##
Updated at UTC 2026-08-09T02:46:41.235164
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-71992 | 9.8 | 0.00% | 2 | 0 | 2026-08-09T00:31:13 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71990 | 9.8 | 0.00% | 2 | 0 | 2026-08-09T00:31:13 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71983 | 9.8 | 0.00% | 2 | 0 | 2026-08-09T00:31:13 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71991 | 9.8 | 0.00% | 4 | 0 | 2026-08-09T00:31:07 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71993 | 9.8 | 0.00% | 4 | 0 | 2026-08-09T00:16:48.550000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71989 | 9.8 | 0.00% | 2 | 0 | 2026-08-09T00:16:47.953000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71988 | 9.8 | 0.00% | 2 | 0 | 2026-08-09T00:16:47.780000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71987 | 9.8 | 0.00% | 2 | 0 | 2026-08-09T00:16:47.637000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71986 | 9.8 | 0.00% | 2 | 0 | 2026-08-09T00:16:47.500000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71985 | 9.8 | 0.00% | 2 | 0 | 2026-08-09T00:16:47.360000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-71984 | 9.8 | 0.00% | 2 | 0 | 2026-08-09T00:16:47.207000 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | |
| CVE-2026-11612 | 0 | 0.00% | 1 | 0 | 2026-08-08T23:16:56.243000 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering | |
| CVE-2026-71955 | 9.8 | 0.00% | 2 | 0 | 2026-08-08T18:30:30 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2 | |
| CVE-2026-71958 | 9.8 | 0.00% | 2 | 0 | 2026-08-08T18:30:30 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2 | |
| CVE-2026-71954 | 9.8 | 0.00% | 2 | 0 | 2026-08-08T18:30:30 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71948 | 9.8 | 0.00% | 2 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71957 | 9.8 | 0.00% | 2 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2 | |
| CVE-2026-71956 | 9.8 | 0.00% | 2 | 0 | 2026-08-08T18:30:29 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2 | |
| CVE-2026-67620 | 7.7 | 0.00% | 2 | 1 | 2026-08-08T18:30:29 | Flowise through 3.1.4 contains a server-side request forgery vulnerability in th | |
| CVE-2026-42170 | 7.8 | 0.00% | 2 | 0 | 2026-08-08T18:30:29 | A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Su | |
| CVE-2026-71950 | 9.8 | 0.00% | 2 | 0 | 2026-08-08T18:16:55.780000 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-71949 | 9.8 | 0.00% | 2 | 0 | 2026-08-08T18:16:55.660000 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1 | |
| CVE-2026-64564 | 9.8 | 0.19% | 8 | 2 | 2026-08-08T15:31:27 | In the Linux kernel, the following vulnerability has been resolved: sctp: don't | |
| CVE-2026-64561 | 8.8 | 0.16% | 10 | 6 | 2026-08-08T15:30:24 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: C | |
| CVE-2026-14526 | 9.8 | 0.61% | 4 | 0 | 2026-08-08T09:30:28 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to authori | |
| CVE-2026-16594 | None | 0.14% | 2 | 0 | 2026-08-08T09:30:28 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorizatio | |
| CVE-2026-16955 | None | 0.16% | 2 | 0 | 2026-08-08T09:30:28 | The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied | |
| CVE-2026-16948 | 0 | 0.13% | 2 | 0 | 2026-08-08T07:17:11.227000 | The Solace Extra WordPress plugin before 1.6.1 does not perform capability check | |
| CVE-2026-8325 | 7.8 | 0.13% | 1 | 0 | 2026-08-08T05:17:10.573000 | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an | |
| CVE-2026-8037 | 9.6 | 99.31% | 8 | 2 | 2026-08-08T05:17:10.403000 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC | |
| CVE-2026-56162 | 10.0 | 0.48% | 1 | 0 | 2026-08-08T05:17:09.723000 | Improper authentication in Azure SQL Database allows an unauthorized attacker to | |
| CVE-2026-71560 | 9.1 | 0.55% | 2 | 0 | 2026-08-08T03:32:14 | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue | |
| CVE-2026-71559 | 7.5 | 0.59% | 2 | 0 | 2026-08-08T01:02:26.643000 | Deserialization of Untrusted Data vulnerability in the Go implementation of Apac | |
| CVE-2026-71558 | 9.8 | 0.71% | 2 | 0 | 2026-08-08T00:52:49.367000 | Heap type confusion vulnerability in Apache Fory C++ deserialization. This issu | |
| CVE-2026-52880 | 7.5 | 0.29% | 2 | 0 | 2026-08-07T23:17:04.890000 | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions f | |
| CVE-2026-52878 | 7.5 | 0.28% | 2 | 0 | 2026-08-07T23:17:04.593000 | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1 | |
| CVE-2026-20347 | 7.5 | 0.33% | 2 | 0 | 2026-08-07T22:16:58.003000 | A vulnerability in the Mach-O file format parser of ClamAV could allow an unauth | |
| CVE-2026-16258 | 9.8 | 0.47% | 2 | 0 | 2026-08-07T21:31:37 | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deseri | |
| CVE-2026-15361 | 8.1 | 0.22% | 2 | 0 | 2026-08-07T21:31:36 | The Content Views WordPress plugin before 4.5 does not perform a capability che | |
| CVE-2025-63235 | 7.5 | 0.32% | 2 | 0 | 2026-08-07T21:30:40 | In sol commit 373d848 (2024-12-12), the broker does not fully release resources | |
| CVE-2026-15215 | 8.8 | 0.35% | 2 | 0 | 2026-08-07T21:30:33 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify | |
| CVE-2026-43622 | 7.8 | 0.13% | 1 | 0 | 2026-08-07T21:30:31 | llama.cpp builds b1886 through b7445 contain a double free vulnerability in the | |
| CVE-2026-50540 | 9.6 | 0.38% | 2 | 0 | 2026-08-07T21:17:28.827000 | Kata Containers is an open source project focusing on a standard implementation | |
| CVE-2026-48169 | 8.8 | 0.26% | 1 | 0 | 2026-08-07T21:16:58 | ### Summary The PraisonAI Platform API has two authorization failures that toge | |
| CVE-2026-62296 | 7.5 | 0.28% | 2 | 0 | 2026-08-07T20:16:52.457000 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i | |
| CVE-2026-15972 | 7.5 | 0.39% | 2 | 0 | 2026-08-07T20:16:50.020000 | Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerab | |
| CVE-2026-48039 | 9.1 | 0.34% | 4 | 0 | 2026-08-07T19:29:59 | # Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token | Fi | |
| CVE-2026-70638 | 7.8 | 0.13% | 1 | 1 | 2026-08-07T19:18:53.427000 | llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability i | |
| CVE-2026-64637 | 9.9 | 0.23% | 4 | 0 | 2026-08-07T19:18:51.483000 | Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows | |
| CVE-2026-64636 | 7.7 | 0.21% | 2 | 0 | 2026-08-07T19:18:51.370000 | An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Win | |
| CVE-2026-20346 | 7.5 | 0.33% | 3 | 0 | 2026-08-07T19:17:41.360000 | A vulnerability in the PDF file format parser of ClamAV could allow an unauthent | |
| CVE-2026-16263 | 8.8 | 0.34% | 2 | 0 | 2026-08-07T19:17:37.240000 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check i | |
| CVE-2026-16262 | 7.5 | 0.16% | 2 | 0 | 2026-08-07T19:17:37.053000 | The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its O | |
| CVE-2026-16041 | 7.5 | 0.21% | 2 | 0 | 2026-08-07T19:17:36.343000 | The MStore API WordPress plugin before 4.21.0 does not perform authorization or | |
| CVE-2026-16038 | 9.1 | 0.24% | 2 | 0 | 2026-08-07T19:17:36.110000 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with | |
| CVE-2026-62918 | 7.5 | 0.29% | 1 | 0 | 2026-08-07T19:01:38.017000 | Improper verification of cryptographic signature in Microsoft Teams allows an un | |
| CVE-2026-65668 | 8.8 | 0.42% | 1 | 0 | 2026-08-07T19:01:11.610000 | Improper access control in Microsoft Purview eDiscovery allows an authorized att | |
| CVE-2026-71851 | 9.0 | 0.32% | 5 | 0 | 2026-08-07T18:50:37 | ### Summary `CryptoJS.lib.WordArray.random()` in affected versions is not a cry | |
| CVE-2026-16030 | 8.1 | 0.23% | 3 | 0 | 2026-08-07T18:32:49 | The MStore API WordPress plugin before 4.21.0 does not correctly verify the cry | |
| CVE-2026-14943 | 7.5 | 0.26% | 2 | 0 | 2026-08-07T18:32:48 | The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial | |
| CVE-2026-14205 | 9.8 | 0.27% | 2 | 0 | 2026-08-07T18:32:48 | The WP Events Manager WordPress plugin before 2.2.5 does not validate the reques | |
| CVE-2026-70636 | 7.5 | 0.37% | 1 | 0 | 2026-08-07T18:32:48 | Flowise through 3.1.4 contains an authentication bypass vulnerability that allow | |
| CVE-2026-20339 | 7.5 | 0.33% | 4 | 0 | 2026-08-07T18:31:54 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauth | |
| CVE-2026-20348 | 7.5 | 0.33% | 2 | 0 | 2026-08-07T18:31:54 | A vulnerability in the XAR file format parser of ClamAV could allow an unauthent | |
| CVE-2026-20345 | 7.5 | 0.33% | 2 | 0 | 2026-08-07T18:31:54 | A vulnerability in the GPT file format parser of ClamAV could allow an unauthent | |
| CVE-2026-20338 | 7.5 | 0.33% | 3 | 0 | 2026-08-07T18:31:53 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat | |
| CVE-2026-68772 | 8.0 | 0.40% | 2 | 0 | 2026-08-07T18:31:53 | ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMa | |
| CVE-2026-20337 | 7.5 | 0.36% | 5 | 0 | 2026-08-07T18:31:52 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat | |
| CVE-2026-19191 | 7.8 | 0.11% | 2 | 0 | 2026-08-07T18:17:12.073000 | A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. T | |
| CVE-2026-15816 | 7.5 | 0.25% | 1 | 0 | 2026-08-07T18:17:09.020000 | A flaw was found in dracut. The die() error-handling function writes its message | |
| CVE-2026-70332 | 9.6 | 0.48% | 2 | 0 | 2026-08-07T15:34:22 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unau | |
| CVE-2026-19264 | 9.8 | 0.63% | 1 | 0 | 2026-08-07T15:33:32 | Postiz is an open-source social media scheduling tool. The route that serves loc | |
| CVE-2026-56793 | 7.7 | 0.31% | 1 | 0 | 2026-08-07T15:33:30 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Im | |
| CVE-2026-34486 | 7.5 | 81.16% | 2 | 6 | 2026-08-07T12:37:06.283000 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f | |
| CVE-2026-54212 | None | 0.47% | 1 | 0 | 2026-08-07T12:32:06 | Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint | |
| CVE-2026-54213 | None | 0.45% | 1 | 0 | 2026-08-07T12:32:06 | Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality tha | |
| CVE-2026-54211 | None | 0.41% | 1 | 0 | 2026-08-07T12:32:00 | Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_ | |
| CVE-2026-49007 | 7.5 | 0.34% | 2 | 0 | 2026-08-07T09:32:04 | By accessing unencrypted information in the device firmware, an attacker can obt | |
| CVE-2026-9169 | 8.8 | 0.14% | 1 | 0 | 2026-08-07T09:32:04 | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows a | |
| CVE-2026-19195 | 7.8 | 0.11% | 1 | 0 | 2026-08-07T06:30:34 | A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affec | |
| CVE-2026-19192 | 7.8 | 0.11% | 2 | 0 | 2026-08-07T06:30:27 | A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affec | |
| CVE-2026-65400 | 7.1 | 0.30% | 4 | 0 | 2026-08-07T03:31:32 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-65667 | 10.0 | 0.44% | 2 | 0 | 2026-08-07T00:31:33 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elev | |
| CVE-2026-63508 | 10.0 | 0.44% | 3 | 0 | 2026-08-07T00:31:33 | Missing authentication for critical function in Microsoft Planetary Computer Pro | |
| CVE-2026-62873 | 9.8 | 0.34% | 2 | 0 | 2026-08-07T00:31:33 | Improper verification of cryptographic signature in Microsoft 365 Admin Center a | |
| CVE-2026-62896 | 9.6 | 0.38% | 1 | 0 | 2026-08-07T00:31:33 | Improper authentication in Microsoft Teams allows an authorized attacker to elev | |
| CVE-2026-68823 | 9.1 | 0.50% | 1 | 0 | 2026-08-07T00:31:33 | Exposed dangerous method or function in Azure Confidential Ledger allows an auth | |
| CVE-2026-59115 | 9.9 | 0.64% | 1 | 0 | 2026-08-07T00:31:28 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an autho | |
| CVE-2026-7406 | 7.8 | 0.13% | 1 | 0 | 2026-08-07T00:31:28 | A maliciously crafted BMP file, when parsed through certain Autodesk products, c | |
| CVE-2026-62836 | 8.7 | 0.36% | 2 | 0 | 2026-08-07T00:31:27 | Improper restriction of communication channel to intended endpoints in Azure SQL | |
| CVE-2026-59118 | 9.3 | 0.39% | 1 | 0 | 2026-08-07T00:31:27 | Improper authorization in Microsoft Power Apps allows an unauthorized attacker t | |
| CVE-2026-62830 | 9.9 | 0.42% | 1 | 0 | 2026-08-07T00:31:27 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevat | |
| CVE-2026-66709 | 9.1 | 0.48% | 1 | 0 | 2026-08-06T22:18:20.627000 | Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. | |
| CVE-2026-65575 | 9.8 | 0.31% | 1 | 0 | 2026-08-06T22:18:16.713000 | Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. | |
| CVE-2026-3430 | 8.6 | 0.24% | 1 | 1 | 2026-08-06T22:17:04.190000 | The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and esc | |
| CVE-2026-18258 | 8.8 | 0.31% | 1 | 0 | 2026-08-06T22:16:49.353000 | Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and | |
| CVE-2026-71488 | 7.5 | 0.35% | 1 | 0 | 2026-08-06T20:37:21 | ### Impact Affected versions of `league/commonmark` can have quadratic time com | |
| CVE-2026-53977 | 7.5 | 0.52% | 1 | 0 | 2026-08-06T18:30:57 | OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows u | |
| CVE-2026-53985 | 7.5 | 0.38% | 1 | 0 | 2026-08-06T18:30:56 | Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vuln | |
| CVE-2026-18359 | 8.5 | 0.22% | 1 | 0 | 2026-08-06T18:30:48 | Server-side request forgery in the METS and IIIF import URI handling in Scripta | |
| CVE-2026-66712 | 7.5 | 0.22% | 1 | 0 | 2026-08-06T16:16:49.343000 | Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions. | |
| CVE-2026-15459 | 8.1 | 0.51% | 1 | 0 | 2026-08-06T16:16:36.700000 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypa | |
| CVE-2026-20313 | 7.7 | 0.25% | 1 | 0 | 2026-08-06T15:44:56.043000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-66665 | 10.0 | 0.29% | 1 | 0 | 2026-08-06T15:32:56 | Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. | |
| CVE-2026-66708 | 8.2 | 0.22% | 1 | 0 | 2026-08-06T15:32:56 | Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. | |
| CVE-2026-67261 | 9.8 | 1.60% | 1 | 0 | 2026-08-06T15:32:56 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10. | |
| CVE-2026-66710 | 8.1 | 0.30% | 1 | 0 | 2026-08-06T15:32:56 | Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions. | |
| CVE-2026-66662 | 9.8 | 0.27% | 1 | 0 | 2026-08-06T15:32:55 | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 | |
| CVE-2026-66447 | 9.3 | 0.24% | 1 | 0 | 2026-08-06T15:32:55 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. | |
| CVE-2026-66733 | 7.5 | 0.89% | 1 | 0 | 2026-08-06T15:32:48 | Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vul | |
| CVE-2026-5430 | 10.0 | 0.22% | 2 | 0 | 2026-08-06T15:31:57.827000 | The JWT authentication mechanism accepts tokens signed with algorithms other tha | |
| CVE-2026-70646 | 7.5 | 0.35% | 1 | 0 | 2026-08-06T14:38:22 | ## Summary `WebhookHandler.feed_update()` deserializes the entire request body | |
| CVE-2026-1728 | 9.8 | 0.30% | 1 | 0 | 2026-08-06T09:30:39 | Tokens issued to a low-privileged user are not sufficiently restricted, allowing | |
