## Updated at UTC 2026-09-20T05:20:56.049859

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-93958 9.1 0.00% 2 0 2026-09-20T03:30:31 A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affec
CVE-2026-94084 9.4 0.00% 4 0 2026-09-20T03:30:29 Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transacti
CVE-2026-94083 9.4 0.00% 4 0 2026-09-20T02:16:53.520000 Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free,
CVE-2026-93993 8.8 0.00% 2 0 2026-09-20T00:30:32 Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the
CVE-2026-93992 8.1 0.00% 2 0 2026-09-20T00:30:32 Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive e
CVE-2026-93990 7.5 0.00% 2 0 2026-09-20T00:30:31 Expat through 2.8.4 fails to validate low surrogates following high surrogates i
CVE-2026-94056 7.5 0.00% 2 0 2026-09-19T23:17:11.113000 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled pro
CVE-2026-93991 7.7 0.00% 2 0 2026-09-19T23:17:10.360000 Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vuln
CVE-2026-86814 8.1 0.14% 4 0 2026-09-19T15:32:25 The UsersWP WordPress plugin before 1.5.10 does not verify that a social login
CVE-2026-88926 8.6 0.18% 2 0 2026-09-19T15:31:25 The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4
CVE-2026-85680 8.8 0.17% 2 0 2026-09-19T15:31:24 The Ultimate Member WordPress plugin before 2.13.1 does not escape a value deri
CVE-2026-84750 6.5 0.20% 2 0 2026-09-19T15:31:24 The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not vali
CVE-2026-86591 9.8 0.18% 4 0 2026-09-19T15:31:23 The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation
CVE-2026-93761 7.5 0.27% 2 0 2026-09-19T15:17:08.503000 An inefficient regular expression complexity issue in the in-memory query evalua
CVE-2026-84398 7.5 0.24% 2 0 2026-09-19T15:17:05.863000 CM2507 IP cameras accept an empty password for a privileged account exposed thro
CVE-2026-84083 7.8 0.11% 2 0 2026-09-19T15:17:05.750000 IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation vi
CVE-2026-84081 8.1 0.20% 3 0 2026-09-19T15:17:05.537000 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-84078 9.9 0.28% 3 0 2026-09-19T15:17:05.430000 IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vuln
CVE-2026-84076 7.6 0.31% 2 0 2026-09-19T15:17:05.317000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84075 9.9 0.35% 3 0 2026-09-19T15:17:05.217000 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-84070 8.9 0.32% 3 0 2026-09-19T15:17:04.867000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-82967 9.8 0.43% 3 0 2026-09-19T15:17:04.430000 IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that
CVE-2026-80441 9.8 0.38% 2 0 2026-09-19T15:17:02.430000 IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-ord
CVE-2026-92807 8.8 0.25% 4 0 2026-09-19T14:17:05.850000 The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitra
CVE-2026-92404 7.5 0.14% 2 0 2026-09-19T14:17:04.240000 The MgoSync WordPress plugin before 2.1.7 does not have authorization controls
CVE-2026-89274 9.1 0.38% 4 1 2026-09-19T14:17:03.127000 The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Ex
CVE-2026-88824 8.8 0.17% 2 0 2026-09-19T14:17:02.290000 The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on
CVE-2026-85658 8.1 0.36% 2 0 2026-09-19T14:17:00.627000 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
CVE-2026-85574 8.0 0.13% 2 0 2026-09-19T14:17:00.477000 The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any au
CVE-2026-84241 8.1 0.30% 3 0 2026-09-19T14:17:00.260000 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-84239 7.6 0.41% 3 0 2026-09-19T14:17:00.143000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84105 7.7 0.35% 2 0 2026-09-19T14:16:59.917000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84089 7.8 0.11% 3 0 2026-09-19T14:16:59.813000 IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated
CVE-2026-84085 8.1 0.32% 2 0 2026-09-19T14:16:59.587000 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-93985 9.9 0.00% 4 0 2026-09-19T12:16:41.873000 OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerabi
CVE-2026-93742 9.9 1.88% 5 0 2026-09-19T09:32:25 A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected b
CVE-2026-4327 8.8 0.70% 2 0 2026-09-19T09:32:22 The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution i
CVE-2026-1255 7.5 0.29% 2 0 2026-09-19T09:32:16 The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Expos
CVE-2026-93741 10.0 0.64% 5 0 2026-09-19T06:16:30.557000 A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affec
CVE-2026-93374 9.6 0.35% 1 0 2026-09-19T04:18:02.537000 Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 all
CVE-2026-53266 8.8 0.28% 4 0 2026-09-19T04:17:53.580000 In the Linux kernel, the following vulnerability has been resolved: netfilter:
CVE-2025-39682 9.8 1.20% 3 1 2026-09-19T04:17:35.263000 In the Linux kernel, the following vulnerability has been resolved: tls: fix ha
CVE-2026-92229 9.1 0.40% 4 1 2026-09-19T03:32:15 The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plug
CVE-2026-87909 7.5 0.53% 2 0 2026-09-19T03:32:11 The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execut
CVE-2026-84434 9.8 0.70% 2 1 2026-09-19T03:32:11 The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in
CVE-2026-93739 9.9 0.49% 2 0 2026-09-19T00:32:51 A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impac
CVE-2026-93923 8.8 0.41% 2 0 2026-09-19T00:32:50 SiYuan through 3.8.4 fails to escape heading style attributes when rendering out
CVE-2026-93922 8.8 0.54% 2 0 2026-09-19T00:16:57.913000 SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker
CVE-2026-93740 10.0 0.61% 2 0 2026-09-18T22:17:10.890000 A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected i
CVE-2026-75885 9.3 0.41% 4 0 2026-09-18T22:17:10.313000 A flaw was found in the OpenShift console. Unauthenticated access to the `/api/d
CVE-2026-88097 8.1 0.22% 2 0 2026-09-18T21:32:43 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke
CVE-2026-93031 8.8 0.58% 2 0 2026-09-18T21:32:41 The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-B
CVE-2026-84077 8.1 0.19% 2 0 2026-09-18T21:32:40 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-84082 9.8 0.40% 2 0 2026-09-18T21:32:39 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-84074 8.9 0.32% 2 0 2026-09-18T21:32:38 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84064 9.9 0.37% 2 0 2026-09-18T21:32:38 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84108 8.1 0.40% 2 0 2026-09-18T21:32:38 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-82887 8.8 0.41% 2 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-82896 7.6 0.36% 2 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84073 9.1 0.26% 2 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84034 8.8 0.25% 2 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulne
CVE-2026-82885 8.8 0.28% 2 0 2026-09-18T21:32:36 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-82832 9.6 0.38% 2 0 2026-09-18T21:32:36 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-82893 7.8 0.11% 2 0 2026-09-18T21:32:36 IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated
CVE-2026-82340 9.8 0.51% 2 0 2026-09-18T21:32:35 IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure dese
CVE-2026-81933 8.8 0.32% 2 0 2026-09-18T21:32:35 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability
CVE-2026-82892 8.1 0.39% 2 0 2026-09-18T21:32:35 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-93868 8.1 0.61% 2 0 2026-09-18T21:18:49.023000 Cotonti through 1.0.0 derives password recovery validation tokens from md5(micro
CVE-2026-93738 9.9 0.50% 2 0 2026-09-18T21:18:48.660000 A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects th
CVE-2026-93572 7.5 0.34% 2 0 2026-09-18T21:18:48.020000 A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker
CVE-2026-84106 8.9 0.32% 2 0 2026-09-18T21:18:44.520000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84084 8.8 0.18% 2 0 2026-09-18T21:18:44.413000 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-84031 9.0 0.33% 3 0 2026-09-18T21:18:44.080000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-68928 8.6 0.13% 2 0 2026-09-18T21:17:14.377000 Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7,
CVE-2026-63447 7.5 0.36% 2 0 2026-09-18T21:17:03.913000 Suricata is a network Intrusion Detection System, Intrusion Prevention System an
CVE-2026-63446 7.5 0.39% 2 0 2026-09-18T21:17:03.763000 Suricata is a network Intrusion Detection System, Intrusion Prevention System an
CVE-2026-57227 7.5 0.40% 2 0 2026-09-18T21:17:01.217000 Suricata is a network Intrusion Detection System, Intrusion Prevention System an
CVE-2026-93872 7.5 0.44% 2 0 2026-09-18T20:17:35.250000 Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without al
CVE-2026-93839 9.8 0.60% 4 0 2026-09-18T20:17:34.047000 LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /p
CVE-2026-93452 7.5 0.49% 1 0 2026-09-18T20:17:32.397000 snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.
CVE-2026-92948 9.9 0.45% 1 0 2026-09-18T20:17:30.980000 vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist b
CVE-2026-92937 10.0 0.79% 1 0 2026-09-18T20:17:30.707000 vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in
CVE-2026-54767 9.1 0.43% 1 0 2026-09-18T20:17:17.253000 WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/soc
CVE-2026-54734 10.0 0.36% 1 0 2026-09-18T20:17:17.137000 Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certai
CVE-2026-20332 9.9 0.30% 1 0 2026-09-18T20:17:14.310000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20331 9.6 0.23% 2 0 2026-09-18T20:17:14.087000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20330 9.9 0.34% 2 0 2026-09-18T20:17:13.870000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-18911 7.5 1.06% 1 0 2026-09-18T20:17:11.233000 ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent a
CVE-2026-13684 9.8 0.46% 3 0 2026-09-18T20:17:08.373000 An improper encoding or escaping of output vulnerability in SCGI in Synology Dis
CVE-2026-13639 9.8 0.51% 1 0 2026-09-18T20:17:06.860000 An insufficient entropy vulnerability in login logic in Synology DiskStation Man
CVE-2026-28197 8.8 0.37% 2 0 2026-09-18T19:24:36.593000 An authenticated, low-privileged user with access to the NetBackup Flex OS mana
CVE-2026-91149 7.5 0.35% 2 0 2026-09-18T19:06:08.407000 A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this
CVE-2026-93760 8.2 0.28% 2 0 2026-09-18T19:05:01.127000 Mongoid does not restrict which query operators may come from caller-supplied fi
CVE-2026-93762 9.8 0.34% 2 0 2026-09-18T19:05:01.127000 Mongoid contains an unsafe reflection weakness in the query path used for embedd
CVE-2026-93758 8.1 0.21% 2 0 2026-09-18T19:05:01.127000 An insecure direct object reference in the nested attributes handling of the Mon
CVE-2026-86863 9.8 0.36% 1 0 2026-09-18T19:05:01.127000 pgAdmin 4's Webserver authentication source is intended to accept an identity as
CVE-2026-93752 7.5 0.47% 2 0 2026-09-18T18:32:08 CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclar
CVE-2026-93759 8.6 0.24% 2 0 2026-09-18T18:32:04 Mongoid does not neutralize a string-typed query criterion supplied to its query
CVE-2026-93687 7.5 0.41% 2 0 2026-09-18T18:32:02 braces through 3.0.3 contains a stack overflow vulnerability in the recursive AS
CVE-2026-93753 7.5 0.36% 2 0 2026-09-18T18:32:01 deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the merg
CVE-2026-93765 9.1 0.29% 2 0 2026-09-18T18:31:58 Mongoid contains an unsafe reflection weakness in the document persistence layer
CVE-2026-85497 9.8 0.21% 2 0 2026-09-18T18:31:57 CareCam CM2507 IP cameras store the device's root-account password using a fixed
CVE-2026-93688 7.5 0.40% 2 0 2026-09-18T18:31:55 SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV tra
CVE-2026-93606 10.0 0.52% 2 0 2026-09-18T18:18:31.267000 vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `Node
CVE-2026-90999 9.8 0.51% 2 0 2026-09-18T17:49:08.457000 Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows
CVE-2026-92943 8.1 0.27% 1 0 2026-09-18T17:48:19.003000 Improper validation of certificate with host mismatch in the MQTT client TLS con
CVE-2026-61672 7.1 0.20% 1 0 2026-09-18T17:14:32 ## Summary Capsule lets a cluster administrator forbid specific metadata keys t
CVE-2026-84383 9.8 0.64% 2 0 2026-09-18T16:17:11.853000 libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.
CVE-2026-93603 10.0 0.43% 2 0 2026-09-18T15:32:25 vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this`
CVE-2026-93592 7.5 0.38% 2 0 2026-09-18T15:32:24 vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the
CVE-2026-93591 7.6 0.29% 2 0 2026-09-18T15:32:24 SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph
CVE-2026-93597 7.7 0.33% 2 0 2026-09-18T15:32:24 ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in th
CVE-2026-93491 7.5 0.44% 2 0 2026-09-18T15:32:17 A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker
CVE-2025-39964 3.3 0.79% 4 1 2026-09-18T15:31:06 In the Linux kernel, the following vulnerability has been resolved: crypto: af_
CVE-2026-17086 8.8 0.89% 1 0 2026-09-18T15:17:06.153000 The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for
CVE-2026-93605 10.0 0.38% 2 0 2026-09-18T14:19:12.453000 vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where t
CVE-2026-20192 10.0 0.43% 5 0 2026-09-18T14:17:16.023000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-28198 8.8 0.20% 2 0 2026-09-18T12:31:28 An authenticated, low-privileged user with access to the NetBackup Flex OS mana
CVE-2026-85410 8.1 0.31% 2 0 2026-09-18T09:31:24 The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder,
CVE-2026-6205 8.1 0.32% 2 0 2026-09-18T09:31:21 An external control of file name or path vulnerability in Upload API in Synology
CVE-2026-67101 9.3 0.27% 1 0 2026-09-18T09:31:08 HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF
CVE-2026-67100 9.8 0.35% 2 0 2026-09-18T09:31:08 HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tena
CVE-2026-18912 7.7 1.50% 1 0 2026-09-18T06:32:11 ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authent
CVE-2026-93456 8.2 0.15% 1 0 2026-09-18T03:30:28 django-page-cms through 2.0.13 exempts five admin mutation views from CSRF prote
CVE-2026-93450 7.5 0.66% 1 0 2026-09-18T00:31:21 go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability
CVE-2026-85889 10.0 0.49% 5 0 2026-09-18T00:31:16 Missing authentication for critical function in Azure AI Foundry allows an unaut
CVE-2026-13584 0 0.13% 1 0 2026-09-18T00:16:53.720000 Improper Enforcement of Message Integrity During Transmission in a Communication
CVE-2026-92956 10.0 0.40% 1 0 2026-09-17T20:18:59.730000 vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a def
CVE-2026-92951 9.9 0.37% 1 0 2026-09-17T20:18:59.610000 vm2 before 3.11.7 contains an incorrect authorization vulnerability in the exter
CVE-2026-92946 10.0 0.59% 1 0 2026-09-17T20:18:59.483000 vm2 before 3.11.7 contains a remote code execution vulnerability when require.ex
CVE-2026-92940 10.0 0.34% 1 0 2026-09-17T20:18:59.213000 vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAg
CVE-2026-92919 8.1 0.38% 1 0 2026-09-17T20:18:58.840000 admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload h
CVE-2026-54752 9.6 0.35% 1 0 2026-09-17T20:16:52.877000 NetBox Device Type Library is a collection of community-sourced device type defi
CVE-2026-28326 8.8 0.55% 2 0 2026-09-17T18:32:05 SolarWinds Access Rights Manager was reported to be affected by an unauthenticat
CVE-2026-92941 10.0 0.27% 1 0 2026-09-17T16:18:34.520000 vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sand
CVE-2026-79752 0 0.46% 1 1 2026-09-17T16:17:44.693000 CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9,
CVE-2026-92950 8.6 0.22% 1 0 2026-09-17T15:32:35 vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that a
CVE-2026-92939 9.9 0.53% 1 0 2026-09-17T15:32:28 vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM san
CVE-2026-92938 9.9 0.42% 1 0 2026-09-17T15:32:28 vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to c
CVE-2026-92960 10.0 0.43% 1 0 2026-09-17T15:32:27 vm2 before 3.11.6 fails to restrict access to os and dns builtins under the buil
CVE-2026-92935 9.0 0.50% 1 0 2026-09-17T15:32:26 vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <
CVE-2026-92944 9.8 0.58% 1 0 2026-09-17T15:32:26 vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Nod
CVE-2026-92957 9.9 0.49% 1 0 2026-09-17T15:32:26 vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when e
CVE-2026-92918 8.8 0.35% 1 0 2026-09-17T15:32:24 admin3 through 3.0.0 persists user session tokens in the audit log event body wh
CVE-2026-92953 10.0 0.34% 1 0 2026-09-17T15:32:22 vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and Array
CVE-2026-92947 10.0 0.43% 1 0 2026-09-17T15:32:21 vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing
CVE-2026-81481 7.5 0.53% 1 0 2026-09-17T15:32:18 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Im
CVE-2026-92955 10.0 0.62% 1 0 2026-09-17T15:17:01.040000 vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows
CVE-2026-92934 9.0 0.74% 1 0 2026-09-17T15:17:00.520000 vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that a
CVE-2026-92954 8.6 0.34% 1 0 2026-09-17T14:18:01.430000 vm2 is a sandbox library for running untrusted JavaScript in Node.js. In version
CVE-2026-15688 None 0.12% 1 0 2026-09-17T09:33:03 Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi
CVE-2026-58704 8.8 0.21% 2 0 2026-09-17T04:17:54.930000 In Cellular Modem, there is a possible permission bypass due to a logic error in
CVE-2026-76460 10.0 0.78% 14 1 2026-09-16T21:33:00 A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an
CVE-2026-89082 None 0.51% 1 0 2026-09-16T21:32:55 HP has identified potential security vulnerabilities in the HP Advance software
CVE-2026-20329 9.9 0.45% 2 0 2026-09-16T21:32:50 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20324 9.9 0.44% 1 0 2026-09-16T21:32:50 A vulnerability in the sftunnel inter-device communication protocol of Cisco Sec
CVE-2026-77179 0 0.16% 5 1 2026-09-16T20:38:33.883000 On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows
CVE-2026-20306 9.1 1.37% 2 0 2026-09-16T18:32:09 A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenti
CVE-2026-20305 9.1 1.37% 2 0 2026-09-16T18:32:04 A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an
CVE-2026-91843 9.8 0.50% 9 1 2026-09-16T15:31:14 A stack overflow during the unauthenticated login process may allow an attacker
CVE-2026-81642 None 0.52% 1 1 2026-09-16T09:30:28 In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in t
CVE-2026-79994 None 0.11% 1 0 2026-09-16T00:32:32 The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a
CVE-2026-76461 9.8 2.01% 2 4 2026-09-15T12:47:32.497000 A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure
CVE-2026-89497 7.8 0.13% 1 0 2026-09-14T15:33:33 In the Linux kernel, the following vulnerability has been resolved: orangefs: s
CVE-2026-89510 7.8 0.18% 1 0 2026-09-14T15:33:33 In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4:
CVE-2026-81000 7.8 0.16% 5 1 2026-09-14T15:33:28 In the Linux kernel, the following vulnerability has been resolved: net: tun: b
CVE-2026-89496 None 0.18% 1 0 2026-09-14T15:32:27 In the Linux kernel, the following vulnerability has been resolved: ocfs2: alwa
CVE-2026-89460 None 0.17% 1 0 2026-09-14T15:32:24 In the Linux kernel, the following vulnerability has been resolved: s390/cpum_c
CVE-2026-80944 7.8 0.13% 1 0 2026-09-14T15:32:21 In the Linux kernel, the following vulnerability has been resolved: wifi: mwifi
CVE-2026-89480 7.5 0.41% 1 0 2026-09-14T13:19:04.623000 In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: r
CVE-2026-89479 9.8 0.51% 1 0 2026-09-14T13:19:04.457000 In the Linux kernel, the following vulnerability has been resolved: sctp: stop
CVE-2026-89473 0 0.20% 1 0 2026-09-14T13:19:03.620000 In the Linux kernel, the following vulnerability has been resolved: power: supp
CVE-2026-80990 0 0.20% 1 0 2026-09-14T13:18:53.787000 In the Linux kernel, the following vulnerability has been resolved: net: thunde
CVE-2026-80949 0 0.18% 1 0 2026-09-14T13:18:50.457000 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmf
CVE-2026-80941 0 0.21% 1 0 2026-09-14T13:18:50.160000 In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88
CVE-2026-89520 7.8 0.16% 1 0 2026-09-13T09:33:29 In the Linux kernel, the following vulnerability has been resolved: sched/core:
CVE-2026-89492 9.8 0.60% 1 0 2026-09-13T09:33:27 In the Linux kernel, the following vulnerability has been resolved: ocfs2: vali
CVE-2026-80986 9.8 0.60% 1 0 2026-09-13T09:33:25 In the Linux kernel, the following vulnerability has been resolved: net/smc: bo
CVE-2026-80953 8.4 0.18% 1 0 2026-09-13T09:32:12 In the Linux kernel, the following vulnerability has been resolved: i3c: master
CVE-2026-80954 7.8 0.15% 1 0 2026-09-13T09:32:11 In the Linux kernel, the following vulnerability has been resolved: i3c: Fix un
CVE-2026-89523 7.8 0.14% 1 0 2026-09-13T07:17:14.697000 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:
CVE-2026-89459 7.0 0.11% 1 0 2026-09-13T07:17:09.733000 In the Linux kernel, the following vulnerability has been resolved: s390/percpu
CVE-2026-89452 8.4 0.18% 1 0 2026-09-13T07:17:09.477000 In the Linux kernel, the following vulnerability has been resolved: iommu/msm:
CVE-2026-80998 7.5 0.47% 1 0 2026-09-13T07:17:06.483000 In the Linux kernel, the following vulnerability has been resolved: net: bnxt:
CVE-2026-78175 8.8 0.59% 2 0 2026-09-12T09:33:41 The Tutor LMS – eLearning and online course solution plugin for WordPress is vul
CVE-2026-89267 4.3 0.19% 1 0 2026-09-12T03:30:28 starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fi
CVE-2026-89455 None 0.20% 1 0 2026-09-11T21:31:28 In the Linux kernel, the following vulnerability has been resolved: PCI: plda:
CVE-2026-80934 None 0.17% 1 0 2026-09-11T21:31:20 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:
CVE-2026-89453 0 0.20% 1 0 2026-09-11T20:19:25.967000 In the Linux kernel, the following vulnerability has been resolved: iommu/amd:
CVE-2026-80957 0 0.17% 1 0 2026-09-11T20:19:01.520000 In the Linux kernel, the following vulnerability has been resolved: dm-pcache:
CVE-2026-80942 0 0.17% 1 0 2026-09-11T20:18:59.660000 In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwi
CVE-2026-0310 None 0.34% 1 0 2026-09-10T06:31:55 A buffer overflow vulnerability in the XML processing functionality of Palo Alto
CVE-2026-80844 0 0.19% 5 1 2026-09-04T16:18:13.023000 In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6:
CVE-2026-13348 None 0.31% 2 0 2026-09-01T15:31:17 CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability
CVE-2026-18963 9.1 3.18% 1 15 template 2026-08-28T22:53:42 A flaw was found in the reset-credentials flow of the keycloak-services componen
CVE-2026-56389 8.6 0.16% 1 0 2026-08-24T18:32:30 GNU Bison allows for an execution of an arbitrary program during HTML report gen
CVE-2026-74469 8.8 0.47% 5 1 2026-08-19T18:33:35 In the Linux kernel, the following vulnerability has been resolved: sctp: preve
CVE-2026-68121 7.8 0.14% 5 1 2026-08-19T18:32:06 In the Linux kernel, the following vulnerability has been resolved: pppoe: relo
CVE-2026-59310 9.8 49.68% 2 2 2026-08-19T04:17:24.940000 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-7646 6.5 0.30% 2 5 2026-08-06T19:27:33.433000 IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from
CVE-2026-58138 9.8 9.26% 4 6 template 2026-07-14T22:17:26.797000 Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code ex
CVE-2026-45321 9.6 2.34% 1 13 2026-06-08T23:53:12 ## Summary On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicio
CVE-2026-78030 0 0.00% 4 0 N/A
CVE-2026-57228 0 0.56% 2 0 N/A
CVE-2026-63452 0 0.36% 2 0 N/A
CVE-2026-71418 0 0.35% 2 0 N/A
CVE-2026-92708 0 0.34% 2 0 N/A
CVE-2026-72878 0 0.27% 1 0 N/A
CVE-2026-54520 0 0.40% 1 1 N/A
CVE-2026-54670 0 0.55% 1 0 N/A
CVE-2026-54671 0 0.41% 1 0 N/A
CVE-2026-93426 0 0.37% 1 0 N/A
CVE-2026-54716 0 0.32% 1 0 N/A
CVE-2026-54692 0 0.14% 1 0 N/A
CVE-2026-54627 0 0.44% 1 0 N/A
CVE-2026-93337 0 0.15% 1 0 N/A
CVE-2026-85500 0 0.55% 1 0 N/A

