extract an archive, the library restores these symbolic

hugovalters@mastodon.social at 2026-06-24T23:14:50.000Z ##

CVE-2026-23879 - Critical RCE in Py7zr. Arbitrary file write via symbolic link chains allows escape from destination directory. CVSS 8.0. No patch available. Update or avoid extraction of untrusted 7z archives. #CVE #infosec #Python

valtersit.com/cve/CVE-2026-238

##

CVE-2026-53662
(9.6 CRITICAL)

EPSS: 0.24%

updated 2026-06-25T20:18:11.603000

1 posts

immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (XSS) vulnerability on the /auth/login page allows an attacker to fully compromise any authenticated user's account with a single link click. The continue query parameter is read from the URL and passed to SvelteKit's redirect() without any scheme or or

offseq@infosec.exchange at 2026-06-24T03:00:27.000Z ##

immich-app suffers CRITICAL reflected XSS (CVE-2026-53662) in /auth/login (commits 4ffa26c9 – 4eb1003). Exploitation = persistent account takeover via API key minting. Update to commit 4eb1003 or later. radar.offseq.com/threat/cve-20 #OffSeq #CVE202653662 #XSS #infosec

##

CVE-2026-10735
(7.5 HIGH)

EPSS: 0.39%

updated 2026-06-25T19:07:56.657000

1 posts

Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 were distributed with malicious code throug

2 repos

https://github.com/HORKimhab/CVE-Wordpress

https://github.com/xxconi/CVE-2026-49777-CVE-2026-10735

offseq@infosec.exchange at 2026-06-24T07:30:26.000Z ##

CVE-2026-10735 (CRITICAL): smart-post-show-pro 4.0.1 for WordPress shipped with malicious code via compromised update server. Unauth attackers can exfiltrate creds & control sites. Remove/disable affected plugin & monitor for IOCs. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #SupplyChain

##

CVE-2026-33612
(7.5 HIGH)

EPSS: 0.12%

updated 2026-06-25T16:00:30.783000

1 posts

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.

offseq@infosec.exchange at 2026-06-25T13:30:24.000Z ##

CVE-2026-33612 (HIGH, CVSS 7.5) impacts PowerDNS Recursor ≤5.4.3. Crafted zones from malicious servers can trigger cache poisoning via ZoneToCache. Review deployments, monitor for patches: radar.offseq.com/threat/cve-20 #OffSeq #PowerDNS #vuln #dns

##

CVE-2026-50256
(7.8 HIGH)

EPSS: 0.15%

updated 2026-06-25T15:31:44

1 posts

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to c

zl2tod@mastodon.online at 2026-06-27T10:37:24.000Z ##

...
* glx: fix reversed length check in ChangeDrawableAttributes (CVE-2026-50262) (Closes: #1138680)
* saver: re-fetch screen private after CheckScreenPrivate in CreateSaverWindow (CVE-2026-50263) (Closes: #1138680)
* dix: increase XLFDMAXFONTNAMELEN to match libXfont2's MAXFONTNAMELEN (CVE-2026-50256) (Closes: #1138680)
* dri2: Use booleans for (fake) front buffer tracking in do_get_buffers (CVE-2026-50264) (Closes: #1138680)
...

##

CVE-2026-55570
(9.0 CRITICAL)

EPSS: 0.33%

updated 2026-06-25T15:16:39.423000

1 posts

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are serialized into the data-obj HTML attribute of each marketplace card. Because the attribute is single-quoted and the value is produced with JSON.stringify() (which does not escape ', <, or >), a package whose name contains a singl

offseq@infosec.exchange at 2026-06-25T01:30:24.000Z ##

CVE-2026-55570: CRITICAL XSS in SiYuan (<3.7.0) enables arbitrary HTML injection. On the desktop client, attackers can escalate to OS command execution due to nodeIntegration. Upgrade to 3.7.0+ now! radar.offseq.com/threat/cve-20 #OffSeq #XSS #Vuln #SiYuan

##

CVE-2026-50551
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-06-25T14:16:45.323000

1 posts

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. This vulnerability is fixed in 3.7.0.

offseq@infosec.exchange at 2026-06-25T03:00:24.000Z ##

CVE-2026-50551: SiYuan (<3.7.0) suffers CRITICAL stored XSS in Attribute View, enabling RCE via Electron client. Upgrade to v3.7.0+ to mitigate. No workaround available. Details: radar.offseq.com/threat/cve-20 #OffSeq #XSS #SiYuan #Cybersecurity

##

CVE-2026-50264
(7.8 HIGH)

EPSS: 0.14%

updated 2026-06-25T14:16:45.140000

2 posts

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.

zl2tod@mastodon.online at 2026-06-27T10:37:40.000Z ##

...
* dri2: Deduplicate attachments in do_get_buffer (CVE-2026-50264) (Closes: #1138680)

##

zl2tod@mastodon.online at 2026-06-27T10:37:24.000Z ##

...
* glx: fix reversed length check in ChangeDrawableAttributes (CVE-2026-50262) (Closes: #1138680)
* saver: re-fetch screen private after CheckScreenPrivate in CreateSaverWindow (CVE-2026-50263) (Closes: #1138680)
* dix: increase XLFDMAXFONTNAMELEN to match libXfont2's MAXFONTNAMELEN (CVE-2026-50256) (Closes: #1138680)
* dri2: Use booleans for (fake) front buffer tracking in do_get_buffers (CVE-2026-50264) (Closes: #1138680)
...

##

CVE-2026-50263
(5.5 MEDIUM)

EPSS: 0.14%

updated 2026-06-25T14:16:44.947000

1 posts

A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.

zl2tod@mastodon.online at 2026-06-27T10:37:24.000Z ##

...
* glx: fix reversed length check in ChangeDrawableAttributes (CVE-2026-50262) (Closes: #1138680)
* saver: re-fetch screen private after CheckScreenPrivate in CreateSaverWindow (CVE-2026-50263) (Closes: #1138680)
* dix: increase XLFDMAXFONTNAMELEN to match libXfont2's MAXFONTNAMELEN (CVE-2026-50256) (Closes: #1138680)
* dri2: Use booleans for (fake) front buffer tracking in do_get_buffers (CVE-2026-50264) (Closes: #1138680)
...

##

CVE-2026-50262
(5.5 MEDIUM)

EPSS: 0.13%

updated 2026-06-25T14:16:44.750000

1 posts

An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.

zl2tod@mastodon.online at 2026-06-27T10:37:24.000Z ##

...
* glx: fix reversed length check in ChangeDrawableAttributes (CVE-2026-50262) (Closes: #1138680)
* saver: re-fetch screen private after CheckScreenPrivate in CreateSaverWindow (CVE-2026-50263) (Closes: #1138680)
* dix: increase XLFDMAXFONTNAMELEN to match libXfont2's MAXFONTNAMELEN (CVE-2026-50256) (Closes: #1138680)
* dri2: Use booleans for (fake) front buffer tracking in do_get_buffers (CVE-2026-50264) (Closes: #1138680)
...

##

CVE-2026-50261
(7.8 HIGH)

EPSS: 0.14%

updated 2026-06-25T14:16:44.510000

1 posts

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.

zl2tod@mastodon.online at 2026-06-27T10:36:37.000Z ##

Ten CVEs fixed in patched xorg-xserver now available for Debian stable (trixie):

* sync: fix deletion of counters and fences (CVE-2026-50257, CVE-2026-50260) (Closes: #1138680)
* sync: restart trigger list iteration in SyncChangeCounter after TriggerFired (CVE-2026-50261) (Closes: #1138680)
* xkb: reject key types with num_levels exceeding XkbMaxShiftLevel (CVE-2026-50258) (Closes: #1138680)
* xkb: clamp nMaps to mapWidths buffer size in CheckKeyTypes (CVE-2026-50259) (Closes: #1138680)
...

##

CVE-2026-50260
(7.8 HIGH)

EPSS: 0.15%

updated 2026-06-25T14:16:43.427000

1 posts

A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.

zl2tod@mastodon.online at 2026-06-27T10:36:37.000Z ##

Ten CVEs fixed in patched xorg-xserver now available for Debian stable (trixie):

* sync: fix deletion of counters and fences (CVE-2026-50257, CVE-2026-50260) (Closes: #1138680)
* sync: restart trigger list iteration in SyncChangeCounter after TriggerFired (CVE-2026-50261) (Closes: #1138680)
* xkb: reject key types with num_levels exceeding XkbMaxShiftLevel (CVE-2026-50258) (Closes: #1138680)
* xkb: clamp nMaps to mapWidths buffer size in CheckKeyTypes (CVE-2026-50259) (Closes: #1138680)
...