| CVE-2026-70432 | 8.8 | 0.21% | 1 | 0 | 2026-08-05T21:32:44 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669 | |
| CVE-2026-63077 | 9.8 | 1.01% | 2 | 4 | 2026-08-05T18:32:31 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe | |
| CVE-2026-20310 | 9.1 | 0.37% | 1 | 0 | 2026-08-05T18:31:49 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20301 | 8.6 | 0.33% | 1 | 0 | 2026-08-05T18:31:48 | A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referre | |
| CVE-2026-20200 | 8.8 | 0.84% | 2 | 1 | 2026-08-05T18:31:42 | A vulnerability in the web-based management interface of Cisco IMC could allow a | |
| CVE-2026-66747 | 9.8 | 0.58% | 1 | 0 | 2026-08-05T15:17:04.690000 | Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, | |
| CVE-2026-58072 | 0 | 0.38% | 1 | 0 | 2026-08-05T05:17:01.967000 | A vulnerability in Veeam Service Provider Console allowing arbitrary file write | |
| CVE-2026-9198 | 9.8 | 17.05% | 1 | 4 | 2026-08-04T21:30:25 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain | |
| CVE-2026-64633 | None | 0.34% | 1 | 1 | 2026-08-04T18:31:36 | A vulnerability allowing remote unauthenticated code execution on the agent host | |
| CVE-2026-58073 | None | 0.22% | 1 | 0 | 2026-08-04T18:31:31 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated at | |
| CVE-2026-18577 | 8.1 | 4.10% | 1 | 2 | 2026-08-04T15:33:20 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco | |
| CVE-2026-18574 | None | 0.99% | 1 | 0 | 2026-08-03T15:32:49 | An authentication bypass vulnerability in Check Point Security Management Server | |
| CVE-2026-28323 | 9.8 | 0.64% | 1 | 0 | 2026-07-30T18:31:47 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass | |
| CVE-2026-64560 | 7.8 | 0.12% | 4 | 1 | 2026-07-30T12:32:18 | In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t | |
| CVE-2025-68260 | 7.8 | 0.16% | 1 | 0 | 2026-07-30T06:33:30 | In the Linux kernel, the following vulnerability has been resolved: rust_binder | |
| CVE-2026-39868 | 9.1 | 0.94% | 1 | 0 | 2026-07-27T21:16:51.020000 | This issue was addressed with improved input validation. This issue is fixed in | |
| CVE-2025-68686 | 5.9 | 1.26% | 1 | 0 | 2026-07-27T18:31:25 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE | |
| CVE-2026-64221 | 7.8 | 0.13% | 1 | 0 | 2026-07-27T06:31:36 | In the Linux kernel, the following vulnerability has been resolved: spi: ti-qsp | |
| CVE-2026-60667 | 7.4 | 0.33% | 1 | 0 | 2026-07-24T21:32:15 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle | |
| CVE-2026-65535 | 4.3 | 0.18% | 2 | 0 | 2026-07-23T12:32:58 | Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. | |
| CVE-2026-15409 | 10.0 | 78.44% | 1 | 6 | 2026-07-14T21:32:22 | A Server-side request forgery (SSRF) vulnerability has been identified in the SM | |
| CVE-2026-15410 | 7.2 | 76.35% | 1 | 3 | 2026-07-14T21:32:21 | Post-authentication improper control of generation of code ('Code Injection') vu | |
| CVE-2026-34348 | 6.5 | 0.71% | 2 | 0 | 2026-07-14T18:31:58 | Protection mechanism failure in Windows Event Logging Service allows an authoriz | |
| CVE-2026-0288 | 7.5 | 0.84% | 1 | 0 | 2026-07-10T15:45:17.463000 | Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (T | |
| CVE-2026-48170 | 9.1 | 0.25% | 4 | 0 | 2026-06-22T22:57:49 | ## Summary `scim-patch` performs prototype pollution when applying a SCIM PATCH | |
| CVE-2026-41679 | 10.0 | 2.95% | 2 | 1 | 2026-06-17T10:46:59.450000 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents | |
| CVE-2025-58486 | 4.0 | 0.16% | 1 | 0 | 2026-06-17T09:44:33.060000 | Improper input validation in Samsung Account prior to version 15.5.01.1 allows l | |
| CVE-2025-32463 | 9.3 | 56.34% | 1 | 77 | template | 2026-06-17T09:12:02.147000 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswi |
| CVE-2024-23692 | 9.8 | 99.47% | 1 | 14 | 2026-06-17T07:13:24.233000 | Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a t | |
| CVE-2026-52879 | 7.5 | 0.29% | 2 | 0 | 2026-06-09T18:40:42 | ### Summary `networkMessenger.directMessageHandler` in `network/p2p/libp2p/netM | |
| CVE-2026-47249 | 7.5 | 0.28% | 2 | 0 | 2026-06-05T15:27:42 | ### Summary A connected peer can send a compressed `RequestDataType_HashArrayTyp | |
| CVE-2026-28299 | 8.2 | 0.49% | 1 | 0 | 2026-06-02T21:30:50 | SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerab | |
| CVE-2026-29146 | 7.5 | 6.26% | 1 | 0 | 2026-04-15T21:33:41 | Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default | |
| CVE-2026-20079 | 10.0 | 37.67% | 1 | 1 | 2026-03-04T18:32:03 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2025-58487 | 4.0 | 0.15% | 1 | 0 | 2025-12-02T03:31:52 | Improper authorization in Samsung Account prior to version 15.5.01.1 allows loca | |
| CVE-2025-21079 | 7.1 | 0.41% | 1 | 0 | 2025-11-05T06:30:37 | Improper input validation in Samsung Members prior to version 5.5.01.3 allows re | |
| CVE-2025-8088 | 8.8 | 94.55% | 1 | 31 | 2025-10-22T00:34:26 | A path traversal vulnerability affecting the Windows version of WinRAR allows th | |
| CVE-2025-42999 | 9.1 | 11.28% | 1 | 1 | 2025-10-22T00:33:19 | SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged | |
| CVE-2021-26708 | 7.0 | 1.60% | 2 | 3 | 2023-11-18T05:04:48 | A local privilege escalation was discovered in the Linux kernel before 5.10.13. | |
| CVE-2015-6609 | None | 2.17% | 2 | 0 | 2023-01-27T05:08:18 | libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote | |
| CVE-2026-61808 | 0 | 0.34% | 3 | 0 | N/A | ||
| CVE-2026-60004 | 0 | 0.00% | 2 | 8 | N/A | ||
| CVE-2026-64638 | 0 | 0.77% | 10 | 18 | N/A | ||
| CVE-2022-40982 | 0 | 3.02% | 1 | 0 | N/A | ||
| CVE-2026-66060 | 0 | 0.11% | 1 | 0 | N/A | ||
| CVE-2026-19082 | 0 | 0.29% | 2 | 0 | N/A | ||
| CVE-2026-48097 | 0 | 0.27% | 2 | 0 | N/A | ||
| CVE-2026-65819 | 0 | 0.37% | 2 | 0 | N/A | ||
| CVE-2026-48026 | 0 | 0.22% | 2 | 0 | N/A | ||
| CVE-2026-46409 | 0 | 0.36% | 2 | 0 | N/A | ||
| CVE-2026-48120 | 0 | 0.14% | 2 | 0 | N/A | ||
| CVE-2026-62295 | 0 | 0.28% | 2 | 0 | N/A | ||
| CVE-2026-33691 | 0 | 3.58% | 1 | 0 | N/A | ||
| CVE-2026-49441 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-48024 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-48162 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-18576 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-16633 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-48088 | 0 | 0.29% | 1 | 0 | N/A | ||
| CVE-2026-7867 | 0 | 0.18% | 1 | 1 | N/A | ||
| CVE-2026-18427 | 0 | 0.46% | 1 | 0 | N/A | ||
| CVE-2026-59774 | 0 | 0.00% | 1 | 1 | N/A | ||
| CVE-2026-15991 | 0 | 0.61% | 1 | 0 | N/A |
updated 2026-08-09T00:31:13
2 posts
🔴 CVE-2026-71992 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71992/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71992 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71992/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:13
2 posts
🔴 CVE-2026-71990 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can expl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71990/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71990 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can expl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71990/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:13
2 posts
🔴 CVE-2026-71983 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parame...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71983 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parame...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:31:07
4 posts
🔴 CVE-2026-71991 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71991/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##MSI Radix AXE6600 routers (v781521) affected by CRITICAL CVE-2026-71991 🛡️. OS command injection via TelnetSSH enables remote root access. Restrict Telnet, segment devices, monitor for vendor fixes. https://radar.offseq.com/threat/cve-2026-71991-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-73b9d5ae919f36d2 #OffSeq #CVE202671991 #RouterSecurity
##🔴 CVE-2026-71991 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71991/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##MSI Radix AXE6600 routers (v781521) affected by CRITICAL CVE-2026-71991 🛡️. OS command injection via TelnetSSH enables remote root access. Restrict Telnet, segment devices, monitor for vendor fixes. https://radar.offseq.com/threat/cve-2026-71991-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-73b9d5ae919f36d2 #OffSeq #CVE202671991 #RouterSecurity
##updated 2026-08-09T00:16:48.550000
4 posts
MSI Radix AXE6600 v781521 suffers CRITICAL CVE-2026-71993 (CVSS 9.3): OS Command Injection via macfilter allows remote root access. Restrict remote access & monitor openvpn/macfilter activity. Details: https://radar.offseq.com/threat/cve-2026-71993-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-d8e25db330470f39 #OffSeq #CVE #RouterSecurity #Infosec
##🔴 CVE-2026-71993 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71993/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##MSI Radix AXE6600 v781521 suffers CRITICAL CVE-2026-71993 (CVSS 9.3): OS Command Injection via macfilter allows remote root access. Restrict remote access & monitor openvpn/macfilter activity. Details: https://radar.offseq.com/threat/cve-2026-71993-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-d8e25db330470f39 #OffSeq #CVE #RouterSecurity #Infosec
##🔴 CVE-2026-71993 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71993/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:16:47.953000
2 posts
🔴 CVE-2026-71989 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability thr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71989/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71989 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability thr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71989/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:16:47.780000
2 posts
🔴 CVE-2026-71988 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71988/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71988 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71988/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:16:47.637000
2 posts
🔴 CVE-2026-71987 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71987/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71987 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71987/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:16:47.500000
2 posts
🔴 CVE-2026-71986 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71986/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71986 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71986/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:16:47.360000
2 posts
🔴 CVE-2026-71985 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71985/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71985 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71985/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-09T00:16:47.207000
2 posts
🔴 CVE-2026-71984 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71984/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71984 - Critical (9.8)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71984/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T23:16:56.243000
1 posts
Critical Vulnerability in Network Device Firmware
📰 Original title: CVE-2026-11612
🤖 IA: It's not clickbait ✅
👥 Users: It's not clickbait ✅
View full AI summary https://en.killbait.com/critical-vulnerability-in-network-device-firmware.html?utm_source=mastodon_social&utm_medium=social&utm_campaign=killbait.mastodon_social
##updated 2026-08-08T18:30:30
2 posts
🔴 CVE-2026-71955 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, ta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71955/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71955 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, ta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71955/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:30
2 posts
🔴 CVE-2026-71958 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71958 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:30
2 posts
🔴 CVE-2026-71954 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71954/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71954 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71954/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
2 posts
🔴 CVE-2026-71948 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71948/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71948 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71948/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
2 posts
🔴 CVE-2026-71957 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71957/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71957 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71957/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
2 posts
🔴 CVE-2026-71956 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst fiel...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71956/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71956 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst fiel...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71956/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
2 posts
1 repos
🟠 CVE-2026-67620 - High (7.7)
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud meta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67620/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67620 - High (7.7)
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud meta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67620/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:30:29
2 posts
🟠 CVE-2026-42170 - High (7.8)
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42170/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-42170 - High (7.8)
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42170/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:16:55.780000
2 posts
🔴 CVE-2026-71950 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71950/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71950 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71950/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T18:16:55.660000
2 posts
🔴 CVE-2026-71949 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71949/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71949 - Critical (9.8)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71949/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T15:31:27
8 posts
2 repos
[1/7]
Most impactful security incidents / vulnerabilities reported between the start‑date you gave (`{date_limit}`) and today (2026‑08‑08)
The list is ordered by the three priority tiers you asked for. Only the most serious findings are shown – routine AV updates, generic router patches or niche‑product fixes have been omitted.
