## Updated at UTC 2026-09-16T05:22:38.222378

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-92178 7.8 0.00% 2 0 2026-09-16T04:19:00.327000 pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution
CVE-2026-92177 7.8 0.00% 2 0 2026-09-16T04:18:59.817000 pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Executio
CVE-2026-63695 9.8 0.00% 2 0 2026-09-16T04:18:37.990000 Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session F
CVE-2026-12793 9.8 0.00% 2 0 2026-09-16T04:17:56.110000 The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnera
CVE-2026-15640 None 0.00% 2 0 2026-09-16T00:31:41 Under certain conditions a valid SAML IdP response may be used to impersonate an
CVE-2026-92248 7.8 0.00% 2 0 2026-09-16T00:31:36 A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail pre
CVE-2026-87289 7.5 0.00% 2 0 2026-09-16T00:31:27 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: hel
CVE-2026-15639 0 0.00% 2 0 2026-09-16T00:17:03.453000 An attacker can craft a malicious link that, if used by a legitimate user, may c
CVE-2026-85893 8.8 0.00% 2 0 2026-09-15T23:19:12.110000 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke
CVE-2026-69486 8.8 0.00% 2 0 2026-09-15T23:17:41.633000 Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthor
CVE-2026-73807 9.8 0.00% 4 0 2026-09-15T22:16:58.683000 The mySCADA myPRO Manager command API does not properly enforce authentication f
CVE-2026-92000 7.5 0.00% 2 0 2026-09-15T21:33:15 adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output li
CVE-2026-68070 8.8 0.00% 2 0 2026-09-15T21:33:13 The affected products are missing authentication for a critical function, which
CVE-2026-66890 9.6 0.00% 2 0 2026-09-15T21:33:13 The affected products use hard-coded credentials, which could allow remote acces
CVE-2026-89040 9.8 0.00% 2 0 2026-09-15T21:33:13 Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated a
CVE-2026-87288 8.1 0.00% 2 0 2026-09-15T21:33:06 Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil
CVE-2026-87287 8.1 0.00% 2 0 2026-09-15T21:33:06 Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil
CVE-2026-92176 7.8 0.00% 2 0 2026-09-15T21:31:29 pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulne
CVE-2026-92179 7.8 0.00% 2 0 2026-09-15T21:31:29 pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Executio
CVE-2026-92180 7.8 0.00% 2 0 2026-09-15T21:31:25 pdfforge PDF Architect activation-service Update Service Uncontrolled Search Pat
CVE-2026-91939 9.8 0.00% 2 0 2026-09-15T21:16:48.957000 Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() witho
CVE-2026-88975 7.5 0.00% 2 0 2026-09-15T20:19:19.943000 Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, E
CVE-2026-87286 8.1 0.00% 2 0 2026-09-15T20:19:18.560000 Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil
CVE-2026-76670 9.9 0.00% 2 0 2026-09-15T20:17:48.833000 Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConn
CVE-2026-90606 9.9 0.49% 3 0 2026-09-15T19:17:46.067000 A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046
CVE-2026-69213 7.5 0.00% 2 0 2026-09-15T19:17:38.317000 Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, E
CVE-2026-89026 9.8 0.00% 4 0 2026-09-15T18:32:43 The Issabel Framework, the web framework supporting Issabel PBX software, before
CVE-2026-91990 7.5 0.00% 2 0 2026-09-15T18:32:43 Tornado before 6.5.8 contains a memory amplification vulnerability in parse_mult
CVE-2026-76441 9.8 0.46% 2 0 2026-09-15T18:32:19 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20353 9.8 0.37% 2 0 2026-09-15T18:32:19 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20275 8.8 0.18% 2 0 2026-09-15T18:32:14 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-90703 9.1 2.80% 1 0 2026-09-15T18:19:38.113000 A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element i
CVE-2026-76440 9.8 0.43% 2 0 2026-09-15T18:19:12.950000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-59160 8.8 0.00% 2 0 2026-09-15T18:17:26.587000 Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to
CVE-2026-20276 8.6 0.25% 2 0 2026-09-15T18:17:18.607000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20274 9.8 0.67% 2 0 2026-09-15T18:17:18.240000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-91985 7.5 0.00% 2 0 2026-09-15T17:17:44.127000 Vikunja before 2.6.0 fails to properly restrict access to the link-share hash fi
CVE-2026-91989 7.5 0.00% 2 0 2026-09-15T16:17:58.010000 atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the
CVE-2026-63696 9.1 0.00% 2 0 2026-09-15T15:32:20 Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download
CVE-2026-89025 7.5 0.00% 2 0 2026-09-15T15:32:20 Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerabilit
CVE-2026-91001 9.9 0.48% 4 0 2026-09-15T15:17:30.983000 A security flaw has been discovered in D-Link DI-8400 16.07. This affects the fu
CVE-2026-89308 0 0.00% 2 0 2026-09-15T13:16:45.543000 An unauthenticated OS command injection vulnerability exists in the ping.php end
CVE-2026-76461 9.8 2.16% 43 3 2026-09-15T12:47:32.497000 A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure
CVE-2026-91995 9.1 0.00% 2 0 2026-09-15T12:17:54.943000 pig before 4.1.0 contains an authentication bypass vulnerability in the /registe
CVE-2026-80217 8.8 0.28% 2 0 2026-09-15T09:30:39 Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allo
CVE-2026-77853 8.8 1.03% 2 0 2026-09-15T09:30:39 Improper neutralization of special elements used in an OS command ('OS Command I
CVE-2026-75983 7.5 0.41% 2 0 2026-09-15T09:30:38 The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugi
CVE-2026-91003 9.1 0.51% 4 0 2026-09-15T06:30:40 A flaw has been found in D-Link DI-8300 16.07. The affected element is the funct
CVE-2026-90847 9.1 2.18% 2 0 2026-09-15T03:30:30 A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element i
CVE-2026-91771 8.8 0.73% 2 0 2026-09-15T02:16:49.680000 Weights & Biases wandb before 0.29.0 fails to validate the file name from server
CVE-2026-91200 8.8 0.42% 2 0 2026-09-15T00:31:22 DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry n
CVE-2026-12944 9.6 0.25% 6 1 2026-09-15T00:31:21 IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary P
CVE-2026-65352 4.3 0.25% 2 0 2026-09-15T00:31:13 An information disclosure issue was addressed with improved state management. Th
CVE-2026-91144 7.5 0.37% 2 0 2026-09-14T22:16:59.053000 ZFile through 5.0.5 fails to validate requested file paths against a share link'
CVE-2026-82232 9.8 0.56% 2 0 2026-09-14T21:32:45 Improper neutralization of special elements used in an SQL command ('SQL injecti
CVE-2026-82028 8.8 0.43% 2 0 2026-09-14T21:31:46 Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-
CVE-2026-53713 9.1 0.41% 2 0 2026-09-14T21:17:12.520000 Envoy Gateway is an open source project for managing Envoy Proxy as a standalone
CVE-2026-15891 7.5 0.34% 1 0 2026-09-14T21:10:41.650000 The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mq
CVE-2026-81648 10.0 0.28% 1 0 2026-09-14T21:10:17.423000 The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an
CVE-2026-74933 8.8 0.27% 1 0 2026-09-14T21:10:17.423000 The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisatio
CVE-2026-88793 8.8 0.28% 1 0 2026-09-14T21:10:17.423000 The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any author
CVE-2026-86406 7.5 0.19% 1 0 2026-09-14T21:10:17.423000 The User Registration & Membership WordPress plugin before 5.2.8 does not check
CVE-2026-89023 8.6 0.23% 2 0 2026-09-14T21:07:11.883000 ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missin
CVE-2026-78330 9.8 0.60% 2 0 2026-09-14T20:58:48.430000 Incorrect privilege assignment vulnerability in Apache Syncope. When the config
CVE-2026-90680 9.9 0.51% 1 0 2026-09-14T20:56:48.220000 A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The im
CVE-2026-90607 9.9 0.47% 2 0 2026-09-14T20:56:48.220000 A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is
CVE-2026-90510 8.3 0.29% 1 0 2026-09-14T20:56:48.220000 A security vulnerability has been detected in dromara orion-visor up to 2.5.7. T
CVE-2026-73496 7.7 0.33% 2 0 2026-09-14T20:16:50.833000 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (C
CVE-2026-91080 7.5 0.59% 2 0 2026-09-14T19:18:14.500000 webhook through 2.8.3 reads the entire request body into memory before evaluatin
CVE-2026-59178 9.8 0.42% 2 0 2026-09-14T19:17:37.617000 ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management
CVE-2026-91079 8.5 0.35% 2 0 2026-09-14T18:31:35 Huly Platform through 0.7.426 contains a server-side request forgery vulnerabili
CVE-2026-90946 7.5 0.57% 2 0 2026-09-14T18:31:29 DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerabili
CVE-2026-85921 8.2 0.26% 2 0 2026-09-14T18:31:29 Double free in Windows Secure Kernel Mode allows an authorized attacker to eleva
CVE-2026-90945 9.8 0.53% 4 0 2026-09-14T18:31:28 Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing
CVE-2026-57129 7.5 0.44% 2 0 2026-09-14T16:17:14.220000 PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, Mentio
CVE-2026-89746 7.8 0.16% 1 0 2026-09-14T15:33:42 In the Linux kernel, the following vulnerability has been resolved: tracing: Fi
CVE-2026-89697 9.1 0.69% 1 0 2026-09-14T15:33:39 In the Linux kernel, the following vulnerability has been resolved: nfsd: add f
CVE-2026-89461 None 0.21% 1 0 2026-09-14T15:33:29 In the Linux kernel, the following vulnerability has been resolved: power: supp
CVE-2026-88802 7.5 0.23% 1 0 2026-09-14T15:32:39 The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events
CVE-2026-85129 8.8 0.26% 1 0 2026-09-14T15:32:39 The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or vali
CVE-2026-89736 7.8 0.13% 1 0 2026-09-14T15:32:36 In the Linux kernel, the following vulnerability has been resolved: usb: gadget
CVE-2026-89706 7.5 0.51% 1 0 2026-09-14T15:32:35 In the Linux kernel, the following vulnerability has been resolved: nfsd: Reset
CVE-2026-89684 7.5 0.51% 1 0 2026-09-14T15:32:34 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix c
CVE-2026-89504 8.4 0.14% 1 0 2026-09-14T15:32:28 In the Linux kernel, the following vulnerability has been resolved: regulator:
CVE-2026-89508 7.8 0.12% 1 0 2026-09-14T15:32:27 In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma:
CVE-2026-89481 7.5 0.41% 1 0 2026-09-14T15:32:26 In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: f
CVE-2026-89458 None 0.18% 1 0 2026-09-14T15:32:24 In the Linux kernel, the following vulnerability has been resolved: s390/dasd:
CVE-2026-80979 7.8 0.13% 1 0 2026-09-14T15:32:22 In the Linux kernel, the following vulnerability has been resolved: net/smc: un
CVE-2026-43502 7.8 0.12% 2 1 2026-09-14T15:32:07 In the Linux kernel, the following vulnerability has been resolved: net/rds: ha
CVE-2026-12258 0 0.40% 2 0 2026-09-14T15:17:04.153000 Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘cus
CVE-2026-85706 10.0 11.96% 20 12 2026-09-14T14:22:15.323000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7
CVE-2026-73324 4.3 0.21% 1 0 2026-09-14T14:17:08.940000 Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memor
CVE-2026-89750 7.8 0.16% 1 0 2026-09-14T13:19:23.640000 In the Linux kernel, the following vulnerability has been resolved: tracing/use
CVE-2026-89744 8.4 0.14% 1 0 2026-09-14T13:19:23.193000 In the Linux kernel, the following vulnerability has been resolved: device prop
CVE-2026-89704 7.5 0.51% 1 0 2026-09-14T13:19:20.367000 In the Linux kernel, the following vulnerability has been resolved: nfsd: sampl
CVE-2026-89696 7.5 0.76% 1 0 2026-09-14T13:19:19.897000 In the Linux kernel, the following vulnerability has been resolved: nfsd: block
CVE-2026-89488 7.8 0.12% 1 0 2026-09-14T13:19:05.627000 In the Linux kernel, the following vulnerability has been resolved: openvswitch
CVE-2026-80973 0 0.21% 1 0 2026-09-14T13:18:52.180000 In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire
CVE-2026-80970 0 0.20% 1 0 2026-09-14T13:18:51.770000 In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP:
CVE-2026-80931 7.8 0.13% 1 0 2026-09-14T13:18:49.327000 In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17
CVE-2026-90919 9.8 1.01% 2 0 2026-09-14T12:31:50 LightLLM through 1.2.0 contains a remote code execution vulnerability in the Con
CVE-2026-12518 0 0.11% 3 0 2026-09-14T11:17:02.930000 A local privilege escalation vulnerability in the Logitech Logi Options+ updater
CVE-2026-90608 9.9 0.80% 2 0 2026-09-14T03:30:29 A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected elemen
CVE-2026-33963 7.5 0.11% 1 0 2026-09-14T03:30:29 An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380,
CVE-2026-31278 7.7 0.15% 2 1 2026-09-14T03:30:22 An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 be
CVE-2026-23789 7.8 0.11% 1 0 2026-09-14T02:17:13.397000 An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processo
CVE-2026-90605 9.9 0.47% 1 0 2026-09-14T00:31:35 A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulne
CVE-2026-82078 9.1 1.69% 1 2 2026-09-14T00:16:56.777000 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-37008 8.1 0.13% 1 0 2026-09-13T21:31:54 CrewAI before fb2323b offers a Python blocklist approach that operates at the wr
CVE-2026-29811 7.7 0.25% 1 0 2026-09-13T21:31:53 CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second dom
CVE-2026-90783 7.8 0.14% 1 0 2026-09-13T15:30:28 MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib l
CVE-2026-90775 6.5 0.34% 1 0 2026-09-13T12:31:19 PostGIS address_standardizer through 3.7.0 fails to validate the Weight paramete
CVE-2026-90779 7.5 0.56% 1 0 2026-09-13T12:31:19 SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthH
CVE-2026-90561 8.7 0.24% 1 0 2026-09-13T12:31:11 Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-
CVE-2026-89080 7.5 0.20% 1 0 2026-09-13T12:31:10 The Really Simple Security WordPress plugin before 9.8.1 does not prevent an un
CVE-2026-90562 8.1 0.42% 1 0 2026-09-13T11:17:00.780000 LangBot before 4.10.11 generates password recovery keys with only 24 bits of ent
CVE-2026-89690 7.8 0.16% 1 0 2026-09-13T09:33:34 In the Linux kernel, the following vulnerability has been resolved: nfsd: defer
CVE-2026-89688 9.8 0.61% 1 0 2026-09-13T09:33:31 In the Linux kernel, the following vulnerability has been resolved: nfsd: drop
CVE-2026-89611 9.8 0.38% 1 0 2026-09-13T09:33:31 In the Linux kernel, the following vulnerability has been resolved: ntfs: valid
CVE-2026-89695 7.5 0.49% 1 0 2026-09-13T09:33:31 In the Linux kernel, the following vulnerability has been resolved: nfsd: cap d
CVE-2026-89689 9.8 0.60% 1 0 2026-09-13T09:33:30 In the Linux kernel, the following vulnerability has been resolved: nfsd: don't
CVE-2026-89521 7.3 0.15% 1 0 2026-09-13T09:33:28 In the Linux kernel, the following vulnerability has been resolved: sched/core:
CVE-2026-80981 9.8 0.59% 1 0 2026-09-13T09:33:25 In the Linux kernel, the following vulnerability has been resolved: net/smc: fi
CVE-2026-81006 7.8 0.13% 2 0 2026-09-13T09:33:21 In the Linux kernel, the following vulnerability has been resolved: ipmi: Remov
CVE-2026-80980 9.8 0.60% 1 0 2026-09-13T09:33:21 In the Linux kernel, the following vulnerability has been resolved: net/smc: st
CVE-2026-89748 7.8 0.15% 1 0 2026-09-13T09:32:30 In the Linux kernel, the following vulnerability has been resolved: tracing: Fi
CVE-2026-89758 7.8 0.14% 1 0 2026-09-13T09:32:30 In the Linux kernel, the following vulnerability has been resolved: mm/mempolic
CVE-2026-89686 9.8 0.67% 1 0 2026-09-13T09:32:28 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix B
CVE-2026-89685 7.5 0.43% 1 0 2026-09-13T09:32:28 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix c
CVE-2026-80947 7.8 0.16% 1 0 2026-09-13T09:32:12 In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8x
CVE-2026-89747 7.8 0.16% 1 0 2026-09-13T07:17:39.363000 In the Linux kernel, the following vulnerability has been resolved: tracing: Fi
CVE-2026-89692 7.5 0.43% 1 0 2026-09-13T07:17:35.107000 In the Linux kernel, the following vulnerability has been resolved: nfsd: clear
CVE-2026-89687 7.5 0.47% 1 0 2026-09-13T07:17:34.493000 In the Linux kernel, the following vulnerability has been resolved: nfsd: ensur
CVE-2026-89682 8.1 0.40% 1 0 2026-09-13T07:17:34.003000 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix f
CVE-2026-89613 9.8 0.55% 1 0 2026-09-13T07:17:26.840000 In the Linux kernel, the following vulnerability has been resolved: ntfs: rejec
CVE-2026-89612 9.8 0.55% 1 0 2026-09-13T07:17:26.730000 In the Linux kernel, the following vulnerability has been resolved: ntfs: rejec
CVE-2026-89501 7.8 0.16% 1 0 2026-09-13T07:17:13.333000 In the Linux kernel, the following vulnerability has been resolved: ring-buffer
CVE-2026-89499 7.8 0.12% 1 0 2026-09-13T07:17:13.100000 In the Linux kernel, the following vulnerability has been resolved: ring-buffer
CVE-2026-89450 8.8 0.13% 1 0 2026-09-13T07:17:09.350000 In the Linux kernel, the following vulnerability has been resolved: iommu/tegra
CVE-2026-80995 7.8 0.12% 1 0 2026-09-13T07:17:06.230000 In the Linux kernel, the following vulnerability has been resolved: net: mctp:
CVE-2026-80936 7.8 0.13% 1 0 2026-09-13T07:17:01.293000 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:
CVE-2026-89517 None 0.20% 1 0 2026-09-11T21:31:37 In the Linux kernel, the following vulnerability has been resolved: sched_ext:
CVE-2026-81911 None 0.30% 1 0 2026-09-11T21:31:32 Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom
CVE-2026-89447 None 0.18% 1 0 2026-09-11T21:31:32 In the Linux kernel, the following vulnerability has been resolved: iommufd: Av
CVE-2026-80927 None 0.17% 1 0 2026-09-11T21:31:19 In the Linux kernel, the following vulnerability has been resolved: timekeeping
CVE-2026-84869 9.9 0.69% 9 0 2026-09-11T21:31:17 A condition in the ScreenConnect client may allow files to be transferred and ex
CVE-2026-42016 8.1 0.89% 3 0 2026-09-11T21:31:06 JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri
CVE-2026-59971 10.0 0.00% 2 0 2026-09-11T20:36:20 ## Summary In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServer
CVE-2026-81861 0 0.38% 2 1 2026-09-11T20:19:13.263000 CWE-522: Insufficiently Protected Credentials vulnerability that could result in
CVE-2026-81018 0 0.13% 1 0 2026-09-11T20:19:10.813000 In the Linux kernel, the following vulnerability has been resolved: platform/x8
CVE-2026-80974 0 0.20% 1 0 2026-09-11T20:19:03.623000 In the Linux kernel, the following vulnerability has been resolved: mfd: sm501:
CVE-2026-80960 0 0.20% 1 0 2026-09-11T20:19:01.863000 In the Linux kernel, the following vulnerability has been resolved: dm-pcache:
CVE-2026-89010 9.8 2.85% 1 0 2026-09-11T17:35:21.440000 WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 cont
CVE-2026-17176 0 3.59% 1 0 2026-09-11T15:21:12.850000 An OS command injection vulnerability in the TDDP module of Deco BE11000 allows
CVE-2026-87020 8.1 0.56% 1 0 2026-09-11T15:17:06.937000 An integer overflow in a specified pitch and buffer-size computation leads to a
CVE-2026-86060 9.8 1.06% 2 1 2026-09-11T12:52:16.507000 RouterOS contains an argument-handling flaw in the SSH login path involving user
CVE-2026-82079 8.4 0.16% 2 0 2026-09-11T03:31:25 A stack-based buffer overflow vulnerability in the Nintendo Switch local wireles
CVE-2026-65638 0 3.20% 1 0 2026-09-10T19:54:25.810000 Improper escaping of a request URL in ConfigServer Security & Firewall allows a
CVE-2026-81467 9.8 3.84% 1 0 2026-09-10T18:33:04 Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutraliza
CVE-2026-81468 9.1 2.28% 1 0 2026-09-10T18:33:03 Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutraliza
CVE-2026-20079 10.0 75.75% 1 3 2026-09-10T12:48:17.580000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2025-25249 8.1 2.40% 1 0 2026-09-10T12:47:59.933000 A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6
CVE-2026-85103 9.8 0.36% 2 0 2026-09-10T04:18:18.390000 A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unau
CVE-2026-87491 8.8 1.00% 1 2 2026-09-09T21:31:35 Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remo
CVE-2026-58113 6.1 0.22% 2 0 2026-09-09T16:17:03.483000 A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.00
CVE-2026-87827 0 1.07% 2 0 2026-09-09T15:37:49.157000 Certain KGUARD DVR devices running vulnerable firmware expose a system command e
CVE-2026-85102 9.8 0.33% 2 0 2026-09-09T15:35:15 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-56711 8.8 0.11% 1 0 2026-09-09T15:35:15 VLC media player computes the size of a picture buffer with 32-bit arithmetic an
CVE-2026-86218 9.8 0.74% 1 3 2026-09-09T05:18:19.490000 N-central is vulnerable to a pre-auth remote code execution This issue affects N
CVE-2026-85880 7.8 0.57% 3 0 2026-09-09T05:18:19.193000 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev
CVE-2026-81963 7.8 0.63% 2 0 2026-09-09T05:18:17.173000 Improper link resolution before file access ('link following') in Windows Update
CVE-2026-75650 10.0 2.15% 3 5 2026-09-09T05:18:07.237000 Adobe Commerce is affected by an Improper Neutralization of Special Elements Use
CVE-2026-12745 9.8 2.09% 1 0 2026-09-08T15:32:04 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM bef
CVE-2026-12744 9.8 2.17% 1 0 2026-09-08T15:32:04 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM bef
CVE-2026-79697 9.9 3.35% 1 0 2026-09-08T14:17:29.160000 A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-661
CVE-2026-48888 7.5 0.26% 2 0 2026-09-08T13:12:58.310000 Allocation of Resources Without Limits or Throttling vulnerability in Automattic
CVE-2026-78488 6.5 3.25% 1 0 2026-09-07T15:34:02 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application
CVE-2026-85046 8.8 1.46% 1 8 2026-09-06T03:30:24 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at
CVE-2026-80881 0 0.17% 1 0 2026-09-04T17:17:00.390000 In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix
CVE-2026-83548 10.0 4.67% 1 3 template 2026-09-03T13:06:16.053000 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla
CVE-2026-83549 7.8 8.51% 1 2 2026-09-02T18:32:06 Post-authentication Improper Neutralization of Special Elements used in an OS Co
CVE-2026-81573 8.6 0.46% 2 0 2026-09-01T20:56:59.203000 If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configu
CVE-2026-81575 7.5 0.44% 2 0 2026-09-01T20:56:59.203000 If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 acce
CVE-2026-81578 9.8 1.62% 1 2 template 2026-08-31T21:31:56 An improper access control vulnerability exists in the web management interface
CVE-2026-82448 9.8 0.41% 2 0 2026-08-29T15:30:20 Shinobi before commit 5a76c74f contains a hardcoded connection key in the child
CVE-2026-81576 7.7 0.33% 2 0 2026-08-27T12:30:27 If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issu
CVE-2026-81572 7.8 0.17% 2 0 2026-08-27T12:30:27 cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-S
CVE-2026-81574 8.2 0.41% 2 0 2026-08-27T12:30:27 In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitiz
CVE-2026-60004 9.8 86.78% 6 10 2026-08-27T11:41:19.230000 Gitea before 1.27.1 allows remote code execution via the diffpatch API through G
CVE-2026-56368 3.7 0.26% 2 0 2026-08-26T20:48:48 A memory leak vulnerability exists in multiple coders that write raw pixel data
CVE-2026-59310 9.8 45.88% 2 2 2026-08-18T18:32:52 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-72898 10.0 94.22% 1 9 template 2026-08-12T15:18:30.347000 Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via t
CVE-2026-62721 7.8 0.41% 2 0 2026-08-11T18:31:23 Insufficient granularity of access control in User-Mode Power Service (UMPS) all
CVE-2026-61511 9.8 70.77% 1 5 2026-08-07T06:31:24 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul
CVE-2026-62946 5.1 0.09% 2 0 2026-08-03T16:19:22.763000 ImageMagick is free and open-source software used for editing and manipulating d
CVE-2026-46331 7.8 0.58% 1 15 2026-07-23T12:33:27 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-4986 5.3 0.20% 1 2 2026-07-23T08:10:00.137000 The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity o
CVE-2026-49176 7.8 0.47% 1 2 2026-07-22T16:17:28.753000 Improper privilege management in Windows WalletService allows an authorized atta
CVE-2026-57130 8.1 0.35% 2 0 2026-07-20T21:26:50 ## Summary The email search tool in `src/praisonai-agents/praisonaiagents/tools
CVE-2026-57126 8.5 0.38% 2 0 2026-07-20T21:25:26 # praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS
CVE-2026-61865 2.9 0.10% 2 0 2026-07-15T18:20:21.237000 ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough li
CVE-2026-61864 2.9 0.10% 2 0 2026-07-15T18:20:21.237000 ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transf
CVE-2026-61863 2.9 0.19% 2 0 2026-07-15T12:32:05 ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in
CVE-2026-61866 2.9 0.19% 2 0 2026-07-15T12:32:05 ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG enco
CVE-2026-50458 7.8 0.26% 1 0 2026-07-14T18:32:25 Use after free in Microsoft Brokering File System allows an authorized attacker
CVE-2026-56373 3.7 0.23% 2 0 2026-07-13T15:15:51.143000 ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB d
CVE-2026-61857 3.7 0.27% 2 0 2026-07-11T15:30:30 ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused
CVE-2026-61870 2.9 0.19% 2 0 2026-07-11T15:30:30 ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF enc
CVE-2026-61465 3.3 0.17% 2 0 2026-07-11T15:30:29 ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed mem
CVE-2026-56366 3.3 0.17% 2 0 2026-07-10T15:31:48 ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META rea
CVE-2026-57239 8.2 0.17% 1 1 2026-07-09T15:33:27 The user-controllable executable files will be directly executed by high-privile
CVE-2026-56371 5.3 0.26% 2 0 2026-07-02T15:17:07.390000 ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c
CVE-2026-56379 None 0.88% 2 0 2026-06-30T03:38:15 ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerabi
CVE-2026-56370 3.3 0.12% 2 0 2026-06-26T21:50:37.890000 ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in Co
CVE-2026-47203 None 0.45% 2 0 2026-06-26T21:32:44 ### Impact **CVSSv4 Baseline Score:** Moderate 6.3 **CVSSv4 Weighted Score:**
CVE-2026-45051 None 0.69% 2 0 2026-06-24T17:25:29 ## Summary **Description** A deserialization of untrusted data vulnerability (
CVE-2026-56378 3.7 0.22% 2 0 2026-06-21T15:31:31 ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bo
CVE-2026-4201 7.3 0.28% 1 0 2026-06-17T10:56:10.603000 A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040f
CVE-2026-28993 5.5 0.12% 2 0 2026-06-17T10:29:27.873000 This issue was addressed by adding an additional prompt for user consent. This i
CVE-2026-27540 9.0 1.73% 3 1 2026-06-17T10:27:18.693000 Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co P
CVE-2025-30208 5.3 74.97% 2 23 2026-06-17T09:08:21.517000 Vite, a provider of frontend development tooling, has a vulnerability in version
CVE-2024-45811 4.8 1.06% 2 0 2026-06-17T07:54:51.767000 Vite a frontend build tooling framework for javascript. In affected versions the
CVE-2024-3094 10.0 85.97% 1 90 2026-06-17T07:43:17.830000 Malicious code was discovered in the upstream tarballs of xz, starting with vers
CVE-2024-1813 9.8 1.22% 1 1 2026-06-17T07:05:03.993000 The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection
CVE-2023-38198 9.8 1.08% 2 0 2026-06-17T06:09:38.793000 acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as e
CVE-2026-39987 9.8 98.95% 4 25 2026-04-27T16:30:09 ## Summary Marimo (19.6k stars) has a Pre-Auth RCE vulnerability. The terminal
CVE-2026-39364 None 2.00% 8 0 2026-04-07T22:16:19 ### Summary The contents of files that are specified by [`server.fs.deny`](http
CVE-2026-2275 9.6 0.44% 1 0 2026-03-31T18:32:38 The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach
CVE-2025-31125 5.3 58.46% 2 7 2026-01-22T21:47:41 ### Summary The contents of arbitrary files can be returned to the browser. ##
CVE-2021-44228 10.0 100.00% 1 100 2025-10-22T19:13:26 # Summary Log4j versions prior to 2.16.0 are subject to a remote code execution
CVE-2026-87886 0 0.00% 5 0 N/A
CVE-2026-90711 0 0.19% 4 0 N/A
CVE-2026-61642 0 0.00% 2 0 N/A
CVE-2026-85498 0 0.00% 2 0 N/A
CVE-2026-88065 0 0.00% 2 0 N/A
CVE-2026-63443 0 0.00% 2 0 N/A
CVE-2026-51990 0 0.00% 6 1 N/A
CVE-2026-57586 0 0.00% 2 0 N/A
CVE-2026-65838 0 0.27% 2 0 N/A
CVE-2026-63030 0 97.27% 1 85 template N/A