CVE-2026-93958
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-20T03:30:31

2 posts

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

thehackerwire@mastodon.social at 2026-09-20T03:02:11.000Z ##

🔴 CVE-2026-93958 - Critical (9.1)

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T03:02:11.000Z ##

🔴 CVE-2026-93958 - Critical (9.1)

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94084
(9.4 CRITICAL)

EPSS: 0.00%

updated 2026-09-20T03:30:29

4 posts

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

thehackerwire@mastodon.social at 2026-09-20T03:02:29.000Z ##

🔴 CVE-2026-94084 - Critical (9.4)

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-20T03:00:23.655Z ##

CRITICAL use-after-free (CVE-2026-94084) in Suricata <8.0.7 🛡️. Exploitable via HTTP/2 rules with http.response_header. Risk: code execution, memory corruption. Patch by upgrading to 8.0.7+. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T03:02:29.000Z ##

🔴 CVE-2026-94084 - Critical (9.4)

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T03:00:23.000Z ##

CRITICAL use-after-free (CVE-2026-94084) in Suricata <8.0.7 🛡️. Exploitable via HTTP/2 rules with http.response_header. Risk: code execution, memory corruption. Patch by upgrading to 8.0.7+. radar.offseq.com/threat/cve-20 #OffSeq #Suricata #Vuln #Infosec

##

CVE-2026-94083
(9.4 CRITICAL)

EPSS: 0.00%

updated 2026-09-20T02:16:53.520000

4 posts

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.

offseq at 2026-09-20T04:30:23.101Z ##

Suricata 8.0.0 – 8.0.6 affected by CRITICAL CVE-2026-94083: Type confusion in DoH2 (CWE-843) can trigger DoS via invalid free. Patch to 8.0.7+. No known exploits yet. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T03:02:19.000Z ##

🔴 CVE-2026-94083 - Critical (9.4)

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T04:30:23.000Z ##

Suricata 8.0.0 – 8.0.6 affected by CRITICAL CVE-2026-94083: Type confusion in DoH2 (CWE-843) can trigger DoS via invalid free. Patch to 8.0.7+. No known exploits yet. radar.offseq.com/threat/cve-20 #OffSeq #Suricata #Vuln #BlueTeam

##

thehackerwire@mastodon.social at 2026-09-20T03:02:19.000Z ##

🔴 CVE-2026-94083 - Critical (9.4)

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93993
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-20T00:30:32

2 posts

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.

thehackerwire@mastodon.social at 2026-09-20T00:02:41.000Z ##

🟠 CVE-2026-93993 - High (8.8)

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:02:41.000Z ##

🟠 CVE-2026-93993 - High (8.8)

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93992
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-20T00:30:32

2 posts

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory traversal sequences that bypass validation, enabling file write operations when users download and extract archives with AutoExtract enabled.

thehackerwire@mastodon.social at 2026-09-20T00:02:29.000Z ##

🟠 CVE-2026-93992 - High (8.1)

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory tra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:02:29.000Z ##

🟠 CVE-2026-93992 - High (8.1)

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory tra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93990
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-20T00:30:31

2 posts

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

thehackerwire@mastodon.social at 2026-09-20T00:01:16.000Z ##

🟠 CVE-2026-93990 - High (7.5)

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:01:16.000Z ##

🟠 CVE-2026-93990 - High (7.5)

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94056
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-19T23:17:11.113000

2 posts

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

thehackerwire@mastodon.social at 2026-09-20T00:01:08.000Z ##

🟠 CVE-2026-94056 - High (7.5)

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:01:08.000Z ##

🟠 CVE-2026-94056 - High (7.5)

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93991
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-19T23:17:10.360000

2 posts

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec

thehackerwire@mastodon.social at 2026-09-20T00:01:26.000Z ##

🟠 CVE-2026-93991 - High (7.7)

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:01:26.000Z ##

🟠 CVE-2026-93991 - High (7.7)

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86814
(8.1 HIGH)

EPSS: 0.14%

updated 2026-09-19T15:32:25

4 posts

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own.

thehackerwire@mastodon.social at 2026-09-19T15:03:14.000Z ##

🟠 CVE-2026-86814 - High (8.1)

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, includin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T07:30:23.429Z ##

UsersWP <1.5.10 is affected by CRITICAL privilege management flaw (CVE-2026-86814). Attackers can hijack any account — including admins — by abusing social login email validation. Update to 1.5.10+ ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T15:03:14.000Z ##

🟠 CVE-2026-86814 - High (8.1)

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, includin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T07:30:23.000Z ##

UsersWP <1.5.10 is affected by CRITICAL privilege management flaw (CVE-2026-86814). Attackers can hijack any account — including admins — by abusing social login email validation. Update to 1.5.10+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202686814 #infosec

##

CVE-2026-88926
(8.6 HIGH)

EPSS: 0.18%

updated 2026-09-19T15:31:25

2 posts

The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-09-19T17:02:28.000Z ##

🟠 CVE-2026-88926 - High (8.6)

The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T17:02:28.000Z ##

🟠 CVE-2026-88926 - High (8.6)

The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85680
(8.8 HIGH)

EPSS: 0.17%

updated 2026-09-19T15:31:24

2 posts

The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that will execute when any visitor, including an administrator, views their profile.

thehackerwire@mastodon.social at 2026-09-19T18:00:33.000Z ##

🟠 CVE-2026-85680 - High (8.8)

The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unaut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T18:00:33.000Z ##

🟠 CVE-2026-85680 - High (8.8)

The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unaut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84750
(6.5 MEDIUM)

EPSS: 0.20%

updated 2026-09-19T15:31:24

2 posts

The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its form fields, and stores them at a predictable public path with the attacker-chosen extension intact, allowing unauthenticated users to upload arbitrary files. The PHP handler shipped by default with the Debian and Ubuntu Apache packages maps .phar to PHP a

offseq at 2026-09-19T12:00:24.090Z ##

Ultra Addons for Contact Form 7 (<3.5.51) is vulnerable (CVE-2026-84750, CRITICAL). Unrestricted file upload enables unauthenticated RCE on Debian/Ubuntu Apache (.phar) or stored XSS. Upgrade to 3.5.51+ ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-19T12:00:24.000Z ##

Ultra Addons for Contact Form 7 (<3.5.51) is vulnerable (CVE-2026-84750, CRITICAL). Unrestricted file upload enables unauthenticated RCE on Debian/Ubuntu Apache (.phar) or stored XSS. Upgrade to 3.5.51+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #RCE

##

CVE-2026-86591
(9.8 CRITICAL)

EPSS: 0.18%

updated 2026-09-19T15:31:23

4 posts

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the si

thehackerwire@mastodon.social at 2026-09-19T15:03:04.000Z ##

🔴 CVE-2026-86591 - Critical (9.8)

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T10:30:24.363Z ##

CVE-2026-86591 | CRITICAL | Botiga Pro <1.6.5 allows unauthenticated attackers to modify WP options, inject persistent XSS, and trash posts due to missing REST API authorization. Immediate upgrade to 1.6.5+ is essential. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T15:03:04.000Z ##

🔴 CVE-2026-86591 - Critical (9.8)

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T10:30:24.000Z ##

CVE-2026-86591 | CRITICAL | Botiga Pro <1.6.5 allows unauthenticated attackers to modify WP options, inject persistent XSS, and trash posts due to missing REST API authorization. Immediate upgrade to 1.6.5+ is essential. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202686591

##

CVE-2026-93761
(7.5 HIGH)

EPSS: 0.27%

updated 2026-09-19T15:17:08.503000

2 posts

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a pattern-matching query condition on an embedded association may become unresponsive.

thehackerwire@mastodon.social at 2026-09-18T20:02:20.000Z ##

🟠 CVE-2026-93761 - High (7.5)

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T20:02:20.000Z ##

🟠 CVE-2026-93761 - High (7.5)

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84398
(7.5 HIGH)

EPSS: 0.24%

updated 2026-09-19T15:17:05.863000

2 posts

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.

thehackerwire@mastodon.social at 2026-09-18T17:05:30.000Z ##

🟠 CVE-2026-84398 - High (7.5)

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T17:05:30.000Z ##

🟠 CVE-2026-84398 - High (7.5)

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84083
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-19T15:17:05.750000

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validation in the SUID binary to execute arbitrary commands as root, resulting in full compromise of the Collector appliance.

thehackerwire@mastodon.social at 2026-09-19T21:00:56.000Z ##

🟠 CVE-2026-84083 - High (7.8)

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T21:00:56.000Z ##

🟠 CVE-2026-84083 - High (7.8)

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84081
(8.1 HIGH)

EPSS: 0.20%

updated 2026-09-19T15:17:05.537000

3 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T20:01:01.000Z ##

🟠 CVE-2026-84081 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T20:01:01.000Z ##

🟠 CVE-2026-84081 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84078
(9.9 CRITICAL)

EPSS: 0.28%

updated 2026-09-19T15:17:05.430000

3 posts

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T20:00:46.000Z ##

🔴 CVE-2026-84078 - Critical (9.9)

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T20:00:46.000Z ##

🔴 CVE-2026-84078 - Critical (9.9)

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84076
(7.6 HIGH)

EPSS: 0.31%

updated 2026-09-19T15:17:05.317000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

thehackerwire@mastodon.social at 2026-09-19T19:00:59.000Z ##

🟠 CVE-2026-84076 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T19:00:59.000Z ##

🟠 CVE-2026-84076 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84075
(9.9 CRITICAL)

EPSS: 0.35%

updated 2026-09-19T15:17:05.217000

3 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T19:00:47.000Z ##

🔴 CVE-2026-84075 - Critical (9.9)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T19:00:47.000Z ##

🔴 CVE-2026-84075 - Critical (9.9)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84070
(8.9 HIGH)

EPSS: 0.32%

updated 2026-09-19T15:17:04.867000

3 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T22:01:23.000Z ##

🟠 CVE-2026-84070 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T22:01:23.000Z ##

🟠 CVE-2026-84070 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82967
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-09-19T15:17:04.430000

3 posts

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-20T01:01:37.000Z ##

🔴 CVE-2026-82967 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T01:01:37.000Z ##

🔴 CVE-2026-82967 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80441
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-09-19T15:17:02.430000

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T03:03:29.000Z ##

🔴 CVE-2026-80441 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T03:03:29.000Z ##

🔴 CVE-2026-80441 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92807
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-19T14:17:05.850000

4 posts

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`button_`/non-`email_` shortcode attribute verbatim into a custom options array without sanitization, allowlist enforcement, or capability checks, and `cr

thehackerwire@mastodon.social at 2026-09-19T07:03:34.000Z ##

🟠 CVE-2026-92807 - High (8.8)

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T06:00:26.230Z ##

CVE-2026-92807: HIGH severity (CVSS 8.8) code injection in pdfcrowd Save as PDF Plugin for WordPress (<=4.6.1). Contributor+ users can run arbitrary PHP — risking API credential leaks & server compromise. Restrict access, monitor for patch. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T07:03:34.000Z ##

🟠 CVE-2026-92807 - High (8.8)

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T06:00:26.000Z ##

CVE-2026-92807: HIGH severity (CVSS 8.8) code injection in pdfcrowd Save as PDF Plugin for WordPress (<=4.6.1). Contributor+ users can run arbitrary PHP — risking API credential leaks & server compromise. Restrict access, monitor for patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec

##

CVE-2026-92404
(7.5 HIGH)

EPSS: 0.14%

updated 2026-09-19T14:17:04.240000

2 posts

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.

thehackerwire@mastodon.social at 2026-09-19T17:02:37.000Z ##

🟠 CVE-2026-92404 - High (7.5)

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, fr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T17:02:37.000Z ##

🟠 CVE-2026-92404 - High (7.5)

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, fr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89274
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-09-19T14:17:03.127000

4 posts

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the `reviewBody` field, which is populated verbatim from the `comment_content` of app

1 repos

https://github.com/murrez/CVE-2026-89274

thehackerwire@mastodon.social at 2026-09-19T07:04:14.000Z ##

🔴 CVE-2026-89274 - Critical (9.1)