---
🎯 PRIORITY 1 – Critical / High‑impact flaws (CVSS 7‑10):
CVE‑2026‑64561
• Linux kernel (all flavours – RHEL, Ubuntu, SLES, OpenSUSE, AlmaLinux, Rocky Linux, Oracle UEK, Amazon Linux)
• 6.12.0‑211.39.1.el10_2 and earlier kernels listed in the CVE entry (≈ 300+ package builds)
• 9.8 / 9.0 (critical)
• Remote code execution / privilege escalation via a kernel‑level memory‑corruption bug that is exploitable without authentication. Affects the core OS of virtually every modern server and cloud image.
• https://vulnerability.circl.lu/vuln/CVE-2026-64561
CVE‑2026‑64564
• Linux kernel (same families as above)
• 6.12.0‑211.39.1.el10_2 and earlier kernels (see CVE entry)
• 9.8 / 9.0
• Same class of flaw as 64561 – a separate but equally critical kernel memory bug.
• https://vulnerability.circl.lu/vuln/CVE-2026-64564
CVE‑2026‑66315
• Microsoft Edge (Chromium‑based) – rendering engine
• All Edge 115.x releases prior to the 2026‑08‑04 security update
• 7.5 (High) – “Use‑after‑free” that leads to remote code execution; actively exploited in the wild.
• A browser used by > 1 billion users; a successful exploit gives full system compromise.
• https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52527
CVE‑2026‑71852
• Tenable Nessus plugin 333383 – unpatched_CVE_2026_71852.nasl (affects multiple Linux distributions)
• All Linux distros that ship the vulnerable library version listed in the plugin (e.g., Ubuntu 22.04, Debian 12, RHEL 9)
• 9.8 / 8.5 (Critical) – Remote code execution via crafted network traffic.
• The plugin shows a CVSS‑3.0 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; the bug is present in core system libraries used by containers and cloud VMs.
• https://www.tenable.com/plugins/nessus/333383
「18年前のLinux SCTPの脆弱性により、ローカルユーザーがroot権限を取得し、コンテナから脱出できる可能性 」: #TheHackerNews
「LinuxのSCTPネットワークコードに存在する解放済みメモリ使用のバグを悪用すると、ホスト上で完全なroot権限を取得できる可能性がある。Tencentの研究者らは、このバグを利用してコンテナから脱出し、その下にあるマシンにアクセスしたと述べている。
この脆弱性は2008年から存在していました。修正版は既にリリースされており、8月3日にリリースされた安定版カーネル7.1.6、6.18.42、6.12.101、6.6.148で修正されています。SCTP接続可能な古いカーネルを使用しているユーザーはアップデートしてください。
CVE-2026-64564 として追跡され 、 発見者によってSCTPhantom と名付けられたこの脆弱性は、カーネルCVEチームが割り当てた2日後の8月6日に公表された。 」
https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html
##SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
##「18年前のLinux SCTPの脆弱性により、ローカルユーザーがroot権限を取得し、コンテナから脱出できる可能性 」: #TheHackerNews
「LinuxのSCTPネットワークコードに存在する解放済みメモリ使用のバグを悪用すると、ホスト上で完全なroot権限を取得できる可能性がある。Tencentの研究者らは、このバグを利用してコンテナから脱出し、その下にあるマシンにアクセスしたと述べている。
この脆弱性は2008年から存在していました。修正版は既にリリースされており、8月3日にリリースされた安定版カーネル7.1.6、6.18.42、6.12.101、6.6.148で修正されています。SCTP接続可能な古いカーネルを使用しているユーザーはアップデートしてください。
CVE-2026-64564 として追跡され 、 発見者によってSCTPhantom と名付けられたこの脆弱性は、カーネルCVEチームが割り当てた2日後の8月6日に公表された。 」
https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html
##SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
##SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free https://lobste.rs/s/wdnet3 #linux #security #vibecoding
https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
#Debian stable has a fix now: linux-image-6.12.101+deb13-amd64
- sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564)
##Yet another linux LPE to root. "CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape"
##updated 2026-08-08T15:30:24
10 posts
6 repos
https://github.com/aarif450/Zapscape
https://github.com/HackSpeak/CVE-2026-64561
https://github.com/Aoripus-LTD/Zapscape-Fix
https://github.com/aarif450/aarif450.github.io
[1/7]
Most impactful security incidents / vulnerabilities reported between the start‑date you gave (`{date_limit}`) and today (2026‑08‑08)
The list is ordered by the three priority tiers you asked for. Only the most serious findings are shown – routine AV updates, generic router patches or niche‑product fixes have been omitted.
---
🎯 PRIORITY 1 – Critical / High‑impact flaws (CVSS 7‑10):
CVE‑2026‑64561
• Linux kernel (all flavours – RHEL, Ubuntu, SLES, OpenSUSE, AlmaLinux, Rocky Linux, Oracle UEK, Amazon Linux)
• 6.12.0‑211.39.1.el10_2 and earlier kernels listed in the CVE entry (≈ 300+ package builds)
• 9.8 / 9.0 (critical)
• Remote code execution / privilege escalation via a kernel‑level memory‑corruption bug that is exploitable without authentication. Affects the core OS of virtually every modern server and cloud image.
• https://vulnerability.circl.lu/vuln/CVE-2026-64561
CVE‑2026‑64564
• Linux kernel (same families as above)
• 6.12.0‑211.39.1.el10_2 and earlier kernels (see CVE entry)
• 9.8 / 9.0
• Same class of flaw as 64561 – a separate but equally critical kernel memory bug.
• https://vulnerability.circl.lu/vuln/CVE-2026-64564
CVE‑2026‑66315
• Microsoft Edge (Chromium‑based) – rendering engine
• All Edge 115.x releases prior to the 2026‑08‑04 security update
• 7.5 (High) – “Use‑after‑free” that leads to remote code execution; actively exploited in the wild.
• A browser used by > 1 billion users; a successful exploit gives full system compromise.
• https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52527
CVE‑2026‑71852
• Tenable Nessus plugin 333383 – unpatched_CVE_2026_71852.nasl (affects multiple Linux distributions)
• All Linux distros that ship the vulnerable library version listed in the plugin (e.g., Ubuntu 22.04, Debian 12, RHEL 9)
• 9.8 / 8.5 (Critical) – Remote code execution via crafted network traffic.
• The plugin shows a CVSS‑3.0 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; the bug is present in core system libraries used by containers and cloud VMs.
• https://www.tenable.com/plugins/nessus/333383
Instale já a correção para vulnerabilidade em máquinas virtuais
Se você usa Proxmox ou apenas tem um VPS, atualize já seu sistema. O problema permite o escape de máquinas virtuais e acesso à máquina física.
Se usa Debian, saiu o kernel 6.12.101-1 que corrige o problema. O Proxmox também já lançou atualização mesmo para quem não é assinante com o kernel 7.0.14-9.
:debian: https://security-tracker.debian.org/tracker/CVE-2026-64561
:xp_secure_server: https://forum.proxmox.com/threads/proxmox-and-cve-2026-64561.185571/
:xp_sys_info: https://www.cve.org/CVERecord?id=CVE-2026-64561
:github: https://github.com/V4bel/Zapscape
A new Linux Kernel KVM vulnerability threatens cloud servers with virtual machine escape risks. Learn about CVE-2026-64561 and secure your host machine now.
#LinuxKernel #KVMVulnerability #CVE202664561 #CloudSecurity #VMescape
##「Zapscape KVMの新たな脆弱性により、特権を持つL1ゲストコードがLinuxホストに漏洩する可能性 」: #TheHackerNews
「Linuxカーネルの新たな脆弱性「Zapscape」 により、L1ゲスト仮想マシン(VM)内でカーネル権限を持つ攻撃者がKVM分離を回避し、ホスト上でコードを実行できる可能性があります。このリスクは、ネストされた仮想化が信頼できないゲストに公開されている場合に発生します。
この脆弱性は CVE-2026-64561 として追跡されており、ネストされたゲストメモリ変換に使用されるシャドウページテーブルを管理するKVM/x86のシャドウメモリ管理ユニット(MMU)に影響を与えます。
このバグを明らかにしたセキュリティ研究者の キム・ヒョヌ氏 は、実証されたエクスプロイト経路によって、カーネル権限、つまりroot権限でホスト上でコマンドを実行できると述べた。 」
https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html
##CVE-2026-64561: Zapscape KVM Escape Runs Commands With Kernel Root Privilege, PoC Exploit Code Publicly Disclosed
##Not sure if I'm late to that party on this one or not. Guest to host escape in Linux KVM.
##Zapscape (CVE-2026-64561)
Zapscape is a use-after-free vulnerability in the shadow MMU emulation of KVM/x86, specifically in the recursive zap path that runs when shadow pages are reclaimed. It can trigger the bug with guest-side actions alone to corrupt the host kernel's shadow page, and it can threaten the guest-host isolation of KVM/x86 hosts that accept untrusted guests and expose nested virtualization, particularly multi-tenant x86 public clouds.