CVE-2026-92178
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-16T04:19:00.327000

2 posts

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF

thehackerwire@mastodon.social at 2026-09-15T19:59:59.000Z ##

🟠 CVE-2026-92178 - High (7.8)

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T19:59:59.000Z ##

🟠 CVE-2026-92178 - High (7.8)

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92177
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-16T04:18:59.817000

2 posts

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of P

thehackerwire@mastodon.social at 2026-09-15T19:59:48.000Z ##

🟠 CVE-2026-92177 - High (7.8)

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T19:59:48.000Z ##

🟠 CVE-2026-92177 - High (7.8)

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63695
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T04:18:37.990000

2 posts

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.

thehackerwire@mastodon.social at 2026-09-15T16:01:02.000Z ##

🔴 CVE-2026-63695 - Critical (9.8)

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T16:01:02.000Z ##

🔴 CVE-2026-63695 - Critical (9.8)

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12793
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T04:17:56.110000

2 posts

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for un

offseq at 2026-09-16T04:30:24.617Z ##

CVE-2026-12793: CRITICAL privilege escalation in JetFormBuilder Dynamic Blocks Form Builder (<=3.6.2). Unauthenticated attackers can create admin accounts. Restrict access & monitor until patch. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-16T04:30:24.000Z ##

CVE-2026-12793: CRITICAL privilege escalation in JetFormBuilder Dynamic Blocks Form Builder (<=3.6.2). Unauthenticated attackers can create admin accounts. Restrict access & monitor until patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202612793 #Infosec

##

CVE-2026-15640(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-16T00:31:41

2 posts

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

offseq at 2026-09-16T01:30:23.928Z ##

Delinea Secret Server (On-Prem, v10.5.0 – 12.1.3) hit by CRITICAL auth bypass (CVE-2026-15640). SAML spoofing may allow attacker impersonation. Patch info not yet available. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-16T01:30:23.000Z ##

Delinea Secret Server (On-Prem, v10.5.0 – 12.1.3) hit by CRITICAL auth bypass (CVE-2026-15640). SAML spoofing may allow attacker impersonation. Patch info not yet available. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Delinea #CVE202615640

##

CVE-2026-92248
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-16T00:31:36

2 posts

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent hea

thehackerwire@mastodon.social at 2026-09-16T00:00:19.000Z ##

🟠 CVE-2026-92248 - High (7.8)

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This lea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-16T00:00:19.000Z ##

🟠 CVE-2026-92248 - High (7.8)

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This lea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87289
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-16T00:31:27

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatabl

thehackerwire@mastodon.social at 2026-09-15T21:03:11.000Z ##

🟠 CVE-2026-87289 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T21:03:11.000Z ##

🟠 CVE-2026-87289 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15639
(0 None)

EPSS: 0.00%

updated 2026-09-16T00:17:03.453000

2 posts

An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.

offseq at 2026-09-16T03:00:24.672Z ##

CVE-2026-15639: CRITICAL XSS in Delinea Secret Server (On-Prem, 10.2.19 – 11.9.48). Exploitation allows remote attackers to run JS in user sessions. Patch status unknown — check vendor advisories. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-16T03:00:24.000Z ##

CVE-2026-15639: CRITICAL XSS in Delinea Secret Server (On-Prem, 10.2.19 – 11.9.48). Exploitation allows remote attackers to run JS in user sessions. Patch status unknown — check vendor advisories. radar.offseq.com/threat/cve-20 #OffSeq #XSS #Vuln #Delinea #Cybersecurity

##

CVE-2026-85893
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-15T23:19:12.110000

2 posts

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-09-16T00:00:00.000Z ##

🟠 CVE-2026-85893 - High (8.8)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-16T00:00:00.000Z ##

🟠 CVE-2026-85893 - High (8.8)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69486
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-15T23:17:41.633000

2 posts

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-09-16T00:00:09.000Z ##

🟠 CVE-2026-69486 - High (8.8)

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-16T00:00:09.000Z ##

🟠 CVE-2026-69486 - High (8.8)

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73807
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-15T22:16:58.683000

4 posts

The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.

DailyCyberSecurity at 2026-09-16T02:09:47.256Z ##

Discover the latest mySCADA myPRO Manager vulnerabilities, including CVE-2026-73807, and learn how to patch your systems to prevent remote attacks.

securityonline.info/myscada-my

##

offseq at 2026-09-16T00:00:36.792Z ##

CVE-2026-73807 | CRITICAL: mySCADA myPRO (v0 – 2.1) API flaw allows unauthenticated access to privileged functions. No patch yet — restrict API network access & monitor logs. radar.offseq.com/threat/cve-20

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T02:09:47.000Z ##

Discover the latest mySCADA myPRO Manager vulnerabilities, including CVE-2026-73807, and learn how to patch your systems to prevent remote attacks.

#mySCADA #CVE202673807 #Cybersecurity #Vulnerability

securityonline.info/myscada-my

##

offseq@infosec.exchange at 2026-09-16T00:00:36.000Z ##

CVE-2026-73807 | CRITICAL: mySCADA myPRO (v0 – 2.1) API flaw allows unauthenticated access to privileged functions. No patch yet — restrict API network access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #ICS #SCADA #Vulnerability

##

CVE-2026-92000
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-15T21:33:15

2 posts

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.

thehackerwire@mastodon.social at 2026-09-15T22:00:04.000Z ##

🟠 CVE-2026-92000 - High (7.5)

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T22:00:04.000Z ##

🟠 CVE-2026-92000 - High (7.5)

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68070
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-15T21:33:13

2 posts

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

thehackerwire@mastodon.social at 2026-09-15T22:01:10.000Z ##

🟠 CVE-2026-68070 - High (8.8)

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T22:01:10.000Z ##

🟠 CVE-2026-68070 - High (8.8)

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66890
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-15T21:33:13

2 posts

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

thehackerwire@mastodon.social at 2026-09-15T22:00:59.000Z ##

🔴 CVE-2026-66890 - Critical (9.6)

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T22:00:59.000Z ##

🔴 CVE-2026-66890 - Critical (9.6)

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89040
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-15T21:33:13

2 posts

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.

thehackerwire@mastodon.social at 2026-09-15T21:00:33.000Z ##

🔴 CVE-2026-89040 - Critical (9.8)

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T21:00:33.000Z ##

🔴 CVE-2026-89040 - Critical (9.8)

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87288
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-15T21:33:06

2 posts

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidenti

thehackerwire@mastodon.social at 2026-09-15T21:03:00.000Z ##

🟠 CVE-2026-87288 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T21:03:00.000Z ##

🟠 CVE-2026-87288 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87287
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-15T21:33:06

2 posts

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidenti

thehackerwire@mastodon.social at 2026-09-15T21:02:51.000Z ##

🟠 CVE-2026-87287 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T21:02:51.000Z ##

🟠 CVE-2026-87287 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92176
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-15T21:31:29

2 posts

pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of App obj

thehackerwire@mastodon.social at 2026-09-15T20:02:50.000Z ##

🟠 CVE-2026-92176 - High (7.8)

pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T20:02:50.000Z ##

🟠 CVE-2026-92176 - High (7.8)

pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92179
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-15T21:31:29

2 posts

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of P

thehackerwire@mastodon.social at 2026-09-15T20:00:10.000Z ##

🟠 CVE-2026-92179 - High (7.8)

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T20:00:10.000Z ##

🟠 CVE-2026-92179 - High (7.8)

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92180
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-15T21:31:25

2 posts

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific fl

thehackerwire@mastodon.social at 2026-09-15T20:02:40.000Z ##

🟠 CVE-2026-92180 - High (7.8)

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T20:02:40.000Z ##

🟠 CVE-2026-92180 - High (7.8)

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91939
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-15T21:16:48.957000

2 posts

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.

thehackerwire@mastodon.social at 2026-09-15T22:00:14.000Z ##

🔴 CVE-2026-91939 - Critical (9.8)

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T22:00:14.000Z ##

🔴 CVE-2026-91939 - Critical (9.8)

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88975
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-15T20:19:19.943000

2 posts

Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthenticated peer can declare a payload near 16 MiB on a connection where Ember advertised 16 KiB and either complete or slowly stream it, causing up to 1024-fol

thehackerwire@mastodon.social at 2026-09-15T21:00:43.000Z ##

🟠 CVE-2026-88975 - High (7.5)

Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T21:00:43.000Z ##

🟠 CVE-2026-88975 - High (7.5)

Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87286
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-15T20:19:18.560000

2 posts

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidenti

thehackerwire@mastodon.social at 2026-09-15T21:00:53.000Z ##

🟠 CVE-2026-87286 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T21:00:53.000Z ##

🟠 CVE-2026-87286 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76670
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-15T20:17:48.833000

2 posts

Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.

DailyCyberSecurity at 2026-09-16T02:03:44.877Z ##

A critical HPE EdgeConnect authorization bypass (CVE-2026-76670) enables full system compromise. Patch this HPE EdgeConnect authorization bypass now.

securityonline.info/hpe-edgeco

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T02:03:44.000Z ##

A critical HPE EdgeConnect authorization bypass (CVE-2026-76670) enables full system compromise. Patch this HPE EdgeConnect authorization bypass now.

#HPE #EdgeConnect #AuthorizationBypass #CVE202676670 #Cybersecurity

securityonline.info/hpe-edgeco

##

CVE-2026-90606
(9.9 CRITICAL)

EPSS: 0.49%

updated 2026-09-15T19:17:46.067000

3 posts

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

offseq@infosec.exchange at 2026-09-14T06:00:25.000Z ##

CVE-2026-90606: HIGH-severity buffer overflow in Totolink A3002MU Hh-B20211125.1046 (boa/formIpv6Setup). Public exploit disclosed. RCE or DoS possible. Restrict access & monitor IPv6 setup. No patch yet. radar.offseq.com/threat/a-secu #OffSeq #Vuln #IoTSecurity #BufferOverflow

##

thehackerwire@mastodon.social at 2026-09-14T01:01:03.000Z ##

🔴 CVE-2026-90606 - Critical (9.9)

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer ov...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-14T00:00:35.000Z ##

CVE-2026-90606: CRITICAL buffer overflow in Totolink A3002MU (Hh-B20211125.1046). Remote attackers can exploit static_ipv6 in /boafrm/formIpv6Setup. Exploit is public — review device exposure now. radar.offseq.com/threat/cve-20 #OffSeq #CVE202690606 #RouterSecurity #NetSec

##

CVE-2026-69213
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-15T19:17:38.317000

2 posts

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can continue sending PING, SETTINGS, or DATA frames that cause Ember to enqueue acknowledgments or WINDOW_UPDATE frames faster than the writer drains them, exhausting h

thehackerwire@mastodon.social at 2026-09-15T20:03:00.000Z ##

🟠 CVE-2026-69213 - High (7.5)

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can continue se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T20:03:00.000Z ##

🟠 CVE-2026-69213 - High (7.5)

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can continue se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89026
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-15T18:32:43

4 posts

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, c

rxerium at 2026-09-15T18:03:42.870Z ##

Thank you to @vulncheck for the smooth collaboration throughout the CNA process.

More details:
cve.org/CVERecord?id=CVE-2026-

##

thehackerwire@mastodon.social at 2026-09-15T18:01:18.000Z ##

🔴 CVE-2026-89026 - Critical (9.8)

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

rxerium@infosec.exchange at 2026-09-15T18:03:42.000Z ##

Thank you to @vulncheck for the smooth collaboration throughout the CNA process.

More details:
cve.org/CVERecord?id=CVE-2026-

##

thehackerwire@mastodon.social at 2026-09-15T18:01:18.000Z ##

🔴 CVE-2026-89026 - Critical (9.8)

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91990
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-15T18:32:43

2 posts

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.

thehackerwire@mastodon.social at 2026-09-15T17:00:03.000Z ##

🟠 CVE-2026-91990 - High (7.5)

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T17:00:03.000Z ##

🟠 CVE-2026-91990 - High (7.5)

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76441
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-09-15T18:32:19

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76441 are related to i

AAKL at 2026-09-14T16:42:45.394Z ##

Welcome to Monday and two new advisories from Cisco.

CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability sec.cloudapps.cisco.com/securi

Two more critical vulnerabilities on the 9th and the 11th sec.cloudapps.cisco.com/securi @TalosSecurity

@cR0w

##

AAKL@infosec.exchange at 2026-09-14T16:42:45.000Z ##

Welcome to Monday and two new advisories from Cisco.

CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability sec.cloudapps.cisco.com/securi

Two more critical vulnerabilities on the 9th and the 11th sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

@cR0w

##

CVE-2026-20353
(9.8 CRITICAL)

EPSS: 0.37%

updated 2026-09-15T18:32:19

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20353 are related to i

AAKL at 2026-09-14T16:42:45.394Z ##

Welcome to Monday and two new advisories from Cisco.

CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability sec.cloudapps.cisco.com/securi

Two more critical vulnerabilities on the 9th and the 11th sec.cloudapps.cisco.com/securi @TalosSecurity

@cR0w

##

AAKL@infosec.exchange at 2026-09-14T16:42:45.000Z ##

Welcome to Monday and two new advisories from Cisco.

CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability sec.cloudapps.cisco.com/securi

Two more critical vulnerabilities on the 9th and the 11th sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

@cR0w

##

CVE-2026-20275
(8.8 HIGH)

EPSS: 0.18%

updated 2026-09-15T18:32:14

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20275 are related to incorrect calculation issues that are group

AAKL at 2026-09-15T15:50:22.060Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official

##

AAKL@infosec.exchange at 2026-09-15T15:50:22.000Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

##

CVE-2026-90703
(9.1 CRITICAL)

EPSS: 2.80%

updated 2026-09-15T18:19:38.113000

1 posts

A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

offseq@infosec.exchange at 2026-09-14T10:30:25.000Z ##

D-Link DWR-M921 v1.1.52 is vulnerable to CRITICAL OS command injection (CVE-2026-90703, CVSS 9.4). No patch yet, public exploit out. Restrict access & monitor logs. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #RouterSecurity #Infosec

##

CVE-2026-76440
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-09-15T18:19:12.950000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76440 are related to

AAKL at 2026-09-14T16:42:45.394Z ##

Welcome to Monday and two new advisories from Cisco.

CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability sec.cloudapps.cisco.com/securi

Two more critical vulnerabilities on the 9th and the 11th sec.cloudapps.cisco.com/securi @TalosSecurity

@cR0w

##

AAKL@infosec.exchange at 2026-09-14T16:42:45.000Z ##

Welcome to Monday and two new advisories from Cisco.

CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability sec.cloudapps.cisco.com/securi

Two more critical vulnerabilities on the 9th and the 11th sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

@cR0w

##

CVE-2026-59160
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-15T18:17:26.587000

2 posts

Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in packages/turbo-graph-ui/app/api/run/route.ts has no authentication, authorization, CSRF protection, or task allowlist. The

thehackerwire@mastodon.social at 2026-09-15T18:01:29.000Z ##

🟠 CVE-2026-59160 - High (8.8)

Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T18:01:29.000Z ##

🟠 CVE-2026-59160 - High (8.8)

Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20276
(8.6 HIGH)

EPSS: 0.25%

updated 2026-09-15T18:17:18.607000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issu

AAKL at 2026-09-15T15:50:22.060Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official

##

AAKL@infosec.exchange at 2026-09-15T15:50:22.000Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

##

CVE-2026-20274
(9.8 CRITICAL)

EPSS: 0.67%

updated 2026-09-15T18:17:18.240000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are

AAKL at 2026-09-15T15:50:22.060Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official

##

AAKL@infosec.exchange at 2026-09-15T15:50:22.000Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

##

CVE-2026-91985
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-15T17:17:44.127000

2 posts

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.

thehackerwire@mastodon.social at 2026-09-15T17:00:15.000Z ##

🟠 CVE-2026-91985 - High (7.5)

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T17:00:15.000Z ##

🟠 CVE-2026-91985 - High (7.5)

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91989
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-15T16:17:58.010000

2 posts

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path containment checks by including '../' segments in requests to the DashboardHandler.do_GET endpoint to access files outside the intended agents_root directory.

thehackerwire@mastodon.social at 2026-09-15T16:59:53.000Z ##

🟠 CVE-2026-91989 - High (7.5)

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path conta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T16:59:53.000Z ##

🟠 CVE-2026-91989 - High (7.5)

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path conta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63696
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-15T15:32:20

2 posts

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

thehackerwire@mastodon.social at 2026-09-15T16:01:34.000Z ##

🔴 CVE-2026-63696 - Critical (9.1)

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T16:01:34.000Z ##

🔴 CVE-2026-63696 - Critical (9.1)

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89025
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-15T15:32:20

2 posts

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. T

thehackerwire@mastodon.social at 2026-09-15T16:00:52.000Z ##

🟠 CVE-2026-89025 - High (7.5)

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specif...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T16:00:52.000Z ##

🟠 CVE-2026-89025 - High (7.5)

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specif...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91001
(9.9 CRITICAL)

EPSS: 0.48%

updated 2026-09-15T15:17:30.983000

4 posts

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

thehackerwire@mastodon.social at 2026-09-15T10:04:12.000Z ##

🔴 CVE-2026-91001 - Critical (9.9)

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-15T06:00:26.004Z ##

Stack-based buffer overflow (CVE-2026-91001, CVSS 9.4) in D-Link DI-8400 (16.07) exposes devices to RCE. Exploit code is public. Restrict management access until fix. Details: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-15T10:04:12.000Z ##

🔴 CVE-2026-91001 - Critical (9.9)

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-15T06:00:26.000Z ##

Stack-based buffer overflow (CVE-2026-91001, CVSS 9.4) in D-Link DI-8400 (16.07) exposes devices to RCE. Exploit code is public. Restrict management access until fix. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202691001 #IoTSecurity #Vulnerability

##

CVE-2026-89308
(0 None)

EPSS: 0.00%

updated 2026-09-15T13:16:45.543000

2 posts

An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.

offseq at 2026-09-15T12:00:26.360Z ##

CVE-2026-89308 in TREXOM TrxTimeATTENDANCE (v1.0.5 – 1.9.5): CRITICAL OS command injection in ping.php allows unauthenticated RCE. Remediate ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-15T12:00:26.000Z ##

CVE-2026-89308 in TREXOM TrxTimeATTENDANCE (v1.0.5 – 1.9.5): CRITICAL OS command injection in ping.php allows unauthenticated RCE. Remediate ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202689308 #infosec #vuln #remediation

##

CVE-2026-76461
(9.8 CRITICAL)

EPSS: 2.16%

updated 2026-09-15T12:47:32.497000

43 posts

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that co

3 repos

https://github.com/fevar54/CVE-2026-76461-Detection-Kit-

https://github.com/0xBlackash/CVE-2026-76461

https://github.com/HORKimhab/CVE-2026-76461

threatnoir at 2026-09-16T02:05:58.455Z ##

⚠️ CRITICAL: Cisco warns customers of actively exploited zero-day in email gateways

Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabili…

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir at 2026-09-16T02:05:54.039Z ##

⚠️ CRITICAL: Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco Secure Email Gateway has a critical zero-day (CVE-2026-76461) that allows unauthenticated attackers to execute arbitrary commands as root via malicious SQL in crafted emails. This is actively exploited in the wild. Any organization running SEG is at immediate risk of full compromise.

threatnoir.com/focus

🤖 AI generated summary

##

sayzard@mastodon.sayzard.org at 2026-09-16T01:39:03.000Z ##

Cisco email security boxes can be rooted by an email

Cisco Secure Email Gateway의 AsyncOS에서 수신 이메일 처리 취약점(CVE-2026-76461)이 악용되고 있으며, 인증 없이 조작된 이메일 하나로 어플라이언스의 root 권한 명령 실행이 가능하다. CVSS는 9.8이고 물리·가상 어플라이언스 구성과 무관하게 영향을 받으며, 우회책이 없어 패치가 유일한 대응이다. 침해 후 공격자는 로컬 로그를 변조해 흔적을 지울 수 있으므로 게이트웨이 로그뿐 아니라 네트워크·방화벽 로그를 함께 조사해야 한다. Cisco는 AsyncO...

theregister.com/security/2026/

##

undercodenews@mastodon.social at 2026-09-15T22:35:16.000Z ##

Cisco Secure Email Gateway Zero-Day Under Active Attack: Critical CVE-2026-76461 Puts Root-Level Access at Risk + Video

A Critical Warning for Cisco Customers A serious cybersecurity warning is unfolding around Cisco Secure Email Gateway after Cisco disclosed active exploitation of CVE-2026-76461, a critical zero-day vulnerability that can allow an unauthenticated remote attacker to execute commands with root privileges. The vulnerability has also been added to the…

undercodenews.com/cisco-secure

##

Matchbook3469@mastodon.social at 2026-09-15T19:34:02.000Z ##

🔵 THREAT INTELLIGENCE

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Vulnerability | CRITICAL
CVEs: CVE-2026-76461

Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]

Full analysis:
yazoul.net/news/article/cisco-

by Yazoul AI

#CyberSecurity #APT #CyberNews

##

Analyst207@mastodon.social at 2026-09-15T18:03:19.000Z ##

Cisco Discloses Actively Exploited Zero-Day in Email Gateways

A critical zero-day vulnerability, CVE-2026-76461, is under active exploitation, allowing hackers to remotely execute commands as root on Cisco Secure Email Gateway appliances with just a simple email. This gaping security hole gives attackers total control of the gateway, putting your email security at risk.

osintsights.com/cisco-disclose

#ZeroDay #Cve202676461 #Cisco #EmailGateway #RemoteCodeExecution

##

netsecio@mastodon.social at 2026-09-15T17:12:32.000Z ##

📰 Cisco Patches Actively Exploited Zero-Day in Secure Email Gateways

Cisco patches critical, actively exploited zero-day (CVE-2026-76461) in Secure Email Gateways. Unauthenticated attackers can compromise devices via a crafted email. CISA has added it to the KEV catalog. #CyberSecurity #ZeroDay #Infosec #Cisco

🔗 cyber.netsecops.io/articles/ci

##

youranonnewsirc@nerdculture.de at 2026-09-15T16:26:27.000Z ##

Geopolitical tensions: A Russian drone struck a Kyiv-Warsaw train near the Polish border (Sept 13), and Houthi forces secured Yemen's Red Sea coast (Sept 11), affecting maritime routes. Tech news: Apple's Siri AI, powered by Apple Intelligence, began its beta rollout (Sept 14). Cybersecurity: Cisco warned of active exploitation of a critical Secure Email Gateway flaw (CVE-2026-76461) (Sept 15), and Anthropic reported Russia-linked spies used its AI Claude for hacking campaigns.

