##
Updated at UTC 2026-08-19T09:24:02.375008
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-70408 | 8.8 | 0.00% | 2 | 0 | 2026-08-19T06:31:24 | An incorrect authorization vulnerability exists in acmailer, which may allow a u | |
| CVE-2026-19942 | 8.1 | 0.00% | 2 | 0 | 2026-08-19T05:17:02.217000 | The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO | |
| CVE-2026-64849 | 9.3 | 0.35% | 8 | 2 | template | 2026-08-19T04:17:32.290000 | MLflow is an open source AI engineering platform for agents, large language mode |
| CVE-2026-76004 | 9.9 | 0.00% | 4 | 0 | 2026-08-19T03:31:30 | A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-21090 | |
| CVE-2026-76008 | 10.0 | 0.00% | 4 | 0 | 2026-08-19T03:31:30 | A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_ | |
| CVE-2026-76003 | 9.9 | 0.00% | 4 | 0 | 2026-08-19T03:31:23 | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected | |
| CVE-2026-75976 | 9.9 | 0.00% | 4 | 0 | 2026-08-19T00:31:19 | A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the | |
| CVE-2026-66602 | 8.8 | 0.00% | 2 | 0 | 2026-08-19T00:31:18 | Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress | |
| CVE-2026-53958 | 7.6 | 0.00% | 2 | 0 | 2026-08-18T22:16:54.717000 | 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4g | |
| CVE-2026-50186 | 8.8 | 0.00% | 2 | 0 | 2026-08-18T22:16:52.783000 | 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4g | |
| CVE-2026-21580 | 0 | 0.00% | 2 | 0 | 2026-08-18T22:16:50.140000 | This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security | |
| CVE-2026-73938 | 7.5 | 0.00% | 2 | 0 | 2026-08-18T21:34:29 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73939 | 8.6 | 0.00% | 2 | 0 | 2026-08-18T21:34:29 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73936 | 7.5 | 0.00% | 2 | 0 | 2026-08-18T21:34:28 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73934 | 7.5 | 0.00% | 2 | 0 | 2026-08-18T21:34:28 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73931 | 8.3 | 0.00% | 2 | 0 | 2026-08-18T21:34:21 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73921 | 9.8 | 0.00% | 2 | 0 | 2026-08-18T21:34:18 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-60782 | 9.8 | 0.00% | 1 | 0 | 2026-08-18T21:32:07 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone | |
| CVE-2026-60720 | 9.9 | 0.00% | 1 | 0 | 2026-08-18T21:32:06 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware | |
| CVE-2026-60730 | 9.9 | 0.00% | 1 | 0 | 2026-08-18T21:32:04 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware | |
| CVE-2026-60392 | 7.8 | 0.00% | 1 | 0 | 2026-08-18T21:32:02 | Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middl | |
| CVE-2026-75877 | 9.9 | 0.00% | 2 | 0 | 2026-08-18T21:31:59 | A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affec | |
| CVE-2026-60702 | 9.9 | 0.00% | 2 | 0 | 2026-08-18T21:31:57 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware | |
| CVE-2026-47629 | 7.5 | 0.00% | 4 | 0 | 2026-08-18T21:31:55 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attac | |
| CVE-2026-47606 | 6.5 | 0.00% | 2 | 0 | 2026-08-18T21:31:54 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attac | |
| CVE-2026-47627 | 9.8 | 0.00% | 4 | 0 | 2026-08-18T21:31:53 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attac | |
| CVE-2026-75935 | 7.5 | 0.00% | 2 | 0 | 2026-08-18T21:18:27.143000 | Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-jav | |
| CVE-2026-73937 | 8.2 | 0.00% | 2 | 0 | 2026-08-18T21:18:26.800000 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73935 | 7.5 | 0.00% | 2 | 0 | 2026-08-18T21:18:26.570000 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73930 | 9.9 | 0.00% | 2 | 0 | 2026-08-18T21:18:26.003000 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-17106 | None | 0.00% | 1 | 3 | 2026-08-18T21:17:30 | ### Summary The tar extraction routines in `moby/go-archive` (`Unpack`, `UnpackL | |
| CVE-2026-60728 | 9.1 | 0.00% | 1 | 0 | 2026-08-18T21:16:40.743000 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware | |
| CVE-2026-60727 | 9.8 | 0.00% | 1 | 0 | 2026-08-18T21:16:40.627000 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware | |
| CVE-2026-60721 | 9.8 | 0.00% | 1 | 0 | 2026-08-18T21:16:40.253000 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware | |
| CVE-2026-75625 | 9.0 | 0.00% | 2 | 0 | 2026-08-18T20:17:32.460000 | Kraken agents fail to verify peer-to-peer downloaded blobs against their request | |
| CVE-2026-16098 | 9.8 | 0.64% | 2 | 0 | 2026-08-18T20:17:12.740000 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U | |
| CVE-2026-47630 | 5.5 | 0.00% | 2 | 0 | 2026-08-18T19:16:52.650000 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attac | |
| CVE-2026-47628 | 7.5 | 0.00% | 4 | 0 | 2026-08-18T19:16:51.740000 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attac | |
| CVE-2026-59310 | 9.8 | 1.14% | 6 | 2 | 2026-08-18T18:32:52 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-75130 | 9.0 | 0.00% | 2 | 0 | 2026-08-18T18:32:11 | Context7 through 2.1.2 contains a prompt injection vulnerability that allows att | |
| CVE-2026-67854 | 9.8 | 0.20% | 1 | 0 | 2026-08-18T18:31:53 | SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute | |
| CVE-2026-65400 | 7.1 | 0.50% | 17 | 1 | 2026-08-18T18:31:47 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-33824 | 9.8 | 55.85% | 4 | 2 | 2026-08-18T18:31:46 | Double free in Windows IKE Extension allows an unauthorized attacker to execute | |
| CVE-2026-9816 | 8.3 | 0.24% | 1 | 0 | 2026-08-18T16:18:24.590000 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail | |
| CVE-2026-75914 | 7.5 | 0.00% | 2 | 0 | 2026-08-18T16:18:23.840000 | CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the i | |
| CVE-2026-75103 | 8.8 | 0.34% | 1 | 0 | 2026-08-18T16:18:20.127000 | Crawlab fails to verify user ownership or administrative role on the password-ch | |
| CVE-2026-15748 | 9.8 | 1.18% | 8 | 2 | 2026-08-18T16:17:02.083000 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload | |
| CVE-2026-69414 | 7.8 | 0.24% | 3 | 2 | 2026-08-18T15:32:27 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect | |
| CVE-2026-74015 | 9.3 | 0.00% | 1 | 0 | 2026-08-18T15:32:02 | Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | |
| CVE-2026-75783 | 9.6 | 0.00% | 2 | 0 | 2026-08-18T15:31:56 | A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Aff | |
| CVE-2026-24301 | 8.8 | 0.00% | 2 | 0 | 2026-08-18T15:31:45 | Improper neutralization of special elements used in a command ('command injectio | |
| CVE-2026-75094 | 9.1 | 2.09% | 2 | 0 | 2026-08-18T15:17:12.947000 | A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_ | |
| CVE-2026-40145 | 0 | 0.11% | 2 | 0 | 2026-08-18T15:04:46.610000 | A vulnerability exists in the interaction between a Endpoint Privilege Managemen | |
| CVE-2026-19478 | 9.4 | 0.72% | 14 | 3 | template | 2026-08-18T14:57:10.630000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 |
| CVE-2026-19650 | 7.1 | 0.24% | 4 | 1 | 2026-08-18T14:57:10.630000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 | |
| CVE-2026-75852 | 9.8 | 0.00% | 2 | 0 | 2026-08-18T14:18:12.260000 | ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data comm | |
| CVE-2026-75081 | 4.3 | 0.27% | 1 | 0 | 2026-08-18T14:18:08.373000 | A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unkno | |
| CVE-2026-19959 | 9.9 | 0.47% | 2 | 0 | 2026-08-18T14:16:59.543000 | A weakness has been identified in Edimax EW-7478APC 1.04. This affects the funct | |
| CVE-2026-75853 | 8.8 | 0.00% | 2 | 0 | 2026-08-18T12:31:30 | ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versi | |
| CVE-2026-75851 | 9.9 | 0.00% | 2 | 0 | 2026-08-18T12:31:30 | ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fa | |
| CVE-2026-75854 | 9.8 | 0.00% | 2 | 0 | 2026-08-18T12:31:30 | ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability i | |
| CVE-2026-75056 | 7.8 | 0.15% | 1 | 0 | 2026-08-18T04:16:47.410000 | In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was poss | |
| CVE-2026-75045 | 9.1 | 0.30% | 1 | 0 | 2026-08-18T04:16:47.170000 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unau | |
| CVE-2026-11801 | 7.5 | 0.30% | 2 | 0 | 2026-08-18T03:31:11 | The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authori | |
| CVE-2026-72831 | 8.8 | 0.30% | 1 | 0 | 2026-08-18T02:17:28.083000 | The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an inc | |
| CVE-2026-56677 | 8.6 | 0.27% | 1 | 0 | 2026-08-17T21:58:44 | ### Summary A Server-Side Request Forgery (SSRF) vulnerability exists in the 9R | |
| CVE-2026-75482 | 7.5 | 0.62% | 1 | 0 | 2026-08-17T21:31:35 | SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is a | |
| CVE-2026-68005 | 7.5 | 0.41% | 1 | 0 | 2026-08-17T21:31:30 | An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a d | |
| CVE-2026-74234 | 7.7 | 0.28% | 2 | 0 | 2026-08-17T21:31:30 | Legora before 2026-08-14 contains a cross-site scripting vulnerability that allo | |
| CVE-2026-75106 | 9.1 | 0.30% | 1 | 0 | 2026-08-17T21:31:30 | OpnForm derives editable-submission secrets from sequential row identifiers usin | |
| CVE-2026-75105 | 7.5 | 0.28% | 1 | 0 | 2026-08-17T21:31:30 | phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the | |
| CVE-2026-71472 | 9.1 | 0.39% | 1 | 0 | 2026-08-17T21:31:30 | A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authentica | |
| CVE-2026-70495 | 8.8 | 0.10% | 1 | 0 | 2026-08-17T21:31:30 | A flaw was found in search-v2-operator. This component's `search-serviceaccount` | |
| CVE-2026-66792 | 9.9 | 0.30% | 1 | 0 | 2026-08-17T21:31:30 | A flaw was found in the multicloud-operators-subscription component. This vulner | |
| CVE-2026-74238 | 7.5 | 0.38% | 1 | 0 | 2026-08-17T21:31:30 | TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the | |
| CVE-2026-75481 | 8.8 | 0.28% | 1 | 0 | 2026-08-17T21:31:27 | SkyPilot fails to validate that authenticated users are entitled to grant admini | |
| CVE-2026-75479 | 7.5 | 0.36% | 1 | 0 | 2026-08-17T21:31:27 | JimuReport contains an authentication bypass vulnerability in the report folder | |
| CVE-2026-75110 | 9.8 | 0.52% | 1 | 0 | 2026-08-17T21:31:27 | MemOS is a memory operating system for LLMs and AI agents. In deployments where | |
| CVE-2026-75111 | 7.5 | 0.39% | 1 | 0 | 2026-08-17T21:16:50.193000 | Evidently UI fails to properly validate the filename parameter in the dataset ma | |
| CVE-2026-45698 | 7.5 | 0.27% | 1 | 0 | 2026-08-17T20:16:43.153000 | Netatalk is a Free and Open Source file server suite for Unix-like operating sys | |
| CVE-2026-19714 | 9.1 | 0.32% | 1 | 0 | 2026-08-17T20:16:42.157000 | The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audien | |
| CVE-2026-17482 | 9.8 | 0.55% | 2 | 0 | 2026-08-17T19:16:28.953000 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to e | |
| CVE-2026-71290 | 9.1 | 0.19% | 3 | 0 | 2026-08-17T19:06:52.793000 | Improper TLS hostname verification vulnerability in Apache HttpComponents Client | |
| CVE-2026-75060 | 8.4 | 0.14% | 1 | 0 | 2026-08-17T18:31:28 | In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthentic | |
| CVE-2026-40144 | None | 0.11% | 2 | 0 | 2026-08-17T18:31:22 | A memory-corruption vulnerability exists in a kernel-mode component of BeyondTru | |
| CVE-2026-75051 | 8.1 | 0.22% | 1 | 0 | 2026-08-17T18:31:19 | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between | |
| CVE-2026-74791 | 8.6 | 0.27% | 1 | 0 | 2026-08-17T18:18:15.150000 | Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when Template | |
| CVE-2026-71479 | 9.1 | 0.52% | 1 | 0 | 2026-08-17T16:36:14 | ## Summary Multiple billing paths multiplied **user-controlled quantity paramet | |
| CVE-2026-74795 | 7.5 | 0.32% | 1 | 0 | 2026-08-17T16:17:48.827000 | Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its rec | |
| CVE-2026-74789 | 7.5 | 0.34% | 1 | 0 | 2026-08-17T16:17:48.590000 | Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only t | |
| CVE-2026-73060 | 7.5 | 0.37% | 1 | 0 | 2026-08-17T16:17:47 | Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerabil | |
| CVE-2026-19961 | 9.9 | 0.47% | 2 | 0 | 2026-08-17T16:16:53.947000 | A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function | |
| CVE-2026-16099 | 8.8 | 0.59% | 1 | 0 | 2026-08-17T16:16:50.930000 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary fi | |
| CVE-2026-15826 | 9.8 | 0.80% | 3 | 1 | template | 2026-08-17T16:16:50.140000 | The User Profile Builder plugin for WordPress is vulnerable to Authentication By |