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T03:00:23.674Z ##

WP Recipe Maker <=10.8.1 hit by CVE-2026-89274: CRITICAL code injection via unsanitized shortcodes in comment ratings. Unauthenticated attackers can trigger arbitrary shortcode execution on recipe pages. Upgrade ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T07:04:14.000Z ##

🔴 CVE-2026-89274 - Critical (9.1)

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T03:00:23.000Z ##

WP Recipe Maker <=10.8.1 hit by CVE-2026-89274: CRITICAL code injection via unsanitized shortcodes in comment ratings. Unauthenticated attackers can trigger arbitrary shortcode execution on recipe pages. Upgrade ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202689274 #Infosec

##

CVE-2026-88824
(8.8 HIGH)

EPSS: 0.17%

updated 2026-09-19T14:17:02.290000

2 posts

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.

thehackerwire@mastodon.social at 2026-09-19T15:03:24.000Z ##

🟠 CVE-2026-88824 - High (8.8)

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T15:03:24.000Z ##

🟠 CVE-2026-88824 - High (8.8)

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85658
(8.1 HIGH)

EPSS: 0.36%

updated 2026-09-19T14:17:00.627000

2 posts

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authe

thehackerwire@mastodon.social at 2026-09-19T09:01:48.000Z ##

🟠 CVE-2026-85658 - High (8.1)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is du...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T09:01:48.000Z ##

🟠 CVE-2026-85658 - High (8.1)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is du...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85574
(8.0 HIGH)

EPSS: 0.13%

updated 2026-09-19T14:17:00.477000

2 posts

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.

thehackerwire@mastodon.social at 2026-09-19T17:02:47.000Z ##

🟠 CVE-2026-85574 - High (8)

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T17:02:47.000Z ##

🟠 CVE-2026-85574 - High (8)

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84241
(8.1 HIGH)

EPSS: 0.30%

updated 2026-09-19T14:17:00.260000

3 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-18T21:03:06.000Z ##

🟠 CVE-2026-84241 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:03:06.000Z ##

🟠 CVE-2026-84241 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84239
(7.6 HIGH)

EPSS: 0.41%

updated 2026-09-19T14:17:00.143000

3 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T19:00:35.000Z ##

🟠 CVE-2026-84239 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T19:00:35.000Z ##

🟠 CVE-2026-84239 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84105
(7.7 HIGH)

EPSS: 0.35%

updated 2026-09-19T14:16:59.917000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

thehackerwire@mastodon.social at 2026-09-19T14:05:21.000Z ##

🟠 CVE-2026-84105 - High (7.7)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T14:05:21.000Z ##

🟠 CVE-2026-84105 - High (7.7)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84089
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-19T14:16:59.813000

3 posts

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T14:05:11.000Z ##

🟠 CVE-2026-84089 - High (7.8)

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T14:05:11.000Z ##

🟠 CVE-2026-84089 - High (7.8)

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84085
(8.1 HIGH)

EPSS: 0.32%

updated 2026-09-19T14:16:59.587000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-19T14:05:01.000Z ##

🟠 CVE-2026-84085 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T14:05:01.000Z ##

🟠 CVE-2026-84085 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93985
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-19T12:16:41.873000

4 posts

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process.

thehackerwire@mastodon.social at 2026-09-19T14:03:52.000Z ##

🔴 CVE-2026-93985 - Critical (9.9)

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T13:30:23.645Z ##

CVE-2026-93985 (CVSS 9.4) in Openpanel-dev openpanel v0: Critical code injection via JS webhook template validator. Attackers with project write access can run arbitrary code in the worker process. Limit permissions & monitor. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T14:03:52.000Z ##

🔴 CVE-2026-93985 - Critical (9.9)

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T13:30:23.000Z ##

CVE-2026-93985 (CVSS 9.4) in Openpanel-dev openpanel v0: Critical code injection via JS webhook template validator. Attackers with project write access can run arbitrary code in the worker process. Limit permissions & monitor. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #AppSec

##

CVE-2026-93742
(9.9 CRITICAL)

EPSS: 1.88%

updated 2026-09-19T09:32:25

5 posts

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

thehackerwire@mastodon.social at 2026-09-19T14:04:18.000Z ##

🔴 CVE-2026-93742 - Critical (9.9)

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

hugovalters@mastodon.social at 2026-09-19T11:02:45.000Z ##

CVE-2026-93742 - Unpatched Command Injection in Totolink A3002MU routers enables remote RCE. Public exploit released. CVSS 9.9. Isolate devices now. #CVE #Totolink #infosec

valtersit.com/cve/CVE-2026-937

##

offseq at 2026-09-19T09:00:25.454Z ##

Totolink A3002MU routers suffer a CRITICAL (CVSS 9.4) command injection vuln (CVE-2026-93742) in formWsc (/boafrm/formWsc). Public exploit available — remote compromise risk. Restrict access, monitor devices, patch ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T14:04:18.000Z ##

🔴 CVE-2026-93742 - Critical (9.9)

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T09:00:25.000Z ##

Totolink A3002MU routers suffer a CRITICAL (CVSS 9.4) command injection vuln (CVE-2026-93742) in formWsc (/boafrm/formWsc). Public exploit available — remote compromise risk. Restrict access, monitor devices, patch ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity

##

CVE-2026-4327
(8.8 HIGH)

EPSS: 0.70%

updated 2026-09-19T09:32:22

2 posts

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the use of eval() to execute user-supplied 'custom logic' code on the frontend. The AJAX handler at twiz-ajax.php verifies a nonce but performs no current_use

thehackerwire@mastodon.social at 2026-09-19T09:01:57.000Z ##

🟠 CVE-2026-4327 - High (8.8)

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T09:01:57.000Z ##

🟠 CVE-2026-4327 - High (8.8)

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-1255
(7.5 HIGH)

EPSS: 0.29%

updated 2026-09-19T09:32:16

2 posts

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible for unauthenticated attackers to retrieve all captured form submission data, including personally identifiable information (PII) such as names, email add

thehackerwire@mastodon.social at 2026-09-19T14:04:06.000Z ##

🟠 CVE-2026-1255 - High (7.5)

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T14:04:06.000Z ##

🟠 CVE-2026-1255 - High (7.5)

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93741
(10.0 CRITICAL)

EPSS: 0.64%

updated 2026-09-19T06:16:30.557000

5 posts

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

offseq at 2026-09-20T00:00:36.191Z ##

CVE-2026-93741: Totolink A3002MU (Hh-B20211125.1046) hit by CRITICAL buffer overflow in formWlWds (CVSS 10). Exploit is public; remote code exec risk. Isolate affected routers or block attacks at the network. radar.offseq.com/threat/cve-20

##

hugovalters@mastodon.social at 2026-09-19T23:09:02.000Z ##

CVE-2026-93741 - Critical CVSS 10 Buffer Overflow in Totolink A3002MU routers. Public exploit available for remote attacks. Isolate affected devices now. #CVE #Totolink #infosec

valtersit.com/cve/CVE-2026-937

##

thehackerwire@mastodon.social at 2026-09-19T07:03:14.000Z ##

🔴 CVE-2026-93741 - Critical (10)

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T00:00:36.000Z ##

CVE-2026-93741: Totolink A3002MU (Hh-B20211125.1046) hit by CRITICAL buffer overflow in formWlWds (CVSS 10). Exploit is public; remote code exec risk. Isolate affected routers or block attacks at the network. radar.offseq.com/threat/cve-20 #OffSeq #CVE202693741 #IoT #Exploit

##

thehackerwire@mastodon.social at 2026-09-19T07:03:14.000Z ##

🔴 CVE-2026-93741 - Critical (10)

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93374
(9.6 CRITICAL)

EPSS: 0.35%

updated 2026-09-19T04:18:02.537000

1 posts

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

DailyCyberSecurity@infosec.exchange at 2026-09-18T06:21:23.000Z ##

Google patched critical Google Chrome vulnerabilities. Update now to address multiple Google Chrome vulnerabilities like CVE-2026-93374 and stay secure.

#GoogleChrome #ChromeSecurity #CVE202693374 #BrowserSecurity #InfoSec

securityonline.info/google-chr

##

CVE-2026-53266
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-19T04:17:53.580000

4 posts

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Aski

AAKL at 2026-09-18T15:47:33.739Z ##

New.

CISA Adds Two Known Exploited Vulnerabilities to Catalog.

CVE-2025-39964 Linux Kernel Race Condition Vulnerability cve.org/CVERecord?id=CVE-2025-

CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability cve.org/CVERecord?id=CVE-2026-

##

secdb at 2026-09-18T15:00:11.403Z ##

🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-39964 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/0f28c4; git.kernel.org/stable/c/e4c1ec; git.kernel.org/stable/c/1f323a; git.kernel.org/stable/c/7c4491; git.kernel.org/stable/c/9aee87; git.kernel.org/stable/c/45bcf6; git.kernel.org/stable/c/1b34cb ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-53266 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/bf84ad; git.kernel.org/stable/c/76280b; git.kernel.org/stable/c/b7e919; git.kernel.org/stable/c/afd64b; git.kernel.org/stable/c/153ea9; git.kernel.org/stable/c/b18675; git.kernel.org/stable/c/c9b5ff; git.kernel.org/stable/c/67ba97 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-09-18T15:47:33.000Z ##

New.

CISA Adds Two Known Exploited Vulnerabilities to Catalog.

CVE-2025-39964 Linux Kernel Race Condition Vulnerability cve.org/CVERecord?id=CVE-2025-

CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #Linux #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-18T15:00:11.000Z ##

🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-39964 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/0f28c4; git.kernel.org/stable/c/e4c1ec; git.kernel.org/stable/c/1f323a; git.kernel.org/stable/c/7c4491; git.kernel.org/stable/c/9aee87; git.kernel.org/stable/c/45bcf6; git.kernel.org/stable/c/1b34cb ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-53266 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/bf84ad; git.kernel.org/stable/c/76280b; git.kernel.org/stable/c/b7e919; git.kernel.org/stable/c/afd64b; git.kernel.org/stable/c/153ea9; git.kernel.org/stable/c/b18675; git.kernel.org/stable/c/c9b5ff; git.kernel.org/stable/c/67ba97 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260918 #cisa20260918 #cve_2025_39964 #cve_2026_53266 #cve202539964 #cve202653266

##

CVE-2025-39682
(9.8 CRITICAL)

EPSS: 1.20%

updated 2026-09-19T04:17:35.263000

3 posts

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we break out of the main processing loop. If the record has already been decrypted

1 repos

https://github.com/khoatran107/cve-2025-39682

Matchbook3469@mastodon.social at 2026-09-19T18:28:22.000Z ##

🔵 THREAT INTELLIGENCE

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

Vulnerability | CRITICAL
CVEs: CVE-2025-39682

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known...

Full analysis:
yazoul.net/news/article/cisa-f

by Yazoul AI

#ThreatIntel #SecurityNews #CyberNews

##

cisakevtracker@mastodon.social at 2026-09-18T20:00:51.000Z ##

CVE ID: CVE-2025-39682
Vendor: Linux
Product: Kernel
Date Added: 2026-09-18
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-09-18T20:00:51.000Z ##

CVE ID: CVE-2025-39682
Vendor: Linux
Product: Kernel
Date Added: 2026-09-18
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-92229
(9.1 CRITICAL)

EPSS: 0.40%

updated 2026-09-19T03:32:15

4 posts

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary sho

1 repos

https://github.com/murrez/CVE-2026-92229

thehackerwire@mastodon.social at 2026-09-19T07:03:24.000Z ##

🔴 CVE-2026-92229 - Critical (9.1)

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T04:30:23.539Z ##

CVE-2026-92229: CRITICAL code injection in wpmudev Forminator Forms plugin (≤1.57.2). Unauthenticated attackers can execute arbitrary shortcodes, risking full WordPress site compromise. Restrict or disable plugin now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T07:03:24.000Z ##

🔴 CVE-2026-92229 - Critical (9.1)

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T04:30:23.000Z ##

CVE-2026-92229: CRITICAL code injection in wpmudev Forminator Forms plugin (≤1.57.2). Unauthenticated attackers can execute arbitrary shortcodes, risking full WordPress site compromise. Restrict or disable plugin now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202692229

##

CVE-2026-87909
(7.5 HIGH)

EPSS: 0.53%

updated 2026-09-19T03:32:11

2 posts

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. This makes it p

thehackerwire@mastodon.social at 2026-09-19T07:04:32.000Z ##

🟠 CVE-2026-87909 - High (7.5)

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T07:04:32.000Z ##

🟠 CVE-2026-87909 - High (7.5)

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84434
(9.8 CRITICAL)

EPSS: 0.70%

updated 2026-09-19T03:32:11

2 posts

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a rejected file's intact upload state is later passed to upload_file() without re-v

1 repos

https://github.com/murrez/CVE-2026-84434

thehackerwire@mastodon.social at 2026-09-19T07:04:23.000Z ##

🔴 CVE-2026-84434 - Critical (9.8)

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T07:04:23.000Z ##

🔴 CVE-2026-84434 - Critical (9.8)

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93739
(9.9 CRITICAL)

EPSS: 0.49%

updated 2026-09-19T00:32:51

2 posts

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

thehackerwire@mastodon.social at 2026-09-18T23:01:09.000Z ##

🔴 CVE-2026-93739 - Critical (9.9)

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed fro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:01:09.000Z ##

🔴 CVE-2026-93739 - Critical (9.9)

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed fro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93923
(8.8 HIGH)

EPSS: 0.41%

updated 2026-09-19T00:32:50

2 posts

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style values that execute in the Electron renderer with full system access.

thehackerwire@mastodon.social at 2026-09-19T08:03:31.000Z ##

🟠 CVE-2026-93923 - High (8.8)

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style va...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T08:03:31.000Z ##

🟠 CVE-2026-93923 - High (8.8)

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style va...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93922
(8.8 HIGH)

EPSS: 0.54%

updated 2026-09-19T00:16:57.913000

2 posts

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.

thehackerwire@mastodon.social at 2026-09-19T08:03:23.000Z ##

🟠 CVE-2026-93922 - High (8.8)

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaSc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T08:03:23.000Z ##

🟠 CVE-2026-93922 - High (8.8)

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaSc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93740
(10.0 CRITICAL)

EPSS: 0.61%

updated 2026-09-18T22:17:10.890000

2 posts

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

thehackerwire@mastodon.social at 2026-09-18T23:01:18.000Z ##

🔴 CVE-2026-93740 - Critical (10)

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:01:18.000Z ##

🔴 CVE-2026-93740 - Critical (10)

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75885
(9.3 CRITICAL)

EPSS: 0.41%

updated 2026-09-18T22:17:10.313000

4 posts

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests withou

offseq at 2026-09-19T00:00:37.803Z ##

CVE-2026-75885: CRITICAL SSRF & DoS in Red Hat OpenShift Container Platform 4. Unauthenticated access to /api/devfile/ endpoints can expose internal services & cause resource exhaustion. No fix yet — restrict access & monitor advisories. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-18T23:00:58.000Z ##

🔴 CVE-2026-75885 - Critical (9.3)

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T00:00:37.000Z ##

CVE-2026-75885: CRITICAL SSRF & DoS in Red Hat OpenShift Container Platform 4. Unauthenticated access to /api/devfile/ endpoints can expose internal services & cause resource exhaustion. No fix yet — restrict access & monitor advisories. radar.offseq.com/threat/cve-20 #OffSeq #OpenShift #SSRF

##

thehackerwire@mastodon.social at 2026-09-18T23:00:58.000Z ##

🔴 CVE-2026-75885 - Critical (9.3)

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88097
(8.1 HIGH)

EPSS: 0.22%

updated 2026-09-18T21:32:43

2 posts

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

thehackerwire@mastodon.social at 2026-09-18T22:02:05.000Z ##

🟠 CVE-2026-88097 - High (8.1)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:02:05.000Z ##

🟠 CVE-2026-88097 - High (8.1)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93031
(8.8 HIGH)

EPSS: 0.58%

updated 2026-09-18T21:32:41

2 posts

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported f

thehackerwire@mastodon.social at 2026-09-18T21:02:33.000Z ##

🟠 CVE-2026-93031 - High (8.8)

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:02:33.000Z ##

🟠 CVE-2026-93031 - High (8.8)

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84077
(8.1 HIGH)

EPSS: 0.19%

updated 2026-09-18T21:32:40

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

thehackerwire@mastodon.social at 2026-09-19T20:00:36.000Z ##

🟠 CVE-2026-84077 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T20:00:36.000Z ##

🟠 CVE-2026-84077 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84082
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-09-18T21:32:39

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

thehackerwire@mastodon.social at 2026-09-19T21:00:44.000Z ##

🔴 CVE-2026-84082 - Critical (9.8)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T21:00:44.000Z ##

🔴 CVE-2026-84082 - Critical (9.8)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84074
(8.9 HIGH)

EPSS: 0.32%

updated 2026-09-18T21:32:38

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

thehackerwire@mastodon.social at 2026-09-19T23:01:13.000Z ##

🟠 CVE-2026-84074 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T23:01:13.000Z ##

🟠 CVE-2026-84074 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84064
(9.9 CRITICAL)

EPSS: 0.37%

updated 2026-09-18T21:32:38

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

thehackerwire@mastodon.social at 2026-09-19T22:01:14.000Z ##

🔴 CVE-2026-84064 - Critical (9.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T22:01:14.000Z ##

🔴 CVE-2026-84064 - Critical (9.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84108
(8.1 HIGH)

EPSS: 0.40%

updated 2026-09-18T21:32:38

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

thehackerwire@mastodon.social at 2026-09-19T18:00:53.000Z ##

🟠 CVE-2026-84108 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T18:00:53.000Z ##

🟠 CVE-2026-84108 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82887
(8.8 HIGH)

EPSS: 0.41%

updated 2026-09-18T21:32:37

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-20T03:03:20.000Z ##

🟠 CVE-2026-82887 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T03:03:20.000Z ##

🟠 CVE-2026-82887 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82896
(7.6 HIGH)

EPSS: 0.36%

updated 2026-09-18T21:32:37

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

thehackerwire@mastodon.social at 2026-09-20T01:01:26.000Z ##

🟠 CVE-2026-82896 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T01:01:26.000Z ##

🟠 CVE-2026-82896 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84073
(9.1 CRITICAL)

EPSS: 0.26%

updated 2026-09-18T21:32:37

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

thehackerwire@mastodon.social at 2026-09-19T23:01:04.000Z ##

🔴 CVE-2026-84073 - Critical (9.1)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T23:01:04.000Z ##

🔴 CVE-2026-84073 - Critical (9.1)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84034
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-18T21:32:37

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information.