##

CVE-2026-50259
(7.8 HIGH)

EPSS: 0.16%

updated 2026-06-25T14:16:43.267000

1 posts

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.

zl2tod@mastodon.online at 2026-06-27T10:36:37.000Z ##

Ten CVEs fixed in patched xorg-xserver now available for Debian stable (trixie):

* sync: fix deletion of counters and fences (CVE-2026-50257, CVE-2026-50260) (Closes: #1138680)
* sync: restart trigger list iteration in SyncChangeCounter after TriggerFired (CVE-2026-50261) (Closes: #1138680)
* xkb: reject key types with num_levels exceeding XkbMaxShiftLevel (CVE-2026-50258) (Closes: #1138680)
* xkb: clamp nMaps to mapWidths buffer size in CheckKeyTypes (CVE-2026-50259) (Closes: #1138680)
...

##

CVE-2026-50258
(7.8 HIGH)

EPSS: 0.15%

updated 2026-06-25T14:16:43.110000

1 posts

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may

zl2tod@mastodon.online at 2026-06-27T10:36:37.000Z ##

Ten CVEs fixed in patched xorg-xserver now available for Debian stable (trixie):

* sync: fix deletion of counters and fences (CVE-2026-50257, CVE-2026-50260) (Closes: #1138680)
* sync: restart trigger list iteration in SyncChangeCounter after TriggerFired (CVE-2026-50261) (Closes: #1138680)
* xkb: reject key types with num_levels exceeding XkbMaxShiftLevel (CVE-2026-50258) (Closes: #1138680)
* xkb: clamp nMaps to mapWidths buffer size in CheckKeyTypes (CVE-2026-50259) (Closes: #1138680)
...

##

CVE-2026-50257
(7.8 HIGH)

EPSS: 0.14%

updated 2026-06-25T14:16:42.940000

1 posts

A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privileg

zl2tod@mastodon.online at 2026-06-27T10:36:37.000Z ##

Ten CVEs fixed in patched xorg-xserver now available for Debian stable (trixie):

* sync: fix deletion of counters and fences (CVE-2026-50257, CVE-2026-50260) (Closes: #1138680)
* sync: restart trigger list iteration in SyncChangeCounter after TriggerFired (CVE-2026-50261) (Closes: #1138680)
* xkb: reject key types with num_levels exceeding XkbMaxShiftLevel (CVE-2026-50258) (Closes: #1138680)
* xkb: clamp nMaps to mapWidths buffer size in CheckKeyTypes (CVE-2026-50259) (Closes: #1138680)
...

##

CVE-2026-12416
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-06-25T14:16:36.007000

1 posts

The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no authorization check, and performing a loose equality comparison between the supplied `reset_activation_code` POST parame

2 repos

https://github.com/xxconi/CVE-2026-12415-or-CVE-2026-12416.py

https://github.com/Nxploited/CVE-2026-12416-CVE-2026-12417

offseq@infosec.exchange at 2026-06-24T09:00:32.000Z ##

CRITICAL (CVSS 9.8): CVE-2026-12416 impacts pravel Invoice Generator ≤1.0.0. Weak password reset lets unauthenticated attackers reset any user’s password, including admins. Restrict access or disable plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #infosec

##

CVE-2026-12850
(9.1 CRITICAL)

EPSS: 1.72%

updated 2026-06-25T14:02:35.347000

1 posts

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi

offseq@infosec.exchange at 2026-06-24T12:00:28.000Z ##

CVE-2026-12850: CRITICAL OS command injection in GeoVision GV-I/O Box 4E v2.09 via libNetSetObj.so allows remote code execution. No patch — restrict access to DVRSearch & Network.cgi. Details: radar.offseq.com/threat/cve-20 #OffSeq #ICS #infosec #vulnerability

##

CVE-2026-12851
(9.1 CRITICAL)

EPSS: 1.68%

updated 2026-06-25T14:02:35.347000

1 posts

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi

offseq@infosec.exchange at 2026-06-24T06:00:25.000Z ##

CVE-2026-12851: CRITICAL OS command injection in GeoVision GV-I/O Box 4E v2.09 via DVRSearch/Network.cgi allows remote code execution. Patch status pending — restrict access & monitor endpoints. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE #Security

##

CVE-2026-9702
(7.5 HIGH)

EPSS: 0.21%

updated 2026-06-25T13:28:35.737000

1 posts

The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site.

offseq@infosec.exchange at 2026-06-25T07:30:26.000Z ##

HIGH severity: CVE-2026-9702 in InPost PL WordPress plugin (<1.9.1) lets unauthenticated attackers redirect WooCommerce order shipping. No patch yet — restrict access, monitor for changes. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #Ecommerce

##

CVE-2026-46752
(0 None)

EPSS: 0.40%

updated 2026-06-25T13:27:40.747000

1 posts

Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.

offseq@infosec.exchange at 2026-06-25T12:00:29.000Z ##

CVE-2026-46752: CRITICAL heap-based buffer overflow in Apache Kvrocks (2.0.4 – 2.15.0) via Redis Lua cjson. RCE & DoS possible. Upgrade to 2.16.0 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Kvrocks #CVE202646752 #infosec

##

CVE-2026-41566
(0 None)

EPSS: 0.29%

updated 2026-06-25T13:27:40.747000

1 posts

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.

offseq@infosec.exchange at 2026-06-25T10:30:25.000Z ##

CVE-2026-41566 (CRITICAL, CVSS 9.4) in Apache Kvrocks 2.8.0 allows privilege escalation via improper permission handling. Upgrade to 2.16.0 is required — no other mitigation. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202641566 #Kvrocks #Security

##

CVE-2026-12417
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-06-25T13:26:11.740000

1 posts

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore accessible to unauthenticated users — performing no nonce verification, no capability

1 repos

https://github.com/Nxploited/CVE-2026-12416-CVE-2026-12417

offseq@infosec.exchange at 2026-06-24T10:30:27.000Z ##

pravel SignUp & SignIn (<=1.0.0) has a CRITICAL flaw (CVE-2026-12417): unauthenticated attackers can reset any WordPress user password, including admins. Remove or disable plugin until patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #CVE202612417

##

CVE-2026-56022
(5.3 MEDIUM)

EPSS: 0.31%

updated 2026-06-24T21:16:58.237000

1 posts

Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641.

beyondmachines1@infosec.exchange at 2026-06-25T12:01:31.000Z ##

Webmin 2.641 Patches Root Takeover and 2FA Bypass Vulnerabilities

Webmin version 2.641 addresses multiple critical vulnerabilities, including a root-level stored XSS (CVE-2026-22678), a path traversal file overwrite (CVE-2026-49103), and a 2FA bypass (CVE-2026-56022). These flaws allow low-privileged users to compromise root accounts and bypass multi-factor authentication in multi-tenant hosting environments.

**Update your Webmin instances to version 2.641 immediately to prevent low-privileged users from taking over your root account. If you cannot patch today, restrict access to the mail and notification modules to only your most trusted administrators.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-34908
(10.0 CRITICAL)

EPSS: 2.45%

updated 2026-06-24T14:50:41.720000

6 posts

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

1 repos

https://github.com/BishopFox/CVE-2026-34908-check

rswebsols@mastodon.social at 2026-06-27T00:41:46.000Z ##

CISA Issues Alert on Actively Exploited Vulnerability in Ubiquiti UniFi OS #internet #cybersecurity

CISA warns of actively exploited vulnerabilities in Ubiquiti UniFi OS. The alert highlights CVE-2026-34908 (critical access control flaw) and related CVEs 34909 and 34910, with remediation guidance and BOD 26-04 deadlines. Read the full analysis and required mitigations here: ift.tt/6eMqVP4

Source: ift.tt/6eMqVP4 | Image: ift.tt/0lLnI6S

##

offseq@infosec.exchange at 2026-06-24T13:30:30.000Z ##

CRITICAL UniFi OS vulnerabilities (CVE-2026-34908/09/10) allow remote, unauthenticated attackers to bypass auth and execute commands (pre-5.0.8). Exploited in the wild. Patch ASAP: radar.offseq.com/threat/critic #OffSeq #infosec #Ubiquiti #vulnerability

##

beyondmachines1@infosec.exchange at 2026-06-24T13:01:42.000Z ##

CISA Repoers Active Exploitation of Three Critical Ubiquiti UniFi OS Vulnerabilities

CISA added three critical Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) to its Known Exploited Vulnerabilities Catalog due to active exploitation. These flaws allow unauthenticated attackers to gain full control over network gateways and consoles through command injection and improper access controls.