| CVE-2026-14564 | 9.0 | 0.24% | 1 | 0 | 2026-08-17T15:30:38 | Insufficiently Protected Credentials vulnerability in Innotim Software Telecommu | |
| CVE-2026-74843 | 10.0 | 0.97% | 1 | 0 | 2026-08-17T15:16:58.230000 | A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected | |
| CVE-2026-74889 | 9.8 | 0.20% | 1 | 0 | 2026-08-17T12:32:31 | openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info para | |
| CVE-2026-74845 | 8.8 | 0.65% | 1 | 0 | 2026-08-17T12:32:26 | Official Document Management System developed by 2100 Technology has an Arbitrar | |
| CVE-2026-15623 | None | 0.20% | 1 | 0 | 2026-08-17T09:30:29 | A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud G | |
| CVE-2026-72407 | 10.0 | 0.52% | 1 | 0 | 2026-08-17T06:19:07.453000 | In the Linux kernel, the following vulnerability has been resolved: geneve: val | |
| CVE-2026-50602 | None | 0.10% | 1 | 0 | 2026-08-17T03:30:28 | A security vulnerability has been identified in Planet9 due to incorrect file pe | |
| CVE-2026-68820 | 7.0 | 0.33% | 6 | 2 | 2026-08-16T19:17:24.183000 | Use after free in Windows Ancillary Function Driver for WinSock allows an author | |
| CVE-2026-65775 | 7.8 | 2.45% | 1 | 0 | 2026-08-16T19:17:18.030000 | Use after free in Windows Win32K allows an authorized attacker to elevate privil | |
| CVE-2026-74794 | 7.5 | 0.28% | 1 | 0 | 2026-08-16T15:30:38 | Scriban before 6.6.0 contains an infinite recursion vulnerability in object rend | |
| CVE-2026-74792 | 7.5 | 0.31% | 1 | 0 | 2026-08-16T15:30:38 | Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vuln | |
| CVE-2026-73056 | 9.8 | 0.45% | 2 | 0 | 2026-08-16T15:30:33 | SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive | |
| CVE-2026-74788 | 7.5 | 0.28% | 1 | 0 | 2026-08-16T15:30:33 | Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memor | |
| CVE-2026-74783 | 7.5 | 0.28% | 1 | 0 | 2026-08-16T15:30:33 | Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimi | |
| CVE-2026-74790 | 9.1 | 0.29% | 1 | 0 | 2026-08-16T15:30:27 | Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering | |
| CVE-2026-73062 | 7.5 | 0.28% | 1 | 0 | 2026-08-16T15:30:26 | Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability i | |
| CVE-2026-73061 | 9.8 | 0.30% | 1 | 0 | 2026-08-16T15:30:26 | Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedOb | |
| CVE-2026-74787 | 7.5 | 0.28% | 1 | 0 | 2026-08-16T15:30:26 | Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the obj | |
| CVE-2026-73057 | 7.5 | 0.28% | 1 | 0 | 2026-08-16T15:30:25 | stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy en | |
| CVE-2026-74251 | None | 0.37% | 1 | 1 | 2026-08-16T15:30:24 | Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filte | |
| CVE-2026-17087 | 7.5 | 0.41% | 1 | 0 | 2026-08-16T09:30:22 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for W | |
| CVE-2026-18316 | 9.1 | 0.32% | 2 | 0 | 2026-08-16T06:30:37 | The Solace Extra plugin for WordPress is vulnerable to unauthorized modification | |
| CVE-2026-18432 | 9.8 | 0.45% | 2 | 0 | 2026-08-16T06:30:32 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege | |
| CVE-2026-14524 | 9.1 | 0.70% | 2 | 0 | 2026-08-16T06:30:32 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file d | |
| CVE-2026-17123 | 8.8 | 0.36% | 1 | 0 | 2026-08-16T06:30:32 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Req | |
| CVE-2026-14498 | 8.8 | 0.55% | 1 | 0 | 2026-08-16T06:30:31 | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution i | |
| CVE-2026-73053 | 9.0 | 0.28% | 1 | 0 | 2026-08-16T00:31:35 | SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th | |
| CVE-2026-73052 | 9.0 | 0.30% | 1 | 0 | 2026-08-16T00:31:34 | SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and | |
| CVE-2026-19188 | 10.0 | 1.89% | 1 | 0 | 2026-08-14T21:31:39 | A critical OS command injection vulnerability has been identified in the Haiwel | |
| CVE-2026-19747 | 9.8 | 2.36% | 1 | 0 | 2026-08-14T19:09:39.140000 | A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B | |
| CVE-2026-72526 | 9.9 | 0.30% | 1 | 0 | 2026-08-14T19:07:46.080000 | A flaw was found in the multicloud-integrations component. The Application propa | |
| CVE-2026-19681 | 9.9 | 2.24% | 1 | 0 | 2026-08-14T18:31:46 | An authenticated command injection vulnerability exists in Security Center relat | |
| CVE-2026-19771 | 7.2 | 2.79% | 1 | 0 | 2026-08-14T03:31:33 | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This im | |
| CVE-2026-68138 | 7.8 | 0.13% | 2 | 3 | 2026-08-14T00:31:53 | In the Linux kernel, the following vulnerability has been resolved: net/sched: | |
| CVE-2026-19001 | 9.8 | 0.38% | 2 | 0 | 2026-08-13T13:17:48.253000 | The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-siz | |
| CVE-2026-18146 | 7.2 | 0.36% | 2 | 0 | 2026-08-13T09:31:16 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Fo | |
| CVE-2026-73268 | 9.9 | 0.37% | 1 | 0 | 2026-08-12T21:31:50 | A flaw was found in the cluster-curator-controller component of multicluster eng | |
| CVE-2026-66804 | 7.8 | 3.42% | 2 | 3 | 2026-08-11T18:31:49 | Improper access control in Windows Cross Device Service allows an authorized att | |
| CVE-2026-62832 | 7.8 | 2.37% | 1 | 0 | 2026-08-11T18:31:33 | Improper link resolution before file access ('link following') in Windows User P | |
| CVE-2026-62696 | 7.8 | 3.17% | 1 | 0 | 2026-08-11T18:31:18 | Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistan | |
| CVE-2026-61358 | 7.8 | 3.68% | 1 | 0 | 2026-08-11T18:31:13 | Improper link resolution before file access ('link following') in Windows Access | |
| CVE-2026-58231 | 10.0 | 0.73% | 4 | 1 | 2026-08-11T12:30:28 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent | |
| CVE-2026-71958 | 9.8 | 0.56% | 2 | 0 | 2026-08-10T14:17:26.737000 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2 | |
| CVE-2026-6540 | 7.5 | 0.37% | 2 | 1 | 2026-08-08T01:10:43.697000 | Calico's Application Layer Policy (disabled by default), which enforces HTTP rul | |
| CVE-2026-6837 | 7.2 | 0.95% | 1 | 1 | 2026-08-04T03:31:16 | A post-authentication command injection vulnerability in the "export-cgi" CGI pr | |
| CVE-2026-12569 | 9.8 | 30.20% | 2 | 1 | 2026-08-01T05:16:55.023000 | A critical remote code execution (RCE) vulnerability has been reported in PTC Wi | |
| CVE-2026-43774 | 5.5 | 0.13% | 1 | 0 | 2026-07-28T18:33:56 | An out-of-bounds read was addressed with improved bounds checking. This issue is | |
| CVE-2026-54121 | 8.8 | 1.05% | 1 | 12 | 2026-07-21T19:54:33.623000 | Improper authorization in Active Directory Certificate Services (AD CS) allows a | |
| CVE-2026-8452 | 9.8 | 0.49% | 5 | 2 | 2026-07-01T18:32:28 | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp | |
| CVE-2026-3286 | 6.3 | 0.31% | 1 | 0 | 2026-06-17T10:43:20.747000 | A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. Th | |
| CVE-2008-5161 | 3.7 | 15.39% | 2 | 1 | 2026-06-16T22:59:22.107000 | Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Conne | |
| CVE-2026-32193 | 8.8 | 0.34% | 1 | 0 | 2026-06-09T18:30:48 | Improper limitation of a pathname to a restricted directory ('path traversal') i | |
| CVE-2026-47719 | 8.2 | 0.00% | 1 | 0 | 2026-06-08T23:06:42 | ## Summary An unauthenticated attacker (Alice) connects to FUXA's Socket.IO end | |
| CVE-2026-27912 | 8.0 | 0.24% | 2 | 3 | 2026-04-14T18:30:50 | Improper authorization in Windows Kerberos allows an authorized attacker to elev | |
| CVE-2025-60710 | 7.8 | 4.60% | 2 | 2 | 2026-04-13T18:31:39 | Improper link resolution before file access ('link following') in Host Process f | |
| CVE-2026-33696 | 9.9 | 0.77% | 1 | 0 | 2026-03-26T16:41:02 | ## Impact An authenticated user with permission to create or modify workflows co | |
| CVE-2025-62593 | None | 1.01% | 11 | 1 | 2025-12-01T16:02:43 | # Summary Developers working with Ray as a development tool can be exploited vi | |
| CVE-2026-50191 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-50142 | 0 | 0.00% | 2 | 1 | N/A | ||
| CVE-2026-52872 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-52877 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-52876 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-75936 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2025-53906 | 0 | 0.73% | 2 | 0 | N/A | ||
| CVE-2026-75913 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-75911 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2024-39302 | 0 | 0.45% | 1 | 0 | N/A | ||
| CVE-2026-45790 | 0 | 0.28% | 1 | 0 | N/A | ||
| CVE-2026-71424 | 0 | 0.29% | 1 | 0 | N/A | ||
| CVE-2026-62356 | 0 | 0.00% | 5 | 0 | N/A | ||
| CVE-2024-69414 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-72898 | 0 | 10.40% | 1 | 6 | template | N/A | |
| CVE-2026-73296 | 0 | 2.61% | 1 | 0 | N/A |
updated 2026-08-19T06:31:24
2 posts
🟠 CVE-2026-70408 - High (8.8)
An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70408/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-70408 - High (8.8)
An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70408/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T05:17:02.217000
2 posts
🟠 CVE-2026-19942 - High (8.1)
The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the AVCF_Abilities_Media::register (repla...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19942/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19942 - High (8.1)
The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the AVCF_Abilities_Media::register (repla...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19942/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T04:17:32.290000
8 posts
2 repos
Attackers Exploit a Critical MLflow Vulnerability
Attackers are actively exploiting a critical flaw in MLflow (CVE-2026-64849) to steal cloud credentials and gain remote code execution.
**If you run MLflow, update it to version 3.15.0 or later ASAP, and make sure the server is not reachable from the internet. Then check your audit logs for any odd requests to cloud metadata services. If you see any (or aren't sure), rotate your cloud credentials and keys as a precaution.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/attackers-exploit-a-critical-mlflow-vulnerability-3-u-3-k-6/gD2P6Ple2L
Active exploitation of CVE-2026-64849 in MLflow enables unauthenticated SSRF to internal endpoints including cloud metadata services. FUXA, a SCADA/HMI platform for industrial automation, faces parallel exposure. Both flaws were confirmed independently by watchTowr and VulnCheck.
#MLflowVulnerability #FUXACVE #IndustrialOT #AISecurity
https://cyberworldops.eu/en/mlflow-and-fuxa-under-attack-critical-ai-and-industrial-automation
##Attackers Exploit MLflow Flaw to Steal Cloud Credentials
A newly discovered vulnerability in MLflow, CVE-2026-64849, with a near-perfect CVSS score of 9.3 is being exploited by attackers to infiltrate cloud metadata services and steal sensitive credentials. This critical flaw allows hackers to issue unauthorized requests and extract confidential data, putting your cloud security at risk.
#Mlflow #CloudCredentialsTheft #Cve202664849 #ServersideRequestForgery #Ssrf
##A public PoC for CVE-2026-64849, an unauthenticated MLflow SSRF (CVSS 9.3), is now live. watchTowr reports exploitation attempts. Patch to 3.15.0.
##Attackers Exploit a Critical MLflow Vulnerability
Attackers are actively exploiting a critical flaw in MLflow (CVE-2026-64849) to steal cloud credentials and gain remote code execution.
**If you run MLflow, update it to version 3.15.0 or later ASAP, and make sure the server is not reachable from the internet. Then check your audit logs for any odd requests to cloud metadata services. If you see any (or aren't sure), rotate your cloud credentials and keys as a precaution.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/attackers-exploit-a-critical-mlflow-vulnerability-3-u-3-k-6/gD2P6Ple2L
Active exploitation of CVE-2026-64849 in MLflow enables unauthenticated SSRF to internal endpoints including cloud metadata services. FUXA, a SCADA/HMI platform for industrial automation, faces parallel exposure. Both flaws were confirmed independently by watchTowr and VulnCheck.
#MLflowVulnerability #FUXACVE #IndustrialOT #AISecurity
https://cyberworldops.eu/en/mlflow-and-fuxa-under-attack-critical-ai-and-industrial-automation
##A public PoC for CVE-2026-64849, an unauthenticated MLflow SSRF (CVSS 9.3), is now live. watchTowr reports exploitation attempts. Patch to 3.15.0.