thehackerwire@mastodon.social at 2026-09-19T22:00:57.000Z ##

🟠 CVE-2026-84034 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthoriz...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T22:00:57.000Z ##

🟠 CVE-2026-84034 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthoriz...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82885
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-18T21:32:36

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

thehackerwire@mastodon.social at 2026-09-20T03:03:11.000Z ##

🟠 CVE-2026-82885 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T03:03:11.000Z ##

🟠 CVE-2026-82885 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82832
(9.6 CRITICAL)

EPSS: 0.38%

updated 2026-09-18T21:32:36

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

thehackerwire@mastodon.social at 2026-09-20T02:02:45.000Z ##

🔴 CVE-2026-82832 - Critical (9.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T02:02:45.000Z ##

🔴 CVE-2026-82832 - Critical (9.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82893
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-18T21:32:36

2 posts

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

thehackerwire@mastodon.social at 2026-09-20T00:02:51.000Z ##

🟠 CVE-2026-82893 - High (7.8)

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:02:51.000Z ##

🟠 CVE-2026-82893 - High (7.8)

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82340
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-18T21:32:35

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code execution in the Guardium appliance.

thehackerwire@mastodon.social at 2026-09-20T02:02:35.000Z ##

🔴 CVE-2026-82340 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T02:02:35.000Z ##

🔴 CVE-2026-82340 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81933
(8.8 HIGH)

EPSS: 0.32%

updated 2026-09-18T21:32:35

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T01:01:47.000Z ##

🟠 CVE-2026-81933 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T01:01:47.000Z ##

🟠 CVE-2026-81933 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82892
(8.1 HIGH)

EPSS: 0.39%

updated 2026-09-18T21:32:35

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-19T23:01:23.000Z ##

🟠 CVE-2026-82892 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T23:01:23.000Z ##

🟠 CVE-2026-82892 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93868
(8.1 HIGH)

EPSS: 0.61%

updated 2026-09-18T21:18:49.023000

2 posts

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and probe them against the passrecover authentication endpoint to reset any account pas

thehackerwire@mastodon.social at 2026-09-18T21:01:38.000Z ##

🟠 CVE-2026-93868 - High (8.1)

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:01:38.000Z ##

🟠 CVE-2026-93868 - High (8.1)

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93738
(9.9 CRITICAL)

EPSS: 0.50%

updated 2026-09-18T21:18:48.660000

2 posts

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

thehackerwire@mastodon.social at 2026-09-18T22:01:34.000Z ##

🔴 CVE-2026-93738 - Critical (9.9)

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:01:34.000Z ##

🔴 CVE-2026-93738 - Critical (9.9)

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93572
(7.5 HIGH)

EPSS: 0.34%

updated 2026-09-18T21:18:48.020000

2 posts

A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to eagerly preallocate a large amount of heap memory, leading to heap memory exhaustion and a Denial of Service (DoS) for applications using `RedisDecoder` with `RedisArrayAggregator`

thehackerwire@mastodon.social at 2026-09-18T14:04:49.000Z ##

🟠 CVE-2026-93572 - High (7.5)

## Summary

`RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis resource-exhaustion advisories. The limits are independent, but the allocator remains eager: every positive nested RESP array he...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T14:04:49.000Z ##

🟠 CVE-2026-93572 - High (7.5)

## Summary

`RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis resource-exhaustion advisories. The limits are independent, but the allocator remains eager: every positive nested RESP array he...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84106
(8.9 HIGH)

EPSS: 0.32%

updated 2026-09-18T21:18:44.520000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

thehackerwire@mastodon.social at 2026-09-19T18:00:43.000Z ##

🟠 CVE-2026-84106 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T18:00:43.000Z ##

🟠 CVE-2026-84106 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84084
(8.8 HIGH)

EPSS: 0.18%

updated 2026-09-18T21:18:44.413000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

thehackerwire@mastodon.social at 2026-09-19T08:03:40.000Z ##

🟠 CVE-2026-84084 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T08:03:40.000Z ##

🟠 CVE-2026-84084 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84031
(9.0 CRITICAL)

EPSS: 0.33%

updated 2026-09-18T21:18:44.080000

3 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T21:01:06.000Z ##

🔴 CVE-2026-84031 - Critical (9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T21:01:06.000Z ##

🔴 CVE-2026-84031 - Critical (9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68928
(8.6 HIGH)

EPSS: 0.13%

updated 2026-09-18T21:17:14.377000

2 posts

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins/terminal/src/android/TerminalService.java does not verify the caller. Any installed Android application can bind the service and send MSG_EXEC with an a

thehackerwire@mastodon.social at 2026-09-18T22:03:20.000Z ##

🟠 CVE-2026-68928 - High (8.6)

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:03:20.000Z ##

🟠 CVE-2026-68928 - High (8.6)

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63447
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-18T21:17:03.913000

2 posts

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp.max-tx is reached while processing one large chunk of FTP command data. The oversized transaction list is repeatedly processed with quadratic complexity

thehackerwire@mastodon.social at 2026-09-18T23:02:21.000Z ##

🟠 CVE-2026-63447 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:02:21.000Z ##

🟠 CVE-2026-63447 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63446
(7.5 HIGH)

EPSS: 0.39%

updated 2026-09-18T21:17:03.763000

2 posts

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only already-inspected transactions as inspected. On flows passed by a pass rule or pass-the-flow exception policy, detection is skipped, so completed transact

thehackerwire@mastodon.social at 2026-09-18T22:03:40.000Z ##

🟠 CVE-2026-63446 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:03:40.000Z ##

🟠 CVE-2026-63446 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57227
(7.5 HIGH)

EPSS: 0.40%

updated 2026-09-18T21:17:01.217000

2 posts

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appended to one transaction without a limit. Crafted MQTT traffic can grow transaction state indefinitely, consuming CPU and memory and causing slowdown or d

thehackerwire@mastodon.social at 2026-09-18T23:02:37.000Z ##

🟠 CVE-2026-57227 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:02:37.000Z ##

🟠 CVE-2026-57227 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93872
(7.5 HIGH)

EPSS: 0.44%

updated 2026-09-18T20:17:35.250000

2 posts

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.

thehackerwire@mastodon.social at 2026-09-18T21:01:05.000Z ##

🟠 CVE-2026-93872 - High (7.5)

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:01:05.000Z ##

🟠 CVE-2026-93872 - High (7.5)

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93839
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-18T20:17:34.047000

4 posts

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to int

cR0w at 2026-09-18T21:38:13.580Z ##

Go hack more LLM shit.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.

##

thehackerwire@mastodon.social at 2026-09-18T21:01:27.000Z ##

🔴 CVE-2026-93839 - Critical (9.8)

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-09-18T21:38:13.000Z ##

Go hack more LLM shit.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.

##

thehackerwire@mastodon.social at 2026-09-18T21:01:27.000Z ##

🔴 CVE-2026-93839 - Critical (9.8)

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93452
(7.5 HIGH)

EPSS: 0.49%

updated 2026-09-18T20:17:32.397000

1 posts

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination.

thehackerwire@mastodon.social at 2026-09-18T03:03:29.000Z ##

🟠 CVE-2026-93452 - High (7.5)

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's rem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92948
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-09-18T20:17:30.980000

1 posts

vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test'] }). On Node.js 24+, module.builtinModules exposes the scheme-only key node:test, which is not covered by vm2's family-based DANGEROUS_BUILTINS protection, so it i

CVE-2026-92937
(10.0 CRITICAL)

EPSS: 0.79%

updated 2026-09-18T20:17:30.707000

1 posts

vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bridge.js:1624 identity-checks only the direct call target when deciding whether to rebuild/sanitise a rejected host Promise value. Registering the rejection handler through Function.prototype.call or .apply indirection (e.

CVE-2026-54767
(9.1 CRITICAL)

EPSS: 0.43%

updated 2026-09-18T20:17:17.253000

1 posts

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source repository. A remote attacker who obtains that value can reach the endpoint's TRUNCATE TABLE operations for the endereco, pessoafis

thehackerwire@mastodon.social at 2026-09-17T23:01:20.000Z ##

🔴 CVE-2026-54767 - Critical (9.1)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54734
(10.0 CRITICAL)

EPSS: 0.36%

updated 2026-09-18T20:17:17.137000

1 posts

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request parameters can cause the server to send HTTP requests to unintended destinations, potentially reaching internal network

thehackerwire@mastodon.social at 2026-09-17T23:00:45.000Z ##

🔴 CVE-2026-54734 - Critical (10)

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20332
(9.9 CRITICAL)

EPSS: 0.30%

updated 2026-09-18T20:17:14.310000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

beyondmachines1@infosec.exchange at 2026-09-17T17:01:13.000Z ##

Cisco Patches 18 Critical and High-Severity Firewall Vulnerabilities, One Actively Exploited

Cisco released a massive security hardening update fixing 18 vulnerabilities in its Secure Firewall suite, including an actively exploited authentication bypass (CVE-2026-20332) and multiple critical remote code execution flaws.

**If you use Cisco Secure Firewall (ASA, FTD, or FMC), this is urgent. Patch now to the fixed versions Cisco lists. At least one flaw is already being exploited by attackers. Make sure the management interfaces are reachable only from your trusted internal network and never from the internet.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-20331
(9.6 CRITICAL)

EPSS: 0.23%

updated 2026-09-18T20:17:14.087000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

AAKL at 2026-09-18T16:27:33.387Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity

##

AAKL@infosec.exchange at 2026-09-18T16:27:33.000Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec

##

CVE-2026-20330
(9.9 CRITICAL)

EPSS: 0.34%

updated 2026-09-18T20:17:13.870000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

AAKL at 2026-09-18T16:27:33.387Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity

##

AAKL@infosec.exchange at 2026-09-18T16:27:33.000Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec

##

CVE-2026-18911
(7.5 HIGH)

EPSS: 1.06%

updated 2026-09-18T20:17:11.233000

1 posts

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

thehackerwire@mastodon.social at 2026-09-18T07:04:32.000Z ##

🟠 CVE-2026-18911 - High (7.5)

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13684
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-09-18T20:17:08.373000

3 posts

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

thehackerwire@mastodon.social at 2026-09-18T14:05:33.000Z ##

🔴 CVE-2026-13684 - Critical (9.8)

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T14:05:33.000Z ##

🔴 CVE-2026-13684 - Critical (9.8)

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-09-18T09:42:54.000Z ##

Synology fixed 8 DSM vulnerabilities, including two critical unauthenticated flaws (CVE-2026-13684, CVE-2026-13639) on DiskStation Manager. Update now.

#Synology #DSM #NAS #CVE #Vulnerability #DiskStation #InfoSec #PatchNow #NetworkSecurity #DataStorage

securityonline.info/synology-d

##

CVE-2026-13639
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-18T20:17:06.860000

1 posts

An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

CVE-2026-28197
(8.8 HIGH)

EPSS: 0.37%

updated 2026-09-18T19:24:36.593000

2 posts

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permissions. Successful exploitation grants the attacker unrestricted control over the Flex appliance host and all hosted containers, fully compromising confidentiality, i

thehackerwire@mastodon.social at 2026-09-18T14:03:48.000Z ##

🟠 CVE-2026-28197 - High (8.8)

An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could supply a specially crafted input to a
privileged administrative command, causing it to execute arbitrary code
with root-level permissions. Success...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T14:03:48.000Z ##

🟠 CVE-2026-28197 - High (8.8)

An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could supply a specially crafted input to a
privileged administrative command, causing it to execute arbitrary code
with root-level permissions. Success...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91149
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-18T19:06:08.407000

2 posts

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of detached threads, consuming system resources such as memory and file descriptors. The primary consequence is a denial of service (DoS), leading to degradat

thehackerwire@mastodon.social at 2026-09-18T18:02:36.000Z ##

🟠 CVE-2026-91149 - High (7.5)

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T18:02:36.000Z ##

🟠 CVE-2026-91149 - High (7.5)

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93760
(8.2 HIGH)

EPSS: 0.28%

updated 2026-09-18T19:05:01.127000

2 posts

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may influence how the database evaluates the query. This may result in unintended disclosure of stored field values and in reduced d

thehackerwire@mastodon.social at 2026-09-18T20:02:10.000Z ##

🟠 CVE-2026-93760 - High (8.2)

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T20:02:10.000Z ##

🟠 CVE-2026-93760 - High (8.2)

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93762
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-09-18T19:05:01.127000

2 posts

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.

thehackerwire@mastodon.social at 2026-09-18T20:00:58.000Z ##

🔴 CVE-2026-93762 - Critical (9.8)

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T20:00:58.000Z ##

🔴 CVE-2026-93762 - Critical (9.8)

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93758
(8.1 HIGH)

EPSS: 0.21%

updated 2026-09-18T19:05:01.127000

2 posts

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up without the usual ownership or scoping restrictions, then updated and linked to the requesting user's own record. This ma

thehackerwire@mastodon.social at 2026-09-18T18:02:16.000Z ##

🟠 CVE-2026-93758 - High (8.1)

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T18:02:16.000Z ##

🟠 CVE-2026-93758 - High (8.1)

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86863
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-09-18T19:05:01.127000

1 posts

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from request.environ and, when that returned nothing, fell back to reading the same name directly from the inbound HTTP request headers via requ

CVE-2026-93752
(7.5 HIGH)

EPSS: 0.47%

updated 2026-09-18T18:32:08

2 posts

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal counter and trigger excessive memory allocation during cssText serialization, causing process termination.

thehackerwire@mastodon.social at 2026-09-18T20:01:09.000Z ##

🟠 CVE-2026-93752 - High (7.5)

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal counter a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T20:01:09.000Z ##

🟠 CVE-2026-93752 - High (7.5)

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal counter a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93759
(8.6 HIGH)

EPSS: 0.24%

updated 2026-09-18T18:32:04

2 posts

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field value

thehackerwire@mastodon.social at 2026-09-18T20:02:01.000Z ##

🟠 CVE-2026-93759 - High (8.6)

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T20:02:01.000Z ##

🟠 CVE-2026-93759 - High (8.6)

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93687
(7.5 HIGH)

EPSS: 0.41%

updated 2026-09-18T18:32:02

2 posts

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.

thehackerwire@mastodon.social at 2026-09-18T17:05:11.000Z ##

🟠 CVE-2026-93687 - High (7.5)

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js proce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T17:05:11.000Z ##

🟠 CVE-2026-93687 - High (7.5)

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js proce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93753
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-18T18:32:01

2 posts

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without ow

thehackerwire@mastodon.social at 2026-09-18T20:01:19.000Z ##

🟠 CVE-2026-93753 - High (7.5)

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T20:01:19.000Z ##

🟠 CVE-2026-93753 - High (7.5)

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93765
(9.1 CRITICAL)

EPSS: 0.29%

updated 2026-09-18T18:31:58

2 posts

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becomin

thehackerwire@mastodon.social at 2026-09-18T18:02:26.000Z ##

🔴 CVE-2026-93765 - Critical (9.1)

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal metho...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T18:02:26.000Z ##

🔴 CVE-2026-93765 - Critical (9.1)

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal metho...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85497
(9.8 CRITICAL)

EPSS: 0.21%

updated 2026-09-18T18:31:57

2 posts

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.

cR0w at 2026-09-18T18:38:34.044Z ##

Oh look, yet another sev:CRIT CVE where the CVSS string doesn't match the description. Thanks, Doge.

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.

nvd.nist.gov/vuln/detail/cve-2

##

cR0w@infosec.exchange at 2026-09-18T18:38:34.000Z ##

Oh look, yet another sev:CRIT CVE where the CVSS string doesn't match the description. Thanks, Doge.

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.

nvd.nist.gov/vuln/detail/cve-2

##

CVE-2026-93688
(7.5 HIGH)

EPSS: 0.40%

updated 2026-09-18T18:31:55

2 posts

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /generate endpoint and submit arbitrary bootstrap_room values to exhaust prefill process memory until out-of-memory termination.

thehackerwire@mastodon.social at 2026-09-18T17:05:18.000Z ##

🟠 CVE-2026-93688 - High (7.5)

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /gene...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T17:05:18.000Z ##

🟠 CVE-2026-93688 - High (7.5)

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /gene...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93606
(10.0 CRITICAL)

EPSS: 0.52%

updated 2026-09-18T18:18:31.267000

2 posts

vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps `then`/`catch` rejection slots that hold a function, and the sandbox-side `Symbol.species`/`

CVE-2026-90999
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-18T17:49:08.457000

2 posts

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.

sayzard@mastodon.sayzard.org at 2026-09-18T14:44:00.000Z ##

PhantomFix: A fake bug to Sentry Seer gets a coding agent to run attacker code

CERT/CC는 Sentry Seer가 이슈를 코딩 에이전트에 자동으로 넘기도록 설정된 경우, 공개 DSN으로 제출한 조작된 오류 이벤트가 에이전트 프롬프트에 유입되는 취약점(CVE-2026-90999)을 공개했습니다. 공격자는 예외 메시지·스택 트레이스·breadcrumb 등 텔레메트리 필드를 이용해 가짜 버그 분석을 만들고, 코딩 에이전트가 공격자 제어 패키지를 내려받아 실행하도록 유도할 수 있습니다. 그 결과 PR 검토 이전에 연결된 저장소에 접근 가능한 에이전트 실행 환경에서 임의 코드 실행이 가능할 수 있습니다. 현재 공급업체 패치 정보는 없으므로 Seer의 자동 re...

kb.cert.org/vuls/id/212479

##

_r_netsec@infosec.exchange at 2026-09-17T14:13:04.000Z ##

CVE-2026-90999: A fabricated Sentry bug report can make Seer's coding agent run attacker code agyn.io/blog/sentry-seer-autof

##

CVE-2026-92943
(8.1 HIGH)

EPSS: 0.27%

updated 2026-09-18T17:48:19.003000

1 posts

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages that the device processes as authentic, via a certificate issued for an unrelated ho

thehackerwire@mastodon.social at 2026-09-17T21:00:31.000Z ##

🟠 CVE-2026-92943 - High (8.1)

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61672
(7.1 HIGH)

EPSS: 0.20%

updated 2026-09-18T17:14:32

1 posts

## Summary Capsule lets a cluster administrator forbid specific metadata keys that tenant owners must not place on their own resources: `Tenant.spec.namespaceOptions.forbiddenLabels` / `forbiddenAnnotations` (namespaces), `Tenant.spec.serviceOptions.forbiddenLabels` / `forbiddenAnnotations` (Services), and the cluster-wide forbidden worker-node labels/annotations. These lists are an isolation con

hugovalters@mastodon.social at 2026-09-18T23:05:34.000Z ##

CVE-2026-61672 - Policy bypass vulnerability in Capsule for Kubernetes allows metadata restriction evasion. CVSS 7.1. Update to 0.13.7 now. #CVE #Kubernetes #infosec

valtersit.com/cve/CVE-2026-616

##

CVE-2026-84383
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-09-18T16:17:11.853000

