##
Updated at UTC 2026-07-05T11:01:11.035646
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-14721 | 8.8 | 0.00% | 4 | 0 | 2026-07-05T08:16:26.647000 | A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Th | |
| CVE-2026-14781 | 4.8 | 0.00% | 2 | 0 | 2026-07-05T07:16:39.820000 | A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker inco | |
| CVE-2026-14703 | 6.3 | 0.00% | 2 | 0 | 2026-07-05T06:30:33 | A vulnerability has been found in itsourcecode Hospital Management System 1.0. A | |
| CVE-2026-14570 | None | 0.00% | 2 | 0 | 2026-07-05T06:30:26 | Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private | |
| CVE-2026-14691 | 6.3 | 0.00% | 2 | 0 | 2026-07-05T03:32:41 | A security vulnerability has been detected in SourceCodester Multi-Vendor Online | |
| CVE-2026-14637 | 8.2 | 0.00% | 2 | 0 | 2026-07-04T18:30:31 | A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter- | |
| CVE-2026-14534 | 8.8 | 0.00% | 2 | 0 | 2026-07-04T15:30:24 | Trail of Bits fickling versions up to and including 0.1.10 do not include the Py | |
| CVE-2026-14535 | 8.8 | 0.00% | 2 | 0 | 2026-07-04T15:30:24 | In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImports | |
| CVE-2026-53360 | None | 0.00% | 2 | 1 | 2026-07-04T12:30:39 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: R | |
| CVE-2026-46242 | 7.8 | 0.12% | 7 | 1 | 2026-07-04T12:16:57.160000 | In the Linux kernel, the following vulnerability has been resolved: eventpoll: | |
| CVE-2026-14622 | 7.3 | 0.52% | 1 | 0 | 2026-07-04T09:31:51 | A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 5214 | |
| CVE-2025-71369 | 8.1 | 0.45% | 2 | 0 | 2026-07-04T03:31:13 | picklescan before 0.0.28 fails to detect malicious pickle files that use torch.u | |
| CVE-2025-71345 | 8.1 | 0.43% | 2 | 0 | 2026-07-04T03:31:08 | picklescan before 0.0.30 fails to detect malicious pickle files that invoke torc | |
| CVE-2025-71367 | 8.1 | 0.45% | 2 | 0 | 2026-07-04T03:31:08 | picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in | |
| CVE-2025-71366 | 8.1 | 0.45% | 2 | 0 | 2026-07-04T03:31:08 | picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main | |
| CVE-2025-71364 | 8.1 | 0.56% | 2 | 0 | 2026-07-04T03:31:08 | picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocess | |
| CVE-2025-71362 | 8.1 | 0.30% | 2 | 0 | 2026-07-04T03:31:08 | picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py. | |
| CVE-2025-71380 | 8.8 | 0.41% | 2 | 0 | 2026-07-04T03:31:08 | The Execute Command node in n8n allows authenticated users to execute arbitrary | |
| CVE-2025-71375 | 8.1 | 0.36% | 2 | 0 | 2026-07-04T03:31:08 | picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in fun | |
| CVE-2025-71372 | 8.1 | 0.38% | 2 | 0 | 2026-07-04T03:31:08 | Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef | |
| CVE-2025-71347 | 8.1 | 0.45% | 2 | 0 | 2026-07-04T03:31:02 | picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py | |
| CVE-2025-71359 | 8.1 | 0.43% | 2 | 0 | 2026-07-04T03:31:02 | picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize | |
| CVE-2025-71356 | 8.1 | 0.30% | 2 | 0 | 2026-07-04T03:31:02 | picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symboli | |
| CVE-2026-12252 | 7.8 | 0.15% | 2 | 0 | 2026-07-04T02:16:23.603000 | In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (Stanfo | |
| CVE-2025-71373 | 8.1 | 0.44% | 2 | 0 | 2026-07-04T02:16:23.220000 | picklescan before 0.0.33 fails to detect operator.methodcaller function calls in | |
| CVE-2025-71360 | 8.1 | 0.30% | 2 | 0 | 2026-07-04T02:16:22.327000 | picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.ca | |
| CVE-2025-71353 | 8.1 | 0.30% | 2 | 0 | 2026-07-04T02:16:21.933000 | picklescan before 0.0.28 fails to detect malicious pickle files that exploit tor | |
| CVE-2025-71343 | 8.1 | 0.30% | 2 | 0 | 2026-07-04T02:16:21.527000 | picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib | |
| CVE-2025-71342 | 8.1 | 0.43% | 2 | 0 | 2026-07-04T02:16:21.387000 | picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.ru | |
| CVE-2026-54424 | 8.4 | 0.24% | 2 | 1 | 2026-07-04T01:16:27.340000 | An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hos | |
| CVE-2026-58288 | 8.3 | 0.45% | 2 | 0 | 2026-07-03T21:31:47 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke | |
| CVE-2026-58287 | 8.3 | 0.45% | 2 | 0 | 2026-07-03T21:31:47 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke | |
| CVE-2026-58286 | 8.1 | 0.39% | 2 | 0 | 2026-07-03T21:31:47 | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorize | |
| CVE-2026-58294 | 7.5 | 0.35% | 2 | 0 | 2026-07-03T21:31:47 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke | |
| CVE-2026-58293 | 8.1 | 0.53% | 2 | 0 | 2026-07-03T21:31:47 | External control of file name or path in Microsoft Edge (Chromium-based) allows | |
| CVE-2026-58292 | 7.5 | 0.29% | 2 | 0 | 2026-07-03T21:31:47 | Improper input validation in Microsoft Edge (Chromium-based) allows an unauthori | |
| CVE-2026-58295 | 8.3 | 0.38% | 2 | 0 | 2026-07-03T21:31:41 | Access of resource using incompatible type ('type confusion') in Microsoft Edge | |
| CVE-2026-57984 | 7.5 | 0.44% | 1 | 0 | 2026-07-03T21:31:39 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke | |
| CVE-2026-14606 | 7.8 | 0.14% | 1 | 0 | 2026-07-03T21:31:36 | A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this i | |
| CVE-2026-58424 | 8.9 | 0.20% | 2 | 0 | 2026-07-03T21:17:05.660000 | Permanent Fork PR Workflow Approval Gate Bypass | |
| CVE-2026-58299 | 7.5 | 0.28% | 3 | 0 | 2026-07-03T21:17:04.907000 | Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android | |
| CVE-2026-58290 | 7.5 | 0.26% | 2 | 0 | 2026-07-03T21:17:03.770000 | Access of resource using incompatible type ('type confusion') in Microsoft Edge | |
| CVE-2026-58289 | 9.0 | 0.53% | 2 | 0 | 2026-07-03T21:17:03.640000 | Access of resource using incompatible type ('type confusion') in Microsoft Edge | |
| CVE-2026-58285 | 8.3 | 0.45% | 2 | 0 | 2026-07-03T21:17:03.180000 | Access of resource using incompatible type ('type confusion') in Microsoft Edge | |
| CVE-2026-58284 | 8.3 | 0.41% | 2 | 0 | 2026-07-03T21:17:03.057000 | Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized | |
| CVE-2026-57992 | 7.5 | 0.44% | 1 | 0 | 2026-07-03T21:17:02.310000 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke | |
| CVE-2026-20896 | 9.8 | 0.78% | 1 | 1 | 2026-07-03T21:16:56.660000 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED | |
| CVE-2026-14605 | 7.8 | 0.14% | 1 | 0 | 2026-07-03T20:16:52.070000 | A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulner | |
| CVE-2026-14460 | 8.8 | 0.16% | 1 | 1 | 2026-07-03T15:32:09 | Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Rese | |
| CVE-2026-49814 | 7.2 | 1.22% | 1 | 0 | 2026-07-03T15:16:32.610000 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release ver | |
| CVE-2026-14459 | 8.8 | 0.20% | 1 | 1 | 2026-07-03T15:16:32.253000 | Improper neutralization of argument delimiters in a command ('argument injection | |
| CVE-2026-13341 | 7.4 | 0.26% | 1 | 0 | 2026-07-03T12:31:51 | A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server p | |
| CVE-2026-10055 | 8.5 | 0.30% | 2 | 0 | 2026-07-03T11:16:27.600000 | In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC | |
| CVE-2026-14544 | 9.8 | 0.51% | 1 | 0 | 2026-07-03T08:16:24.433000 | A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnera | |
| CVE-2026-9725 | 9.1 | 0.74% | 1 | 0 | 2026-07-03T06:32:11 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress | |
| CVE-2026-44935 | 9.9 | 0.57% | 1 | 0 | 2026-07-03T04:17:51.603000 | Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher F | |
| CVE-2026-14432 | 8.8 | 0.25% | 1 | 0 | 2026-07-03T04:17:51.457000 | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote at | |
| CVE-2026-14431 | 8.8 | 0.27% | 1 | 0 | 2026-07-03T04:17:51.320000 | Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote at | |
| CVE-2026-14428 | 8.3 | 0.26% | 1 | 0 | 2026-07-03T04:17:50.907000 | Insufficient validation of untrusted input in Dawn in Google Chrome on Android p | |
| CVE-2026-14427 | 8.3 | 0.24% | 1 | 0 | 2026-07-03T04:17:50.770000 | Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a r | |
| CVE-2026-14425 | 9.6 | 0.22% | 2 | 0 | 2026-07-03T04:17:50.317000 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote | |
| CVE-2026-14423 | 9.6 | 0.22% | 1 | 0 | 2026-07-03T04:17:49.760000 | Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote | |
| CVE-2026-14416 | 9.6 | 0.24% | 1 | 0 | 2026-07-03T04:17:48.653000 | Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a rem | |
| CVE-2026-14398 | 9.6 | 0.21% | 1 | 0 | 2026-07-03T04:17:44.787000 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote | |
| CVE-2026-13768 | 10.0 | 0.56% | 1 | 1 | 2026-07-03T00:32:02 | Gardyn devices expose a privileged iothubowner key. Access to this key will allo | |
| CVE-2026-54998 | 8.8 | 0.64% | 1 | 1 | 2026-07-03T00:31:57 | Incorrect authorization in Microsoft Exchange Online allows an authorized attack | |
| CVE-2026-45499 | 9.9 | 0.62% | 1 | 0 | 2026-07-03T00:31:53 | Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker | |
| CVE-2026-13368 | 0 | 0.59% | 4 | 0 | 2026-07-03T00:16:50.890000 | WatchGuard Fireware OS contains a race condition leading to a use-after-free vul | |
| CVE-2026-57100 | 9.9 | 0.64% | 1 | 0 | 2026-07-02T23:16:51.267000 | Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (Sync | |
| CVE-2026-57517 | 9.8 | 0.59% | 1 | 1 | 2026-07-02T21:33:17 | Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability | |
| CVE-2026-58460 | 7.7 | 0.14% | 1 | 0 | 2026-07-02T21:32:21 | react-native-receive-sharing-intent contains a path traversal vulnerability that | |
| CVE-2026-52830 | 9.4 | 0.42% | 1 | 0 | 2026-07-02T20:38:51 | ## Summary fast-mcp-telegram validates HTTP Bearer tokens by joining the raw to | |
| CVE-2026-59099 | 9.1 | 0.36% | 1 | 0 | 2026-07-02T20:17:08.240000 | Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that al | |
| CVE-2026-14191 | 7.8 | 0.29% | 2 | 0 | 2026-07-02T18:45:21.210000 | An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in | |
| CVE-2026-44941 | 8.4 | 0.49% | 1 | 0 | 2026-07-02T18:36:28 | A relative path traversal in the "keyhint" option in repomd.xml parsing of libzy | |
| CVE-2026-14430 | 8.8 | 0.29% | 1 | 0 | 2026-07-02T18:36:25 | Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote | |
| CVE-2026-14439 | 0 | 0.60% | 1 | 0 | 2026-07-02T17:42:54.390000 | A path traversal vulnerability exists in the Git Service component shared by Alt | |
| CVE-2026-58455 | 9.8 | 1.19% | 1 | 0 | 2026-07-02T17:42:23.640000 | Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulne | |
| CVE-2026-10134 | 10.0 | 0.31% | 1 | 0 | 2026-07-02T17:03:09.633000 | IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret ava | |
| CVE-2026-56842 | 7.5 | 0.19% | 1 | 0 | 2026-07-02T16:54:47.880000 | A malicious actor with access to the network and under certain conditions could | |
| CVE-2026-10109 | 9.8 | 0.86% | 1 | 0 | 2026-07-02T16:46:53.917000 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote | |
| CVE-2026-55112 | 7.5 | 0.19% | 1 | 0 | 2026-07-02T15:32:20 | A malicious actor with access to the network and low privileges and under certai | |
| CVE-2026-56004 | 8.8 | 0.38% | 1 | 0 | 2026-07-02T15:32:20 | A shellcode injection in the mercurial handler of the obs tar_scm source service | |
| CVE-2026-56841 | 8.8 | 0.24% | 1 | 0 | 2026-07-02T15:32:20 | A malicious actor with access to the network and low privileges could exploit an | |
| CVE-2026-54403 | 8.6 | 0.48% | 1 | 0 | 2026-07-02T15:32:20 | A malicious actor with access to the network could exploit a Path Traversal vuln | |
| CVE-2026-5524 | 9.8 | 0.54% | 1 | 1 | 2026-07-02T15:32:20 | The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Uploa | |
| CVE-2026-50027 | 9.8 | 0.00% | 1 | 0 | 2026-07-02T15:26:24 | ## Missing Authentication on Document API Endpoints Allows Unauthenticated Memor | |
| CVE-2026-57683 | 9.3 | 0.25% | 1 | 0 | 2026-07-02T12:31:09 | Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions. | |
| CVE-2026-43503 | 8.8 | 0.14% | 3 | 8 | 2026-07-02T12:17:20.070000 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff | |
| CVE-2026-45659 | 8.8 | 3.22% | 11 | 3 | 2026-07-02T12:16:47.143000 | Deserialization of untrusted data in Microsoft Office SharePoint allows an autho | |
| CVE-2026-14426 | 7.5 | 0.22% | 1 | 0 | 2026-07-02T03:31:27 | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote at | |
| CVE-2026-14424 | 9.6 | 0.21% | 1 | 0 | 2026-07-02T00:31:50 | Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a | |
| CVE-2026-14420 | 9.6 | 0.25% | 1 | 0 | 2026-07-02T00:31:50 | Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 all | |
| CVE-2026-14417 | 9.6 | 0.21% | 2 | 0 | 2026-07-02T00:31:50 | Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote | |
| CVE-2026-14429 | 8.3 | 0.23% | 1 | 0 | 2026-07-02T00:31:50 | Insufficient validation of untrusted input in Skia in Google Chrome prior to 150 | |
| CVE-2026-14390 | 9.6 | 0.24% | 1 | 0 | 2026-07-02T00:31:49 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote | |
| CVE-2026-14419 | 9.6 | 0.21% | 2 | 0 | 2026-07-02T00:31:49 | Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote | |
| CVE-2026-54428 | 7.5 | 0.41% | 1 | 0 | 2026-07-01T21:36:16 | Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder | |
| CVE-2026-10539 | 9.0 | 0.24% | 1 | 0 | 2026-07-01T19:59:44.537000 | A Control-M/Server communication command does not sufficiently filter or sanitiz | |
| CVE-2025-23351 | 9.0 | 0.27% | 1 | 0 | 2026-07-01T18:31:55 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface w | |
| CVE-2026-13775 | 9.8 | 0.31% | 1 | 0 | 2026-07-01T18:31:27 | Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote a | |
| CVE-2026-8451 | 7.5 | 0.50% | 6 | 4 | 2026-07-01T18:31:24 | Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to | |
| CVE-2026-7840 | 9.8 | 1.20% | 1 | 0 | 2026-07-01T18:29:00.013000 | UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embed | |
| CVE-2026-50110 | 9.2 | 0.13% | 1 | 0 | 2026-07-01T18:17:31.553000 | Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous int | |
| CVE-2026-54399 | 7.5 | 0.41% | 1 | 0 | 2026-07-01T18:16:34.317000 | Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser i | |
| CVE-2026-20191 | 7.5 | 0.76% | 1 | 0 | 2026-07-01T18:16:30.850000 | A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote | |
| CVE-2026-20230 | 8.6 | 41.69% | 3 | 3 | 2026-07-01T18:15:24.060000 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco U | |
| CVE-2026-48286 | 10.0 | 0.71% | 1 | 0 | 2026-07-01T17:16:35.583000 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected | |
| CVE-2026-6688 | 7.6 | 0.21% | 2 | 0 | 2026-07-01T15:35:28 | FatFs R0.16 and earlier contains a downstream-caller vulnerability pattern assoc | |
| CVE-2026-6682 | 7.6 | 0.21% | 4 | 0 | 2026-07-01T15:35:27 | In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume | |
| CVE-2026-13774 | 8.1 | 0.30% | 1 | 0 | 2026-07-01T15:35:00 | Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an | |
| CVE-2026-41991 | 4.7 | 0.10% | 1 | 0 | 2026-07-01T15:34:56 | GNU gzip contains a vulnerability in the gzexe utility related to insecure tempo | |
| CVE-2026-11387 | 9.8 | 0.38% | 1 | 1 | 2026-07-01T09:30:33 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart | |
| CVE-2025-15666 | 5.3 | 0.12% | 2 | 0 | 2026-07-01T09:30:31 | A security vulnerability has been detected in Open Asset Import Library Assimp u | |
| CVE-2026-6070 | 9.1 | 0.41% | 1 | 0 | 2026-07-01T06:31:41 | The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated A | |
| CVE-2026-8037 | 9.6 | 29.64% | 6 | 1 | template | 2026-07-01T05:16:25.290000 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC |
| CVE-2026-48282 | 10.0 | 1.02% | 1 | 0 | 2026-07-01T05:16:21.907000 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limi | |
| CVE-2026-50003 | 9.8 | 0.43% | 1 | 0 | 2026-07-01T00:34:02 | A malicious or compromised server can make a DCMTK client using bit-preserving C | |
| CVE-2026-48276 | 10.0 | 0.92% | 1 | 0 | 2026-06-30T18:31:41 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted | |
| CVE-2026-39868 | 9.1 | 0.37% | 1 | 0 | 2026-06-30T18:22:26.317000 | This issue was addressed with improved input validation. This issue is fixed in | |
| CVE-2026-50564 | 9.9 | 0.27% | 1 | 0 | 2026-06-30T18:19:33 | ### Summary Fission's `Environment` CRD exposes `spec.runtime.podSpec` and `spe | |
| CVE-2026-43724 | 9.8 | 0.14% | 1 | 0 | 2026-06-30T15:31:48 | The issue was addressed with improved input sanitization. This issue is fixed in | |
| CVE-2026-54475 | 7.5 | 0.59% | 1 | 0 | 2026-06-30T15:30:45 | Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ A | |
| CVE-2026-55957 | 7.3 | 0.43% | 1 | 0 | 2026-06-30T15:30:44 | Missing Critical Step in Authentication vulnerability in Apache Tomcat when the | |
| CVE-2026-55200 | 8.1 | 0.73% | 2 | 3 | 2026-06-30T15:30:33 | libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write | |
| CVE-2026-43715 | 8.8 | 0.36% | 1 | 0 | 2026-06-30T00:32:31 | A use-after-free issue was addressed with improved memory management. This issue | |
| CVE-2026-43705 | 8.8 | 0.27% | 1 | 0 | 2026-06-30T00:32:31 | A type confusion issue was addressed with improved checks. This issue is fixed i | |
| CVE-2026-13762 | 9.8 | 0.44% | 1 | 0 | 2026-06-29T21:32:12 | Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF | |
| CVE-2026-13763 | 9.8 | 0.47% | 1 | 0 | 2026-06-29T21:32:12 | Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer | |
| CVE-2026-11834 | 0 | 0.41% | 1 | 1 | 2026-06-26T22:16:30.897000 | A command injection vulnerability has been identified in the DHCP option process | |