##🔴 CVE-2026-64849 - Critical (9.3)
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/va...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64849/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T03:31:30
4 posts
UTT HiPER 1250GW v3.2.7-210907-180535 hit by CRITICAL stack-based buffer overflow (CVE-2026-76004) in HTTP handler. Exploitable via 'pvid' arg. No patch yet — restrict remote access & monitor traffic. https://radar.offseq.com/threat/cve-2026-76004-stack-based-buffer-overflow-in-utt-hiper-1250gw-976b1783bc5dbe2e #OffSeq #CVE202676004 #Vuln #Infosec
##🔴 CVE-2026-76004 - Critical (9.9)
A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The manipulation of the argumen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76004/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##UTT HiPER 1250GW v3.2.7-210907-180535 hit by CRITICAL stack-based buffer overflow (CVE-2026-76004) in HTTP handler. Exploitable via 'pvid' arg. No patch yet — restrict remote access & monitor traffic. https://radar.offseq.com/threat/cve-2026-76004-stack-based-buffer-overflow-in-utt-hiper-1250gw-976b1783bc5dbe2e #OffSeq #CVE202676004 #Vuln #Infosec
##🔴 CVE-2026-76004 - Critical (9.9)
A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The manipulation of the argumen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76004/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T03:31:30
4 posts
🔴 CVE-2026-76008 - Critical (10)
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76008/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Comfast CF-N1-S v2.6.0.1 hit by CRITICAL CVE-2026-76008: stack-based buffer overflow in /cgi-bin/mbox-config (get_para_from_uri). Remote exploitation risk; mitigation unavailable. Monitor for patches. #OffSeq #CVE202676008 #IoTSecurity https://radar.offseq.com/threat/cve-2026-76008-stack-based-buffer-overflow-in-comfast-cf-n1-s-3ceda49f6d8d37d6
##🔴 CVE-2026-76008 - Critical (10)
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76008/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Comfast CF-N1-S v2.6.0.1 hit by CRITICAL CVE-2026-76008: stack-based buffer overflow in /cgi-bin/mbox-config (get_para_from_uri). Remote exploitation risk; mitigation unavailable. Monitor for patches. #OffSeq #CVE202676008 #IoTSecurity https://radar.offseq.com/threat/cve-2026-76008-stack-based-buffer-overflow-in-comfast-cf-n1-s-3ceda49f6d8d37d6
##updated 2026-08-19T03:31:23
4 posts
CVE-2026-76003 (CRITICAL): Stack-based buffer overflow in UTT HiPER 1200GW (2.5.3-170306). Remote code execution possible via timestart argument; public exploit exists. No patch yet. Restrict access & monitor. https://radar.offseq.com/threat/cve-2026-76003-stack-based-buffer-overflow-in-utt-hiper-1200gw-f42b168f89ef1ec7 #OffSeq #CVE202676003 #infosec #vuln
##🔴 CVE-2026-76003 - Critical (9.9)
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based buffer overflow. The attack may ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76003/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-76003 (CRITICAL): Stack-based buffer overflow in UTT HiPER 1200GW (2.5.3-170306). Remote code execution possible via timestart argument; public exploit exists. No patch yet. Restrict access & monitor. https://radar.offseq.com/threat/cve-2026-76003-stack-based-buffer-overflow-in-utt-hiper-1200gw-f42b168f89ef1ec7 #OffSeq #CVE202676003 #infosec #vuln
##🔴 CVE-2026-76003 - Critical (9.9)
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based buffer overflow. The attack may ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76003/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T00:31:19
4 posts
🔴 CVE-2026-75976 - Critical (9.9)
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based buffer overflow. The attac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75976/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Stack-based buffer overflow (CVE-2026-75976, CVSS 9.4) in TRENDnet TEW-823DRU 1.1.02b01: remote exploitation possible via /cgi-bin/wan.cgi. Public exploit exists. Assess exposure & monitor for patches: https://radar.offseq.com/threat/cve-2026-75976-stack-based-buffer-overflow-in-trendnet-tew-823dru-3e76dd1e5f15fcab #OffSeq #Vulnerability #Infosec #IoTSecurity
##🔴 CVE-2026-75976 - Critical (9.9)
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based buffer overflow. The attac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75976/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Stack-based buffer overflow (CVE-2026-75976, CVSS 9.4) in TRENDnet TEW-823DRU 1.1.02b01: remote exploitation possible via /cgi-bin/wan.cgi. Public exploit exists. Assess exposure & monitor for patches: https://radar.offseq.com/threat/cve-2026-75976-stack-based-buffer-overflow-in-trendnet-tew-823dru-3e76dd1e5f15fcab #OffSeq #Vulnerability #Infosec #IoTSecurity
##updated 2026-08-19T00:31:18
2 posts
🟠 CVE-2026-66602 - High (8.8)
Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery.
This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66602/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-66602 - High (8.8)
Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery.
This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66602/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T22:16:54.717000
2 posts
🟠 CVE-2026-53958 - High (7.6)
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcI...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-53958 - High (7.6)
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcI...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T22:16:52.783000
2 posts
🟠 CVE-2026-50186 - High (8.8)
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports/:id/:filename. In server/api/controllers/boards...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50186/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-50186 - High (8.8)
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports/:id/:filename. In server/api/controllers/boards...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50186/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T22:16:50.140000
2 posts
A Confluence vulnerability, CVE-2026-21580, is a stored XSS flaw (CVSS 8.6) allowing unauthenticated attacks. A Jira flaw also patched. Update now.
#Atlassian #Confluence #CVE202621580 #StoredXSS #Jira #InfoSec
##A Confluence vulnerability, CVE-2026-21580, is a stored XSS flaw (CVSS 8.6) allowing unauthenticated attacks. A Jira flaw also patched. Update now.
#Atlassian #Confluence #CVE202621580 #StoredXSS #Jira #InfoSec
##updated 2026-08-18T21:34:29
2 posts
🟠 CVE-2026-73938 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73938/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73938 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73938/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T21:34:29
2 posts
🟠 CVE-2026-73939 - High (8.6)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73939/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73939 - High (8.6)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73939/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T21:34:28
2 posts
🟠 CVE-2026-73936 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73936/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73936 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73936/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T21:34:28
2 posts
🟠 CVE-2026-73934 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73934/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73934 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73934/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T21:34:21
2 posts
🟠 CVE-2026-73931 - High (8.3)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73931/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73931 - High (8.3)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73931/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T21:34:18
2 posts
🔴 CVE-2026-73921 - Critical (9.8)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73921/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73921 - Critical (9.8)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73921/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T21:32:07
1 posts
[1/9]
Most Impactful Security Incidents ( 2026‑08‑18 → 2026‑08‑19 )
---
PRIORITY 1 – Critical / High‑Severity Flaws (CVSS 7‑10):
CVE‑2026‑60392
• 7.8 (HIGH)
• Oracle Outside In Technology – PDF Export SDK (Fusion Middleware)
• Local‑privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
• 8.5.8
• Easily exploitable (local) – requires user interaction.
• https://cveawg.mitre.org/api/cve/CVE-2026-60392
CVE‑2026‑60782
• 9.8 (CRITICAL)
• Oracle Payments (E‑Business Suite) – File Transmission
• Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
• 12.2.3‑12.2.15
• Network‑accessible, no authentication required.
• https://cveawg.mitre.org/api/cve/CVE-2026-60782
CVE‑2026‑60730
• 9.9 (CRITICAL)
• Oracle WebCenter Portal – Composer component
• Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728
• 9.1 (CRITICAL)
• Oracle WebCenter Portal – Portlet Services
• Remote unauthenticated attacker can cause denial‑of‑service and full compromise of portal data.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can take over the IAM system via HTTP.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Same vector as above; full takeover possible.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720
• 9.9 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can compromise the IAM system.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60720
updated 2026-08-18T21:32:06
1 posts
[1/9]
Most Impactful Security Incidents ( 2026‑08‑18 → 2026‑08‑19 )
---
PRIORITY 1 – Critical / High‑Severity Flaws (CVSS 7‑10):
CVE‑2026‑60392
• 7.8 (HIGH)
• Oracle Outside In Technology – PDF Export SDK (Fusion Middleware)
• Local‑privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
• 8.5.8
• Easily exploitable (local) – requires user interaction.
• https://cveawg.mitre.org/api/cve/CVE-2026-60392
CVE‑2026‑60782
• 9.8 (CRITICAL)
• Oracle Payments (E‑Business Suite) – File Transmission
• Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
• 12.2.3‑12.2.15
• Network‑accessible, no authentication required.
• https://cveawg.mitre.org/api/cve/CVE-2026-60782
CVE‑2026‑60730
• 9.9 (CRITICAL)
• Oracle WebCenter Portal – Composer component
• Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728
• 9.1 (CRITICAL)
• Oracle WebCenter Portal – Portlet Services
• Remote unauthenticated attacker can cause denial‑of‑service and full compromise of portal data.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can take over the IAM system via HTTP.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Same vector as above; full takeover possible.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720
• 9.9 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can compromise the IAM system.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60720
updated 2026-08-18T21:32:04
1 posts
[1/9]
Most Impactful Security Incidents ( 2026‑08‑18 → 2026‑08‑19 )
---
PRIORITY 1 – Critical / High‑Severity Flaws (CVSS 7‑10):
CVE‑2026‑60392
• 7.8 (HIGH)
• Oracle Outside In Technology – PDF Export SDK (Fusion Middleware)
• Local‑privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
• 8.5.8
• Easily exploitable (local) – requires user interaction.
• https://cveawg.mitre.org/api/cve/CVE-2026-60392
CVE‑2026‑60782
• 9.8 (CRITICAL)
• Oracle Payments (E‑Business Suite) – File Transmission
• Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
• 12.2.3‑12.2.15
• Network‑accessible, no authentication required.
• https://cveawg.mitre.org/api/cve/CVE-2026-60782
CVE‑2026‑60730
• 9.9 (CRITICAL)
• Oracle WebCenter Portal – Composer component
• Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728
• 9.1 (CRITICAL)
• Oracle WebCenter Portal – Portlet Services
• Remote unauthenticated attacker can cause denial‑of‑service and full compromise of portal data.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can take over the IAM system via HTTP.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Same vector as above; full takeover possible.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720
• 9.9 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can compromise the IAM system.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60720
updated 2026-08-18T21:32:02
1 posts
[1/9]
Most Impactful Security Incidents ( 2026‑08‑18 → 2026‑08‑19 )
---
PRIORITY 1 – Critical / High‑Severity Flaws (CVSS 7‑10):
CVE‑2026‑60392
• 7.8 (HIGH)
• Oracle Outside In Technology – PDF Export SDK (Fusion Middleware)
• Local‑privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
• 8.5.8
• Easily exploitable (local) – requires user interaction.
• https://cveawg.mitre.org/api/cve/CVE-2026-60392
CVE‑2026‑60782
• 9.8 (CRITICAL)
• Oracle Payments (E‑Business Suite) – File Transmission
• Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
• 12.2.3‑12.2.15
• Network‑accessible, no authentication required.
• https://cveawg.mitre.org/api/cve/CVE-2026-60782
CVE‑2026‑60730
• 9.9 (CRITICAL)
• Oracle WebCenter Portal – Composer component
• Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728
• 9.1 (CRITICAL)
• Oracle WebCenter Portal – Portlet Services
• Remote unauthenticated attacker can cause denial‑of‑service and full compromise of portal data.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can take over the IAM system via HTTP.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Same vector as above; full takeover possible.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720
• 9.9 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can compromise the IAM system.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60720
updated 2026-08-18T21:31:59
2 posts
🔴 CVE-2026-75877 - Critical (9.9)
A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/FUN_0043372C of the component alphapd. Executing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75877/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75877 - Critical (9.9)
A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/FUN_0043372C of the component alphapd. Executing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75877/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T21:31:57
2 posts
An Oracle WebLogic vulnerability, CVE-2026-60702 (CVSS 9.9), allows full server takeover. Oracle patched nine flaws, five rated critical. Update now.
#OracleWebLogic #CVE202660702 #RCE #FusionMiddleware #ServerTakeover #InfoSec
##An Oracle WebLogic vulnerability, CVE-2026-60702 (CVSS 9.9), allows full server takeover. Oracle patched nine flaws, five rated critical. Update now.
#OracleWebLogic #CVE202660702 #RCE #FusionMiddleware #ServerTakeover #InfoSec
##updated 2026-08-18T21:31:55
4 posts
🟠 CVE-2026-47629 - High (7.5)
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47629/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Nvidia has new advisories addressing two vulnerabilities:
- NVIDIA Cumulus Linux and NVOS - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5817
- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630
NVIDIA Triton Inference Server - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5865 #Nvidia #infosec #vulnerability #Linux
##🟠 CVE-2026-47629 - High (7.5)
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47629/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Nvidia has new advisories addressing two vulnerabilities:
- NVIDIA Cumulus Linux and NVOS - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5817
- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630
NVIDIA Triton Inference Server - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5865 #Nvidia #infosec #vulnerability #Linux
##updated 2026-08-18T21:31:54
2 posts
Nvidia has new advisories addressing two vulnerabilities:
- NVIDIA Cumulus Linux and NVOS - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5817
- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630
NVIDIA Triton Inference Server - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5865 #Nvidia #infosec #vulnerability #Linux
##Nvidia has new advisories addressing two vulnerabilities:
- NVIDIA Cumulus Linux and NVOS - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5817
- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630
NVIDIA Triton Inference Server - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5865 #Nvidia #infosec #vulnerability #Linux
##updated 2026-08-18T21:31:53
4 posts
🔴 CVE-2026-47627 - Critical (9.8)
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47627/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Nvidia has new advisories addressing two vulnerabilities:
- NVIDIA Cumulus Linux and NVOS - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5817
- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630
NVIDIA Triton Inference Server - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5865 #Nvidia #infosec #vulnerability #Linux
##🔴 CVE-2026-47627 - Critical (9.8)
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47627/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Nvidia has new advisories addressing two vulnerabilities:
- NVIDIA Cumulus Linux and NVOS - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5817
- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630
NVIDIA Triton Inference Server - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5865 #Nvidia #infosec #vulnerability #Linux
##updated 2026-08-18T21:18:27.143000
2 posts
🟠 CVE-2026-75935 - High (7.5)
Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75935 - High (7.5)
Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T21:18:26.800000
2 posts
🟠 CVE-2026-73937 - High (8.2)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73937/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73937 - High (8.2)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73937/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T21:18:26.570000
2 posts
🟠 CVE-2026-73935 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73935 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T21:18:26.003000
2 posts
🔴 CVE-2026-73930 - Critical (9.9)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73930/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73930 - Critical (9.9)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73930/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T21:17:30
1 posts
3 repos
https://github.com/masasron/CopyEscape-CVE-2026-17106
CVE-2026-17106 (CVSS 7.1) is the Docker CopyEscape vulnerability, letting malicious containers overwrite host files and trigger code execution.
##updated 2026-08-18T21:16:40.743000
1 posts
[1/9]
Most Impactful Security Incidents ( 2026‑08‑18 → 2026‑08‑19 )
---
PRIORITY 1 – Critical / High‑Severity Flaws (CVSS 7‑10):
CVE‑2026‑60392
• 7.8 (HIGH)
• Oracle Outside In Technology – PDF Export SDK (Fusion Middleware)
• Local‑privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
• 8.5.8
• Easily exploitable (local) – requires user interaction.
• https://cveawg.mitre.org/api/cve/CVE-2026-60392
CVE‑2026‑60782
• 9.8 (CRITICAL)
• Oracle Payments (E‑Business Suite) – File Transmission
• Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
• 12.2.3‑12.2.15
• Network‑accessible, no authentication required.
• https://cveawg.mitre.org/api/cve/CVE-2026-60782
CVE‑2026‑60730
• 9.9 (CRITICAL)
• Oracle WebCenter Portal – Composer component
• Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728
• 9.1 (CRITICAL)
• Oracle WebCenter Portal – Portlet Services
• Remote unauthenticated attacker can cause denial‑of‑service and full compromise of portal data.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can take over the IAM system via HTTP.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Same vector as above; full takeover possible.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720
• 9.9 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can compromise the IAM system.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60720
updated 2026-08-18T21:16:40.627000
1 posts
[1/9]
Most Impactful Security Incidents ( 2026‑08‑18 → 2026‑08‑19 )
---
PRIORITY 1 – Critical / High‑Severity Flaws (CVSS 7‑10):
CVE‑2026‑60392
• 7.8 (HIGH)
• Oracle Outside In Technology – PDF Export SDK (Fusion Middleware)
• Local‑privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
• 8.5.8
• Easily exploitable (local) – requires user interaction.