2 posts

libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplicate Alpha planes with different bit depths to m_storage. HeifPixelImage::scale_nearest_neighbor() in libheif/image/pixelimage.cc allocates the destination Alpha pla

e_nomem@hachyderm.io at 2026-09-19T17:15:33.000Z ##

@paul @arda AVIF is a specific profile/subtype of HEIF. Mastodon uses libvips to handle images and libvips uses libheif to handle both HEIF and AVIF.

libheif was disabled in mastodon 4.7.2 due to unspecified security issues but it's probably because of CVE-2026-84383

##

e_nomem@hachyderm.io at 2026-09-19T17:15:33.000Z ##

@paul @arda AVIF is a specific profile/subtype of HEIF. Mastodon uses libvips to handle images and libvips uses libheif to handle both HEIF and AVIF.

libheif was disabled in mastodon 4.7.2 due to unspecified security issues but it's probably because of CVE-2026-84383

##

CVE-2026-93603
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-09-18T15:32:25

2 posts

vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.g. `fn()`, a detached method, `fn.call()`, `fn.apply(undefined)`, `Reflect.apply(fn, undefined, [])`, or `fn.bind()()` — the undefined receiver is passed straight

CVE-2026-93592
(7.5 HIGH)

EPSS: 0.38%

updated 2026-09-18T15:32:24

2 posts

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.

thehackerwire@mastodon.social at 2026-09-18T15:05:58.000Z ##

🟠 CVE-2026-93592 - High (7.5)

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T15:05:58.000Z ##

🟠 CVE-2026-93592 - High (7.5)

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93591
(7.6 HIGH)

EPSS: 0.29%

updated 2026-09-18T15:32:24

2 posts

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can inject SQL via inline HTML span tags in the getGraph endpoint to execute arbitrary queries on the read-write database and exfiltrate private data across n

thehackerwire@mastodon.social at 2026-09-18T15:05:51.000Z ##

🟠 CVE-2026-93591 - High (7.6)

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T15:05:51.000Z ##

🟠 CVE-2026-93591 - High (7.6)

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93597
(7.7 HIGH)

EPSS: 0.33%

updated 2026-09-18T15:32:24

2 posts

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or loopback IPv4 payloads to reach internal services and cloud metadata endpoints.

thehackerwire@mastodon.social at 2026-09-18T15:05:34.000Z ##

🟠 CVE-2026-93597 - High (7.7)

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T15:05:34.000Z ##

🟠 CVE-2026-93597 - High (7.7)

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93491
(7.5 HIGH)

EPSS: 0.44%

updated 2026-09-18T15:32:17

2 posts

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.

thehackerwire@mastodon.social at 2026-09-18T14:03:37.000Z ##

🟠 CVE-2026-93491 - High (7.5)

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T14:03:37.000Z ##

🟠 CVE-2026-93491 - High (7.5)

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-39964
(3.3 LOW)

EPSS: 0.79%

updated 2026-09-18T15:31:06

4 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates

1 repos

https://github.com/n1k0oowang/CVE-2025-39964_EXP

AAKL at 2026-09-18T15:47:33.739Z ##

New.

CISA Adds Two Known Exploited Vulnerabilities to Catalog.

CVE-2025-39964 Linux Kernel Race Condition Vulnerability cve.org/CVERecord?id=CVE-2025-

CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability cve.org/CVERecord?id=CVE-2026-

##

secdb at 2026-09-18T15:00:11.403Z ##

🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-39964 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/0f28c4; git.kernel.org/stable/c/e4c1ec; git.kernel.org/stable/c/1f323a; git.kernel.org/stable/c/7c4491; git.kernel.org/stable/c/9aee87; git.kernel.org/stable/c/45bcf6; git.kernel.org/stable/c/1b34cb ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-53266 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/bf84ad; git.kernel.org/stable/c/76280b; git.kernel.org/stable/c/b7e919; git.kernel.org/stable/c/afd64b; git.kernel.org/stable/c/153ea9; git.kernel.org/stable/c/b18675; git.kernel.org/stable/c/c9b5ff; git.kernel.org/stable/c/67ba97 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-09-18T15:47:33.000Z ##

New.

CISA Adds Two Known Exploited Vulnerabilities to Catalog.

CVE-2025-39964 Linux Kernel Race Condition Vulnerability cve.org/CVERecord?id=CVE-2025-

CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #Linux #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-18T15:00:11.000Z ##

🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-39964 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/0f28c4; git.kernel.org/stable/c/e4c1ec; git.kernel.org/stable/c/1f323a; git.kernel.org/stable/c/7c4491; git.kernel.org/stable/c/9aee87; git.kernel.org/stable/c/45bcf6; git.kernel.org/stable/c/1b34cb ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-53266 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/bf84ad; git.kernel.org/stable/c/76280b; git.kernel.org/stable/c/b7e919; git.kernel.org/stable/c/afd64b; git.kernel.org/stable/c/153ea9; git.kernel.org/stable/c/b18675; git.kernel.org/stable/c/c9b5ff; git.kernel.org/stable/c/67ba97 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260918 #cisa20260918 #cve_2025_39964 #cve_2026_53266 #cve202539964 #cve202653266

##

CVE-2026-17086
(8.8 HIGH)

EPSS: 0.89%

updated 2026-09-18T15:17:06.153000

1 posts

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this

thehackerwire@mastodon.social at 2026-09-18T07:04:42.000Z ##

🟠 CVE-2026-17086 - High (8.8)

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for auth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93605
(10.0 CRITICAL)

EPSS: 0.38%

updated 2026-09-18T14:19:12.453000

2 posts

vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.

CVE-2026-20192
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-09-18T14:17:16.023000

5 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CV

security_crawler_carl at 2026-09-18T14:02:42.144Z ##

Reward: You've received the Cursed Amulet of Maximum CVSS — it goes great with your existing collection of regrets.

ionix.io/threat-center/cve-202

(3/3)

##

security_crawler_carl at 2026-09-18T14:02:41.867Z ##

🏆 New Achievement! Perfect Score, Perfect Doom!

Splendid news, brave adventurer! Your quest to secure the network is absolutely still possible — and to help you on your way, Cisco has gifted the world CVE-2026-20192, a shiny CVSS 10.0 access control bypass in Cisco Identity Services Engine and ISE Passive Identity Connector. Maximum score! Like a Tamagotchi dying the moment you crack the box open.

Cisco caught this one themselves during an internal review, which is the good news. (1/3)

##

security_crawler_carl@infosec.exchange at 2026-09-18T14:02:42.000Z ##

Reward: You've received the Cursed Amulet of Maximum CVSS — it goes great with your existing collection of regrets.

ionix.io/threat-center/cve-202

#CyberSecurity #CVE #Cisco #CriticalVulnerability #AccessControl #PatchedOrPerish (3/3)

##

security_crawler_carl@infosec.exchange at 2026-09-18T14:02:41.000Z ##

🏆 New Achievement! Perfect Score, Perfect Doom!

Splendid news, brave adventurer! Your quest to secure the network is absolutely still possible — and to help you on your way, Cisco has gifted the world CVE-2026-20192, a shiny CVSS 10.0 access control bypass in Cisco Identity Services Engine and ISE Passive Identity Connector. Maximum score! Like a Tamagotchi dying the moment you crack the box open.

Cisco caught this one themselves during an internal review, which is the good news. (1/3)

##

beyondmachines1@infosec.exchange at 2026-09-17T14:01:13.000Z ##

Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days

Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.

**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-28198
(8.8 HIGH)

EPSS: 0.20%

updated 2026-09-18T12:31:28

2 posts

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. Successful exploitation grants the attacker an unrestricted root shell with full control over the Flex appliance host and all hosted containers, completely compr

thehackerwire@mastodon.social at 2026-09-18T14:03:56.000Z ##

🟠 CVE-2026-28198 - High (8.8)

An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could bypass the cryptographic signature
verification step of a privileged support command by supplying a
specially formed access credential. Successful...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T14:03:56.000Z ##

🟠 CVE-2026-28198 - High (8.8)

An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could bypass the cryptographic signature
verification step of a privileged support command by supplying a
specially formed access credential. Successful...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85410
(8.1 HIGH)

EPSS: 0.31%

updated 2026-09-18T09:31:24

2 posts

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-leve

thehackerwire@mastodon.social at 2026-09-18T14:05:34.000Z ##

🟠 CVE-2026-85410 - High (8.1)

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T14:05:34.000Z ##

🟠 CVE-2026-85410 - High (8.1)

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6205
(8.1 HIGH)

EPSS: 0.32%

updated 2026-09-18T09:31:21

2 posts

An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks.

thehackerwire@mastodon.social at 2026-09-18T14:05:05.000Z ##

🟠 CVE-2026-6205 - High (8.1)

An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct den...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T14:05:05.000Z ##

🟠 CVE-2026-6205 - High (8.1)

An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct den...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67101
(9.3 CRITICAL)

EPSS: 0.27%

updated 2026-09-18T09:31:08

1 posts

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet.

offseq@infosec.exchange at 2026-09-18T12:00:28.000Z ##

CVE-2026-67101: CRITICAL SSRF in HCL BigFix Service Management v23 (CVSS 9.3). Unauthenticated attackers can access internal systems. No patch yet — restrict service and monitor requests. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #Vuln #Infosec

##

CVE-2026-67100
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-09-18T09:31:08

2 posts

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations.

DailyCyberSecurity@infosec.exchange at 2026-09-18T09:26:48.000Z ##

HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.

#HCLBigFix #Cybersecurity #CVE202667100 #Vulnerability #InfoSec

securityonline.info/hcl-bigfix

##

offseq@infosec.exchange at 2026-09-18T09:00:25.000Z ##

CVE-2026-67100: HCL BigFix Service Management v23 faces CRITICAL SQL injection & cross-tenant data exposure (CVSS 9.8). Authenticated attackers can access PII across orgs. No patch yet — restrict access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #SQLi #Infosec

##

CVE-2026-18912
(7.7 HIGH)

EPSS: 1.50%

updated 2026-09-18T06:32:11

1 posts

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

thehackerwire@mastodon.social at 2026-09-18T07:04:23.000Z ##

🟠 CVE-2026-18912 - High (7.7)

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93456
(8.2 HIGH)

EPSS: 0.15%

updated 2026-09-18T03:30:28

1 posts

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing unescaped content that renders to all visitors, enabling stored cross-site scripting attacks.

thehackerwire@mastodon.social at 2026-09-18T03:03:10.000Z ##

🟠 CVE-2026-93456 - High (8.2)

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93450
(7.5 HIGH)

EPSS: 0.66%

updated 2026-09-18T00:31:21

1 posts

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI specifications, causing fatal stack overflow that terminates the process and all in-flight requests.

thehackerwire@mastodon.social at 2026-09-18T03:03:20.000Z ##

🟠 CVE-2026-93450 - High (7.5)

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85889
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-09-18T00:31:16

5 posts

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

AAKL at 2026-09-18T15:40:57.616Z ##

If you missed this, Microsoft patched this vulnerability yesterday:

CVE-2026-85889: Azure AI Foundry Elevation of Privilege Vulnerability (new) msrc.microsoft.com/update-guid

More:

The Hacker News: Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation thehackernews.com/2026/09/micr @thehackernews

##

cyberworldops at 2026-09-18T15:00:01.549Z ##

Microsoft patched CVE-2026-85889 in Azure AI Foundry, a missing authentication for critical function flaw with CVSS 10.0 enabling unauthenticated remote privilege escalation. MSRC reports full mitigation, but the network-accessible, no-auth vector makes tenant privilege review and log auditing critical.

cyberworldops.eu/en/azure-ai-f

##

AAKL@infosec.exchange at 2026-09-18T15:40:57.000Z ##

If you missed this, Microsoft patched this vulnerability yesterday:

CVE-2026-85889: Azure AI Foundry Elevation of Privilege Vulnerability (new) msrc.microsoft.com/update-guid

More:

The Hacker News: Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation thehackernews.com/2026/09/micr @thehackernews #infosec #vulnerability #Microsoft #Azure

##

cyberworldops@infosec.exchange at 2026-09-18T15:00:01.000Z ##

Microsoft patched CVE-2026-85889 in Azure AI Foundry, a missing authentication for critical function flaw with CVSS 10.0 enabling unauthenticated remote privilege escalation. MSRC reports full mitigation, but the network-accessible, no-auth vector makes tenant privilege review and log auditing critical. #AzureSecurity #PrivilegeEscalation #AiSecurity

cyberworldops.eu/en/azure-ai-f

##

offseq@infosec.exchange at 2026-09-18T00:00:34.000Z ##

CVE-2026-85889 | CRITICAL flaw in Azure AI Foundry: missing authentication for a critical function (CVSS 10) allows remote privilege escalation. Microsoft patched this cloud vulnerability — verify your environment per MSRC: radar.offseq.com/threat/cve-20 #OffSeq #Azure #Infosec #CVE202685889

##

CVE-2026-13584
(0 None)

EPSS: 0.13%

updated 2026-09-18T00:16:53.720000

1 posts

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Dig

cyberworldops@infosec.exchange at 2026-09-18T02:40:00.000Z ##

Mitsubishi Electric CC-Link IE TSN is affected by CVE-2026-13584, CWE-924 message integrity failure. An adjacent attacker can inject crafted packets under timing conditions to tamper with OT traffic. It matters for ICS integrity and safety assumptions on trusted segments. #IcsSecurity #OtSecurity #MessageIntegrity

cyberworldops.eu/en/mitsubishi

##

CVE-2026-92956
(10.0 CRITICAL)

EPSS: 0.40%

updated 2026-09-17T20:18:59.730000

1 posts

vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox code receives that raw host error, walks from the h

CVE-2026-92951
(9.9 CRITICAL)

EPSS: 0.37%

updated 2026-09-17T20:18:59.610000

1 posts

vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute unauthorized host packages in the host context.

CVE-2026-92946
(10.0 CRITICAL)

EPSS: 0.59%

updated 2026-09-17T20:18:59.483000

1 posts

vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands via child_process.

CVE-2026-92940
(10.0 CRITICAL)

EPSS: 0.34%

updated 2026-09-17T20:18:59.213000

1 posts

vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin loader wraps host modules in a read-only proxy, but method calls such as Agent.prototype.on() are forwarded to the underlying host object, so sandbox code can register a listener for the agent's 'free' event. When an unr

CVE-2026-92919
(8.1 HIGH)

EPSS: 0.38%

updated 2026-09-17T20:18:58.840000

1 posts

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the configured storage directory and overwrite arbitrary files accessible to the server process.

thehackerwire@mastodon.social at 2026-09-17T14:02:33.000Z ##

🟠 CVE-2026-92919 - High (8.1)

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54752
(9.6 CRITICAL)

EPSS: 0.35%

updated 2026-09-17T20:16:52.877000

1 posts

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_data function in tests/pickle_operations.py. An unauthenticated contributor can change USE_LOCAL_KNOWN_SLUGS in tests/test_configuration.py and supply a c

thehackerwire@mastodon.social at 2026-09-17T21:01:39.000Z ##

🔴 CVE-2026-54752 - Critical (9.6)

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-28326
(8.8 HIGH)

EPSS: 0.55%

updated 2026-09-17T18:32:05

2 posts

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

undercodenews@mastodon.social at 2026-09-19T13:24:24.000Z ##

SolarWinds Patches Critical Access Rights Manager Flaw That Could Open the Door to Unauthenticated Remote Code Execution + Video

Introduction SolarWinds has patched a serious security vulnerability in its Access Rights Manager (ARM) platform that could potentially allow an attacker to execute malicious code remotely without first authenticating to the affected system. Tracked as CVE-2026-28326, the vulnerability is tied to a hard-coded static key and affects Access…

undercodenews.com/solarwinds-p

##

Analyst207@mastodon.social at 2026-09-19T12:04:27.000Z ##

SolarWinds Fixes Hard-Coded Key Flaw in Access Rights Manager

SolarWinds has patched a high-severity vulnerability in its Access Rights Manager software, known as CVE-2026-28326, which could have allowed hackers to remotely execute code without authentication due to a hard-coded static key. The flaw, scoring 8.8 out of 10 in severity, has been fixed in ARM 2026.2.1, and users are…

osintsights.com/solarwinds-fix

#Solarwinds #AccessRightsManager #Cve202628326 #RemoteCodeExecution #UnauthenticatedRce

##

CVE-2026-92941
(10.0 CRITICAL)

EPSS: 0.27%

updated 2026-09-17T16:18:34.520000

1 posts

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-co

CVE-2026-79752
(0 None)

EPSS: 0.46%

updated 2026-09-17T16:17:44.693000

1 posts

CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passe

1 repos

https://github.com/abraxas/CVE-2026-79752

offseq@infosec.exchange at 2026-09-18T01:30:23.000Z ##

CVE-2026-79752: CakePHP <4.5.12, 4.6.0-4.6.4, 5.0.0-5.1.8, 5.2.0-5.2.13, 5.3.0-5.3.6 FunctionsBuilder SQL injection risk! CRITICAL severity — patch ASAP or avoid user input in $dataType, $part, $unit. radar.offseq.com/threat/databa #OffSeq #CakePHP #SQLi #Infosec

##

CVE-2026-92950
(8.6 HIGH)

EPSS: 0.22%

updated 2026-09-17T15:32:35

1 posts

vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.

CVE-2026-92939
(9.9 CRITICAL)

EPSS: 0.53%

updated 2026-09-17T15:32:28

1 posts

vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, but its callable exports still execute with host-process authority. Sandboxed JavaScript can therefore call crypto.setEngine() with a filesystem path to an attacker-supplied native library (for example, one bundled in an u

CVE-2026-92938
(9.9 CRITICAL)

EPSS: 0.42%

updated 2026-09-17T15:32:28

1 posts

vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver treats any request starting with 'node:' as a core-module request and t

CVE-2026-92960
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-09-17T15:32:27

1 posts

vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host process DNS resolver globally, redirecting all subsequent host DNS queries through an attacker-controlled resolver.