**Now this advisory is urgent, since the flaws are actively exploited. Make sure all your UniFi devices (UDM, UNVR, UCG gateways, Cloud Keys, etc.) are isolated from the internet and accessible only from trusted networks. Immediately update UniFi OS to the latest patched version for your model (5.1.12+ for most hardware, 5.0.8 for UniFi OS Server, 4.0.14 for Express).**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-06-23T19:03:54.000Z ##

CISA has updated the KEV catalogue:

- CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2025-67038:
Lantronix EDS5000 Code Injection Vulnerability cve.org/CVERecord?id=CVE-2025- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-06-23T19:00:51.000Z ##

🚨 [CISA-2026:0623] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-67038 (secdb.nttzen.cloud/cve/detail/)
- Name: Lantronix EDS5000 Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Lantronix
- Product: EDS5000
- Notes: ltrxdev.atlassian.net/wiki/spa ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34908 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34909 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34910 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260623 #cisa20260623 #cve_2025_67038 #cve_2026_34908 #cve_2026_34909 #cve_2026_34910 #cve202567038 #cve202634908 #cve202634909 #cve202634910

##

cisakevtracker@mastodon.social at 2026-06-23T18:01:34.000Z ##

CVE ID: CVE-2026-34908
Vendor: Ubiquiti
Product: UniFi OS
Date Added: 2026-06-23
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-34909
(10.0 CRITICAL)

EPSS: 2.27%

updated 2026-06-24T14:49:53.287000

4 posts

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

beyondmachines1@infosec.exchange at 2026-06-24T13:01:42.000Z ##

CISA Repoers Active Exploitation of Three Critical Ubiquiti UniFi OS Vulnerabilities

CISA added three critical Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) to its Known Exploited Vulnerabilities Catalog due to active exploitation. These flaws allow unauthenticated attackers to gain full control over network gateways and consoles through command injection and improper access controls.

**Now this advisory is urgent, since the flaws are actively exploited. Make sure all your UniFi devices (UDM, UNVR, UCG gateways, Cloud Keys, etc.) are isolated from the internet and accessible only from trusted networks. Immediately update UniFi OS to the latest patched version for your model (5.1.12+ for most hardware, 5.0.8 for UniFi OS Server, 4.0.14 for Express).**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-06-23T19:03:54.000Z ##

CISA has updated the KEV catalogue:

- CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2025-67038:
Lantronix EDS5000 Code Injection Vulnerability cve.org/CVERecord?id=CVE-2025- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-06-23T19:00:51.000Z ##

🚨 [CISA-2026:0623] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-67038 (secdb.nttzen.cloud/cve/detail/)
- Name: Lantronix EDS5000 Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Lantronix
- Product: EDS5000
- Notes: ltrxdev.atlassian.net/wiki/spa ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34908 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34909 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34910 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260623 #cisa20260623 #cve_2025_67038 #cve_2026_34908 #cve_2026_34909 #cve_2026_34910 #cve202567038 #cve202634908 #cve202634909 #cve202634910

##

cisakevtracker@mastodon.social at 2026-06-23T18:01:17.000Z ##

CVE ID: CVE-2026-34909
Vendor: Ubiquiti
Product: UniFi OS
Date Added: 2026-06-23
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-34910
(10.0 CRITICAL)

EPSS: 78.55%

updated 2026-06-24T14:49:47.237000

4 posts

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Nuclei template

beyondmachines1@infosec.exchange at 2026-06-24T13:01:42.000Z ##

CISA Repoers Active Exploitation of Three Critical Ubiquiti UniFi OS Vulnerabilities

CISA added three critical Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) to its Known Exploited Vulnerabilities Catalog due to active exploitation. These flaws allow unauthenticated attackers to gain full control over network gateways and consoles through command injection and improper access controls.

**Now this advisory is urgent, since the flaws are actively exploited. Make sure all your UniFi devices (UDM, UNVR, UCG gateways, Cloud Keys, etc.) are isolated from the internet and accessible only from trusted networks. Immediately update UniFi OS to the latest patched version for your model (5.1.12+ for most hardware, 5.0.8 for UniFi OS Server, 4.0.14 for Express).**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-06-23T19:03:54.000Z ##

CISA has updated the KEV catalogue:

- CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2025-67038:
Lantronix EDS5000 Code Injection Vulnerability cve.org/CVERecord?id=CVE-2025- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-06-23T19:00:51.000Z ##

🚨 [CISA-2026:0623] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-67038 (secdb.nttzen.cloud/cve/detail/)
- Name: Lantronix EDS5000 Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Lantronix
- Product: EDS5000
- Notes: ltrxdev.atlassian.net/wiki/spa ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34908 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34909 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34910 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260623 #cisa20260623 #cve_2025_67038 #cve_2026_34908 #cve_2026_34909 #cve_2026_34910 #cve202567038 #cve202634908 #cve202634909 #cve202634910

##

cisakevtracker@mastodon.social at 2026-06-23T18:01:01.000Z ##

CVE ID: CVE-2026-34910
Vendor: Ubiquiti
Product: UniFi OS
Date Added: 2026-06-23
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-67038
(9.8 CRITICAL)

EPSS: 1.13%

updated 2026-06-24T05:17:25.670000

6 posts

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

1 repos

https://github.com/HORKimhab/CVE-2025-67038

darses@mastodon.nl at 2026-06-26T17:49:52.000Z ##

If you have any LuCI-based #Lantronix Serial-to-Ethernet device exposed on the internet, then you may want to kickoff your incident response plan.

My suspicion is that the unauthenticated Remote Code Execution vulnerability CVE-2025-67038 affects a lot more device types than just the EDS5000 that is mentioned in the advisory.

The vulnerable code path is in a modified OpenWRT LuCI RPC module that puts a user-controlled variable inside a Lua `os.execute` call. This vulnerable code is contained in a lot of device firmware versions released in or after 2023. Unfortunately, I do not have the devices to actually test exploitability. My analysis is based purely on patch diffing and grepping publicly released firmware versions. The incomplete list of device types that contain the vulnerable code: EDS5000, G520, G526, G526RP, G527, G528, X300, X300-WiFi, X303, X304. I also suspect E210 is on the incomplete list of vulnerable devices.

Back in April this vulnerability was published by Forescout as part of their BRIDGE:BREAK report on Serial-to-Ethernet adapters. Two days ago this vulnerability was added to the CISA KEV Catalog. Yesterday Forescout published a blogpost they first observed exploitation attempts on the 5th of April 2026. Attacks are attributed to a new cluster Chaya_006. It is unclear if Lantronix took the effort to check if any of their other devices are vulnerable given that they contain the same RPC module.

You want to look for POST requests to `/cgi-bin/luci/rpc/auth` in your logs. Forescout has a number 3 octet IP addresses as Indicator of Compromise here: forescout.com/blog/analyzing-a . The running theory is that these are supposed to be /24 CIDR ranges.

@Secure_ICS_OT
@cisacyber

#vulnerability #cybersecurity #ics #CVE202567038

##

beyondmachines1@infosec.exchange at 2026-06-24T20:01:42.000Z ##

CISA Reports Active Exploitation of Lantronix Flaws

CISA flagged an actively exploited critical flaw (CVE-2025-67038) in Lantronix EDS5000 v2.1.0.0R3 devices: an unauthenticated OS command injection in the HTTP RPC module that lets attackers gain root access and fully compromise the equipment.