#Cybersecurity #Geopolitics #TechNews

##

thecybermind at 2026-09-15T16:25:35.618Z ##

Actionable C-Suite threat intelligence and mitigation strategies for CVE-2026-76461, addressing active SQL injection exploitation vectors within enterprise Cisco Secure Email Gateway infrastructures. thecybermind.co/r5ry

##

Analyst207@mastodon.social at 2026-09-15T16:03:31.000Z ##

Cisco Email Gateways Exploited by Malicious Emails

A single malicious email can wreak havoc on your Cisco Secure Email Gateway, thanks to a critical vulnerability (CVE-2026-76461) that allows hackers to gain root access with a 9.8 CVSS score - and patching is the only fix.

osintsights.com/cisco-email-ga

#Cisco #Cve202676461 #EmailGateway #SecureEmailGateway #Vulnerability

##

AAKL at 2026-09-15T15:50:22.060Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official

##

undercodenews@mastodon.social at 2026-09-15T13:47:25.000Z ##

Cisco Secure Email Gateway Zero-Day CVE-2026-76461: Critical 98 Flaw Is Already Being Exploited in the Wild + Video

A Dangerous New Threat Hiding Inside Email Traffic Email security appliances are supposed to stand between organizations and malicious messages. This time, however, attackers are using the email-processing function itself as the entry point. Cisco has disclosed CVE-2026-76461, a critical SQL-injection vulnerability in Cisco Secure Email Gateway appliances…

undercodenews.com/cisco-secure

##

Matchbook3469@mastodon.social at 2026-09-15T12:02:26.000Z ##

🔴 New security advisory:

CVE-2026-76461 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#CVE #PatchNow #InfoSecCommunity

##

undercodenews@mastodon.social at 2026-09-15T10:58:52.000Z ##

Cisco Secure Email Gateway Hit by Critical Zero-Day as Attackers Gain Root Access Through Malicious Emails + Video

A Dangerous New Cisco Zero-Day A critical zero-day vulnerability in Cisco Secure Email Gateway has moved from a theoretical security concern into an active incident, with Cisco confirming exploitation in the wild. Tracked as CVE-2026-76461, the flaw carries a CVSS score of 9.8 and can allow an unauthenticated remote attacker to execute arbitrary commands…

undercodenews.com/cisco-secure

##

undercodenews@mastodon.social at 2026-09-15T10:33:18.000Z ##

Cisco Secure Email Gateway Zero-Day Exploited in the Wild: Critical CVE-2026-76461 Gives Attackers a Path to Root + Video

A New Cisco Security Crisis Is Unfolding A serious security warning has emerged for organizations relying on Cisco Secure Email Gateway. Cisco has confirmed that CVE-2026-76461, a critical SQL injection vulnerability in Cisco AsyncOS, is being actively exploited in the wild. The flaw can allow a remote, unauthenticated attacker to send a specially…

undercodenews.com/cisco-secure

##

cyberveille@mastobot.ping.moi at 2026-09-15T09:00:06.000Z ##

📢 [VULN] ⚠️Injection SQL exploitée dans Cisco Secure Email Gateway - CVE-2026-76461

Le 14 septembre 2026 à 16 h 00 UTC, Cisco a publié deux avis de sécurité sur sa passerelle de messagerie.

🔗 blog.marcfredericgomez.fr/inje
💬 discussion : infosec.pub/post/52317366
#CVE #Cyberveille

##

ottoto2017@prattohome.com at 2026-09-15T08:14:44.000Z ##

「Ciscoのセキュアメールゲートウェイの脆弱性が実際に悪用され、ルート権限でのコマンド実行が可能になる 」: #TheHackerNews

「スコは、Cisco Secure Email Gateway向けAsyncOSソフトウェアに影響を与える新たな重大な脆弱性が、実際に悪用されていると警告した。

CVE-2026-76461 として追跡されているこの脆弱性は 、CVSSスコアが10.0点満点中9.8点です。これは、メール解析ロジックにおける検証の不備が原因で、認証されていないリモート攻撃者が、基盤となるオペレーティングシステム上でroot権限で任意のコマンドを実行できる可能性があるとされています。

シスコは月曜日の勧告で、「攻撃者は、悪意のあるSQL文を含む細工された電子メールメッセージを影響を受けるデバイスに送信することで、この脆弱性を悪用する可能性がある」 と述べた 。」

thehackernews.com/2026/09/cisc

#prattohome

##

Analyst207@mastodon.social at 2026-09-15T07:33:31.000Z ##

Cisco Discloses Zero-Day Exploited in Secure Email Gateway Attacks

Cisco has warned of a zero-day flaw in its Secure Email Gateway that allows attackers to run commands as root, prompting federal agencies to patch the vulnerability within just three days. This critical defect, tracked as CVE-2026-76461, lets hackers execute arbitrary commands with root privileges, putting systems at risk.

osintsights.com/cisco-disclose

#ZeroDay #SecureEmailGateway #Cve202676461 #EmergingThreats #Cisco

##

Analyst207@mastodon.social at 2026-09-15T07:03:21.000Z ##

Cisco Email Gateway Flaw Exploited, Enables Root Command Execution

A critical Cisco email gateway flaw, CVE-2026-76461, with a near-perfect CVSS score of 9.8, is being actively exploited in the wild, allowing attackers to send a single crafted email and gain root command execution on vulnerable devices. This severe vulnerability stems from insufficient validation in AsyncOS email parsing, making it…

osintsights.com/cisco-email-ga

#Cisco #Cve202676461 #EmailGateway #RemoteCodeExecution #SupplyChain

##

undercodenews@mastodon.social at 2026-09-15T06:47:21.000Z ##

Cisco Secure Email Gateway Zero-Day Under Active Attack as Root-Level Access Puts Defenders on High Alert + Video

A Critical Warning for Email Security Teams Cisco has confirmed that a critical vulnerability in Cisco Secure Email Gateway is being actively exploited in the wild, turning a security weakness inside email-processing logic into a potential gateway for complete operating-system compromise. Tracked as CVE-2026-76461, the flaw carries a CVSS score of 9.8,…

undercodenews.com/cisco-secure

##

offseq at 2026-09-15T03:00:26.099Z ##

CRITICAL (CVSS 9.8): CVE-2026-76461 in Cisco AsyncOS for Secure Email Gateway lets unauthenticated attackers execute commands as root via crafted emails. Patch status unknown — monitor Cisco’s updates. radar.offseq.com/threat/a-vuln

##

DailyCyberSecurity at 2026-09-15T02:18:05.203Z ##

CVE-2026-76461 (CVSS 9.8) is a Cisco Secure Email Gateway vulnerability exploited in the wild. SQL injection grants root command execution. Patch now.

securityonline.info/cve-2026-7

##

ssvc at 2026-09-14T22:16:17.750Z ##

No one else seems to have noticed the Cisco exploited zero-day:

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability

cisa.gov/news-events/alerts/20

##

secdb at 2026-09-14T21:00:30.745Z ##

🚨 [CISA-2026:0914] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-76461 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Email Gateway SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Email Gateway
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

thecybermind at 2026-09-14T20:55:43.327Z ##

CRITICAL CISA KEV ALERT: CVE-2026-76461 targets Cisco Secure Email Gateway via SQL injection, granting root-level RCE. Active exploitation verified. Access our TSUITE brief for SIEM queries and hardening steps to secure your email perimeter.

thecybermind.co/al1f

##

cisakevtracker@mastodon.social at 2026-09-14T20:00:50.000Z ##

CVE ID: CVE-2026-76461
Vendor: Cisco
Product: Secure Email Gateway
Date Added: 2026-09-14
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL at 2026-09-14T16:42:45.394Z ##

Welcome to Monday and two new advisories from Cisco.

CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability sec.cloudapps.cisco.com/securi

Two more critical vulnerabilities on the 9th and the 11th sec.cloudapps.cisco.com/securi @TalosSecurity

@cR0w

##

ssvc at 2026-09-14T16:31:59.297Z ##

ayy lmao Cisco CVE-2026-76461
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.

sec.cloudapps.cisco.com/securi

##

threatnoir@infosec.exchange at 2026-09-16T02:05:58.000Z ##

⚠️ CRITICAL: Cisco warns customers of actively exploited zero-day in email gateways

Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabili…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-16T02:05:54.000Z ##

⚠️ CRITICAL: Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco Secure Email Gateway has a critical zero-day (CVE-2026-76461) that allows unauthenticated attackers to execute arbitrary commands as root via malicious SQL in crafted emails. This is actively exploited in the wild. Any organization running SEG is at immediate risk of full compromise.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

youranonnewsirc@nerdculture.de at 2026-09-15T16:26:27.000Z ##

Geopolitical tensions: A Russian drone struck a Kyiv-Warsaw train near the Polish border (Sept 13), and Houthi forces secured Yemen's Red Sea coast (Sept 11), affecting maritime routes. Tech news: Apple's Siri AI, powered by Apple Intelligence, began its beta rollout (Sept 14). Cybersecurity: Cisco warned of active exploitation of a critical Secure Email Gateway flaw (CVE-2026-76461) (Sept 15), and Anthropic reported Russia-linked spies used its AI Claude for hacking campaigns.

#Cybersecurity #Geopolitics #TechNews

##

thecybermind@infosec.exchange at 2026-09-15T16:25:35.000Z ##

Actionable C-Suite threat intelligence and mitigation strategies for CVE-2026-76461, addressing active SQL injection exploitation vectors within enterprise Cisco Secure Email Gateway infrastructures. thecybermind.co/r5ry

##

AAKL@infosec.exchange at 2026-09-15T15:50:22.000Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

##

cyberveille@mastobot.ping.moi at 2026-09-15T09:00:06.000Z ##

📢 [VULN] ⚠️Injection SQL exploitée dans Cisco Secure Email Gateway - CVE-2026-76461

Le 14 septembre 2026 à 16 h 00 UTC, Cisco a publié deux avis de sécurité sur sa passerelle de messagerie.

🔗 blog.marcfredericgomez.fr/inje
💬 discussion : infosec.pub/post/52317366
#CVE #Cyberveille

##

ottoto2017@prattohome.com at 2026-09-15T08:14:44.000Z ##

「Ciscoのセキュアメールゲートウェイの脆弱性が実際に悪用され、ルート権限でのコマンド実行が可能になる 」: #TheHackerNews

「スコは、Cisco Secure Email Gateway向けAsyncOSソフトウェアに影響を与える新たな重大な脆弱性が、実際に悪用されていると警告した。

CVE-2026-76461 として追跡されているこの脆弱性は 、CVSSスコアが10.0点満点中9.8点です。これは、メール解析ロジックにおける検証の不備が原因で、認証されていないリモート攻撃者が、基盤となるオペレーティングシステム上でroot権限で任意のコマンドを実行できる可能性があるとされています。

シスコは月曜日の勧告で、「攻撃者は、悪意のあるSQL文を含む細工された電子メールメッセージを影響を受けるデバイスに送信することで、この脆弱性を悪用する可能性がある」 と述べた 。」

thehackernews.com/2026/09/cisc

#prattohome

##

offseq@infosec.exchange at 2026-09-15T03:00:26.000Z ##

CRITICAL (CVSS 9.8): CVE-2026-76461 in Cisco AsyncOS for Secure Email Gateway lets unauthenticated attackers execute commands as root via crafted emails. Patch status unknown — monitor Cisco’s updates. radar.offseq.com/threat/a-vuln #OffSeq #Cisco #Vulnerability #EmailSecurity

##

DailyCyberSecurity@infosec.exchange at 2026-09-15T02:18:05.000Z ##

CVE-2026-76461 (CVSS 9.8) is a Cisco Secure Email Gateway vulnerability exploited in the wild. SQL injection grants root command execution. Patch now.

#Cisco #EmailSecurity #CVE202676461 #SQLInjection #RCE #ExploitedInTheWild #AsyncOS #InfoSec #PatchNow #RootAccess

securityonline.info/cve-2026-7

##

ssvc@infosec.exchange at 2026-09-14T22:16:17.000Z ##

Since no one seems to have noticed the Cisco exploited zero-day:

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability

cisa.gov/news-events/alerts/20

#CISA #KEV #Cisco #zeroday #CVE

##

secdb@infosec.exchange at 2026-09-14T21:00:30.000Z ##

🚨 [CISA-2026:0914] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-76461 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Email Gateway SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Email Gateway
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260914 #cisa20260914 #cve_2026_76461 #cve202676461

##

thecybermind@infosec.exchange at 2026-09-14T20:55:43.000Z ##

CRITICAL CISA KEV ALERT: CVE-2026-76461 targets Cisco Secure Email Gateway via SQL injection, granting root-level RCE. Active exploitation verified. Access our TSUITE brief for SIEM queries and hardening steps to secure your email perimeter.

thecybermind.co/al1f

##

cisakevtracker@mastodon.social at 2026-09-14T20:00:50.000Z ##

CVE ID: CVE-2026-76461
Vendor: Cisco
Product: Secure Email Gateway
Date Added: 2026-09-14
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-09-14T16:42:45.000Z ##

Welcome to Monday and two new advisories from Cisco.

CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability sec.cloudapps.cisco.com/securi

Two more critical vulnerabilities on the 9th and the 11th sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

@cR0w

##

ssvc@infosec.exchange at 2026-09-14T16:31:59.000Z ##

ayy lmao Cisco CVE-2026-76461
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.

sec.cloudapps.cisco.com/securi

#cve #cisco #zeroday #eitw

##

CVE-2026-91995
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-15T12:17:54.943000

2 posts

pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.

offseq at 2026-09-15T13:30:26.442Z ##

pig-mesh pig <4.1.0 hit by CRITICAL vuln (CVE-2026-91995, CVSS 9.3): remote attackers can reset any account password — admin included — via /register/password auth bypass. Restrict access & monitor logs while awaiting patch. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-15T13:30:26.000Z ##

pig-mesh pig <4.1.0 hit by CRITICAL vuln (CVE-2026-91995, CVSS 9.3): remote attackers can reset any account password — admin included — via /register/password auth bypass. Restrict access & monitor logs while awaiting patch. radar.offseq.com/threat/cve-20 #OffSeq #vulnerability #CVE #infosec

##

CVE-2026-80217
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-15T09:30:39

2 posts

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

thehackerwire@mastodon.social at 2026-09-15T10:04:02.000Z ##

🟠 CVE-2026-80217 - High (8.8)

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T10:04:02.000Z ##

🟠 CVE-2026-80217 - High (8.8)

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77853
(8.8 HIGH)

EPSS: 1.03%

updated 2026-09-15T09:30:39

2 posts

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

thehackerwire@mastodon.social at 2026-09-15T10:03:52.000Z ##

🟠 CVE-2026-77853 - High (8.8)

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T10:03:52.000Z ##

🟠 CVE-2026-77853 - High (8.8)

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75983
(7.5 HIGH)

EPSS: 0.41%

updated 2026-09-15T09:30:38

2 posts

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap` filter and unconditionally returning the always-true `'exist'` primitive for every c

thehackerwire@mastodon.social at 2026-09-15T08:00:29.000Z ##

🟠 CVE-2026-75983 - High (7.5)

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` func...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T08:00:29.000Z ##

🟠 CVE-2026-75983 - High (7.5)

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` func...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91003
(9.1 CRITICAL)

EPSS: 0.51%

updated 2026-09-15T06:30:40

4 posts

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

thehackerwire@mastodon.social at 2026-09-15T08:00:39.000Z ##

🔴 CVE-2026-91003 - Critical (9.1)

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-15T07:30:25.006Z ##

D-Link DI-8300 (fw 16.07) hit by CRITICAL stack buffer overflow (CVE-2026-91003) in /rzgl.asp — remote RCE possible, public exploit code out. Restrict access & monitor traffic until patch. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-15T08:00:39.000Z ##

🔴 CVE-2026-91003 - Critical (9.1)

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-15T07:30:25.000Z ##

D-Link DI-8300 (fw 16.07) hit by CRITICAL stack buffer overflow (CVE-2026-91003) in /rzgl.asp — remote RCE possible, public exploit code out. Restrict access & monitor traffic until patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE202691003 #DLink #Security

##

CVE-2026-90847
(9.1 CRITICAL)

EPSS: 2.18%

updated 2026-09-15T03:30:30

2 posts

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

offseq at 2026-09-15T01:30:24.723Z ##

EFM ipTIME C200E v1.094 suffers CRITICAL OS command injection (CVE-2026-90847, CVSS 9.4) via iux_set.cgi. Remotely exploitable, public exploit available. Restrict device access and monitor. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-15T01:30:24.000Z ##

EFM ipTIME C200E v1.094 suffers CRITICAL OS command injection (CVE-2026-90847, CVSS 9.4) via iux_set.cgi. Remotely exploitable, public exploit available. Restrict device access and monitor. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE

##

CVE-2026-91771
(8.8 HIGH)

EPSS: 0.73%

updated 2026-09-15T02:16:49.680000

2 posts

Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences to write files outside the intended download directory, potentially enabling code execution through modification of shell startup files or Python import p

thehackerwire@mastodon.social at 2026-09-15T04:00:11.000Z ##

🟠 CVE-2026-91771 - High (8.8)

Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T04:00:11.000Z ##

🟠 CVE-2026-91771 - High (8.8)

Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91200
(8.8 HIGH)

EPSS: 0.42%

updated 2026-09-15T00:31:22

2 posts

DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer workstation, enabling code execution.

thehackerwire@mastodon.social at 2026-09-15T00:00:17.000Z ##

🟠 CVE-2026-91200 - High (8.8)

DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T00:00:17.000Z ##

🟠 CVE-2026-91200 - High (8.8)

DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12944
(9.6 CRITICAL)

EPSS: 0.25%

updated 2026-09-15T00:31:21

6 posts

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal services

1 repos

https://github.com/cflowsec/CVE-2026-12944

DailyCyberSecurity at 2026-09-16T01:03:01.753Z ##

A critical Langflow SSRF flaw (CVE-2026-12944) exposes cloud credentials and internal networks. Patch your Langflow OSS servers immediately.

securityonline.info/langflow-s

##

offseq at 2026-09-15T00:00:36.910Z ##

CVE-2026-12944 (CRITICAL, CVSS 9.6) affects IBM Langflow OSS 1.0.0 – 1.10.0. Attackers can execute arbitrary Python as root via SSRF, steal AWS creds, and move laterally. Patch is available — validate remediation. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-14T23:00:59.000Z ##

🔴 CVE-2026-12944 - Critical (9.6)

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T01:03:01.000Z ##

A critical Langflow SSRF flaw (CVE-2026-12944) exposes cloud credentials and internal networks. Patch your Langflow OSS servers immediately.

#Langflow #SSRF #CVE202612944 #CVE202617628 #Cybersecurity

securityonline.info/langflow-s

##

offseq@infosec.exchange at 2026-09-15T00:00:36.000Z ##

CVE-2026-12944 (CRITICAL, CVSS 9.6) affects IBM Langflow OSS 1.0.0 – 1.10.0. Attackers can execute arbitrary Python as root via SSRF, steal AWS creds, and move laterally. Patch is available — validate remediation. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #IBM #CloudSecurity

##

thehackerwire@mastodon.social at 2026-09-14T23:00:59.000Z ##

🔴 CVE-2026-12944 - Critical (9.6)

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65352
(4.3 MEDIUM)

EPSS: 0.25%

updated 2026-09-15T00:31:13

2 posts

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.

mysk@mastodon.social at 2026-09-15T14:41:27.000Z ##

Apple acknowledges fixing the Private Relay bug leaking the IP in the secure release notes of iOS 26.6.1 and macOS 26.6.2.
CVE-2026-65352 was assigned to it

##

mysk@mastodon.social at 2026-09-15T14:41:27.000Z ##

Apple acknowledges fixing the Private Relay bug leaking the IP in the secure release notes of iOS 26.6.1 and macOS 26.6.2.
CVE-2026-65352 was assigned to it

##

CVE-2026-91144
(7.5 HIGH)

EPSS: 0.37%

updated 2026-09-14T22:16:59.053000

2 posts

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.

thehackerwire@mastodon.social at 2026-09-14T23:00:48.000Z ##

🟠 CVE-2026-91144 - High (7.5)

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared ba...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T23:00:48.000Z ##

🟠 CVE-2026-91144 - High (7.5)

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared ba...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82232
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-09-14T21:32:45

2 posts

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort clauses for Task search. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2

DailyCyberSecurity at 2026-09-16T01:52:03.188Z ##

Six Apache Syncope vulnerabilities, including CVE-2026-82232, expose severe identity management flaws. Patch your Apache Syncope servers immediately.

securityonline.info/apache-syn

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T01:52:03.000Z ##

Six Apache Syncope vulnerabilities, including CVE-2026-82232, expose severe identity management flaws. Patch your Apache Syncope servers immediately.

#ApacheSyncope #IdentityManagement #CVE202682232 #Cybersecurity #Vulnerability

securityonline.info/apache-syn

##

CVE-2026-82028
(8.8 HIGH)

EPSS: 0.43%

updated 2026-09-14T21:31:46

2 posts

Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interpolated directly into the FROM clause without parameterization or identifier quoting. Attackers with a self-registered account can substitute arbitrary su

thehackerwire@mastodon.social at 2026-09-14T21:00:35.000Z ##

🟠 CVE-2026-82028 - High (8.8)

Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T21:00:35.000Z ##

🟠 CVE-2026-82028 - High (8.8)

Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53713
(9.1 CRITICAL)

EPSS: 0.41%

updated 2026-09-14T21:17:12.520000

2 posts

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redundant separators before is_critical_path evaluates Lua submitted through EnvoyExtensionPolicy during default Strict validation. Linux resolves a double-s

thehackerwire@mastodon.social at 2026-09-14T23:01:09.000Z ##

🔴 CVE-2026-53713 - Critical (9.1)

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T23:01:09.000Z ##

🔴 CVE-2026-53713 - Critical (9.1)

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15891
(7.5 HIGH)

EPSS: 0.34%

updated 2026-09-14T21:10:41.650000

1 posts

The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result. That macro is a pure expression that does not assign to gw, so gw retained its NULL initializer regardless of the list contents. The code then derefere

thehackerwire@mastodon.social at 2026-09-13T23:59:47.000Z ##

🟠 CVE-2026-15891 - High (7.5)

The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81648
(10.0 CRITICAL)

EPSS: 0.28%

updated 2026-09-14T21:10:17.423000

1 posts

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.

thehackerwire@mastodon.social at 2026-09-14T05:03:02.000Z ##

🔴 CVE-2026-81648 - Critical (10)

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74933
(8.8 HIGH)

EPSS: 0.27%

updated 2026-09-14T21:10:17.423000

1 posts

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.

thehackerwire@mastodon.social at 2026-09-14T04:00:26.000Z ##

🟠 CVE-2026-74933 - High (8.8)

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88793
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-14T21:10:17.423000

1 posts

The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will execute in the session of any user viewing the affected content, including an adminis

thehackerwire@mastodon.social at 2026-09-14T03:02:00.000Z ##

🟠 CVE-2026-88793 - High (8.8)

The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86406
(7.5 HIGH)

EPSS: 0.19%

updated 2026-09-14T21:10:17.423000

1 posts

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged ro

thehackerwire@mastodon.social at 2026-09-13T14:00:58.000Z ##

🟠 CVE-2026-86406 - High (7.5)

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89023
(8.6 HIGH)

EPSS: 0.23%

updated 2026-09-14T21:07:11.883000

2 posts

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stored offer records, delete arbitrary offers by numeric identifier, and access dashboard statistics to disclose bidder contact information, offer details, m

thehackerwire@mastodon.social at 2026-09-14T20:00:08.000Z ##

🟠 CVE-2026-89023 - High (8.6)

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T20:00:08.000Z ##

🟠 CVE-2026-89023 - High (8.6)

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78330
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-14T20:58:48.430000

2 posts

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a valid low-privileges JWT. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, fr

offseq at 2026-09-15T04:30:30.471Z ##

CVE-2026-78330 | CRITICAL: Apache Syncope vuln allows admin escalation if JWKS is exposed and JWT auth used. Affects 3.0.0-M0 – 3.0.16, 4.0.0-M0 – 4.0.7, 4.1.0-M0 – 4.1.2. Upgrade to 4.0.8/4.1.3 to mitigate. Details: radar.offseq.com/threat/incorr

##

offseq@infosec.exchange at 2026-09-15T04:30:30.000Z ##

CVE-2026-78330 | CRITICAL: Apache Syncope vuln allows admin escalation if JWKS is exposed and JWT auth used. Affects 3.0.0-M0 – 3.0.16, 4.0.0-M0 – 4.0.7, 4.1.0-M0 – 4.1.2. Upgrade to 4.0.8/4.1.3 to mitigate. Details: radar.offseq.com/threat/incorr #OffSeq #Vulnerability #ApacheSyncope

##

CVE-2026-90680
(9.9 CRITICAL)

EPSS: 0.51%

updated 2026-09-14T20:56:48.220000

1 posts

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.

thehackerwire@mastodon.social at 2026-09-14T05:00:51.000Z ##

🔴 CVE-2026-90680 - Critical (9.9)

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90607
(9.9 CRITICAL)

EPSS: 0.47%

updated 2026-09-14T20:56:48.220000

2 posts

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.

thehackerwire@mastodon.social at 2026-09-14T03:01:46.000Z ##

🔴 CVE-2026-90607 - Critical (9.9)

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-14T03:00:25.000Z ##

Totolink A3002MU routers hit by CRITICAL (CVSS 9.4) buffer overflow (CVE-2026-90607) in formNewSchedule. Public exploit code available. Restrict remote access & monitor systems until a patch is released. radar.offseq.com/threat/cve-20 #OffSeq #CVE202690607 #RouterSecurity #Infosec

##

CVE-2026-90510
(8.3 HIGH)

EPSS: 0.29%

updated 2026-09-14T20:56:48.220000

1 posts

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key . The attack is possible to b

thehackerwire@mastodon.social at 2026-09-13T14:00:49.000Z ##

🟠 CVE-2026-90510 - High (8.3)

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/drom...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73496
(7.7 HIGH)

EPSS: 0.33%

updated 2026-09-14T20:16:50.833000

2 posts

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassian/confluence/attachments.py upload_attachment, and the jira_update_issue attachments parameter reaches src/mcp_atlassian/jira/attachments.py upload_at

thehackerwire@mastodon.social at 2026-09-14T21:00:46.000Z ##

🟠 CVE-2026-73496 - High (7.7)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T21:00:46.000Z ##

🟠 CVE-2026-73496 - High (7.7)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91080
(7.5 HIGH)

EPSS: 0.59%

updated 2026-09-14T19:18:14.500000

2 posts

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signatures to trigger out-of-memory conditions and crash the service.

thehackerwire@mastodon.social at 2026-09-14T20:00:27.000Z ##

🟠 CVE-2026-91080 - High (7.5)

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T20:00:27.000Z ##

🟠 CVE-2026-91080 - High (7.5)

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59178
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-09-14T19:17:37.617000

2 posts

ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legacy `esphome` dashboard, read the bare `$USERNAME` and `$PASSWORD` instead. When the env vars were renamed the bare names were dropped with no fallback, so

thehackerwire@mastodon.social at 2026-09-14T20:00:17.000Z ##

🔴 CVE-2026-59178 - Critical (9.8)

ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T20:00:17.000Z ##

🔴 CVE-2026-59178 - Critical (9.8)

ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91079
(8.5 HIGH)

EPSS: 0.35%

updated 2026-09-14T18:31:35

2 posts

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to internal metadata services and network hosts.

thehackerwire@mastodon.social at 2026-09-14T19:01:55.000Z ##

🟠 CVE-2026-91079 - High (8.5)

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T19:01:55.000Z ##

🟠 CVE-2026-91079 - High (8.5)

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90946
(7.5 HIGH)

EPSS: 0.57%

updated 2026-09-14T18:31:29

2 posts

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including Python, JavaScript, YAML, and JSON files containing hardcoded secrets and credentials.

thehackerwire@mastodon.social at 2026-09-14T19:01:45.000Z ##

🟠 CVE-2026-90946 - High (7.5)

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T19:01:45.000Z ##

🟠 CVE-2026-90946 - High (7.5)

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85921
(8.2 HIGH)

EPSS: 0.26%

updated 2026-09-14T18:31:29

2 posts

Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

AAKL at 2026-09-14T17:40:55.319Z ##

Looks like Microsoft has a couple of new flaws.

NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerabilityhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921

NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerability New msrc.microsoft.com/update-guid

##

AAKL@infosec.exchange at 2026-09-14T17:40:55.000Z ##

Looks like Microsoft has a couple of new flaws.

NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerabilityhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921

NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerability New msrc.microsoft.com/update-guid #infosec #Microsoft #vulnerability #Windows

##

CVE-2026-90945
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-14T18:31:28

4 posts

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.

thehackerwire@mastodon.social at 2026-09-14T19:01:34.000Z ##

🔴 CVE-2026-90945 - Critical (9.8)

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w at 2026-09-14T18:49:58.905Z ##

Go fuck with some crawlers.

nvd.nist.gov/vuln/detail/cve-2

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.

##

thehackerwire@mastodon.social at 2026-09-14T19:01:34.000Z ##

🔴 CVE-2026-90945 - Critical (9.8)

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-09-14T18:49:58.000Z ##

Go fuck with some crawlers.

nvd.nist.gov/vuln/detail/cve-2

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.

##

CVE-2026-57129
(7.5 HIGH)

EPSS: 0.44%

updated 2026-09-14T16:17:14.220000

2 posts

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, or workspace-boundary validation. Prompt input from users, bots, or workflows can therefore read arbitrary files accessible to the process, including credentials, k

thehackerwire@mastodon.social at 2026-09-14T16:00:27.000Z ##

🟠 CVE-2026-57129 - High (7.5)

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, or workspac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T16:00:27.000Z ##

🟠 CVE-2026-57129 - High (7.5)

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, or workspac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89746
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T15:33:42

1 posts

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free with same-name named triggers When two hist triggers on different events are registered with the same name=, the second one reuses the first as named_data. Both are added to tr->hist_vars by save_hist_vars() during event_hist_trigger_parse(), because save_hist_vars() is called before event_trigger_re

thehackerwire@mastodon.social at 2026-09-13T15:00:53.000Z ##

🟠 CVE-2026-89746 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix use-after-free with same-name named triggers

When two hist triggers on different events are registered with the same
name=, the second one reuses the first as named...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89697
(9.1 CRITICAL)

EPSS: 0.69%

updated 2026-09-14T15:33:39

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare() can inspect the dentry. This causes nfsd_setattr() to skip fh_want_write(), so notify_change() runs without a mount write reference. Add the missing fh_want_write() call after the ear

thehackerwire@mastodon.social at 2026-09-13T19:59:53.000Z ##

🔴 CVE-2026-89697 - Critical (9.1)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()

The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare()
can inspect the dentry. This ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89461(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-09-14T15:33:29

1 posts

In the Linux kernel, the following vulnerability has been resolved: power: supply: max17040: synchronize work cancellation on suspend max17040_work() requeues itself after every poll. cancel_delayed_work() only cancels a pending instance and does not wait for a callback that is already running. If system suspend races with the polling callback, the callback can continue accessing the fuel gauge

hugovalters@mastodon.social at 2026-09-14T21:10:01.000Z ##

CVE-2026-89461 Linux kernel max17040 power supply race on suspend. Work callback can keep running and requeue itself after suspend, causing use-after-suspend. No CVSS, still unpatched. Update kernel when fix lands. #CVE #Linux valtersit.com/cve/CVE-2026-894

##

CVE-2026-88802
(7.5 HIGH)

EPSS: 0.23%

updated 2026-09-14T15:32:39

1 posts

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.

thehackerwire@mastodon.social at 2026-09-14T04:00:04.000Z ##

🟠 CVE-2026-88802 - High (7.5)

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85129
(8.8 HIGH)

EPSS: 0.26%

updated 2026-09-14T15:32:39

1 posts

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's

thehackerwire@mastodon.social at 2026-09-13T23:59:58.000Z ##

🟠 CVE-2026-85129 - High (8.8)

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89736
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-14T15:32:36

1 posts

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_audio: Fix use-after-free on sound card disconnect g_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound card teardown and immediately frees the underlying struct snd_uac_chip context. However, snd_card_free_when_closed() returns asynchronously while ALSA control elements (kctls) remain open in u

thehackerwire@mastodon.social at 2026-09-13T17:00:05.000Z ##

🟠 CVE-2026-89736 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: u_audio: Fix use-after-free on sound card disconnect

g_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound
card teardown and immediately frees the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89706
(7.5 HIGH)

EPSS: 0.51%

updated 2026-09-14T15:32:35

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: Reset write verifier when async COPY writeback fails Async COPY captures nn->writeverf at request time and reports it to the client via CB_OFFLOAD after the worker kthread completes. When the post-copy vfs_fsync_range() or filemap_check_wb_err() in _nfsd_copy_file_range() reports an error, the worker correctly leaves NFSD4

thehackerwire@mastodon.social at 2026-09-13T18:00:07.000Z ##

🟠 CVE-2026-89706 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: Reset write verifier when async COPY writeback fails

Async COPY captures nn->writeverf at request time and reports it to
the client via CB_OFFLOAD after the worker kthread...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89684
(7.5 HIGH)

EPSS: 0.51%

updated 2026-09-14T15:32:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix cpntf publish race in nfs4_init_cp_state nfs4_alloc_init_cpntf_state() published the new cpntf entry into the s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock section, then took the lock again to list_add() it onto p_stid->sc_cp_list. In the gap the entry is reachable by so_id but cp_list is still {NULL,NULL}

thehackerwire@mastodon.social at 2026-09-13T20:00:13.000Z ##

🟠 CVE-2026-89684 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix cpntf publish race in nfs4_init_cp_state

nfs4_alloc_init_cpntf_state() published the new cpntf entry into the
s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89504
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-14T15:32:28

1 posts

In the Linux kernel, the following vulnerability has been resolved: regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer In as3722_get_regulator_dt_data(), of_get_child_by_name() acquires a reference on np, which is then assigned to pdev->dev.of_node. The function immediately calls of_node_put(np), releasing the reference and leaving pdev->dev.of_no

hugovalters@mastodon.social at 2026-09-14T16:30:03.000Z ##

CVE-2026-89504 Linux kernel regulator as3722 use-after-free via premature of_node_put, dangling of_node pointer. CVSS N/A, no patch yet. Audit your kernels and apply fixes as soon as they land. valtersit.com/cve/CVE-2026-895 #CVE #Linux #infosec

##

CVE-2026-89508
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-14T15:32:27

1 posts

In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma: Lock the handler in ucma_set_ib_path() ucma_set_ib_path() calls ucma_event_handler() straight from the write() path, without the handler lock that keeps ctx->file stable while a uevent is queued. The handler re-reads ctx->file for every dereference: mutex_lock(&ctx->file->mut); /* file A */ list_add_tail(&uevent

hugovalters@mastodon.social at 2026-09-15T16:00:02.000Z ##

CVE-2026-89508 UAF in Linux kernel RDMA/ucma. No CVSS, no patch. Update immediately. valtersit.com/cve/CVE-2026-895 #CVE #Linux #infosec

##

CVE-2026-89481
(7.5 HIGH)

EPSS: 0.41%

updated 2026-09-14T15:32:26

1 posts

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix host memory disclosure on R2T for a read command nvme_tcp_handle_r2t() does not check the direction of the request the R2T refers to. A malicious controller can send an R2T for a READ and the host will answer it: nvme_tcp_setup_h2c_data_pdu() builds the H2CData header and nvme_tcp_try_send_data() sends the request'

hugovalters@mastodon.social at 2026-09-15T11:20:01.000Z ##

CVE-2026-89481 Linux kernel nvme-tcp host memory disclosure: a malicious controller can send an R2T for a READ and the host returns the read buffer, leaking kernel memory. CVSS N/A, patch status unknown. Patch valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89458(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-09-14T15:32:24

1 posts

In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Do not complete a failed ESE read as successful dasd_int_handler() completes an NRF read of an unallocated ESE track by calling ese_read() and unconditionally marking the request DASD_CQR_SUCCESS. dasd_eckd_ese_read() can return an error before it has zeroed the destination buffer: a failed sense-data parse or a curre

hugovalters@mastodon.social at 2026-09-15T14:20:03.000Z ##

CVE-2026-89458 Linux kernel s390/dasd flaw: failed ESE reads can be marked successful, returning uninitialized data. No CVSS or patch yet. Audit and update s390 systems now. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80979
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-14T15:32:22

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: unregister the connection before draining the rx tasklet smc_conn_free() calls smc_ism_unset_conn() only while the link group is still on its device list, and never sets conn->killed. smc_lgr_terminate_sched() unlinks the group immediately and defers killing its connections to a work item, so a connection freed in that

hugovalters@mastodon.social at 2026-09-15T19:10:01.000Z ##

CVE-2026-80979 Linux kernel net/smc: use-after-free via smc_conn_free() when lgr termination races conn teardown. CVSS N/A, no patch confirmed. Verify your kernel build and update immediately. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-43502
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-14T15:32:07

2 posts

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the sending socket. The purge path currently infers zerocopy state from rm->m_rs, so an unqueued message can be cleaned up as if it owned normal payload pages. Howev

1 repos

https://github.com/suominen/pintheft

secdb at 2026-09-14T22:14:36.215Z ##

🚨 ZcopyReaper (CVE-2026-43502) has been identified as a notable vulnerability.

In the Linux kernel, the following vulnerability has been resolved:

net/rds: handle zerocopy send cleanup before the message is queued

A zerocopy send can fail after user pages have been pinned but before
the message is attached to the sending socket.

The purge path currently infers zerocopy state from rm->m_rs, so an
unqueued message can be cleaned up as if it owned normal payload pages.
However, zerocopy ownership is really determined by the presence of
op_mmp_znotifier, regardless of whether the message has reached the
socket queue.

Capture op_mmp_znotifier up front in rds_message_purge() and use it as
the cleanup discriminator. If the message is already associated with a
socket, keep the existing completion path. Otherwise, drop the pinned
page accounting directly and release the notifier before putting the
payload pages.

This keeps early send failure cleanup consistent with the zerocopy
lifetime rules without changing the normal queued completion path.

ℹ️ Additional information on ZEN SecDB 👉 secdb.nttzen.cloud/cve/detail/


##

secdb@infosec.exchange at 2026-09-14T22:14:36.000Z ##

🚨 ZcopyReaper (CVE-2026-43502) has been identified as a notable vulnerability.

In the Linux kernel, the following vulnerability has been resolved:

net/rds: handle zerocopy send cleanup before the message is queued

A zerocopy send can fail after user pages have been pinned but before
the message is attached to the sending socket.

The purge path currently infers zerocopy state from rm->m_rs, so an
unqueued message can be cleaned up as if it owned normal payload pages.
However, zerocopy ownership is really determined by the presence of
op_mmp_znotifier, regardless of whether the message has reached the
socket queue.

Capture op_mmp_znotifier up front in rds_message_purge() and use it as
the cleanup discriminator. If the message is already associated with a
socket, keep the existing completion path. Otherwise, drop the pinned
page accounting directly and release the notifier before putting the
payload pages.

This keeps early send failure cleanup consistent with the zerocopy
lifetime rules without changing the normal queued completion path.

ℹ️ Additional information on ZEN SecDB 👉 secdb.nttzen.cloud/cve/detail/

#Infosec #ZcopyReaper #Linux #Kernel #LPE #CVE202643502
#NTTData #ZEN #SecDB

##

CVE-2026-12258
(0 None)

EPSS: 0.40%

updated 2026-09-14T15:17:04.153000

2 posts

Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone number). No authentication is required beyond a static bearer token, and there is no ra

offseq at 2026-09-14T13:30:25.596Z ##

Hiperdino REST API v1.0 (CVE-2026-12258) has a CRITICAL info disclosure flaw (CVSS 9.2): attackers with a static bearer token can enumerate user contact info via the 'customer/check' endpoint. No patch yet. Restrict token access & monitor usage. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-14T13:30:25.000Z ##

Hiperdino REST API v1.0 (CVE-2026-12258) has a CRITICAL info disclosure flaw (CVSS 9.2): attackers with a static bearer token can enumerate user contact info via the 'customer/check' endpoint. No patch yet. Restrict token access & monitor usage. radar.offseq.com/threat/cve-20 #OffSeq #infosec #APIsecurity

##

CVE-2026-85706
(10.0 CRITICAL)

EPSS: 11.96%

updated 2026-09-14T14:22:15.323000

20 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

12 repos

https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab

https://github.com/0xenesbayram/cve-2026-85706

https://github.com/brigadeops32/CVE-2026-85706

https://github.com/guneykabel/cve-2026-85706

https://github.com/FlowerWitch/CVE-2026-85706_docker_exp

https://github.com/ynsmroztas/GitLabSniper

https://github.com/gabrielunknown/CVE-2026-85706

https://github.com/plur1bu5/gitread

https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc

https://github.com/gagaltotal/CVE-2026-85706-gitlab-poc

https://github.com/mhtsec/CVE-2026-85706

https://github.com/solivaquaant/CVE-2026-85706

DailyCyberSecurity at 2026-09-16T04:17:24.317Z ##

Learn why CISA added GitLab CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Discover how this CVSS 10 flaw allows remote secret extraction.

meterpreter.org/gitlab-cve-202

##

eric.zip@bsky.brid.gy at 2026-09-16T02:09:52.270Z ##

Dropped some research and detection/hunt content on CVE-2026-85706 🤓

RE: https://bsky.app/profile/did:plc:lsvsraxh3ckc7frgv5p5d7gy/post/3mvl6a4xflz23

##

censys at 2026-09-15T15:32:12.849Z ##

🚨 GitLab CVE-2026-85706 is a critical CVSS 10.0 vulnerability under active exploitation.
Censys sees 86K+ GitLab hosts on the Internet.

Patch immediately. If your instance was exposed while vulnerable, rotate credentials and investigate for compromise. censys.com/advisory/cve-2026-8

##

benzogaga33@mamot.fr at 2026-09-15T09:20:04.000Z ##

Comment la faille de GitLab peut mettre à nu vos serveurs goodtech.info/gitlab-faille-cr #Développement #Revuedepresse #Sécurité

##

tierrasapiens@mastodon.social at 2026-09-15T06:11:10.000Z ##

🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Maximum Severity GitLab Flaw Puts Supply Chains at Risk
🔗 darkreading.com/cyberattacks-d

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

##

hackmag at 2026-09-15T03:06:55.633Z ##

⚪️ Developers Urge Immediate Fix for Critical GitLab Vulnerability

🗨️ GitLab engineers have released patches for the critical CVE-2026-85706 vulnerability, which received the maximum CVSS score of 10 and allows an unauthenticated attacker to read arbitrary files on a server. Security researchers warn that attackers began attempting to exploit the…

🔗 hackmag.com/news/gitlab-patch?

##

thecybermind at 2026-09-14T20:01:09.772Z ##

CRITICAL CISA KEV ALERT: CVE-2026-85706 targets GitLab CE/EE via path traversal in the repository commits API. Active exploitation verified. Access our TSUITE brief for SIEM detection queries and compensating controls to protect your CI/CD pipeline and isolate your secrets.

thecybermind.co/pcid

##

undercodenews@mastodon.social at 2026-09-14T19:34:00.000Z ##

GitLab CVE-2026-85706: A Critical Zero-Authentication Flaw Is Now Being Exploited in the Wild + Video

GitLab CVE-2026-85706: A Critical Zero-Authentication Flaw Is Now Being Exploited in the Wild Introduction: A GitLab Warning That Security Teams Cannot Ignore A critical GitLab vulnerability has rapidly moved from a newly patched security issue to an active exploitation concern. Tracked as CVE-2026-85706, the flaw carries the maximum CVSS score of 10.0 and affects…

undercodenews.com/gitlab-cve-2

##

AAKL at 2026-09-14T17:47:44.652Z ##

New.

Rapid7: CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official

##

decio at 2026-09-14T14:41:51.072Z ##

⚠️GitLab : CVE-2026-85706 est activement exploitée.

Une faille critique de traversée de répertoires permet à un attaquant non authentifié de lire des fichiers arbitraires sur le serveur.

Encore une vulnérabilité qui prend des chemins de traverse…
../../../../etc/ :dumpster_fire_gif: 👀

-->GitLab auto-hébergé exposé sur Internet : mise à jour rapide recommandée.

Correctifs : 19.1.8, 19.2.6 et 19.3.2.

La faille a déjà rejoint le catalogue KEV de la CISA, et ça commence clairement à renifler autour : watchTowr et plusieurs honeypots ont déjà vu passer des tentatives de probing.

Onyphe recense une bonne centaine d’instances vulnérables en CH aujourd'hui...

🩹
👇
docs.gitlab.com/releases/patch

🔍
👇
vulnerability.circl.lu/vuln/CV

##

threatcodex at 2026-09-14T12:31:48.619Z ##

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

rapid7.com/blog/post/etr-cve-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T04:17:24.000Z ##

Learn why CISA added GitLab CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Discover how this CVSS 10 flaw allows remote secret extraction.

#GitLab #CVE202685706 #CISA #CyberSecurity #Vulnerability

meterpreter.org/gitlab-cve-202

##

censys@infosec.exchange at 2026-09-15T15:32:12.000Z ##

🚨 GitLab CVE-2026-85706 is a critical CVSS 10.0 vulnerability under active exploitation.
Censys sees 86K+ GitLab hosts on the Internet.

Patch immediately. If your instance was exposed while vulnerable, rotate credentials and investigate for compromise. censys.com/advisory/cve-2026-8

#GitLab #Cybersecurity #Vulnerability #CVE

##

benzogaga33@mamot.fr at 2026-09-15T09:20:04.000Z ##

Comment la faille de GitLab peut mettre à nu vos serveurs goodtech.info/gitlab-faille-cr #Développement #Revuedepresse #Sécurité

##

hackmag@infosec.exchange at 2026-09-15T03:06:55.000Z ##

⚪️ Developers Urge Immediate Fix for Critical GitLab Vulnerability

🗨️ GitLab engineers have released patches for the critical CVE-2026-85706 vulnerability, which received the maximum CVSS score of 10 and allows an unauthenticated attacker to read arbitrary files on a server. Security researchers warn that attackers began attempting to exploit the…

🔗 hackmag.com/news/gitlab-patch?

#news

##

thecybermind@infosec.exchange at 2026-09-14T20:01:09.000Z ##

CRITICAL CISA KEV ALERT: CVE-2026-85706 targets GitLab CE/EE via path traversal in the repository commits API. Active exploitation verified. Access our TSUITE brief for SIEM detection queries and compensating controls to protect your CI/CD pipeline and isolate your secrets.

thecybermind.co/pcid

##

AAKL@infosec.exchange at 2026-09-14T17:47:44.000Z ##

New.

Rapid7: CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #infosec #GitLab #vulnerability

##

decio@infosec.exchange at 2026-09-14T14:41:51.000Z ##

⚠️GitLab : CVE-2026-85706 est activement exploitée.

Une faille critique de traversée de répertoires permet à un attaquant non authentifié de lire des fichiers arbitraires sur le serveur.

Encore une vulnérabilité qui prend des chemins de traverse…
../../../../etc/ :dumpster_fire_gif: 👀

-->GitLab auto-hébergé exposé sur Internet : mise à jour rapide recommandée.

Correctifs : 19.1.8, 19.2.6 et 19.3.2.

La faille a déjà rejoint le catalogue KEV de la CISA, et ça commence clairement à renifler autour : watchTowr et plusieurs honeypots ont déjà vu passer des tentatives de probing.

Onyphe recense une bonne centaine d’instances vulnérables en CH aujourd'hui...

🩹
👇
docs.gitlab.com/releases/patch

🔍
👇
vulnerability.circl.lu/vuln/CV

#CyberVeille #GitLab #CVE202685706

##

threatcodex@infosec.exchange at 2026-09-14T12:31:48.000Z ##

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
#CVE_2026_85706
rapid7.com/blog/post/etr-cve-2

##

youranonnewsirc@nerdculture.de at 2026-09-14T10:26:20.000Z ##

Recent reports confirm a critical GitLab zero-day (CVE-2026-85706) exploited within 24 hours, alongside new EU Cyber Resilience Act mandates for 24-hour vulnerability reporting. Operational technology (OT) sectors face emerging ransomware threats. Meanwhile, leading AI developers advocate for a slowdown in development due to safety concerns, prompting market shifts. Geopolitically, the BRICS summit addressed rising global tensions and the "weaponization of technology."

#Cybersecurity #TechNews #Geopolitics

##

CVE-2026-73324
(4.3 MEDIUM)

EPSS: 0.21%

updated 2026-09-14T14:17:08.940000

1 posts

Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build configuration.

beyondmachines1@infosec.exchange at 2026-09-13T17:01:13.000Z ##

VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure

VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams.

**If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN releases it. Until you've updated, don't open media files, playlists, or RTSP streaming links that come from people or websites you don't know and trust.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-89750
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T13:19:23.640000

1 posts

In the Linux kernel, the following vulnerability has been resolved: tracing/user_events: Clear copied tracing state before fork duplication dup_task_struct() copies user_event_mm from the parent into the child, without grabbing a reference to it. user_event_mm_dup() should replace it, but it leaves that copied pointer unmodified if user_event_mm_alloc() fails. When the child exits, user_event_m

thehackerwire@mastodon.social at 2026-09-13T16:01:19.000Z ##

🟠 CVE-2026-89750 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

tracing/user_events: Clear copied tracing state before fork duplication

dup_task_struct() copies user_event_mm from the parent into the child,
without grabbing a reference to it...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89744
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-14T13:19:23.193000

1 posts

In the Linux kernel, the following vulnerability has been resolved: device property: fix infinite loop in fwnode_for_each_child_node() When iterate over children of a fwnode that has a secondary fwnode, fwnode_get_next_child_node() can enter an infinite loop if the secondary fwnode has more than one child. Parent Child (Primary fwnode) FWa: {FWa1, FWa2, F

thehackerwire@mastodon.social at 2026-09-13T15:00:42.000Z ##

🟠 CVE-2026-89744 - High (8.4)

In the Linux kernel, the following vulnerability has been resolved:

device property: fix infinite loop in fwnode_for_each_child_node()

When iterate over children of a fwnode that has a secondary fwnode,
fwnode_get_next_child_node() can enter an ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89704
(7.5 HIGH)

EPSS: 0.51%

updated 2026-09-14T13:19:20.367000

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: sample writeback error cursor before async COPY loop _nfsd_copy_file_range() samples dst->f_wb_err into "since" after the copy loop, then uses it to detect writeback errors via filemap_check_wb_err() once vfs_fsync_range() returns. Because the nfsd_file cache reuses a single struct file across requests targeting the same i

thehackerwire@mastodon.social at 2026-09-13T17:59:56.000Z ##

🟠 CVE-2026-89704 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: sample writeback error cursor before async COPY loop

_nfsd_copy_file_range() samples dst->f_wb_err into "since"
after the copy loop, then uses it to detect writeback error...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89696
(7.5 HIGH)

EPSS: 0.76%

updated 2026-09-14T13:19:19.897000

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return success with fh_dentry and fh_export both NULL if fh_verify() returns nfserr_stale and putfh->no_verify is true. The NFSD4_FH_FOREIGN flag is set, but the compound dispatch loop only uses this

thehackerwire@mastodon.social at 2026-09-13T19:00:21.000Z ##

🟠 CVE-2026-89696 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref

When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return
success with fh_dentry and fh_export bo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89488
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-14T13:19:05.627000

1 posts

In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix CT limit teardown use-after-free Packet processing uses CT limit state under RCU, while netns teardown frees that state under ovs_mutex. The CT limit pointer was neither removed from readers nor protected by a grace period, allowing packet processing to dereference the freed state. An unprivileged user can trig

hugovalters@mastodon.social at 2026-09-14T18:00:54.000Z ##

CVE-2026-89488: use-after-free in Linux openvswitch CT limit teardown. Unprivileged user can trigger slab-UAF in ovs_ct_execute(). CVSS N/A, no patch yet. Update immediately. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80973
(0 None)

EPSS: 0.21%

updated 2026-09-14T13:18:52.180000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: bound the MIDI event length from the device usb6fire_comm_receiver_handler() forwards a MIDI event using a length byte the device supplies, with no bound and no check that the transfer delivered that many bytes: if (!urb->status) { if (rt->receiver_buffer[0] == 0x10) /* midi in event */ if (midi_rt) midi_

hugovalters@mastodon.social at 2026-09-16T03:40:01.000Z ##

CVE-2026-80973 Linux ALSA 6fire: unvalidated MIDI length byte allows out-of-bounds read. CVSS N/A, patch status unknown. Patch now if you use this driver. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80970
(0 None)

EPSS: 0.20%

updated 2026-09-14T13:18:51.770000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: do not copy out an uninitialised init response fcp_ioctl_init() allocates its response buffer with kmalloc() and copies the whole buffer back to userspace: buf_size = init.step0_resp_size + init.step2_resp_size; void *resp __free(kfree) = kmalloc(buf_size, GFP_KERNEL); ... if (copy_to_user(arg->resp, resp, buf

hugovalters@mastodon.social at 2026-09-14T19:40:01.000Z ##

CVE-2026-80970 Linux kernel ALSA FCP ioctl leaks uninitialised kmalloc memory to userspace via copy_to_user. Info disclosure, no CVSS or patch yet. Patch or restrict ioctl access. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-80931
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-14T13:18:49.327000

1 posts

In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17: reject an oversize length on an I2C block read w1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire to I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the device. The downstream slave puts a length byte in buf[0]. The driver then reads that many bytes into buf[1] with w1_f19_i2c_rea

hugovalters@mastodon.social at 2026-09-16T04:30:01.000Z ##

CVE-2026-80931 Linux kernel w1 ds28e17: OOB access via oversize I2C block read length. No CVSS, patch status unknown. Update now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-90919
(9.8 CRITICAL)

EPSS: 1.01%

updated 2026-09-14T12:31:50

2 posts

LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Config Server port and send a malicious serialized payload with a __reduce__ method to execute arbitrary code with Config Server process privileges.

offseq at 2026-09-14T12:00:27.236Z ##

CVE-2026-90919: ModelTC LightLLM <=1.2.0 faces CRITICAL RCE risk. Unauthenticated /visual_register WebSocket lets attackers send malicious pickle data, leading to code execution. Patch or restrict access fast. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-14T12:00:27.000Z ##

CVE-2026-90919: ModelTC LightLLM <=1.2.0 faces CRITICAL RCE risk. Unauthenticated /visual_register WebSocket lets attackers send malicious pickle data, leading to code execution. Patch or restrict access fast. radar.offseq.com/threat/cve-20 #OffSeq #CVE202690919 #RCE #LightLLM

##

CVE-2026-12518
(0 None)

EPSS: 0.11%

updated 2026-09-14T11:17:02.930000

3 posts

A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.

benzogaga33@mamot.fr at 2026-09-15T15:40:03.000Z ##

Logitech Options+ : une faille donne les privilèges SYSTEM à n’importe quel utilisateur Windows it-connect.fr/logitech-options #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

cyberveille@mastobot.ping.moi at 2026-09-15T13:30:06.000Z ##

📢 [VULN] Logitech Options+ : une faille donne les privilèges SYSTEM à n’importe quel utilisateur Windows - CVE-2026-12518

C'est un simple logiciel destiné à configurer une souris ou un clavier, et pourtant Logitech Options+ contient une faille de sécurité permettant d'obtenir les privilèges SYSTEM sur Windows. Voici ce que l'on sait sur ce problème de sécurité.