CVE-2026-92935
(9.0 None)

EPSS: 0.50%

updated 2026-09-17T15:32:26

1 posts

vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === 'object' && requireOpts !== null`, so an array-shaped `require` value (for example `require: []`) satisfies the guard that is meant to reject nesting without an explicit require configuration. `makeResolverFromLegacyOptions()`

CVE-2026-92944
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-09-17T15:32:26

1 posts

vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an async function that returns a Promise with an attacker-controlled constructor Symbol.species, allowing them to reach the host Function constr

CVE-2026-92957
(9.9 CRITICAL)

EPSS: 0.49%

updated 2026-09-17T15:32:26

1 posts

vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy such as `new NodeVM({ require: { builtin: ['*', '-

CVE-2026-92918
(8.8 HIGH)

EPSS: 0.35%

updated 2026-09-17T15:32:24

1 posts

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and replay them as bearer credentials for full user access.

thehackerwire@mastodon.social at 2026-09-17T14:02:24.000Z ##

🟠 CVE-2026-92918 - High (8.8)

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and repla...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92953
(10.0 CRITICAL)

EPSS: 0.34%

updated 2026-09-17T15:32:22

1 posts

vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing host-created typed arrays to observe attacker-controlled properties after VM.run() returns.

CVE-2026-92947
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-09-17T15:32:21

1 posts

vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.

CVE-2026-81481
(7.5 HIGH)

EPSS: 0.53%

updated 2026-09-17T15:32:18

1 posts

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

thehackerwire@mastodon.social at 2026-09-17T14:02:43.000Z ##

🟠 CVE-2026-81481 - High (7.5)

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92955
(10.0 CRITICAL)

EPSS: 0.62%

updated 2026-09-17T15:17:01.040000

1 posts

vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with process context, bypassing code generation restrictions.

CVE-2026-92934
(9.0 CRITICAL)

EPSS: 0.74%

updated 2026-09-17T15:17:00.520000

1 posts

vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to access unsanitized host proxies embedded in the errors array, enabling full remote code execution and process information dis

CVE-2026-92954
(8.6 HIGH)

EPSS: 0.34%

updated 2026-09-17T14:18:01.430000

1 posts

vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into the sandbox are not marked as handled at the bridge boundary; only Promises created inside the sandbox are wrapped with a rejection-swallowing handler (lib/setup-sandbox.js), and the bridge only installs host-side rejection sanitizers when sandbox co

CVE-2026-15688(CVSS UNKNOWN)

EPSS: 0.12%

updated 2026-09-17T09:33:03

1 posts

Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the executable module in memory, and thereby may be able to view, tamper with, destroy, or delete control programs.

cyberworldops@infosec.exchange at 2026-09-18T05:10:00.000Z ##

Mitsubishi GX Works3 and bundled Motion Control Settings allow local bypass of block-password auth via in-memory patching (CVE-2026-15688). It matters because it breaks project protection for PLC logic, enabling undetected modification. #OtSecurity #PlcSecurity #VulnerabilityManagement

cyberworldops.eu/en/mitsubishi

##

CVE-2026-58704
(8.8 HIGH)

EPSS: 0.21%

updated 2026-09-17T04:17:54.930000

2 posts

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

kuketzblog@social.tchncs.de at 2026-09-18T06:19:59.000Z ##

Google sieht Hinweise auf eine begrenzte, gezielte Ausnutzung von
CVE-2026-58704 auf Pixel-Geräten. Die Schwachstelle steckt im Modem
und ermöglicht eine Rechteausweitung. Der September-Patchlevel
2026-09-05 behebt die Lücke.

source.android.com/docs/securi

#Android #Pixel #ITSecurity

##

DarkWebInformer@infosec.exchange at 2026-09-17T17:33:47.000Z ##

🚨 Google confirms Pixel phones targeted in zero-click zero-day attacks

Google has patched CVE-2026-58704, a high-severity vulnerability in Pixel phones' cellular modem that the company says was already under "limited, targeted exploitation."

The flaw is caused by a logic error that can allow an attacker to bypass permission checks and escalate privileges beyond the modem's isolated environment.

Most importantly, exploitation requires no interaction from the victim.

No malicious link needs to be clicked and no file needs to be opened, making it a zero-click attack.

Google has not disclosed:

• Who carried out the attacks
• How many Pixel owners were targeted
• How the victims were selected
• What tools or spyware may have been deployed

CISA has added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog and set a September 19 remediation deadline for affected federal systems.

Google says Pixel devices with the September 5, 2026 security patch level or later are protected.

Pixel owners should update their devices immediately.

Source: techcrunch.com/2026/09/16/goog

##

CVE-2026-76460
(10.0 CRITICAL)

EPSS: 0.78%

updated 2026-09-16T21:33:00

14 posts

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized acce

1 repos

https://github.com/S3v3n-JG/CVE-2026-76460

tierrasapiens@mastodon.social at 2026-09-19T22:57:11.000Z ##

🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Cisco Zero-Day Highlights API Endpoint Authentication Issues
🔗 darkreading.com/vulnerabilitie

The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.

##

security_crawler_carl at 2026-09-19T15:43:41.269Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

sayzard@mastodon.sayzard.org at 2026-09-19T10:41:44.000Z ##

Cisco Identity Services Engine Authentication Bypass Vulnerability

Cisco Identity Services Engine(ISE) 및 ISE Passive Identity Connector에서 인증되지 않은 원격 공격자가 API 엔드포인트의 인증 우회를 통해 관리 인터페이스에 접근할 수 있는 CVE-2026-76460이 공개됐다. CVSS 10.0의 Critical 취약점이며, Cisco는 실제 공격에 악용되고 있음을 인지하고 있다. 공격 성공 시 루트 권한의 명령 실행까지 가능해 로그 증거가 삭제·은닉될 수 있으므로, ISE 접근 로그뿐 아...

sec.cloudapps.cisco.com/securi

##

netsecio@mastodon.social at 2026-09-18T15:43:36.000Z ##

📰 Cisco ISE Zero-Day (CVSS 10.0) Under Active Attack, Bypasses Auth

Cisco warns of a critical (CVSS 10.0) zero-day in Identity Services Engine (ISE) actively exploited in the wild. The flaw, CVE-2026-76460, allows full authentication bypass. CISA added to KEV catalog. Patch immediately! #Cisco #ZeroDay #CyberSecurity

🔗 cyber.netsecops.io/articles/ci

##

cyclone at 2026-09-18T14:20:41.864Z ##

Cisco ISE zero-day CVE-2026-76460 is being actively exploited.

The CVSS 10.0 flaw allows remote, unauthenticated attackers to bypass authentication and potentially execute commands with root privileges.

Cisco says there is no complete workaround and recommends upgrading immediately.

Read more here:
forum.hashpwn.net/post/16740

##

PC_Fluesterer@social.tchncs.de at 2026-09-18T12:47:45.000Z ##

Noch ein Cisco Zero-Day (perfekte 10) unter Angriff

Ja, Cisco-Evangelisten müssen dieser Tage ganz stark sein. Kurz nach dem Desaster mit dem "sicheren" E-Mail-Gateway ist die nächste "Sicherheitslücke" aufgefallen, weil sie bereits angegriffen wird. CVE-2026-76460 hat eine perfekte 10 (von 10) als Risiko-Einstufung erhalten. Die "Sicherheitslücke" steckt in der Cisco Identity Services Engine (ISE). Wie der Name nahelegt, ist die Aufgabe dieser Funktion, Benutzer/innen zu identifizieren und dann für bestimmte Tätigkeiten zu autorisieren. Die Schwachstelle entsteht durch, ich zitiere: "... insufficient authentication control ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #backdoor #closedsource #exploits #hersteller #identität #sicherheit #UnplugTrump #zeroday #cisco

##

security_crawler_carl@infosec.exchange at 2026-09-19T15:43:41.000Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

cyclone@infosec.exchange at 2026-09-18T14:20:41.000Z ##

Cisco ISE zero-day CVE-2026-76460 is being actively exploited.

The CVSS 10.0 flaw allows remote, unauthenticated attackers to bypass authentication and potentially execute commands with root privileges.

Cisco says there is no complete workaround and recommends upgrading immediately.

Read more here:
forum.hashpwn.net/post/16740

#Cisco #CVE #CyberSecurity #InfoSec #hashpwn

##

PC_Fluesterer@social.tchncs.de at 2026-09-18T12:47:45.000Z ##

Noch ein Cisco Zero-Day (perfekte 10) unter Angriff

Ja, Cisco-Evangelisten müssen dieser Tage ganz stark sein. Kurz nach dem Desaster mit dem "sicheren" E-Mail-Gateway ist die nächste "Sicherheitslücke" aufgefallen, weil sie bereits angegriffen wird. CVE-2026-76460 hat eine perfekte 10 (von 10) als Risiko-Einstufung erhalten. Die "Sicherheitslücke" steckt in der Cisco Identity Services Engine (ISE). Wie der Name nahelegt, ist die Aufgabe dieser Funktion, Benutzer/innen zu identifizieren und dann für bestimmte Tätigkeiten zu autorisieren. Die Schwachstelle entsteht durch, ich zitiere: "... insufficient authentication control ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #backdoor #closedsource #exploits #hersteller #identität #sicherheit #UnplugTrump #zeroday #cisco

##

oversecurity@mastodon.social at 2026-09-18T12:00:10.000Z ##

Cisco ISE Vulnerability With CVSS 10.0 Score Under Active Attack

Cisco patched CVE-2026-76460, a critical Cisco Identity Services Engine (ISE) bug under active attack. CISA lists it as an exploited vulnerability.

🔗️ [Thecyberexpress] link.is.it/LOu95i

##

ottoto2017@prattohome.com at 2026-09-18T08:03:46.000Z ##

「Cisco、ISE認証バイパスの新たなゼロデイ脆弱性(CVSS 10.0)が現在進行中の攻撃で悪用されていると警告 」: #TheHackerNews

「Ciscoは、Identity Services Engine(ISE)に影響を与える新たな最高レベルのセキュリティ脆弱性が発見され、現在悪用されていると警告した。

CVE-2026-76460 (CVSSスコア:10.0)として追跡されているこの脆弱性により 、認証されていないリモート攻撃者が認証を回避できる可能性がある。

「この脆弱性は、APIエンドポイントにおける認証制御の不備に起因するものです」とシスコは述べています。「攻撃者は、細工されたリクエストを影響を受けるAPIエンドポイントに送信することで、この脆弱性を悪用する可能性があります。攻撃が成功すると、攻撃者はWebベースの管理インターフェースを迂回して、影響を受けるデバイスへの不正アクセスを取得できる可能性があります。」 」

thehackernews.com/2026/09/cisc

#prattohome

##

youranonnewsirc@nerdculture.de at 2026-09-18T04:26:20.000Z ##

Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.

#Cybersecurity #TechNews #Geopolitics

##

threatnoir@infosec.exchange at 2026-09-18T03:05:51.000Z ##

⚠️ CRITICAL: Cisco alerts customers to second actively exploited zero-day in as many days

Cisco ISE zero-day CVE-2026-76460 is actively exploited in the wild. Remote attackers can bypass authentication, take full device control, modify network policies, and steal credentials. If you run ISE, this is a direct threat to your network perimeter and access controls.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

beyondmachines1@infosec.exchange at 2026-09-17T14:01:13.000Z ##

Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days

Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.

**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-89082(CVSS UNKNOWN)

EPSS: 0.51%

updated 2026-09-16T21:32:55

1 posts

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.

DailyCyberSecurity@infosec.exchange at 2026-09-17T14:52:01.000Z ##

HP released updates to fix critical HP Advance vulnerabilities (CVE-2026-89082). Patch these HP Advance vulnerabilities to stop remote code execution.

#HP #HPAdvance #CVE202689082 #Cybersecurity #Vulnerability

securityonline.info/hp-advance

##

CVE-2026-20329
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-09-16T21:32:50

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

AAKL at 2026-09-18T16:27:33.387Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity

##

AAKL@infosec.exchange at 2026-09-18T16:27:33.000Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec

##

CVE-2026-20324
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-09-16T21:32:50

1 posts

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerabilit

guru@thecybersecguru.com at 2026-09-18T12:30:57.000Z ##

Cisco FMC CVE-2026-20324: critical sftunnel root RCE explained

Cisco FMC CVE-2026-20324 is a critical CVSS 9.9 sftunnel flaw enabling arbitrary file writes and root command execution. Learn the impact and fix

thecybersecguru.com/news/cisco

##

CVE-2026-77179
(0 None)

EPSS: 0.16%

updated 2026-09-16T20:38:33.883000

5 posts

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

1 repos

https://github.com/HORKimhab/CVE-2026-77179

sayzard@mastodon.sayzard.org at 2026-09-19T11:40:29.000Z ##

Guest to host: escaping Docker's hypervisor

Docker의 macOS용 하이퍼바이저(VMM)에서 컨테이너가 호스트 파일시스템을 임의로 읽고 쓸 수 있는 샌드박스 탈출 취약점 CVE-2026-77179가 공개되었습니다. virtio-fs 서버가 파일의 inode 기반 재확인에 실패한 뒤 저장된 경로 문자열로 폴백하는 과정에서, 공격자가 부모 디렉터리를 심볼릭 링크로 교체하면 마운트 범위 밖의 호스트 경로로 접근할 수 있었습니다. Docker Sandboxes 0.42.0 및 Docker Desktop 4.88.0에서 수정됐으며, 특히 Docker Desktop에서 Docker VMM을 활성화한 macOS 사용자는 즉시 업데이트해야 합니다. 에이전트...

accomplish.ai/blog/escaping-do

##

_r_netsec at 2026-09-19T06:28:04.750Z ##

CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes) accomplish.ai/blog/escaping-do

##

_r_netsec@infosec.exchange at 2026-09-19T06:28:04.000Z ##

CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes) accomplish.ai/blog/escaping-do

##

ottoto2017@prattohome.com at 2026-09-18T07:52:46.000Z ##

「Dockerサンドボックスの重大な脆弱性により、悪意のあるゲストコードがmacOSホストファイルを読み取り、変更することが可能になる。 」: #TheHackerNews

「Dockerは9月15日のセキュリティ発表 で、macOS上のDocker Sandboxes 仮想マシン内で実行されている悪意のあるコードが、 共有されているプロジェクトディレクトリから脱出し、ホスト上の他の場所にあるファイルを読み取ったり変更したりする可能性があると警告した 。

このエスケープ処理は、仮想マシンを実行するホストアカウントの権限で実行されます。この脆弱性( CVE-2026-77179 )は、深刻度が「重大」と評価されており、macOS 版のバージョン 0.28.0 から 0.42.0 まで(0.42.0 は含まない)に影響があり、 9 月 7 日にリリースされたバージョン 0.42.0 で修正されました。 」

thehackernews.com/2026/09/crit

#prattohome

##

guru@thecybersecguru.com at 2026-09-18T06:46:02.000Z ##

Critical Docker Sandboxes Flaws Let AI Agents Escape MicroVMs to Hijack Hosts (CVE-2026-77179 & CVE-2026-79994)

Critical Docker Sandboxes flaws CVE-2026-77179 and CVE-2026-79994 can let malicious AI agents escape microVM isolation and access the host system

thecybersecguru.com/news/docke

##

CVE-2026-20306
(9.1 CRITICAL)

EPSS: 1.37%

updated 2026-09-16T18:32:09

2 posts

A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this

security_crawler_carl at 2026-09-19T15:43:41.269Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-09-19T15:43:41.000Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

CVE-2026-20305
(9.1 CRITICAL)

EPSS: 1.37%

updated 2026-09-16T18:32:04

2 posts

A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to&nbsp;root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could

security_crawler_carl at 2026-09-19T15:43:41.269Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-09-19T15:43:41.000Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

CVE-2026-91843
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-09-16T15:31:14

9 posts

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

1 repos

https://github.com/HORKimhab/CVE-2026-91843

security_crawler_carl at 2026-09-18T20:55:25.862Z ##

Two companion curses arrived earlier: an auth bypass in August and a heap overflow in VPN certificate decoding in September.

INVENTORY PENALTY: Your management plane is now haunted. Patch Check Point Security Management Server immediately to close CVE-2026-91843 and its critical siblings.

Reward: You've received the Debuffed Robe of Five Failures — Armor Class: negative five. The "found internally, no exploitation detected" enchantment is fading fast. (2/3)

##

security_crawler_carl at 2026-09-18T20:55:25.725Z ##

🏆 New Achievement! Stack Overflow, Stack Underdelivery!

ITEM ACQUIRED: Cursed Login Request (very long username, -9.8 integrity, equips in zero hands). Check Point's Security Management Server has taken its fifth critical unauthenticated hit since July — CVE-2026-91843, a 9.8-rated stack overflow in the login handler that lets attackers execute code as root before a single password is checked. Censys confirms the trigger: just send a comically oversized username. (1/3)

##

netsecio@mastodon.social at 2026-09-18T15:42:44.000Z ##

📰 Check Point Patches Critical RCE Flaw in Management Servers

Check Point patches critical RCE flaw (CVE-2026-91843, CVSS 9.8) in Security Management Servers. Unauthenticated attackers can gain root access via a long username. LivePatch is available. Restrict trusted client access now! #CyberSecurity #CheckPoin...

🔗 cyber.netsecops.io/articles/ch

##

security_crawler_carl@infosec.exchange at 2026-09-18T20:55:25.000Z ##

Two companion curses arrived earlier: an auth bypass in August and a heap overflow in VPN certificate decoding in September.

INVENTORY PENALTY: Your management plane is now haunted. Patch Check Point Security Management Server immediately to close CVE-2026-91843 and its critical siblings.

Reward: You've received the Debuffed Robe of Five Failures — Armor Class: negative five. The "found internally, no exploitation detected" enchantment is fading fast. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-09-18T20:55:25.000Z ##

🏆 New Achievement! Stack Overflow, Stack Underdelivery!

ITEM ACQUIRED: Cursed Login Request (very long username, -9.8 integrity, equips in zero hands). Check Point's Security Management Server has taken its fifth critical unauthenticated hit since July — CVE-2026-91843, a 9.8-rated stack overflow in the login handler that lets attackers execute code as root before a single password is checked. Censys confirms the trigger: just send a comically oversized username. (1/3)

##

offseq@infosec.exchange at 2026-09-18T10:30:23.000Z ##

Check Point Security Mgmt & Log Server face CRITICAL stack buffer overflow (CVE-2026-91843). Remote, unauthenticated RCE as root possible. Patch now or restrict access, monitor for 'Username too long' login failures. radar.offseq.com/threat/new-ch #OffSeq #CheckPoint #Vuln #RCE

##

beyondmachines1@infosec.exchange at 2026-09-18T09:01:13.000Z ##

Critical Check Point Management Flaw Allows Unauthenticated Remote Root Access

Check Point issued an patch for a critical stack overflow vulnerability (CVE-2026-91843) in its Security Management and Log Servers that allows unauthenticated attackers to gain root-level code execution.