**Make sure all Lantronix EDS5000 devices are isolated from the internet and accessible only from trusted networks, since this flaw lets attackers gain full root control without any login. Check your inventory for version 2.1.0.0R3, apply the latest firmware update from Lantronix, and because attackers can survive patches by creating rogue admin accounts, audit for unknown accounts and rotate any stored secrets after patching.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-06-24T18:30:10.000Z ##

For the Boardroom: A critical unauthenticated code injection flaw (CVE-2025-67038) in Lantronix EDS5000 servers is under active exploitation. Read the full C-SUITE threat advisory on mitigating this operational risk. Ping the word 'ok' mike@thecybermind.co to upgrade your intel. thecybermind.co/jpul
#CyberSec #RiskManagement

##

AAKL@infosec.exchange at 2026-06-23T19:03:54.000Z ##

CISA has updated the KEV catalogue:

- CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2025-67038:
Lantronix EDS5000 Code Injection Vulnerability cve.org/CVERecord?id=CVE-2025- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-06-23T19:00:51.000Z ##

🚨 [CISA-2026:0623] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-67038 (secdb.nttzen.cloud/cve/detail/)
- Name: Lantronix EDS5000 Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Lantronix
- Product: EDS5000
- Notes: ltrxdev.atlassian.net/wiki/spa ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34908 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34909 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34910 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260623 #cisa20260623 #cve_2025_67038 #cve_2026_34908 #cve_2026_34909 #cve_2026_34910 #cve202567038 #cve202634908 #cve202634909 #cve202634910

##

cisakevtracker@mastodon.social at 2026-06-23T18:00:45.000Z ##

CVE ID: CVE-2025-67038
Vendor: Lantronix
Product: EDS5000
Date Added: 2026-06-23
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-52465
(7.2 HIGH)

EPSS: 0.35%

updated 2026-06-24T05:17:25.543000

1 posts

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists that allows an authenticated administrator with access to GeoServer's security system to pass arbitrary file names to the Master Password Dump web page and create files containing the master password in plaintext. The provided file name must be an abso

CVE-2026-53753
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-06-23T20:16:48.907000

1 posts

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (gi_frame, f_back, f_builtins) do NOT start with underscore, enabling a complete sandbox escape to achieve arbitrary code execution.

offseq@infosec.exchange at 2026-06-24T01:30:27.000Z ##

CVE-2026-53753: CRITICAL code injection in unclecode crawl4ai (<0.8.7). Unauthenticated RCE via /crawl POST request due to insufficient AST validation. Patch to 0.8.7 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202653753 #infosec #vuln

##

CVE-2026-12957
(7.8 HIGH)

EPSS: 0.12%

updated 2026-06-23T19:36:18.347000

2 posts

Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted. To remediate this issue, users should

halildeniz@mastodon.social at 2026-06-27T15:53:24.000Z ##

🚨 AWS Language Server Flaw!

CVE-2026-12957 allows zero-click command injection and cloud credential theft simply by opening a poisoned repository inside your IDE (affecting Amazon Q Developer).

denizhalil.com/2026/06/27/cve-

#CVE202612957 #aws #Cybersecurity #infosec #CloudSecurity

##

awssecurityfeed@infosec.exchange at 2026-06-23T16:30:01.000Z ##

CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins

Bulletin ID: 2026-047-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/23/2026 09:30 AM PDT
Description:
Language Servers for AWS provide the underlying language-server runtime that powers Amazon ...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-12958
(7.8 HIGH)

EPSS: 0.14%

updated 2026-06-23T19:36:18.347000

1 posts

Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary. To remediate this issue, users should upgrade to version 1.69.0 or higher.

awssecurityfeed@infosec.exchange at 2026-06-23T16:30:01.000Z ##

CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins

Bulletin ID: 2026-047-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/23/2026 09:30 AM PDT
Description:
Language Servers for AWS provide the underlying language-server runtime that powers Amazon ...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-11940(CVSS UNKNOWN)

EPSS: 0.60%

updated 2026-06-23T18:31:51

2 posts

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory.  T

DailyCyberSecurity at 2026-06-28T02:30:31.626Z ##

A new CPython tarfile vulnerability (CVE-2026-11940) allows directory escape attacks. Learn how this extraction filter bypass exposes systems.

securityonline.info/cpython-ta

##

DailyCyberSecurity@infosec.exchange at 2026-06-28T02:30:31.000Z ##

A new CPython tarfile vulnerability (CVE-2026-11940) allows directory escape attacks. Learn how this extraction filter bypass exposes systems.

securityonline.info/cpython-ta

##

CVE-2026-28496
(0 None)

EPSS: 1.89%

updated 2026-06-23T16:16:59.350000

1 posts

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnerability in the template rendering system. Administrators with access to features that render Twig templates (email templates, mass mail campaigns, custom payment adapters, and the `string_render` API endpoint) can inject arbitrary Twig expressions, lea

Nuclei template

AAKL@infosec.exchange at 2026-06-23T18:20:05.000Z ##

New.

"Today VulnCheck is disclosing CVE-2026-28496, an unauthenticated remote code execution chain in FOSSBilling, the open-source billing and client-management platform."

VulnCheck: CVE-2026-28496 - FOSSBilling Auth Bypass and Twig SSTI to Unauthenticated RCE vulncheck.com/blog/fossbilling @vulncheck #infosec #opensource #vulnerability

##

CVE-2026-49494
(7.5 HIGH)

EPSS: 0.54%

updated 2026-06-23T15:16:35.747000

1 posts

Xcitium Client Security (XCS) before 13.8.2.10019 and Comodo Internet Security (CIS) through 12.3.4.8162 (fix expected by 2026 Q3) contain an integer underflow vulnerability in the firewall driver Inspect.sys that allows remote unauthenticated attackers to crash the system by sending a crafted IPv6 packet with a declared payload length smaller than the sum of its extension-header lengths. The unsi

malwaretech@infosec.exchange at 2026-06-25T20:07:45.000Z ##

I think it’s hilarious that I now have my first CVE because I got annoyed with an unresponsive vendor and just posted the zero day exploit I was trying to report to them on my GitHub 😆

nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-8461
(8.8 HIGH)

EPSS: 0.39%

updated 2026-06-22T20:31:03.510000

19 posts

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.

5 repos

https://github.com/Y5neKO/CVE-2026-8461-EXP

https://github.com/HORKimhab/CVE-2026-8461

https://github.com/anyanything/CVE-2026-8461-PoC

https://github.com/0xBlackash/CVE-2026-8461

https://github.com/ray-goldman/ffmpeg-jellyfix

nemo@mas.to at 2026-06-27T07:59:14.000Z ##

Pixelsmash: Eine 50‑KB‑Videodatei reicht, um per FFmpeg-Decoder (MagicYUV/libavcodec) zahlreiche Anwendungen zum Absturz zu bringen – teils sogar mit Codeausführung. Schwere Lücke: CVE-2026-8461 (CVSS 8,8). Patch: FFmpeg 8.1.2. golem.de/news/pixelsmash-lueck 🎥🛡️💥 #FFmpeg #Cybersecurity #CVE #Patch #Exploit

##

nemo@mas.to at 2026-06-27T07:40:12.000Z ##

🚨 FFmpeg’s MagicYUV decoder bug “PixelSmash” (CVE-2026-8461) can be triggered by a crafted AVI/MKV/MOV to achieve remote code execution on media open—per JFrog researchers. Affected apps include Jellyfin & Nextcloud. Fix: FFmpeg 8.1.2. cyberinsider.com/ffmpeg-pixels #FFmpeg #CyberSecurity #RCE #CVE #Infosec

##

nemo@mas.to at 2026-06-27T07:59:14.000Z ##

Pixelsmash: Eine 50‑KB‑Videodatei reicht, um per FFmpeg-Decoder (MagicYUV/libavcodec) zahlreiche Anwendungen zum Absturz zu bringen – teils sogar mit Codeausführung. Schwere Lücke: CVE-2026-8461 (CVSS 8,8). Patch: FFmpeg 8.1.2. golem.de/news/pixelsmash-lueck 🎥🛡️💥 #FFmpeg #Cybersecurity #CVE #Patch #Exploit

##

nemo@mas.to at 2026-06-27T07:40:12.000Z ##

🚨 FFmpeg’s MagicYUV decoder bug “PixelSmash” (CVE-2026-8461) can be triggered by a crafted AVI/MKV/MOV to achieve remote code execution on media open—per JFrog researchers. Affected apps include Jellyfin & Nextcloud. Fix: FFmpeg 8.1.2. cyberinsider.com/ffmpeg-pixels #FFmpeg #CyberSecurity #RCE #CVE #Infosec

##

ottoto2017@prattohome.com at 2026-06-26T00:26:53.000Z ##

#Mastodon v4.6.2 へ #update した。

CVE-2026-8461へのセキュリティ対応。

git fetch && git checkout v4.6.2
だけで完了。

#prattohome #更新

##

xeiaso.net@bsky.brid.gy at 2026-06-25T22:11:38.191Z ##

"No way to prevent this" say users of only language where this regularly happens

https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-8461/

"No way to prevent this" say u...

##

cadey@pony.social at 2026-06-25T22:11:38.000Z ##

"No way to prevent this" say users of only language where this regularly happens

xeiaso.net/shitposts/no-way-to

##

null@puddle.town at 2026-06-25T18:29:09.000Z ##

I built FFmpeg 7.1.5 from source since Ubuntu is moving slowly on CVE-2026-8461, and leaving a Mastodon server that processes untrusted media all day long unpatched seems like a bad idea. So anyway, testing with a #Goose post.