| CVE-2026-48755 | 9.9 | 0.00% | 1 | 0 | 2026-06-26T19:03:32 | ### Summary Improper validation of user-provided backup compression algorithm l | |
| CVE-2026-44161 | 7.2 | 0.00% | 1 | 0 | 2026-06-26T16:36:11 | The `out_http` output plugin allows the use of placeholders (such as `${tag}`) i | |
| CVE-2026-44024 | 9.8 | 0.00% | 1 | 0 | 2026-06-26T16:32:06 | Fluentd allows dynamically constructing file paths using the `${tag}` placeholde | |
| CVE-2026-57878 | 9.8 | 0.53% | 1 | 0 | 2026-06-26T16:16:36.820000 | An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in | |
| CVE-2026-45051 | None | 0.00% | 1 | 0 | 2026-06-24T17:25:29 | ## Summary **Description** A deserialization of untrusted data vulnerability ( | |
| CVE-2026-35025 | 8.1 | 0.33% | 1 | 0 | 2026-06-24T15:31:50 | ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerabi | |
| CVE-2026-35019 | 8.1 | 0.43% | 1 | 0 | 2026-06-23T15:32:48 | NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenti | |
| CVE-2026-10523 | 9.9 | 47.19% | 1 | 3 | 2026-06-22T20:07:04.253000 | An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10 | |
| CVE-2026-50242 | 10.0 | 0.42% | 1 | 0 | 2026-06-19T15:33:15 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.14812 | |
| CVE-2026-20253 | 9.8 | 88.17% | 1 | 5 | template | 2026-06-18T18:35:18 | In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform |
| CVE-2026-48907 | 9.8 | 80.42% | 1 | 17 | template | 2026-06-17T18:36:17 | A vulnerability in the JCE editor extension for Joomla allows the creation of ne |
| CVE-2026-6637 | 8.8 | 0.38% | 3 | 0 | 2026-06-17T11:01:08.343000 | Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged datab | |
| CVE-2026-50751 | 9.3 | 70.10% | 2 | 7 | template | 2026-06-17T10:57:46.373000 | A logic flow weakness in Remote Access and Mobile Access certificate validation |
| CVE-2026-50566 | 9.9 | 0.29% | 1 | 0 | 2026-06-17T10:57:43.053000 | Fission is an open-source, Kubernetes-native serverless framework that simplifie | |
| CVE-2026-48611 | 9.8 | 0.66% | 3 | 2 | 2026-06-17T10:55:09.423000 | Improper authentication checks in the OAuth implementation allow account hijacki | |
| CVE-2026-43456 | 7.8 | 0.15% | 2 | 0 | 2026-06-17T10:49:38.170000 | In the Linux kernel, the following vulnerability has been resolved: bonding: fi | |
| CVE-2026-34182 | 9.1 | 0.24% | 1 | 0 | 2026-06-17T10:38:36.970000 | Issue Summary: Cryptographic Message Services (CMS) processing fails to perform | |
| CVE-2026-33017 | 9.8 | 98.41% | 1 | 14 | template | 2026-06-17T10:36:47.177000 | Langflow is a tool for building and deploying AI-powered agents and workflows. I |
| CVE-2026-10520 | 10.0 | 99.04% | 1 | 6 | template | 2026-06-17T10:12:16.930000 | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6 |
| CVE-2026-0826 | 0 | 26.47% | 1 | 0 | 2026-06-17T10:11:27.080000 | In certain scenarios when the admin has enabled Interactive Connectivity Establi | |
| CVE-2024-2658 | 0 | 0.42% | 1 | 2 | 2026-06-17T07:24:59.037000 | A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 | |
| CVE-2026-35273 | 9.8 | 92.33% | 2 | 4 | template | 2026-06-12T18:31:50 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS |
| CVE-2026-48612 | 8.0 | 0.12% | 2 | 0 | 2026-06-12T06:33:21 | Improper state verification in the OAuth implementation could allow an attacker | |
| CVE-2026-49160 | 7.5 | 48.44% | 1 | 1 | 2026-06-09T18:31:11 | Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to d | |
| CVE-2026-45504 | 8.8 | 0.46% | 1 | 1 | 2026-06-09T18:30:58 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an author | |
| CVE-2026-25089 | 9.8 | 23.39% | 1 | 2 | 2026-06-09T18:30:47 | A improper neutralization of special elements used in an os command ('os command | |
| CVE-2026-31694 | 7.8 | 0.13% | 1 | 1 | 2026-06-01T18:32:31 | In the Linux kernel, the following vulnerability has been resolved: fuse: rejec | |
| CVE-2026-46817 | 9.8 | 0.68% | 2 | 2 | 2026-05-29T18:31:20 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone | |
| CVE-2026-35368 | 7.8 | 0.14% | 2 | 0 | 2026-04-30T17:50:13 | A vulnerability exists in the chroot utility of uutils coreutils when using the | |
| CVE-2026-33825 | 7.8 | 6.75% | 1 | 5 | 2026-04-23T00:31:18 | Insufficient granularity of access control in Microsoft Defender allows an autho | |
| CVE-2025-5777 | 7.5 | 99.90% | 1 | 25 | template | 2025-10-22T00:34:22 | Insufficient input validation leading to memory overread on the NetScaler Manage |
| CVE-2019-3855 | 8.8 | 9.22% | 1 | 0 | 2023-02-01T05:04:28 | An integer overflow flaw which could lead to an out of bounds write was discover | |
| CVE-2026-58426 | 0 | 0.18% | 3 | 0 | N/A | ||
| CVE-2026-58423 | 0 | 0.31% | 2 | 0 | N/A | ||
| CVE-2026-20779 | 0 | 0.48% | 1 | 0 | N/A | ||
| CVE-2026-22874 | 0 | 0.46% | 1 | 1 | N/A | ||
| CVE-2026-50548 | 0 | 0.64% | 2 | 0 | N/A | ||
| CVE-2026-50549 | 0 | 0.64% | 1 | 0 | N/A | ||
| CVE-2026-54588 | 0 | 0.31% | 1 | 0 | N/A | ||
| CVE-2026-53657 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-58418 | 0 | 0.24% | 1 | 0 | N/A | ||
| CVE-2026-48769 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-57149 | 0 | 0.00% | 1 | 0 | N/A |
updated 2026-07-05T08:16:26.647000
4 posts
UTT HiPER 1250GW (v3.2.7-210907-180535) hit by HIGH severity stack buffer overflow (CVE-2026-14721). Remote code execution possible via 'ssid' in /goform/ConfigWirelessBase_5g. No patch — restrict access. https://radar.offseq.com/threat/cve-2026-14721-stack-based-buffer-overflow-in-utt--61b09d8093b25eb2 #OffSeq #CVE #Infosec #NetSec
##🟠 CVE-2026-14721 - High (8.8)
A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects an unknown function of the file /goform/ConfigWirelessBase_5g of the component Web Endpoint. The manipulation of the argument ssid leads to stack-based buff...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##UTT HiPER 1250GW (v3.2.7-210907-180535) hit by HIGH severity stack buffer overflow (CVE-2026-14721). Remote code execution possible via 'ssid' in /goform/ConfigWirelessBase_5g. No patch — restrict access. https://radar.offseq.com/threat/cve-2026-14721-stack-based-buffer-overflow-in-utt--61b09d8093b25eb2 #OffSeq #CVE #Infosec #NetSec
##🟠 CVE-2026-14721 - High (8.8)
A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects an unknown function of the file /goform/ConfigWirelessBase_5g of the component Web Endpoint. The manipulation of the argument ssid leads to stack-based buff...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-05T07:16:39.820000
2 posts
CVE-2026-14781 (MEDIUM): Red Hat Build of Keycloak flaw in OIDC broker email_verified claim sync. If trustEmail=true & userinfo enabled, attacker can mark emails as verified. Review config & monitor fixes. https://radar.offseq.com/threat/cve-2026-14781-improper-validation-of-consistency--d19be74f7ead5808 #OffSeq #Keycloak #Vuln #IAM
##CVE-2026-14781 (MEDIUM): Red Hat Build of Keycloak flaw in OIDC broker email_verified claim sync. If trustEmail=true & userinfo enabled, attacker can mark emails as verified. Review config & monitor fixes. https://radar.offseq.com/threat/cve-2026-14781-improper-validation-of-consistency--d19be74f7ead5808 #OffSeq #Keycloak #Vuln #IAM
##updated 2026-07-05T06:30:33
2 posts
SQL injection (MEDIUM severity) found in itsourcecode Hospital Management System 1.0 via 'editid' in /patientorder.php (CVE-2026-14703). No patch yet — enforce input validation & parameterized queries. https://radar.offseq.com/threat/cve-2026-14703-sql-injection-in-itsourcecode-hospi-f942c28e535ca531 #OffSeq #SQLInjection #Vuln #HealthcareIT
##SQL injection (MEDIUM severity) found in itsourcecode Hospital Management System 1.0 via 'editid' in /patientorder.php (CVE-2026-14703). No patch yet — enforce input validation & parameterized queries. https://radar.offseq.com/threat/cve-2026-14703-sql-injection-in-itsourcecode-hospi-f942c28e535ca531 #OffSeq #SQLInjection #Vuln #HealthcareIT
##updated 2026-07-05T06:30:26
2 posts
CVE-2026-14570: HIGH severity in TIMLEGGE Crypt::DSA (<1.22) — insufficiently random values in DSA signing allow attackers to recover private keys using lattice attacks. Replace all affected keys and upgrade to 1.22+. https://radar.offseq.com/threat/cve-2026-14570-cwe-330-use-of-insufficiently-rando-539cd2ae349f5a7a #OffSeq #Vuln #Perl #Crypto
##CVE-2026-14570: HIGH severity in TIMLEGGE Crypt::DSA (<1.22) — insufficiently random values in DSA signing allow attackers to recover private keys using lattice attacks. Replace all affected keys and upgrade to 1.22+. https://radar.offseq.com/threat/cve-2026-14570-cwe-330-use-of-insufficiently-rando-539cd2ae349f5a7a #OffSeq #Vuln #Perl #Crypto
##updated 2026-07-05T03:32:41
2 posts
CVE-2026-14691 (MEDIUM): SourceCodester Multi-Vendor Online Grocery Management System 1.0 is vulnerable to remote code injection via update_settings_info in SystemSettings.php. Exploit is public. Monitor & restrict access until fix released. https://radar.offseq.com/threat/cve-2026-14691-code-injection-in-sourcecodester-mu-dfa4f0d89d3ba2d7 #OffSeq #Vuln #AppSec
##CVE-2026-14691 (MEDIUM): SourceCodester Multi-Vendor Online Grocery Management System 1.0 is vulnerable to remote code injection via update_settings_info in SystemSettings.php. Exploit is public. Monitor & restrict access until fix released. https://radar.offseq.com/threat/cve-2026-14691-code-injection-in-sourcecodester-mu-dfa4f0d89d3ba2d7 #OffSeq #Vuln #AppSec
##updated 2026-07-04T18:30:31
2 posts
🟠 CVE-2026-14637 - High (8.2)
A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affected element is the function getCartItems in the library application/libraries/ShoppingCart.php. The ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14637/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-14637 - High (8.2)
A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affected element is the function getCartItems in the library application/libraries/ShoppingCart.php. The ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14637/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T15:30:24
2 posts
🟠 CVE-2026-14534 - High (8.8)
Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). Because these modules are absent from the denylist, fickli...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14534/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-14534 - High (8.8)
Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). Because these modules are absent from the denylist, fickli...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14534/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T15:30:24
2 posts
🟠 CVE-2026-14535 - High (8.8)
In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. This...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14535/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-14535 - High (8.8)
In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. This...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14535/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T12:30:39
2 posts
1 repos
CVE-2026-53360: Linux kernel KVM SEV-SNP HIGH vuln allows SEV-SNP guests OOB read/write on host heap memory 🐧. Heap corruption & info leaks possible. Patch status unclear — avoid untrusted guests & check advisories. https://radar.offseq.com/threat/ghsa-4pq2-jh73-g3hw-1f03f05c22f6fb26 #OffSeq #Linux #Vuln
##CVE-2026-53360: Linux kernel KVM SEV-SNP HIGH vuln allows SEV-SNP guests OOB read/write on host heap memory 🐧. Heap corruption & info leaks possible. Patch status unclear — avoid untrusted guests & check advisories. https://radar.offseq.com/threat/ghsa-4pq2-jh73-g3hw-1f03f05c22f6fb26 #OffSeq #Linux #Vuln
##updated 2026-07-04T12:16:57.160000
7 posts
1 repos
https://thecybersecguru.com/exploits/cve-2026-46242-bad-epoll-linux-vulnerability/
##Bad Epoll (CVE-2026-46242) https://lobste.rs/s/drf6my #linux #security
https://github.com/J-jaeyoung/bad-epoll
🚨 Bad Epoll (CVE-2026-46242) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
eventpoll: fix ep_remove struct eventpoll / struct file UAF
ℹ️ Additional information on ZEN SecDB:
- BadEpoll: https://secdb.nttzen.cloud/updates/79198418-b310-4e40-80cd-d98ba3da0b2a/bad-epoll-vulnerability
- CVE details, sightings and advisories: https://secdb.nttzen.cloud/cve/detail/CVE-2026-46242
#InfoSec #BadEpoll #CVE202646242 #Linux #Kernel
#NTTDATA #Zen #SecDB #VulnerabilityIntelligence #Security
https://thecybersecguru.com/exploits/cve-2026-46242-bad-epoll-linux-vulnerability/
##Bad Epoll (CVE-2026-46242) https://lobste.rs/s/drf6my #linux #security
https://github.com/J-jaeyoung/bad-epoll
🚨 Bad Epoll (CVE-2026-46242) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
eventpoll: fix ep_remove struct eventpoll / struct file UAF
ℹ️ Additional information on ZEN SecDB:
- BadEpoll: https://secdb.nttzen.cloud/updates/79198418-b310-4e40-80cd-d98ba3da0b2a/bad-epoll-vulnerability
- CVE details, sightings and advisories: https://secdb.nttzen.cloud/cve/detail/CVE-2026-46242
#InfoSec #BadEpoll #CVE202646242 #Linux #Kernel
#NTTDATA #Zen #SecDB #VulnerabilityIntelligence #Security
New “Bad Epoll” Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Technology
https://www.newsbeep.com/us/742153/
updated 2026-07-04T09:31:51
1 posts
CVE-2026-14622 – Missing Auth in Jairiidriss restaurant-website-php-mysql. AJAX endpoint /admin/ajax_files allows remote exploitation. CVSS 7.3. No patch available. Apply workarounds immediately. #CVE #infosec #cybersecurity
##updated 2026-07-04T03:31:13
2 posts
🟠 CVE-2025-71369 - High (8.1)
picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing attackers to bypass safety checks. Remote attackers can embed undetected malicious code in ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71369/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71369 - High (8.1)
picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing attackers to bypass safety checks. Remote attackers can embed undetected malicious code in ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71369/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T03:31:08
2 posts
🟠 CVE-2025-71345 - High (8.1)
picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote code ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71345/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71345 - High (8.1)
picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote code ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71345/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T03:31:08
2 posts
🟠 CVE-2025-71367 - High (8.1)
picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using _operator.attrgetter in reduce methods to execut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71367/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71367 - High (8.1)
picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using _operator.attrgetter in reduce methods to execut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71367/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T03:31:08
2 posts
🟠 CVE-2025-71366 - High (8.1)
picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to bypass safety checks. Remote attackers can embed undetected code in pickle files to achieve arbit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71366/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71366 - High (8.1)
picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to bypass safety checks. Remote attackers can embed undetected code in pickle files to achieve arbit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71366/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T03:31:08
2 posts
🟠 CVE-2025-71364 - High (8.1)
picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. Attackers can craft malicious pickle files embedding this built-in function that ev...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71364/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71364 - High (8.1)
picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. Attackers can craft malicious pickle files embedding this built-in function that ev...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71364/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T03:31:08
2 posts
🟠 CVE-2025-71362 - High (8.1)
picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. Attackers can embed malicious code in pickle files that executes when loaded from untrusted sources.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71362/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71362 - High (8.1)
picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. Attackers can embed malicious code in pickle files that executes when loaded from untrusted sources.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71362/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T03:31:08
2 posts
🟠 CVE-2025-71380 - High (8.8)
The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71380/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71380 - High (8.8)
The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71380/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T03:31:08
2 posts
🟠 CVE-2025-71375 - High (8.1)
picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71375/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71375 - High (8.1)
picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71375/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T03:31:08
2 posts
🟠 CVE-2025-71372 - High (8.1)
Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded, bypa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71372/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71372 - High (8.1)
Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded, bypa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71372/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T03:31:02
2 posts
🟠 CVE-2025-71347 - High (8.1)
picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. Remote attackers can embed undetected code in pickle files that exec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71347/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71347 - High (8.1)
picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. Remote attackers can embed undetected code in pickle files that exec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71347/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T03:31:02
2 posts
🟠 CVE-2025-71359 - High (8.1)
picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method, allowing remote code execution. Attackers can craft pickle files embedding dangerous code that evades pickles...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71359/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71359 - High (8.1)
picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method, allowing remote code execution. Attackers can craft pickle files embedding dangerous code that evades pickles...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71359/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T03:31:02
2 posts
🟠 CVE-2025-71356 - High (8.1)
picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle files. Attackers can embed undetected code in pickle files that executes remote code when loaded ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71356/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71356 - High (8.1)
picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle files. Attackers can embed undetected code in pickle files that executes remote code when loaded ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71356/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T02:16:23.603000
2 posts
🟠 CVE-2026-12252 - High (7.8)
In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These cla...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12252/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-12252 - High (7.8)
In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These cla...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12252/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T02:16:23.220000
2 posts
🟠 CVE-2025-71373 - High (8.1)
picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads using operator.methodcaller that execute arbitrary co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71373/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71373 - High (8.1)
picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads using operator.methodcaller that execute arbitrary co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71373/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T02:16:22.327000
2 posts
🟠 CVE-2025-71360 - High (8.1)
picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71360/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71360 - High (8.1)
picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71360/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T02:16:21.933000
2 posts
🟠 CVE-2025-71353 - High (8.1)
picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attackers can craft pickle files with embedded code that evades picklescan detection and executes arbitr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71353/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71353 - High (8.1)
picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attackers can craft pickle files with embedded code that evades picklescan detection and executes arbitr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71353/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T02:16:21.527000
2 posts
🟠 CVE-2025-71343 - High (8.1)
picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. Attackers can craft malicious pickle files with embedded code that evades detection but execu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71343/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71343 - High (8.1)
picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. Attackers can craft malicious pickle files with embedded code that evades detection but execu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71343/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T02:16:21.387000
2 posts
🟠 CVE-2025-71342 - High (8.1)
picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in PyTorch ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71342/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-71342 - High (8.1)
picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in PyTorch ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71342/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-04T01:16:27.340000
2 posts
1 repos
🟠 CVE-2026-54424 - High (8.4)
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54424/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54424 - High (8.4)
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54424/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:31:47
2 posts
🟠 CVE-2026-58288 - High (8.3)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58288 - High (8.3)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:31:47
2 posts
🟠 CVE-2026-58287 - High (8.3)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58287/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58287 - High (8.3)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58287/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:31:47
2 posts
🟠 CVE-2026-58286 - High (8.1)
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58286 - High (8.1)
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:31:47
2 posts
🟠 CVE-2026-58294 - High (7.5)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58294/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58294 - High (7.5)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58294/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:31:47
2 posts
🟠 CVE-2026-58293 - High (8.1)
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58293/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58293 - High (8.1)
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58293/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:31:47
2 posts
🟠 CVE-2026-58292 - High (7.5)
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58292/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58292 - High (7.5)
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58292/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:31:41
2 posts
🟠 CVE-2026-58295 - High (8.3)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58295/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58295 - High (8.3)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58295/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:31:39
1 posts
CVE-2026-57984 - Use After Free in Microsoft Edge. Unauthorized RCE over network. CVSS 7.5. No patch available. Mitigate now. #CVE #MicrosoftEdge #infosec
##updated 2026-07-03T21:31:36
1 posts
🟠 CVE-2026-14606 - High (7.8)
A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the library bsp/synwit/libraries/SWM341_CSL/CMSIS/DeviceSupport/SWM341.h of the component SWM341 CAN Handler. Performing a manipula...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14606/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:17:05.660000
2 posts
🟠 CVE-2026-58424 - High (8.9)
Permanent Fork PR Workflow Approval Gate Bypass
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58424/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58424 - High (8.9)
Permanent Fork PR Workflow Approval Gate Bypass
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58424/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:17:04.907000
3 posts
🟠 CVE-2026-58299 - High (7.5)
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58299/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-58299 TOCTOU race condition in Microsoft Edge for Android. CVSS 7.5. Unauthorized attacker can execute code over network. No patch available. Monitor for updates. #CVE #MicrosoftEdge #infosec
##🟠 CVE-2026-58299 - High (7.5)
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58299/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:17:03.770000
2 posts
🟠 CVE-2026-58290 - High (7.5)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58290/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58290 - High (7.5)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58290/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:17:03.640000
2 posts
🔴 CVE-2026-58289 - Critical (9)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58289/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-58289 - Critical (9)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58289/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:17:03.180000
2 posts
🟠 CVE-2026-58285 - High (8.3)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58285 - High (8.3)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:17:03.057000
2 posts
🟠 CVE-2026-58284 - High (8.3)
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58284/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58284 - High (8.3)
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58284/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T21:17:02.310000
1 posts
CVE-2026-57992 - Use After Free in Microsoft Edge (Chromium-based) allows network-based code execution. CVSS 7.5. No patch available yet. Monitor for updates & apply immediately. #CVE #Microsoft #infosec
##updated 2026-07-03T21:16:56.660000
1 posts
1 repos
CVE-2026-20896 - Critical auth bypass in Gitea Docker images ≤1.26.2. Default REVERSE_PROXY_TRUSTED_PROXIES=* allows IP spoofing via X-WEBAUTH-USER headers. CVSS 9.8. No patch available. Update config now. #CVE #Gitea #infosec
##updated 2026-07-03T20:16:52.070000
1 posts
🟠 CVE-2026-14605 - High (7.8)
A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the library bsp/loongson/ls1cdev/libraries/ls1c_can.h of the component ls1c CAN Handler. Such manipulation leads to stack-based buff...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14605/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T15:32:09
1 posts
1 repos
https://github.com/dasokkk/CVE-2026-14459-14460-pardus-software
🟠 CVE-2026-14460 - High (8.8)
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection.
This issue affects pardus-software: from <= 1.0.4 before 1.0.5.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14460/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T15:16:32.610000
1 posts
CVE-2026-49814 - High-severity OS Command Injection in Dell PowerProtect Data Domain. CVSS 7.2. High-privileged remote attacker can execute arbitrary commands. Patch status unknown. Monitor for updates. #CVE #Dell #infosec
##updated 2026-07-03T15:16:32.253000
1 posts
1 repos
https://github.com/dasokkk/CVE-2026-14459-14460-pardus-software
🟠 CVE-2026-14459 - High (8.8)
Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection.
This issue affects pardus-software: from <= ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14459/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T12:31:51
1 posts
KongHQ mcp-konnect (<1.0.0) has a HIGH severity flaw (CVE-2026-13341, CVSS 7.4) allowing remote prompt injection with risk to confidentiality. No patch — monitor vendor updates. https://radar.offseq.com/threat/cve-2026-13341-cwe-20-improper-input-validation-in-a1d90aa86cfef676 #OffSeq #KongHQ #Infosec #Vulnerability
##updated 2026-07-03T11:16:27.600000
2 posts
🟠 CVE-2026-10055 - High (8.5)
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and returns the full...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10055/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Server-Side Request Forgery (SSRF) in Eclipse Theia 1.26.0 (CVE-2026-10055, HIGH, CVSS 8.5). Attackers with access to the service connection can target internal resources. Restrict access now. https://radar.offseq.com/threat/cve-2026-10055-cwe-918-server-side-request-forgery-66116bce3c83a4f6 #OffSeq #SSRF #EclipseTheia #Cybersecurity
##updated 2026-07-03T08:16:24.433000
1 posts
CVE-2026-14544: CRITICAL integer overflow in HPLIP (RHEL 10) enables remote code execution or privilege escalation via crafted print data 🖨️. Patch status not confirmed. Stay updated: https://radar.offseq.com/threat/cve-2026-14544-integer-overflow-or-wraparound-in-r-d57463ec7bf8b710 #OffSeq #CVE202614544 #LinuxSecurity
##updated 2026-07-03T06:32:11
1 posts
CRITICAL: CVE-2026-9725 in Printcart Web to Print Product Designer for WooCommerce ≤2.5.2 enables unauthenticated file deletion via path traversal. No patch yet — restrict AJAX endpoints & monitor logs. https://radar.offseq.com/threat/cve-2026-9725-cwe-22-improper-limitation-of-a-path-a96c709af943903a #OffSeq #WordPress #CVE2026_9725 #PathTraversal
##updated 2026-07-03T04:17:51.603000
1 posts
🔴 CVE-2026-44935 - Critical (9.9)
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other ten...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T04:17:51.457000
1 posts
🟠 CVE-2026-14432 - High (8.8)
Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14432/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T04:17:51.320000
1 posts
🟠 CVE-2026-14431 - High (8.8)
Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14431/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T04:17:50.907000
1 posts
🟠 CVE-2026-14428 - High (8.3)
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium sec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T04:17:50.770000
1 posts
🟠 CVE-2026-14427 - High (8.3)
Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14427/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T04:17:50.317000
2 posts
Use-after-free in Chrome’s ANGLE (CVE-2026-14425, HIGH) allows remote sandbox escape via crafted HTML in versions before 150.0.7871.46. Patch status unclear — update Chrome past this version. More: https://radar.offseq.com/threat/cve-2026-14425-use-after-free-in-google-chrome-d16c7cab93365fc8 #OffSeq #Chrome #Vuln #Infosec
##🔴 CVE-2026-14425 - Critical (9.6)
Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14425/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T04:17:49.760000
1 posts
CVE-2026-14423: Type confusion in Chrome (pre-150.0.7871.46) enables sandbox escape via crafted HTML. HIGH severity — update Chrome ASAP to patch. Details: https://radar.offseq.com/threat/cve-2026-14423-type-confusion-in-google-chrome-ebdcbaa0782002d1 #OffSeq #Chrome #Vuln #BrowserSecurity
##updated 2026-07-03T04:17:48.653000
1 posts
🔴 CVE-2026-14416 - Critical (9.6)
Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14416/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T04:17:44.787000
1 posts
CRITICAL use-after-free in Chrome ANGLE (CVE-2026-14398) enables remote sandbox escape via crafted HTML. Affected: versions before 150.0.7871.46. Patch ASAP! Details: https://radar.offseq.com/threat/cve-2026-14398-use-after-free-in-google-chrome-da42cd40eed38355 #OffSeq #Chrome #Vuln #CVE202614398
##updated 2026-07-03T00:32:02
1 posts
1 repos
CVE-2026-13768: Gardyn Home Firmware (CRITICAL, CVSS 10) exposes a privileged iothubowner key, enabling attackers to control devices & move laterally on networks. No patch yet. Monitor and segment IoT devices. https://radar.offseq.com/threat/cve-2026-13768-cwe-798-in-gardyn-gardyn-home-firmw-08332214fc38f3ba #OffSeq #IoTSecurity #CVE202613768
##updated 2026-07-03T00:31:57
1 posts
1 repos
🟠 CVE-2026-54998 - High (8.8)
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54998/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T00:31:53
1 posts
🔴 CVE-2026-45499 - Critical (9.9)
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45499/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-03T00:16:50.890000
4 posts
WatchGuard Patches Third Critical IKEv2 RCE in Firebox Appliances
WatchGuard patched a critical pre-authentication RCE vulnerability (CVE-2026-13368) in Firebox appliances. The vulnerability allows unauthenticated attackers to gain administrative control. Legacy T15 and T35 models currently do not have a patch.
**If you use WatchGuard Firebox firewalls, read the advisory in detail. Plan a very quick update to Fireware OS 2026.2.1 or 12.12.1. If you run legacy T15/T35 models, disable external LDAP authentication for IKEv2 as a temporary fix, and if you're on version 11.x, migrate to supported hardware since no patch is coming.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/watchguard-patches-third-critical-ikev2-rce-in-firebox-appliances-l-z-o-j-u/gD2P6Ple2L
WatchGuard Patches Third Critical IKEv2 RCE in Firebox Appliances
WatchGuard patched a critical pre-authentication RCE vulnerability (CVE-2026-13368) in Firebox appliances. The vulnerability allows unauthenticated attackers to gain administrative control. Legacy T15 and T35 models currently do not have a patch.
**If you use WatchGuard Firebox firewalls, read the advisory in detail. Plan a very quick update to Fireware OS 2026.2.1 or 12.12.1. If you run legacy T15/T35 models, disable external LDAP authentication for IKEv2 as a temporary fix, and if you're on version 11.x, migrate to supported hardware since no patch is coming.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/watchguard-patches-third-critical-ikev2-rce-in-firebox-appliances-l-z-o-j-u/gD2P6Ple2L
WatchGuard Firebox vulnerabilities include a critical unauthenticated RCE (CVE-2026-13368, CVSS 9.2) plus six more Fireware OS flaws. Patch now.