**If you run Check Point Security Management or Log Servers, make sure they are never reachable from the internet and restrict the Trusted Clients setting so only specific, known admin IP addresses can connect (use a VPN for remote access). Then apply the LivePatch fix released on September 16, 2026 to every management and log server, confirm it installed with `cplp list`, and check your logs for "Administrator failed to log in: Username too long" to spot attempted attacks.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-09-18T07:30:24.000Z ##

Check Point Security Mgmt & Log Server hit by CRITICAL RCE (CVE-2026-91843) via unauthenticated login. No active exploitation yet. Patch ASAP. Tanium (SQLi, RCE) & Kaspersky (Redis) also patched. radar.offseq.com/threat/check- #OffSeq #Vulnerability #RCE #PatchNow

##

youranonnewsirc@nerdculture.de at 2026-09-18T04:26:20.000Z ##

Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.

#Cybersecurity #TechNews #Geopolitics

##

CVE-2026-81642(CVSS UNKNOWN)

EPSS: 0.52%

updated 2026-09-16T09:30:28

1 posts

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerabili

1 repos

https://github.com/suominen/CVE-2026-81642

cyberworldops@infosec.exchange at 2026-09-17T20:30:00.000Z ##

NLnet Labs Unbound before 1.26.1 contains heap overflow CVE-2026-81642 in the DNSSEC validator via crafted DNSKEY with compression pointer into RDATA. Any resolver induced to query a malicious zone risks crash or potential RCE, exposing core DNS infrastructure. #Unbound #DnsSec #HeapOverflow

cyberworldops.eu/en/unbound-dn

##

CVE-2026-79994(CVSS UNKNOWN)

EPSS: 0.11%

updated 2026-09-16T00:32:32

1 posts

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary AF_UNIX socket outside the shared workspace. This can expose data or host-side cap

guru@thecybersecguru.com at 2026-09-18T06:46:02.000Z ##

Critical Docker Sandboxes Flaws Let AI Agents Escape MicroVMs to Hijack Hosts (CVE-2026-77179 & CVE-2026-79994)

Critical Docker Sandboxes flaws CVE-2026-77179 and CVE-2026-79994 can let malicious AI agents escape microVM isolation and access the host system

thecybersecguru.com/news/docke

##

CVE-2026-76461
(9.8 CRITICAL)

EPSS: 2.01%

updated 2026-09-15T12:47:32.497000

2 posts

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that co

4 repos

https://github.com/fevar54/CVE-2026-76461-Detection-Kit-

https://github.com/HORKimhab/CVE-2026-76461

https://github.com/S3v3n-JG/CVE-2026-76461

https://github.com/0xBlackash/CVE-2026-76461

hackmag at 2026-09-18T15:36:29.481Z ##

⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email

🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…

🔗 hackmag.com/news/cve-2026-7646

##

hackmag@infosec.exchange at 2026-09-18T15:36:29.000Z ##

⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email

🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…

🔗 hackmag.com/news/cve-2026-7646

#news

##

CVE-2026-89497
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-14T15:33:33

1 posts

In the Linux kernel, the following vulnerability has been resolved: orangefs: skip leading spaces before parsing client debug masks orangefs_prepare_cdm_array() sizes each client debug keyword buffer with strcspn(cds_head, " "), but then parses the keyword with %s. The %s conversion skips leading whitespace, while strcspn() does not. If a client debug entry starts with a space, the allocation c

hugovalters@mastodon.social at 2026-09-19T10:50:16.000Z ##

CVE-2026-89497: buffer overflow in Linux kernel orangefs debug parsing can lead to memory corruption. CVSS N/A but unpatched. Patch now if you run orangefs. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89510
(7.8 HIGH)

EPSS: 0.18%

updated 2026-09-14T15:33:33

1 posts

In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Cancel reg_work before freeing device on remove c4iw_uld_state_change() queues reg_work to register the RDMA device. c4iw_remove() can free ctx->dev while this work is pending or running, leaving c4iw_register_device() accessing the freed device. Cancel reg_work before removing the device. The registration work can

hugovalters@mastodon.social at 2026-09-18T17:40:01.000Z ##

CVE-2026-89510 Linux kernel RDMA/cxgb4 use-after-free in c4iw_remove, reg_work frees device while registration work still runs. No CVSS, no patch yet. Update your kernel now. valtersit.com/cve/CVE-2026-895 #CVE #infosec #Linux

##

CVE-2026-81000
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T15:33:28

5 posts

In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the re

1 repos

https://github.com/0xBlackash/CVE-2026-81000

cyberworldops at 2026-09-19T04:30:00.974Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk.

cyberworldops.eu/en/four-publi

##

sayzard@mastodon.sayzard.org at 2026-09-18T14:40:50.000Z ##

A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, DiagSpill

Linux 커널에서 일반 로컬 사용자를 root로 승격할 수 있는 4개 취약점 DirtyAH6(CVE-2026-80844), TUNderflow(CVE-2026-81000), PPPoEject(CVE-2026-68121), DiagSpill(CVE-2026-74469)가 공개됐다. 취약점들은 네트워크 서브시스템의 오래된 메모리 손상 문제이며, DiagSpill은 별도 capability나 비특권 사용자 네임스페이스 없이도 조건 충족 시 LPE가 가능하고 컨테이너 호스트 탈출 가능성도 있다. 수정은 Linux stable 5.10.270,...

openwall.com/lists/oss-securit

##

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

decio@infosec.exchange at 2026-09-18T08:13:07.000Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

#Linux #CyberSecurity #Vulnerability #CVE #Debian

##

harrysintonen@infosec.exchange at 2026-09-18T06:48:39.000Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469

##

CVE-2026-89496(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-09-14T15:32:27

1 posts

In the Linux kernel, the following vulnerability has been resolved: ocfs2: always run deallocs on copy-on-write completion Local fuzzing of 6.12.94 has found the following memory leak caused by doing 'copy_file_range()' within the same filesystem: unreferenced object 0xffff88812192c980 (size 32): comm "syz.0.49", pid 12095, jiffies 4294964143 hex dump (first 32 bytes): 00 00 00 00 00 00

hugovalters@mastodon.social at 2026-09-19T18:40:01.000Z ##

CVE-2026-89496 Linux kernel ocfs2 memory leak via copy_file_range, local fuzzing found it, patch status unknown. Patch now. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89460(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-14T15:32:24

1 posts

In the Linux kernel, the following vulnerability has been resolved: s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks The command 'perf stat -e cycles -- <command>' crashes the kernel when CPUs are hotplug added during that run. Root cause is the allocation of struct cpu_cf_events at first event initialization. The allocation is dynamic and the first event that has task context create

hugovalters@mastodon.social at 2026-09-18T19:10:09.000Z ##

CVE-2026-89460: Linux kernel s390 cpum_cf crash on CPU hotplug, DoS risk. CVSS N/A, patch status unknown. Audit and update now. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80944
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-14T15:32:21

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Detach sync cmd buffer on interrupted wait mwifiex synchronous commands keep the caller-provided data buffer in cmd_node->data_buf. Several callers pass stack-allocated objects there. If wait_event_interruptible_timeout() is interrupted, the caller can return and release that stack object while the firmware comma

hugovalters@mastodon.social at 2026-09-19T12:20:12.000Z ##

CVE-2026-80944: Linux kernel mwifiex flaw. An interrupted wait can free a stack buffer while firmware still holds it, risking use-after-free in the WiFi driver. No patch or CVSS yet. Track it and update when a valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-89480
(7.5 HIGH)

EPSS: 0.41%

updated 2026-09-14T13:19:04.623000

1 posts

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: reject a read that transferred too few bytes nvme_tcp_recv_data() completes a request once the current C2HData PDU has been consumed. Nothing compares the total bytes received against the length the command asked for: struct nvme_tcp_request has no receive-side counter, queue->data_remaining is per queue, and blk_mq_en

hugovalters@mastodon.social at 2026-09-19T14:00:02.000Z ##

CVE-2026-89480: Linux nvme-tcp accepts short reads without comparing received bytes to requested length, risking data corruption. CVSS N/A, unpatched. Patch now: valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89479
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-14T13:19:04.457000

1 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: stop processing a packet once its association is deleted sctp_endpoint_bh_rcv() looks the association up only when chunk->asoc is NULL, and caches the result in chunk->asoc and chunk->transport without taking a reference. A packet that matches no association is handed to the endpoint, so a peer can bundle COOKIE ECHO, SHU

hugovalters@mastodon.social at 2026-09-19T04:30:02.000Z ##

CVE-2026-89479 Linux kernel SCTP use-after-free, unpatched, no CVSS assigned. Crafted packet can free an association mid-processing. Patch status unclear, so track kernel updates now. Details: valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89473
(0 None)

EPSS: 0.20%

updated 2026-09-14T13:19:03.620000

1 posts

In the Linux kernel, the following vulnerability has been resolved: power: supply: bq25890: Fix power_supply reference leak bq25890_fw_probe() acquires a reference to a secondary charger using power_supply_get_by_name(), but the reference is not released on later probe failures or on driver detach. In particular, failures after bq25890_fw_probe() returns successfully, such as a failure in bq258

hugovalters@mastodon.social at 2026-09-18T16:00:01.000Z ##

CVE-2026-89473 Linux kernel bq25890 driver ref leak on probe fail or detach, causing resource exhaustion. No CVSS, no patch yet. Update when vendor fix lands. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80990
(0 None)

EPSS: 0.20%

updated 2026-09-14T13:18:53.787000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Release the Rx HopID that was handed out on mismatch tb_xdomain_alloc_in_hopid() passes the wanted HopID to ida_alloc_range() as the lower bound, so a taken id is not an error there: the allocator returns the next free one above it. tbnet_connected_work() asks for the peer's transmit path, treats any other id a

hugovalters@mastodon.social at 2026-09-20T04:20:02.000Z ##

CVE-2026-80990 Linux kernel thunderbolt net driver leaks Rx HopID on mismatch, leading to resource exhaustion over time. CVSS N/A, no patch confirmed. Update your kernel now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80949
(0 None)

EPSS: 0.18%

updated 2026-09-14T13:18:50.457000

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() The memory allocated for buf is not freed in some of the error paths in brcmf_sdio_read_control(). Fix that by adding vfree() calls. [arend: rework as suggested by Johannes]

hugovalters@mastodon.social at 2026-09-20T04:00:01.000Z ##

CVE-2026-80949 Linux kernel brcmfmac memory leak in brcmf_sdio_read_control() error paths. CVSS N/A, unpatched. Patch now. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-80941
(0 None)

EPSS: 0.21%

updated 2026-09-14T13:18:50.160000

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() The skb passed to the rtw_hci_tx_write() is expected to be freed when the function fails, but the error path in rtw_txq_push_skb() does not free the skb before returning. This can lead to a memory leak in rtw_txq_push() where a dequeued skb is passed to rtw_txq_push_sk

hugovalters@mastodon.social at 2026-09-19T04:20:03.000Z ##

CVE-2026-80941 Linux rtw88 wifi driver memory leak in rtw_txq_push_skb error path. No CVSS or patch confirmed yet. Update your kernel as soon as fixes land. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-89520
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T09:33:29

1 posts

In the Linux kernel, the following vulnerability has been resolved: sched/core: Make core-sched flips wait for in-flight selections Core scheduling's pick_next_task() operates on all sibling rqs under one acquisition of the shared core-wide lock. A ->pick_task() that releases the rq lock leaves every sibling __lock momentarily free, letting __sched_core_flip(false) complete mid-selection and reb

hugovalters@mastodon.social at 2026-09-18T14:30:38.000Z ##

CVE-2026-89520 Linux kernel core-sched race lets __sched_core_flip rebind rq_lockp mid-selection. No CVSS, no patch yet. Update to latest stable kernel when fixed. valtersit.com/cve/CVE-2026-895 #CVE #Linux #infosec

##

CVE-2026-89492
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-13T09:33:27

1 posts

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when reading metadata ocfs2_validate_dx_leaf() and ocfs2_validate_dx_root() check the ECC and signature of an indexed-directory block before it reaches higher-level callers, but neither validator bounds the ocfs2_dx_entry_list counts against the capacity of the block that holds them.

hugovalters@mastodon.social at 2026-09-19T06:10:01.000Z ##

CVE-2026-89492 Linux kernel ocfs2 out-of-bounds access via unchecked directory-index entry counts. No CVSS or patch yet. Treat as unpatched and update immediately if ocfs2 is in use. valtersit.com/cve/CVE-2026-894 #CVE #infosec #Linux

##

CVE-2026-80986
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-13T09:33:25

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages On a link whose device has max_recv_sge == 1 there is no shared v2 receive buffer, and smc_llc_save_add_link_rkeys() takes the v2 extension from 44 bytes past the start of the queue entry's inline message: ext = (struct smc_llc_msg_add_link_v2_ext *)(llc_msg + SMC_WR

hugovalters@mastodon.social at 2026-09-19T17:10:03.000Z ##

CVE-2026-80986 Linux kernel out-of-bounds access in net/smc SMC-Rv2 LLC handling. CVSS N/A, patch status unknown. Review and mitigate now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80953
(8.4 HIGH)

EPSS: 0.18%

updated 2026-09-13T09:32:12

1 posts

In the Linux kernel, the following vulnerability has been resolved: i3c: master: adi: initialize the lock before enabling interrupts adi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR before the controller's IBI state, transfer queue list and transfer queue lock are initialized. A pending CMDR interrupt can therefore run adi_i3c_master_irq() and take master->xferqueue.lock

hugovalters@mastodon.social at 2026-09-19T01:10:00.000Z ##

CVE-2026-80953 Linux i3c adi driver inits lock after enabling IRQ, risking race and memory corruption. CVSS N/A, unpatched. Patch or mitigate now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80954
(7.8 HIGH)

EPSS: 0.15%

updated 2026-09-13T09:32:11

1 posts

In the Linux kernel, the following vulnerability has been resolved: i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() i3c_device_get_supported_xfer_mode() uses dev->desc to obtain the master controller. However, dev->desc must not be dereferenced unless bus->lock is held, and this function does not take that lock. The function only needs access to the master co

hugovalters@mastodon.social at 2026-09-18T20:40:07.000Z ##

CVE-2026-80954 Linux kernel i3c unlocked dev->desc dereference, unpatched, CVSS N/A. Patch now if you run i3c. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-89523
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-13T07:17:14.697000

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel pending mlo_pm_work If the device is reset, suspended or unregistered within that window, the pending work can still run and access vif/bss data that may already be freed, or send MCU commands while the firmware is not available. Add cancel_delayed_work_sync(&dev->mlo_pm_work) in all relevant teardown

hugovalters@mastodon.social at 2026-09-19T09:20:20.000Z ##

CVE-2026-89523 Linux kernel mt76 mt7925 wifi: pending mlo_pm_work can touch freed memory or send MCU commands during reset/suspend. No CVSS yet, patch status unknown. Update promptly. valtersit.com/cve/CVE-2026-895 #CVE #infosec #LinuxKernel

##

CVE-2026-89459
(7.0 HIGH)

EPSS: 0.11%

updated 2026-09-13T07:17:09.733000

1 posts

In the Linux kernel, the following vulnerability has been resolved: s390/percpu: Fix MVIY_PERCPU() with older binutils Commit a737737cdb9c ("s390/percpu: Infrastructure for more efficient this_cpu operations") introduced MVIY_PERCPU(), which stringifies arguments that are already C string literals. This generates an assembler macro invocation with whitespace-separated quoted arguments: GEN_MV

hugovalters@mastodon.social at 2026-09-19T15:30:03.000Z ##

CVE-2026-89459 Linux kernel s390/percpu build flaw with older binutils, CVSS N/A, patch status unknown. Check if you are affected and update kernel immediately. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89452
(8.4 HIGH)

EPSS: 0.18%

updated 2026-09-13T07:17:09.477000

1 posts

In the Linux kernel, the following vulnerability has been resolved: iommu/msm: Unwind probe state on registration failure msm_iommu_probe() adds its devm-managed IOMMU object to qcom_iommu_devices before adding the IOMMU sysfs device and registering it with the IOMMU core. If iommu_device_sysfs_add() fails, probe returns with the object still on qcom_iommu_devices. The driver core then releases

hugovalters@mastodon.social at 2026-09-18T12:50:01.000Z ##

CVE-2026-89452 Linux kernel iommu/msm probe failure leaves a dangling list entry, risking use-after-free on later list walks. No CVSS score and no patch yet. Track it and update the kernel as soon as a fix valtersit.com/cve/CVE-2026-894 #CVE #LinuxKernel #infosec

##

CVE-2026-80998
(7.5 HIGH)

EPSS: 0.47%

updated 2026-09-13T07:17:06.483000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: bnxt: ring the doorbell when SW USO exits early When a burst of packets is handed down to the driver, the driver defers the doorbell to the end by setting txr->kick_pending = 1. The normal TX path handles this, but the SW USO path can miss it if it returns early. If bnxt_sw_udp_gso_xmit runs but returns early with NETDEV_T

hugovalters@mastodon.social at 2026-09-19T07:40:16.000Z ##

CVE-2026-80998 Linux kernel bnxt driver: missed doorbell on early SW USO exit stalls TX queue. No CVSS assigned. Patch status unknown. Check your kernel version and update immediately. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-78175
(8.8 HIGH)

EPSS: 0.59%

updated 2026-09-12T09:33:41

2 posts

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler lacking any capability or role check, relying solely on a nonce, while also passing attacker-supplied values through `esc_sq

guru@thecybersecguru.com at 2026-09-18T13:12:51.000Z ##

Tutor LMS Critical Flaw (CVE-2026-78175) Exposes 100,000+ WordPress Sites to Remote Code Execution

Tutor LMS CVE-2026-78175 is a critical RCE flaw affecting 100,000+ WordPress sites. Learn how the exploit works and how to patch it

thecybersecguru.com/news/cve-2

##

guru@thecybersecguru.com at 2026-09-18T13:12:51.000Z ##

Tutor LMS Critical Flaw (CVE-2026-78175) Exposes 100,000+ WordPress Sites to Remote Code Execution

Tutor LMS CVE-2026-78175 is a critical RCE flaw affecting 100,000+ WordPress sites. Learn how the exploit works and how to patch it

thecybersecguru.com/news/cve-2

##

CVE-2026-89267
(4.3 MEDIUM)