Zapscape (CVE-2026-64561): Guest-to-Host Escape in KVM/x86
Link: https://github.com/V4bel/Zapscape
Discussion: https://news.ycombinator.com/item?id=49198843
🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
https://github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated
Zapscape (CVE-2026-64561)
https://github.com/V4bel/Zapscape
Comments: https://news.ycombinator.com/item?id=49198843
#HackerNews #Zapscape #CVE-2026-64561 #cybersecurity #vulnerability #hackernews #open_source #software_security
##Zapscape (CVE-2026-64561): Guest-to-Host Escape in KVM/x86
##updated 2026-08-08T09:30:28
4 posts
CVE-2026-14526: AI Copilot – Content Generator <=1.5.6 has a CRITICAL auth bypass. Unauth attackers can create WordPress admin users via an exposed nonce, leading to site takeover. Disable [aiwu-form]/chatbot & check for vendor patch. https://radar.offseq.com/threat/cve-2026-14526-cwe-269-improper-privilege-management-in-wupsales-ai-copilot-content-generator-735a53bb0d60cd45 #OffSeq #CVE202614526 #WordPress
##🔴 CVE-2026-14526 - Critical (9.8)
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This make...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14526/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-14526: AI Copilot – Content Generator <=1.5.6 has a CRITICAL auth bypass. Unauth attackers can create WordPress admin users via an exposed nonce, leading to site takeover. Disable [aiwu-form]/chatbot & check for vendor patch. https://radar.offseq.com/threat/cve-2026-14526-cwe-269-improper-privilege-management-in-wupsales-ai-copilot-content-generator-735a53bb0d60cd45 #OffSeq #CVE202614526 #WordPress
##🔴 CVE-2026-14526 - Critical (9.8)
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This make...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14526/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T09:30:28
2 posts
CVE-2026-16594: WP Directory Kit <1.5.5 has a HIGH severity info exposure flaw. Any authenticated user (even Subscribers) can access API keys/secrets due to missing authorization on AJAX action. Restrict user roles & monitor logs. https://radar.offseq.com/threat/cve-2026-16594-cwe-200-information-exposure-in-wp-directory-kit-3d8a39f4c5fd7c8a #OffSeq #WordPress #CVE
##CVE-2026-16594: WP Directory Kit <1.5.5 has a HIGH severity info exposure flaw. Any authenticated user (even Subscribers) can access API keys/secrets due to missing authorization on AJAX action. Restrict user roles & monitor logs. https://radar.offseq.com/threat/cve-2026-16594-cwe-200-information-exposure-in-wp-directory-kit-3d8a39f4c5fd7c8a #OffSeq #WordPress #CVE
##updated 2026-08-08T09:30:28
2 posts
CVE-2026-16955: HIGH severity path traversal in AI Engine WP plugin <3.6.6. Subscribers can read arbitrary files if public API is enabled. Restrict API & admin privileges. Await patch. https://radar.offseq.com/threat/cve-2026-16955-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-ai-72905be644e71053 #OffSeq #WordPress #CVE2026_16955 #Security
##CVE-2026-16955: HIGH severity path traversal in AI Engine WP plugin <3.6.6. Subscribers can read arbitrary files if public API is enabled. Restrict API & admin privileges. Await patch. https://radar.offseq.com/threat/cve-2026-16955-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-ai-72905be644e71053 #OffSeq #WordPress #CVE2026_16955 #Security
##updated 2026-08-08T07:17:11.227000
2 posts
CVE-2026-16948 | HIGH severity in Solace Extra WP plugin <1.6.1: Missing capability checks on AJAX actions lets Subscribers change site settings & delete imported content. Patch status unknown — tighten role permissions. https://radar.offseq.com/threat/cve-2026-16948-cwe-284-improper-access-control-in-solace-extra-5877e08458999aac #OffSeq #WordPress #CVE2026_16948
##CVE-2026-16948 | HIGH severity in Solace Extra WP plugin <1.6.1: Missing capability checks on AJAX actions lets Subscribers change site settings & delete imported content. Patch status unknown — tighten role permissions. https://radar.offseq.com/threat/cve-2026-16948-cwe-284-improper-access-control-in-solace-extra-5877e08458999aac #OffSeq #WordPress #CVE2026_16948
##updated 2026-08-08T05:17:10.573000
1 posts
🟠 CVE-2026-8325 - High (7.8)
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8325/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T05:17:10.403000
8 posts
2 repos
🔵 THREAT INTELLIGENCE
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
Vulnerability | CRITICAL
CVEs: CVE-2026-8037
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster...
Full analysis:
https://www.yazoul.net/news/article/progress-kemp-loadmaster-flaw-hits-cisa-kev-after-792-reported-exploit-attempts
by Yazoul AI
##CISA Sounds the Alarm on Progress LoadMaster: Critical CVE-2026-8037 Is Now Under Active Exploitation + Video
A New Warning for Internet-Facing Infrastructure A dangerous vulnerability in Progress Kemp LoadMaster appliances has moved from a serious security concern to an urgent exploitation threat. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8037 to its Known Exploited Vulnerabilities (KEV) catalog, signaling that attackers are…
##Critical Progress Kemp LoadMaster Flaw Under Active Attack: CVE-2026-8037 Puts Enterprise Infrastructure at Risk + Video
Introduction: The Infrastructure Behind the Network Is Now in the Crosshairs Some of the most dangerous vulnerabilities are not found in the applications employees use every day. They are buried inside the infrastructure that quietly keeps those applications available. Load balancers are a perfect example. They sit between users and backend servers,…
##CRITICAL THREAT ALERT: Active exploitation of CVE-2026-8037 in Progress LoadMaster allows unauthenticated RCE via command injection. Securing your perimeter requires immediate SIEM detection updates and access restrictions. Review our full TSUITE analysis: https://thecybermind.co/5yde
##CRITICAL THREAT ALERT: Active exploitation of CVE-2026-8037 in Progress LoadMaster allows unauthenticated RCE via command injection. Securing your perimeter requires immediate SIEM detection updates and access restrictions. Review our full TSUITE analysis: https://thecybermind.co/5yde
##🚨 [CISA-2026:0807] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-8037 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8037)
- Name: Progress LoadMaster Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Progress
- Product: LoadMaster
- Notes: https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8037
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260807 #cisa20260807 #cve_2026_8037 #cve20268037
##CVE ID: CVE-2026-8037
Vendor: Progress
Product: LoadMaster
Date Added: 2026-08-07
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8037
CISA has added one vulnerability to the KEV catalogue:
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-8037 #CISA
Cisco:
NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 #Cisco
Palo Alto:
CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent https://security.paloaltonetworks.com/CVE-2026-0288
Microsoft:
Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: https://msrc.microsoft.com/update-guide/ #Microsoft
Google:
New: Chrome Dev for Android Update https://chromereleases.googleblog.com/ #Google #Chrome
Broadcom:
One new advisory for a high-severity vulnerability that was first published on July 23 https://support.broadcom.com/web/ecx/security-advisory
Posted yesterday:
Apple security updates https://support.apple.com/en-us/100100 #Apple
AMD: Safe RET Interrupt Vulnerability https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7061.html #AMD
Dell:
CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities #Dell #infosec #vulnerability #Java #SQL
##updated 2026-08-08T05:17:09.723000
1 posts
If you missed these yesterday.
"Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10."
Security Week: Microsoft, Apple Release Fresh Security Updates https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/ #Microsoft #Apple #infosec #vylnerability #Apple
##updated 2026-08-08T03:32:14
2 posts
🔴 CVE-2026-71560 - Critical (9.1)
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71560/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71560 - Critical (9.1)
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71560/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T01:02:26.643000
2 posts
🟠 CVE-2026-71559 - High (7.5)
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic.
This issue aff...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71559/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71559 - High (7.5)
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic.
This issue aff...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71559/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-08T00:52:49.367000
2 posts
🔴 CVE-2026-71558 - Critical (9.8)
Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserializat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71558/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71558 - Critical (9.8)
Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserializat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71558/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T23:17:04.890000
2 posts
🟠 CVE-2026-52880 - High (7.5)
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52880/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-52880 - High (7.5)
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52880/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T23:17:04.593000
2 posts
🟠 CVE-2026-52878 - High (7.5)
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawD...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52878/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-52878 - High (7.5)
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawD...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52878/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T22:16:58.003000
2 posts
🟠 CVE-2026-20347 - High (7.5)
A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerabili...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20347/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-20347 - High (7.5)
A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerabili...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20347/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:31:37
2 posts
🔴 CVE-2026-16258 - Critical (9.8)
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Searc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-16258 - Critical (9.8)
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Searc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:31:36
2 posts
🟠 CVE-2026-15361 - High (8.1)
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscrib...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15361/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-15361 - High (8.1)
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscrib...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15361/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:30:40
2 posts
🟠 CVE-2025-63235 - High (7.5)
In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-63235/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-63235 - High (7.5)
In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-63235/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:30:33
2 posts
🟠 CVE-2026-15215 - High (8.8)
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protecte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-15215 - High (8.8)
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protecte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:30:31
1 posts
🟠 CVE-2026-43622 - High (7.8)
llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43622/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:17:28.827000
2 posts
🔴 CVE-2026-50540 - Critical (9.6)
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated config...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50540/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-50540 - Critical (9.6)
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated config...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50540/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T21:16:58
1 posts
🟠 CVE-2026-48169 - High (8.8)
PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48169/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T20:16:52.457000
2 posts
🟠 CVE-2026-62296 - High (7.5)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62296/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62296 - High (7.5)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62296/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T20:16:50.020000
2 posts
🟠 CVE-2026-15972 - High (7.5)
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15972/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-15972 - High (7.5)
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15972/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:29:59
4 posts
pipeboard-co meta-ads-mcp (<1.0.109) affected by CRITICAL auth bypass (CVE-2026-48039). Unauthenticated requests can access tools & leak access tokens via error responses. Patch to 1.0.109+ ASAP. https://radar.offseq.com/threat/cve-2026-48039-cwe-287-improper-authentication-in-pipeboard-co-meta-ads-mcp-cda3b9551f498ab7 #OffSeq #CVE202648039 #infosec #vuln
##🔴 CVE-2026-48039 - Critical (9.1)
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48039/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##pipeboard-co meta-ads-mcp (<1.0.109) affected by CRITICAL auth bypass (CVE-2026-48039). Unauthenticated requests can access tools & leak access tokens via error responses. Patch to 1.0.109+ ASAP. https://radar.offseq.com/threat/cve-2026-48039-cwe-287-improper-authentication-in-pipeboard-co-meta-ads-mcp-cda3b9551f498ab7 #OffSeq #CVE202648039 #infosec #vuln
##🔴 CVE-2026-48039 - Critical (9.1)
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48039/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:18:53.427000
1 posts
1 repos
🟠 CVE-2026-70638 - High (7.8)
llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70638/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:18:51.483000
4 posts
🔴 CVE-2026-64637 - Critical (9.9)
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64637/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-64637 (CRITICAL, CVSS 9.9): WebPros Plesk <18.0.80 allows authenticated resellers to escalate privileges to root via XML-RPC API. Patch not confirmed — restrict access, monitor API use. https://radar.offseq.com/threat/cve-2026-64637-cwe-269-improper-privilege-management-in-webpros-plesk-ea44a21d820141d3 #OffSeq #Plesk #Vuln #PrivilegeEscalation
##🔴 CVE-2026-64637 - Critical (9.9)
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64637/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-64637 (CRITICAL, CVSS 9.9): WebPros Plesk <18.0.80 allows authenticated resellers to escalate privileges to root via XML-RPC API. Patch not confirmed — restrict access, monitor API use. https://radar.offseq.com/threat/cve-2026-64637-cwe-269-improper-privilege-management-in-webpros-plesk-ea44a21d820141d3 #OffSeq #Plesk #Vuln #PrivilegeEscalation
##updated 2026-08-07T19:18:51.370000
2 posts
🟠 CVE-2026-64636 - High (7.7)
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64636/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-64636 - High (7.7)
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64636/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:17:41.360000
3 posts
CVE-2026-20346 - ClamAV PDF parser memory corruption. Remote DoS via crafted PDFs. CVSS 7.5. Unpatched—monitor updates. #CVE #Cisco #infosec
##🟠 CVE-2026-20346 - High (7.5)
A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-20346 - High (7.5)
A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:17:37.240000
2 posts
🟠 CVE-2026-16263 - High (8.8)
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to includ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16263/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-16263 - High (8.8)
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to includ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16263/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:17:37.053000
2 posts
🟠 CVE-2026-16262 - High (7.5)
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16262/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-16262 - High (7.5)
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16262/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:17:36.343000