🔗 it-connect.fr/logitech-options
💬 discussion : infosec.pub/post/52323085
#Vulnérabilité #CVE #Cyberveille

##

benzogaga33@mamot.fr at 2026-09-15T15:40:03.000Z ##

Logitech Options+ : une faille donne les privilèges SYSTEM à n’importe quel utilisateur Windows it-connect.fr/logitech-options #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

CVE-2026-90608
(9.9 CRITICAL)

EPSS: 0.80%

updated 2026-09-14T03:30:29

2 posts

A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.

thehackerwire@mastodon.social at 2026-09-14T03:01:32.000Z ##

🔴 CVE-2026-90608 - Critical (9.9)

A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-14T01:30:25.000Z ##

CVE-2026-90608: Totolink A3002MU routers have a CRITICAL buffer overflow (CVSS 9.4) in /boafrm/formPortFw. Exploit code is public; RCE possible. No patch — restrict external access & monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202690608 #RouterSecurity

##

CVE-2026-33963
(7.5 HIGH)

EPSS: 0.11%

updated 2026-09-14T03:30:29

1 posts

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.

thehackerwire@mastodon.social at 2026-09-14T02:59:57.000Z ##

🟠 CVE-2026-33963 - High (7.5)

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-31278
(7.7 HIGH)

EPSS: 0.15%

updated 2026-09-14T03:30:22

2 posts

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.

1 repos

https://github.com/mda1r/CVE-2026-31278

Matchbook3469@mastodon.social at 2026-09-14T13:16:46.000Z ##

🟠 New security advisory:

CVE-2026-31278 affects multiple systems.

• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #ZeroDay #ThreatIntel

##

thehackerwire@mastodon.social at 2026-09-14T02:59:48.000Z ##

🟠 CVE-2026-31278 - High (7.7)

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-23789
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-14T02:17:13.397000

1 posts

An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling) leads to kernel memory corruption and potential arbitrary code execution.

thehackerwire@mastodon.social at 2026-09-14T03:00:10.000Z ##

🟠 CVE-2026-23789 - High (7.8)

An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90605
(9.9 CRITICAL)

EPSS: 0.47%

updated 2026-09-14T00:31:35

1 posts

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

thehackerwire@mastodon.social at 2026-09-14T01:00:54.000Z ##

🔴 CVE-2026-90605 - Critical (9.9)

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 1.69%

updated 2026-09-14T00:16:56.777000

1 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/virologi-info/papercut-toolkit

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

sayzard@mastodon.sayzard.org at 2026-09-14T12:46:09.000Z ##

PaperCut Attacker (Russian Linked) Uses AI Agents to Compromise 440 Instances

러시아어권으로 추정되는 공격자가 PaperCut NG/MF의 인증 우회·RCE 체인(CVE-2026-81578, CVE-2026-82078)을 악용해 48개국 395개 조직의 최소 440개 인스턴스를 침해한 것으로 보고됐다. 공격자는 OpenAI Codex, DeepSeek 모델, Hindsight의 지속 메모리, AionUi 멀티 에이전트 작업 공간을 결합해 취약점 분석부터 익스플로잇 수정, 표적 분류, 재시도, AD 정찰까지 자동화했으며, 실제 공격 개시 후 2...

swapupdate.in/papercut-attacke

##

CVE-2026-37008
(8.1 HIGH)

EPSS: 0.13%

updated 2026-09-13T21:31:54

1 posts

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library without relying in any import statements. In other words, a within-process sandbox

thehackerwire@mastodon.social at 2026-09-14T04:00:15.000Z ##

🟠 CVE-2026-37008 - High (8.1)

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete obj...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-29811
(7.7 HIGH)

EPSS: 0.25%

updated 2026-09-13T21:31:53

1 posts

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

thehackerwire@mastodon.social at 2026-09-13T20:59:49.000Z ##

🟠 CVE-2026-29811 - High (7.7)

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90783
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-13T15:30:28

1 posts

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.

thehackerwire@mastodon.social at 2026-09-13T13:59:47.000Z ##

🟠 CVE-2026-90783 - High (7.8)

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an unde...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90775
(6.5 MEDIUM)

EPSS: 0.34%

updated 2026-09-13T12:31:19

1 posts

PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.

offseq@infosec.exchange at 2026-09-13T13:30:23.000Z ##

CVE-2026-90775: HIGH severity vuln in PostGIS address_standardizer (≤3.7.0) allows out-of-bounds read via unvalidated Weight parameter, crashing PostgreSQL backend (DoS). Patch status pending — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #PostGIS #Vuln

##

CVE-2026-90779
(7.5 HIGH)

EPSS: 0.56%

updated 2026-09-13T12:31:19

1 posts

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.

thehackerwire@mastodon.social at 2026-09-13T13:01:17.000Z ##

🟠 CVE-2026-90779 - High (7.5)

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90561
(8.7 HIGH)

EPSS: 0.24%

updated 2026-09-13T12:31:11

1 posts

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's session when the preview pane is expanded, enabling account takeover.

offseq@infosec.exchange at 2026-09-14T04:30:23.000Z ##

Strapi 4.x – 4.26.2 & 5.x<5.48.1: CRITICAL stored XSS (CVE-2026-90561, CVSS 8.7) in WYSIWYG preview lets Author roles execute malicious scripts in higher-privileged sessions. Restrict roles & monitor vendor updates. radar.offseq.com/threat/strapi #OffSeq #Strapi #XSS #Infosec

##

CVE-2026-89080
(7.5 HIGH)

EPSS: 0.20%

updated 2026-09-13T12:31:10

1 posts

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.

thehackerwire@mastodon.social at 2026-09-13T14:01:09.000Z ##

🟠 CVE-2026-89080 - High (7.5)

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the sec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90562
(8.1 HIGH)

EPSS: 0.42%

updated 2026-09-13T11:17:00.780000

1 posts

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.

thehackerwire@mastodon.social at 2026-09-13T13:01:27.000Z ##

🟠 CVE-2026-90562 - High (8.1)

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89690
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T09:33:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: defer vfree of compound ops to fix rpc_status UAF The rpc_status netlink dumpit walks every in-flight svc_rqst under rcu_read_lock and, for NFSv4 requests, reads opnums out of args->ops[]. But args->ops is a separate vmalloc buffer freed synchronously by vfree() in nfsd4_release_compoundargs() at the end of every compound.

thehackerwire@mastodon.social at 2026-09-13T18:00:20.000Z ##

🟠 CVE-2026-89690 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: defer vfree of compound ops to fix rpc_status UAF

The rpc_status netlink dumpit walks every in-flight svc_rqst under
rcu_read_lock and, for NFSv4 requests, reads opnums ou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89688
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-09-13T09:33:31

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: drop the stateid, not the stateowner, on seqid_op replay retry In nfs4_preprocess_seqid_op() the stateid is obtained from nfsd4_lookup_stateid(), which holds a reference on the nfs4_stid (sc_count) but takes no reference on the stateowner. openlockstateid() merely casts that stid and likewise takes no reference. When nfsd

thehackerwire@mastodon.social at 2026-09-14T07:00:20.000Z ##

🔴 CVE-2026-89688 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: drop the stateid, not the stateowner, on seqid_op replay retry

In nfs4_preprocess_seqid_op() the stateid is obtained from
nfsd4_lookup_stateid(), which holds a reference o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89611
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-09-13T09:33:31

1 posts

In the Linux kernel, the following vulnerability has been resolved: ntfs: validate non-resident attribute offsets ntfs_attr_update_meta() shifts the attribute name when converting between non-sparse and sparse attributes. Converting to sparse also adds the compressed_size field before the name and mapping pairs, requiring eight additional bytes in the attribute record. However, the validator do

thehackerwire@mastodon.social at 2026-09-13T22:59:51.000Z ##

🔴 CVE-2026-89611 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

ntfs: validate non-resident attribute offsets

ntfs_attr_update_meta() shifts the attribute name when converting between
non-sparse and sparse attributes. Converting to sparse al...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89695
(7.5 HIGH)

EPSS: 0.49%

updated 2026-09-13T09:33:31

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: cap decoded POSIX ACL count to bound sort cost nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes it straight to posix_acl_alloc() and sort_pacl_range(). The latter is an O(n^2) bubble sort, so a client-chosen count drives unbounded CPU in the server's compound processing path. nfsd4_decode_posixa

thehackerwire@mastodon.social at 2026-09-13T19:00:11.000Z ##

🟠 CVE-2026-89695 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: cap decoded POSIX ACL count to bound sort cost

nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes
it straight to posix_acl_alloc() and sort_pacl_range...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89689
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-13T09:33:30

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: don't free session slots that are still in use nfsd4_sequence() can free the very slot it is currently processing. When the session shrinker has reduced se_target_maxslots below se_fchannel.maxreqs, the shrink path checks three conditions before calling free_session_slots(): 1. se_target_maxslots < maxreqs (shrink was

thehackerwire@mastodon.social at 2026-09-14T07:00:31.000Z ##

🔴 CVE-2026-89689 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: don't free session slots that are still in use

nfsd4_sequence() can free the very slot it is currently processing.
When the session shrinker has reduced se_target_maxslots...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89521
(7.3 HIGH)

EPSS: 0.15%

updated 2026-09-13T09:33:28

1 posts

In the Linux kernel, the following vulnerability has been resolved: sched/core: Handle pick_task() releasing the rq lock Core scheduling's pick_next_task() breaks when a ->pick_task() implementation can release the rq lock. The selection state derived on entry is only valid while the lock is held continuously. Once a pick can drop the lock, an interleaving selection can invalidate all of it: the

hugovalters@mastodon.social at 2026-09-15T06:30:19.000Z ##

CVE-2026-89521 Linux kernel core scheduling race: pick_task() can release the rq lock, invalidating selection state and committing uncookied picks. No CVSS, no patch yet. Track it and update as soon as fixes land. valtersit.com/cve/CVE-2026-895 #CVE #Linux #infosec

##

CVE-2026-80981
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-09-13T09:33:25

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() smc_llc_srv_add_link() keeps add_llc pointing into the queue entry: add_llc = &qentry->msg.add_link; smc_llc.c:1482 ... smc_llc_save_add_link_info(link_new, add_llc); smc_llc.c:1494 smc_llc_flow_qentry_del(&lgr->llc_flow_lcl); smc_llc.c:1495 ..

hugovalters@mastodon.social at 2026-09-15T20:40:10.000Z ##

CVE-2026-80981 Linux kernel use-after-free in net/smc smc_llc_srv_add_link. CVSS N/A, patch status unknown. Update your kernel now. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-81006
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-13T09:33:21

2 posts

In the Linux kernel, the following vulnerability has been resolved: ipmi: Remove all sysfs files on registration failure ipmi_add_smi() creates the nr_users and nr_msgs files before trying to create the maintenance_mode file. If that last creation fails, the error path removes only nr_users before dropping the final reference to the interface. Remove nr_msgs as well so no sysfs attribute embedd

hugovalters@mastodon.social at 2026-09-15T03:30:01.000Z ##

CVE-2026-81006 Linux kernel ipmi: failed registration leaves sysfs files on freed memory, risking use-after-free. CVSS N/A, patch status unknown. Update your kernel now. valtersit.com/cve/CVE-2026-810 #CVE #Linux #infosec

##

hugovalters@mastodon.social at 2026-09-15T03:30:01.000Z ##

CVE-2026-81006 Linux kernel ipmi: failed registration leaves sysfs files on freed memory, risking use-after-free. CVSS N/A, patch status unknown. Update your kernel now. valtersit.com/cve/CVE-2026-810 #CVE #Linux #infosec

##

CVE-2026-80980
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-13T09:33:21

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharing a byte The three connection state flags are single-bit bitfields, so they occupy one byte of struct smc_connection and every store to one is a read-modify-write of the other two: u8 killed : 1; u8 freed : 1; u8 out_of_sync : 1; They are not written under a comm

hugovalters@mastodon.social at 2026-09-14T11:50:01.000Z ##

CVE-2026-80980 Linux kernel net/smc bitfield race - killed, freed, out_of_sync share one byte without a common lock, a data race that can corrupt connection state. CVSS N/A, patch status unknown/unpatched. Audit valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-89748
(7.8 HIGH)

EPSS: 0.15%

updated 2026-09-13T09:32:30

1 posts

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix retry exhaustion in simple ring buffer reader swap simple_ring_buffer_swap_reader_page() starts with retry set to 8 and post-decrements it only after a failed link replacement. On the final attempt, a successful replacement leaves retry at zero, while a failed replacement leaves it at -1. The current !retry test re

thehackerwire@mastodon.social at 2026-09-13T16:01:07.000Z ##

🟠 CVE-2026-89748 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix retry exhaustion in simple ring buffer reader swap

simple_ring_buffer_swap_reader_page() starts with retry set to 8 and
post-decrements it only after a failed link ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89758
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-13T09:32:30

1 posts

In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: skip non-present PMDs when queueing folios Patch series "mm: handle device-private PMDs in walk callbacks", v3. Since commit 368076f52ebe ("mm/huge_memory: add device-private THP support to PMD operations") a PMD may hold a device-private swap entry whenever an HMM-based GPU driver migrates an anonymous THP folio

thehackerwire@mastodon.social at 2026-09-13T15:00:31.000Z ##

🟠 CVE-2026-89758 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

mm/mempolicy: skip non-present PMDs when queueing folios

Patch series "mm: handle device-private PMDs in walk callbacks", v3.

Since commit 368076f52ebe ("mm/huge_memory: add de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89686
(9.8 CRITICAL)

EPSS: 0.67%

updated 2026-09-13T09:32:28

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding fi_lock when the parent stateid is a delegation. A concurrent delegation revoke via the laundromat can clear fi_deleg_file under fi_lock, causing nfsd_file_get() to return NULL and trigger

thehackerwire@mastodon.social at 2026-09-14T05:03:22.000Z ##

🔴 CVE-2026-89686 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke

nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding
fi_lock when the parent stateid is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89685
(7.5 HIGH)

EPSS: 0.43%

updated 2026-09-13T09:32:28

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix clock domain mismatch in clients_still_reclaiming() clients_still_reclaiming() computes a deadline from nn->boot_time (CLOCK_REALTIME, ~1.7 billion) but compares it against ktime_get_boottime_seconds() (CLOCK_BOOTTIME, seconds since boot). The comparison is always false — it would take ~54 years of uptime for BOOTTIME

thehackerwire@mastodon.social at 2026-09-14T05:03:12.000Z ##

🟠 CVE-2026-89685 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix clock domain mismatch in clients_still_reclaiming()

clients_still_reclaiming() computes a deadline from nn->boot_time
(CLOCK_REALTIME, ~1.7 billion) but compares it ag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80947
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T09:32:12

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop rtl8xxxu arms rx_urb_wq from the RX completion path: rtl8xxxu_rx_complete() hands the URB to rtl8xxxu_queue_rx_urb(), which queues it on rx_urb_pending_list and, once the list grows past RTL8XXXU_RX_URB_PENDING_WATER, schedules rx_urb_wq. The worker rtl8xxxu_rx_urb_work(

hugovalters@mastodon.social at 2026-09-15T04:50:02.000Z ##

CVE-2026-80947 Linux kernel rtl8xxxu wifi driver use-after-free on stop, triggered via RX path. CVSS N/A, no patch yet. Update your kernel now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-89747
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T07:17:39.363000

1 posts

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in trace_pipe read on sub-buffer order change Writing to buffer_subbuf_size_kb calls ring_buffer_subbuf_order_set(), which frees every sub-buffer of the ring buffer, including the reader page, and replaces them with newly allocated ones. Readers of trace_pipe hold pointers into those pages. ring_buff

thehackerwire@mastodon.social at 2026-09-13T16:00:55.000Z ##

🟠 CVE-2026-89747 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix use-after-free in trace_pipe read on sub-buffer order change

Writing to buffer_subbuf_size_kb calls ring_buffer_subbuf_order_set(),
which frees every sub-buffer of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89692
(7.5 HIGH)

EPSS: 0.43%

updated 2026-09-13T07:17:35.107000

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: clear CALLBACK_RUNNING on failed delegation recall queue nfsd_break_one_deleg() sets NFSD4_CALLBACK_RUNNING via test_and_set_bit at entry to serialize recall work, then calls nfsd4_run_cb() to queue the recall. When the queue attempt fails the refcount bump is undone, but the RUNNING bit is left set. The only site that c

thehackerwire@mastodon.social at 2026-09-13T19:00:01.000Z ##

🟠 CVE-2026-89692 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: clear CALLBACK_RUNNING on failed delegation recall queue

nfsd_break_one_deleg() sets NFSD4_CALLBACK_RUNNING via test_and_set_bit
at entry to serialize recall work, then ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89687
(7.5 HIGH)

EPSS: 0.47%

updated 2026-09-13T07:17:34.493000

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file ->atomic_open is permitted to return success without actually opening the file. It indicates this by calling finish_no_open(). This means dentry_create() can return a file which hasn't been opened. This is extremely unlikely as ->atomic_open handlers typically u

thehackerwire@mastodon.social at 2026-09-14T07:00:09.000Z ##

🟠 CVE-2026-89687 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file

->atomic_open is permitted to return success without actually opening
the file. It indicates this by calling ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89682
(8.1 HIGH)

EPSS: 0.40%

updated 2026-09-13T07:17:34.003000

1 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net nfsd_file_dispose_list_delayed() defers fput() to nfsd service threads via a per-net freeme queue, preventing the shrinker and GC worker from bearing the cost of closing files (see ffb402596147). However, the queue lives in a separately-allocated struct nfsd_

thehackerwire@mastodon.social at 2026-09-13T20:00:03.000Z ##

🟠 CVE-2026-89682 - High (8.1)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net

nfsd_file_dispose_list_delayed() defers fput() to nfsd service threads
via a per-net freeme queue, preventi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89613
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-09-13T07:17:26.840000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid empty mapping pairs Reject an attribute with empty mapping pairs if it has inconsistent highest VCN and size.

thehackerwire@mastodon.social at 2026-09-13T23:00:11.000Z ##

🔴 CVE-2026-89613 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

ntfs: reject invalid empty mapping pairs

Reject an attribute with empty mapping pairs if it has inconsistent
highest VCN and size.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89612
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-09-13T07:17:26.730000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid MFT LCNs from boot sector The NTFS boot sector stores the MFT and MFTMirr locations as unsigned 64-bit LCNs, but parse_ntfs_boot_sector() decoded them into an s64. A crafted high-bit value could therefore become negative and pass the existing upper-bound check. The invalid value then propagated into the MFT

thehackerwire@mastodon.social at 2026-09-13T23:00:01.000Z ##

🔴 CVE-2026-89612 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

ntfs: reject invalid MFT LCNs from boot sector

The NTFS boot sector stores the MFT and MFTMirr locations as unsigned
64-bit LCNs, but parse_ntfs_boot_sector() decoded them into ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89501
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T07:17:13.333000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Hold cpu_buffer::lock when resizing a subbuf Because, ring_buffer_subbuf_order_set() can clear cpu_buffer->free_page, hold cpu_buffer->lock to prevent races with ring_buffer_alloc_read_page() and ring_buffer_free_read_page().

hugovalters@mastodon.social at 2026-09-16T04:10:21.000Z ##

CVE-2026-89501 Linux kernel ring-buffer race on subbuf resize, unpatched, CVSS N/A. Update immediately. valtersit.com/cve/CVE-2026-895 #CVE #Linux #infosec

##

CVE-2026-89499
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-13T07:17:13.100000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Stop remote reader update when page swap fails The remote swap_reader_page callback can return -EBUSY when the writer moves the head before the remote catches it, particularly during an event storm on a small buffer. __rb_get_reader_page_from_remote() currently warns about that failure but continues with the unchang

hugovalters@mastodon.social at 2026-09-15T02:20:55.000Z ##

CVE-2026-89499 Linux kernel ring-buffer flaw: failed remote page swap corrupts reader state, risking kernel crash or memory corruption during event storms. No CVSS or patch yet. Track it and apply updates as valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89450
(8.8 HIGH)

EPSS: 0.13%

updated 2026-09-13T07:17:09.350000

1 posts

In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field tegra241_vintf_init_vsid() programs the guest-provided vSID into SID_MATCH, whose VIRT_SID field spans bits [20:1] with bit 0 as the match-enable flag. The HW therefore matches only a 20-bit Stream ID. The bound check rejects only virt_sid > UINT_MAX, which admi

hugovalters@mastodon.social at 2026-09-15T08:10:01.000Z ##

CVE-2026-89450 Linux kernel iommu/tegra241-cmdqv: vSID wider than SID_MATCH field bypasses bound check, dropping bits above 20. CVSS N/A, unpatched. Update immediately. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80995
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-13T07:17:06.230000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: mctp: hold a reference to the route device in mctp_route_lookup() mctp_route_lookup() uses rt->dev without holding a reference on it. mctp_route_lookup_single() returns the route under RCU only, so the route's device can be torn down concurrently: mctp_dev_put() drops the last reference and synchronously kfree()s mdev->addr

hugovalters@mastodon.social at 2026-09-15T17:30:02.000Z ##

CVE-2026-80995 Linux kernel use-after-free in mctp_route_lookup can crash systems, possibly worse. No CVSS, no patch yet. Track it and update the moment a fix lands. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80936
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-13T07:17:01.293000

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel mlo_pm_work on stop mt7925 queues mlo_pm_work with a 5 second delay during multi-link power-save setup and never cancels it on the stop path. If the device is torn down inside that window, the work outlives the teardown and its timer fires afterwards, trying to queue onto the workqueue that is already

hugovalters@mastodon.social at 2026-09-16T04:10:01.000Z ##

CVE-2026-80936 Linux mt76 mt7925: uncancelled mlo_pm_work fires after teardown, causing a use-after-free-style workqueue warning and kernel crash risk. CVSS N/A, unpatched - update your kernel now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-89517(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-09-11T21:31:37

1 posts

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix rq->core_pick corruption under core scheduling Core scheduling's pick_next_task() picks what to run on every SMT sibling of the core in a single pass under the shared core-wide rq lock. The selection state is consistent only while the lock is held continuously, so ->pick_task() originally could not release it. How

hugovalters@mastodon.social at 2026-09-15T01:10:15.000Z ##

CVE-2026-89517 Linux kernel: sched_ext rq->core_pick corruption under core scheduling. CVSS N/A, patch status unknown. Kernel memory corruption risk. Patch now if a fix lands. valtersit.com/cve/CVE-2026-895 #CVE #Linux #infosec

##

CVE-2026-81911(CVSS UNKNOWN)

EPSS: 0.30%

updated 2026-09-11T21:31:32

1 posts

Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_template endpoint authorizes the request only against the target board instance (canEditBoardContents()) and then persists the client-supplied selectedTemplateOption[collection] verbatim, rather than rebuilding the content object collection server-side and verifying that each item bel

hugovalters@mastodon.social at 2026-09-15T12:50:02.000Z ##

CVE-2026-81911 Concrete CMS 9.0.0-9.5.2 Stored XSS via the custom_slot save_template endpoint. No CVSS assigned and no patch available, so treat as unpatched. Restrict board edit permissions and sanitize valtersit.com/cve/CVE-2026-819 #CVE #infosec #ConcreteCMS

##

CVE-2026-89447(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-09-11T21:31:32

1 posts

In the Linux kernel, the following vulnerability has been resolved: iommufd: Avoid locking internal accesses during unmap iommufd_access_notify_unmap() skips internal accesses because they do not have an external unmap callback to invoke. However, the current test calls iommufd_lock_obj() before checking whether the access is internal. If iommufd_lock_obj() succeeds, the loop then sees the inte

hugovalters@mastodon.social at 2026-09-14T14:50:01.000Z ##

CVE-2026-89447 Linux kernel iommufd flaw: internal accesses skip the matching put during unmap, risking a refcount/lock imbalance. No CVSS yet, patch status unknown. Patch or update now. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80927(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-11T21:31:19

1 posts

In the Linux kernel, the following vulnerability has been resolved: timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() If the auxiliary clock is disabled during tk_get_aux_ts64() but is enabled before tks->clock_valid is checked, then uninitialized stackdata will be used in the calculations and indirectly leaked to userspace. The same race window also exists after this ch

hugovalters@mastodon.social at 2026-09-15T05:00:20.000Z ##

CVE-2026-80927: Linux kernel timekeeping race leaks uninitialized stack data to userspace. CVSS N/A, patch status unknown. Update your kernel now. valtersit.com/cve/CVE-2026-809 #CVE #infosec #LinuxKernel

##

CVE-2026-84869
(9.9 CRITICAL)

EPSS: 0.69%

updated 2026-09-11T21:31:17

9 posts

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

beyondmachines1 at 2026-09-15T11:01:13.932Z ##

ConnectWise Patches Critical ScreenConnect Flaw Exploited in Worm Attacks

ConnectWise fixed a critical vulnerability (CVE-2026-84869) in ScreenConnect that allows unauthorized file execution and worm-like propagation across remote sessions.