#WatchGuard #Firebox #CVE202613368 #FirewareOS #CyberSecurity
##CVE-2026-13368 (CRITICAL, CVSS 9.2): WatchGuard Fireware OS LDAP auth flaw in Mobile VPN with IKEv2 allows remote code execution (iked process). Disable affected configs or restrict access until patch. https://radar.offseq.com/threat/cve-2026-13368-cwe-416-use-after-free-in-watchguar-10bc07017e60512c #OffSeq #WatchGuard #CVE202613368 #Infosec
##updated 2026-07-02T23:16:51.267000
1 posts
🔴 CVE-2026-57100 - Critical (9.9)
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57100/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T21:33:17
1 posts
1 repos
A public PoC is available for CVE-2026-57517, a critical CVSS 9.8 Control Web Panel SQLi flaw allowing unauthenticated remote code execution.
#CVE202657517 #ControlWebPanel #SQLInjection #CyberSecurity #Vulnerability
##updated 2026-07-02T21:32:21
1 posts
🟠 CVE-2026-58460 - High (7.7)
react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application to write files outside the intended cache directory by supplying a crafted _display_name value containing dot-dot path comp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58460/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T20:38:51
1 posts
🔴 CVE-2026-52830 - Critical (9.4)
fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The verifier rejects the exact reserved token telegram, but it does not reject pa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52830/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T20:17:08.240000
1 posts
🔴 CVE-2026-59099 - Critical (9.1)
Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse across the server lifetime. Attackers c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T18:45:21.210000
2 posts
A WinRAR vulnerability (CVE-2026-14191) causes a heap overflow via crafted .rev recovery files. Update WinRAR and UnRAR to version 7.23 now.
#WinRAR #UnRAR #CVE202614191 #HeapOverflow #RAR5 #RARLAB #Vulnerability
##updated 2026-07-02T18:36:28
1 posts
🟠 CVE-2026-44941 - High (8.4)
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44941/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T18:36:25
1 posts
🟠 CVE-2026-14430 - High (8.8)
Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14430/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T17:42:54.390000
1 posts
CVE-2026-14439: CRITICAL path traversal in Altium Enterprise Server & Altium 365 Git Service. Authenticated users can achieve RCE & cross-tenant data access. Upgrade Altium Server to v8.1.1; cloud already remediated. https://radar.offseq.com/threat/cve-2026-14439-cwe-22-improper-limitation-of-a-pat-19675f7d579c103e #OffSeq #CVE202614439 #infosec #remediation
##updated 2026-07-02T17:42:23.640000
1 posts
🔴 CVE-2026-58455 - Critical (9.8)
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php combined with u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58455/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T17:03:09.633000
1 posts
Multiple Langflow OSS vulnerabilities, including the critical CVE-2026-10134 flaw, expose servers to code execution. Patch immediately.
#Langflow #Vulnerabilities #CyberSecurity #CVE202610134 #InfoSec
##updated 2026-07-02T16:54:47.880000
1 posts
🟠 CVE-2026-56842 - High (7.5)
A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56842/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T16:46:53.917000
1 posts
A critical IBM Db2 RCE flaw (CVE-2026-10109) allows pre-auth code execution. IBM patched it plus two other Db2 bugs. Update 11.5 and 12.1 now.
##updated 2026-07-02T15:32:20
1 posts
🟠 CVE-2026-55112 - High (7.5)
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55112/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T15:32:20
1 posts
🔴 CVE-2026-56004 - Critical (10)
A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious se...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56004/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T15:32:20
1 posts
🟠 CVE-2026-56841 - High (8.8)
A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56841/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T15:32:20
1 posts
@cR0w ../ spotted!
Summary 7 of 25
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances.
CVE-2026-54403
##updated 2026-07-02T15:32:20
1 posts
1 repos
CVE-2026-5524: Divi Form Builder <=5.1.8 has a CRITICAL file upload vuln (CVSS 9.8). Unauth RCE possible via PHP extensions not blocked by .htaccess, esp. on Nginx. Restrict uploads, monitor for patch. https://radar.offseq.com/threat/cve-2026-5524-cwe-434-unrestricted-upload-of-file--ef397843e92862b0 #OffSeq #WordPress #Infosec #CVE2026_5524
##updated 2026-07-02T15:26:24
1 posts
CVE-2026-50027: mcp-memory-service (<10.67.1) has a CRITICAL auth bypass in /api/documents/* 🚨. Unauthenticated attackers can read, write, delete memory data. Restrict access or disable endpoints until fixed. https://radar.offseq.com/threat/ghsa-84hp-mqvj-3p8h-mcp-memory-service-missing-aut-09a7b270b55ce238 #OffSeq #CVE202650027 #APIsecurity
##updated 2026-07-02T12:31:09
1 posts
CVE-2026-57683: CRITICAL SQL injection (CVSS 9.3) in Epsiloncool WP Fast Total Search ≤1.80.280 enables unauthenticated exploitation. Patch pending — monitor for fixes and restrict access. https://radar.offseq.com/threat/cve-2026-57683-cwe-89-improper-neutralization-of-s-608880638f90634f #OffSeq #WordPress #Infosec #Vuln
##updated 2026-07-02T12:17:20.070000
3 posts
8 repos
https://github.com/gl1tch0x1/DirtyClone
https://github.com/SecureWithUmer/CVE-2026-43503
https://github.com/mooder1/dirtyclone-CVE-2026-43503
https://github.com/douglasmun/pagecache-lpe-containment-kit
https://github.com/aexdyhaxor/CVE-2026-43503-DirtyClone
https://github.com/sec0x/CVE-2026-43503
Dissecting and Exploiting Linux LPE Variant: DirtyClone (CVE-2026-43503) https://lobste.rs/s/adgyhb #linux #security
https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/
Dissecting and Exploiting Linux LPE Variant: DirtyClone (CVE-2026-43503) https://lobste.rs/s/adgyhb #linux #security
https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/
Dissecting and Exploiting Linux LPE Variant: DirtyClone (CVE-2026-43503) - JFrog Security Research #devopsish https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/
##updated 2026-07-02T12:16:47.143000
11 posts
3 repos
https://github.com/jenniferreire26/CVE-2026-45659
https://github.com/HORKimhab/CVE-2026-45659
https://github.com/mistbarbarianspot/CVE-2026-45659-SharePoint-RCE
Here's a brief on recent geopolitical, technology, and cybersecurity developments:
Geopolitically, Russia claims control of Kostyantynivka in Ukraine, and Presidents Putin and Trump discussed Ukraine ahead of the upcoming NATO summit. In technology, Amazon launched its satellite internet service to compete with Starlink, and Alibaba banned Anthropic AI usage amidst a data dispute. Cybersecurity noted a US government entity paid $1 million in a data-theft extortion, while a critical SharePoint RCE (CVE-2026-45659) is actively exploited. AI-powered phishing and scams are also targeting the World Cup 2026.
##Geopolitical: US-Iran talks paused for funeral (July 4-5, 2026). Ukraine's Zelenskiy and Trump discussed the Russia-Ukraine war.
Technology: SK Telecom plans a 15GW AI data center in Asia (July 5, 2026). OpenAI reportedly eyes US government equity.
Cybersecurity: CISA urged patching an actively exploited SharePoint RCE (CVE-2026-45659) by July 4, 2026. Ransomware attacks typically spike during US holidays. A Homeland Security network (HSIN) breach was reported.
##Here's a brief on recent geopolitical, technology, and cybersecurity developments:
Geopolitically, Russia claims control of Kostyantynivka in Ukraine, and Presidents Putin and Trump discussed Ukraine ahead of the upcoming NATO summit. In technology, Amazon launched its satellite internet service to compete with Starlink, and Alibaba banned Anthropic AI usage amidst a data dispute. Cybersecurity noted a US government entity paid $1 million in a data-theft extortion, while a critical SharePoint RCE (CVE-2026-45659) is actively exploited. AI-powered phishing and scams are also targeting the World Cup 2026.
##Geopolitical: US-Iran talks paused for funeral (July 4-5, 2026). Ukraine's Zelenskiy and Trump discussed the Russia-Ukraine war.
Technology: SK Telecom plans a 15GW AI data center in Asia (July 5, 2026). OpenAI reportedly eyes US government equity.
Cybersecurity: CISA urged patching an actively exploited SharePoint RCE (CVE-2026-45659) by July 4, 2026. Ransomware attacks typically spike during US holidays. A Homeland Security network (HSIN) breach was reported.
##OpenAI voluntarily limited new AI models at government request on July 2. Cybersecurity threats remain high with critical Citrix Bleed 2 (CVE-2025-5777) and Microsoft SharePoint RCE (CVE-2026-45659) vulnerabilities being actively exploited, as reported on July 2-3. Google, in collaboration with the FBI, disrupted NetNut, a major residential proxy network spanning 2 million devices. Geopolitically, Iran issued warnings to ships regarding unapproved routes in the Strait of Hormuz on July 3.
##CISA Reports Active Exploitation of SharePoint RCE Flaw
CISA warned that attackers are exploiting a high-severity SharePoint vulnerability (CVE-2026-45659) that allows authenticated users to run arbitrary code.
**If you run on-premises Microsoft SharePoint Server (Subscription Edition, 2019, or 2016), this is urgent. Your Sharepoint is under attack. Apply Microsoft's security update for CVE-2026-45659 immediately. Prioritize any internet-facing SharePoint instances first, and confirm every server is updated to the latest secure version. If possible, isolate SharePoint from the Internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-reports-active-exploitation-of-sharepoint-rce-flaw-a-p-5-o-0/gD2P6Ple2L
https://thecybersecguru.com/news/hsin-breach-dhs-sharepoint-hack/
##C-Suite Alert: CVE-2026-45659 is actively exploited. CISA BOD 26-04 mandates immediate action. Is your organization compliant? My executive briefing provides the risk assessment and strategic roadmap to secure your SharePoint assets and mitigate enterprise liability. https://thecybermind.co/x3h5
#Governance #InfoSec #SharePoint
CISA flags an actively exploited SharePoint vulnerability (CVE-2026-45659) enabling remote code execution. Patch SharePoint Server 2016 now.
#SharePoint #Microsoft #CVE202645659 #CISAKEV #RCE #ExploitedInTheWild #Vulnerability
##🚨 [CISA-2026:0701] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-45659 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45659)
- Name: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SharePoint Server
- Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-45659
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260701 #cisa20260701 #cve_2026_45659 #cve202645659
##CVE ID: CVE-2026-45659
Vendor: Microsoft
Product: SharePoint Server
Date Added: 2026-07-01
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45659
updated 2026-07-02T03:31:27
1 posts
🟠 CVE-2026-14426 - High (7.5)
Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14426/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T00:31:50
1 posts
CVE-2026-14424: HIGH severity use-after-free in Chrome (Mac <150.0.7871.46) enables sandbox escape via crafted HTML. Update to 150.0.7871.46+ now. https://radar.offseq.com/threat/cve-2026-14424-use-after-free-in-google-chrome-1a17c58d72224f47 #OffSeq #Chrome #Infosec #Vuln
##updated 2026-07-02T00:31:50
1 posts
🔴 CVE-2026-14420 - Critical (9.6)
Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14420/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T00:31:50
2 posts
CVE-2026-14417: CRITICAL use-after-free in Chrome’s Dawn (pre-150.0.7871.46). Remote attackers can potentially escape the sandbox — patch ASAP. Details: https://radar.offseq.com/threat/cve-2026-14417-use-after-free-in-google-chrome-b3887b8e713f2d29 #OffSeq #Chrome #CVE202614417 #Infosec
##🔴 CVE-2026-14417 - Critical (9.6)
Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14417/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T00:31:50
1 posts
🟠 CVE-2026-14429 - High (8.3)
Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sever...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14429/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-02T00:31:49
1 posts
CVE-2026-14390: Use-after-free in Chrome ANGLE (High severity, ≤150.0.7871.45) can enable sandbox escape via crafted HTML. Update to 150.0.7871.46+ to mitigate. No active exploits reported. https://radar.offseq.com/threat/cve-2026-14390-use-after-free-in-google-chrome-7f7b248bc3c84ce8 #OffSeq #GoogleChrome #Infosec #Vulnerability
##updated 2026-07-02T00:31:49
2 posts
🔴 CVE-2026-14419 - Critical (9.6)
Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14419/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-14419: CRITICAL use-after-free in Chrome <150.0.7871.46 (Skia) enables remote sandbox escape via crafted HTML. Patch immediately to prevent code execution outside the browser. https://radar.offseq.com/threat/cve-2026-14419-use-after-free-in-google-chrome-0ddc404b4a28d10f #OffSeq #Chrome #CVE202614419 #Infosec
##updated 2026-07-01T21:36:16
1 posts
Apache HttpComponents Core vulnerabilities CVE-2026-54399 and CVE-2026-54428 allow remote denial of service through memory exhaustion. Upgrade now.
##updated 2026-07-01T19:59:44.537000
1 posts
CVE-2026-10539: CRITICAL auth bypass in BMC Control-M/Server (v9.0.20 – 9.0.21.200). Unauthenticated attackers can execute commands. Patch status unconfirmed — monitor vendor. https://radar.offseq.com/threat/cve-2026-10539-cwe-305-authentication-bypass-by-pr-1a4c43a69f0e2740 #OffSeq #CVE202610539 #infosec #vuln
##updated 2026-07-01T18:31:55
1 posts
Recent NVIDIA security updates address critical vulnerabilities, including CVE-2025-23351. Apply patches to secure your ConnectX and BlueField devices.
##updated 2026-07-01T18:31:27
1 posts
For the second time in a row, a post by cr0w on Mastodon regarding the Chrome release blog appearing to not render anything resulted in me firing up lynx to show a sub-second load and render, then finally doing something a bit more tangible about the situation.
The Google Blogger pages load an ancient copy of jQuery (1.11.3, from 2015) synchronously in the <head>, alongside a 53KB widgets.js Blogger framework. Then, posts like this one — https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html — stuff 433 CVE entries into the DOM — 670KB of HTML, 5,045 nodes. The Blogger WidgetManager processes all of that against the DOM using jQuery’s notoriously slow selector engine, and the main thread stays locked for 81 seconds. Nothing else runs. Not even the HTTP request for the DoubleClick tracking pixel queued behind it (because ofc there’s a DoubleClick tracking pixel).
The Safari Navigation Timing API numbers make it embarrassingly concrete:
responseEnd: 143msdomInteractive: 231msdomContentLoaded: 81,280msThat’s 81 seconds between “DOM is ready” and “page is loaded.” All burning prescious CPU cycles with zero network activity during that window.
This is the second time I’ve felt compelled to dig into this particular mess. The Chrome Releases page is a real/tangible operational resource — security teams, vulnerability managers, and researchers (somewhat, at least) depend on it for CVE data. When it’s broken, it creates a bottleneck for people who have real jobs to do.
The 433 CVE entries choking the page are exactly what people came to read. But they’re baked into the HTML as rendered text, not exposed as structured data anywhere. So even when the page eventually loads, you’re still scraping HTML to get at anything useful.
unjam solves that problem. It’s a small CLI that connects to a Blogger page and extracts structured data — both the widget configuration from the _WidgetManager._SetDataContext inline script and the CVE entries from Chrome Release posts — without touching a browser at all.
It’s a single Deno binary for macOS, Linux, and Windows. No dependencies, no configuration overhead, just download and run:
unjam --cve https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html
[
{
"issueId": "506558270",
"issueUrl": "https://issues.chromium.org/issues/506558270",
"severity": "Critical",
"cveId": "CVE-2026-13774",
"description": "Use after free in Extensions.",
"reporter": "Google",
"reportedOn": "2026-04-26"
},
{
"issueId": "511766407",
"issueUrl": "https://issues.chromium.org/issues/511766407",
"severity": "Critical",
"cveId": "CVE-2026-13775",
"description": "Use after free in GPU.",
"reporter": "Google",
"reportedOn": "2026-05-10"
},
…
]
Getting CVE data from one of these posts used to mean waiting 81 seconds for a browser tab to finish wrestling with jQuery, then hand-scraping HTML. Now it takes about a second and returns clean JSON. The --cve flag parses each entry into structured fields — CVE ID, severity, description, issue tracker URL, reporter, and date reported — ready to pipe into jq, load into a database, or feed into whatever vulnerability management pipeline you’re running.