2 posts
🟠 CVE-2026-16041 - High (7.5)
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chose...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16041/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-16041 - High (7.5)
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chose...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16041/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:17:36.110000
2 posts
🔴 CVE-2026-16038 - Critical (9.1)
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order ful...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16038/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-16038 - Critical (9.1)
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order ful...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16038/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:01:38.017000
1 posts
🟠 CVE-2026-62918 - High (7.5)
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62918/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T19:01:11.610000
1 posts
🟠 CVE-2026-65668 - High (8.8)
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65668/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:50:37
5 posts
CVE-2026-71851 - Critical RCE in crypto-js <4.0.0. Weak PRNG seeded from Math.random() breaks entropy, enabling key recovery. CVSS 9.0. Patch now. #CVE #infosec #crypto
##CVE-2026-71851 (CRITICAL, CVSS 9): brix crypto-js <4.0.0 uses weak RNG in WordArray.random(), risking private key recovery in wallet apps using BIP39. Upgrade to 4.0.0+ now. https://radar.offseq.com/threat/cve-2026-71851-cwe-331-insufficient-entropy-in-brix-crypto-js-e5283f6c465bd95e #OffSeq #CryptoJS #InfoSec #Vulnerability
##🔴 CVE-2026-71851 - Critical (9)
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71851/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-71851 (CRITICAL, CVSS 9): brix crypto-js <4.0.0 uses weak RNG in WordArray.random(), risking private key recovery in wallet apps using BIP39. Upgrade to 4.0.0+ now. https://radar.offseq.com/threat/cve-2026-71851-cwe-331-insufficient-entropy-in-brix-crypto-js-e5283f6c465bd95e #OffSeq #CryptoJS #InfoSec #Vulnerability
##🔴 CVE-2026-71851 - Critical (9)
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71851/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:32:49
3 posts
🟠 CVE-2026-16030 - High (8.1)
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16030/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-16030 - High (8.1)
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16030/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##MStore API WordPress plugin (<4.21.0) hit by CRITICAL vuln (CVE-2026-16030): improper phone token checks enable account takeover, incl. admins. Restrict endpoints & monitor logins until patched. https://radar.offseq.com/threat/cve-2026-16030-cwe-287-improper-authentication-in-mstore-api-799def1fc3890a44 #OffSeq #WordPress #CVE2026_16030 #Vuln
##updated 2026-08-07T18:32:48
2 posts
🟠 CVE-2026-14943 - High (7.5)
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14943/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-14943 - High (7.5)
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14943/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:32:48
2 posts
🔴 CVE-2026-14205 - Critical (9.8)
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed book...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14205/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-14205 - Critical (9.8)
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed book...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14205/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:32:48
1 posts
🟠 CVE-2026-70636 - High (7.5)
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70636/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:54
4 posts
CVE-2026-20339 - ClamAV PESpin integer overflow, memory corruption DoS. CVSS 7.5. Unpatched. Update/limit scanning exposure. #CVE #Cisco #infosec
##🟠 CVE-2026-20339 - High (7.5)
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerabili...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20339/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-20339 - High (7.5)
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerabili...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20339/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CISA has added one vulnerability to the KEV catalogue:
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-8037 #CISA
Cisco:
NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 #Cisco
Palo Alto:
CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent https://security.paloaltonetworks.com/CVE-2026-0288
Microsoft:
Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: https://msrc.microsoft.com/update-guide/ #Microsoft
Google:
New: Chrome Dev for Android Update https://chromereleases.googleblog.com/ #Google #Chrome
Broadcom:
One new advisory for a high-severity vulnerability that was first published on July 23 https://support.broadcom.com/web/ecx/security-advisory
Posted yesterday:
Apple security updates https://support.apple.com/en-us/100100 #Apple
AMD: Safe RET Interrupt Vulnerability https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7061.html #AMD
Dell:
CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities #Dell #infosec #vulnerability #Java #SQL
##updated 2026-08-07T18:31:54
2 posts
🟠 CVE-2026-20348 - High (7.5)
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20348/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-20348 - High (7.5)
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20348/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:54
2 posts
🟠 CVE-2026-20345 - High (7.5)
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20345/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-20345 - High (7.5)
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20345/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:53
3 posts
🟠 CVE-2026-20338 - High (7.5)
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper memory handling when processing content in zip files durin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20338/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-20338 - High (7.5)
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper memory handling when processing content in zip files durin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20338/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CISA has added one vulnerability to the KEV catalogue:
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-8037 #CISA
Cisco:
NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 #Cisco
Palo Alto:
CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent https://security.paloaltonetworks.com/CVE-2026-0288
Microsoft:
Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: https://msrc.microsoft.com/update-guide/ #Microsoft
Google:
New: Chrome Dev for Android Update https://chromereleases.googleblog.com/ #Google #Chrome
Broadcom:
One new advisory for a high-severity vulnerability that was first published on July 23 https://support.broadcom.com/web/ecx/security-advisory
Posted yesterday:
Apple security updates https://support.apple.com/en-us/100100 #Apple
AMD: Safe RET Interrupt Vulnerability https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7061.html #AMD
Dell:
CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities #Dell #infosec #vulnerability #Java #SQL
##updated 2026-08-07T18:31:53
2 posts
🟠 CVE-2026-68772 - High (8)
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68772/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-68772 - High (8)
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68772/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:31:52
5 posts
CVE-2026-20337 - Memory corruption in ClamAV ZIP parsing, out-of-bounds write DoS. CVSS 7.5. Unpatched. Update or mitigate immediately. #CVE #Cisco #infosec
##🟠 CVE-2026-20337 - High (7.5)
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper boundary checks for content in zip files during scanning, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20337/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-20337 - Memory corruption in ClamAV ZIP parsing, out-of-bounds write DoS. CVSS 7.5. Unpatched. Update or mitigate immediately. #CVE #Cisco #infosec
##🟠 CVE-2026-20337 - High (7.5)
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper boundary checks for content in zip files during scanning, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20337/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CISA has added one vulnerability to the KEV catalogue:
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-8037 #CISA
Cisco:
NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 #Cisco
Palo Alto:
CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent https://security.paloaltonetworks.com/CVE-2026-0288
Microsoft:
Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: https://msrc.microsoft.com/update-guide/ #Microsoft
Google:
New: Chrome Dev for Android Update https://chromereleases.googleblog.com/ #Google #Chrome
Broadcom:
One new advisory for a high-severity vulnerability that was first published on July 23 https://support.broadcom.com/web/ecx/security-advisory
Posted yesterday:
Apple security updates https://support.apple.com/en-us/100100 #Apple
AMD: Safe RET Interrupt Vulnerability https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7061.html #AMD
Dell:
CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities #Dell #infosec #vulnerability #Java #SQL
##updated 2026-08-07T18:17:12.073000
2 posts
🟠 CVE-2026-19191 - High (7.8)
A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation lead...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19191/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19191 - High (7.8)
A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation lead...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19191/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T18:17:09.020000
1 posts
🟠 CVE-2026-15816 - High (7.5)
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH opt...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15816/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T15:34:22
2 posts
Critical SSRF (CVE-2026-70332) in Microsoft SharePoint Online (CVSS 9.6) lets attackers send unauthorized network requests. Patch ASAP with the official fix: https://radar.offseq.com/threat/cve-2026-70332-cwe-918-server-side-request-forgery-ssrf-in-microsoft-microsoft-sharepoint-online-34600d2dd5541b7c #OffSeq #InfoSec #Microsoft #SSRF #CloudSecurity
##🔴 CVE-2026-70332 - Critical (9.6)
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70332/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T15:33:32
1 posts
🔴 CVE-2026-19264 - Critical (9.8)
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19264/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T15:33:30
1 posts
🟠 CVE-2026-56793 - High (7.7)
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56793/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T12:37:06.283000
2 posts
6 repos
https://github.com/punitdarji/tomcat-cve-2026-34486
https://github.com/404-src/CVE-2026-34486
https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction
https://github.com/AirSkye/CVE-2026-34486-poc
🏆 New Achievement! Patch Notes From Hell!
Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)
##CISA Reports Active Exploitation of Apache Tomcat RCE Vulnerability
CISA reports active exploitation of an Apache Tomcat vulnerability (CVE-2026-34486) to its KEV catalog after Chinese threat actors exploited a fail-open logic error in the EncryptInterceptor to achieve remote code execution.
**If you run Apache Tomcat with clustering enabled, upgrade ASAP to 9.0.117, 10.1.54, or 11.0.21 This flaw is being actively exploited and can give attackers full remote code execution on every node in the cluster. If you can't patch, make sure your cluster traffic ports are not reachable from the internet, check `server.xml` and `context.xml` to confirm EncryptInterceptor is active with no custom interceptors overriding it, and turn off plain HTTP in favour of HTTPS only.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-reports-active-exploitation-of-apache-tomcat-rce-vulnerability-t-a-b-r-8/gD2P6Ple2L
updated 2026-08-07T12:32:06
1 posts
CVE-2026-54212: CRITICAL buffer overflow in Tobit TeamDavid Webbox API (≤ Rollout 524). Crafted JSON lets unauthenticated attackers crash servers; RCE possible if combined with other flaws. Restrict API, monitor activity. https://radar.offseq.com/threat/cve-2026-54212-cwe-787-out-of-bounds-write-in-tobit-laboratories-ag-teamdavid-2e946f5b4b7b0ab5 #OffSeq #CVE #bufferOverflow #infosec
##updated 2026-08-07T12:32:06
1 posts
CVE-2026-54213: CRITICAL improper access control in Tobit TeamDavid Webbox — public /internalRestart endpoint lets remote attackers trigger persistent DoS by shutting down servers. No patch yet. Restrict access & monitor. https://radar.offseq.com/threat/cve-2026-54213-cwe-284-improper-access-control-in-tobit-laboratories-ag-teamdavid-7d00f2efd17d315b #OffSeq #Cybersecurity #Vuln
##updated 2026-08-07T12:32:00
1 posts
Tobit TeamDavid (Webbox ≤ Rollout 524) hit by CRITICAL buffer overflow (CVE-2026-54211). Authenticated attackers can crash servers; possible RCE if stack canary is disclosed. Restrict access & monitor. No patch yet. https://radar.offseq.com/threat/cve-2026-54211-cwe-787-out-of-bounds-write-in-tobit-laboratories-ag-teamdavid-dd683c887b0f0b7a #OffSeq #Vulnerability #InfoSec
##updated 2026-08-07T09:32:04
2 posts
🟠 CVE-2026-49007 - High (7.5)
By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49007/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-49007 - High (7.5)
By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49007/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T09:32:04
1 posts
🟠 CVE-2026-9169 - High (8.8)
DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH en...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9169/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T06:30:34
1 posts
CVE-2026-19195 - Local privilege escalation in V-Secure Jingyun Antivirus via ZyArk.sys improper access controls. CVSS 7.8. Exploit public, no patch. Update or isolate now. #CVE #infosec #cybersecurity
##updated 2026-08-07T06:30:27
2 posts
🟠 CVE-2026-19192 - High (7.8)
A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19192/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19192 - High (7.8)
A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19192/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T03:31:32
4 posts
Whoa, macOS Sequoia 15.7.9 changes:
> An attacker on the network may be able to authenticate to Screen Sharing without valid credentials
https://xcancel.com/calif_io/status/2086022794840793454
> If Screen Sharing is enabled, any network attacker can exploit the bug to log in as any account, without knowing the password.
Good thing it requires screen sharing to be enabled though.
CVE-2026-65400
##macOS vulnerability: authenticate Screen Sharing without valid credentials
Calif 연구자가 macOS Screen Sharing이 활성화된 시스템에서 네트워크 공격자가 유효한 자격 증명 없이 임의 계정으로 로그인할 수 있다는 CVE-2026-65400 PoC를 공개했습니다. 설명대로라면 원격 데스크톱 접근 경로의 인증 우회로 이어지는 치명적 취약점이며, 개발용 macOS 워크스테이션·빌드 머신·원격 관리 호스트가 직접적인 영향권입니다. Apple은 macOS 26.6.1에서 이를 수정한 것으로 언급됐으며, 기술적 원인과 익스플로잇 상세 분석은 후속 공개 예정입니다. Screen Sharing을 사용 중인 조직은 즉시...
##https://thecybersecguru.com/news/cve-2026-65400-macos-screen-sharing-authentication-bypass/
##Whoa, macOS Sequoia 15.7.9 changes:
> An attacker on the network may be able to authenticate to Screen Sharing without valid credentials
https://xcancel.com/calif_io/status/2086022794840793454
> If Screen Sharing is enabled, any network attacker can exploit the bug to log in as any account, without knowing the password.
Good thing it requires screen sharing to be enabled though.
CVE-2026-65400
##updated 2026-08-07T00:31:33
2 posts
If you missed these yesterday.
"Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10."
Security Week: Microsoft, Apple Release Fresh Security Updates https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/ #Microsoft #Apple #infosec #vylnerability #Apple
##🔴 CVE-2026-65667 - Critical (10)
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65667/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:33
3 posts
If you missed these yesterday.
"Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10."
