## Updated at UTC 2026-09-20T19:13:59.937333

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-94036 8.8 0.00% 2 1 2026-09-20T18:31:25 A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0
CVE-2026-87067 8.5 0.17% 2 0 2026-09-20T15:31:27 The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which c
CVE-2026-92965 3.7 0.13% 2 0 2026-09-20T15:31:27 The TikTok WordPress plugin before 1.4.2 does not check that a request is author
CVE-2026-87068 6.6 0.13% 2 0 2026-09-20T15:31:27 The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role v
CVE-2026-85017 7.5 0.15% 2 0 2026-09-20T15:31:26 The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not per
CVE-2026-90817 9.8 0.00% 4 0 2026-09-20T15:30:29 An unauthenticated Remote Code Execution vulnerability was found in the survey p
CVE-2026-82842 8.1 0.13% 4 0 2026-09-20T15:30:25 The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the confi
CVE-2026-87839 7.5 0.14% 2 0 2026-09-20T14:16:59.197000 The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, a
CVE-2026-94106 8.8 0.00% 2 0 2026-09-20T12:30:37 getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out
CVE-2026-94109 8.8 0.00% 2 0 2026-09-20T12:30:35 openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerabili
CVE-2026-94104 8.8 0.00% 2 0 2026-09-20T12:30:28 NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the Fi
CVE-2026-94003 10.0 0.00% 4 0 2026-09-20T12:30:28 A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the funct
CVE-2026-94107 8.1 0.00% 2 0 2026-09-20T12:17:06.277000 NivoCart through 2.4.0 contains a predictable password reset token vulnerability
CVE-2026-86553 8.8 0.45% 2 0 2026-09-20T10:16:52.607000 SmartLife app dynamically generates fresh SmartLife application authentication p
CVE-2026-93962 8.3 0.53% 2 0 2026-09-20T06:30:21 A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. T
CVE-2026-88097 8.1 0.22% 2 0 2026-09-20T04:17:08.050000 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke
CVE-2026-93958 9.1 2.17% 4 1 2026-09-20T03:30:31 A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affec
CVE-2026-94084 9.4 0.40% 4 0 2026-09-20T03:30:29 Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transacti
CVE-2026-94083 9.4 0.40% 4 0 2026-09-20T02:16:53.520000 Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free,
CVE-2026-78030 9.8 0.73% 4 0 2026-09-20T01:16:30.017000 DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_ty
CVE-2026-94056 7.5 0.24% 3 0 2026-09-20T00:30:32 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled pro
CVE-2026-93993 8.8 0.60% 2 0 2026-09-20T00:30:32 Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the
CVE-2026-93992 8.1 0.80% 2 0 2026-09-20T00:30:32 Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive e
CVE-2026-93991 7.7 0.33% 2 0 2026-09-20T00:30:25 Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vuln
CVE-2026-93990 7.5 0.35% 2 0 2026-09-19T23:17:10.203000 Expat through 2.8.4 fails to validate low surrogates following high surrogates i
CVE-2026-86814 8.1 0.23% 4 0 2026-09-19T15:32:25 The UsersWP WordPress plugin before 1.5.10 does not verify that a social login
CVE-2026-92404 7.5 0.26% 2 0 2026-09-19T15:31:26 The MgoSync WordPress plugin before 2.1.7 does not have authorization controls
CVE-2026-88926 8.6 0.26% 2 0 2026-09-19T15:31:25 The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4
CVE-2026-85680 8.8 0.28% 2 0 2026-09-19T15:31:24 The Ultimate Member WordPress plugin before 2.13.1 does not escape a value deri
CVE-2026-85574 8.0 0.19% 2 0 2026-09-19T15:31:24 The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any au
CVE-2026-86591 9.8 0.37% 4 0 2026-09-19T15:31:23 The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation
CVE-2026-93761 7.5 0.27% 1 0 2026-09-19T15:17:08.503000 An inefficient regular expression complexity issue in the in-memory query evalua