**If you use ConnectWise ScreenConnect, update to version 26.6.5 right away and then reinstall every host client. The update only takes effect once the clients are reinstalled, and this flaw is already being exploited to spread from machine to machine. If you can't patch, turn off the TransferFiles permission for all user roles as a mitigating measures. Don't forget to check integrated tools like ConnectWise Automate for their own patched versions.**

beyondmachines.net/event_detai

##

security_crawler_carl at 2026-09-14T19:46:27.876Z ##

🏆 New Achievement! The Help Desk Has Turned Against You!

PHASE ONE: ConnectWise ScreenConnect, your trusted remote support companion, enters the arena. PHASE TWO: CVE-2026-84869 awakens — CVSS 9.9, the kind of score that makes sysadmins physically leave their bodies. PHASE THREE: the worm-like propagation begins, chaining active remote sessions into unauthorized file transfers and full remote code execution. Huntress confirmed real-world exploitation. (1/2)

##

undercodenews@mastodon.social at 2026-09-14T19:33:56.000Z ##

ConnectWise ScreenConnect Flaw Turns Remote Support Into a Worm-Like Attack Engine + Video

A Critical Vulnerability With a Dangerous Twist ConnectWise has rushed out an emergency security update for its ScreenConnect remote access and support platform after a critical vulnerability was exploited in real-world attacks. Tracked as CVE-2026-84869 and rated 9.9 out of 10, the flaw is particularly dangerous because attackers can potentially abuse an active remote session to…

undercodenews.com/connectwise-

##

thecybermind at 2026-09-14T14:01:07.511Z ##

CRITICAL CISA KEV ALERT: CVE-2026-84869 targets ConnectWise ScreenConnect with unauthorized file transfer and RCE. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to protect your environment. thecybermind.co/g5ob

##

beyondmachines1@infosec.exchange at 2026-09-15T11:01:13.000Z ##

ConnectWise Patches Critical ScreenConnect Flaw Exploited in Worm Attacks

ConnectWise fixed a critical vulnerability (CVE-2026-84869) in ScreenConnect that allows unauthorized file execution and worm-like propagation across remote sessions.

**If you use ConnectWise ScreenConnect, update to version 26.6.5 right away and then reinstall every host client. The update only takes effect once the clients are reinstalled, and this flaw is already being exploited to spread from machine to machine. If you can't patch, turn off the TransferFiles permission for all user roles as a mitigating measures. Don't forget to check integrated tools like ConnectWise Automate for their own patched versions.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-09-14T19:46:27.000Z ##

🏆 New Achievement! The Help Desk Has Turned Against You!

PHASE ONE: ConnectWise ScreenConnect, your trusted remote support companion, enters the arena. PHASE TWO: CVE-2026-84869 awakens — CVSS 9.9, the kind of score that makes sysadmins physically leave their bodies. PHASE THREE: the worm-like propagation begins, chaining active remote sessions into unauthorized file transfers and full remote code execution. Huntress confirmed real-world exploitation. (1/2)

##

thecybermind@infosec.exchange at 2026-09-14T14:01:07.000Z ##

CRITICAL CISA KEV ALERT: CVE-2026-84869 targets ConnectWise ScreenConnect with unauthorized file transfer and RCE. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to protect your environment. thecybermind.co/g5ob

##

cyberworldops@infosec.exchange at 2026-09-14T10:20:01.000Z ##

ConnectWise patched CVE-2026-84869, a critical ScreenConnect authorization flaw allowing file transfer and execution via active sessions. Huntress reports worm-like exploitation since August 20. It enables lateral spread without host confirmation, requiring immediate patching and session review. #ScreenConnect #CyberSecurity #InfoSec

cyberworldops.eu/en/critical-s

##

offseq@infosec.exchange at 2026-09-14T09:00:25.000Z ##

ConnectWise ScreenConnect CRITICAL vuln (CVE-2026-84869) exploited in worm-like attacks — unauthorized file transfer & execution via remote sessions in versions <26.6.5. Patch to 26.6.5 now or disable TransferFiles. radar.offseq.com/threat/connec #OffSeq #Cybersecurity #Vuln #CISA

##

CVE-2026-42016
(8.1 HIGH)

EPSS: 0.89%

updated 2026-09-11T21:31:06

3 posts

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

thecybermind at 2026-09-14T17:10:44.668Z ##

CRITICAL CISA KEV ALERT: CVE-2026-42016 targets JFrog Artifactory via incorrect authorization and token scope flaws. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to secure your software pipelines.

thecybermind.co/4u1b

##

cyberveille@mastobot.ping.moi at 2026-09-14T16:30:05.000Z ##

📢 Exploitation active de trois vulnérabilités critiques dans JFrog Artifactory

🔍 Contexte : Le 10 septembre 2026, Wiz Research publie une analyse technique détaillant l'exploitation active en conditions réelles de trois vulnérabilités critiques et de haute sévérité affectant JFrog Artifactory.

📖 cyberveille : cyberveille.ch/posts/2026-09-1
🌐 source : wiz.io/blog/artifactory-under-
🟢 vérification factuelle haute
#JFrogArtifactory #ExploitationActive #Cyberveille

##

thecybermind@infosec.exchange at 2026-09-14T17:10:44.000Z ##

CRITICAL CISA KEV ALERT: CVE-2026-42016 targets JFrog Artifactory via incorrect authorization and token scope flaws. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to secure your software pipelines.

thecybermind.co/4u1b

##

CVE-2026-59971
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-11T20:36:20

2 posts

## Summary In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServerTransport` without passing `security_settings`. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to `0.0.0.0` by default with no authentication on any route. **Trigger condition

thehackerwire@mastodon.social at 2026-09-15T16:01:54.000Z ##

🔴 CVE-2026-59971 - Critical (10)

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T16:01:54.000Z ##

🔴 CVE-2026-59971 - Critical (10)

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81861
(0 None)

EPSS: 0.38%

updated 2026-09-11T20:19:13.263000

2 posts

CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.

1 repos

https://github.com/abhinavagarwal07/scadapack-secure-lock-poc

cyberworldops at 2026-09-15T18:50:00.545Z ##

Schneider Electric disclosed CVE-2026-81861 (CWE-522) affecting SCADAPack x70 RTUs. Legacy Secure Lock insufficiently protects credentials, exposing RTU authentication data. Exposed credentials matter for OT as they can enable unauthorized access to monitoring and control functions.

cyberworldops.eu/en/schneider-

##

cyberworldops@infosec.exchange at 2026-09-15T18:50:00.000Z ##

Schneider Electric disclosed CVE-2026-81861 (CWE-522) affecting SCADAPack x70 RTUs. Legacy Secure Lock insufficiently protects credentials, exposing RTU authentication data. Exposed credentials matter for OT as they can enable unauthorized access to monitoring and control functions. #IcsSecurity #ScadaSecurity #OtSecurity

cyberworldops.eu/en/schneider-

##

CVE-2026-81018
(0 None)

EPSS: 0.13%

updated 2026-09-11T20:19:10.813000

1 posts

In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Free system certificate signatures Multi-certificate support also allows the system authentication object to store ->signature and ->save_signature, which leak when the driver is removed. Free the signatures to avoid leaking memory.

hugovalters@mastodon.social at 2026-09-15T09:40:00.000Z ##

CVE-2026-81018 Linux kernel think-lmi driver leaks system certificate signatures on removal. Memory leak only, CVSS not assigned, no patch. Track status and apply fixes when available: valtersit.com/cve/CVE-2026-810 #CVE #Linux #infosec

##

CVE-2026-80974
(0 None)

EPSS: 0.20%

updated 2026-09-11T20:19:03.623000

1 posts

In the Linux kernel, the following vulnerability has been resolved: mfd: sm501: Fix potential memory leaks during remove The memory allocated for struct sm501_devdata in sm501_pci_probe() and sm501_plat_probe() is not freed by the corresponding remove functions sm501_pci_remove() and sm501_plat_remove(). Fix that by adding a call to kfree().

hugovalters@mastodon.social at 2026-09-14T13:20:02.000Z ##

CVE-2026-80974 Linux kernel sm501 mfd driver leaks memory on device removal. No CVSS assigned, patch status unknown. Update your kernel when a fix lands. Details: valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80960
(0 None)

EPSS: 0.20%

updated 2026-09-11T20:19:01.863000

1 posts

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate on-media seg_num against the cache device size seg_num is read from the crc32c-only superblock, so whoever supplies the cache device on a table load (CAP_SYS_ADMIN) controls it. It sizes cache->segments[] and is the value every later on-media segment id is bounded against, yet it is never checked against the

hugovalters@mastodon.social at 2026-09-16T04:20:03.000Z ##

CVE-2026-80960 Linux kernel dm-pcache out-of-bounds access via unchecked seg_num from on-media superblock. Can lead to memory corruption. CVSS N/A, patch status unknown. Patch now if you use dm-pcache. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-89010
(9.8 CRITICAL)

EPSS: 2.85%

updated 2026-09-11T17:35:21.440000

1 posts

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136. The daemon interpolates attacker-controlled filename input containing shell metacharacters into a shell command string vi

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-17176
(0 None)

EPSS: 3.59%

updated 2026-09-11T15:21:12.850000

1 posts

An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise, including unauthorized command execution, modification of device settings, and loss of confidentiality, integrity, and availability

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-87020
(8.1 HIGH)

EPSS: 0.56%

updated 2026-09-11T15:17:06.937000

1 posts

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

cyberworldops@infosec.exchange at 2026-09-13T18:50:01.000Z ##

Orthanc DICOM Server is affected by CVE-2026-87020, an integer overflow in image pitch calculation enabling authenticated heap out-of-bounds write via malicious PNG. It matters for clinical environments where exploitation risks service disruption and imaging integrity. #OrthancServer #DicomSecurity #HeapCorruption

cyberworldops.eu/en/orthanc-di

##

CVE-2026-86060
(9.8 CRITICAL)

EPSS: 1.06%

updated 2026-09-11T12:52:16.507000

2 posts

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable

1 repos

https://github.com/bahirul/cve-2026-86060

thecybermind at 2026-09-14T18:30:04.775Z ##

CRITICAL CISA KEV ALERT: CVE-2026-86060 targets MikroTik RouterOS via improper argument delimiter neutralization and command injection. Active exploitation verified. Access our TSUITE brief for hardening steps and network segmentation protocols to secure your perimeter.

thecybermind.co/957k

##

thecybermind@infosec.exchange at 2026-09-14T18:30:04.000Z ##

CRITICAL CISA KEV ALERT: CVE-2026-86060 targets MikroTik RouterOS via improper argument delimiter neutralization and command injection. Active exploitation verified. Access our TSUITE brief for hardening steps and network segmentation protocols to secure your perimeter.

thecybermind.co/957k

##

CVE-2026-82079
(8.4 HIGH)

EPSS: 0.16%

updated 2026-09-11T03:31:25

2 posts

A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic. This issue affects Nintendo Switch: before 23.0.0.

DailyCyberSecurity at 2026-09-14T13:11:53.355Z ##

Discover the dangerous Nintendo Switch QR code vulnerability (CVE-2026-82079) allowing hackers to execute code. Learn how system update 23.0.0 fixes it.

meterpreter.org/nintendo-switc

##

DailyCyberSecurity@infosec.exchange at 2026-09-14T13:11:53.000Z ##

Discover the dangerous Nintendo Switch QR code vulnerability (CVE-2026-82079) allowing hackers to execute code. Learn how system update 23.0.0 fixes it.

#NintendoSwitch #CyberSecurity #CVE202682079 #QRCode #Vulnerability

meterpreter.org/nintendo-switc

##

CVE-2026-65638
(0 None)

EPSS: 3.20%

updated 2026-09-10T19:54:25.810000

1 posts

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed t

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-81467
(9.8 CRITICAL)

EPSS: 3.84%

updated 2026-09-10T18:33:04

1 posts

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-81468
(9.1 CRITICAL)

EPSS: 2.28%

updated 2026-09-10T18:33:03

1 posts

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 75.75%

updated 2026-09-10T12:48:17.580000

1 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp; This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this v

3 repos

https://github.com/DiegoArias008/CVE-2026-20079-checker

https://github.com/CyberAuth/CVE-2026-20079

https://github.com/0xBlackash/CVE-2026-20079

8bitsecurity@mastodon.social at 2026-09-14T07:05:00.000Z ##

🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The vulnerability…

Also tracked this week: Hackers exploit Sangoma Switchvox flaw to deploy reverse… · Microsoft Plugs Nearly 1,000…

nexus8.8bitsecurity.com/entity

##

CVE-2025-25249
(8.1 HIGH)

EPSS: 2.40%

updated 2026-09-10T12:47:59.933000

1 posts

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

DailyCyberSecurity@infosec.exchange at 2026-09-14T07:16:02.000Z ##

Discover how the PivotC2 FortiGate RAT uses CVE-2025-25249 exploitation to harvest credentials and tunnel traffic across corporate network environments.

#PivotC2 #FortiGate #Malware #Cybercrime #CVE202525249

securityonline.info/pivotc2-fo

##

CVE-2026-85103
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-09-10T04:18:18.390000

2 posts

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

threatnoir@infosec.exchange at 2026-09-14T02:05:45.000Z ##

⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

guru@thecybersecguru.com at 2026-09-13T13:02:46.000Z ##

Check Point patches two critical VPN gateway flaws scoring 9.8 on CVSS

Check Point patches two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, rated CVSS 9.8 and capable of unauthenticated remote code execution

thecybersecguru.com/news/check

##

CVE-2026-87491
(8.8 HIGH)

EPSS: 1.00%

updated 2026-09-09T21:31:35

1 posts

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

2 repos

https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.

https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter

CapTechGroup@mastodon.social at 2026-09-15T12:46:42.000Z ##

BlueMoon chain: CVE-2026-85046 for arbitrary read/write in the Chrome V8 sandbox, CVE-2026-87491 to escape the browser sandbox, CVE-2026-85880 (Windows ALPC) to inject into the Chrome process. Delivery: reflected XSS on a...

captechgroup.com/threat-intell

##

CVE-2026-58113
(6.1 MEDIUM)

EPSS: 0.22%

updated 2026-09-09T16:17:03.483000

2 posts

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could al

cyberworldops at 2026-09-16T04:50:00.761Z ##

Siemens patched CVE-2026-58113, a reflected XSS (CWE-79) in Teamcenter /auth/ redirect flow. An unauthenticated attacker can craft a URL executing JavaScript in an authenticated user's session. Update all four affected branches.

cyberworldops.eu/en/siemens-pa

##

cyberworldops@infosec.exchange at 2026-09-16T04:50:00.000Z ##

Siemens patched CVE-2026-58113, a reflected XSS (CWE-79) in Teamcenter /auth/ redirect flow. An unauthenticated attacker can craft a URL executing JavaScript in an authenticated user's session. Update all four affected branches. #SiemensTeamcenter #CrossSiteScripting #PatchManagement

cyberworldops.eu/en/siemens-pa

##

CVE-2026-87827
(0 None)

EPSS: 1.07%

updated 2026-09-09T15:37:49.157000

2 posts

Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device, potentially resulting in complete compromise of the DVR. The vulnerability is known to have been exploited in t

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-09-09T15:35:15

2 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

threatnoir@infosec.exchange at 2026-09-14T02:05:45.000Z ##

⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

guru@thecybersecguru.com at 2026-09-13T13:02:46.000Z ##

Check Point patches two critical VPN gateway flaws scoring 9.8 on CVSS

Check Point patches two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, rated CVSS 9.8 and capable of unauthenticated remote code execution

thecybersecguru.com/news/check

##

CVE-2026-56711
(8.8 HIGH)

EPSS: 0.11%

updated 2026-09-09T15:35:15

1 posts

VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result. In AllocatePicture in src/misc/picture.c the running total is accumulated as i_bytes += p->i_pitch * p->i_lines, and both plane_t fields are declared int in include/vlc_picture.h, so the multiplication is evaluated at 32 bits and wraps before it is widened to the size_t accumulator.

beyondmachines1@infosec.exchange at 2026-09-13T17:01:13.000Z ##

VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure

VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams.

**If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN releases it. Until you've updated, don't open media files, playlists, or RTSP streaming links that come from people or websites you don't know and trust.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-86218
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-09-09T05:18:19.490000

1 posts

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

3 repos

https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit

https://github.com/Udyz/CVE-2026-86218

https://github.com/HORKimhab/CVE-2026-86218

DailyCyberSecurity@infosec.exchange at 2026-09-14T02:34:52.000Z ##

CVE-2026-86218, a CVSS 10 N-central vulnerability, is exploited in the wild for remote code execution. A public Metasploit PoC is out. Patch now.

#Nable #Ncentral #CVE202686218 #Cybersecurity #InfoSec

securityonline.info/n-able-n-c

##

CVE-2026-85880
(7.8 HIGH)

EPSS: 0.57%

updated 2026-09-09T05:18:19.193000

3 posts

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

CapTechGroup@mastodon.social at 2026-09-15T12:46:42.000Z ##

BlueMoon chain: CVE-2026-85046 for arbitrary read/write in the Chrome V8 sandbox, CVE-2026-87491 to escape the browser sandbox, CVE-2026-85880 (Windows ALPC) to inject into the Chrome process. Delivery: reflected XSS on a...

captechgroup.com/threat-intell

##

youranonnewsirc@nerdculture.de at 2026-09-15T04:26:24.000Z ##

Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.

#AnonNews_irc #Cybersecurity #News

##

youranonnewsirc@nerdculture.de at 2026-09-15T04:26:24.000Z ##

Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.

#AnonNews_irc #Cybersecurity #News

##

CVE-2026-81963
(7.8 HIGH)

EPSS: 0.63%

updated 2026-09-09T05:18:17.173000

2 posts

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

youranonnewsirc@nerdculture.de at 2026-09-15T04:26:24.000Z ##

Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.

#AnonNews_irc #Cybersecurity #News

##

youranonnewsirc@nerdculture.de at 2026-09-15T04:26:24.000Z ##

Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.

#AnonNews_irc #Cybersecurity #News

##

CVE-2026-75650
(10.0 CRITICAL)

EPSS: 2.15%

updated 2026-09-09T05:18:07.237000

3 posts

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

5 repos

https://github.com/dinosn/cve-2026-75650-magento-validation-lab

https://github.com/disrex-group/stylesmuggler-adobe-patches

https://github.com/fortbridge/stylesmuggler

https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos

https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit

threatcodex at 2026-09-15T14:30:56.587Z ##

CVE-2026-75650: StyleSmuggler — Critical RCE in Adobe Commerce and Magento

akamai.com/blog/security-resea

##

threatcodex@infosec.exchange at 2026-09-15T14:30:56.000Z ##

CVE-2026-75650: StyleSmuggler — Critical RCE in Adobe Commerce and Magento
#CVE_2026_75650 #AdobeCommerce
akamai.com/blog/security-resea

##

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12745
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-09-08T15:32:04

1 posts

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12744
(9.8 CRITICAL)

EPSS: 2.17%

updated 2026-09-08T15:32:04

1 posts

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-79697
(9.9 CRITICAL)

EPSS: 3.35%

updated 2026-09-08T14:17:29.160000

1 posts

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argu

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-48888
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-08T13:12:58.310000

2 posts

Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.

wpguyuk at 2026-09-15T07:04:31.833Z ##

WooCommerce CVE-2026-48888 is a high-severity flaw an attacker can exploit with no account and no elevated permissions. If my clients have not updated to 11.1.0, their customer data and payment layer are exposed right now. I recommend updating immediately.

wpguy.uk/blog/woocommerce-cve-

##

wpguyuk@infosec.exchange at 2026-09-15T07:04:31.000Z ##

WooCommerce CVE-2026-48888 is a high-severity flaw an attacker can exploit with no account and no elevated permissions. If my clients have not updated to 11.1.0, their customer data and payment layer are exposed right now. I recommend updating immediately.

#WordPress #WooCommerce #CVE #SecurityHardening #WordPressSecurity

wpguy.uk/blog/woocommerce-cve-

##

CVE-2026-78488
(6.5 MEDIUM)

EPSS: 3.25%

updated 2026-09-07T15:34:02

1 posts

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution.

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CapTechGroup@mastodon.social at 2026-09-15T12:46:42.000Z ##

BlueMoon chain: CVE-2026-85046 for arbitrary read/write in the Chrome V8 sandbox, CVE-2026-87491 to escape the browser sandbox, CVE-2026-85880 (Windows ALPC) to inject into the Chrome process. Delivery: reflected XSS on a...

captechgroup.com/threat-intell

##

CVE-2026-80881
(0 None)

EPSS: 0.17%

updated 2026-09-04T17:17:00.390000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix buffer head management in ocfs2_read_blocks() In ocfs2_read_blocks(), caller should't assume that buffer head returned by 'sb_getblk()' is exclusively owned and so 'put_bh()' always drops b_count from 1 to 0. If it is not so, buffer head remains on hold and likely to be returned by the next call to 'sb_getblk()' unch

sigint@fosstodon.org at 2026-09-15T23:45:08.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-09-16

Another kernel CVE patched upstream and in Ubuntu. If you run your own kernel builds or LTS HWE stacks, check this against your running version before your next reboot window.

🔗 vulners.com/osv/OSV:UBUNTU-CVE

#Ubuntu #Linux #infosec

##

CVE-2026-83548
(10.0 CRITICAL)

EPSS: 4.67%

updated 2026-09-03T13:06:16.053000

1 posts

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Nuclei template

3 repos

https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis

https://github.com/HORKimhab/CVE-2026-83548-CVE-2026-83549

https://github.com/xcoy0te/CVE-2026-83548-checker

cyberveille@mastobot.ping.moi at 2026-09-14T15:30:05.000Z ##

📢 SonicWall SMA1000 : module Metasploit pour chaîne RCE non authentifiée (CVE-2026-83548 + CVE-2026-83549)

Ce pull request Metasploit (PR #21883) documente l'intégration d'un module d'exploitation complet pour une chaîne de vulnérabilités zero-day affectant les appliances SonicWall Secure Mobile Access 1000 (SMA1000), divulguée début septembre 2026 comme…

📖 cyberveille : cyberveille.ch/posts/2026-09-1
🌐 source : github.com/rapid7/metasploit-f
🟡 vérification factuelle moyenne
#Metasploit #RCE #Cyberveille

##

CVE-2026-83549
(7.8 HIGH)

EPSS: 8.51%

updated 2026-09-02T18:32:06

1 posts

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

2 repos

https://github.com/HORKimhab/CVE-2026-83548-CVE-2026-83549

https://github.com/xcoy0te/CVE-2026-83548-checker

cyberveille@mastobot.ping.moi at 2026-09-14T15:30:05.000Z ##

📢 SonicWall SMA1000 : module Metasploit pour chaîne RCE non authentifiée (CVE-2026-83548 + CVE-2026-83549)

Ce pull request Metasploit (PR #21883) documente l'intégration d'un module d'exploitation complet pour une chaîne de vulnérabilités zero-day affectant les appliances SonicWall Secure Mobile Access 1000 (SMA1000), divulguée début septembre 2026 comme…

📖 cyberveille : cyberveille.ch/posts/2026-09-1
🌐 source : github.com/rapid7/metasploit-f
🟡 vérification factuelle moyenne
#Metasploit #RCE #Cyberveille

##

CVE-2026-81573
(8.6 HIGH)

EPSS: 0.46%

updated 2026-09-01T20:56:59.203000

2 posts

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the

certvde at 2026-09-15T08:17:37.359Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

##

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-81575
(7.5 HIGH)

EPSS: 0.44%

updated 2026-09-01T20:56:59.203000

2 posts

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime.

certvde at 2026-09-15T08:17:37.359Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

##

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 1.62%

updated 2026-08-31T21:31:56

1 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

Nuclei template

2 repos

https://github.com/virologi-info/papercut-toolkit

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

sayzard@mastodon.sayzard.org at 2026-09-14T12:46:09.000Z ##

PaperCut Attacker (Russian Linked) Uses AI Agents to Compromise 440 Instances

러시아어권으로 추정되는 공격자가 PaperCut NG/MF의 인증 우회·RCE 체인(CVE-2026-81578, CVE-2026-82078)을 악용해 48개국 395개 조직의 최소 440개 인스턴스를 침해한 것으로 보고됐다. 공격자는 OpenAI Codex, DeepSeek 모델, Hindsight의 지속 메모리, AionUi 멀티 에이전트 작업 공간을 결합해 취약점 분석부터 익스플로잇 수정, 표적 분류, 재시도, AD 정찰까지 자동화했으며, 실제 공격 개시 후 2...

swapupdate.in/papercut-attacke

##

CVE-2026-82448
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-08-29T15:30:20

2 posts

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.

DailyCyberSecurity at 2026-09-14T14:01:45.847Z ##

A critical Shinobi vulnerability (CVE-2026-82448) uses a hardcoded child node key to reach the camera database unauthenticated. Patch and lock port 8288.

meterpreter.org/shinobi-hardco

##

DailyCyberSecurity@infosec.exchange at 2026-09-14T14:01:45.000Z ##

A critical Shinobi vulnerability (CVE-2026-82448) uses a hardcoded child node key to reach the camera database unauthenticated. Patch and lock port 8288.