##

apz@some.apz.fi at 2026-06-25T17:45:39.000Z ##

Looks like #ffmpeg leaks (CVE-2026-8461), #mastodon Docker images have all been updated with a fixed version.

#infosec #vulnerability

##

jenbanim@mastodo.neoliber.al at 2026-06-25T16:32:33.000Z ##

#Sysadmin #Infosec #MastoAdmin am I reading correctly that Ubuntu is still triaging the lastest FFMPEG vulnerability and hasn't released a fix?

Running 24.04 LTS and I don't wanna get pwned

ubuntu.com/security/CVE-2026-8

#ffmpeg

##

adamhotep@infosec.exchange at 2026-06-25T14:25:54.000Z ##

RE: social.coop/@cwebber/116810673

Every once in a while, we observe flaws in media players that allow exploits to be delivered by video files. These files often get free passes in security gateways.

Fortunately, it doesn't work by default. BleepingComputer wrote:

the RCE exploit requires ASLR (Address Space Layout Randomization) to be disabled, and that CVE-2026-8461 alone does not bypass this memory protection.

In theory, a separate information-disclosure bug in FFmpeg's FlashSV decoder could be chained with PixelSmash to bypass ASLR.

##

vv@solarpunk.moe at 2026-06-25T13:07:51.000Z ##

@cwebber Ubuntu doesn't either: ubuntu.com/security/CVE-2026-8

Does the ubuntu security team need to be briefed on how concerning this issue is?

##

glitch_soc_release_watcher@kodesumber.com at 2026-06-25T11:52:26.000Z ##

v4.6.2

This release is made solely to update FFmpeg in our docker container images to fix CVE-2026-8461 (critical severity). It is critical to update if you use our docker container images. If you are not using our docker container images, please make...

github.com/glitch-soc/mastodon

#glitchsoc #glitch #mastodon #mastoadmin

##

glitch_soc_release_watcher@kodesumber.com at 2026-06-25T11:52:26.000Z ##

v4.5.13

This release is made solely to update FFmpeg in our docker container images to fix CVE-2026-8461 (critical severity). It is critical to update if you use our docker container images. If you are not using our docker container images, please make...

github.com/glitch-soc/mastodon

#glitchsoc #glitch #mastodon #mastoadmin

##

mstdn_release_watcher@kodesumber.com at 2026-06-25T11:35:06.000Z ##

v4.5.13

This release is made solely to update FFmpeg in our docker container images to fix CVE-2026-8461 (critical severity). It is critical to update if you use our docker container images. If you are not using our docker container images, please make...

github.com/mastodon/mastodon/r

#mastodon #mastoadmin

##

mstdn_release_watcher@kodesumber.com at 2026-06-25T11:35:05.000Z ##

v4.6.2

This release is made solely to update FFmpeg in our docker container images to fix CVE-2026-8461 (critical severity). It is critical to update if you use our docker container images. If you are not using our docker container images, please make...

github.com/mastodon/mastodon/r

#mastodon #mastoadmin

##

admin@m.somincola.org at 2026-06-25T10:16:20.000Z ##

🌿 站点更新完成:Mastodon 4.6.2

服务器花园完成了一轮快速修整!Somincola Social 已从 Mastodon 4.6.0 更新至 4.6.2,目前运行正常。🐘

本次更新包括:
• 修复 Emoji、下拉菜单、高级界面、个人资料字段及 LDAP 登录等问题
• 更新 Docker 镜像中的 FFmpeg,修复严重安全漏洞 CVE-2026-8461
• 本站的 5000 字符上限继续保留
大家无需进行额外操作。Tangerine UI 目前宣布停更,暂时移出了服务器花园。希望它在花园外能继续茁壮成长

感谢大家的等待!辛勤的园艺师傅已经扫完落叶,联邦小路继续开放啦。🌿

#SomincolaSocial #Mastodon #站点更新

##

love@jiaojiao.org at 2026-06-25T09:57:28.000Z ##

@mastodon_releases
Mastodon v4.6.2 has been released, fixing critical FFmpeg vulnerability CVE-2026-8461.

Attackers can upload malicious videos to crash the service or execute arbitrary code. High risk.

Please update Mastodon/FFmpeg ASAP. Ensure your FFmpeg version is:
• 8.1.2
• 7.1.5
• 6.1.6
• 5.1.10

nvd.nist.gov/vuln/detail/CVE-2

##

admin@fnordon.de at 2026-06-25T09:43:50.000Z ##

Mastodon 4.6.2
(manchmal kommen sie schnell hintereinander, diesmal wegen CVE-2026-8461)

#Mastoadmin

##

CVE-2026-41950
(6.5 MEDIUM)

EPSS: 0.33%

updated 2026-06-22T18:16:37.293000

1 posts

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files array of a chat-messages request. Attackers can exploit insufficient permission verification in the chat-messages endpoints to access files without ownership valid

threatnoir@infosec.exchange at 2026-06-24T21:05:19.000Z ##

⚠️ CRITICAL: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Four critical vulnerabilities in Dify AI platform (CVE-2026-41947, CVE-2026-41948, CVE-2026-41950) enable unauthorized access to private chats, cross-tenant document theft, and lateral API calls across multi-tenant environments. The platform powers 1 million applications, making this a widespread s…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-41948
(9.4 CRITICAL)

EPSS: 0.51%

updated 2026-06-22T18:16:37.033000

1 posts

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints su

threatnoir@infosec.exchange at 2026-06-24T21:05:19.000Z ##

⚠️ CRITICAL: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Four critical vulnerabilities in Dify AI platform (CVE-2026-41947, CVE-2026-41948, CVE-2026-41950) enable unauthorized access to private chats, cross-tenant document theft, and lateral API calls across multi-tenant environments. The platform powers 1 million applications, making this a widespread s…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-41947
(9.1 CRITICAL)

EPSS: 0.45%

updated 2026-06-22T18:16:36.883000

1 posts

Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. Attackers can exploit missing tenant ownership checks in the trace configuration endpoints to redirect all messages and responses from victim applications to attacker-controlled LLM trace provider

threatnoir@infosec.exchange at 2026-06-24T21:05:19.000Z ##

⚠️ CRITICAL: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Four critical vulnerabilities in Dify AI platform (CVE-2026-41947, CVE-2026-41948, CVE-2026-41950) enable unauthorized access to private chats, cross-tenant document theft, and lateral API calls across multi-tenant environments. The platform powers 1 million applications, making this a widespread s…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-6637
(8.8 HIGH)

EPSS: 0.38%

updated 2026-06-17T11:01:08.343000

1 posts

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update v

mastokukei@social.josko.org at 2026-06-27T09:02:01.000Z ##

AdvancedCLI, and multiple sensor/toolkit updates.
- **PostgreSQL updates**: Security patches (CVE-2026-6637), pg_qualstats 2.1.4, pg_stat_kcache 2.3.2, and PGDay.UK 2026 schedule.
- **Rust & Zig**: Dr.Jit 1.4, Mitsuba 3.9, and Mach Nominated Zig versions for gamedev.
- **Security vulnerabilities**: Squidbleed (CVE-2026-47729), NetBSD/pkgsrc CVEs, and TXE firmware flaws. [2/2]

##

CVE-2026-49103
(0 None)

EPSS: 0.30%

updated 2026-06-17T10:55:30.553000

1 posts

Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.

beyondmachines1@infosec.exchange at 2026-06-25T12:01:31.000Z ##

Webmin 2.641 Patches Root Takeover and 2FA Bypass Vulnerabilities

Webmin version 2.641 addresses multiple critical vulnerabilities, including a root-level stored XSS (CVE-2026-22678), a path traversal file overwrite (CVE-2026-49103), and a 2FA bypass (CVE-2026-56022). These flaws allow low-privileged users to compromise root accounts and bypass multi-factor authentication in multi-tenant hosting environments.