Security Week: Microsoft, Apple Release Fresh Security Updates https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/ #Microsoft #Apple #infosec #vylnerability #Apple
##CVE-2026-63508 (CRITICAL, CVSS 10): Microsoft Planetary Computer Pro (GeoCatalog) suffers from missing authentication, enabling remote privilege escalation. Immediate patching recommended. Details: https://radar.offseq.com/threat/cve-2026-63508-cwe-306-missing-authentication-for-critical-function-in-microsoft-microsoft-planetary-431bf04580187f39 #OffSeq #Vuln #Microsoft #Infosec
##🔴 CVE-2026-63508 - Critical (10)
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63508/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:33
2 posts
CVE-2026-62873 (CRITICAL, CVSS 9.8) affects Microsoft 365 Admin Center: Improper cryptographic signature checks allow privilege escalation over the network. Microsoft has issued a fix — confirm your environment is patched. https://radar.offseq.com/threat/cve-2026-62873-cwe-347-improper-verification-of-cryptographic-signature-in-microsoft-microsoft-365-5fad3518811d36c2 #OffSeq #Microsoft365 #Vuln
##🔴 CVE-2026-62873 - Critical (9.8)
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62873/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:33
1 posts
🔴 CVE-2026-62896 - Critical (9.6)
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62896/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:33
1 posts
🔴 CVE-2026-68823 - Critical (9.1)
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68823/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:28
1 posts
🔴 CVE-2026-59115 - Critical (9.9)
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59115/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:28
1 posts
🟠 CVE-2026-7406 - High (7.8)
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7406/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:27
2 posts
CVE-2026-62836 - Privilege escalation in Azure SQL Managed Instance via improper endpoint restriction. CVSS 8.7. Unpatched. Restrict network access and monitor. #CVE #Azure #infosec
##🟠 CVE-2026-62836 - High (8.7)
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62836/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:27
1 posts
🔴 CVE-2026-59118 - Critical (9.3)
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59118/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-07T00:31:27
1 posts
🔴 CVE-2026-62830 - Critical (9.9)
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62830/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T22:18:20.627000
1 posts
🔴 CVE-2026-66709 - Critical (9.1)
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66709/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T22:18:16.713000
1 posts
🔴 CVE-2026-65575 - Critical (9.8)
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65575/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T22:17:04.190000
1 posts
1 repos
🟠 CVE-2026-3430 - High (8.6)
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3430/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T22:16:49.353000
1 posts
🟠 CVE-2026-18258 - High (8.8)
Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via prim...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T20:37:21
1 posts
🟠 CVE-2026-71488 - High (7.5)
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71488/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T18:30:57
1 posts
🟠 CVE-2026-53977 - High (7.5)
OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authenti...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53977/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T18:30:56
1 posts
🟠 CVE-2026-53985 - High (7.5)
Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53985/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T18:30:48
1 posts
🟠 CVE-2026-18359 - High (8.5)
Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metada...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18359/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T16:16:49.343000
1 posts
🟠 CVE-2026-66712 - High (7.5)
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66712/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T16:16:36.700000
1 posts
🟠 CVE-2026-15459 - High (8.1)
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15459/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T15:44:56.043000
1 posts
🟠 CVE-2026-20313 - High (7.7)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20313/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T15:32:56
1 posts
🔴 CVE-2026-66665 - Critical (10)
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66665/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T15:32:56
1 posts
🟠 CVE-2026-66708 - High (8.2)
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66708/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T15:32:56
1 posts
🔴 CVE-2026-67261 - Critical (9.8)
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67261/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T15:32:56
1 posts
🟠 CVE-2026-66710 - High (8.1)
Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66710/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T15:32:55
1 posts
🔴 CVE-2026-66662 - Critical (9.8)
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66662/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T15:32:55
1 posts
🔴 CVE-2026-66447 - Critical (9.3)
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66447/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T15:32:48
1 posts
CVE-2026-66733: HIGH severity vuln in Eukaryot sonic3air ≤26.03.28.0. Crafted UDP packets can force unbounded memory allocation, crashing the server (DoS, no RCE). Patch unconfirmed — check vendor. https://radar.offseq.com/threat/cve-2026-66733-memory-allocation-with-excessive-size-value-in-eukaryot-sonic3air-4d6f914f9dea29a1 #OffSeq #Vuln #DoS #sonic3air
##updated 2026-08-06T15:31:57.827000
2 posts
WSO2 patched four critical account takeover flaws, including CVE-2026-5430 at CVSS 10 via JWT auth bypass. Details and fixes inside.
##WSO2 Universal Gateway v4.5.0 & 4.6.0 affected by CRITICAL CVE-2026-5430 (CVSS 10.0). Improper JWT validation enables account takeover. No patch yet — apply compensating controls. https://radar.offseq.com/threat/cve-2026-5430-cwe-347-improper-validation-of-certificate-with-host-mismatch-in-wso2-wso2-universal-f913080655427dd8 #OffSeq #WSO2 #JWT #Vulnerability
##updated 2026-08-06T14:38:22
1 posts
🟠 CVE-2026-70646 - High (7.5)
aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70646/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-06T09:30:39
1 posts
CVE-2026-1728 | CRITICAL: WSO2 API Manager (v4.0.0 – 4.6.0) has an improper privilege management flaw. Low-privileged user tokens can access admin REST APIs — possible admin account takeover. Patch status unknown. Restrict access & monitor. https://radar.offseq.com/threat/cve-2026-1728-cwe-269-improper-privilege-management-in-wso2-wso2-api-manager-fea4a27d18a06e70 #OffSeq #WSO2 #Vuln
##updated 2026-08-05T21:32:44
1 posts
🟠 CVE-2026-70432 - High (8.8)
A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70432/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T18:32:31
2 posts
4 repos
https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap
https://github.com/sfewer-r7/CVE-2026-63077
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html
##🚨 CSUITE THREAT ADVISORY: CISA confirms active exploitation of CVE-2026-63077 in JetBrains TeamCity. Unauthenticated RCE threatens core build pipelines & supply chain integrity. Get the executive governance, risk management, and compliance brief now: https://thecybermind.co/jvee
##updated 2026-08-05T18:31:49
1 posts
🔴 CVE-2026-20310 - Critical (9.1)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20310/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T18:31:48
1 posts
🟠 CVE-2026-20301 - High (8.6)
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20301/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T18:31:42
2 posts
1 repos
PoC exploit code is public for CVE-2026-20200, a Cisco IMC argument injection flaw enabling root RCE. CVSS 8.8. Patch details inside.
#Cisco #RCE #CVE #InfoSec #CyberSecurity
https://securityonline.info/cisco-imc-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
##🏆 New Achievement! Root Access: Now Available In Select Markets While Supplies Last!
TERMS AND CONDITIONS APPLY. Cisco IMC (CVE-2026-20200) is now eligible for the Root Prize Draw, in which any authenticated remote attacker — even one with low privileges, congratulations to them — may submit crafted inputs to the web-based management interface for a chance to execute arbitrary commands as root on your rack server. (1/3)
##updated 2026-08-05T15:17:04.690000
1 posts
CVE-2026-66747: a Zbtlink router backdoor named ENDLESSDOORS gives unauthenticated remote code execution as root. No fix exists. CVSS 9.8.
#Zbtlink #RouterBackdoor #CVE #IoT #CyberSecurity
https://securityonline.info/zbtlink-router-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-05T05:17:01.967000
1 posts
Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console
Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.
**If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-credential-theft-and-rce-flaws-in-service-provider-console-y-k-8-e-6/gD2P6Ple2L
updated 2026-08-04T21:30:25
1 posts
4 repos
https://github.com/rmhowe425/PoC-CVE-2026-9198
https://github.com/0xdak/CVE-2026-9198_exploit
🏆 New Achievement! Patch Notes From Hell!
Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)
##updated 2026-08-04T18:31:36
1 posts
1 repos
Veeam ONE Patches Critical Remote Code Execution and SQL Injection Flaws
Veeam ONE version 13 contains six vulnerabilities, including a CVSS 10.0 critical remote code execution flaw and a high-severity SQL injection bug. These vulnerabilities allow unauthenticated attackers to take over agent hosts, read arbitrary files, and extract sensitive database information.
**If you run Veeam ONE version 13, update it to build 13.1.0.7034. One of these flaws (CVE-2026-64633) lets an attacker take over the system remotely without any login or clicks from you. While you're at it, make sure Veeam ONE is only reachable from your trusted admin network, not from the internet or the general user network.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-one-patches-critical-remote-code-execution-and-sql-injection-flaws-q-a-8-7-1/gD2P6Ple2L
updated 2026-08-04T18:31:31
1 posts
Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console
Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.
**If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-credential-theft-and-rce-flaws-in-service-provider-console-y-k-8-e-6/gD2P6Ple2L
updated 2026-08-04T15:33:20
1 posts
2 repos
https://github.com/HORKimhab/CVE-2026-18577
https://github.com/CreamyG31337/ncentral-compromise-ioc-triage
⚠️ N-central auth bypass exploited in attacks
CVE-2026-18577 enables admin takeover; N-able issued an urgent hotfix.
🔗 read more: www.bleepingcomputer...
#ransomNews #cybersecurity
N-able warns of N-central auth...
updated 2026-08-03T15:32:49
1 posts
📢 Check Point : faille critique d'authentification CVE-2026-18574 sur Security Management Server
📰 Source : Cyber Security News — Date : 4 août 2026 Check Point a publié des mises à jour de sécurité pour corriger une vulnérabilité de haute sévérité identifiée sous CVE-2026-18574, affectant les environnements Security Management Server et…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-08-check-point-faille-critique-d-authentification-cve-2026-18574-sur-security-management-server/
🌐 source : https://cybersecuritynews.com/check-point-authentication-bypass-flaw/
🟡 vérification factuelle moyenne
#CheckPoint #AuthenticationBypass #Cyberveille
updated 2026-07-30T18:31:47
1 posts
This post is from yesterday.
Note: Arctic Wolf will sell your data without consent. You need to scroll to the bottom and opt out of being sold to unscrupulous third-parties.
Arctic Wolf: SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299 https://arcticwolf.com/resources/blog/cve-2026-28323-and-cve-2026-28299/ #infosec #vulnerability #privacy
##updated 2026-07-30T12:32:18
4 posts
1 repos
🚨 Tails has released an emergency security update: Tails 7.10.1, patching critical flaws that could enable privilege escalation and potentially deanonymize users. It fixes CVE-2026-64560 (Linux kernel) and multiple Expat XML library issues. 🔐➡️ https://cyberinsider.com/tails-emergency-update-fixes-flaws-that-could-deanonymize-users/ #Tails #Tor #Cybersecurity #Privacy #SecurityUpdate
##🚨 Tails has released an emergency security update: Tails 7.10.1, patching critical flaws that could enable privilege escalation and potentially deanonymize users. It fixes CVE-2026-64560 (Linux kernel) and multiple Expat XML library issues. 🔐➡️ https://cyberinsider.com/tails-emergency-update-fixes-flaws-that-could-deanonymize-users/ #Tails #Tor #Cybersecurity #Privacy #SecurityUpdate
##Tails 7.10.1 patches CVE-2026-64560, a Linux kernel race condition letting a compromised Tor Browser gain root and deanonymize users via a malicious website.
#Tails #CVE202664560 #LinuxKernel #TorBrowser #Deanonymization #PrivilegeEscalation #AnonymityOS #TailsOS
##Tails 7.10.1 patches CVE-2026-64560 in the Linux kernel and expat library flaws that could let attackers deanonymize users and gain admin privileges.
#Tails #Linux #Privacy #CVE202664560 #Cybersecurity #AnonymousOS
##updated 2026-07-30T06:33:30
1 posts
For one, Rust is vibecoded now. There are Claude commits in it and probably more than GitHub is willing to tell me.
Two, users try to rewrite everything to Rust when there is no point. When Rust was no longer experimental in Linux it caused CVEs (CVE-2025-68260).
Three, Rust projects can take 10 seconds to compile or 20 minutes.
Four, it uses LLVM and that's bloated and vibecoded now.
Five, I generally just don't like it either. I prefer C and some other similar langs much more.
updated 2026-07-27T21:16:51.020000
1 posts
CVE-2026-39868: Public PoC Discloses a macOS and iOS Kernel Memory Corruption Flaw
##updated 2026-07-27T18:31:25
1 posts
Hackers bypass patch using new FortiOS vulnerability
An actively exploited #vulnerability in #FortiOS allows for the bypass of a previous protection mechanism against manipulated symbolic links. Affected systems should be updated and checked for prior compromise.
Sensitive information on potentially compromised #FortiGate systems running FortiOS with SSL-VPN enabled may be at risk.
##updated 2026-07-27T06:31:36
1 posts
🐧 SIGINT // Ubuntu Watch — 2026-08-09
CVE-2026-64221 hits multiple Ubuntu kernel variants with DoS risk. Check USN-8620-3/4 for your exact flavor and kernel version before assuming you are covered by a generic patch pass.
🔗 https://www.hkcert.org/security-bulletin/ubuntu-linux-kernel-multiple-vulnerabilities_20260803
##updated 2026-07-24T21:32:15
1 posts
@da_667 oh the number of times my sleep deprived brain tried to understand how the text in front of me relates to the CVE I thought to analyse *UNTIL I FIGURED THE SEARCH RESULTS WERE BORKED AND CVE-2026-60667 IS IN FACT NOT THE CVE I WAS ORIGINALLY LOOKING FOR* gave me serious PTSD.
Relieved to see I'm not the dumbo after all.
##updated 2026-07-23T12:32:58
2 posts
CVE-2026-65535: Ranch Overflow
##CVE-2026-65535: Ranch Overflow
##updated 2026-07-14T21:32:22
1 posts
6 repos
https://github.com/remmons-r7/rapid7-CVE-2026-15409
https://github.com/0xBlackash/CVE-2026-15409
https://github.com/Ch4120N/CVE-2026-15409
https://github.com/HORKimhab/CVE-2026-15409
https://github.com/tc4dy/CVE-2026-15409-15410-Framework
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
Podcast: Play in new window | Download | Embed
Subscribe: RSS
https://www.youtube.com/watch?v=LL0ez4JXGWE
https://www.helpnetsecurity.com/2026/07/21/sonicwall-sma-zero-days-exploited-cve-2026-15409-cve-2026-15410/
https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html
https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
https://openai.com/index/hugging-face-model-evaluation-security-incident/
https://www.darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause
https://www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/
updated 2026-07-14T21:32:21
1 posts
3 repos
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
Podcast: Play in new window | Download | Embed
Subscribe: RSS
https://www.youtube.com/watch?v=LL0ez4JXGWE
https://www.helpnetsecurity.com/2026/07/21/sonicwall-sma-zero-days-exploited-cve-2026-15409-cve-2026-15410/
https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html
https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
https://openai.com/index/hugging-face-model-evaluation-security-incident/
https://www.darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause
https://www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/
updated 2026-07-14T18:31:58
2 posts
@adamshostack @gsuberland the main vulnerability is CVE-2026-34348. As I understood, a signature of sign-in is stored in event log, which can be replayed and used for impersonation, as there is no validation of reused signatures in Entra ID.