• https://cveawg.mitre.org/api/cve/CVE-2026-60392
CVE‑2026‑60782
• 9.8 (CRITICAL)
• Oracle Payments (E‑Business Suite) – File Transmission
• Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
• 12.2.3‑12.2.15
• Network‑accessible, no authentication required.
• https://cveawg.mitre.org/api/cve/CVE-2026-60782
CVE‑2026‑60730
• 9.9 (CRITICAL)
• Oracle WebCenter Portal – Composer component
• Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728
• 9.1 (CRITICAL)
• Oracle WebCenter Portal – Portlet Services
• Remote unauthenticated attacker can cause denial‑of‑service and full compromise of portal data.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can take over the IAM system via HTTP.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Same vector as above; full takeover possible.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720
• 9.9 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can compromise the IAM system.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60720
updated 2026-08-18T21:16:40.253000
1 posts
[1/9]
Most Impactful Security Incidents ( 2026‑08‑18 → 2026‑08‑19 )
---
PRIORITY 1 – Critical / High‑Severity Flaws (CVSS 7‑10):
CVE‑2026‑60392
• 7.8 (HIGH)
• Oracle Outside In Technology – PDF Export SDK (Fusion Middleware)
• Local‑privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
• 8.5.8
• Easily exploitable (local) – requires user interaction.
• https://cveawg.mitre.org/api/cve/CVE-2026-60392
CVE‑2026‑60782
• 9.8 (CRITICAL)
• Oracle Payments (E‑Business Suite) – File Transmission
• Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
• 12.2.3‑12.2.15
• Network‑accessible, no authentication required.
• https://cveawg.mitre.org/api/cve/CVE-2026-60782
CVE‑2026‑60730
• 9.9 (CRITICAL)
• Oracle WebCenter Portal – Composer component
• Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728
• 9.1 (CRITICAL)
• Oracle WebCenter Portal – Portlet Services
• Remote unauthenticated attacker can cause denial‑of‑service and full compromise of portal data.
• 12.2.1.4.0, 14.1.2.0.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can take over the IAM system via HTTP.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721
• 9.8 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Same vector as above; full takeover possible.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720
• 9.9 (CRITICAL)
• Oracle Identity Manager – OIM Legacy UI
• Remote unauthenticated attacker can compromise the IAM system.
• 12.2.1.4.0, 14.1.2.1.0
• Network‑accessible, no auth.
• https://cveawg.mitre.org/api/cve/CVE-2026-60720
updated 2026-08-18T20:17:32.460000
2 posts
🔴 CVE-2026-75625 - Critical (9)
Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or mal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75625/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75625 - Critical (9)
Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or mal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75625/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T20:17:12.740000
2 posts
CVE-2026-16098 (CRITICAL): ProSolution WP Client <=2.0.10 lets unauthenticated attackers upload dangerous files via nonce leak, leading to remote code execution. Restrict plugin use & monitor for patches. https://radar.offseq.com/threat/cve-2026-16098-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-prosolution-prosolution-wp-b1b65fccc57ffd67 #OffSeq #WordPress #CVE202616098 #Infosec
##🔴 CVE-2026-16098 - Critical (9.8)
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Dispo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T19:16:52.650000
2 posts
Nvidia has new advisories addressing two vulnerabilities:
- NVIDIA Cumulus Linux and NVOS - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5817
- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630
NVIDIA Triton Inference Server - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5865 #Nvidia #infosec #vulnerability #Linux
##Nvidia has new advisories addressing two vulnerabilities:
- NVIDIA Cumulus Linux and NVOS - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5817
- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630
NVIDIA Triton Inference Server - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5865 #Nvidia #infosec #vulnerability #Linux
##updated 2026-08-18T19:16:51.740000
4 posts
🟠 CVE-2026-47628 - High (7.5)
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47628/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Nvidia has new advisories addressing two vulnerabilities:
- NVIDIA Cumulus Linux and NVOS - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5817
- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630
NVIDIA Triton Inference Server - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5865 #Nvidia #infosec #vulnerability #Linux
##🟠 CVE-2026-47628 - High (7.5)
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47628/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Nvidia has new advisories addressing two vulnerabilities:
- NVIDIA Cumulus Linux and NVOS - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5817
- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630
NVIDIA Triton Inference Server - August 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5865 #Nvidia #infosec #vulnerability #Linux
##updated 2026-08-18T18:32:52
6 posts
2 repos
CISA Sounds the Alarm on Critical VMware vCenter Flaw: Active Exploitation Puts Enterprise Virtual Infrastructure at Risk
A New Warning for VMware Administrators A critical security vulnerability in VMware vCenter has become an urgent concern for organizations running virtualized infrastructure. Tracked as CVE-2026-59310, the flaw is a directory traversal vulnerability in the vCenter Syslog server that can ultimately allow a network-accessible attacker to execute…
##⚠️ CRITICAL: ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Three critical vulnerabilities are under active exploitation: VMware vCenter (CVE-2026-59310) by China-nexus APT for potential ransomware deployment, Windows 0-day (CVE-2026-68820) by Lazarus Group targeting defense contractors with backdoors, and macOS flaw (CVE-2026-65400) distributing crypto min…
🤖 AI generated summary
##📢 Exploitation active de CVE-2026-59310 : 361 victimes dans 47 pays via VMware vCenter
Cet article documente une campagne d'exploitation active découverte lors d'un engagement de réponse à incident. La source est le blog Medium officiel de QUIRSO. CVE-2026-59310 est une vulnérabilité critique de type directory traversal affectant le serveur…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-18-exploitation-active-de-cve-2026-59310-361-victimes-dans-47-pays-via-vmware-vcenter/
🌐 source : https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff
🟢 vérification factuelle haute
#VMwareVCenter #ExploitationActive #Cyberveille
⚠️ CRITICAL: ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Three critical vulnerabilities are under active exploitation: VMware vCenter (CVE-2026-59310) by China-nexus APT for potential ransomware deployment, Windows 0-day (CVE-2026-68820) by Lazarus Group targeting defense contractors with backdoors, and macOS flaw (CVE-2026-65400) distributing crypto min…
🤖 AI generated summary
##vCenter Flaw Exploited Just Five Days After Disclosure https://www.infosecurity-magazine.com/news/vcenter-cve-2026-59310-exploited/
##2026-W33 — Weekly Threat Roundup
🔥 VMware vCenter RCE (CVE-2026-59310) under active APT exploitation across 47 countries, patch and hunt for persistence now.
🤖 Near-autonomous AI cyberattack observed against Taiwan's government, adapting mid-operation without human direction.
💀 Lazarus Group's Operation Dream Job exploits Windo…
https://threatnoir.com/weekly/2026-w33
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##updated 2026-08-18T18:32:11
2 posts
🔴 CVE-2026-75130 - Critical (9)
Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75130/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75130 - Critical (9)
Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75130/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T18:31:53
1 posts
SQL Injection flaw (CVE-2026-67854) in Qcms v6.0.6 rated CRITICAL: remote code execution risk. No official patch. Restrict access & monitor for injection attempts. Details: https://radar.offseq.com/threat/sql-injection-vulnerability-in-qcms-v606-allows-a-remote-attacker-to-execute-arbitrary-code-cve-2026-3286c90b2be69269 #OffSeq #SQLInjection #Vulnerability #Qcms #InfoSec
##updated 2026-08-18T18:31:47
17 posts
1 repos
Attackers are exploiting CVE-2026-65400, a critical macOS Screen Sharing auth bypass, to gain root access and deploy Monero miners on Macs with exposed port 5900.
##⚪️ Hackers Exploit macOS Screen Sharing Vulnerability to Install Crypto Miners
🗨️ The Netherlands’ National Cyber Security Centre (NCSC) has warned that attackers have begun exploiting the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. The flaw allows authentication to be bypassed, granting access to a Mac without a password, and is already…
##⚠️ CRITICAL: ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Three critical vulnerabilities are under active exploitation: VMware vCenter (CVE-2026-59310) by China-nexus APT for potential ransomware deployment, Windows 0-day (CVE-2026-68820) by Lazarus Group targeting defense contractors with backdoors, and macOS flaw (CVE-2026-65400) distributing crypto min…
🤖 AI generated summary
##Apple aktualisiert allerhand 2026-08
Wer jetzt denkt "ja klar, Apples Flickentag (gestern, 17.8.) bringt die Updates", irrt. Zumindest ist das nur die halbe Wahrheit. Apple hat nämlich bereits am 6.8. Updates für die drei noch gepflegten Versionen von macOS veröffentlicht (Sonoma 14.8.9; Sequoia 15.7.9; Tahoe 26.6.1). Diese schließen die Sicherheitslücke CVE-2026-65400 in der Funktion Screen Sharing (Bildschirmfreigabe für Fernzugriff) von macOS. Die ursprünglich mit dem Risiko 7,1 (von 10) bewertete Lücke wurde gerade auf 9,8 hoch gestuft, da inzwischen ein Exploit öffentlich verfügbar ist und die Lücke aktiv für Angriffe ausgenutzt wird. ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/08/18/apple-aktualisiert-allerhand-2026-08/
#apple #browser #exploits #ios #macos #sicherheit #UnplugApple #UnplugTrump #webkit
##Attackers are exploiting CVE-2026-65400, a critical macOS Screen Sharing auth bypass, to gain root access and deploy Monero miners on Macs with exposed port 5900.
##⚪️ Hackers Exploit macOS Screen Sharing Vulnerability to Install Crypto Miners
🗨️ The Netherlands’ National Cyber Security Centre (NCSC) has warned that attackers have begun exploiting the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. The flaw allows authentication to be bypassed, granting access to a Mac without a password, and is already…
##⚠️ CRITICAL: ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Three critical vulnerabilities are under active exploitation: VMware vCenter (CVE-2026-59310) by China-nexus APT for potential ransomware deployment, Windows 0-day (CVE-2026-68820) by Lazarus Group targeting defense contractors with backdoors, and macOS flaw (CVE-2026-65400) distributing crypto min…
🤖 AI generated summary
##An AI agent built a working exploit for this macOS flaw in four hours
https://thenextweb.com/news/macos-screen-sharing-flaw-cve-2026-65400-monero-miner?utm_source=flipboard&utm_medium=activitypub
Posted into Technology (UK Edition) @technology-uk-edition-FlipboardUK
##An AI agent built a working exploit for this macOS flaw in four hours
https://thenextweb.com/news/macos-screen-sharing-flaw-cve-2026-65400-monero-miner?utm_source=flipboard&utm_medium=activitypub
Posted into TNW - All Stories @tnw-all-stories-thenextweb
##Here's a summary of the latest geopolitical, technology, and cybersecurity news from the last 24-48 hours:
Cybersecurity: Apple patched a critical macOS Screen Sharing vulnerability (CVE-2026-65400) and issued mercenary spyware alerts across 110 countries. Microsoft's August Patch Tuesday fixed 421 vulnerabilities, including an actively exploited Windows zero-day (CVE-2026-68820). France reported a Bloctel data leak exposing three million phone numbers and a DGFiP tax data leak.
Technology: Massive tech layoffs continue in 2026, surpassing last year's totals, as companies shift to "AI-first" strategies; AI "inference" spending now exceeds "training". Elon Musk's SpaceX committed exclusively to NVIDIA GPUs, forming a major AI partnership.
Geopolitics: US-Iran tensions remain high over the Strait of Hormuz, with new threats and defense contracts emerging. Ukraine faces critical Patriot interceptor shortages, threatening its winter air defense.
##⚠️ Important security update for Mac users:
A vulnerability in macOS Screen Sharing (CVE-2026-65400) is being actively exploited.
If you use Screens or another VNC client app to remotely access a Mac, we strongly recommend updating macOS as soon as possible.
##Attackers actively exploit the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. Discover how to protect your Mac from root access and cryptominers.
#macOS #CVE202665400 #ScreenSharing #Vulnerability #Cybersecurity
##CVE-2026-65400 (HIGH) - macOS Screen Sharing vuln lets remote attackers bypass auth and gain root. Active exploitation seen, mainly on systems with port 5900 open. Patch Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9. https://radar.offseq.com/threat/recent-macos-screen-sharing-vulnerability-exploited-in-attacks-6aa0fe0406c5717d #OffSeq #macOS #infosec #vuln
##🏆 New Achievement! Screen Sharing Is Caring (About My Monero Wallet)!
Allow me to monologue, as any proper villain must. CVE-2026-65400 — a gorgeous authentication bypass in macOS Screen Sharing — handed attackers root access through port 5900, wide open to the internet like a velvet rope with no bouncer. Apple patched it August 6 in macOS Tahoe 26.6.1. You simply... did not apply it. Delicious. (1/2)
##⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…
🤖 AI generated summary
##Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks
The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
#hardware
https://www.tomshardware.com/tech-industry/cyber-security/macos-screen-sharing-flaw-exploited-to-root-macs-and-plant-monero-miners
Apple Patches Actively Exploited macOS Screen Sharing Vulnerability Used in Crypto Mining Attacks
Apple patched a macOS Screen Sharing vulnerability (CVE-2026-65400) that allows remote attackers to bypass authentication and gain root access. Attackers are actively exploiting the flaw to install Monero crypto miners on systems with port 5900 exposed to the internet.
**If you use a Mac, update macOS now to Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 to fix CVE-2026-65400, which attackers are already using to take full control of Macs without a password. Also turn off Screen Sharing when you don't need it and make sure port 5900 is not reachable from the internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/apple-patches-actively-exploited-macos-screen-sharing-vulnerability-used-in-crypto-mining-attacks-n-5-j-v-1/gD2P6Ple2L
updated 2026-08-18T18:31:46
4 posts
2 repos
🚨 NEW CISA KEV: CVE-2026-33824. Active RCE weaponization targeting Microsoft Internet Key Exchange (IKE) via double-free memory corruption. Unauthenticated access possible. Get the full T-Suite brief & custom CrowdStrike detection queries to secure your Precinct Hybrid architecture.