**Update your Webmin instances to version 2.641 immediately to prevent low-privileged users from taking over your root account. If you cannot patch today, restrict access to the mail and notification modules to only your most trusted administrators.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-46243
(7.1 HIGH)

EPSS: 0.31%

updated 2026-06-17T10:53:23.893000

1 posts

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that cifs.upcall treats as kernel-originating inputs. However, userspace can also create keys of this type through request_key(2) or add_key(2), allowing those fields t

4 repos

https://github.com/cumakurt/linuxpi

https://github.com/Koshmare-Blossom/CIFSwitch-go

https://github.com/MrForkBomb/CIFSwitch-Checker-CVE-2026-46243

https://github.com/liamromanis101/cifswitch-check

netsecio@mastodon.social at 2026-06-27T16:41:30.000Z ##

📰 19-Year-Old 'CIFSwitch' Linux Flaw (CVE-2026-46243) Gives Instant Root

🚨 CRITICAL FLAW: 'CIFSwitch' (CVE-2026-46243), a 19-year-old Linux kernel bug, allows instant root access on Ubuntu & RHEL with a single command. Patch immediately! This is the 5th Linux LPE this year. #Linux #infosec #CyberSecurity #CVE

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ci

##

CVE-2026-45504
(8.8 HIGH)

EPSS: 0.46%

updated 2026-06-17T10:52:10.200000

1 posts

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/hawktrace/CVE-2026-45504

obivan@infosec.exchange at 2026-06-24T18:49:48.000Z ##

CVE-2026-45504 Microsoft Exchange SSRF via File Read hawktrace.com/blog/CVE-2026-45

##

CVE-2026-42508
(9.1 CRITICAL)

EPSS: 0.37%

updated 2026-06-17T10:47:57.267000

1 posts

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

canartuc@mastodon.social at 2026-06-27T10:55:00.000Z ##

Podman 5.8.4 closes CVE-2026-57231. A malicious image could ship malformed Env entries that, when the container started, leaked the host's environment variables into it, including through glob operators that grab multiple variables without knowing their names. The release also updates golang.org/x/crypto to v0.53.0 for CVE-2026-39830 and CVE-2026-42508. When you pull a public image, do you think about what its metadata can read from your host?
#containers #security

##

CVE-2026-39830
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-06-17T10:42:39.483000

1 posts

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

canartuc@mastodon.social at 2026-06-27T10:55:00.000Z ##

Podman 5.8.4 closes CVE-2026-57231. A malicious image could ship malformed Env entries that, when the container started, leaked the host's environment variables into it, including through glob operators that grab multiple variables without knowing their names. The release also updates golang.org/x/crypto to v0.53.0 for CVE-2026-39830 and CVE-2026-42508. When you pull a public image, do you think about what its metadata can read from your host?
#containers #security

##

CVE-2026-35373
(3.3 LOW)

EPSS: 0.12%

updated 2026-06-17T10:40:28.933000

2 posts

A logic error in the ln utility of uutils coreutils causes the program to reject source paths containing non-UTF-8 filename bytes when using target-directory forms (e.g., ln SOURCE... DIRECTORY). While GNU ln treats filenames as raw bytes and creates the links correctly, the uutils implementation enforces UTF-8 encoding, resulting in a failure to stat the file and a non-zero exit code. In environm

thecybermind at 2026-06-27T11:34:41.896Z ##

CVE-2026-35373 introduces a critical operational divergence in modern Linux system utilities, causing strict encoding enforcement to break automated backup and data migration pipelines. Access our strategic CSUITE briefing to audit system integrity: thecybermind.co/393z

##

thecybermind@infosec.exchange at 2026-06-27T11:34:41.000Z ##

CVE-2026-35373 introduces a critical operational divergence in modern Linux system utilities, causing strict encoding enforcement to break automated backup and data migration pipelines. Access our strategic CSUITE briefing to audit system integrity: thecybermind.co/393z

##

CVE-2026-34926
(6.7 MEDIUM)

EPSS: 12.68%

updated 2026-06-17T10:39:49.727000

2 posts

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained adminis

1 repos

https://github.com/HORKimhab/CVE-2026-34926

thecybermind at 2026-06-27T02:41:06.236Z ##

CISA confirms active zero-day exploitation of Trend Micro Apex One (CVE-2026-34926), introducing critical directory traversal and code injection risks across the endpoint control plane. Access our full executive advisory on asset mitigation and strategic governance alignment: thecybermind.co/22mw

##

thecybermind@infosec.exchange at 2026-06-27T02:41:06.000Z ##

CISA confirms active zero-day exploitation of Trend Micro Apex One (CVE-2026-34926), introducing critical directory traversal and code injection risks across the endpoint control plane. Access our full executive advisory on asset mitigation and strategic governance alignment: thecybermind.co/22mw

##

CVE-2026-33017
(9.8 CRITICAL)

EPSS: 98.41%

updated 2026-06-17T10:36:47.177000

2 posts

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored f

Nuclei template

11 repos

https://github.com/EQSTLab/CVE-2026-33017

https://github.com/r3nsi15/CVE-2026-33017-langflow-rce

https://github.com/0xBlackash/CVE-2026-33017

https://github.com/oscar-mine/CVE-2026-33017-Exploit

https://github.com/SimoesCTT/Sovereign-Echo-33017

https://github.com/masterwok/PoC-CVE-2026-33017

https://github.com/Jorrit-VM/CVE-2026-33017

https://github.com/omer-efe-curkus/CVE-2026-33017-Langflow-RCE-PoC

https://github.com/z4yd3/PoC-CVE-2026-33017

https://github.com/rootdirective-sec/CVE-2026-33017-Lab

https://github.com/MaxMnMl/langflow-CVE-2026-33017-poc

DailyCyberSecurity at 2026-06-27T01:05:40.879Z ##

Langflow Cryptominer Malware Exploits CVE-2026-33017

At least 39 rival malware families appear on a kill list used by a new Langflow cryptominer malware campaign. Threat actors now target exposed artificial intelligence application endpoints to breach enterprise networks. They exploit CVE-2026-33017, which is a critical remote code execution vulnerability. Consequently, attackers hijack servers to mine cryptocurrency. At a glance Malware Family: Modified KORKERDS/MALXMR variant Threat Actor:

securityonline.info/langflow-c

##

DailyCyberSecurity@infosec.exchange at 2026-06-27T01:05:40.000Z ##

Langflow Cryptominer Malware Exploits CVE-2026-33017

At least 39 rival malware families appear on a kill list used by a new Langflow cryptominer malware campaign. Threat actors now target exposed artificial intelligence application endpoints to breach enterprise networks. They exploit CVE-2026-33017, which is a critical remote code execution vulnerability. Consequently, attackers hijack servers to mine cryptocurrency. At a glance Malware Family: Modified KORKERDS/MALXMR variant Threat Actor:

securityonline.info/langflow-c

##

CVE-2026-28910
(3.3 LOW)

EPSS: 0.12%

updated 2026-06-17T10:29:19.940000

1 posts

This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app may be able to access arbitrary files.

mysk@mastodon.social at 2026-06-26T16:02:35.000Z ##

@0 Oh, I stopped dragging and dropping things in the Terminal since we published this:

mysk.blog/2026/05/19/cve-2026-

##

CVE-2026-22678
(5.4 MEDIUM)

EPSS: 0.17%

updated 2026-06-17T10:20:13.247000

1 posts

Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attackers to execute arbitrary JavaScript in the browser context of administrators by injecting unsanitized input stored in save_tmpl.cgi and rendered unescaped in list_tmpls.cgi.

beyondmachines1@infosec.exchange at 2026-06-25T12:01:31.000Z ##

Webmin 2.641 Patches Root Takeover and 2FA Bypass Vulnerabilities

Webmin version 2.641 addresses multiple critical vulnerabilities, including a root-level stored XSS (CVE-2026-22678), a path traversal file overwrite (CVE-2026-49103), and a 2FA bypass (CVE-2026-56022). These flaws allow low-privileged users to compromise root accounts and bypass multi-factor authentication in multi-tenant hosting environments.

**Update your Webmin instances to version 2.641 immediately to prevent low-privileged users from taking over your root account. If you cannot patch today, restrict access to the mail and notification modules to only your most trusted administrators.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-20971
(7.8 HIGH)

EPSS: 0.13%

updated 2026-06-17T10:18:08.213000

4 posts

Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

nemo@mas.to at 2026-06-27T07:54:03.000Z ##

🔒 Sicherheitslücke im Android-Kernel: Forscher von Lucid Bit Labs melden einen Use-after-free-Bug (CVE-2026-20971, CVSS 7,8) in Samsung-Proca/Knox. Betroffen: Galaxy S9–S25 u. a. Angriff möglich via bösartige App & Race-Condition. Patch: Januar 2026. golem.de/news/sicherheitslueck #CyberSecurity #Samsung #Android #Vulnerability #Patch

##

nemo@mas.to at 2026-06-27T07:54:03.000Z ##

🔒 Sicherheitslücke im Android-Kernel: Forscher von Lucid Bit Labs melden einen Use-after-free-Bug (CVE-2026-20971, CVSS 7,8) in Samsung-Proca/Knox. Betroffen: Galaxy S9–S25 u. a. Angriff möglich via bösartige App & Race-Condition. Patch: Januar 2026. golem.de/news/sicherheitslueck #CyberSecurity #Samsung #Android #Vulnerability #Patch

##

_r_netsec@infosec.exchange at 2026-06-24T10:58:06.000Z ##

CVE-2026-20971: Samsung Android kernel UAF affecting Galaxy S9-S25 lucidbitlabs.com/blog/when-def

##

informapirata@mastodon.uno at 2026-06-23T23:06:19.000Z ##

La vulnerabilità UAF del kernel KNOX di Samsung espone milioni di dispositivi Galaxy.