#Shinobi #CVE202682448 #CCTV #Vulnerability #HardcodedKey #CyberSecurity #InfoSec

meterpreter.org/shinobi-hardco

##

CVE-2026-81576
(7.7 HIGH)

EPSS: 0.33%

updated 2026-08-27T12:30:27

2 posts

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

certvde at 2026-09-15T08:17:37.359Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

##

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-81572
(7.8 HIGH)

EPSS: 0.17%

updated 2026-08-27T12:30:27

2 posts

cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, thi

certvde at 2026-09-15T08:17:37.359Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

##

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-81574
(8.2 HIGH)

EPSS: 0.41%

updated 2026-08-27T12:30:27

2 posts

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely

certvde at 2026-09-15T08:17:37.359Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

##

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

VirusBulletin at 2026-09-15T08:43:23.308Z ##

Acronis TRU uncovered a multinational campaign in which Red Heron, a Chinese-speaking threat actor, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. acronis.com/en/tru/posts/red-h

##

cyberworldops at 2026-09-14T19:00:01.109Z ##

Red Heron exploited CVE-2026-60004, a critical Gitea RCE, to compromise 13 organizations after scanning 1,386 exposed instances. Exposed dev platforms offer direct access to code and lateral movement. Patch, restrict exposure and review logs.

cyberworldops.eu/en/red-heron-

##

hackmag at 2026-09-14T15:03:08.768Z ##

⚪️ Over 8,300 Gitea Servers Vulnerable to Remote Code Execution

🗨️ Researchers at The Shadowserver Foundation warn that more than 8,300 internet-exposed Gitea instances remain unprotected against the critical CVE-2026-60004 vulnerability. The flaw is already being exploited in real-world attacks and allows arbitrary commands to be executed on vulnerable servers.…

🔗 hackmag.com/news/gitea-rce?utm

##

VirusBulletin@infosec.exchange at 2026-09-15T08:43:23.000Z ##

Acronis TRU uncovered a multinational campaign in which Red Heron, a Chinese-speaking threat actor, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. acronis.com/en/tru/posts/red-h

##

cyberworldops@infosec.exchange at 2026-09-14T19:00:01.000Z ##

Red Heron exploited CVE-2026-60004, a critical Gitea RCE, to compromise 13 organizations after scanning 1,386 exposed instances. Exposed dev platforms offer direct access to code and lateral movement. Patch, restrict exposure and review logs. #GiteaSecurity #ThreatIntel #SupplyChain

cyberworldops.eu/en/red-heron-

##

hackmag@infosec.exchange at 2026-09-14T15:03:08.000Z ##

⚪️ Over 8,300 Gitea Servers Vulnerable to Remote Code Execution

🗨️ Researchers at The Shadowserver Foundation warn that more than 8,300 internet-exposed Gitea instances remain unprotected against the critical CVE-2026-60004 vulnerability. The flaw is already being exploited in real-world attacks and allows arbitrary commands to be executed on vulnerable servers.…

🔗 hackmag.com/news/gitea-rce?utm

#news

##

CVE-2026-56368
(3.7 LOW)

EPSS: 0.26%

updated 2026-08-26T20:48:48

2 posts

A memory leak vulnerability exists in multiple coders that write raw pixel data where an object is not freed. ``` Direct leak of 160 byte(s) in 1 object(s) allocated from: ```

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 45.88%

updated 2026-08-18T18:32:52

2 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

2 repos

https://github.com/HORKimhab/CVE-2026-59310

https://github.com/BiuTrap/CVE-2026-59310

undercodenews@mastodon.social at 2026-09-15T17:41:50.000Z ##

CISA Warns VMware vCenter Flaw Is Now in the Hands of Ransomware Gangs + Video

CISA Warns VMware vCenter Flaw Is Now in the Hands of Ransomware Gangs A Critical VMware Vulnerability Has Entered a More Dangerous Phase A critical vulnerability in VMware vCenter Server has moved from a serious patching concern to an active ransomware threat. CISA has warned that ransomware operators are now exploiting CVE-2026-59310, a critical directory-traversal vulnerability that can…

undercodenews.com/cisa-warns-v

##

Analyst207@mastodon.social at 2026-09-15T12:33:40.000Z ##

Ransomware gangs exploit VMware flaw

Ransomware gangs are actively exploiting a critical VMware flaw, CVE-2026-59310, that was patched just two weeks ago, putting organizations at risk of devastating attacks. The US Cybersecurity and Infrastructure Security Agency has warned of the vulnerability, which allows unauthenticated attackers to execute arbitrary code.

osintsights.com/ransomware-gan

#VmwareFlaw #Ransomware #Cve202659310 #EmergingThreats #SupplyChain

##

netsecio@mastodon.social at 2026-09-14T16:54:33.000Z ##

📰 Mathspace Breach Affects 1M Users via Metabase Flaw

Education platform Mathspace discloses a data breach affecting over 1 million users. Attackers exploited a known SQL injection flaw (CVE-2026-72898) in a self-hosted Metabase instance to access user PII. #DataBreach #CyberSecurity #EdTech #Metabase

🔗 cyber.netsecops.io/articles/ma

##

CVE-2026-62721
(7.8 HIGH)

EPSS: 0.41%

updated 2026-08-11T18:31:23

2 posts

Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.

briankrebs at 2026-09-14T20:43:08.956Z ##

Microsoft today released an out of band update that includes a security update to a vulnerability they first patched in August. I guess the first patch didn't work broadly enough or introduced more flaws (or both). According to MS, though, there aren't any signs this vulnerability is actively being exploited. MS just says "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix."

support.microsoft.com/en-us/se

msrc.microsoft.com/update-guid

##

briankrebs@infosec.exchange at 2026-09-14T20:43:08.000Z ##

Microsoft today released an out of band update that includes a security update to a vulnerability they first patched in August. I guess the first patch didn't work broadly enough or introduced more flaws (or both). According to MS, though, there aren't any signs this vulnerability is actively being exploited. MS just says "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix."

support.microsoft.com/en-us/se

msrc.microsoft.com/update-guid

##

CVE-2026-61511
(9.8 CRITICAL)

EPSS: 70.77%

updated 2026-08-07T06:31:24

1 posts

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style

5 repos

https://github.com/shootcannon/CVE-2026-61511

https://github.com/puj790201-lab/cve-2026-61511

https://github.com/tc4dy/CVE-2026-61511-PoC-Exploit

https://github.com/HORKimhab/CVE-2026-61511

https://github.com/codeb0ssx/Ultimate-CVE-2026-61511

_r_netsec@infosec.exchange at 2026-09-13T17:43:13.000Z ##

[CVE-2026-61511] vBulletin <= 6.2.1 (runMaths) Pre-Auth RCE Vulnerability karmainsecurity.com/KIS-2026-13

##

CVE-2026-62946
(5.1 MEDIUM)

EPSS: 0.09%

updated 2026-08-03T16:19:22.763000

2 posts

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52 and 7.1.2-27.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-4986
(5.3 MEDIUM)

EPSS: 0.20%

updated 2026-07-23T08:10:00.137000

1 posts

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

2 repos

https://github.com/Ap0dexMe0/CVE-2026-49869

https://github.com/cyeezy08/Kimai-CVE-2026-49865-POC

CVE-2026-49176
(7.8 HIGH)

EPSS: 0.47%

updated 2026-07-22T16:17:28.753000

1 posts

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/DavidCarliez/CVE-2026-49176_LPE_POC

https://github.com/777erp/CVE-2026-49176_BOF

CVE-2026-57130
(8.1 HIGH)

EPSS: 0.35%

updated 2026-07-20T21:26:50

2 posts

## Summary The email search tool in `src/praisonai-agents/praisonaiagents/tools/email_tools.py` constructs IMAP SEARCH commands by interpolating LLM-controlled parameters (from_addr, subject, query) directly into IMAP protocol strings using f-string formatting with double-quote delimiters. An attacker who can influence the arguments to the `search_emails` or `reply_email` tool (via crafted agent

thehackerwire@mastodon.social at 2026-09-14T16:00:38.000Z ##

🟠 CVE-2026-57130 - High (8.1)

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedde...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T16:00:38.000Z ##

🟠 CVE-2026-57130 - High (8.1)

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedde...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57126
(8.5 HIGH)

EPSS: 0.38%

updated 2026-07-20T21:25:26

2 posts

# praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS **Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial & Offensive Security Research **Target:** https://github.com/MervinPraison/PraisonAI **Weakness:** CWE-918 Server-Side Request Forgery (SSRF). --- ## Summary The SSRF guard shared by PraisonAI's web tools (`SpiderTools._validate_url` → `_host_is_bl

thehackerwire@mastodon.social at 2026-09-14T16:00:16.000Z ##

🟠 CVE-2026-57126 - High (8.5)

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extract_text, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T16:00:16.000Z ##

🟠 CVE-2026-57126 - High (8.5)

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extract_text, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61865
(2.9 LOW)

EPSS: 0.10%

updated 2026-07-15T18:20:21.237000

2 posts

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-61864
(2.9 LOW)

EPSS: 0.10%

updated 2026-07-15T18:20:21.237000

2 posts

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-61863
(2.9 LOW)

EPSS: 0.19%

updated 2026-07-15T12:32:05

2 posts

ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-61866
(2.9 LOW)

EPSS: 0.19%

updated 2026-07-15T12:32:05

2 posts

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-50458
(7.8 HIGH)

EPSS: 0.26%

updated 2026-07-14T18:32:25

1 posts

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-56373
(3.7 LOW)

EPSS: 0.23%

updated 2026-07-13T15:15:51.143000

2 posts

ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-61857
(3.7 LOW)

EPSS: 0.27%

updated 2026-07-11T15:30:30

2 posts

ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-61870
(2.9 LOW)

EPSS: 0.19%

updated 2026-07-11T15:30:30

2 posts

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-61465
(3.3 LOW)

EPSS: 0.17%

updated 2026-07-11T15:30:29

2 posts

ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56366
(3.3 LOW)

EPSS: 0.17%

updated 2026-07-10T15:31:48

2 posts

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-57239
(8.2 HIGH)

EPSS: 0.17%

updated 2026-07-09T15:33:27

1 posts

The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.

1 repos

https://github.com/Paradoxis/CVE-2026-57239

CVE-2026-56371
(5.3 MEDIUM)

EPSS: 0.26%

updated 2026-07-02T15:17:07.390000

2 posts

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56379(CVSS UNKNOWN)

EPSS: 0.88%

updated 2026-06-30T03:38:15

2 posts

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56370
(3.3 LOW)

EPSS: 0.12%

updated 2026-06-26T21:50:37.890000

2 posts

ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential code execution.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-47203(CVSS UNKNOWN)

EPSS: 0.45%

updated 2026-06-26T21:32:44

2 posts

### Impact **CVSSv4 Baseline Score:** Moderate 6.3 **CVSSv4 Weighted Score:** Low 2.9 The full CVSSv4 Vector for this vulnerability is: > CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:L/IR:L/AR:L/MAV:N/MAC:H/MAT:N/MPR:N/MUI:N/MVC:L/MVI:N/MVA:N/MSC:N/MSI:N/MSA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Green **CVSSv3.1 Baseline Score:** Low 3.7 **CVSSv3.1 Overall Score:** Medium 4.0

IanTwenty@piefed.social at 2026-09-15T19:05:41.993Z ##

Say that new authelia exploit looks like one fail2ban already recognises or relies on timing/brute-force then you’re covered even before a patch is available.

Here’s a real authelia vuln:

https://app.opencve.io/cve/CVE-2026-47203

allowing an attacker to circumvent login throttling or account lockouts by simply altering the case of their credentials.

I think fail2ban would help protect authelia here?

##

IanTwenty@piefed.social at 2026-09-15T19:05:41.993Z ##

Say that new authelia exploit looks like one fail2ban already recognises or relies on timing/brute-force then you’re covered even before a patch is available.

Here’s a real authelia vuln:

https://app.opencve.io/cve/CVE-2026-47203

allowing an attacker to circumvent login throttling or account lockouts by simply altering the case of their credentials.

I think fail2ban would help protect authelia here?

##

CVE-2026-45051(CVSS UNKNOWN)

EPSS: 0.69%

updated 2026-06-24T17:25:29

2 posts

## Summary **Description** A deserialization of untrusted data vulnerability (CWE-502) exists in OpenAM's WebAuthn authentication module. Under certain conditions, this may allow an attacker to achieve arbitrary code execution in the context of the application server. This affects OpenAM Community Edition through version 16.0.6 and was patched in version 16.1.1. This is not the default configur

offseq at 2026-09-15T10:30:25.725Z ##

OpenAM <16.1.1 suffers from CRITICAL deserialization vuln (CVE-2026-45051, CVSS 9.2). WebAuthnAuthentication lets attackers run arbitrary code via crafted serialized data. Patch to 16.1.1 ASAP! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-15T10:30:25.000Z ##

OpenAM <16.1.1 suffers from CRITICAL deserialization vuln (CVE-2026-45051, CVSS 9.2). WebAuthnAuthentication lets attackers run arbitrary code via crafted serialized data. Patch to 16.1.1 ASAP! radar.offseq.com/threat/cve-20 #OffSeq #CVE202645051 #OpenAM #infosec

##

CVE-2026-56378
(3.7 LOW)

EPSS: 0.22%

updated 2026-06-21T15:31:31

2 posts

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-4201
(7.3 HIGH)

EPSS: 0.28%

updated 2026-06-17T10:56:10.603000

1 posts

A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This vulnerability affects the function Upload of the file business/business-system/src/main/java/com/glowxq/system/admin/controller/SysFileController.java. Executing a manipulation can lead to unrestricted upload. The attack can be launched remotely. The exploit has been made available to the public

cyberveille@mastobot.ping.moi at 2026-09-14T16:30:05.000Z ##

📢 Exploitation active de trois vulnérabilités critiques dans JFrog Artifactory

🔍 Contexte : Le 10 septembre 2026, Wiz Research publie une analyse technique détaillant l'exploitation active en conditions réelles de trois vulnérabilités critiques et de haute sévérité affectant JFrog Artifactory.

📖 cyberveille : cyberveille.ch/posts/2026-09-1
🌐 source : wiz.io/blog/artifactory-under-
🟢 vérification factuelle haute
#JFrogArtifactory #ExploitationActive #Cyberveille

##

CVE-2026-28993
(5.5 MEDIUM)

EPSS: 0.12%

updated 2026-06-17T10:29:27.873000

2 posts

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access user-sensitive data.

jgordon@appdot.net at 2026-09-14T13:23:07.000Z ##

Sequoia 15.7.7 broke a critical shortcut I use. Terra says "Apple’s Shortcuts security fix for CVE-2026-28993,"

It doesn't always fail, just most of the time.

It feels like I run into something of this nature every day now.

##

jgordon@appdot.net at 2026-09-14T13:23:07.000Z ##

Sequoia 15.7.7 broke a critical shortcut I use. Terra says "Apple’s Shortcuts security fix for CVE-2026-28993,"

It doesn't always fail, just most of the time.

It feels like I run into something of this nature every day now.

##

CVE-2026-27540
(9.0 CRITICAL)

EPSS: 1.73%

updated 2026-06-17T10:27:18.693000

3 posts

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.

1 repos

https://github.com/Nxploited/CVE-2026-27542-CVE-2026-27540-

security_crawler_carl at 2026-09-15T19:55:23.914Z ##

🏆 New Achievement! Exceeded All KPIs Except Staying Uncompromised!

Your Q3 infrastructure review is in. Uptime: stellar. Deployment pipeline: smooth. WooCommerce Wholesale Lead Capture plugin: actively backdoored via CVE-2026-27540. That last one is what we in management call an "opportunity area."

Attackers are currently exploiting this critical flaw in the wild, planting PHP backdoors and achieving full takeover of WordPress stores. Everything was going so well, team. Really. (1/3)

##

undercodenews@mastodon.social at 2026-09-15T19:36:55.000Z ##

Critical WooCommerce Vulnerability Is Under Active Attack, Putting WordPress Stores at Risk of PHP Backdoors and Full Takeover + Video

Introduction: A WordPress Plugin Became an Open Door A critical vulnerability in the WooCommerce Wholesale Lead Capture plugin is now being actively exploited by attackers, turning a seemingly ordinary WordPress extension into a potential gateway for complete website compromise. The vulnerability, tracked as CVE-2026-27540, allows…

undercodenews.com/critical-woo

##

security_crawler_carl@infosec.exchange at 2026-09-15T19:55:23.000Z ##

🏆 New Achievement! Exceeded All KPIs Except Staying Uncompromised!

Your Q3 infrastructure review is in. Uptime: stellar. Deployment pipeline: smooth. WooCommerce Wholesale Lead Capture plugin: actively backdoored via CVE-2026-27540. That last one is what we in management call an "opportunity area."

Attackers are currently exploiting this critical flaw in the wild, planting PHP backdoors and achieving full takeover of WordPress stores. Everything was going so well, team. Really. (1/3)

##

CVE-2025-30208
(5.3 MEDIUM)

EPSS: 74.97%

updated 2026-06-17T09:08:21.517000

2 posts

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places

23 repos

https://github.com/TH-SecForge/CVE-2025-30208

https://github.com/iSee857/CVE-2025-30208-PoC

https://github.com/4m3rr0r/CVE-2025-30208-PoC

https://github.com/nkuty/CVE-2025-30208-31125-31486-32395

https://github.com/cc3305/CVE-2025-30208

https://github.com/ThemeHackers/CVE-2025-30208

https://github.com/sumeet-darekar/CVE-2025-30208

https://github.com/keklick1337/CVE-2025-30208-ViteVulnScanner

https://github.com/xuemian168/CVE-2025-30208

https://github.com/lilil3333/Vite-CVE-2025-30208-EXP

https://github.com/HazaVVIP/CVE-2025-30208

https://github.com/r0ngy40/CVE-2025-30208-Series

https://github.com/0xshaheen/CVE-2025-30208

https://github.com/On1onss/CVE-2025-30208

https://github.com/MiclelsonCN/CVE-2025-30208_POC

https://github.com/jackieya/ViteVulScan

https://github.com/sadhfdw129/CVE-2025-30208-Vite

https://github.com/4xura/CVE-2025-30208

https://github.com/imbas007/CVE-2025-30208-template

https://github.com/ThumpBo/CVE-2025-30208-EXP

https://github.com/marino-admin/Vite-CVE-2025-30208-Scanner

https://github.com/Lusensec/CVE-2025-30208

https://github.com/HaGsec/CVE-2025-30208

cyberworldops at 2026-09-15T01:00:00.926Z ##

F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets.

cyberworldops.eu/en/hackers-sc

##

cyberworldops@infosec.exchange at 2026-09-15T01:00:00.000Z ##

F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence

cyberworldops.eu/en/hackers-sc

##

CVE-2024-45811
(4.8 MEDIUM)

EPSS: 1.06%

updated 2026-06-17T07:54:51.767000

2 posts

Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it exists. This issue has been patched in versions 5.4.6, 5.3.6, 5.2.14, 4.5.5, and 3.2.11. Users are adv

cyberworldops at 2026-09-15T01:00:00.926Z ##

F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets.

cyberworldops.eu/en/hackers-sc

##

cyberworldops@infosec.exchange at 2026-09-15T01:00:00.000Z ##

F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence

cyberworldops.eu/en/hackers-sc

##

CVE-2024-3094
(10.0 CRITICAL)

EPSS: 85.97%

updated 2026-06-17T07:43:17.830000

1 posts

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked

90 repos

https://github.com/Dermot-lab/TryHack

https://github.com/mesutgungor/xz-backdoor-vulnerability

https://github.com/nnatsopoulos/xz-backdoor-research

https://github.com/weltregie/liblzma-scan

https://github.com/badsectorlabs/ludus_xz_backdoor

https://github.com/BOSE122/CVE-2024-3094

https://github.com/amlweems/xzbot

https://github.com/robertdfrench/ifuncd-up

https://github.com/byinarie/CVE-2024-3094-info

https://github.com/Juul/xz-backdoor-scan

https://github.com/encikayelwhitehat-glitch/CVE-2024-3094

https://github.com/FabioBaroni/CVE-2024-3094-checker

https://github.com/AndreaCicca/Sicurezza-Informatica-Presentazione

https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094

https://github.com/brinhosa/CVE-2024-3094-One-Liner

https://github.com/mrk336/CVE-2024-3094

https://github.com/galacticquest/cve-2024-3094-detect

https://github.com/devjanger/CVE-2024-3094-XZ-Backdoor-Detector

https://github.com/Simplifi-ED/CVE-2024-3094-patcher

https://github.com/harekrishnarai/xz-utils-vuln-checker

https://github.com/jfrog/cve-2024-3094-tools

https://github.com/Michel-DV/xz-utils-backdoor-case-study

https://github.com/MagpieRYL/CVE-2024-3094-backdoor-env-container

https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094

https://github.com/robertdebock/ansible-playbook-cve-2024-3094

https://github.com/ykhurshudyan-blip/CVE-2024-3094

https://github.com/been22426/CVE-2024-3094

https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project

https://github.com/ackemed/detectar_cve-2024-3094

https://github.com/Ava-Vispilio/CVE-2024-3094

https://github.com/Fractal-Tess/CVE-2024-3094

https://github.com/0xlane/xz-cve-2024-3094

https://github.com/shefirot/CVE-2024-3094

https://github.com/Security-Phoenix-demo/CVE-2024-3094-fix-exploits

https://github.com/hackura/xz-cve-2024-3094

https://github.com/Yuma-Tsushima07/CVE-2024-3094

https://github.com/hackingetico21/revisaxzutils

https://github.com/robertdebock/ansible-role-cve_2024_3094

https://github.com/hariskhalil555000-sketch/What-utility-does-CVE-2024-3094-refer-to-

https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094

https://github.com/h3raklez/CVE-2024-3094

https://github.com/hazemkya/CVE-2024-3094-checker

https://github.com/bsekercioglu/cve2024-3094-Checker

https://github.com/ElinaNotElina/cve-2024-3094-analysis

https://github.com/0xBlackash/CVE-2024-3094

https://github.com/valeriot30/cve-2024-3094

https://github.com/spidygal/CVE-2024-3094-Nmap-NSE-script

https://github.com/fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-

https://github.com/gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer

https://github.com/wgetnz/CVE-2024-3094-check

https://github.com/jbnetwork-git/CVE-2024-3094-XZ-Utils-Check

https://github.com/mightysai1997/CVE-2024-3094

https://github.com/neuralinhibitor/xzwhy

https://github.com/zpxlz/CVE-2024-3094

https://github.com/mhicairo-hue/cs50-cybersecurity-final-project

https://github.com/ThomRgn/xzutils_backdoor_obfuscation

https://github.com/KaminaDuck/ansible-CVE-2024-3094

https://github.com/M1lo25/CS50FinalProject

https://github.com/stevehenderson/lab_xz_backdoor

https://github.com/24Owais/threat-intel-cve-2024-3094

https://github.com/r0binak/xzk8s

https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker

https://github.com/isuruwa/CVE-2024-3094

https://github.com/Mustafa1986/CVE-2024-3094

https://github.com/ashwani95/CVE-2024-3094

https://github.com/vnchk1/sec_review_cve-2024-3094

https://github.com/TheTorjanCaptain/CVE-2024-3094-Checker

https://github.com/przemoc/xz-backdoor-links

https://github.com/Ikram124/CVE-2024-3094-analysis

https://github.com/vesjolyjd/Kaspersky_CVE-2024-3094

https://github.com/buluma/ansible-role-cve_2024_3094

https://github.com/lockness-Ko/xz-vulnerable-honeypot

https://github.com/pentestfunctions/CVE-2024-3094

https://github.com/iheb2b/CVE-2024-3094-Checker

https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094

https://github.com/ScrimForever/CVE-2024-3094

https://github.com/extracoding-dozen/CVE-2024-3094

https://github.com/dah4k/CVE-2024-3094

https://github.com/felipecosta09/cve-2024-3094

https://github.com/bioless/xz_cve-2024-3094_detection

https://github.com/Bella-Bc/xz-backdoor-CVE-2024-3094-Check

https://github.com/gustavorobertux/CVE-2024-3094

https://github.com/teyhouse/CVE-2024-3094

https://github.com/mightysai1997/CVE-2024-3094-info

https://github.com/emirkmo/xz-backdoor-github

https://github.com/Horizon-Software-Development/CVE-2024-3094

https://github.com/HackerHermanos/CVE-2024-3094_xz_check

https://github.com/x-cmd-build/xz

https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public

https://github.com/michalAshurov/writeup-CVE-2024-3094

hugovalters@mastodon.social at 2026-09-16T03:20:23.000Z ##

Scraping NVD means rate limits, pagination, and schema drift you own forever. The ValtersIT CVE API returns normalized CVE, vendor, and exploit data in one call: curl valtersit.com/api/cve/CVE-2024 Pricing: valtersit.com/cve/pricing/

##

CVE-2024-1813
(9.8 CRITICAL)

EPSS: 1.22%

updated 2026-06-17T07:05:03.993000

1 posts

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could al

1 repos

https://github.com/MobetaSec/CVE-2024-1813-POC

_r_netsec@infosec.exchange at 2026-09-13T17:43:15.000Z ##

Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) mobeta.fr/simple-job-board-una

##

CVE-2023-38198
(9.8 CRITICAL)

EPSS: 1.08%

updated 2026-06-17T06:09:38.793000

2 posts

acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.

niconiconi@mk.absturztau.be at 2026-09-16T02:31:21.811Z ##

Using acme.sh to renew a certificate as root sounds like a RCE-as-root waiting to happen. A Web client written in pure shell, what could possibly go wrong? I just wrote a script to drop its own privilege when it calls acme.sh, so it's safe to use in a root cronjob.

After writing this, I found RCE-as-root is not just "waiting" to happen, it has already happened as CVE-2023-38198. Someone even argued the case as a possible mechanism responsible for the jabber.ru wiretapping incident.
https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/

##

niconiconi@mk.absturztau.be at 2026-09-16T02:31:21.811Z ##

Using acme.sh to renew a certificate as root sounds like a RCE-as-root waiting to happen. A Web client written in pure shell, what could possibly go wrong? I just wrote a script to drop its own privilege when it calls acme.sh, so it's safe to use in a root cronjob.