The tool also handles the general case: any Blogger page carrying the _WidgetManager._SetDataContext inline script can be unwedged with the default mode, which converts the JavaScript object literal into proper JSON. That turned out to be useful enough to bake in as default functionality.
The project’s at https://git.sr.ht/~hrbrmstr/unjam and has pre-built binaries for popular platforms.
I don’t expect this page to stay broken forever…I mean, someone at Google will eventually update the template (right, Anakin? right? Anakin?), and may even quietly drop the DoubleClick pixel (LOL) — but until then, unjam fills the gap cleanly.
updated 2026-07-01T18:31:24
6 posts
4 repos
https://github.com/derekpreston81/CVE_ADC_IOC_2026
https://github.com/0xBlackash/CVE-2026-8451
https://github.com/watchtowrlabs/watchTowr-vs-Netscaler-CVE-2026-8451
Citrix NetScaler vulnerability CVE-2026-8451 is exploited in the wild after a public PoC exposed a pre-auth memory overread. Patch now.
##CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/ #bot #cybersecurity #infosec
##Citrix has patched a series of bugs this week, including another CitrixBleed-like vulnerability that can allow remote attackers to leak a device's memory and find goodies inside, such as auth or config data.
This impacts NetScaler ADC devices.
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604
##‼️ CVE-2026-8451: Citrix Netscaler overread Detection Artifact Generator Tool
GitHub: https://github.com/watchtowrlabs/watchTowr-vs-Netscaler-CVE-2026-8451
Full writeup: https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/
CVE-2026-8451 is a NetScaler ADC and NetScaler Gateway memory overread flaw caused by insufficient input validation, affecting appliances configured as a SAML Identity Provider.
The risk is sensitive memory disclosure, with researchers showing NetScaler can be tricked into returning process memory that should never leave the appliance.
##mum: what impact did you have on the cybersecurity industry?
me: LOGOS
if you have SAML IDP enabled on Netscaler, you want to patch CVE-2026-8451 https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451
This is already being exploited in the wild, one of my honeypots got MFA bypassed with it.
Edit: actually looking at it it looks like the honeypot got owned via a different vuln but you should probably patch this too.
##CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/
##updated 2026-07-01T18:29:00.013000
1 posts
Two UltraVNC repeater vulnerabilities enable arbitrary code execution (CVE-2026-7840) plus admin access via a hardcoded password. Update now.
#UltraVNC #RemoteAccess #CVE20267839 #CVE20267840 #ArbitraryCodeExecution #BufferOverflow #Vulnerability
##updated 2026-07-01T18:17:31.553000
1 posts
StoneFly Storage Concentrator (SC & SCVM) faces a CRITICAL vulnerability (CVE-2026-50110): hardcoded, encoded credentials allow potential access to databases & internal services. No patch yet — restrict config file access, increase monitoring. https://radar.offseq.com/threat/cve-2026-50110-cwe-798-use-of-hard-coded-credentia-ae0ab8c00c52fe63 #OffSeq #CVE #infosec
##updated 2026-07-01T18:16:34.317000
1 posts
Apache HttpComponents Core vulnerabilities CVE-2026-54399 and CVE-2026-54428 allow remote denial of service through memory exhaustion. Upgrade now.
##updated 2026-07-01T18:16:30.850000
1 posts
Cisco fixes a Cisco Catalyst Center vulnerability (CVE-2026-20191, CVSS 7.5) and seven ClamAV vulnerabilities causing DoS in Secure Endpoint Connectors.
##updated 2026-07-01T18:15:24.060000
3 posts
3 repos
Cisco confirma exploração ativa de vulnerabilidade nos sistemas Unified CM. A empresa confirmou que agentes maliciosos estão a explorar a vulnerabilidade CVE-2026-20230, que permite ataques de falsificação de pedidos do lado do servidor. 🚨
##New Cisco advisory relating to a June 3 critical vulnerability:
CVE-2026-20230: Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW @TalosSecurity #vulnerability #Cisco
##📈 CVE Published in last 30 days (2026-06-01 - 2026-07-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 855
- High: 3079
- Medium: 2559
- Low: 534
- None: 684
Status:
- : 344
- Analyzed: 2815
- Awaiting Analysis: 562
- Deferred: 3102
- Modified: 173
- Received: 551
- Rejected: 49
- Undergoing Analysis: 115
CISA KEVs:
- CISA-2026:0601 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0601)
- CISA-2026:0602 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0602)
- CISA-2026:0603 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0603)
- CISA-2026:0605 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0605)
- CISA-2026:0608 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0608)
- CISA-2026:0609 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0609)
- CISA-2026:0611 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0611)
- CISA-2026:0612 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0612)
- CISA-2026:0615 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0615)
- CISA-2026:0616 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0616)
- CISA-2026:0618 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0618)
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
- CISA-2026:0629 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0629)
Top CNAs:
- GitHub, Inc.: 1163
- Patchstack: 731
- VulnCheck: 612
- Chrome: 584
- kernel.org: 514
- VulDB: 468
- N/A: 344
- MITRE: 329
- Wordfence: 256
- Oracle: 242
Top Affected Products:
- UNKNOWN: 4698
- Google Chrome: 583
- Google Android: 118
- Microsoft Windows 11 26h1: 111
- Microsoft Windows Server 2025: 109
- Microsoft Windows 11 24h2: 105
- Microsoft Windows 11 25h2: 105
- Microsoft Windows Server 2022: 104
- Microsoft Windows 11 23h2: 99
- Microsoft Windows 10 22h2: 91
Top EPSS Score:
- CVE-2026-10520 - 98.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10520)
- CVE-2026-35273 - 92.33 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-35273)
- CVE-2026-20253 - 88.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20253)
- CVE-2026-48907 - 80.43 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48907)
- CVE-2026-50751 - 71.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50751)
- CVE-2026-49160 - 48.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49160)
- CVE-2026-10523 - 47.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10523)
- CVE-2026-20230 - 41.69 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20230)
- CVE-2026-0826 - 26.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0826)
- CVE-2026-25089 - 23.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-25089)
updated 2026-07-01T17:16:35.583000
1 posts
CRITICAL vulnerabilities patched in Adobe ColdFusion (2025/2023) & Campaign Classic (7.4.3 build 9397). Multiple CVSS 10.0 flaws incl. CVE-2026-48286, CVE-2026-48276 – 83. No active exploits, but patch ASAP. https://radar.offseq.com/threat/adobe-patches-critical-coldfusion-campaign-classic-baee08e7ac9d8888 #OffSeq #Adobe #ColdFusion #Vuln
##updated 2026-07-01T15:35:28
2 posts
🤖 Researchers at runZero say AI-assisted testing found 7 security flaws in the FatFs FAT/exFAT filesystem library (CVE-2026-6682 to CVE-2026-6688), potentially exposing millions of embedded devices via malicious USB drives/SD cards—and sometimes OTA update paths. 🔓📉 https://cyberinsider.com/ai-helps-find-flaws-in-fatfs-library-used-in-millions-of-devices/ #cybersecurity #IoT #vulnerabilities #embedded
##🤖 Researchers at runZero say AI-assisted testing found 7 security flaws in the FatFs FAT/exFAT filesystem library (CVE-2026-6682 to CVE-2026-6688), potentially exposing millions of embedded devices via malicious USB drives/SD cards—and sometimes OTA update paths. 🔓📉 https://cyberinsider.com/ai-helps-find-flaws-in-fatfs-library-used-in-millions-of-devices/ #cybersecurity #IoT #vulnerabilities #embedded
##updated 2026-07-01T15:35:27
4 posts
🤖 Researchers at runZero say AI-assisted testing found 7 security flaws in the FatFs FAT/exFAT filesystem library (CVE-2026-6682 to CVE-2026-6688), potentially exposing millions of embedded devices via malicious USB drives/SD cards—and sometimes OTA update paths. 🔓📉 https://cyberinsider.com/ai-helps-find-flaws-in-fatfs-library-used-in-millions-of-devices/ #cybersecurity #IoT #vulnerabilities #embedded
##🧩 Runzero warnt: Eine KI-gestützte Suche fand eine gefährliche Lücke im FatFs-Treiber. Schon das Anschließen eines USB-Sticks soll genügen, um über CVE-2026-6682 (CVSS 7,6) Schadcode einzuschleusen. Patch derzeit unklar. Angriff auch via manipulierte OTA-Updates möglich. 🔥
https://www.golem.de/news/angriff-per-usb-stick-ki-findet-gefaehrliche-luecke-in-populaerem-fatfs-treiber-2607-210484.html
#Security #IoT #Embedded #USB #CVE #Vulnerability
🤖 Researchers at runZero say AI-assisted testing found 7 security flaws in the FatFs FAT/exFAT filesystem library (CVE-2026-6682 to CVE-2026-6688), potentially exposing millions of embedded devices via malicious USB drives/SD cards—and sometimes OTA update paths. 🔓📉 https://cyberinsider.com/ai-helps-find-flaws-in-fatfs-library-used-in-millions-of-devices/ #cybersecurity #IoT #vulnerabilities #embedded
##🧩 Runzero warnt: Eine KI-gestützte Suche fand eine gefährliche Lücke im FatFs-Treiber. Schon das Anschließen eines USB-Sticks soll genügen, um über CVE-2026-6682 (CVSS 7,6) Schadcode einzuschleusen. Patch derzeit unklar. Angriff auch via manipulierte OTA-Updates möglich. 🔥
https://www.golem.de/news/angriff-per-usb-stick-ki-findet-gefaehrliche-luecke-in-populaerem-fatfs-treiber-2607-210484.html
#Security #IoT #Embedded #USB #CVE #Vulnerability
updated 2026-07-01T15:35:00
1 posts
For the second time in a row, a post by cr0w on Mastodon regarding the Chrome release blog appearing to not render anything resulted in me firing up lynx to show a sub-second load and render, then finally doing something a bit more tangible about the situation.
The Google Blogger pages load an ancient copy of jQuery (1.11.3, from 2015) synchronously in the <head>, alongside a 53KB widgets.js Blogger framework. Then, posts like this one — https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html — stuff 433 CVE entries into the DOM — 670KB of HTML, 5,045 nodes. The Blogger WidgetManager processes all of that against the DOM using jQuery’s notoriously slow selector engine, and the main thread stays locked for 81 seconds. Nothing else runs. Not even the HTTP request for the DoubleClick tracking pixel queued behind it (because ofc there’s a DoubleClick tracking pixel).
The Safari Navigation Timing API numbers make it embarrassingly concrete:
responseEnd: 143msdomInteractive: 231msdomContentLoaded: 81,280msThat’s 81 seconds between “DOM is ready” and “page is loaded.” All burning prescious CPU cycles with zero network activity during that window.
This is the second time I’ve felt compelled to dig into this particular mess. The Chrome Releases page is a real/tangible operational resource — security teams, vulnerability managers, and researchers (somewhat, at least) depend on it for CVE data. When it’s broken, it creates a bottleneck for people who have real jobs to do.
The 433 CVE entries choking the page are exactly what people came to read. But they’re baked into the HTML as rendered text, not exposed as structured data anywhere. So even when the page eventually loads, you’re still scraping HTML to get at anything useful.
unjam solves that problem. It’s a small CLI that connects to a Blogger page and extracts structured data — both the widget configuration from the _WidgetManager._SetDataContext inline script and the CVE entries from Chrome Release posts — without touching a browser at all.
It’s a single Deno binary for macOS, Linux, and Windows. No dependencies, no configuration overhead, just download and run:
unjam --cve https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html
[
{
"issueId": "506558270",
"issueUrl": "https://issues.chromium.org/issues/506558270",
"severity": "Critical",
"cveId": "CVE-2026-13774",
"description": "Use after free in Extensions.",
"reporter": "Google",
"reportedOn": "2026-04-26"
},
{
"issueId": "511766407",
"issueUrl": "https://issues.chromium.org/issues/511766407",
"severity": "Critical",
"cveId": "CVE-2026-13775",
"description": "Use after free in GPU.",
"reporter": "Google",
"reportedOn": "2026-05-10"
},
…
]
Getting CVE data from one of these posts used to mean waiting 81 seconds for a browser tab to finish wrestling with jQuery, then hand-scraping HTML. Now it takes about a second and returns clean JSON. The --cve flag parses each entry into structured fields — CVE ID, severity, description, issue tracker URL, reporter, and date reported — ready to pipe into jq, load into a database, or feed into whatever vulnerability management pipeline you’re running.
The tool also handles the general case: any Blogger page carrying the _WidgetManager._SetDataContext inline script can be unwedged with the default mode, which converts the JavaScript object literal into proper JSON. That turned out to be useful enough to bake in as default functionality.
The project’s at https://git.sr.ht/~hrbrmstr/unjam and has pre-built binaries for popular platforms.
I don’t expect this page to stay broken forever…I mean, someone at Google will eventually update the template (right, Anakin? right? Anakin?), and may even quietly drop the DoubleClick pixel (LOL) — but until then, unjam fills the gap cleanly.
updated 2026-07-01T15:34:56
1 posts
A GNU gzip vulnerability (CVE-2026-41991) lets a local attacker overwrite files through a gzexe symlink attack. Update to the patched gzip release now.
#GNUgzip #gzip #CVE202641991 #CVE202641992 #gzexe #LinuxSecurity #Vulnerability
##updated 2026-07-01T09:30:33
1 posts
1 repos
CVE-2026-11387 | SMS Alert – SMS & OTP for WooCommerce <=3.9.5 has a CRITICAL auth flaw (CVSS 9.8): Unauth attackers can take over any WP account if OTP resets & phone numbers are enabled. Disable OTP resets ASAP. https://radar.offseq.com/threat/cve-2026-11387-cwe-287-improper-authentication-in--cb792a6868247a84 #OffSeq #WordPress #Infosec
##updated 2026-07-01T09:30:31
2 posts
@Andres4NY@social.ridetrans.it https://nvd.nist.gov/vuln/detail/CVE-2025-15666
Congrats to anyone who ever wondered if ‘ass imp’ would show up on a .gov site, I guess.
@aud *stares in CVE-2025-15666*
##updated 2026-07-01T06:31:41
1 posts
CVE-2026-6070: WP-BusinessDirectory plugin (≤4.0.1) has a CRITICAL unauthenticated file deletion flaw (CVSS 9.1). Attackers can delete wp-config.php via path traversal. Restrict endpoint & monitor logs until patched. https://radar.offseq.com/threat/cve-2026-6070-cwe-73-external-control-of-file-name-ae3a571ee4bae8b5 #OffSeq #WordPress #CVE20266070 #infosec
##updated 2026-07-01T05:16:25.290000
6 posts
1 repos
⚠️ CRITICAL: Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
A critical pre-auth RCE vulnerability (CVE-2026-8037, CVSS 9.6) in Progress Kemp LoadMaster is actively being exploited. The flaw allows unauthenticated attackers to execute arbitrary OS commands via the /accessv2 API endpoint. Any organization running Kemp LoadMaster is at immediate risk.
##Progress Kemp LoadMaster Vulnerability Actively Exploited
Progress Software's Kemp LoadMaster is reportedly actively attacked following the release of a proof-of-concept for a remote code execution flaw (CVE-2026-8037).
**This is now urgent. Make sure all your Kemp LoadMaster appliances are updated to the latest versions immediately, because you are being hacked. If you do not require the management API for daily operations, disable it or isolate it behind a secure VPN so it is reachable only from trusted internal networks.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/progress-kemp-loadmaster-vulnerability-actively-exploited-u-c-i-k-t/gD2P6Ple2L
Kemp LoadMaster RCE Vulnerability Exploited in the Wild After Public PoC Release
##eSentire, from yesterday: Progress Kemp LoadMaster Vulnerability Targeted (CVE-2026-8037) https://www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037 #infosec #vulnerability
##📢 CVE-2026-8037 : RCE pré-authentifiée dans Progress Kemp LoadMaster via heap non initialisé
📝 ## 🔍 Contexte
Le 29 juin 2026, watchTowr Labs publie une anal...
📖 cyberveille : https://cyberveille.ch/posts/2026-07-01-cve-2026-8037-rce-pre-authentifiee-dans-progress-kemp-loadmaster-via-heap-non-initialise/
🌐 source : https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037
#CVE_2026_8037 #IOC #Cyberveille
⚠️ CRITICAL: Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
Critical unauthenticated RCE in Progress Kemp LoadMaster (CVE-2026-8037) allows attackers to execute arbitrary root commands via API input sanitization bypass. A public proof-of-concept exists. All LoadMaster instances are at risk unless patched immediately.