La vulnerabilità KNOX di Samsung (CVE-2026-20971) è una UAF del kernel in PROCA/FIVE che può consentire la corruzione [della memoria] tramite una race condition; Samsung l'ha corretta nel gennaio 2026.

securityaffairs.com/194090/sec

@informatica

infosec.exchange/@securityaffa

##

CVE-2026-20245
(7.8 HIGH)

EPSS: 9.92%

updated 2026-06-17T10:17:19.370000

6 posts

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of us

3 repos

https://github.com/HORKimhab/CVE-2026-20245

https://github.com/0xBlackash/CVE-2026-20245

https://github.com/fevar54/CVE-2026-20245---Cisco-SD-WAN-Privilege-Escalation-Exploit

vitobotta@mastodon.social at 2026-06-26T14:19:36.000Z ##

Cisco SD-WAN zero-day CVE-2026-20245 exploited for two months before disclosure. Mandiant found the traces. Attacker had netadmin access, escalated to root, cleaned up config files. Inside for months.

thehackernews.com/2026/06/cisc

##

DailyCyberSecurity@infosec.exchange at 2026-06-26T12:15:27.000Z ##

Cisco SD-WAN Zero-Day Exploited in Attacks

At a glance Actor: Unknown threat actor Activity Type: Privilege escalation and zero-day exploitation Targets: Service provider infrastructure Scale: Unknown victim count Jurisdiction: Active investigation; no arrests reported Source: Mandiant TL;DR Attackers breached a service provider using a Cisco SD-WAN zero-day flaw. They exploited CVE-2026-20245 to gain root-level control over network systems. Therefore, administrators must upgrade their software immediately to block further intrusions.

securityonline.info/cisco-sd-w

##

oversecurity@mastodon.social at 2026-06-26T08:44:10.000Z ##

CVE-2026-20245 Zero-Day Exploited in Cisco Catalyst SD-WAN Manager to Gain Root Access

A newly disclosed zero-day vulnerability, CVE-2026-20245, has been exploited by a threat actor targeting Cisco Catalyst SD-WAN Manager. By exploiting

🔗️ [Thecyberexpress] link.is.it/YtDctR

##

oversecurity@mastodon.social at 2026-06-24T21:40:06.000Z ##

Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access

New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to...

🔗️ [Bleepingcomputer] link.is.it/gbIA4V

##

AAKL@infosec.exchange at 2026-06-24T15:57:48.000Z ##

New.

Mandiant: Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager cloud.google.com/blog/topics/t #Google

Microsoft:

StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them microsoft.com/en-us/security/b

Kaspersky:

StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader securelist.com/strikeshark-cam @Kaspersky

Symantec: Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker security.com/threat-intelligen

Picus:

The ShinyHunters Domino Effect: One Breach, Hundreds of Victims picussecurity.com/resource/blo

Proofpoint:

StealC You Later: Proofpoint and IBM X-Force Support Operation Endgame Disruptions proofpoint.com/us/blog/threat- #threatresearch #cybercrime #Microsoft #infosec #threatintelligence #Cisco #vulnerability #zeroday #ransomware

##

Mozilla@activitypub.awakari.com at 2026-06-24T14:15:55.000Z ## Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan Introduction to Malware Binary Triage (IMBT) ...

#Malware #News

Origin | Interest | Match ##

CVE-2026-20175
(6.1 MEDIUM)

EPSS: 0.18%

updated 2026-06-17T10:17:15.950000

1 posts

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address

AAKL@infosec.exchange at 2026-06-25T16:45:31.000Z ##

New advisory.

CVE-2026-20175, medium severity: Cisco Finesse Remote File Inclusion Vulnerability sec.cloudapps.cisco.com/securi

From yesterday:

Cisco Advance Notification for Publication of July 1, 2026, Security Advisories sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-20045
(8.2 HIGH)

EPSS: 4.31%

updated 2026-06-17T10:16:58.097000

1 posts

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying

1 repos

https://github.com/dkstar11q/Ashwesker-CVE-2026-20045

beyondmachines1@infosec.exchange at 2026-06-25T09:01:30.000Z ##

Active Exploitation of Cisco Unified Communications Manager Vulnerabilities Grants Root Access

Cisco Unified Communications Manager is facing active exploitation of two vulnerabilities, CVE-2026-20230 and CVE-2026-20045, which allow unauthenticated attackers to gain root access and deploy webshells.

**Apply the latest software updates, including Unified CM 14SU6 and 15SU5, immediately. If patching is not possible, disable the Cisco WebDialer Web Service to sever the attack path, and aggressively audit your /platform-services/ directory for unusual .jsp files or unauthorized webshells.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2024-2658
(0 None)

EPSS: 0.41%

updated 2026-06-17T07:24:59.037000

1 posts

A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated p

2 repos

https://github.com/laoqin1234/Linux-Root-CVE-2024-26581-PoC

https://github.com/madfxr/CVE-2024-26581-Checker

AAKL@infosec.exchange at 2026-06-26T14:39:26.000Z ##

New and part promo.

Kaspersky:Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk securelist.com/tr/schneider-el @Kaspersky #infosec #vulnerability

##

CVE-2018-13818
(9.8 CRITICAL)

EPSS: 6.99%

updated 2026-06-17T01:40:13.793000

2 posts

Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly wrap input to it

CVE-2014-0160
(7.5 HIGH)

EPSS: 100.00%

updated 2026-06-17T00:02:24.467000

1 posts

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Nuclei template

74 repos

https://github.com/tomdevman/heartbleed-bug

https://github.com/0xinf0/bleeding_onions

https://github.com/marstornado/cve-2014-0160-Yunfeng-Jiang

https://github.com/obayesshelton/CVE-2014-0160-Scanner

https://github.com/undacmic/heartbleed-proof-of-concept

https://github.com/hybridus/heartbleedscanner

https://github.com/MrE-Fog/CVE-2014-0160-Chrome-Plugin

https://github.com/OffensivePython/HeartLeak

https://github.com/hreese/heartbleed-dtls

https://github.com/GuillermoEscobero/heartbleed

https://github.com/siddolo/knockbleed

https://github.com/xanas/heartbleed.py

https://github.com/a0726h77/heartbleed-test

https://github.com/fb1h2s/CVE-2014-0160

https://github.com/sammyfung/openssl-heartbleed-fix

https://github.com/proactiveRISK/heartbleed-extention

https://github.com/ArtemCyberLab/Project-Field-Analysis-and-Memory-Leak-Demonstration

https://github.com/iwaffles/heartbleed-test.crx

https://github.com/SimoesCTT/CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160