After writing this, I found RCE-as-root is not just "waiting" to happen, it has already happened as CVE-2023-38198. Someone even argued the case as a possible mechanism responsible for the jabber.ru wiretapping incident.
https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/

##

CVE-2026-39987
(9.8 CRITICAL)

EPSS: 98.95%

updated 2026-04-27T16:30:09

4 posts

## Summary Marimo (19.6k stars) has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint `/terminal/ws` lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., `/ws`) that correctly call `validate_auth()` for authentication, the `/terminal/ws` endpoint only checks the

25 repos

https://github.com/Nxploited/CVE-2026-39987

https://github.com/rootdirective-sec/CVE-2026-39987-Lab

https://github.com/0xBlackash/CVE-2026-39987

https://github.com/vanhari/CVE-2026-39987

https://github.com/Ghxstsec/CVE-2026-39987

https://github.com/MADA0L/CVE-2026-39987-Poc

https://github.com/matesz44/cve-2026-39987

https://github.com/mki9/CVE-2026-39987_exploit

https://github.com/alreadyClosed/CVE-2026-39987

https://github.com/HORKimhab/CVE-2026-39987

https://github.com/K3ysTr0K3R/CVE-2026-39987

https://github.com/M3PH1569/CVE-2026-39987-POC

https://github.com/keraattin/CVE-2026-39987

https://github.com/iapetus12/cohort-htb

https://github.com/fevar54/marimo_CVE-2026-39987_RCE_PoC

https://github.com/gbuyssens/CVE-2026-39987

https://github.com/dodeepsink/CVE-2026-39987.py

https://github.com/julichaan/CVE-2026-39987_POC

https://github.com/h3raklez/CVE-2026-39987

https://github.com/Wind010/CVE-2026-39987_PoC

https://github.com/Clara-M-Grossl/Exploit-Marimo

https://github.com/0xdeadroot/CVE-2026-39987-marimo-rce

https://github.com/Dhiaelhak-Rached/CVE-2026-39987-lab-or-marimo-cve-lab

https://github.com/stapat1245/CVE-2026-39987-PoC

https://github.com/jasonbernier/CVE-2026-39987

cyberworldops at 2026-09-15T14:50:01.149Z ##

Sysdig reports a human operator exploited CVE-2026-39987, a pre-auth RCE in Marimo, and pivoted from the notebook to an SSH bastion in eight seconds with a custom Python toolkit. It shows manual tradecraft can match automation speed, shrinking detection windows for exposed dev infrastructure.

cyberworldops.eu/en/human-oper

##

Analyst207@mastodon.social at 2026-09-15T13:03:19.000Z ##

Skilled Human Attackers Exploit Marimo Flaw to Reach SSH Bastion in 8 Seconds

In a stunning display of speed, a skilled human attacker exploited a flaw in Marimo to breach a secure SSH bastion in just 8 seconds - a pace typically associated with AI-assisted attacks. This remarkable feat was made possible by a pre-authenticated remote code execution bug, CVE-2026-39987, with a near-perfect CVSS score of 9.3.

osintsights.com/skilled-human-

#Marimo #RceExploit #Cve202639987 #SshBastion #CredentialPivot

##

Analyst207@mastodon.social at 2026-09-14T15:04:17.000Z ##

Human Exploits Marimo Flaw to Breach SSH Bastion Host in 8 Seconds

In just 8 seconds, a human attacker exploited a vulnerability in Marimo notebooks to breach an SSH bastion host, showcasing the alarming speed and ease of lateral movement within compromised systems. This lightning-fast breach was achieved without the aid of AI tools, highlighting the severity of the CVE-2026-39987 flaw.

osintsights.com/human-exploits

#Marimo #Cve202639987 #SshBastionHost #RemoteCodeExecution #Preauthentication

##

cyberworldops@infosec.exchange at 2026-09-15T14:50:01.000Z ##

Sysdig reports a human operator exploited CVE-2026-39987, a pre-auth RCE in Marimo, and pivoted from the notebook to an SSH bastion in eight seconds with a custom Python toolkit. It shows manual tradecraft can match automation speed, shrinking detection windows for exposed dev infrastructure. #MarimoRce #SshBastion #IncidentResponse

cyberworldops.eu/en/human-oper

##

CVE-2026-39364(CVSS UNKNOWN)

EPSS: 2.00%

updated 2026-04-07T22:16:19

8 posts

### Summary The contents of files that are specified by [`server.fs.deny`](https://vite.dev/config/server-options#server-fs-deny) can be returned to the browser. ### Impact Only apps that match the following conditions are affected: - explicitly exposes the Vite dev server to the network (using `--host` or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host)

Analyst207@mastodon.social at 2026-09-15T13:05:37.000Z ##

Mass-Scanning Campaign Exploits Vite Flaw to Harvest Cloud Credentials

A high-severity flaw in Vite, tracked as CVE-2026-39364, has been exploited in a mass-scanning campaign, allowing attackers to bypass security restrictions and harvest cloud credentials. By manipulating query parameters, unauthenticated attackers can leak sensitive files that were meant to be blocked.

osintsights.com/mass-scanning-

#ViteFlaw #Cve202639364 #CloudCredentials #SupplyChain #EmergingThreats

##

ottoto2017@prattohome.com at 2026-09-15T05:47:23.000Z ##

「ハッカーがViteの開発サーバーを標的にAWSとAzureの機密情報を盗み出す 」: #BLEEPINGCOMPUTER

「インターネットに公開されているVite開発サーバーを標的とした大規模なスキャンキャンペーンが、AWSおよびAzure環境からクラウド認証情報と設定を盗み出そうとしている。

この攻撃は、Vite バージョン 7.1.0 から 7.3.2、および 8.x ブランチの 8.0.5 より前のバージョンにおいて、ファイルの読み取り/アクセス制御を回避できる深刻な脆弱性である CVE-2026-39364 を悪用するものです。

この脆弱性は4月7日に公表され、認証されていない攻撃者がHTTP GETリクエストのクエリパラメータを操作することで、セキュリティ制限を回避し、通常はアクセスできないはずの場所から平文のファイルを取得できるというものである。」

bleepingcomputer.com/news/secu

#prattohome

##

DailyCyberSecurity at 2026-09-15T01:40:44.791Z ##

The Vite development server vulnerability CVE-2026-39364 is exploited in mass scanning for credential harvesting. F5 Labs logged 32,000 events. Patch now.

securityonline.info/vite-cve-2

##

cyberworldops at 2026-09-15T01:00:00.926Z ##

F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets.

cyberworldops.eu/en/hackers-sc

##

undercodenews@mastodon.social at 2026-09-14T22:00:14.000Z ##

Hackers Are Mass-Scanning Exposed Vite Servers to Steal AWS, Azure and Terraform Secrets + Video

A New Warning for Developers Modern web development depends heavily on fast local development environments, but convenience can become dangerous when those environments are accidentally exposed to the public internet. A new mass-scanning campaign is reportedly targeting exposed Vite development servers, abusing CVE-2026-39364 to access sensitive files and potentially…

undercodenews.com/hackers-are-

##

ottoto2017@prattohome.com at 2026-09-15T05:47:23.000Z ##

「ハッカーがViteの開発サーバーを標的にAWSとAzureの機密情報を盗み出す 」: #BLEEPINGCOMPUTER

「インターネットに公開されているVite開発サーバーを標的とした大規模なスキャンキャンペーンが、AWSおよびAzure環境からクラウド認証情報と設定を盗み出そうとしている。

この攻撃は、Vite バージョン 7.1.0 から 7.3.2、および 8.x ブランチの 8.0.5 より前のバージョンにおいて、ファイルの読み取り/アクセス制御を回避できる深刻な脆弱性である CVE-2026-39364 を悪用するものです。

この脆弱性は4月7日に公表され、認証されていない攻撃者がHTTP GETリクエストのクエリパラメータを操作することで、セキュリティ制限を回避し、通常はアクセスできないはずの場所から平文のファイルを取得できるというものである。」

bleepingcomputer.com/news/secu

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-09-15T01:40:44.000Z ##

The Vite development server vulnerability CVE-2026-39364 is exploited in mass scanning for credential harvesting. F5 Labs logged 32,000 events. Patch now.

#Vite #CVE202639364 #CloudSecurity #CredentialHarvesting #F5Labs #DevSecOps #FileDisclosure #InfoSec #AWS #MassScanning

securityonline.info/vite-cve-2

##

cyberworldops@infosec.exchange at 2026-09-15T01:00:00.000Z ##

F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence

cyberworldops.eu/en/hackers-sc

##

CVE-2026-2275
(9.6 CRITICAL)

EPSS: 0.44%

updated 2026-03-31T18:32:38

1 posts

The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling.

thehackerwire@mastodon.social at 2026-09-14T04:00:15.000Z ##

🟠 CVE-2026-37008 - High (8.1)

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete obj...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-31125
(5.3 MEDIUM)

EPSS: 58.46%

updated 2026-01-22T21:47:41

2 posts

### Summary The contents of arbitrary files can be returned to the browser. ### Impact Only apps explicitly exposing the Vite dev server to the network (using `--host` or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host)) are affected. ### Details - base64 encoded content of non-allowed files is exposed using `?inline&import` (originally reported as `?imp

7 repos

https://github.com/xuemian168/CVE-2025-30208

https://github.com/MuhammadWaseem29/Vitejs-exploit

https://github.com/0xgh057r3c0n/CVE-2025-31125

https://github.com/nkuty/CVE-2025-30208-31125-31486-32395

https://github.com/harshgupptaa/Path-Transversal-CVE-2025-31125-

https://github.com/sunhuiHi666/CVE-2025-31125

https://github.com/jackieya/ViteVulScan

cyberworldops at 2026-09-15T01:00:00.926Z ##

F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets.

cyberworldops.eu/en/hackers-sc

##

cyberworldops@infosec.exchange at 2026-09-15T01:00:00.000Z ##

F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence

cyberworldops.eu/en/hackers-sc

##

CVE-2021-44228
(10.0 CRITICAL)

EPSS: 100.00%

updated 2025-10-22T19:13:26

1 posts

# Summary Log4j versions prior to 2.16.0 are subject to a remote code execution vulnerability via the ldap JNDI parser. As per [Apache's Log4j security guide](https://logging.apache.org/log4j/2.x/security.html): Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who

100 repos

https://github.com/mergebase/log4j-detector

https://github.com/AlexandreHeroux/Fix-CVE-2021-44228

https://github.com/christophetd/log4shell-vulnerable-app

https://github.com/lfama/log4j_checker

https://github.com/toramanemre/log4j-rce-detect-waf-bypass

https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes

https://github.com/CERTCC/CVE-2021-44228_scanner

https://github.com/alexandre-lavoie/python-log4rce

https://github.com/stripe/log4j-remediation-tools

https://github.com/puzzlepeaches/Log4jUnifi

https://github.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit

https://github.com/pedrohavay/exploit-CVE-2021-44228

https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs

https://github.com/darkarnium/Log4j-CVE-Detect

https://github.com/corretto/hotpatch-for-apache-log4j2

https://github.com/bigsizeme/Log4j-check

https://github.com/LiveOverflow/log4shell

https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce

https://github.com/logpresso/CVE-2021-44228-Scanner

https://github.com/tippexs/nginx-njs-waf-cve2021-44228

https://github.com/redhuntlabs/Log4JHunt

https://github.com/Kadantte/CVE-2021-44228-poc

https://github.com/rubo77/log4j_checker_beta

https://github.com/dwisiswant0/look4jar

https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept

https://github.com/MalwareTech/Log4jTools

https://github.com/future-client/CVE-2021-44228

https://github.com/marcourbano/CVE-2021-44228

https://github.com/qingtengyun/cve-2021-44228-qingteng-online-patch

https://github.com/mr-r3b00t/CVE-2021-44228

https://github.com/Diverto/nse-log4shell

https://github.com/NorthwaveSecurity/log4jcheck

https://github.com/CreeperHost/Log4jPatcher

https://github.com/cisagov/log4j-scanner

https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator

https://github.com/thomaspatzke/Log4Pot

https://github.com/CodeShield-Security/Log4JShell-Bytecode-Detector

https://github.com/greymd/CVE-2021-44228

https://github.com/momos1337/Log4j-RCE

https://github.com/Jeromeyoung/log4j2burpscanner

https://github.com/puzzlepeaches/Log4jHorizon

https://github.com/simonis/Log4jPatch

https://github.com/mzlogin/CVE-2021-44228-Demo

https://github.com/fireeye/CVE-2021-44228

https://github.com/claranet/ansible-role-log4shell

https://github.com/toramanemre/apache-solr-log4j-CVE-2021-44228

https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes

https://github.com/kozmer/log4j-shell-poc

https://github.com/justakazh/Log4j-CVE-2021-44228

https://github.com/1lann/log4shelldetect

https://github.com/puzzlepeaches/Log4jCenter

https://github.com/0xDexter0us/Log4J-Scanner

https://github.com/fullhunt/log4j-scan

https://github.com/leonjza/log4jpwn

https://github.com/BinaryDefense/log4j-honeypot-flask

https://github.com/HynekPetrak/log4shell-finder

https://github.com/kubearmor/log4j-CVE-2021-44228

https://github.com/takito1812/log4j-detect

https://github.com/KosmX/CVE-2021-44228-example

https://github.com/Adikso/minecraft-log4j-honeypot

https://github.com/ssl/scan4log4j

https://github.com/thecyberneh/Log4j-RCE-Exploiter

https://github.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228

https://github.com/yahoo/check-log4j

https://github.com/mufeedvh/log4jail

https://github.com/lucab85/log4j-cve-2021-44228

https://github.com/wortell/log4j

https://github.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell

https://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228

https://github.com/boundaryx/cloudrasp-log4j2

https://github.com/NCSC-NL/log4shell

https://github.com/blake-fm/vcenter-log4j

https://github.com/fox-it/log4j-finder

https://github.com/nu11secur1ty/CVE-2021-44228-VULN-APP

https://github.com/corelight/cve-2021-44228

https://github.com/giterlizzi/nmap-log4shell

https://github.com/hackinghippo/log4shell_ioc_ips

https://github.com/cyberxml/log4j-poc

https://github.com/jas502n/Log4j2-CVE-2021-44228

https://github.com/0xInfection/LogMePwn

https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words

https://github.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228

https://github.com/alexbakker/log4shell-tools

https://github.com/DragonSurvivalEU/RCE

https://github.com/CrackerCat/CVE-2021-44228-Log4j-Payloads

https://github.com/dtact/divd-2021-00038--log4j-scanner

https://github.com/qingtengyun/cve-2021-44228-qingteng-patch

https://github.com/Labout/log4shell-rmi-poc

https://github.com/infiniroot/nginx-mitigate-log4shell

https://github.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent

https://github.com/f0ng/log4j2burpscanner

https://github.com/roxas-tan/CVE-2021-44228

https://github.com/sunnyvale-it/CVE-2021-44228-PoC

https://github.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab

https://github.com/sec13b/CVE-2021-44228-POC

https://github.com/Nanitor/log4fix

https://github.com/nccgroup/log4j-jndi-be-gone

https://github.com/mr-vill4in/log4j-fuzzer

https://github.com/NS-Sp4ce/Vm4J

https://github.com/back2root/log4shell-rex

hugovalters@mastodon.social at 2026-09-15T03:20:32.000Z ##

GET /api/cve/CVE-2021-44228 returns CVSS, CPEs, affected vendors, and known exploits in one call. No scraping, no joins. Docs: valtersit.com/cve/pricing/

##

CVE-2026-87886
(0 None)

EPSS: 0.00%

5 posts

N/A

undercodenews@mastodon.social at 2026-09-16T03:27:17.000Z ##

Acronis Backup Plugin Under Attack: Critical Linux Privilege Escalation Flaw Puts Hosting Servers at Risk + Video

A New Warning for Web Hosting Administrators Acronis has disclosed CVE-2026-87886, a high-severity Linux local privilege escalation vulnerability affecting its backup integrations for cPanel & WHM and Plesk. The vulnerability carries a CVSS score of 7.8 and, more importantly, Acronis says exploitation has already been detected in limited, targeted attacks…

undercodenews.com/acronis-back

##

cyberworldops at 2026-09-16T01:00:01.227Z ##

Acronis confirmed active exploitation of CVE-2026-87886, a CVSS 7.8 local privilege escalation in its backup plugin for cPanel and WHM and Plesk. Any local user on shared hosting could escalate to root and compromise all tenants, making immediate patching and audit critical.

cyberworldops.eu/en/acronis-wa

##

Analyst207@mastodon.social at 2026-09-15T22:03:31.000Z ##

Acronis Discloses Exploited Flaw in cPanel Backup Plugin

A high-severity flaw, CVE-2026-87886, has been discovered in the Acronis Backup plugin for cPanel &amp; WHM deployments, and it's been exploited in limited, targeted attacks. This Linux local privilege-escalation vulnerability has a CVSS severity score of 7.8, making it a critical issue that needs attention.

osintsights.com/acronis-disclo

#Cve202687886 #Acronis #Cpanel #Linux #LocalPrivilegeEscalation

##

undercodenews@mastodon.social at 2026-09-15T22:00:28.000Z ##

Acronis Backup Vulnerability Puts Linux Hosting Servers at Risk as Limited Attacks Begin + Video

Introduction: A Quiet Flaw With Serious Consequences A vulnerability hiding inside a widely used server-backup integration has turned into an urgent warning for Linux hosting administrators. Acronis has disclosed CVE-2026-87886, a high-severity local privilege escalation flaw affecting its backup integrations for cPanel & WHM and Plesk, two platforms commonly used to manage…

undercodenews.com/acronis-back

##

cyberworldops@infosec.exchange at 2026-09-16T01:00:01.000Z ##

Acronis confirmed active exploitation of CVE-2026-87886, a CVSS 7.8 local privilege escalation in its backup plugin for cPanel and WHM and Plesk. Any local user on shared hosting could escalate to root and compromise all tenants, making immediate patching and audit critical. #LinuxSecurity #PrivilegeEscalation #CpanelSecurity

cyberworldops.eu/en/acronis-wa

##

CVE-2026-90711
(0 None)

EPSS: 0.19%

4 posts

N/A

DailyCyberSecurity at 2026-09-16T01:18:01.291Z ##

A critical proxy-addr IP spoofing flaw (CVE-2026-90711) exposes Node.js apps to access control bypasses. Patch this proxy-addr IP spoofing bug today.

securityonline.info/proxy-addr

##

thehackerwire@mastodon.social at 2026-09-15T08:00:18.000Z ##

🔴 CVE-2026-90711 - Critical (9.1)

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-si...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T01:18:01.000Z ##

A critical proxy-addr IP spoofing flaw (CVE-2026-90711) exposes Node.js apps to access control bypasses. Patch this proxy-addr IP spoofing bug today.

#ProxyAddr #NodeJS #IPspoofing #CVE202690711 #Cybersecurity

securityonline.info/proxy-addr

##

thehackerwire@mastodon.social at 2026-09-15T08:00:18.000Z ##

🔴 CVE-2026-90711 - Critical (9.1)

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-si...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61642
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-09-16T00:32:00.460Z ##

Multiple critical Squid proxy vulnerabilities, including CVE-2026-61642, allow request smuggling and buffer overflows. Patch your servers immediately.

securityonline.info/squid-prox

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T00:32:00.000Z ##

Multiple critical Squid proxy vulnerabilities, including CVE-2026-61642, allow request smuggling and buffer overflows. Patch your servers immediately.

#SquidProxy #CVE202661642 #Cybersecurity #Vulnerability #InfoSec

securityonline.info/squid-prox

##

CVE-2026-85498
(0 None)

EPSS: 0.00%

2 posts

N/A

ottoto2017@prattohome.com at 2026-09-16T00:18:47.000Z ##

#Ubuntu 24.04.5 で #update

krb5 (1.20.1-6ubuntu2.10)
セキュリティ対応ではない。
krb5-locales
libgssapi-krb5-2
libk5crypto3
libkrb5-3
libkrb5support0

netplan.io (1.1.2-8ubuntu1~24.04.3)
セキュリティ対応ではない。
libnetplan1
netplan-generator
python3-netplan

policykit-1 (124-2ubuntu1.24.04.4)
CVE-2026-85498へのセキュリティ対応。
libpolkit-agent-1-0
libpolkit-gobject-1-0
libsrt1.5-gnutls
polkitd

セキュリティ対応もあるので、お早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-16T00:18:47.000Z ##

#Ubuntu 24.04.5 で #update

krb5 (1.20.1-6ubuntu2.10)
セキュリティ対応ではない。
krb5-locales
libgssapi-krb5-2
libk5crypto3
libkrb5-3
libkrb5support0

netplan.io (1.1.2-8ubuntu1~24.04.3)
セキュリティ対応ではない。
libnetplan1
netplan-generator
python3-netplan

policykit-1 (124-2ubuntu1.24.04.4)
CVE-2026-85498へのセキュリティ対応。
libpolkit-agent-1-0
libpolkit-gobject-1-0
libsrt1.5-gnutls
polkitd

セキュリティ対応もあるので、お早めに。

#prattohome #更新

##

CVE-2026-88065
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-15T22:00:50.000Z ##

🟠 CVE-2026-88065 - High (7.5)

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T22:00:50.000Z ##

🟠 CVE-2026-88065 - High (7.5)

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63443
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-15T18:01:40.000Z ##

🟠 CVE-2026-63443 - High (8.3)

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request U...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T18:01:40.000Z ##

🟠 CVE-2026-63443 - High (8.3)

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request U...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-51990
(0 None)

EPSS: 0.00%

6 posts

N/A

1 repos

https://github.com/HORKimhab/CVE-2026-51990

netsecio@mastodon.social at 2026-09-15T17:12:53.000Z ##

📰 Chinese Hackers Exploit Critical Flaw in Tencent's Sogou IME Software

A critical flaw (CVE-2026-51990) in Tencent's popular Sogou Input Method is being exploited by Chinese hackers for 1-click RCE. The attack chains a custom protocol handler flaw with an old browser engine. #CyberSecurity #Vulnerability #Tencent

🔗 cyber.netsecops.io/articles/ch

##

cyberworldops at 2026-09-14T12:40:00.947Z ##

UNC3569 is exploiting CVE-2026-51990 in Tencent Sogou Input Method for Windows. A crafted sgbiz:// URL enables one-click SYSTEM-level code execution and GrayRabbit backdoor deployment. Widespread IME deployment makes this a high-priority patch and detection target.

cyberworldops.eu/en/tencent-so

##

cyberworldops@infosec.exchange at 2026-09-14T12:40:00.000Z ##

UNC3569 is exploiting CVE-2026-51990 in Tencent Sogou Input Method for Windows. A crafted sgbiz:// URL enables one-click SYSTEM-level code execution and GrayRabbit backdoor deployment. Widespread IME deployment makes this a high-priority patch and detection target. #SogouFlaw #GrayRabbit #ThreatIntel

cyberworldops.eu/en/tencent-so

##

DailyCyberSecurity@infosec.exchange at 2026-09-14T00:02:51.000Z ##

Defend against the CVE-2026-51990 Sogou exploit. Discover how hackers use this one-click flaw to drop backdoors and how to secure your systems today.

#CVE202651990 #SogouInputMethod #CyberSecurity #UNC3569 #InfoSec #EndpointSecurity #ThreatIntel

securityonline.info/cve-2026-5

##

security_crawler_carl@infosec.exchange at 2026-09-13T18:52:46.000Z ##

🏆 New Achievement! One Click to the Food Chain Bottom!

Here, in the wild habitat of Windows enterprise environments, we observe the Sogou Input Method — a text entry tool installed by millions — standing perfectly still as UNC3569, a China-aligned espionage group, approaches from the brush. CVE-2026-51990 is a critical one-click remote code execution flaw exploiting an unsandboxed Chromium chain. The creature does not run. It simply... accepts the GrayRabbit backdoor. (1/2)

##

oversecurity@mastodon.social at 2026-09-13T15:20:36.000Z ##

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method...

🔗️ [Bleepingcomputer] link.is.it/DXBwPD

##

CVE-2026-57586
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-15T16:01:44.000Z ##

🟠 CVE-2026-57586 - High (8.6)

CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py tre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T16:01:44.000Z ##

🟠 CVE-2026-57586 - High (8.6)

CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py tre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65838
(0 None)

EPSS: 0.27%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-14T21:00:56.000Z ##

🟠 CVE-2026-65838 - High (8.2)

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T21:00:56.000Z ##

🟠 CVE-2026-65838 - High (8.2)

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63030
(0 None)

EPSS: 97.27%

1 posts

N/A

Nuclei template

85 repos

https://github.com/fullhunt/wp2shell-scan

https://github.com/Madelleimproved411/wp-to-code

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/ikow/wp2shell

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/0xsha/wp2shell

https://github.com/shinthink/CVE-2026-63030

https://github.com/Iqbalx7/wp2shell

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/InstaWP/wp2shell-scan

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/AnggaTechI/CVE-2026-63030

https://github.com/attackercan/wp2shell-poc2

https://github.com/0xWhoknows/wp2shell

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/dinosn/wp2shell-lab

https://github.com/ivanesk315/CVE-2026-60137-and-CVE-2026-63030

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-

https://github.com/ekomsSavior/wp2shell

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/Icex0/wp2shell-poc

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/h4cd0c/wp2shell

https://github.com/kulichr/wp2shell

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/x-znn/CVE-2026-63030

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/bahartanir/wp2shell-scanner

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/Sec-Dan/WP2Shell-Scanner

https://github.com/g0d150ne/WP2Shell

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/Crypto-Cat/wp2shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/vulnquest58/PressVector

https://github.com/zi3lak/wp2shell_scanner

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/4minx/CVE-2026-63030

https://github.com/mcipekci/wp2shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/mhtsec/CVE-2026-63030

https://github.com/0xjessie21/wp2shell-checker

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/Procjevt/CVE-2026-63030

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/mverschu/CVE-2026-63030

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/securelayer7/WordPresShell

https://github.com/47Cid/wp2shell-lab

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass

https://github.com/DeadExpl0it/wp2shell-poc

https://github.com/yuag/wp2shell

https://github.com/c0gnit00/Wp2Shell

https://github.com/NULL200OK/WP2Shell

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/ananay/wp2shell-lab

https://github.com/mhassani97/cve-2026-63030-lab

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/gbrsh/CVE-2026-63030

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/imXur/WordPress-CVE-2026-63030-Analysis

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/sowarma/wp2shell-PoC

https://github.com/johnlodan/wp2shell-rce

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

_r_netsec@infosec.exchange at 2026-09-13T17:43:06.000Z ##

wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner fullhunt.io/blog/2026/07/17/wp

##

Visit counter For Websites