Link below 👇
https://thecybermind.co/jily
Looks like CVE-2026-33824 was added to KEV. Keep in mind that this service isn't just for IPSec VPNs. It's also used with some Windows Firewall policies so check your internal systems for listeners, not just public-facing systems.
An unauthenticated attacker could send specially crafted packets to a Windows machine with Internet Key Exchange (IKE) version 2 enabled, which could enable remote code execution.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824
##🚨 NEW CISA KEV: CVE-2026-33824. Active RCE weaponization targeting Microsoft Internet Key Exchange (IKE) via double-free memory corruption. Unauthenticated access possible. Get the full T-Suite brief & custom CrowdStrike detection queries to secure your Precinct Hybrid architecture.
Link below 👇
https://thecybermind.co/jily
Looks like CVE-2026-33824 was added to KEV. Keep in mind that this service isn't just for IPSec VPNs. It's also used with some Windows Firewall policies so check your internal systems for listeners, not just public-facing systems.
An unauthenticated attacker could send specially crafted packets to a Windows machine with Internet Key Exchange (IKE) version 2 enabled, which could enable remote code execution.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824
##updated 2026-08-18T16:18:24.590000
1 posts
🟠 CVE-2026-9816 - High (8.3)
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board adm...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9816/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T16:18:23.840000
2 posts
🟠 CVE-2026-75914 - High (7.5)
CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image extensions to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75914/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75914 - High (7.5)
CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image extensions to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75914/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T16:18:20.127000
1 posts
🟠 CVE-2026-75103 - High (8.8)
Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change admi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75103/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T16:17:02.083000
8 posts
2 repos
📢 [VULN] 600 000 sites WordPress menacés par une faille critique dans Forminator Forms CVE-2026-15748
Une faille critique touche Forminator Forms, une extension WordPress utilisée sur plus de 600 000 sites. Référencée CVE-2026-15748, la vulnérabilité obtient un score de 9,8/10 et peut permettre à un attaquant non authentifié d’exécuter du code sur un serveur vulnérable.
🔗 https://www.cyberattaque.org/600-000-sites-wordpress-menaces-par-une-faille-critique-dans-forminator-forms/
💬 discussion : https://infosec.pub/post/51136301
#Vulnérabilité #CVE #Cyberveille
https://thecybersecguru.com/news/cve-2026-15748-forminator-rce-cve-2026-15826-user-profile-builder/
##CVE-2026-15748, scored 9.8 out of 10, allows unauthenticated attackers to manipulate Select field configurations and bypass the plugin's blocklist entirely, uploading executable files through handle_file_upload. Defiant confirms this is several weaknesses working together in a kind of tragic team-building exercise.
Remote code execution is not a learning objective we endorse. Please update Forminator Forms to version 1.56.2 or later immediately. (2/3)
##CVE-2026-15748, scored 9.8 out of 10, allows unauthenticated attackers to manipulate Select field configurations and bypass the plugin's blocklist entirely, uploading executable files through handle_file_upload. Defiant confirms this is several weaknesses working together in a kind of tragic team-building exercise.
Remote code execution is not a learning objective we endorse. Please update Forminator Forms to version 1.56.2 or later immediately. (2/3)
##CVE-2026-15748 (CRITICAL, CVSS 9.8): wpmudev Forminator Forms for WordPress up to 1.56.1 lets unauthenticated attackers upload dangerous files via handle_file_upload, risking remote code execution. Patch urgently: https://radar.offseq.com/threat/cve-2026-15748-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-wpmudev-forminator-forms-087a3235e4aa61cd #OffSeq #WordPress #Vuln
##「Forminator WordPressの脆弱性により、悪意のあるPHPファイルのアップロードを介して認証なしのリモートコード実行が可能になる 」: #TheHackerNews
「0万件以上のインストール実績を持つWordPressプラグイン「Forminator Forms」に、重大なセキュリティ上の欠陥が発見された。この欠陥を悪用すれば、脆弱性のあるサイトで任意のコードを実行できる可能性がある。
CVE-2026-15748 として追跡されているこの脆弱性は 、CVSSスコアリングシステムで10点満点中9.8点と評価されている。この脆弱性は、「daroo」というオンライン上のニックネームを持つセキュリティ研究者によって発見され、報告された。
https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html
##CVE-2026-15748 (CVSS 9.8): Forminator Flaw Enables Pre-Auth RCE
##Two critical flaws disclosed in WordPress plugins: Forminator Forms (CVE-2026-15748) allows unauthenticated PHP file upload leading to RCE, and User Profile Builder (CVE-2026-15826) lets unauthenticated attackers authenticate as the site admin. Both can result in full site compromise.
#WordPressSecurity #CVE #RemoteCodeExecution #InfoSec
https://cyberworldops.eu/en/two-critical-wordpress-plugin-vulnerabilities-could-lead-to-full-site
##updated 2026-08-18T15:32:27
3 posts
2 repos
Microsoft working on Defender patch for ShieldBreak zero-day
Microsoft는 Microsoft Defender의 Malware Protection Engine에서 발생하는 로컬 권한 상승 제로데이 ‘ShieldBreak’(CVE-2026-69414)을 추적하고 패치를 개발 중이다. 공개된 PoC는 제한된 권한의 로컬 공격자가 Defender가 활성화된 최신 패치 상태의 Windows 11 및 Windows Server 환경에서 SYSTEM 권한을 얻을 수 있음을 보이며, 분석가가 동작을 확인했다. 이 취약점은 앞서 공개된 RoguePl...
##ShieldBreak : cette faille zero-day menace Windows, Microsoft prépare un patch https://www.it-connect.fr/shieldbreak-zero-day-defender-cve-2026-69414/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #Windows
##ShieldBreak appears to be CVE-2026-69414 ht @wdormann https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
updated 2026-08-18T15:32:02
1 posts
CVE-2026-74015 - Unauthenticated SQLi in Readabler < 2.0.18. CVSS 9.3. No patch yet. Disable or isolate now. #CVE #infosec #SQLi
##updated 2026-08-18T15:31:56
2 posts
TRENDnet TEW-WLC100P v12.07b01 impacted by CRITICAL stack-based buffer overflow (CVE-2026-75783, CVSS 9.4) in DHCP blobmsg Handler. Exploit needs local network access. No patch yet — restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-75783-stack-based-buffer-overflow-in-trendnet-tew-wlc100p-e172681d65344cad #OffSeq #CVE202675783 #Vuln #IoTSecurity
##TRENDnet TEW-WLC100P v12.07b01 impacted by CRITICAL stack-based buffer overflow (CVE-2026-75783, CVSS 9.4) in DHCP blobmsg Handler. Exploit needs local network access. No patch yet — restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-75783-stack-based-buffer-overflow-in-trendnet-tew-wlc100p-e172681d65344cad #OffSeq #CVE202675783 #Vuln #IoTSecurity
##updated 2026-08-18T15:31:45
2 posts
Microsoft has an advisory for a new critical Copilot vulnerability.
CRITICAL: CVE-2026-24301: Microsoft Copilot Information Disclosure Vulnerability https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24301
More information:
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') https://cwe.mitre.org/data/definitions/77.html #infosec #Microsoft #Copilot #vulnerability
##Microsoft has an advisory for a new critical Copilot vulnerability.
CRITICAL: CVE-2026-24301: Microsoft Copilot Information Disclosure Vulnerability https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24301
More information:
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') https://cwe.mitre.org/data/definitions/77.html #infosec #Microsoft #Copilot #vulnerability
##updated 2026-08-18T15:17:12.947000
2 posts
CVE-2026-75094: CRITICAL OS command injection in COMFAST CF-N1-S v2.6.0.1. Exploit code is public, no official patch. Restrict access to /cgi-bin/mbox-config to reduce risk. Details: https://radar.offseq.com/threat/cve-2026-75094-os-command-injection-in-comfast-cf-n1-s-07737fa4c8cac0ee #OffSeq #CVE #IoT #Security
##🔴 CVE-2026-75094 - Critical (9.1)
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injectio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75094/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T15:04:46.610000
2 posts
BeyondTrust patched two high-severity EPM flaws (CVE-2026-40144, CVE-2026-40145) that allow local privilege escalation on Windows. Update to 26.1.2.
#BeyondTrust #CVE202640144 #PrivilegeEscalation #Windows #EndpointSecurity #InfoSec
##BeyondTrust patched two high-severity EPM flaws (CVE-2026-40144, CVE-2026-40145) that allow local privilege escalation on Windows. Update to 26.1.2.
#BeyondTrust #CVE202640144 #PrivilegeEscalation #Windows #EndpointSecurity #InfoSec
##updated 2026-08-18T14:57:10.630000
14 posts
3 repos
https://github.com/HORKimhab/CVE-2026-19650-CVE-2026-19478
Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects
GitLab has patched two security flaws, including CVE-2026-19478, a critical code injection vulnerability that could allow unauthenticated attackers...
🔗️ [Thecyberexpress] https://link.is.it/otTWyh
##GitLab CVE-2026-19478: GraphQL authorization bypass
본문은 자체 운영 GitLab의 GraphQL directive 결함(CVE-2026-19478)이 인증 없이 공개 프로젝트와 사용자 데이터를 변경·삭제할 수 있는 CVSS 9.4급 취약점이라고 주장합니다. 영향 범위로 GitLab 18.2~18.11.10, 19.0~19.0.7, 19.1~19.1.5, 19.2~19.2.3을 제시하며, 각각 18.11.11·19.0.8·19.1.6·19.2.4 이상으로 즉시 업그레이드할 것을 권고합니다. 함께 수정됐다는 CVE-2026-19650은 GraphQL multiplex handler의 CSRF 결함으로, 인증 사용자의 상호작용이 필요...
https://techupdate24.com/gitlab-cve-2026-19478-graphql-flaw/
##⚠️ CRITICAL: GitLab Patches Critical Code Injection Vulnerability
GitLab released patches for a critical unauthenticated code injection vulnerability (CVE-2026-19478, CVSS 9.4) in GraphQL directives that allows attackers to modify or delete user data and public projects. A secondary CSRF flaw (CVE-2026-19650) affects the GraphQL multiplex query handler. Versions…
🤖 AI generated summary
##CVE-2026-19478 - Critical unauthenticated data tampering in GitLab CE/EE. Remote modify/delete of public projects via GraphQL. CVSS 9.4. No patch yet. Harden access & monitor. #CVE #GitLab #infosec
##📢 GitLab : patch critique corrigeant une injection de code via GraphQL (CVE-2026-19478, CVSS 9.4)
Le 17 août 2026, GitLab a publié des versions correctives pour ses éditions Community (CE) et Enterprise (EE) : 19.2.4, 19.1.6, 19.0.8 et 18.11.11. Ces versions constituent un patch critique ad-hoc destiné à corriger des vulnérabilités de haute et critique…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-18-gitlab-patch-critique-corrigeant-une-injection-de-code-via-graphql-cve-2026-19478-cvss-9-4/
🌐 source : https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/
🟡 vérification factuelle moyenne
#GitLab #GraphQL #Cyberveille
GitLab Issues Emergency Patch for Critical GraphQL Flaw Allowing Remote Project Deletion
GitLab issued an emergency security update to fix a critical GraphQL code injection vulnerability (CVE-2026-19478) that allows unauthenticated attackers to remotely delete or modify public projects and user data.
**If you run a self-managed GitLab server (version 18.2 through 19.2.3), update it ASAP to 19.2.4, 19.1.6, 19.0.8, or 18.11.11. The patch is quick and won't take your system offline. Before you patch, check your logs for unusual GraphQL activity so you know nobody has already deleted or altered your projects or user data.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/gitlab-issues-emergency-patch-for-critical-graphql-flaw-allowing-remote-project-deletion-k-u-c-h-x/gD2P6Ple2L
Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects
GitLab has patched two security flaws, including CVE-2026-19478, a critical code injection vulnerability that could allow unauthenticated attackers...
🔗️ [Thecyberexpress] https://link.is.it/otTWyh
##⚠️ CRITICAL: GitLab Patches Critical Code Injection Vulnerability
GitLab released patches for a critical unauthenticated code injection vulnerability (CVE-2026-19478, CVSS 9.4) in GraphQL directives that allows attackers to modify or delete user data and public projects. A secondary CSRF flaw (CVE-2026-19650) affects the GraphQL multiplex query handler. Versions…
🤖 AI generated summary
##GitLab Issues Emergency Patch for Critical GraphQL Flaw Allowing Remote Project Deletion
GitLab issued an emergency security update to fix a critical GraphQL code injection vulnerability (CVE-2026-19478) that allows unauthenticated attackers to remotely delete or modify public projects and user data.
**If you run a self-managed GitLab server (version 18.2 through 19.2.3), update it ASAP to 19.2.4, 19.1.6, 19.0.8, or 18.11.11. The patch is quick and won't take your system offline. Before you patch, check your logs for unusual GraphQL activity so you know nobody has already deleted or altered your projects or user data.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/gitlab-issues-emergency-patch-for-critical-graphql-flaw-allowing-remote-project-deletion-k-u-c-h-x/gD2P6Ple2L
CRITICAL: GitLab CE/EE (v18.2+ to 19.2.4) patched CVE-2026-19478, a code injection bug allowing unauthenticated data modification/deletion via GraphQL. CSRF (CVE-2026-19650) also fixed. Upgrade to safe versions ASAP. https://radar.offseq.com/threat/gitlab-patches-critical-code-injection-vulnerability-ce00fcde61cd1cd5 #OffSeq #GitLab #Infosec #CVE
##GitLab addressed a critical GraphQL flaw, CVE-2026-19478, with a CVSS score of 9.4, allowing attackers to modify or delete projects in GitLab CE and EE. This poses serious risks to code repositories and requires immediate patching to prevent exploitation. #GitLabCVE #GraphQLFlaw #CyberSecurityUpdate #InfoSecCritical
https://cyberworldops.eu/en/gitlab-fixes-critical-graphql-flaw-that-could-modify-or-delete
##🏆 New Achievement! Delete Yourself From This Industry!
Welcome to Module 9: GraphQL Directive Hygiene. Today's learning objective: CVE-2026-19478, a CVSS 9.4 flaw in GitLab Community and Enterprise Edition that allows a completely unauthenticated attacker — no credentials, no victim interaction, no participation trophy — to remotely modify or delete public projects and user data. (1/2)
##GitLab patched CVE-2026-19478, a CVSS 9.4 GraphQL code injection flaw letting unauthenticated users alter or delete project data.