##updated 2026-07-01T05:16:21.907000
1 posts
A critical CVSS 10 ColdFusion arbitrary code execution flaw (CVE-2026-48282) is actively exploited in the wild. Update immediately to prevent attacks.
#ColdFusion #CVE202648282 #CyberSecurity #Vulnerability #Infosec
##updated 2026-07-01T00:34:02
1 posts
Five DCMTK vulnerabilities hit the DICOM toolkit, including a CVSS 9.8 path traversal file write (CVE-2026-50003). Update DCMTK now.
#DCMTK #DICOM #PathTraversal #CVE202650003 #MedicalImaging #ICS #Vulnerability
##updated 2026-06-30T18:31:41
1 posts
CRITICAL vulnerabilities patched in Adobe ColdFusion (2025/2023) & Campaign Classic (7.4.3 build 9397). Multiple CVSS 10.0 flaws incl. CVE-2026-48286, CVE-2026-48276 – 83. No active exploits, but patch ASAP. https://radar.offseq.com/threat/adobe-patches-critical-coldfusion-campaign-classic-baee08e7ac9d8888 #OffSeq #Adobe #ColdFusion #Vuln
##updated 2026-06-30T18:22:26.317000
1 posts
Apple's June 2026 update fixes 28 CVEs with no confirmed in-the-wild exploitation. Focus on WebKit memory corruption (CVE-2026-43705, CVE-2026-43715) and kernel-write bugs (CVE-2026-39868, CVE-2026-43724)—classic chain toward...
##updated 2026-06-30T18:19:33
1 posts
CVE-2026-50564 (CRITICAL): Fission <1.24.0 lets CRD users deploy privileged pods via unfiltered podSpec, leading to node escape & full compromise. Patch to v1.24.0. Restrict permissions if upgrade not possible. https://radar.offseq.com/threat/ghsa-gx55-f84r-v3r7-fission-environment-crd-podspe-d60bd0900af19d2d #OffSeq #Kubernetes #CVE202650564 #CloudSec
##updated 2026-06-30T15:31:48
1 posts
Apple's June 2026 update fixes 28 CVEs with no confirmed in-the-wild exploitation. Focus on WebKit memory corruption (CVE-2026-43705, CVE-2026-43715) and kernel-write bugs (CVE-2026-39868, CVE-2026-43724)—classic chain toward...
##updated 2026-06-30T15:30:45
1 posts
Nine Apache ActiveMQ vulnerabilities allow denial of service and a temporary destination takeover (CVE-2026-54475). Upgrade to 6.2.7 now.
#ApacheActiveMQ #ActiveMQ #CVE202654475 #DenialOfService #OpenWire #STOMP #MessageBroker #Vulnerability
##updated 2026-06-30T15:30:44
1 posts
Seven Apache Tomcat vulnerabilities are patched, including an authentication bypass (CVE-2026-55957). Update to a fixed Tomcat release now.
#ApacheTomcat #Tomcat #CVE202655957 #AuthenticationBypass #JNDIRealm #WebServerSecurity #Vulnerability
##updated 2026-06-30T15:30:33
2 posts
3 repos
https://github.com/kaleth4/CVE-2026-55200
No, the libssh2 vulnerability CVE-2026-55200 isn't end of the world.
1. You need to defeat ASLR to successfully exploit it. The PoC works only when you disable ASLR. In most realistic use cases you need additional off-band infoleak from the app using libssh2.
2. You also must somehow convince the victim to connect to your malicious server, OR compromise some existing server to perform the attack.
Calling this a "CRITICAL VULNERABILITY" is dumb.
##@bascule libssh2 was the most concerning dependency needed to add cargo to Ubuntu main (lp#1991650).
In 2018 @chrisccoulson reported CVE-2019-3855 through -3863. CVE-2019-3855 is the same bug as today's: a server-controlled packet_length with no upper bound, overflowing the transport read. 1.8.1 added a bounds check. CVE-2026-55200 is the same check missing 7 years later, on the chacha20-poly1305 path. That path is post-KEX, so at least host-key verification gates it (unlike 3855).
##updated 2026-06-30T00:32:31
1 posts
Apple's June 2026 update fixes 28 CVEs with no confirmed in-the-wild exploitation. Focus on WebKit memory corruption (CVE-2026-43705, CVE-2026-43715) and kernel-write bugs (CVE-2026-39868, CVE-2026-43724)—classic chain toward...
##updated 2026-06-30T00:32:31
1 posts
Apple's June 2026 update fixes 28 CVEs with no confirmed in-the-wild exploitation. Focus on WebKit memory corruption (CVE-2026-43705, CVE-2026-43715) and kernel-write bugs (CVE-2026-39868, CVE-2026-43724)—classic chain toward...
##updated 2026-06-29T21:32:12
1 posts
CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF #devopsish https://aws.amazon.com/security/security-bulletins/2026-048-aws/
##updated 2026-06-29T21:32:12
1 posts
CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF #devopsish https://aws.amazon.com/security/security-bulletins/2026-048-aws/
##updated 2026-06-26T22:16:30.897000
1 posts
1 repos
TP-Link DHCP Option 66 Unauthenticated RCE (CVE-2026-11834) | mattg.systems https://mattg.systems/posts/cve-2026-11834/
##updated 2026-06-26T19:03:32
1 posts
Six Incus vulnerabilities, all rated CVSS 9.9, are fixed in v7.2.0. CVE-2026-48769 and CVE-2026-48755 enable root attacks. Update now.
#Incus #LinuxContainers #ContainerSecurity #CVE #Cybersecurity #Infosec
##updated 2026-06-26T16:36:11
1 posts
Four Fluentd vulnerabilities are fixed in v1.19.3, including a 9.8 RCE (CVE-2026-44024) and SSRF (CVE-2026-44161). Patch now.
##updated 2026-06-26T16:32:06
1 posts
Four Fluentd vulnerabilities are fixed in v1.19.3, including a 9.8 RCE (CVE-2026-44024) and SSRF (CVE-2026-44161). Patch now.
##updated 2026-06-26T16:16:36.820000
1 posts
Ten GeoVision camera vulnerabilities hit GV-LPC2011/2211 models, four rated CVSS 9.8 (CVE-2026-57878). Update to firmware V1.13 now.
#GeoVision #IoTSecurity #CVE #BufferOverflow #Cybersecurity #Infosec
##updated 2026-06-24T17:25:29
1 posts
A critical OpenAM WebAuthn RCE flaw (CVE-2026-45051) allows code execution via Java deserialization. Update OpenAM to 16.1.1 to stay protected.
#OpenAM #WebAuthn #RCE #CVE202645051 #CyberSecurity #InfoSec
https://securityonline.info/openam-webauthn-rce/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-06-24T15:31:50
1 posts
A ProFTPD ACL bypass (CVE-2026-35025, CVSS 8.6) lets logged-in FTP users reach files in restricted directories. No patch is out yet; use DefaultRoot.
#ProFTPD #CVE202635025 #ACLBypass #FTP #CyberSecurity
https://securityonline.info/proftpd-acl-bypass/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-06-23T15:32:48
1 posts
A NetComm authentication bypass (CVE-2026-35019, CVSS 9.2) uses a hardcoded AES key to forge admin session cookies. Update to firmware R6B032 now.
##updated 2026-06-22T20:07:04.253000
1 posts
3 repos
https://github.com/HORKimhab/CVE-2026-10520-10523
https://github.com/gagaltotal/CVE-2026-10523-Ivanti-sentry
https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523
📈 CVE Published in last 30 days (2026-06-01 - 2026-07-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 855
- High: 3079
- Medium: 2559
- Low: 534
- None: 684
Status:
- : 344
- Analyzed: 2815
- Awaiting Analysis: 562
- Deferred: 3102
- Modified: 173
- Received: 551
- Rejected: 49
- Undergoing Analysis: 115
CISA KEVs:
- CISA-2026:0601 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0601)
- CISA-2026:0602 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0602)
- CISA-2026:0603 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0603)
- CISA-2026:0605 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0605)
- CISA-2026:0608 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0608)
- CISA-2026:0609 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0609)
- CISA-2026:0611 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0611)
- CISA-2026:0612 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0612)
- CISA-2026:0615 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0615)
- CISA-2026:0616 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0616)
- CISA-2026:0618 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0618)
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
- CISA-2026:0629 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0629)
Top CNAs:
- GitHub, Inc.: 1163
- Patchstack: 731
- VulnCheck: 612
- Chrome: 584
- kernel.org: 514
- VulDB: 468
- N/A: 344
- MITRE: 329
- Wordfence: 256
- Oracle: 242
Top Affected Products:
- UNKNOWN: 4698
- Google Chrome: 583
- Google Android: 118
- Microsoft Windows 11 26h1: 111
- Microsoft Windows Server 2025: 109
- Microsoft Windows 11 24h2: 105
- Microsoft Windows 11 25h2: 105
- Microsoft Windows Server 2022: 104
- Microsoft Windows 11 23h2: 99
- Microsoft Windows 10 22h2: 91
Top EPSS Score:
- CVE-2026-10520 - 98.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10520)
- CVE-2026-35273 - 92.33 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-35273)
- CVE-2026-20253 - 88.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20253)
- CVE-2026-48907 - 80.43 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48907)
- CVE-2026-50751 - 71.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50751)
- CVE-2026-49160 - 48.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49160)
- CVE-2026-10523 - 47.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10523)
- CVE-2026-20230 - 41.69 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20230)
- CVE-2026-0826 - 26.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0826)
- CVE-2026-25089 - 23.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-25089)
updated 2026-06-19T15:33:15
1 posts
JetBrains patched a CVSS 10 authentication bypass and two more flaws (CVE-2026-50242). Its tools reach 15M developers. Update JetBrains Hub now.
#JetBrains #AuthenticationBypass #CVE202650242 #JetBrainsHub #GoLand
##updated 2026-06-18T18:35:18
1 posts
5 repos
https://github.com/fevar54/CVE-2026-20253-Splunk-Enterprise-Pre-Auth-RCE-
https://github.com/0xBlackash/CVE-2026-20253
https://github.com/watchtowrlabs/watchTowr-vs-Splunk-CVE-2026-20253
📈 CVE Published in last 30 days (2026-06-01 - 2026-07-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 855
- High: 3079
- Medium: 2559
- Low: 534
- None: 684
Status:
- : 344
- Analyzed: 2815
- Awaiting Analysis: 562
- Deferred: 3102
- Modified: 173
- Received: 551
- Rejected: 49
- Undergoing Analysis: 115
CISA KEVs:
- CISA-2026:0601 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0601)
- CISA-2026:0602 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0602)
- CISA-2026:0603 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0603)
- CISA-2026:0605 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0605)
- CISA-2026:0608 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0608)
- CISA-2026:0609 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0609)
- CISA-2026:0611 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0611)
- CISA-2026:0612 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0612)
- CISA-2026:0615 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0615)
- CISA-2026:0616 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0616)
- CISA-2026:0618 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0618)
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
- CISA-2026:0629 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0629)
Top CNAs:
- GitHub, Inc.: 1163
- Patchstack: 731
- VulnCheck: 612
- Chrome: 584
- kernel.org: 514
- VulDB: 468
- N/A: 344
- MITRE: 329
- Wordfence: 256
- Oracle: 242
Top Affected Products:
- UNKNOWN: 4698
- Google Chrome: 583
- Google Android: 118
- Microsoft Windows 11 26h1: 111
- Microsoft Windows Server 2025: 109
- Microsoft Windows 11 24h2: 105
- Microsoft Windows 11 25h2: 105
- Microsoft Windows Server 2022: 104
- Microsoft Windows 11 23h2: 99
- Microsoft Windows 10 22h2: 91
Top EPSS Score:
- CVE-2026-10520 - 98.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10520)
- CVE-2026-35273 - 92.33 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-35273)
- CVE-2026-20253 - 88.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20253)
- CVE-2026-48907 - 80.43 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48907)
- CVE-2026-50751 - 71.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50751)
- CVE-2026-49160 - 48.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49160)
- CVE-2026-10523 - 47.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10523)
- CVE-2026-20230 - 41.69 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20230)
- CVE-2026-0826 - 26.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0826)
- CVE-2026-25089 - 23.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-25089)
updated 2026-06-17T18:36:17
1 posts
17 repos
https://github.com/0xBlackash/CVE-2026-48907
https://github.com/87achrafg-stack/CVE-2026-48907
https://github.com/K3ysTr0K3R/CVE-2026-48907
https://github.com/g0thamRabb1t/joomla-jce-cve-2026-48907-detection
https://github.com/wearehackers160/CVE-2026-48907
https://github.com/bayu06802/CVE-2026-48907
https://github.com/ywh-jfellus/CVE-2026-48907
https://github.com/Almavj/Joomla_CVE_2026_48907
https://github.com/pssec-io/CVE-2026-48907
https://github.com/0xgh057r3c0n/CVE-2026-48907
https://github.com/webshellseo8/CVE-2026-48907-Unauthenticated-RCE-in-JCE
https://github.com/xitexploiter96-dot/CVE-2026-48907-
https://github.com/grayxploit/CVE-2026-48907
https://github.com/gh1mau/masta-cve-2026-48907
https://github.com/sec0x/CVE-2026-48907
📈 CVE Published in last 30 days (2026-06-01 - 2026-07-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 855
- High: 3079
- Medium: 2559
- Low: 534
- None: 684
Status:
- : 344
- Analyzed: 2815
- Awaiting Analysis: 562
- Deferred: 3102
- Modified: 173
- Received: 551
- Rejected: 49
- Undergoing Analysis: 115
CISA KEVs:
- CISA-2026:0601 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0601)
- CISA-2026:0602 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0602)
- CISA-2026:0603 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0603)
- CISA-2026:0605 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0605)
- CISA-2026:0608 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0608)
- CISA-2026:0609 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0609)
- CISA-2026:0611 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0611)
- CISA-2026:0612 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0612)
- CISA-2026:0615 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0615)
- CISA-2026:0616 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0616)
- CISA-2026:0618 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0618)
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
- CISA-2026:0629 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0629)
Top CNAs:
- GitHub, Inc.: 1163
- Patchstack: 731
- VulnCheck: 612
- Chrome: 584
- kernel.org: 514
- VulDB: 468
- N/A: 344
- MITRE: 329
- Wordfence: 256
- Oracle: 242
Top Affected Products:
- UNKNOWN: 4698
- Google Chrome: 583
- Google Android: 118
- Microsoft Windows 11 26h1: 111
- Microsoft Windows Server 2025: 109
- Microsoft Windows 11 24h2: 105
- Microsoft Windows 11 25h2: 105
- Microsoft Windows Server 2022: 104
- Microsoft Windows 11 23h2: 99
- Microsoft Windows 10 22h2: 91
Top EPSS Score:
- CVE-2026-10520 - 98.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10520)
- CVE-2026-35273 - 92.33 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-35273)
- CVE-2026-20253 - 88.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20253)
- CVE-2026-48907 - 80.43 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48907)
- CVE-2026-50751 - 71.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50751)
- CVE-2026-49160 - 48.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49160)
- CVE-2026-10523 - 47.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10523)
- CVE-2026-20230 - 41.69 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20230)
- CVE-2026-0826 - 26.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0826)
- CVE-2026-25089 - 23.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-25089)
updated 2026-06-17T11:01:08.343000
3 posts
maintainability concerns.
- **Arduino/ESP32 libraries**: DeterministicESPAsyncWebServer, AMY Synthesizer, Ultrasonic Sensor Library, XC_GUI, ServoTimer2Plus, RisalDash, SuperDMZ, ArduboyI2C, HomeAssistantMQTT.
- **PostgreSQL & databases**: PostgreSQL 19 beta (`WAIT FOR LSN`), TimescaleDB 2.28.1, pg_lake extension, CVE-2026-6637, durable execution in Postgres (pgdurable).
- **LLM-driven development**: Fable for macOS/iOS ports, pxpipe for token efficiency, AI agent frameworks [2/3]
Blip blop, I'm a #mastobot.
Here is a summary (in beta) of the latest posts in #programmingAtKukei https://masto.kukei.eu/browse/programming category:
- **AI coding tools & workflows**: Claude Code, GitHub Copilot, LangGraph, CrewAI, OpenAI Agents SDK, AI-generated code bans (Godot Engine, Alibaba).
- **PostgreSQL updates**: PostgreSQL 19 beta (`WAIT FOR LSN`), TimescaleDB 2.28.1, pg_lake extension, CVE-2026-6637.