##@adamshostack @gsuberland the main vulnerability is CVE-2026-34348. As I understood, a signature of sign-in is stored in event log, which can be replayed and used for impersonation, as there is no validation of reused signatures in Entra ID.
##updated 2026-07-10T15:45:17.463000
1 posts
CISA has added one vulnerability to the KEV catalogue:
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-8037 #CISA
Cisco:
NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 #Cisco
Palo Alto:
CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent https://security.paloaltonetworks.com/CVE-2026-0288
Microsoft:
Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: https://msrc.microsoft.com/update-guide/ #Microsoft
Google:
New: Chrome Dev for Android Update https://chromereleases.googleblog.com/ #Google #Chrome
Broadcom:
One new advisory for a high-severity vulnerability that was first published on July 23 https://support.broadcom.com/web/ecx/security-advisory
Posted yesterday:
Apple security updates https://support.apple.com/en-us/100100 #Apple
AMD: Safe RET Interrupt Vulnerability https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7061.html #AMD
Dell:
CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities #Dell #infosec #vulnerability #Java #SQL
##updated 2026-06-22T22:57:49
4 posts
CVE-2026-48170 (CRITICAL, CVSS 9.1): Prototype pollution in scim-patch <0.9.1 lets attackers alter Object.prototype globally in Node.js. Upgrade to 0.9.1+ or freeze prototypes for mitigation. https://radar.offseq.com/threat/cve-2026-48170-cwe-1321-improperly-controlled-modification-of-object-prototype-attributes-prototype-1a8d5ec623a7b014 #OffSeq #CVE202648170 #NodeJS #InfoSec
##🔴 CVE-2026-48170 - Critical (9.1)
`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch,
`Object.prototype.somePr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48170/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-48170 (CRITICAL, CVSS 9.1): Prototype pollution in scim-patch <0.9.1 lets attackers alter Object.prototype globally in Node.js. Upgrade to 0.9.1+ or freeze prototypes for mitigation. https://radar.offseq.com/threat/cve-2026-48170-cwe-1321-improperly-controlled-modification-of-object-prototype-attributes-prototype-1a8d5ec623a7b014 #OffSeq #CVE202648170 #NodeJS #InfoSec
##🔴 CVE-2026-48170 - Critical (9.1)
`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch,
`Object.prototype.somePr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48170/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-17T10:46:59.450000
2 posts
1 repos
Vuln critica (CVSS 10.0) a Paperclip, orquestracio d'agents d'IA
CVE-2026-41679: RCE via bypass d'autenticacio. Registrar-se sense verificar email, aconseguir token d'API persistent, i importar un .paperclip.yaml malicios que executa comandes al servidor
Tambe afecta el mode local_trusted: DNS rebinding des del navegador executa comandes al PC del dev.
Actualitza ja.
https://blog.elhacker.net/2026/08/vulnerabilidades-criticas-de-paperclip.html
##CVE-2026-41679 | Paperclip AI platform CRITICAL vuln: auth bypass let attackers register, obtain API tokens, & run code as server. DNS rebinding risk in dev mode. Patch now. https://radar.offseq.com/threat/critical-paperclip-flaw-allowed-admin-access-code-execution-09ee35c54d49b29b #OffSeq #CVE #Paperclip #vuln
##updated 2026-06-17T09:44:33.060000
1 posts
⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…
🤖 AI generated summary
##updated 2026-06-17T09:12:02.147000
1 posts
77 repos
https://github.com/Rajneeshkarya/CVE-2025-32463
https://github.com/dr4xp/sudo-chroot
https://github.com/FreeDurok/CVE-2025-32463-PoC
https://github.com/abrewer251/CVE-2025-32463_Sudo_PoC
https://github.com/K3ysTr0K3R/CVE-2025-32463-EXPLOIT
https://github.com/Fomovet/cve-2025-32463
https://github.com/cybertechajju/CVE-2025-32463
https://github.com/IC3-512/linux-root-kit
https://github.com/AC8999/CVE-2025-32463
https://github.com/D3ltaFormation/CVE-2025-32463-Sudo-Chroot-Escape
https://github.com/hackingyseguridad/root
https://github.com/harsh1verma/CVE-Analysis
https://github.com/toohau/CVE-2025-32462-32463-Detection-Script-
https://github.com/4f-kira/CVE-2025-32463
https://github.com/Mr-Alperen/CVE-2025-32463
https://github.com/san8383/CVE-2025-32463
https://github.com/12bijaya/CVE-2025-32463
https://github.com/yonathanpy/CVE-2025-32462-CVE-2025-32463-PoC-Lab
https://github.com/0xAkarii/CVE-2025-32463
https://github.com/dr4x-c0d3r/sudo-chroot
https://github.com/zinzloun/CVE-2025-32463
https://github.com/SysMancer/CVE-2025-32463
https://github.com/zhaduchanhzz/CVE-2025-32463_POC
https://github.com/blackcat4347/CVE-2025-32463_PoC
https://github.com/AdityaBhatt3010/Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462
https://github.com/y4ney/CVE-2025-32463-lab
https://github.com/behnamvanda/CVE-2025-32463
https://github.com/MAAYTHM/CVE-2025-32462_32463-Lab
https://github.com/MGunturG/CVE-2025-32463
https://github.com/neko205-mx/CVE-2025-32463_Exploit
https://github.com/0xdak/CVE-2025-32463_exploit
https://github.com/0x00315732/musical-engine
https://github.com/SpycioKon/CVE-2025-32463
https://github.com/K1tt3h/CVE-2025-32463-POC
https://github.com/onniio/CVE-2025-32463
https://github.com/0x3c4dfa1/CVE-2025-32463
https://github.com/7r00t/cve-2025-32463-lab
https://github.com/krypton-0x00/CVE-2025-32463-Chwoot-POC
https://github.com/khoazero123/CVE-2025-32463
https://github.com/ill-deed/CVE-2025-32463_illdeed
https://github.com/aldoClau98/CVE-2025-32463
https://github.com/robbert1978/CVE-2025-32463_POC
https://github.com/ashardev002/CVE-2025-32463_chwoot
https://github.com/NewComrade12211/CVE-2025-32463
https://github.com/danilo1992-sys/CVE-2025-32463
https://github.com/shazed-x/CVE-2025-32463
https://github.com/MohamedKarrab/CVE-2025-32463
https://github.com/Maalfer/Sudo-CVE-2021-3156
https://github.com/Yuy0ung/CVE-2025-32463_chwoot
https://github.com/muhammedkayag/CVE-2025-32463
https://github.com/v3rycl0p3r/CVE-2025-32463
https://github.com/Ghstxz/CVE-2025-32463
https://github.com/ChetanKomal/sudo_exploit
https://github.com/morgenm/sudo-chroot-CVE-2025-32463
https://github.com/pevinkumar10/CVE-2025-32463
https://github.com/pr0v3rbs/CVE-2025-32463_chwoot
https://github.com/kh4sh3i/CVE-2025-32463
https://github.com/daryllundy/CVE-2025-32463
https://github.com/KaiHT-Ladiant/CVE-2025-32463
https://github.com/CIA911/sudo_patch_CVE-2025-32463
https://github.com/robbin0919/CVE-2025-32463
https://github.com/0p5cur/CVE-2025-32463-POC
https://github.com/gmh5225/Blackash-CVE-2025-32463
https://github.com/SpongeBob-369/cve-2025-32463
https://github.com/1xPwn/CVE-2025-32463
https://github.com/lakshan-sameera/CVE-2025-32462-and-CVE-2025-32463---Critical-Sudo-Vulnerabilities
https://github.com/painoob/CVE-2025-32463
https://github.com/lowercasenumbers/CVE-2025-32463_sudo_chroot
https://github.com/secvulnhub/CVE-2025-32463-EXPLOIT
https://github.com/r3dBust3r/CVE-2025-32463
https://github.com/ankitpandey383/CVE-2025-32463-Sudo-Privilege-Escalation
https://github.com/ricardomaia/CVE-2025-32463
https://github.com/0xBlackash/CVE-2025-32463
https://github.com/vpr-labs/CVE-2025-32463
https://github.com/mirchr/CVE-2025-32463-sudo-chwoot
updated 2026-06-17T07:13:24.233000
1 posts
14 repos
https://github.com/sandimfz/CVE-2024-23692
https://github.com/jakabakos/CVE-2024-23692-RCE-in-Rejetto-HFS
https://github.com/Tupler/CVE-2024-23692-exp
https://github.com/Mr-r00t11/CVE-2024-23692
https://github.com/vanboomqi/CVE-2024-23692
https://github.com/WanLiChangChengWanLiChang/CVE-2024-23692-RCE
https://github.com/pradeepboo/Rejetto-HFS-2.x-RCE-CVE-2024-23692
https://github.com/verylazytech/CVE-2024-23692
https://github.com/NanoWraith/CVE-2024-23692
https://github.com/0x20c/CVE-2024-23692-EXP
https://github.com/wgetnz/hfs2
https://github.com/NingXin2002/HFS2.3_poc
CVE-2024-23692 - Changed to Known Ransomware Status
Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine VulnerabilityVendor: RejettoProduct: HTTP File ServerRejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted https://nvd.nist.gov/vuln/detail/CVE-2024-23692
##updated 2026-06-09T18:40:42
2 posts
🟠 CVE-2026-52879 - High (7.5)
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message before the processor-level antiflood layer makes a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52879/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-52879 - High (7.5)
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message before the processor-level antiflood layer makes a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52879/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-05T15:27:42
2 posts
🟠 CVE-2026-47249 - High (7.5)
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a compressed RequestDataType_HashArrayType direct r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47249/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47249 - High (7.5)
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a compressed RequestDataType_HashArrayType direct r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47249/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-02T21:30:50
1 posts
This post is from yesterday.
Note: Arctic Wolf will sell your data without consent. You need to scroll to the bottom and opt out of being sold to unscrupulous third-parties.
Arctic Wolf: SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299 https://arcticwolf.com/resources/blog/cve-2026-28323-and-cve-2026-28299/ #infosec #vulnerability #privacy
##updated 2026-04-15T21:33:41
1 posts
🏆 New Achievement! Patch Notes From Hell!
Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)
##updated 2026-03-04T18:32:03
1 posts
1 repos
CRITICAL vulnerabilities patched in Cisco SD-WAN, IOS XE, FMC, and IMC. FMC flaw (CVE-2026-20079, CVSS 10.0) allows remote root access; IMC PoC public. No active exploitation. Patch now: https://radar.offseq.com/threat/cisco-patches-critical-sd-wan-ios-xe-fmc-vulnerabilities-d0d83f67659b4d15 #OffSeq #Cisco #Vulnerability #PatchTuesday
##updated 2025-12-02T03:31:52
1 posts
⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…
🤖 AI generated summary
##updated 2025-11-05T06:30:37
1 posts
⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…
🤖 AI generated summary
##updated 2025-10-22T00:34:26
1 posts
31 repos
https://github.com/kitsuneshade/WinRAR-Exploit-Tool---Rust-Edition
https://github.com/travisbgreen/cve-2025-8088
https://github.com/pexlexity/WinRAR-CVE-2025-8088-Path-Traversal-PoC
https://github.com/Shinkirou789/Cve-2025-8088-WinRar-vulnerability
https://github.com/0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC
https://github.com/hbesljx/CVE-2025-8088-EXP
https://github.com/nhattanhh/CVE-2025-8088
https://github.com/walidpyh/CVE-2025-8088
https://github.com/nuky-alt/CVE-2025-8088
https://github.com/shaheeryasirofficial/CVE-2025-8088
https://github.com/IsmaelCosma/CVE-2025-8088
https://github.com/pentestfunctions/best-CVE-2025-8088
https://github.com/Lewis-Ricardo/Amaranth-Project
https://github.com/aldisakti2/CVE-2025-8088-BUILDER-Winrar-Tool
https://github.com/jordan922/CVE-2025-8088
https://github.com/knight0x07/WinRAR-CVE-2025-8088-PoC-RAR
https://github.com/onlytoxi/CVE-2025-8088-Winrar-Tool
https://github.com/ghostn4444/CVE-2025-8088
https://github.com/lennertdefauw/CVE-2025-8088
https://github.com/papcaii2004/CVE-2025-8088-WinRAR-builder
https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool
https://github.com/undefined-name12/CVE-2025-8088-Winrar
https://github.com/starfallreverie/winrar-exploit
https://github.com/AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal
https://github.com/pentestfunctions/CVE-2025-8088-Multi-Document
https://github.com/xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit
https://github.com/sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-
https://github.com/Syrins/CVE-2025-8088-Winrar-Tool-Gui
https://github.com/pescada-dev/-CVE-2025-8088
CVE-2025-8088 - Changed to Known Ransomware Status
RARLAB WinRAR Path Traversal VulnerabilityVendor: RARLABProduct: WinRARRARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 06, 2026 at 14:08:17 UTCDate https://nvd.nist.gov/vuln/detail/CVE-2025-8088
##updated 2025-10-22T00:33:19
1 posts
1 repos
https://github.com/Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment
CVE-2025-42999 - Changed to Known Ransomware Status
SAP NetWeaver Deserialization VulnerabilityVendor: SAPProduct: NetWeaverSAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.Status changed from Unknown to Known for ransomware campaign https://nvd.nist.gov/vuln/detail/CVE-2025-42999
##updated 2023-11-18T05:04:48
2 posts
3 repos
https://github.com/azpema/CVE-2021-26708
⚪️ Four Bytes of Power: How I Found the CVE-2021-26708 Vulnerability in the Linux Kernel
🗨️ In January 2021, I discovered and fixed five vulnerabilities in the Linux kernel’s virtual socket (vsock) implementation, collectively tracked as CVE-2021-26708. In this article, I will show how they can be used to compromise the entire operating system while bypassing the platform’s security mec…
##⚪️ Four Bytes of Power: How I Found the CVE-2021-26708 Vulnerability in the Linux Kernel
🗨️ In January 2021, I discovered and fixed five vulnerabilities in the Linux kernel’s virtual socket (vsock) implementation, collectively tracked as CVE-2021-26708. In this article, I will show how they can be used to compromise the entire operating system while bypassing the platform’s security mec…
##updated 2023-01-27T05:08:18
2 posts
The paper has a table listing the patches they're inaccurately claiming are missing in GrapheneOS. They claim the ones marked as green were manually verified to be missing. The first patch listed in the table is CVE-2015-6609, which we reported to Google in 2015.