#CVE202619478 #GitLab #CodeInjection #GraphQL #CVE202619650 #PatchNow
##Unauthenticated remote code execution in GitLab.
Update to 19.2.4 / 19.1.6 / 19.0.8 / 18.11.11!
updated 2026-08-18T14:57:10.630000
4 posts
1 repos
GitLab CVE-2026-19478: GraphQL authorization bypass
본문은 자체 운영 GitLab의 GraphQL directive 결함(CVE-2026-19478)이 인증 없이 공개 프로젝트와 사용자 데이터를 변경·삭제할 수 있는 CVSS 9.4급 취약점이라고 주장합니다. 영향 범위로 GitLab 18.2~18.11.10, 19.0~19.0.7, 19.1~19.1.5, 19.2~19.2.3을 제시하며, 각각 18.11.11·19.0.8·19.1.6·19.2.4 이상으로 즉시 업그레이드할 것을 권고합니다. 함께 수정됐다는 CVE-2026-19650은 GraphQL multiplex handler의 CSRF 결함으로, 인증 사용자의 상호작용이 필요...
https://techupdate24.com/gitlab-cve-2026-19478-graphql-flaw/
##⚠️ CRITICAL: GitLab Patches Critical Code Injection Vulnerability
GitLab released patches for a critical unauthenticated code injection vulnerability (CVE-2026-19478, CVSS 9.4) in GraphQL directives that allows attackers to modify or delete user data and public projects. A secondary CSRF flaw (CVE-2026-19650) affects the GraphQL multiplex query handler. Versions…
🤖 AI generated summary
##⚠️ CRITICAL: GitLab Patches Critical Code Injection Vulnerability
GitLab released patches for a critical unauthenticated code injection vulnerability (CVE-2026-19478, CVSS 9.4) in GraphQL directives that allows attackers to modify or delete user data and public projects. A secondary CSRF flaw (CVE-2026-19650) affects the GraphQL multiplex query handler. Versions…
🤖 AI generated summary
##CRITICAL: GitLab CE/EE (v18.2+ to 19.2.4) patched CVE-2026-19478, a code injection bug allowing unauthenticated data modification/deletion via GraphQL. CSRF (CVE-2026-19650) also fixed. Upgrade to safe versions ASAP. https://radar.offseq.com/threat/gitlab-patches-critical-code-injection-vulnerability-ce00fcde61cd1cd5 #OffSeq #GitLab #Infosec #CVE
##updated 2026-08-18T14:18:12.260000
2 posts
🔴 CVE-2026-75852 - Critical (9.8)
ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75852/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75852 - Critical (9.8)
ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75852/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T14:18:08.373000
1 posts
CVE-2026-75081 (MEDIUM): Webkul Bagisto ≤2.4.4 has a vuln in /customer/account/rma/store. Public exploit exists — remote attackers may abuse RMA workflow. Monitor for suspicious RMA activity. https://radar.offseq.com/threat/cve-2026-75081-enforcement-of-behavioral-workflow-in-webkul-bagisto-ee135525efc80a57 #OffSeq #Bagisto #Vuln #Infosec
##updated 2026-08-18T14:16:59.543000
2 posts
CVE-2026-19959: CRITICAL stack buffer overflow in Edimax EW-7478APC v1.04 (CVSS 9.4). Remote code execution possible. Public exploit out, no fix from vendor. Restrict access or replace device. https://radar.offseq.com/threat/cve-2026-19959-stack-based-buffer-overflow-in-edimax-ew-7478apc-5dd669bf84d8d7ec #OffSeq #CVE #IoTSecurity #infosec
##🔴 CVE-2026-19959 - Critical (9.9)
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19959/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T12:31:30
2 posts
🟠 CVE-2026-75853 - High (8.8)
ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and never binds ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75853/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75853 - High (8.8)
ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and never binds ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75853/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T12:31:30
2 posts
🔴 CVE-2026-75851 - Critical (9.9)
ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on an asyn...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75851/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75851 - Critical (9.9)
ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on an asyn...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75851/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T12:31:30
2 posts
CVE-2026-75854: ArcadeDB <26.8.1 has a CRITICAL Redis plugin vuln (CVSS 9.3). Missing auth lets attackers run any command & access/modify/delete all DB data. Restrict Redis port access & monitor for fixes. https://radar.offseq.com/threat/cve-2026-75854-missing-authentication-for-critical-function-in-arcadedata-arcadedb-033f47986cfb9941 #OffSeq #Vuln #ArcadeDB #Infosec
##CVE-2026-75854: ArcadeDB <26.8.1 has a CRITICAL Redis plugin vuln (CVSS 9.3). Missing auth lets attackers run any command & access/modify/delete all DB data. Restrict Redis port access & monitor for fixes. https://radar.offseq.com/threat/cve-2026-75854-missing-authentication-for-critical-function-in-arcadedata-arcadedb-033f47986cfb9941 #OffSeq #Vuln #ArcadeDB #Infosec
##updated 2026-08-18T04:16:47.410000
1 posts
🟠 CVE-2026-75056 - High (7.8)
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T04:16:47.170000
1 posts
JetBrains patched CVE-2026-75045, a critical YouTrack flaw letting an unauthenticated attacker download database backups.
#CVE202675045 #YouTrack #JetBrains #DatabaseBackup #DataBreach #PatchNow
##updated 2026-08-18T03:31:11
2 posts
🟠 CVE-2026-11801 - High (7.5)
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This make...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11801/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##WPAdverts – Classifieds Plugin <=2.3.2 hit by HIGH severity CWE-862 auth bypass (CVE-2026-11801). Unauthenticated users can access internal config data via REST API. Restrict endpoints & monitor for fixes. https://radar.offseq.com/threat/cve-2026-11801-cwe-862-missing-authorization-in-gwin-wpadverts-classifieds-plugin-89cace2672af27dd #OffSeq #WordPress #Vulnerability
##updated 2026-08-18T02:17:28.083000
1 posts
CVE-2026-72831 - Auth bypass in Grav Flex Objects plugin ≤1.4.6. Improper authorization lets low-priv users exploit generic /api/v1 endpoint. CVSS 8.8. Exploit risk high. Update immediately. #CVE #GravCMS #infosec
##updated 2026-08-17T21:58:44
1 posts
🟠 CVE-2026-56677 - High (8.6)
9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js without restri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56677/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:35
1 posts
🟠 CVE-2026-75482 - High (7.5)
SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the buil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:30
1 posts
CVE-2026-68005 DoS in ACME mini_httpd 1.30. Remote HTTP header parser crash. CVSS 7.5. Unpatched. Update immediately. #CVE #infosec #ACME
##updated 2026-08-17T21:31:30
2 posts
CVE-2026-74234 - Critical XSS in Legora. Mermaid block + JS front-matter triggers eval() before sanitization. CVSS 7.7. Arbitrary JS in victim's browser. Patch unknown. Update immediately. #CVE #Legora #infosec
##🟠 CVE-2026-74234 - High (7.7)
Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter directive...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74234/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:30
1 posts
🔴 CVE-2026-75106 - Critical (9.1)
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission da...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:30
1 posts
🟠 CVE-2026-75105 - High (7.5)
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75105/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:30
1 posts
🔴 CVE-2026-71472 - Critical (9.1)
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_M...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71472/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:30
1 posts
🟠 CVE-2026-70495 - High (8.8)
A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70495/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:30
1 posts
🔴 CVE-2026-66792 - Critical (9.9)
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:30
1 posts
🟠 CVE-2026-74238 - High (7.5)
TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap mem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74238/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:27
1 posts
🟠 CVE-2026-75481 - High (8.8)
SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75481/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:27
1 posts
🟠 CVE-2026-75479 - High (7.5)
JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75479/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:27
1 posts
🔴 CVE-2026-75110 - Critical (9.8)
MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the is_internal_request() check ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75110/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:16:50.193000
1 posts
🟠 CVE-2026-75111 - High (7.5)
Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75111/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T20:16:43.153000
1 posts
🟠 CVE-2026-45698 - High (7.5)
Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the deletedir() function of Netatalk's afpd daemon due to an integer underflow in the c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T20:16:42.157000
1 posts
CVE-2026-19714 (CRITICAL): Simple JWT Login <3.6.8 for WordPress fails to validate Google token audiences. Sites with Google sign-in enabled risk admin impersonation & takeover. Disable Google sign-in or update ASAP. https://radar.offseq.com/threat/cve-2026-19714-cwe-287-improper-authentication-in-simple-jwt-login-2d90d2253c004239 #OffSeq #WordPress #CVE202619714
##updated 2026-08-17T19:16:28.953000
2 posts
A critical IBM remote code execution flaw (CVE-2026-17482, CVSS 9.8) allows attackers to compromise workstations. Discover how to apply the software patch.
#IBM #CyberSecurity #CVE202617482 #RCE #VulnerabilityManagement
##A critical IBM remote code execution flaw (CVE-2026-17482, CVSS 9.8) allows attackers to compromise workstations. Discover how to apply the software patch.
#IBM #CyberSecurity #CVE202617482 #RCE #VulnerabilityManagement
##updated 2026-08-17T19:06:52.793000
3 posts
Apache HttpClient TLS Flaw Could Let Attackers Impersonate Trusted Servers in MITM Attacks + Video
Introduction: When HTTPS Looks Secure but the Hostname Check Quietly Fails HTTPS is built around a simple promise: when an application connects to api.example.com, it should be able to confirm that the server on the other end is actually authorized to represent api.example.com. That trust relationship is now under scrutiny after the disclosure of CVE-2026-71290, a serious…
##CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1)
##CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1)
##updated 2026-08-17T18:31:28
1 posts
🟠 CVE-2026-75060 - High (8.4)
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75060/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T18:31:22
2 posts
BeyondTrust patched two high-severity EPM flaws (CVE-2026-40144, CVE-2026-40145) that allow local privilege escalation on Windows. Update to 26.1.2.
#BeyondTrust #CVE202640144 #PrivilegeEscalation #Windows #EndpointSecurity #InfoSec
##BeyondTrust patched two high-severity EPM flaws (CVE-2026-40144, CVE-2026-40145) that allow local privilege escalation on Windows. Update to 26.1.2.
#BeyondTrust #CVE202640144 #PrivilegeEscalation #Windows #EndpointSecurity #InfoSec
##updated 2026-08-17T18:31:19
1 posts
🟠 CVE-2026-75051 - High (8.1)
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75051/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T18:18:15.150000
1 posts
🟠 CVE-2026-74791 - High (8.6)
Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to acce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74791/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T16:36:14
1 posts
CVE-2026-71479, an integer overflow in New API billing, is exploited in the wild to inflate user account balances.
#CVE202671479 #IntegerOverflow #NewAPI #ExploitedInTheWild #AIGateway #BillingFraud
##updated 2026-08-17T16:17:48.827000
1 posts
🟠 CVE-2026-74795 - High (7.5)
Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74795/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T16:17:48.590000
1 posts
🟠 CVE-2026-74789 - High (7.5)
Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T16:17:47
1 posts
🟠 CVE-2026-73060 - High (7.5)
Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73060/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T16:16:53.947000
2 posts
🔴 CVE-2026-19961 - Critical (9.9)
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19961/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-19961: CRITICAL buffer overflow in Edimax EW-7478APC v1.04 via /goform/formWlSiteSurvey (selSSID). Remote code execution is possible; no patch, public exploit exists. Isolate affected devices. https://radar.offseq.com/threat/cve-2026-19961-buffer-overflow-in-edimax-ew-7478apc-657492e4d05158fa #OffSeq #CVE202619961 #IoTSecurity
##updated 2026-08-17T16:16:50.930000
1 posts
🟠 CVE-2026-16099 - High (8.8)
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authentic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T16:16:50.140000
3 posts
1 repos
https://thecybersecguru.com/news/cve-2026-15748-forminator-rce-cve-2026-15826-user-profile-builder/
##Critical Authentication Bypass Reported in User Profile Builder
Cozmoslabs patched a critical authentication bypass vulnerability (CVE-2026-15826) in the User Profile Builder WordPress plugin that allowed unauthenticated attackers to gain full administrative control.
**If you run the User Profile Builder plugin on WordPress, update it to version 3.16.5 or later ASAP. If you can't update immediately, turn off the "Automatically Log In after Registration" setting in the plugin options, and check whether your admin account is user ID 1 and if possible switch to a different admin account.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-authentication-bypass-reported-in-user-profile-builder-p-k-x-p-g/gD2P6Ple2L
Two critical flaws disclosed in WordPress plugins: Forminator Forms (CVE-2026-15748) allows unauthenticated PHP file upload leading to RCE, and User Profile Builder (CVE-2026-15826) lets unauthenticated attackers authenticate as the site admin. Both can result in full site compromise.