- **NetBSD updates**: Pullups for NetBSD 9/10/11, Canna input method fixes, [1/2]
*DeterministicESPAsyncWebServer*, *AMY Synthesizer*, *LionArray*, *RisalDash*, *GyverLibs* updates.
- **PostgreSQL updates**: PostgreSQL 19 beta (`WAIT FOR LSN`), TimescaleDB 2.28.1, pg_lake extension for Iceberg, CVE-2026-6637 (stack buffer overflow).
- **JupyterLab 4.6 & Notebook 7.6**: New Scratchpad console, faster extension builds with Rspack.
- **Rust & SemVer**: `cargo-semver-checks` for API-breaking changes, Rust stabilization reports. [2/2]
updated 2026-06-17T10:57:46.373000
2 posts
7 repos
https://github.com/WadesWeaponShed/CVE-2026-50751-Mitigation-Scripts
https://github.com/fevar54/CVE-2026-50751---Check-Point-IKEv1-Authentication-Bypass-Exploit
https://github.com/0xBlackash/CVE-2026-50751
https://github.com/fernstedt/CVE-2026-50751
https://github.com/hlkysipv/CVE-2026-50751-Check-Point-IKEv1-Authentication-Bypass
https://github.com/watchtowrlabs/watchTowr-vs-Check-Point-CVE-2026-50751
https://github.com/WadesWeaponShed/CheckPoint-CVE-Webscanner
Why patch directives only go so far https://cyberscoop.com/why-security-patching-is-not-enough-cve-2026-50751-op-ed/
##📈 CVE Published in last 30 days (2026-06-01 - 2026-07-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 855
- High: 3079
- Medium: 2559
- Low: 534
- None: 684
Status:
- : 344
- Analyzed: 2815
- Awaiting Analysis: 562
- Deferred: 3102
- Modified: 173
- Received: 551
- Rejected: 49
- Undergoing Analysis: 115
CISA KEVs:
- CISA-2026:0601 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0601)
- CISA-2026:0602 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0602)
- CISA-2026:0603 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0603)
- CISA-2026:0605 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0605)
- CISA-2026:0608 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0608)
- CISA-2026:0609 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0609)
- CISA-2026:0611 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0611)
- CISA-2026:0612 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0612)
- CISA-2026:0615 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0615)
- CISA-2026:0616 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0616)
- CISA-2026:0618 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0618)
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
- CISA-2026:0629 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0629)
Top CNAs:
- GitHub, Inc.: 1163
- Patchstack: 731
- VulnCheck: 612
- Chrome: 584
- kernel.org: 514
- VulDB: 468
- N/A: 344
- MITRE: 329
- Wordfence: 256
- Oracle: 242
Top Affected Products:
- UNKNOWN: 4698
- Google Chrome: 583
- Google Android: 118
- Microsoft Windows 11 26h1: 111
- Microsoft Windows Server 2025: 109
- Microsoft Windows 11 24h2: 105
- Microsoft Windows 11 25h2: 105
- Microsoft Windows Server 2022: 104
- Microsoft Windows 11 23h2: 99
- Microsoft Windows 10 22h2: 91
Top EPSS Score:
- CVE-2026-10520 - 98.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10520)
- CVE-2026-35273 - 92.33 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-35273)
- CVE-2026-20253 - 88.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20253)
- CVE-2026-48907 - 80.43 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48907)
- CVE-2026-50751 - 71.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50751)
- CVE-2026-49160 - 48.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49160)
- CVE-2026-10523 - 47.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10523)
- CVE-2026-20230 - 41.69 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20230)
- CVE-2026-0826 - 26.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0826)
- CVE-2026-25089 - 23.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-25089)
updated 2026-06-17T10:57:43.053000
1 posts
CVE-2026-50566 (CRITICAL): Fission <1.24.0 allows SecurityContext bypass, letting attackers with Environment CRD access create privileged pods — risking container escape & cluster takeover. Patch to 1.24.0 & tighten RBAC. https://radar.offseq.com/threat/ghsa-m63v-2g9w-2w6v-fission-environment-runtimecon-e24c700c3e6ffd6e #OffSeq #Kubernetes #InfoSec
##updated 2026-06-17T10:55:09.423000
3 posts
2 repos
https://github.com/citruscitruscitruscitruscitrusci/CVE-2026-48611-poc
Remember the phpBB authentication bypass our research team found? We said the proof was coming. 💥 It's here.
Two working PoCs, one for each vulnerability, are now live in the research:
👉 PTT-2026-004 (CVE-2026-48611, 9.4): the PoC shows the full path from a single crafted request to a valid admin session. No credentials that work, no prior access, no user interaction. Just the request and the session cookie that _shouldn't_ exist.
👉 PTT-2026-005 (CVE-2026-48612, 8.3): the PoC walks through the silent OAuth account takeover, including the case where the victim only has to load a forum post for the chain to fire.
Talk is cheap in this line of work, so check out both PoCs, plus the mitigation steps: https://pentest-tools.com/research/phpbb-authentication-bypass
phpBB 3.3.17 fixes both. If you haven't patched, the PoCs are a good reason to move today.
##Remember the phpBB authentication bypass our research team found? We said the proof was coming. 💥 It's here.
Two working PoCs, one for each vulnerability, are now live in the research:
👉 PTT-2026-004 (CVE-2026-48611, 9.4): the PoC shows the full path from a single crafted request to a valid admin session. No credentials that work, no prior access, no user interaction. Just the request and the session cookie that _shouldn't_ exist.
👉 PTT-2026-005 (CVE-2026-48612, 8.3): the PoC walks through the silent OAuth account takeover, including the case where the victim only has to load a forum post for the chain to fire.
Talk is cheap in this line of work, so check out both PoCs, plus the mitigation steps: https://pentest-tools.com/research/phpbb-authentication-bypass
phpBB 3.3.17 fixes both. If you haven't patched, the PoCs are a good reason to move today.
##Critical phpBB Authentication Bypass Allows Instant Account Takeover
phpBB version 3.3.17 patches a critical authentication bypass (CVE-2026-48611) that allows unauthenticated attackers to take over any account, including administrators, by manipulating the auth_provider parameter.
**If you run a phpBB forum (versions 3.1.0 through 3.3.16, or 4.0.0-a2), this is important and urgent. Update to version 3.3.17 immediately. If you can't patch right away, delete the apache.php and ldap.php files from the phpbb/auth/provider/ directory, and check your server logs for suspicious auth_provider=apache and mode=login_link requests. If found, reset all user sessions and assume those accounts are compromised.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-phpbb-authentication-bypass-allows-instant-account-takeover-b-z-9-a-7/gD2P6Ple2L
updated 2026-06-17T10:49:38.170000
2 posts
https://thecybersecguru.com/exploits/cve-2026-43456-linux-kernel-zero-day/
##https://thecybersecguru.com/exploits/cve-2026-43456-linux-kernel-zero-day/
##updated 2026-06-17T10:38:36.970000
1 posts
#GnuPG 2.5.21-freepg has been released.
It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.
Note that the FreePG project considers the 2.5.x branch to be experimental, and does not enable non-standard OpenPGP algorithms unless “--compliance=gnupg” is explicitly set.
Release notes
=============
Noteworthy changes in version 2.5.21-freepg (2026-07-03)
--------------------------------------------------------
* No FreePG-specific changes.
https://gitlab.com/freepg/gnupg/-/releases/gnupg-2.5.21-freepg
Upstream's release notes follow.
----
Noteworthy changes in version 2.5.21 (2026-07-02)
-------------------------------------------------
* New and extended features:
- gpg, gpgsm: Use partial file on decryption, remove on failure.
Disable with "--compatibility-flags=no-partial-file-guard".
[T7873]
- gpg: Use the INT_RCP_FPR subpacket in revocation signatures.
[T8252]
- Create a pkgversioninfo.txt file when building using the speedo
build system.
* Bug fixes:
- gpg: Fix potential use-after-free in batch key generation when
handling the keyserver URL option. [T8277]
- gpgsm: Fix regression in gpgsm_verify with expired certificates.
[T8188]
- gpgsm: Require a minimum tag length for GCM decryption.
[rG4c7e68cf3d, CVE-2026-34182]
- scd: Limit the size of returned APDU objects from faulty cards.
[T8281]
- scd: Fix condition to retrieve ATR. [rGca25a7a61b]
- scd:openpgp: Fix regression in CHV1 retry counter byte index.
[rG245330ebea]
- agent: Make batch import of Kyber keys work. [T8029]
- dirmngr: Add a validation check in get_dns_cert_standard.
[T8303]
- gpgconf: Raise an error on certain parse errors. [T8261]
- Fix use of usleep in file remove function on Windows. Regression
since 2.5.13. [rGab9ce5f5e7]
Release-info: https://dev.gnupg.org/T8262
##updated 2026-06-17T10:36:47.177000
1 posts
14 repos
https://github.com/rootdirective-sec/CVE-2026-33017-Lab
https://github.com/Jorrit-VM/CVE-2026-33017
https://github.com/diamorphine666/CVE-2026-33017-Exploit
https://github.com/EQSTLab/CVE-2026-33017
https://github.com/r3nsi15/CVE-2026-33017-langflow-rce
https://github.com/omer-efe-curkus/CVE-2026-33017-Langflow-RCE-PoC
https://github.com/oscar-mine/CVE-2026-33017-Exploit
https://github.com/SimoesCTT/Sovereign-Echo-33017
https://github.com/MaxMnMl/langflow-CVE-2026-33017-poc
https://github.com/yayip/CVE-2026-33017
https://github.com/0xBlackash/CVE-2026-33017
https://github.com/masterwok/PoC-CVE-2026-33017
‼️ One POST to RCE: Unauthenticated Code Execution in Langflow (CVE-2026-33017)
##updated 2026-06-17T10:12:16.930000
1 posts
6 repos
https://github.com/error-inside/CVE-2026-10520
https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523
https://github.com/0xBlackash/CVE-2026-10520
https://github.com/emilliewatson96/spryCVE-2026-10520
📈 CVE Published in last 30 days (2026-06-01 - 2026-07-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 855
- High: 3079
- Medium: 2559
- Low: 534
- None: 684
Status:
- : 344
- Analyzed: 2815
- Awaiting Analysis: 562
- Deferred: 3102
- Modified: 173
- Received: 551
- Rejected: 49
- Undergoing Analysis: 115
CISA KEVs:
- CISA-2026:0601 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0601)
- CISA-2026:0602 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0602)
- CISA-2026:0603 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0603)
- CISA-2026:0605 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0605)
- CISA-2026:0608 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0608)
- CISA-2026:0609 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0609)
- CISA-2026:0611 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0611)
- CISA-2026:0612 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0612)
- CISA-2026:0615 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0615)
- CISA-2026:0616 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0616)
- CISA-2026:0618 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0618)
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
- CISA-2026:0629 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0629)
Top CNAs:
- GitHub, Inc.: 1163
- Patchstack: 731
- VulnCheck: 612
- Chrome: 584
- kernel.org: 514
- VulDB: 468
- N/A: 344
- MITRE: 329
- Wordfence: 256
- Oracle: 242
Top Affected Products:
- UNKNOWN: 4698
- Google Chrome: 583
- Google Android: 118
- Microsoft Windows 11 26h1: 111
- Microsoft Windows Server 2025: 109
- Microsoft Windows 11 24h2: 105
- Microsoft Windows 11 25h2: 105
- Microsoft Windows Server 2022: 104
- Microsoft Windows 11 23h2: 99
- Microsoft Windows 10 22h2: 91
Top EPSS Score:
- CVE-2026-10520 - 98.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10520)
- CVE-2026-35273 - 92.33 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-35273)
- CVE-2026-20253 - 88.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20253)
- CVE-2026-48907 - 80.43 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48907)
- CVE-2026-50751 - 71.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50751)
- CVE-2026-49160 - 48.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49160)
- CVE-2026-10523 - 47.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10523)
- CVE-2026-20230 - 41.69 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20230)
- CVE-2026-0826 - 26.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0826)
- CVE-2026-25089 - 23.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-25089)
updated 2026-06-17T10:11:27.080000
1 posts
📈 CVE Published in last 30 days (2026-06-01 - 2026-07-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 855
- High: 3079
- Medium: 2559
- Low: 534
- None: 684
Status:
- : 344
- Analyzed: 2815
- Awaiting Analysis: 562
- Deferred: 3102
- Modified: 173
- Received: 551
- Rejected: 49
- Undergoing Analysis: 115
CISA KEVs:
- CISA-2026:0601 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0601)
- CISA-2026:0602 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0602)
- CISA-2026:0603 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0603)
- CISA-2026:0605 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0605)
- CISA-2026:0608 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0608)
- CISA-2026:0609 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0609)
- CISA-2026:0611 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0611)
- CISA-2026:0612 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0612)
- CISA-2026:0615 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0615)
- CISA-2026:0616 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0616)
- CISA-2026:0618 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0618)
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
- CISA-2026:0629 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0629)
Top CNAs:
- GitHub, Inc.: 1163
- Patchstack: 731
- VulnCheck: 612
- Chrome: 584
- kernel.org: 514
- VulDB: 468
- N/A: 344
- MITRE: 329
- Wordfence: 256
- Oracle: 242
Top Affected Products:
- UNKNOWN: 4698
- Google Chrome: 583
- Google Android: 118
- Microsoft Windows 11 26h1: 111
- Microsoft Windows Server 2025: 109
- Microsoft Windows 11 24h2: 105
- Microsoft Windows 11 25h2: 105
- Microsoft Windows Server 2022: 104
- Microsoft Windows 11 23h2: 99
- Microsoft Windows 10 22h2: 91
Top EPSS Score:
- CVE-2026-10520 - 98.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10520)
- CVE-2026-35273 - 92.33 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-35273)
- CVE-2026-20253 - 88.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20253)
- CVE-2026-48907 - 80.43 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48907)
- CVE-2026-50751 - 71.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50751)
- CVE-2026-49160 - 48.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49160)
- CVE-2026-10523 - 47.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10523)
- CVE-2026-20230 - 41.69 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20230)
- CVE-2026-0826 - 26.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0826)
- CVE-2026-25089 - 23.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-25089)
updated 2026-06-17T07:24:59.037000
1 posts
2 repos
Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk
Analysis of CVE-2024-2658 as found in Schneider Electric's Floating License Manager. Discover how this FlexNet Publisher vulnerability potentially...
🔗️ [Securelist] https://link.is.it/DVUIfS
##updated 2026-06-12T18:31:50
2 posts
4 repos
https://github.com/0xBlackash/CVE-2026-35273
https://github.com/ekomsSavior/POC_cve_2026_35273
📈 CVE Published in last 30 days (2026-06-01 - 2026-07-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 855
- High: 3079
- Medium: 2559
- Low: 534
- None: 684
Status:
- : 344
- Analyzed: 2815
- Awaiting Analysis: 562
- Deferred: 3102
- Modified: 173
- Received: 551
- Rejected: 49
- Undergoing Analysis: 115
CISA KEVs:
- CISA-2026:0601 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0601)
- CISA-2026:0602 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0602)
- CISA-2026:0603 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0603)
- CISA-2026:0605 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0605)
- CISA-2026:0608 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0608)
- CISA-2026:0609 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0609)
- CISA-2026:0611 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0611)
- CISA-2026:0612 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0612)
- CISA-2026:0615 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0615)
- CISA-2026:0616 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0616)
- CISA-2026:0618 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0618)
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
- CISA-2026:0629 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0629)
Top CNAs:
- GitHub, Inc.: 1163
- Patchstack: 731
- VulnCheck: 612
- Chrome: 584
- kernel.org: 514
- VulDB: 468
- N/A: 344
- MITRE: 329
- Wordfence: 256
- Oracle: 242
Top Affected Products:
- UNKNOWN: 4698
- Google Chrome: 583
- Google Android: 118
- Microsoft Windows 11 26h1: 111
- Microsoft Windows Server 2025: 109
- Microsoft Windows 11 24h2: 105
- Microsoft Windows 11 25h2: 105
- Microsoft Windows Server 2022: 104
- Microsoft Windows 11 23h2: 99
- Microsoft Windows 10 22h2: 91
Top EPSS Score:
- CVE-2026-10520 - 98.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10520)
- CVE-2026-35273 - 92.33 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-35273)
- CVE-2026-20253 - 88.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20253)
- CVE-2026-48907 - 80.43 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48907)
- CVE-2026-50751 - 71.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50751)
- CVE-2026-49160 - 48.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49160)
- CVE-2026-10523 - 47.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10523)
- CVE-2026-20230 - 41.69 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20230)
- CVE-2026-0826 - 26.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0826)
- CVE-2026-25089 - 23.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-25089)
updated 2026-06-12T06:33:21
2 posts
Remember the phpBB authentication bypass our research team found? We said the proof was coming. 💥 It's here.