https://github.com/belmind/heartbleed

https://github.com/ingochris/heartpatch.us

https://github.com/cved-sources/cve-2014-0160

https://github.com/DisK0nn3cT/MaltegoHeartbleed

https://github.com/0xBlackash/CVE-2014-0160

https://github.com/WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed

https://github.com/victoriacfigueiredo/heartbleed-lab

https://github.com/musalbas/heartbleed-masstest

https://github.com/waqasjamal-zz/HeartBleed-Vulnerability-Checker

https://github.com/sensepost/heartbleed-poc

https://github.com/FiloSottile/Heartbleed

https://github.com/yryz/heartbleed.js

https://github.com/GardeniaWhite/fuzzing

https://github.com/pierceoneill/bleeding-heart

https://github.com/titanous/heartbleeder

https://github.com/amerine/coronary

https://github.com/timsonner/cve-2014-0160-heartbleed

https://github.com/Xyl2k/CVE-2014-0160-Chrome-Plugin

https://github.com/mpgn/heartbleed-PoC

https://github.com/0x90/CVE-2014-0160

https://github.com/artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS

https://github.com/xlucas/heartbleed

https://github.com/caiqiqi/OpenSSL-HeartBleed-CVE-2014-0160-PoC

https://github.com/pblittle/aws-suture

https://github.com/takeshixx/ssl-heartbleed.nse

https://github.com/cheese-hub/heartbleed

https://github.com/ice-security88/CVE-2014-0160

https://github.com/22imer/CVE-2014-0160

https://github.com/iSCInc/heartbleed

https://github.com/Shayhha/HeartbleedAttack

https://github.com/h3x0v3rl0rd/CVE-2014-0160_Heartbleed

https://github.com/PinkP4nther/Heartbleed_PoC

https://github.com/cyphar/heartthreader

https://github.com/anthophilee/A2SV--SSL-VUL-Scan

https://github.com/roganartu/heartbleedchecker-chrome

https://github.com/hmlio/vaas-cve-2014-0160

https://github.com/ThanHuuTuan/Heartexploit

https://github.com/mozilla-services/Heartbleed

https://github.com/froyo75/Heartbleed_Dockerfile_with_Nginx

https://github.com/einaros/heartbleed-tools

https://github.com/yashfren/CVE-2014-0160-HeartBleed

https://github.com/indiw0rm/-Heartbleed-

https://github.com/Ryo-Soikutsu/Heartbleed

https://github.com/idkqh7/heatbleeding

https://github.com/isgroup/openmagic

https://github.com/indrajeetmp11/Heartbleed-PoC-Exploit-Script

https://github.com/rouze-d/heartbleed

https://github.com/Lekensteyn/pacemaker

https://github.com/zouguangxian/heartbleed

https://github.com/jdauphant/patch-openssl-CVE-2014-0160

https://github.com/DominikTo/bleed

https://github.com/Saymeis/HeartBleed

https://github.com/cbk914/heartbleed-checker

https://github.com/GeeksXtreme/ssl-heartbleed.nse

https://github.com/vortextube/ssl_scanner

hugovalters@mastodon.social at 2026-06-27T08:21:28.000Z ##

Exploit Heartbleed (CVE-2014-0160) with OpenSSL s_client: send a malformed heartbeat request with oversized payload length to extract up to 64KB of heap memory. Use -no_ssl3 -no_tls1 for TLS 1.0/1.1, -msg to capture leaked data. #cve #snippet #heartbleed #cve-2014-0160 #ValtersIT

valtersit.com/vault/heartbleed

##

CVE-2026-10646
(0 None)

EPSS: 0.00%

2 posts

N/A

offseq at 2026-06-28T06:00:24.771Z ##

Zephyr 4.0.0 – 4.4.0 is affected by CVE-2026-10646 (HIGH, CVSS 7.4): use-after-free in getaddrinfo() can cause memory corruption via spoofed DNS responses. Patch pending — limit untrusted network access. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-28T06:00:24.000Z ##

Zephyr 4.0.0 – 4.4.0 is affected by CVE-2026-10646 (HIGH, CVSS 7.4): use-after-free in getaddrinfo() can cause memory corruption via spoofed DNS responses. Patch pending — limit untrusted network access. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #CVE #Security

##

CVE-2026-45408
(0 None)

EPSS: 0.23%

2 posts

N/A

hugovalters@mastodon.social at 2026-06-28T05:07:14.000Z ##

CVE-2026-45408 - Critical Command Injection in Dokku. CVSS 9.0. No patch available. Mitigations required. Limit git push access and review app name validation. #CVE #Dokku #infosec

valtersit.com/cve/CVE-2026-454

##

hugovalters@mastodon.social at 2026-06-28T05:07:14.000Z ##

CVE-2026-45408 - Critical Command Injection in Dokku. CVSS 9.0. No patch available. Mitigations required. Limit git push access and review app name validation. #CVE #Dokku #infosec

valtersit.com/cve/CVE-2026-454

##

CVE-2026-47729
(0 None)

EPSS: 0.00%

3 posts

N/A

1 repos

https://github.com/0xBlackash/CVE-2026-47729

mastokukei@social.josko.org at 2026-06-27T09:02:01.000Z ##

AdvancedCLI, and multiple sensor/toolkit updates.
- **PostgreSQL updates**: Security patches (CVE-2026-6637), pg_qualstats 2.1.4, pg_stat_kcache 2.3.2, and PGDay.UK 2026 schedule.
- **Rust & Zig**: Dr.Jit 1.4, Mitsuba 3.9, and Mach Nominated Zig versions for gamedev.
- **Security vulnerabilities**: Squidbleed (CVE-2026-47729), NetBSD/pkgsrc CVEs, and TXE firmware flaws. [2/2]

##

nemo@mas.to at 2026-06-27T07:55:51.000Z ##

🛡️ Squidbleed: Eine seit 1997 in Squid klaffende Lücke (CVE-2026-47729) ermöglicht laut Forschern das unbemerkt mögliche Leaken von HTTP-Daten über Heap-Buffer-Overread. Besonders riskant bei Klartext-Traffic (HTTP/FTP). Fix seit Squid 7.6. Details: golem.de/news/squidbleed-29-ja #Security #CyberSecurity #Squid #CVE #Vulnerability

##

nemo@mas.to at 2026-06-27T07:55:51.000Z ##

🛡️ Squidbleed: Eine seit 1997 in Squid klaffende Lücke (CVE-2026-47729) ermöglicht laut Forschern das unbemerkt mögliche Leaken von HTTP-Daten über Heap-Buffer-Overread. Besonders riskant bei Klartext-Traffic (HTTP/FTP). Fix seit Squid 7.6. Details: golem.de/news/squidbleed-29-ja #Security #CyberSecurity #Squid #CVE #Vulnerability

##

CVE-2026-11705
(0 None)

EPSS: 0.00%

1 posts

N/A

beyondmachines1@infosec.exchange at 2026-06-26T16:01:21.000Z ##

Arista Patches Critical Telemetry and Authentication Flaws in EOS Network Operating System

Arista Networks has patched six vulnerabilities in its EOS operating system, including a critical flaw (CVE-2026-11705) in the telemetry agent that allows attackers to modify system data. The updates also fix policy-based authentication bypass and internal credential exposure risks in data center and cloud environments.

**First, make sure all Arista EOS management interfaces and streaming telemetry is isolated from the internet and reachable only from trusted management networks. Then update affected devices (EOS 4.31 through 4.36) to version 4.36.1F or apply Arista's telemetry agent hotfixes; As a mitigation, ensure the telemetry agent isn't running from the /usr/bin/TerminAttrRW path and remove the -cveapimode=queued flag.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-20896
(0 None)

EPSS: 0.00%

1 posts

N/A

guru@thecybersecguru.com at 2026-06-26T04:51:47.000Z ##

Three Vulnerabilities, One Platform: Why Your Self-Hosted Gitea/Gogs Instance Is Probably Already Owned

Three critical Gitea and Gogs CVEs disclosed in 2026: a CVSS 9.8 auth bypass via X-WEBAUTH-USER header, a stored DOM XSS through Semantic UI's preserveHTML, and an incomplete SSRF fix exposing AWS IMDS credentials

thecybersecguru.com/news/cve-2

##

CVE-2026-8932
(0 None)

EPSS: 0.00%

2 posts

N/A

1 repos

https://github.com/0xBlackash/CVE-2026-8932

beyondmachines1@infosec.exchange at 2026-06-25T17:01:31.000Z ##

curl Patches 25-Year-Old Vulnerability and 17 Other Flaws

curl version 8.21.0 addresses 18 vulnerabilities, including a 25-year-old authentication bypass (CVE-2026-8932) and multiple memory safety issues. The flaws primarily affect libcurl, the library used by billions of devices for data transfer.

**Plan to update your curl and libcurl installations to version 8.21.0. Since libcurl is hidden inside many apps and devices, you should check your entire software stack for outdated versions.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

bagder@mastodon.social at 2026-06-24T07:20:34.000Z ##

CVE-2026-8932 is the oldest #curl vulnerability reported so far. 25.25 years old. Shipped in releases since curl version 7.7, released on March 22 2001

Still rather benign and it probably hurt about three users, at most.

curl.se/docs/CVE-2026-8932.html

##

CVE-2026-50000
(0 None)

EPSS: 0.00%

1 posts

N/A

legoktm@wikis.world at 2026-06-24T14:57:43.000Z ##

RE: social.freedom.press/@securedr

The low priority issue we disclosed today managed to get assigned CVE-2026-50000.

Didn't include this in the writeup, but just for the purpose of keeping score, this would likely not have happened if it was written in #Rust because mutability is part of the type system, so you don't end up accidentally mutating what should be an immutable object!

github.com/freedomofpress/secu

##

CVE-2026-50160
(0 None)

EPSS: 0.00%

1 posts

N/A

_r_netsec@infosec.exchange at 2026-06-23T17:43:05.000Z ##

CVE-2026-50160: Four Independent Weaknesses Combine Into a CVSS 10.0 Full Compromise in Hoppscotch offgridsec.com/blog-hoppscotch

##

Visit counter For Websites