#WordPressSecurity #CVE #RemoteCodeExecution #InfoSec
https://cyberworldops.eu/en/two-critical-wordpress-plugin-vulnerabilities-could-lead-to-full-site
##updated 2026-08-17T15:30:38
1 posts
CVE-2026-14564: CRITICAL vuln in Logsign SIEM (6.4.97 – <6.4.114) due to insufficiently protected credentials (CWE-522). High-priv users can retrieve sensitive data. Patch status unknown — restrict access & monitor vendor updates. https://radar.offseq.com/threat/cve-2026-14564-cwe-522-insufficiently-protected-credentials-in-innotim-software-telecommunications-and-42bf4f857150f859 #OffSeq #SIEM #Vuln
##updated 2026-08-17T15:16:58.230000
1 posts
CVE-2026-74843 (CRITICAL, CVSS 10.0) impacts Wavlink WN531P3 & WN535M1: stack buffer overflow in export_pingortrace.cgi enables remote, unauthenticated RCE. No patch. Restrict access & monitor activity. Exploit code public. https://radar.offseq.com/threat/cve-2026-74843-stack-based-buffer-overflow-in-wavlink-wn531p3-0ad150d2e4038bcd #OffSeq #CVE202674843 #IoTSecurity
##updated 2026-08-17T12:32:31
1 posts
CVE-2026-74889 - Critical crypto weakness in openssl_encrypt <1.4.0. HKDF with no salt/static info weakens key derivation, enabling multi-target attacks. CVSS 9.8. Update immediately. #CVE #cryptography #infosec
##updated 2026-08-17T12:32:26
1 posts
CVE-2026-74845 (HIGH, CVSS 8.7): 2100 Technology Official Document Management System lets authenticated attackers upload dangerous files — risk of code execution. No patch yet. Limit upload rights & monitor files. https://radar.offseq.com/threat/cve-2026-74845-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-2100-technology-official-1d9f0343bf21764a #OffSeq #vuln #infosec #CVE2026_74845
##updated 2026-08-17T09:30:29
1 posts
CVE-2026-15623: CRITICAL SQL Injection vuln (CVSS 9.4) in Google Cloud Google SecOps (Chronicle SOAR) <6.3.85. Auth attackers could run blind SQL queries. Google patched server-side — no customer action needed. https://radar.offseq.com/threat/cve-2026-15623-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-f5c28e40dedcd311 #OffSeq #GoogleCloud #Infosec
##updated 2026-08-17T06:19:07.453000
1 posts
Say what you will about 'branded' vulnerability disclosures, at least they tend to provide understandable information about the issue, which functionality it concerns, whether you might be affected, and often how to mitigate while waiting for the patch to propagate. As opposed to raw CVEs like https://www.cve.org/CVERecord?id=CVE-2026-72407
##updated 2026-08-17T03:30:28
1 posts
CVE-2026-50602: HIGH severity (CVSS 8.5) vuln in Acer Planet9 background service 🖥️. Incorrect permissions on SYSTEM-level executable allow local users to escalate privileges. Restrict permissions or disable service until patched. https://radar.offseq.com/threat/cve-2026-50602-cwe-732-incorrect-permission-assignment-for-critical-resource-in-acer-planet9-b9a1b490c423207e #OffSeq #vuln #Infosec
##updated 2026-08-16T19:17:24.183000
6 posts
2 repos
August 17-18, 2026:
**Geopolitical:** Saudi Arabia, Türkiye, and Pakistan formalized a strategic defense pact. Commercial tanker traffic in the Strait of Hormuz plummeted to near-zero following recent strikes and stalled US-Iran negotiations.
**Technology:** Nvidia plans significant AI data center investments for OpenAI. AI-driven tech layoffs have now surpassed 2025 totals. Google Cloud targets 2029 for post-quantum cryptographic readiness.
**Cybersecurity:** Major data breaches impacted RingCentral (1.6M users) and Poland's MyDr healthcare platform (19M citizens). Microsoft patched 421 vulnerabilities, including an actively exploited Windows zero-day by Lazarus Group (CVE-2026-68820).
##⚠️ CRITICAL: ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Three critical vulnerabilities are under active exploitation: VMware vCenter (CVE-2026-59310) by China-nexus APT for potential ransomware deployment, Windows 0-day (CVE-2026-68820) by Lazarus Group targeting defense contractors with backdoors, and macOS flaw (CVE-2026-65400) distributing crypto min…
🤖 AI generated summary
##August 17-18, 2026:
**Geopolitical:** Saudi Arabia, Türkiye, and Pakistan formalized a strategic defense pact. Commercial tanker traffic in the Strait of Hormuz plummeted to near-zero following recent strikes and stalled US-Iran negotiations.
**Technology:** Nvidia plans significant AI data center investments for OpenAI. AI-driven tech layoffs have now surpassed 2025 totals. Google Cloud targets 2029 for post-quantum cryptographic readiness.
**Cybersecurity:** Major data breaches impacted RingCentral (1.6M users) and Poland's MyDr healthcare platform (19M citizens). Microsoft patched 421 vulnerabilities, including an actively exploited Windows zero-day by Lazarus Group (CVE-2026-68820).
##⚠️ CRITICAL: ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Three critical vulnerabilities are under active exploitation: VMware vCenter (CVE-2026-59310) by China-nexus APT for potential ransomware deployment, Windows 0-day (CVE-2026-68820) by Lazarus Group targeting defense contractors with backdoors, and macOS flaw (CVE-2026-65400) distributing crypto min…
🤖 AI generated summary
##Here's a summary of the latest geopolitical, technology, and cybersecurity news from the last 24-48 hours:
Cybersecurity: Apple patched a critical macOS Screen Sharing vulnerability (CVE-2026-65400) and issued mercenary spyware alerts across 110 countries. Microsoft's August Patch Tuesday fixed 421 vulnerabilities, including an actively exploited Windows zero-day (CVE-2026-68820). France reported a Bloctel data leak exposing three million phone numbers and a DGFiP tax data leak.
Technology: Massive tech layoffs continue in 2026, surpassing last year's totals, as companies shift to "AI-first" strategies; AI "inference" spending now exceeds "training". Elon Musk's SpaceX committed exclusively to NVIDIA GPUs, forming a major AI partnership.
Geopolitics: US-Iran tensions remain high over the Strait of Hormuz, with new threats and defense contracts emerging. Ukraine faces critical Patriot interceptor shortages, threatening its winter air defense.
##Geopolitical tensions rise with a Middle East conflict stalemate and Israeli retaliatory strikes against Hezbollah in Lebanon. Ukraine's air defense faces threats amid Patriot interceptor depletion and drone attacks on Moscow.
In tech, NVIDIA and SpaceX have forged a significant AI partnership, with massive infrastructure spending projected. Cybersecurity sees the US allowing vetted private companies to conduct offensive cyber operations. Microsoft patched a critical, exploited Windows zero-day (CVE-2026-68820), and Cl0p ransomware leveraged a PTC Windchill flaw impacting nearly 50 firms.
##updated 2026-08-16T19:17:18.030000
1 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-16T15:30:38
1 posts
🟠 CVE-2026-74794 - High (7.5)
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74794/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:38
1 posts
🟠 CVE-2026-74792 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:33
2 posts
🔴 CVE-2026-73056 - Critical (9.8)
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 https://radar.offseq.com/threat/cve-2026-73056-improper-restriction-of-excessive-authentication-attempts-in-siyuan-note-siyuan-28d3540593a8ef28 #OffSeq #CVE202673056 #infosec
##updated 2026-08-16T15:30:33
1 posts
🟠 CVE-2026-74788 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to ....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74788/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:33
1 posts
🟠 CVE-2026-74783 - High (7.5)
Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:27
1 posts
🔴 CVE-2026-74790 - Critical (9.1)
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74790/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:26
1 posts
🟠 CVE-2026-73062 - High (7.5)
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73062/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:26
1 posts
🔴 CVE-2026-73061 - Critical (9.8)
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73061/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:26
1 posts
🟠 CVE-2026-74787 - High (7.5)
Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74787/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:25
1 posts
🟠 CVE-2026-73057 - High (7.5)
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:24
1 posts
1 repos
CVE-2026-74251: Phoca Cart (Joomla ext. v5.0.0 – 6.1.16) suffers CRITICAL SQL injection via unauthenticated a[]/s[] params. Full DB extraction possible. Patch status unclear — check vendor. https://radar.offseq.com/threat/cve-2026-74251-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-a5081e610a943a93 #OffSeq #SQLInjection #Joomla #Infosec
##updated 2026-08-16T09:30:22
1 posts
🟠 CVE-2026-17087 - High (7.5)
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authori...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17087/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:37
2 posts
🔴 CVE-2026-18316 - Critical (9.1)
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_act...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18316/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-18316: CRITICAL auth bypass in Solace Extra WordPress plugin (≤1.6.0). Subscriber-level users can perform destructive actions — no patch yet. Restrict user roles & monitor import_zip() activity. https://radar.offseq.com/threat/cve-2026-18316-cwe-862-missing-authorization-in-solacewp-solace-extra-02691f8987449b12 #OffSeq #WordPress #Vuln #CVE202618316
##updated 2026-08-16T06:30:32
2 posts
CVE-2026-18432 (CVSS 9.8): CRITICAL privilege escalation in DynamiApps Frontend Admin <=3.29.9. Unauthenticated attackers can become admins via flawed user ID checks. Restrict access to vulnerable forms & endpoints. https://radar.offseq.com/threat/cve-2026-18432-cwe-269-improper-privilege-management-in-shabti-frontend-admin-by-dynamiapps-0c7e8a2e9b4496ea #OffSeq #WordPress #PrivilegeEscalation #CVE
##🔴 CVE-2026-18432 - Critical (9.8)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18432/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:32
2 posts
CRITICAL: CVE-2026-14524 in ProSolution WP Client ≤2.0.8 enables unauthenticated file deletion via path traversal — risking RCE if key files are removed. No patch; restrict or disable plugin. https://radar.offseq.com/threat/cve-2026-14524-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-2ffa65eefa2c3a5d #OffSeq #WordPress #CVE202614524 #Vuln
##🔴 CVE-2026-14524 - Critical (9.1)
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unaut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14524/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:32
1 posts
🟠 CVE-2026-17123 - High (8.8)
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-control...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17123/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:31
1 posts
🟠 CVE-2026-14498 - High (8.8)
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_for...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:35
1 posts
CVE-2026-73053: CRITICAL XSS in SiYuan (pre-v3.7.4) risks code execution on host via crafted icons when Node integration is enabled. No patch confirmed — disable Node integration or avoid untrusted files. https://radar.offseq.com/threat/cve-2026-73053-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-1654398c24cf93d4 #OffSeq #XSS #Vuln #SiYuan
##updated 2026-08-16T00:31:34
1 posts
CVE-2026-73052: CRITICAL XSS in SiYuan (<3.7.4) enables arbitrary JS & potential code execution if Node integration is enabled. Desktop users most at risk — upgrade ASAP & disable Node integration where possible. https://radar.offseq.com/threat/cve-2026-73052-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-c5f0eb8b5e84714b #OffSeq #XSS #SiYuan #Infosec
##updated 2026-08-14T21:31:39
1 posts
A critical Haiwell HMI Gateway flaw (CVE-2026-19188) allows remote attackers to execute arbitrary OS commands with root privileges.
##updated 2026-08-14T19:09:39.140000
1 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-14T19:07:46.080000
1 posts
Red Hat fixes RHACM remote code execution flaws, including CVE-2026-72526 and CVE-2026-73268, both CVSS 9.9. See patch and mitigation steps.
#RHACM #RedHat #Kubernetes #ArgoCD #RCE #CVE #CyberSecurity #InfoSec
##updated 2026-08-14T18:31:46
1 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-14T03:31:33
1 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-14T00:31:53
2 posts
3 repos
https://github.com/aramosf/CVE-2026-68138
A public PoC for CVE-2026-68138 escalates a normal Linux user to root through a qdisc rate-table race condition.
#CVE202668138 #PrivilegeEscalation #LinuxKernel #qdisc #UseAfterFree #LPE
##A public PoC for CVE-2026-68138 escalates a normal Linux user to root through a qdisc rate-table race condition.
#CVE202668138 #PrivilegeEscalation #LinuxKernel #qdisc #UseAfterFree #LPE
##updated 2026-08-13T13:17:48.253000
2 posts
MongoDB Patches 32 Vulnerabilities, Including CVE-2026-19001 Arbitrary Code Execution Flaw (CVSS 9.5)
##MongoDB Patches 32 Vulnerabilities, Including CVE-2026-19001 Arbitrary Code Execution Flaw (CVSS 9.5)
##updated 2026-08-13T09:31:16
2 posts
If you are running Fluent Forms and have not updated since 13 August 2026, attackers may already be scanning for your installation. CVE-2026-18146 is high-severity and affects every version below 6.2.12. Update now.
#WordPress #WordPressSecurity #FluentForms #CVE #WebSecurity
##If you are running Fluent Forms and have not updated since 13 August 2026, attackers may already be scanning for your installation. CVE-2026-18146 is high-severity and affects every version below 6.2.12. Update now.
#WordPress #WordPressSecurity #FluentForms #CVE #WebSecurity
##updated 2026-08-12T21:31:50
1 posts
Red Hat fixes RHACM remote code execution flaws, including CVE-2026-72526 and CVE-2026-73268, both CVSS 9.9. See patch and mitigation steps.
#RHACM #RedHat #Kubernetes #ArgoCD #RCE #CVE #CyberSecurity #InfoSec
##updated 2026-08-11T18:31:49
2 posts
3 repos
https://github.com/DavidCarliez/CVE-2026-66804-CrossDevice-LPE
https://github.com/CypherHippie/CVE-2026-66804
https://github.com/Rat5ak/CVE-2026-66804-CrossDevice-Service-EoP
A public PoC for CVE-2026-66804 escalates a standard Windows user to SYSTEM through the Cross Device virtual camera COM service.
#CVE202666804 #PrivilegeEscalation #Windows11 #SYSTEMprivileges #EoP #PoCExploit
##📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-11T18:31:33
1 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-11T18:31:18
1 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-11T18:31:13
1 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-11T12:30:28
4 posts
1 repos
DefusedCyber detected exploitation attempts against CVE-2026-58231, a critical unauthenticated SAP Commerce Cloud flaw, just three days after SAP's patch shipped.
#SAPCommerceCloud #CVE202658231 #SAPSecurity #Vulnerability #DataHubAdapter
##DefusedCyber detected exploitation attempts against CVE-2026-58231, a critical unauthenticated SAP Commerce Cloud flaw, just three days after SAP's patch shipped.
#SAPCommerceCloud #CVE202658231 #SAPSecurity #Vulnerability #DataHubAdapter
##“A maximum-severity bug in SAP Commerce Cloud was exploited in the wild, research group Defused posted on X Aug. 14.
The 10.0 bug — CVE-2026-58231 — was described as having insufficient authorization checks and input validation and was earlier patched by SAP on Aug. 11.”
https://www.scworld.com/news/critical-sap-commerce-cloud-flaw-exploited-days-after-patch
##「SAP Commerce Cloudの脆弱性CVE-2026-58231が、パッチ適用後数日で悪用される試みの標的となる 」: #TheHackerNews
「SAP Commerce Cloudに影響を与える、最も深刻なセキュリティ脆弱性について、現在活発な悪用活動が行われています。
CVE-2026-58231 として追跡されているこの脆弱性は、 CVSSスコアリングシステムで10.0と評価されています。これは、認証チェックと入力検証が不十分なケースに関連しています。
CVE.orgによると、「SAP Commerce Cloudでは、認証されていない攻撃者がデフォルトの認証クライアントを悪用し、十分な検証が行われていない特定の機能に特別に細工された入力を送信できる」とのことです。
「脆弱性を悪用されると、任意のコード実行が可能になり、内部コンポーネントが侵害される可能性があり、アプリケーションの機密性、完全性、可用性に重大な影響を与える可能性があります。」 」
https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html
##updated 2026-08-10T14:17:26.737000
2 posts
D-Link fixes 15 flaws in the DWR-M961 router, including D-Link router command injection and buffer overflow bugs like CVE-2026-71958. Update firmware now.