Two working PoCs, one for each vulnerability, are now live in the research:
👉 PTT-2026-004 (CVE-2026-48611, 9.4): the PoC shows the full path from a single crafted request to a valid admin session. No credentials that work, no prior access, no user interaction. Just the request and the session cookie that _shouldn't_ exist.
👉 PTT-2026-005 (CVE-2026-48612, 8.3): the PoC walks through the silent OAuth account takeover, including the case where the victim only has to load a forum post for the chain to fire.
Talk is cheap in this line of work, so check out both PoCs, plus the mitigation steps: https://pentest-tools.com/research/phpbb-authentication-bypass
phpBB 3.3.17 fixes both. If you haven't patched, the PoCs are a good reason to move today.
##Remember the phpBB authentication bypass our research team found? We said the proof was coming. 💥 It's here.
Two working PoCs, one for each vulnerability, are now live in the research:
👉 PTT-2026-004 (CVE-2026-48611, 9.4): the PoC shows the full path from a single crafted request to a valid admin session. No credentials that work, no prior access, no user interaction. Just the request and the session cookie that _shouldn't_ exist.
👉 PTT-2026-005 (CVE-2026-48612, 8.3): the PoC walks through the silent OAuth account takeover, including the case where the victim only has to load a forum post for the chain to fire.
Talk is cheap in this line of work, so check out both PoCs, plus the mitigation steps: https://pentest-tools.com/research/phpbb-authentication-bypass
phpBB 3.3.17 fixes both. If you haven't patched, the PoCs are a good reason to move today.
##updated 2026-06-09T18:31:11
1 posts
1 repos
https://github.com/dhmosfunk/CVE-2026-49160-CVE-2026-47291-HTTP.sys
📈 CVE Published in last 30 days (2026-06-01 - 2026-07-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 855
- High: 3079
- Medium: 2559
- Low: 534
- None: 684
Status:
- : 344
- Analyzed: 2815
- Awaiting Analysis: 562
- Deferred: 3102
- Modified: 173
- Received: 551
- Rejected: 49
- Undergoing Analysis: 115
CISA KEVs:
- CISA-2026:0601 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0601)
- CISA-2026:0602 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0602)
- CISA-2026:0603 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0603)
- CISA-2026:0605 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0605)
- CISA-2026:0608 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0608)
- CISA-2026:0609 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0609)
- CISA-2026:0611 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0611)
- CISA-2026:0612 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0612)
- CISA-2026:0615 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0615)
- CISA-2026:0616 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0616)
- CISA-2026:0618 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0618)
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
- CISA-2026:0629 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0629)
Top CNAs:
- GitHub, Inc.: 1163
- Patchstack: 731
- VulnCheck: 612
- Chrome: 584
- kernel.org: 514
- VulDB: 468
- N/A: 344
- MITRE: 329
- Wordfence: 256
- Oracle: 242
Top Affected Products:
- UNKNOWN: 4698
- Google Chrome: 583
- Google Android: 118
- Microsoft Windows 11 26h1: 111
- Microsoft Windows Server 2025: 109
- Microsoft Windows 11 24h2: 105
- Microsoft Windows 11 25h2: 105
- Microsoft Windows Server 2022: 104
- Microsoft Windows 11 23h2: 99
- Microsoft Windows 10 22h2: 91
Top EPSS Score:
- CVE-2026-10520 - 98.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10520)
- CVE-2026-35273 - 92.33 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-35273)
- CVE-2026-20253 - 88.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20253)
- CVE-2026-48907 - 80.43 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48907)
- CVE-2026-50751 - 71.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50751)
- CVE-2026-49160 - 48.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49160)
- CVE-2026-10523 - 47.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10523)
- CVE-2026-20230 - 41.69 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20230)
- CVE-2026-0826 - 26.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0826)
- CVE-2026-25089 - 23.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-25089)
updated 2026-06-09T18:30:58
1 posts
1 repos
HawkTrace publicly disclosed Microsoft Exchange vulnerability CVE-2026-45504 with PoC exploit code. The SSRF flaw reads arbitrary files. Patch now.
#MicrosoftExchange #CVE202645504 #SSRF #Cybersecurity #PoC #Infosec
updated 2026-06-09T18:30:47
1 posts
2 repos
📈 CVE Published in last 30 days (2026-06-01 - 2026-07-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 855
- High: 3079
- Medium: 2559
- Low: 534
- None: 684
Status:
- : 344
- Analyzed: 2815
- Awaiting Analysis: 562
- Deferred: 3102
- Modified: 173
- Received: 551
- Rejected: 49
- Undergoing Analysis: 115
CISA KEVs:
- CISA-2026:0601 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0601)
- CISA-2026:0602 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0602)
- CISA-2026:0603 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0603)
- CISA-2026:0605 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0605)
- CISA-2026:0608 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0608)
- CISA-2026:0609 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0609)
- CISA-2026:0611 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0611)
- CISA-2026:0612 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0612)
- CISA-2026:0615 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0615)
- CISA-2026:0616 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0616)
- CISA-2026:0618 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0618)
- CISA-2026:0623 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0623)
- CISA-2026:0625 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0625)
- CISA-2026:0629 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0629)
Top CNAs:
- GitHub, Inc.: 1163
- Patchstack: 731
- VulnCheck: 612
- Chrome: 584
- kernel.org: 514
- VulDB: 468
- N/A: 344
- MITRE: 329
- Wordfence: 256
- Oracle: 242
Top Affected Products:
- UNKNOWN: 4698
- Google Chrome: 583
- Google Android: 118
- Microsoft Windows 11 26h1: 111
- Microsoft Windows Server 2025: 109
- Microsoft Windows 11 24h2: 105
- Microsoft Windows 11 25h2: 105
- Microsoft Windows Server 2022: 104
- Microsoft Windows 11 23h2: 99
- Microsoft Windows 10 22h2: 91
Top EPSS Score:
- CVE-2026-10520 - 98.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10520)
- CVE-2026-35273 - 92.33 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-35273)
- CVE-2026-20253 - 88.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20253)
- CVE-2026-48907 - 80.43 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48907)
- CVE-2026-50751 - 71.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50751)
- CVE-2026-49160 - 48.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49160)
- CVE-2026-10523 - 47.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-10523)
- CVE-2026-20230 - 41.69 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20230)
- CVE-2026-0826 - 26.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0826)
- CVE-2026-25089 - 23.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-25089)
updated 2026-06-01T18:32:31
1 posts
1 repos
Unprivileged root via an out-of-bounds write in the FUSE readdir cache (CVE-2026-31694) https://lobste.rs/s/0kc445 #linux #security
https://cyberstan.co.uk/fuse-readdir-oob/
updated 2026-05-29T18:31:20
2 posts
2 repos
Oracle E-Business Suite under attack via critical flaw before exploit code emerged
https://1ban.news/oracle-ebs-attack-cve-2026-46817/
#1ban #oracle #ebs #attack #cve #tech
CRITICAL CVE-2026-46817 in Oracle E-Business Suite: Over 900 exposed instances face active exploit attempts via HTTP. Attackers can fully compromise systems. Apply May 2026 patch ASAP. Details: https://radar.offseq.com/threat/over-900-oracle-e-business-instances-exposed-to-on-032c4945a3a53de9 #OffSeq #Oracle #Vuln #ThreatIntel
##updated 2026-04-30T17:50:13
2 posts
Root Privilege Escalation and Container Escape Flaw Discovered in Coreutils
A high-severity vulnerability (CVE-2026-35368) in the uutils coreutils chroot utility allows attackers to execute arbitrary code as root and escape containers. The flaw occurs when the utility loads untrusted libraries from a new root directory before dropping system privileges.
**Update your Rust-based coreutils to version 0.8.0 immediately to prevent attackers from gaining root access through the chroot command. If you can't patch right away, stop using the --userspec flag on any directory that an untrusted user can edit.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/root-privilege-escalation-and-container-escape-flaw-discovered-in-coreutils-n-9-7-w-o/gD2P6Ple2L
Root Privilege Escalation and Container Escape Flaw Discovered in Coreutils
A high-severity vulnerability (CVE-2026-35368) in the uutils coreutils chroot utility allows attackers to execute arbitrary code as root and escape containers. The flaw occurs when the utility loads untrusted libraries from a new root directory before dropping system privileges.
**Update your Rust-based coreutils to version 0.8.0 immediately to prevent attackers from gaining root access through the chroot command. If you can't patch right away, stop using the --userspec flag on any directory that an untrusted user can edit.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/root-privilege-escalation-and-container-escape-flaw-discovered-in-coreutils-n-9-7-w-o/gD2P6Ple2L
updated 2026-04-23T00:31:18
1 posts
5 repos
https://github.com/0xBlackash/CVE-2026-33825
https://github.com/Letlaka/redsun-bluehammer-undefend-detection-pack
https://github.com/kaleth4/CVE-2026-33825
⚠️ CRITICAL: BlueHammer Vulnerability Exploited in Ransomware Attacks
CVE-2026-33825 (BlueHammer) in Microsoft Defender is being actively exploited in ransomware campaigns in the wild. This zero-day was publicly disclosed before patches became available on April 14, and CISA has confirmed active abuse. All Windows environments running vulnerable Defender versions are…
##updated 2025-10-22T00:34:22
1 posts
25 repos
https://github.com/ndr-repo/CVE-2025-5777
https://github.com/FrenzisRed/CVE-2025-5777
https://github.com/0xBlackash/CVE-2025-5777
https://github.com/SleepNotF0und/CVE-2025-5777
https://github.com/orange0Mint/CitrixBleed-2-CVE-2025-5777
https://github.com/bughuntar/CVE-2025-5777
https://github.com/RickGeex/CVE-2025-5777-CitrixBleed
https://github.com/win3zz/CVE-2025-5777
https://github.com/rootxsushant/Citrix-NetScaler-Memory-Leak-CVE-2025-5777
https://github.com/soltanali0/CVE-2025-5777-Exploit
https://github.com/sentinel-aidefense/CVE-2025-5777
https://github.com/mr-r3b00t/CVE-2025-5777
https://github.com/RaR1991/citrix_bleed_2
https://github.com/0xgh057r3c0n/CVE-2025-5777
https://github.com/cyberleelawat/ExploitVeer
https://github.com/Shivshantp/CVE-2025-5777-TrendMicro-ApexCentral-RCE
https://github.com/below0day/Honeypot-Logs-CVE-2025-5777
https://github.com/Chocapikk/CVE-2025-5777
https://github.com/fox-it/citrix-netscaler-triage
https://github.com/mingshenhk/CitrixBleed-2-CVE-2025-5777-PoC-
https://github.com/nocerainfosec/cve-2025-5777
https://github.com/Anshika2709/Citrixbleed2-CVE-2025-5777
https://github.com/idobarel/CVE-2025-5777
OpenAI voluntarily limited new AI models at government request on July 2. Cybersecurity threats remain high with critical Citrix Bleed 2 (CVE-2025-5777) and Microsoft SharePoint RCE (CVE-2026-45659) vulnerabilities being actively exploited, as reported on July 2-3. Google, in collaboration with the FBI, disrupted NetNut, a major residential proxy network spanning 2 million devices. Geopolitically, Iran issued warnings to ships regarding unapproved routes in the Strait of Hormuz on July 3.
##updated 2023-02-01T05:04:28
1 posts
@bascule libssh2 was the most concerning dependency needed to add cargo to Ubuntu main (lp#1991650).
In 2018 @chrisccoulson reported CVE-2019-3855 through -3863. CVE-2019-3855 is the same bug as today's: a server-controlled packet_length with no upper bound, overflowing the transport read. 1.8.1 added a bounds check. CVE-2026-55200 is the same check missing 7 years later, on the chacha20-poly1305 path. That path is post-KEX, so at least host-key verification gates it (unlike 3855).
##🔴 CVE-2026-58426 - Critical (9.6)
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58426/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-58426 - Critical (9.6)
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58426/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-58426 | CRITICAL in Gitea 1.22.0: Ambiguous HMAC signing enables cross-repo artifact reads & cross-task upload tampering. No patch available — restrict access, monitor activity. Details: https://radar.offseq.com/threat/cve-2026-58426-cwe-347-in-gitea-gitea-open-source--93937e1ae55d7b31 #OffSeq #CVE202658426 #Gitea #infosec
##🟠 CVE-2026-58423 - High (7.7)
LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58423/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58423 - High (7.7)
LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58423/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-20779 - Supply chain attack risk in Gitea. TOTP reuse flaw bypasses 2FA. CVSS 7.1. Update to 1.26.3 or later immediately. #CVE #Gitea #infosec
##1 posts
1 repos
https://github.com/M8seven/cve-2026-22874-gitea-ssrf-allowlist
CVE-2026-22874 - Critical SSRF in Gitea <=1.26.2. Incomplete webhook/migration filtering. CVSS 9.6. Upgrade immediately. #CVE #Gitea #infosec
##DuneSlide (CVE-2026-50548/50549): CRITICAL zero-click RCE in Cursor AI editor <3.0. Flaws in sandbox & symlink handling enable attackers to escape IDE, compromise OS. Upgrade to v3.0+ now. https://radar.offseq.com/threat/critical-cursor-ai-code-editor-flaws-could-lead-to-2cf2d4969fcd376b #OffSeq #Infosec #Vuln #RCE
##DuneSlide: Zero-Click RCE Vulnerabilities Discovered in Cursor IDE
Cato AI Labs identified two critical vulnerabilities (CVE-2026-50548 and CVE-2026-50549) in Cursor IDE that allow attackers to achieve remote code execution via zero-click prompt injection. The flaws enable sandbox escapes by overwriting system binaries through manipulated working directories and symlink resolution errors.
**If you use Cursor IDE, update ASAP to version 3.0 or later, because these flaws will be attacked very soon. Be cautious about letting the AI agent pull in content from untrusted external sources (like websites or files), since a malicious prompt hidden there is enough to trigger the attack with no other action from you.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/duneslide-zero-click-rce-vulnerabilities-discovered-in-cursor-ide-5-n-j-t-d/gD2P6Ple2L
DuneSlide: Zero-Click RCE Vulnerabilities Discovered in Cursor IDE
Cato AI Labs identified two critical vulnerabilities (CVE-2026-50548 and CVE-2026-50549) in Cursor IDE that allow attackers to achieve remote code execution via zero-click prompt injection. The flaws enable sandbox escapes by overwriting system binaries through manipulated working directories and symlink resolution errors.
**If you use Cursor IDE, update ASAP to version 3.0 or later, because these flaws will be attacked very soon. Be cautious about letting the AI agent pull in content from untrusted external sources (like websites or files), since a malicious prompt hidden there is enough to trigger the attack with no other action from you.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/duneslide-zero-click-rce-vulnerabilities-discovered-in-cursor-ide-5-n-j-t-d/gD2P6Ple2L
A critical Poweradmin host header injection flaw (CVE-2026-54588) lets attackers hijack DNS admin accounts. Update to 4.2.4 or 4.3.3 now.
#Poweradmin #PowerDNS #CVE202654588 #AccountTakeover #CyberSecurity #DNS
##Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657) https://syntetisk.tech/blog/posts/privilege-escalation-to-root-in-lima-qemu-guests-via-a-world-writable-agent-socket-cve-2026-53657/
##Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657) https://syntetisk.tech/blog/posts/privilege-escalation-to-root-in-lima-qemu-guests-via-a-world-writable-agent-socket-cve-2026-53657/
##New Gitea vulnerability found by me, tracked as CVE-2026-58418, just published: https://github.com/go-gitea/gitea/security/advisories/GHSA-rqhx-647v-wx32
##Six Incus vulnerabilities, all rated CVSS 9.9, are fixed in v7.2.0. CVE-2026-48769 and CVE-2026-48755 enable root attacks. Update now.
#Incus #LinuxContainers #ContainerSecurity #CVE #Cybersecurity #Infosec
##A critical Plone RCE vulnerability (CVE-2026-57149, CVSS 9.9) allows TALES injection via the Classic portlet. Two more flaws enable DoS and SSRF.
#Plone #RCE #CyberSecurity #CMS #PatchNow
https://securityonline.info/plone-rce-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
##