https://source.android.com/docs/security/bulletin/2015-11-01#acknowledgements
##The paper has a table listing the patches they're inaccurately claiming are missing in GrapheneOS. They claim the ones marked as green were manually verified to be missing. The first patch listed in the table is CVE-2015-6609, which we reported to Google in 2015.
https://source.android.com/docs/security/bulletin/2015-11-01#acknowledgements
##CVE-2026-61808 - Critical unauthenticated access in LightRAG API server. Full data breach, doc manipulation, LLM abuse. CVSS 9.8. Upgrade to 1.5.5rc1 immediately. #CVE #LightRAG #infosec
##🔴 CVE-2026-61808 - Critical (9.8)
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61808/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-61808 - Critical (9.8)
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61808/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##2 posts
8 repos
https://github.com/shinthink/CVE-2026-60004
https://github.com/gagaltotal/CVE-2026-60004-poc-gitea
https://github.com/0xBlackash/CVE-2026-60004
https://github.com/imbas007/CVE-2026-60004-POC
https://github.com/HackSpeak/CVE-2026-60004
https://github.com/HORKimhab/CVE-2026-60004
Welp. My Forgejo instance got popped by CVE-2026-60004. Hooray for RCE 🙃
My two screw-ups were
1. I pinned it to v13 "for stability" forever ago, then forgot about it.
2. I accidentally left sign-ups enabled.
Grabbed the seemingly obfuscated payload script from the attacker's server. Looks like it hits a different IP and grabs one of three different binaries depending on the victim's CPU architecture. You best believe I'm grabbing those too
Will probably write a blog post on what I find, but I'll at least post updates here, too
##Welp. My Forgejo instance got popped by CVE-2026-60004. Hooray for RCE 🙃
My two screw-ups were
1. I pinned it to v13 "for stability" forever ago, then forgot about it.
2. I accidentally left sign-ups enabled.
Grabbed the seemingly obfuscated payload script from the attacker's server. Looks like it hits a different IP and grabs one of three different binaries depending on the victim's CPU architecture. You best believe I'm grabbing those too
Will probably write a blog post on what I find, but I'll at least post updates here, too
##10 posts
18 repos
https://github.com/renzi25031469/CVE-2026-64638-WordPress-Core-XSS2Shell
https://github.com/mohwahyudi/poc-CVE-2026-64638-
https://github.com/686f6c61/POC-WP-XSS2Shell-CVE-2026-64638
https://github.com/0xBlackash/CVE-2026-64638
https://github.com/yogaGymn/XSS2Shell-CVE-2026-64638
https://github.com/imbas007/CVE-2026-64638-POC
https://github.com/wordsec/XSS2Shell
https://github.com/4minx/CVE-2026-64638
https://github.com/Boreas37/CVE-2026-64638-PoC
https://github.com/Linuxhackingid-official/XSS2Shell-CVE-2026-64638
https://github.com/tc4dy/CVE-2026-64638-PoC-Exploit
https://github.com/5yu4n/CVE-2026-64638
https://github.com/jendmaoul/XSS2Shell-CVE-2026-64638
https://github.com/MR-LeonardoGomes/XSS2Shell-CVE-2026-64638
https://github.com/ZSecur1ty/XSS2Shell-CVE-2026-64638
https://github.com/Dungsocool/CVE-2026-64638
🚨 XSS2shell (CVE-2026-64638) has been identified as a notable vulnerability.
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.
This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
Discovered and responsibly disclosed by the team at pwn.ai.
ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/267dffcb-04e8-4ba6-9c9e-2305d1d11b59/xss2shell-vulnerability
#infosec #xss2shell #wordpress #xss #rce
#nttdata #zen #secdb
WordPress RCE. Every version ever released (except the latest, 7.0.3). 500+ million sites. 43% of the Internet-facing sites. Hacker's paradise.
"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)":
##「WordPressの事前認証における新たなXSS脆弱性によりPHPコードの実行につながる可能性あり - 早急に修正を! 」: #TheHackerNews
「WordPressは、ログイン画面に存在する、認証前のリフレクテッドクロスサイトスクリプティング(XSS)の脆弱性を修正しました。この脆弱性は、コンテンツ管理システムのすべてのバージョンに影響を与えます。pwn.aiは、ログインした管理者が攻撃者によって制御されたページを操作する際に、この脆弱性がサーバー上でPHPコードの実行に連鎖的に繋がる仕組みを実証しました。
CVE-2026-64638 (CVSSスコア:8.9)として追跡されている この深刻な脆弱性は、攻撃者に特別な権限を必要としません。 」
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
##"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
https://pwn.ai/blog/xss2shell
🚨 XSS2shell (CVE-2026-64638) has been identified as a notable vulnerability.
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.
This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
Discovered and responsibly disclosed by the team at pwn.ai.
ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/267dffcb-04e8-4ba6-9c9e-2305d1d11b59/xss2shell-vulnerability
#infosec #xss2shell #wordpress #xss #rce
#nttdata #zen #secdb
WordPress RCE. Every version ever released (except the latest, 7.0.3). 500+ million sites. 43% of the Internet-facing sites. Hacker's paradise.
"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)":
##「WordPressの事前認証における新たなXSS脆弱性によりPHPコードの実行につながる可能性あり - 早急に修正を! 」: #TheHackerNews
「WordPressは、ログイン画面に存在する、認証前のリフレクテッドクロスサイトスクリプティング(XSS)の脆弱性を修正しました。この脆弱性は、コンテンツ管理システムのすべてのバージョンに影響を与えます。pwn.aiは、ログインした管理者が攻撃者によって制御されたページを操作する際に、この脆弱性がサーバー上でPHPコードの実行に連鎖的に繋がる仕組みを実証しました。
CVE-2026-64638 (CVSSスコア:8.9)として追跡されている この深刻な脆弱性は、攻撃者に特別な権限を必要としません。 」
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
##"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
https://pwn.ai/blog/xss2shell
🚨 WordPress patches XSS2Shell flaw that could lead to server code execution
CVE-2026-64638 is a CVSS 8.9 pre-authentication XSS vulnerability in the WordPress login screen.
The XSS itself requires no account. Researchers at pwn.ai demonstrated how it can be chained against a logged-in administrator to reach PHP code execution after social engineering the admin into interacting with an attacker-controlled page.
A successful chain could potentially allow attackers to:
• Create API credentials
• Gain authenticated REST access
• Upload malicious plugin files
• Execute PHP on the server
• Access WordPress secrets and database credentials
WordPress 7.0.3 fixes the flaw, with patches backported through the 4.7 branch.
NHS England says exploitation is likely following the release of technical details and a PoC.
WordPress has not reported confirmed exploitation in the wild as of August 7.
Update immediately.
##WordPress 7.0.3 fixes CVE-2026-64638, a pre-auth XSS on the login screen that can escalate to remote code execution. CVSS 8.9. Update now.
##Downfall
Downfall(CVE-2022-40982)은 Intel 6세대 Skylake부터 11세대 Tiger Lake 계열 CPU의 Gather 명령어가 추측 실행 중 벡터 레지스터 파일 데이터를 누출하는 취약점이다. 공격자는 동일 물리 코어를 공유하는 다른 프로세스·VM·커널·SGX 영역에서 AES 키, 비밀번호, 기타 민감 데이터를 탈취할 수 있으며, 클라우드 멀티테넌트 환경과 AI 학습·추론 워크로드의 격리 경계에도 영향을 준다. 핵심 기법은 Gather Data Sampling(GDS) 및 Gather Value Injection(GVI)이며, OpenSSL 키 탈취 PoC가 제시됐다. Intel 마이크로코드 완화책이 제공되지만 Gather가 병목 경로인 워크로드에서는 최대 50% 성능 저하 가능성이 있어, 운영 환경에서...
##CVE-2026-66060 – High severity flaw in Home Assistant. Companion app executes NFC/QR tag automations without caller validation, letting malicious apps trigger actions. CVSS 7.1. Update to 2026.5.3+ immediately. #CVE #HomeAssistant #infosec
##🟠 CVE-2026-19082 - High (7.5)
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags.
copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19082/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19082 - High (7.5)
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags.
copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19082/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48097 - High (7.8)
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely on executa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48097/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48097 - High (7.8)
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely on executa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48097/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65819 - High (7.5)
gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded through De...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65819/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65819 - High (7.5)
gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded through De...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65819/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48026 - High (8.7)
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects withou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48026/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48026 - High (8.7)
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects withou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48026/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-46409 - Critical (9.6)
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:` (commonly 19141) without server-side Origin validat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46409/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-46409 - Critical (9.6)
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:` (commonly 19141) without server-side Origin validat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46409/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48120 - High (8.6)
Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Ka...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48120/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48120 - High (8.6)
Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Ka...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48120/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62295 - High (7.5)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or obje...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62295/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62295 - High (7.5)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or obje...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62295/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🚨 [CISA-2026:0807] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-8037 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8037)
- Name: Progress LoadMaster Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Progress
- Product: LoadMaster
- Notes: https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8037
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260807 #cisa20260807 #cve_2026_8037 #cve20268037
##three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.
CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.
CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.
CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.
patched in 4.14.6.
https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2
https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc
https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc
#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity
##three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.
CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.
CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.
CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.
patched in 4.14.6.
https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2
https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc
https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc
#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity
##three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.
CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.
CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.
CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.
patched in 4.14.6.
https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2
https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc
https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc
#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity
##🏆 New Achievement! Patch Notes From Hell!
Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)
##Vulnerability in ngx-extended-pdf-viewer (HIGH): Bundled pdf.js exposes XFA (enabled by default), risking JS execution via malicious PDFs (CVE-2026-16633). Update to 29.0.0-rc.3 or disable XFA for mitigation. https://radar.offseq.com/threat/ngx-extended-pdf-viewer-bundles-a-version-of-pdfjs-vulnerable-to-cve-2026-16633-3a7320cdbeb0cda3 #OffSeq #Vulnerability #PDF #Infosec
##CVE-2026-48088 | CRITICAL in open-reception appointment-booking-software <1.0.4: Missing authorization on crypto key API lets attackers decrypt appointments & disrupt flows. Patch to 1.0.4 now. https://radar.offseq.com/threat/cve-2026-48088-cwe-862-missing-authorization-in-open-reception-appointment-booking-software-d1c4584f6afe2ecc
#OffSeq #CVE202648088 #Vuln #AppSec
🟠 CVE-2026-7867 - High (7.8)
A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7867/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18427 - High (7.5)
@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or back...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18427/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🏆 New Achievement! Open Source, Open Season!
The court finds Gitea guilty of harboring CVE-2026-59774. The charges: permitting unauthenticated attackers to submit specially crafted Org-mode markup to a public repository and read arbitrary files from the server — with sentencing escalating, in certain configurations, to full remote code execution as the Gitea operating system user. No login required. No accomplices named. (1/2)
##🟠 CVE-2026-15991 - High (8.8)
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15991/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##