#DLink #DWRM961 #CommandInjection #BufferOverflow #RouterSecurity #CVE #InfoSec #CyberSecurity
##D-Link fixes 15 flaws in the DWR-M961 router, including D-Link router command injection and buffer overflow bugs like CVE-2026-71958. Update firmware now.
#DLink #DWRM961 #CommandInjection #BufferOverflow #RouterSecurity #CVE #InfoSec #CyberSecurity
##updated 2026-08-08T01:10:43.697000
2 posts
1 repos
⚪️ Hackers Exploit macOS Screen Sharing Vulnerability to Install Crypto Miners
🗨️ The Netherlands’ National Cyber Security Centre (NCSC) has warned that attackers have begun exploiting the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. The flaw allows authentication to be bypassed, granting access to a Mac without a password, and is already…
##⚪️ Hackers Exploit macOS Screen Sharing Vulnerability to Install Crypto Miners
🗨️ The Netherlands’ National Cyber Security Centre (NCSC) has warned that attackers have begun exploiting the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. The flaw allows authentication to be bypassed, granting access to a Mac without a password, and is already…
##updated 2026-08-04T03:31:16
1 posts
1 repos
https://github.com/minanagehsalalma/CVE-2026-6837-zyxel-export-cgi-command-injection
CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/
##updated 2026-08-01T05:16:55.023000
2 posts
1 repos
Cl0p Turns PTC Windchill Into a Data-Theft Weapon: Critical CVE-2026-12569 Exploited to Steal Industrial Secrets + Video
Introduction: When the Blueprint Becomes the Target The most dangerous cyberattacks do not always begin with a locked computer, a destroyed server, or a ransom note appearing across an employee's screen. Sometimes, the attack begins quietly against an application that nobody outside the engineering department thinks of as a critical security…
##🏆 New Achievement! Clop Sends Its Regards to the Living!
Attention, all undead assets and legacy infrastructure currently haunting your network closets: please report to Compliance for re-onboarding. Tech giants General Electric and Philips have confirmed they are investigating claims by the Clop ransomware group that data was stolen, with CVE-2026-12569 tagged in connection with the incident. (1/3)
##updated 2026-07-28T18:33:56
1 posts
Petit insight très sympa sur la recherche de vulnérabilité macOS
Le chercheur Csaba Fitzl revient sur une jolie vuln dans Spotlight (Spotlight PostScript plugin), une sorte de petite chimère qui traînait depuis un moment dans sa TODO list : quelques fonctions décompilées du parser PostScript soumises à Claude, une piste identifiée, puis validation humaine.
Résultat : CVE-2026-43774, un simple fichier .ps pouvant faire fuiter des morceaux de mémoire de mdworker via les métadonnées Spotlight.
Au-delà du bug, le billet montre très directement comment les IA s’intègrent naturellement aux workflows de recherche de vulnérabilités, en partant de l’expertise humaine : une intuition et une approche, puis fuzzing dopé au LLM, reverse, détection de patterns suspects…
...et pourquoi les éditeurs comme la pomme doivent courir toujours plus vite derrière les patchs.
"How a single PostScript file leaks your Mac's memory"
👇
https://www.iru.com/blog/how-a-single-postscript-file-leaks-your-macs-memory
updated 2026-07-21T19:54:33.623000
1 posts
12 repos
https://github.com/marcgoam/CVE-2026-54121-CertiGhost
https://github.com/HORKimhab/CVE-2026-54121
https://github.com/GlendonNotGlen/certighost-cve-2026-54121-slides
https://github.com/mwnickerson/certighost-bof
https://github.com/ChPratik/CVE-2026-54121
https://github.com/AtlasVector/Certighost-CVE-2026-54121
https://github.com/nafiez/Metasploit-CVE-2026-54121-Certighost
https://github.com/KrakenEU/CVE-2026-54121-CertiGhost
https://github.com/0xBlackash/CVE-2026-54121
https://github.com/sam00/POC-CVE-2026-54121-Certighost
Certighost and the Privilege Hiding in Your Certificate Authority
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing...
🔗️ [Bleepingcomputer] https://link.is.it/wWmVkm
##updated 2026-07-01T18:32:28
5 posts
2 repos
https://github.com/derekpreston81/CVE_ADC_IOC_2026
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
##CVE-2026-8452 in Netscaler is under active pray and spray exploitation - somebody popped my honeypot with it today. Three webshells, x.php, y.php and z.php
I don't think this one will be super impactful in terms of breach numbers as most orgs don't have SAML IDP enabled - you can check with the paths I posted above.
##‼️ Detection Artifact Generator for Citrix NetScaler CVE-2026-8452
GitHub: https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
##Oof; if you're a NetScaler shop you probably want to be very sure you update for this one: https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
Pre-auth RCE is... yikes. Relatively low EPSS for now, but I wouldn't trust that with the CVSSv4 vectors in play: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
##PoC exploit code for CVE-2026-8452, a Citrix NetScaler pre-auth RCE, is now public. The SAML heap overflow grants root. Patch now.
#Citrix #NetScaler #CVE #PreAuthRCE #SAML #CyberSecurity #InfoSec #PatchNow
##updated 2026-06-17T10:43:20.747000
1 posts
SQL Injection flaw (CVE-2026-67854) in Qcms v6.0.6 rated CRITICAL: remote code execution risk. No official patch. Restrict access & monitor for injection attempts. Details: https://radar.offseq.com/threat/sql-injection-vulnerability-in-qcms-v606-allows-a-remote-attacker-to-execute-arbitrary-code-cve-2026-3286c90b2be69269 #OffSeq #SQLInjection #Vulnerability #Qcms #InfoSec
##updated 2026-06-16T22:59:22.107000
2 posts
1 repos
https://github.com/talha3117/OpenSSH-4.7p1-CVE-2008-5161-Exploit
@sten @lennybacon @b0rk
Ad CBC:
https://en.wikipedia.org/wiki/Padding_oracle_attack#Symmetric_cryptography
https://crypto.stackexchange.com/questions/77975/how-to-break-cbc-cipher-with-partly-known-plaintext
##@sten @lennybacon @b0rk
Ad CBC:
https://en.wikipedia.org/wiki/Padding_oracle_attack#Symmetric_cryptography
https://crypto.stackexchange.com/questions/77975/how-to-break-cbc-cipher-with-partly-known-plaintext
##updated 2026-06-09T18:30:48
1 posts
From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193) https://zerolabs.rubrik.com/blog/breaking-m365-copilot-sandbox-chatmate
##updated 2026-06-08T23:06:42
1 posts
CVE-2026-47719 - Critical SSRF in FUXA SCADA/HMI. Unauthenticated attackers can probe internal networks via axios. CVSS 8.2. Unpatched - restrict access now. #CVE #ICS #cybersecurity
##updated 2026-04-14T18:30:50
2 posts
3 repos
https://github.com/oxstussz-eng/Kerberos-CVE-2026-27912
ResetNightmare : cette faille Kerberos permet de prendre le contrôle du domaine Active Directory https://www.it-connect.fr/resetnightmare-cve-2026-27912-kerberos-active-directory/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft
##ResetNightmare : cette faille Kerberos permet de prendre le contrôle du domaine Active Directory https://www.it-connect.fr/resetnightmare-cve-2026-27912-kerberos-active-directory/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft
##updated 2026-04-13T18:31:39
2 posts
2 repos
CISA: Windows Task Host flaw now exploited by ransomware gangs
CISA는 Windows Task Host의 권한 상승 취약점 CVE-2025-60710이 랜섬웨어 그룹에 의해 악용되고 있다고 KEV 카탈로그에 추가했습니다. 이 취약점은 Windows 11 및 Windows Server 2025의 링크 추적(link following) 문제로, 기본 사용자 권한을 가진 로컬 공격자가 SYSTEM 권한을 획득할 수 있습니다. Microsoft는 2025년 11월 패치를 배포했으므로, AI 개발·학습·추론 워크로드를 운영하는 Windows...
##CISA Warns: Ransomware Gangs Are Exploiting a Windows Task Host Flaw That Can Unlock SYSTEM Access + Video
A Quiet Windows Component Has Become a Dangerous Ransomware Gateway A Windows vulnerability that initially looked like another privilege-escalation flaw in a long list of security advisories has taken on a much more serious meaning. CISA has confirmed that CVE-2025-60710, a high-severity vulnerability affecting the Windows Host Process for Windows Tasks, is now…
##updated 2026-03-26T16:41:02
1 posts
CVE-2026-33696: From a Schema Name to RCE in n8n https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce
##updated 2025-12-01T16:02:43
11 posts
1 repos
Recent alerts include CISA adding a critical RCE flaw in Ray-Project Ray (CVE-2025-62593) to its KEV catalog (Aug 18). Heights Finance also reported a data breach impacting over 1.2 million customers. Globally, ransomware incidents remain high, with AI increasingly used in attacks. Geopolitically, US-Iran talks have stalled, intensifying Middle East tensions and affecting global shipping.
##🚨 C-SUITE ALERT: CISA has flagged CVE-2025-62593 (Ray-Project) for active exploitation. This critical RCE flaw requires immediate executive oversight. Read our board-ready risk assessment and compliance framework to secure your enterprise. Command the wire. 👇 Link below
https://thecybermind.co/k3rh
#CyberSecurity
Recent alerts include CISA adding a critical RCE flaw in Ray-Project Ray (CVE-2025-62593) to its KEV catalog (Aug 18). Heights Finance also reported a data breach impacting over 1.2 million customers. Globally, ransomware incidents remain high, with AI increasingly used in attacks. Geopolitically, US-Iran talks have stalled, intensifying Middle East tensions and affecting global shipping.
##🚨 C-SUITE ALERT: CISA has flagged CVE-2025-62593 (Ray-Project) for active exploitation. This critical RCE flaw requires immediate executive oversight. Read our board-ready risk assessment and compliance framework to secure your enterprise. Command the wire. 👇 Link below
https://thecybermind.co/k3rh
#CyberSecurity
🚨 [CISA-2026:0817] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-62593 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-62593)
- Name: Ray-Project Ray Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ray-Project
- Product: Ray
- Notes: https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v ; https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-62593
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260817 #cisa20260817 #cve_2025_62593 #cve202562593
##🚨 NEW CISA KEV: CVE-2025-62593 - Ray. Active RCE weaponization via DNS rebinding targeting developers on Firefox/Safari. Vendor patch 2.52.0 is mandatory. Get the full T-Suite brief & SOC detection queries to secure your Precinct Hybrid architecture. Command the wire. Link below 👇
https://thecybermind.co/jily
#CyberSecurity
CVE ID: CVE-2025-62593
Vendor: Ray-Project
Product: Ray
Date Added: 2026-08-17
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2025-62593
🚨 [CISA-2026:0818] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-62593 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-62593)
- Name: Ray-Project Ray Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ray-Project
- Product: Ray
- Notes: https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v ; https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-62593
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260818 #cisa20260818 #cve_2025_62593 #cve202562593
##CISA confirms CVE-2025-62593, a Ray code injection RCE, is exploited in the wild. A public PoC targets Firefox and Safari.
#CVE202562593 #Ray #RemoteCodeExecution #DNSRebinding #KEV #ExploitedInTheWild
https://securityonline.info/cve-2025-62593-ray-rce/?utm_source=mastodon&utm_medium=jetpack_social
##CISA has added one known vulnerability to the KEV catalogue.
- CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-62593 #CISA #infosec #vulnerability
##CVE ID: CVE-2025-62593
Vendor: Ray-Project
Product: Ray
Date Added: 2026-08-18
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2025-62593
🟠 CVE-2026-50191 - High (8.8)
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50191/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-50191 - High (8.8)
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50191/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-50142 - High (7.5)
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequences/seq_bo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50142/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-50142 - High (7.5)
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequences/seq_bo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50142/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-52872 - High (8.8)
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied subtitle ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52872/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-52872 - High (8.8)
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied subtitle ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52872/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-52877 - High (8.3)
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal withou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52877/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-52877 - High (8.3)
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal withou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52877/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-52876 - High (8.8)
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52876/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-52876 - High (8.8)
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52876/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75936 - High (7.5)
Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75936/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75936 - High (7.5)
Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75936/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##@hugovalters I’m curious. What does “unpatched” mean in this context? I had presumed it meant the vulnerability hasn’t been fixed yet, but this doesn’t seem to be the case. e.g. this page lists the CVE as “unpatched” but also says what version of Vim it was fixed in: https://www.valtersit.com/cve/CVE-2025-53906
##@hugovalters I’m curious. What does “unpatched” mean in this context? I had presumed it meant the vulnerability hasn’t been fixed yet, but this doesn’t seem to be the case. e.g. this page lists the CVE as “unpatched” but also says what version of Vim it was fixed in: https://www.valtersit.com/cve/CVE-2025-53906
##🔴 CVE-2026-75913 - Critical (9.3)
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options se...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75913/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75913 - Critical (9.3)
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options se...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75913/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75911 - High (7.8)
CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml file to a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75911/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75911 - High (7.8)
CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml file to a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75911/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##A CVSS 10.0 unauthenticated arbitrary file read flaw in BigBlueButton path traversal exposes servers. Prevent attacks like CVE-2024-39302 and update now.
##🟠 CVE-2026-45790 - High (8)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission to invite an account ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45790/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71424 - Critical (9.6)
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and On...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71424/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
####Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path...
##Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path...
##Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path...
##Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path...
##Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-after-free in the TLS pending-data list when a command closes another...
🏆 New Achievement! Your Antivirus Has a Virus Problem!
PATCH NOTES v0.0.0 — KNOWN ISSUES: Microsoft Defender, the product specifically designed to protect you from threats, is currently a threat. The Microsoft Malware Protection Engine contains a zero-day tracked as CVE-2024-69414, nicknamed ShieldBreak, which attackers in the wild are actively using to elevate their privileges. Think of it as a DLC nobody ordered.
ADDED: Unauthorized privilege escalation. FIXED: Nothing yet. (1/2)
##1 posts
6 repos
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
https://github.com/Franc-Zar/CVE-2026-72898-safe-detection
https://github.com/0xBlackash/CVE-2026-72898
https://github.com/VuxNx/CVE-2026-72898
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)