EPSS: 0.19%

updated 2026-09-12T03:30:28

1 posts

starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.

hugovalters@mastodon.social at 2026-09-19T21:50:23.000Z ##

CVE-2026-89267: Starlette-Admin 0.16.1-0.17.1 ignores empty searchable_fields allowlists, letting authenticated users query excluded columns via the where parameter. CVSS 4.3, patch status unknown. Audit valtersit.com/cve/CVE-2026-892 #CVE #infosec #cybersecurity

##

CVE-2026-89455(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-09-11T21:31:28

1 posts

In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix use-after-free of event IRQs during teardown plda_pcie_irq_domain_deinit() removes pcie->event_domain via irq_domain_remove(), but the per-event IRQs mapped from that domain are requested with devm_request_irq() in plda_init_interrupts(). The actual free_irq() for a devm-managed IRQ is deferred by devres until aft

hugovalters@mastodon.social at 2026-09-19T01:40:18.000Z ##

CVE-2026-89455 Linux kernel PCI plda use-after-free during IRQ teardown. No CVSS or patch yet. Audit and update affected systems. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80934(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-11T21:31:20

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames mt7996/mt7992 hand the firmware a HW MAC-TXP for AddBA req action frames (MT_TXD7_MAC_TXD, set in mt7996_mac_write_txwi_80211()), but are otherwise FW-TXP devices. On tx free mt76_connac_txp_skb_unmap() therefore decodes the per-frame txp as a struct mt76_connac_fw

hugovalters@mastodon.social at 2026-09-19T20:10:03.000Z ##

CVE-2026-80934 Linux kernel mt76 mt7996 TX DMA mapping leak. No CVSS or patch yet. Update now if you run mt7996 wifi. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-89453
(0 None)

EPSS: 0.20%

updated 2026-09-11T20:19:25.967000

1 posts

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faults iommu_call_iopf_notifier() looks up the requester with pci_get_domain_bus_and_slot(), which returns a PCI device with its reference count incremented. Neither the successful iommu_report_device_fault() path nor the abort path drops that reference, so every handled PPR request

hugovalters@mastodon.social at 2026-09-19T03:40:18.000Z ##

CVE-2026-89453 Linux kernel iommu/amd PPR fault handling leaks PCI device references. Unpatched. Patch now valtersit.com/cve/CVE-2026-894 #CVE #infosec #Linux

##

CVE-2026-80957
(0 None)

EPSS: 0.17%

updated 2026-09-11T20:19:01.520000

1 posts

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: detect a cycle in the last-kset chain during replay cache_replay() follows the on-media last-kset chain by next_cache_seg_id with no cond_resched(). A forged chain that points back into a segment it has already visited makes the replay loop follow it forever. Cap the last-kset hops at cache->n_segs; a valid chain vis

hugovalters@mastodon.social at 2026-09-20T04:00:32.000Z ##

CVE-2026-80957 Linux kernel dm-pcache infinite loop via forged last-kset chain during replay, DoS on mount. No CVSS yet, unpatched. Update now: valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80942
(0 None)

EPSS: 0.17%

updated 2026-09-11T20:18:59.660000

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subsequent error paths in rtl92du_init_sw_vars(). Fix that by adding a call to rtl92du_deinit_shared_data() in the error path.

hugovalters@mastodon.social at 2026-09-20T04:31:00.000Z ##

CVE-2026-80942 Linux rtlwifi rtl8192du: memory leak in error paths of rtl92du_init_sw_vars(), unfixed. No CVSS assigned. Patch status unknown, update now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-0310(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-09-10T06:31:55

1 posts

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimiz

CVE-2026-80844
(0 None)

EPSS: 0.19%

updated 2026-09-04T16:18:13.023000

5 posts

In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of addresses described by the routing header's hdrlen field. That assumption does not hold for raw IPv6 HDRINCL packets.

1 repos

https://github.com/0xBlackash/CVE-2026-80844

cyberworldops at 2026-09-19T04:30:00.974Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk.

cyberworldops.eu/en/four-publi

##

sayzard@mastodon.sayzard.org at 2026-09-18T14:40:50.000Z ##

A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, DiagSpill

Linux 커널에서 일반 로컬 사용자를 root로 승격할 수 있는 4개 취약점 DirtyAH6(CVE-2026-80844), TUNderflow(CVE-2026-81000), PPPoEject(CVE-2026-68121), DiagSpill(CVE-2026-74469)가 공개됐다. 취약점들은 네트워크 서브시스템의 오래된 메모리 손상 문제이며, DiagSpill은 별도 capability나 비특권 사용자 네임스페이스 없이도 조건 충족 시 LPE가 가능하고 컨테이너 호스트 탈출 가능성도 있다. 수정은 Linux stable 5.10.270,...

openwall.com/lists/oss-securit

##

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

decio@infosec.exchange at 2026-09-18T08:13:07.000Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

#Linux #CyberSecurity #Vulnerability #CVE #Debian

##

harrysintonen@infosec.exchange at 2026-09-18T06:48:39.000Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469

##

CVE-2026-13348(CVSS UNKNOWN)

EPSS: 0.31%

updated 2026-09-01T15:31:17

2 posts

CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.

cyberworldops at 2026-09-18T22:40:00.819Z ##

Schneider Electric disclosed CVE-2026-13348 (CWE-307) in PowerChute Serial Shutdown, allowing unrestricted authentication attempts. Successful brute-forcing enables account takeover with impact on UPS management and operational continuity.

cyberworldops.eu/en/powerchute

##

cyberworldops@infosec.exchange at 2026-09-18T22:40:00.000Z ##

Schneider Electric disclosed CVE-2026-13348 (CWE-307) in PowerChute Serial Shutdown, allowing unrestricted authentication attempts. Successful brute-forcing enables account takeover with impact on UPS management and operational continuity. #SchneiderElectric #PowerChute #BruteForce

cyberworldops.eu/en/powerchute

##

DailyCyberSecurity@infosec.exchange at 2026-09-18T09:26:48.000Z ##

HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.

#HCLBigFix #Cybersecurity #CVE202667100 #Vulnerability #InfoSec

securityonline.info/hcl-bigfix

##

CVE-2026-56389
(8.6 HIGH)

EPSS: 0.16%

updated 2026-08-24T18:32:30

1 posts

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided gramma

ottoto2017@prattohome.com at 2026-09-18T00:27:51.000Z ##

#Ubuntu 24.04.5 で #update

bison (2:3.8.2+dfsg-1ubuntu0.24.04.1)
CVE-2026-56389へのセキュリティ対応。

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-74469
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-19T18:33:35

5 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sctp_assoc_add_peer() increments the association's 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero. SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload, then copies one sockaddr_storage for every entry in t

1 repos

https://github.com/0xBlackash/CVE-2026-74469

cyberworldops at 2026-09-19T04:30:00.974Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk.

cyberworldops.eu/en/four-publi

##

sayzard@mastodon.sayzard.org at 2026-09-18T14:40:50.000Z ##

A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, DiagSpill

Linux 커널에서 일반 로컬 사용자를 root로 승격할 수 있는 4개 취약점 DirtyAH6(CVE-2026-80844), TUNderflow(CVE-2026-81000), PPPoEject(CVE-2026-68121), DiagSpill(CVE-2026-74469)가 공개됐다. 취약점들은 네트워크 서브시스템의 오래된 메모리 손상 문제이며, DiagSpill은 별도 capability나 비특권 사용자 네임스페이스 없이도 조건 충족 시 LPE가 가능하고 컨테이너 호스트 탈출 가능성도 있다. 수정은 Linux stable 5.10.270,...

openwall.com/lists/oss-securit

##

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

decio@infosec.exchange at 2026-09-18T08:13:07.000Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

#Linux #CyberSecurity #Vulnerability #CVE #Debian

##

harrysintonen@infosec.exchange at 2026-09-18T06:48:39.000Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469

##

CVE-2026-68121
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-19T18:32:06

5 posts

In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is

1 repos

https://github.com/0xBlackash/CVE-2026-68121

cyberworldops at 2026-09-19T04:30:00.974Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk.

cyberworldops.eu/en/four-publi

##

sayzard@mastodon.sayzard.org at 2026-09-18T14:40:50.000Z ##

A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, DiagSpill

Linux 커널에서 일반 로컬 사용자를 root로 승격할 수 있는 4개 취약점 DirtyAH6(CVE-2026-80844), TUNderflow(CVE-2026-81000), PPPoEject(CVE-2026-68121), DiagSpill(CVE-2026-74469)가 공개됐다. 취약점들은 네트워크 서브시스템의 오래된 메모리 손상 문제이며, DiagSpill은 별도 capability나 비특권 사용자 네임스페이스 없이도 조건 충족 시 LPE가 가능하고 컨테이너 호스트 탈출 가능성도 있다. 수정은 Linux stable 5.10.270,...

openwall.com/lists/oss-securit

##

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

decio@infosec.exchange at 2026-09-18T08:13:07.000Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

#Linux #CyberSecurity #Vulnerability #CVE #Debian

##

harrysintonen@infosec.exchange at 2026-09-18T06:48:39.000Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 49.68%

updated 2026-08-19T04:17:24.940000

2 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

2 repos

https://github.com/BiuTrap/CVE-2026-59310

https://github.com/HORKimhab/CVE-2026-59310

CapTechGroup@mastodon.social at 2026-09-18T12:48:49.000Z ##

Oracle's quarterly release fixed 800+ flaws, none flagged as exploited. Meanwhile CVE-2026-59310, an unauthenticated directory traversal in the VMware vCenter Syslog server patched in July, is now in ransomware hands after...

captechgroup.com/threat-intell

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T14:01:28.000Z ##

Discover how ransomware gangs actively exploit the critical VMware vCenter flaw, CVE-2026-59310. Learn about the swift weaponization and severe infrastructure risks.

#VMware #vCenter #CVE202659310 #Ransomware #CyberSecurity

meterpreter.org/vmware-vcenter

##

CVE-2026-7646
(6.5 MEDIUM)

EPSS: 0.30%

updated 2026-08-06T19:27:33.433000

2 posts

IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path traversal sequence in the filename.

5 repos

https://github.com/fevar54/CVE-2026-76461-Detection-Kit-

https://github.com/S3v3n-JG/CVE-2026-76460

https://github.com/HORKimhab/CVE-2026-76461

https://github.com/0xBlackash/CVE-2026-76461

https://github.com/S3v3n-JG/CVE-2026-76461

hackmag at 2026-09-18T15:36:29.481Z ##

⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email

🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…

🔗 hackmag.com/news/cve-2026-7646

##

hackmag@infosec.exchange at 2026-09-18T15:36:29.000Z ##

⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email

🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…

🔗 hackmag.com/news/cve-2026-7646

#news

##

CVE-2026-58138
(9.8 CRITICAL)

EPSS: 9.26%

updated 2026-07-14T22:17:26.797000

4 posts

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or

Nuclei template

6 repos

https://github.com/Procjevt/CVE-2026-58138

https://github.com/0xBlackash/CVE-2026-58138

https://github.com/BiiTts/CVE-2026-58138-Conductor-Unauth-RCE

https://github.com/Ch4120N/CVE-2026-58138

https://github.com/seqra/cve-2026-58138

https://github.com/0xgh057r3c0n/CVE-2026-58138

threatnoir at 2026-09-20T04:05:50.702Z ##

⚠️ CRITICAL: Critical Orkes Conductor Vulnerability Exploited in Attacks

Orkes Conductor versions below 3.30.2 have an unauthenticated remote code execution vulnerability (CVE-2026-58138) that is actively being exploited. Attackers can execute arbitrary system commands by injecting malicious JavaScript or Python into workflow definitions. Any organization running Conduc…

threatnoir.com/focus

🤖 AI generated summary

##

cyberworldops at 2026-09-18T13:10:00.595Z ##

Orkes Conductor 3.21.21 through before 3.30.2 is affected by CVE-2026-58138, an unauthenticated RCE via malicious workflow definitions using inline JS/Python. Exposed APIs allow arbitrary OS command execution with host-level impact. Patch to 3.30.2 and restrict exposure.

cyberworldops.eu/en/exposed-or

##

threatnoir@infosec.exchange at 2026-09-20T04:05:50.000Z ##

⚠️ CRITICAL: Critical Orkes Conductor Vulnerability Exploited in Attacks

Orkes Conductor versions below 3.30.2 have an unauthenticated remote code execution vulnerability (CVE-2026-58138) that is actively being exploited. Attackers can execute arbitrary system commands by injecting malicious JavaScript or Python into workflow definitions. Any organization running Conduc…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

cyberworldops@infosec.exchange at 2026-09-18T13:10:00.000Z ##

Orkes Conductor 3.21.21 through before 3.30.2 is affected by CVE-2026-58138, an unauthenticated RCE via malicious workflow definitions using inline JS/Python. Exposed APIs allow arbitrary OS command execution with host-level impact. Patch to 3.30.2 and restrict exposure. #OrkesConductor #RemoteCodeExecution #ThreatIntel

cyberworldops.eu/en/exposed-or

##

CVE-2026-45321
(9.6 CRITICAL)

EPSS: 2.34%

updated 2026-06-08T23:53:12

1 posts

## Summary On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 `@tanstack/*` packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for `TanStack/router`, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a `pull_req

13 repos

https://github.com/digi4care/shai-scan

https://github.com/Intrudify/mini-shai-hulud-scanner

https://github.com/nkopylov/tanscript-exploit-check

https://github.com/7whyex/CVE-2026-45321-Tanstack

https://github.com/renewablehacking/CVE-2026-45321-Tanstack

https://github.com/Yomisana/are-you-get-tanstack-attack

https://github.com/Breakingcircuitsllc/teampcp_shai_hulud.yar

https://github.com/fabriziosalmi/tanstack-compromise-checker

https://github.com/qi-scape/scan-shai-hulud

https://github.com/ry-allan/tanstack-compromise-checker

https://github.com/prashanthnataraj/mini-shai-hulud-detector

https://github.com/shayr1/shai-hulud-scan

https://github.com/Caixa-git/tanstack-shield

Analyst207@mastodon.social at 2026-09-19T08:03:27.000Z ##

TanStack npm Attack Exposes 170 Private GitHub Repositories

A shocking npm attack on TanStack exposed a massive 170 private GitHub repositories after a malicious actor exploited a stolen OAuth token from a former employee's account. The breach was linked to a supply-chain compromise of TanStack's npm packages, tracked as CVE-2026-45321, which allowed attackers to steal sensitive credentials.

osintsights.com/tanstack-npm-a

#TanstackNpmAttack #SupplyChain #Github #OauthToken #Cve202645321

##

CVE-2026-78030
(0 None)

EPSS: 0.00%

4 posts

N/A

thehackerwire@mastodon.social at 2026-09-20T02:02:25.000Z ##

🔴 CVE-2026-78030 - Critical (9.8)

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.

DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. requ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-20T01:30:24.159Z ##

DBD::DBM (<1.653) for Perl is affected by CVE-2026-78030 (CRITICAL, CVSS 9.8). Unvalidated dbm_type/dbm_mldbm allow arbitrary code execution if attacker controls input. Patch status unknown — sanitize attributes now! radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T02:02:25.000Z ##

🔴 CVE-2026-78030 - Critical (9.8)

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.

DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. requ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T01:30:24.000Z ##

DBD::DBM (<1.653) for Perl is affected by CVE-2026-78030 (CRITICAL, CVSS 9.8). Unvalidated dbm_type/dbm_mldbm allow arbitrary code execution if attacker controls input. Patch status unknown — sanitize attributes now! radar.offseq.com/threat/cve-20 #OffSeq #CVE202678030 #Perl #Infosec

##

CVE-2026-57228
(0 None)

EPSS: 0.56%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T23:02:48.000Z ##

🟠 CVE-2026-57228 - High (8.2)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:02:48.000Z ##

🟠 CVE-2026-57228 - High (8.2)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63452
(0 None)

EPSS: 0.36%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T22:03:30.000Z ##

🟠 CVE-2026-63452 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli comp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:03:30.000Z ##

🟠 CVE-2026-63452 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli comp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71418
(0 None)

EPSS: 0.35%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T22:02:15.000Z ##

🟠 CVE-2026-71418 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame cont...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:02:15.000Z ##

🟠 CVE-2026-71418 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame cont...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92708
(0 None)

EPSS: 0.34%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T21:02:57.000Z ##

🟠 CVE-2026-92708 - High (7.5)

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing Arr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:02:57.000Z ##

🟠 CVE-2026-92708 - High (7.5)

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing Arr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72878
(0 None)

EPSS: 0.27%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-09-18T06:14:51.000Z ##

A critical Dokploy OS command injection flaw (CVE-2026-72878) exposes servers to root takeover via backups. Patch this Dokploy OS command injection now.

#Dokploy #CommandInjection #CVE202672878 #Cybersecurity #PaaS

securityonline.info/dokploy-os

##

CVE-2026-54520
(0 None)

EPSS: 0.40%

1 posts

N/A

1 repos

https://github.com/chaitanyagarware/CVE-2026-54520

thehackerwire@mastodon.social at 2026-09-17T23:01:41.000Z ##

🟠 CVE-2026-54520 - High (8.1)

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54670
(0 None)

EPSS: 0.55%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T23:01:30.000Z ##

🔴 CVE-2026-54670 - Critical (9.1)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and meth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54671
(0 None)

EPSS: 0.41%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T23:00:35.000Z ##

🟠 CVE-2026-54671 - High (8.8)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93426
(0 None)

EPSS: 0.37%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T23:00:26.000Z ##

🟠 CVE-2026-93426 - High (8.5)

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54716
(0 None)

EPSS: 0.32%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T21:01:30.000Z ##

🟠 CVE-2026-54716 - High (7.5)

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unboun...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54692
(0 None)

EPSS: 0.14%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T21:01:19.000Z ##

🟠 CVE-2026-54692 - High (7.8)

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54627
(0 None)

EPSS: 0.44%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T21:00:40.000Z ##

🔴 CVE-2026-54627 - Critical (9.8)

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap col...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93337
(0 None)

EPSS: 0.15%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T21:00:20.000Z ##

🟠 CVE-2026-93337 - High (7.8)

NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85500
(0 None)

EPSS: 0.55%

1 posts

N/A

offseq@infosec.exchange at 2026-09-17T13:30:29.000Z ##

CVE-2026-85500: team-alembic ash_authentication (4.3.8 – 4.15.0, 5.0.0-rc.14) suffers a CRITICAL auth bypass — unconfirmed users may gain sessions, defeating email confirmation. Patch urgently. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE202685500 #AshAuthentication

##

Visit counter For Websites