CVE-2026-84073 9.1 0.26% 2 0 2026-09-19T15:17:04.983000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84070 8.9 0.32% 3 0 2026-09-19T15:17:04.867000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-82893 7.8 0.11% 2 0 2026-09-19T15:17:04.220000 IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated
CVE-2026-82885 8.8 0.28% 2 0 2026-09-19T15:17:03.877000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-81656 8.8 0.29% 2 0 2026-09-19T15:17:03.380000 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability
CVE-2026-80442 9.9 0.63% 2 0 2026-09-19T15:17:02.547000 IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command i
CVE-2026-75878 9.1 0.48% 2 0 2026-09-19T15:17:00.883000 IBM Sterling File Gateway could allow a remote attacker to bypass authentication
CVE-2026-88824 8.8 0.28% 2 0 2026-09-19T14:17:02.290000 The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on
CVE-2026-87909 7.5 0.53% 2 0 2026-09-19T14:17:01.943000 The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execut
CVE-2026-84434 9.8 0.70% 4 1 2026-09-19T14:17:00.363000 The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in
CVE-2026-84108 8.1 0.40% 2 0 2026-09-19T14:17:00.037000 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-84085 8.1 0.32% 2 0 2026-09-19T14:16:59.587000 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-4327 8.8 0.70% 2 0 2026-09-19T14:16:57.917000 The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution i
CVE-2026-84750 6.5 0.27% 2 0 2026-09-19T13:16:51.780000 The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not vali
CVE-2026-93985 9.9 0.48% 4 0 2026-09-19T12:32:19 OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerabi
CVE-2026-93742 9.9 1.88% 5 0 2026-09-19T09:32:25 A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected b
CVE-2026-85658 8.1 0.36% 2 0 2026-09-19T09:32:23 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
CVE-2026-1255 7.5 0.29% 2 0 2026-09-19T09:32:16 The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Expos
CVE-2026-93741 10.0 0.64% 5 0 2026-09-19T06:32:09 A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affec
CVE-2026-53266 8.8 0.28% 5 1 2026-09-19T04:17:53.580000 In the Linux kernel, the following vulnerability has been resolved: netfilter:
CVE-2025-39964 7.8 0.79% 6 2 2026-09-19T04:17:48.307000 In the Linux kernel, the following vulnerability has been resolved: crypto: af_
CVE-2025-39682 9.8 1.20% 6 2 2026-09-19T04:17:35.263000 In the Linux kernel, the following vulnerability has been resolved: tls: fix ha
CVE-2026-92807 8.8 0.25% 4 0 2026-09-19T03:32:15 The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitra
CVE-2026-92229 9.1 0.40% 4 1 2026-09-19T03:32:15 The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plug
CVE-2026-89274 9.1 0.38% 4 2 2026-09-19T03:32:09 The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Ex
CVE-2026-93739 9.9 0.49% 2 0 2026-09-19T00:32:51 A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impac
CVE-2026-93923 8.8 0.41% 2 0 2026-09-19T00:32:50 SiYuan through 3.8.4 fails to escape heading style attributes when rendering out
CVE-2026-75885 9.3 0.41% 4 0 2026-09-19T00:32:50 A flaw was found in the OpenShift console. Unauthenticated access to the `/api/d
CVE-2026-93740 10.0 0.61% 2 0 2026-09-19T00:32:50 A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected i
CVE-2026-93922 8.8 0.54% 2 0 2026-09-19T00:32:45 SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker
CVE-2026-93738 9.9 0.50% 2 0 2026-09-18T21:32:44 A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects th
CVE-2026-93872 7.5 0.44% 2 0 2026-09-18T21:32:42 Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without al
CVE-2026-93031 8.8 0.58% 2 0 2026-09-18T21:32:41 The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-B
CVE-2026-93868 8.1 0.61% 2 0 2026-09-18T21:32:41 Cotonti through 1.0.0 derives password recovery validation tokens from md5(micro
CVE-2026-84239 7.6 0.41% 3 0 2026-09-18T21:32:40 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84241 8.1 0.30% 3 0 2026-09-18T21:32:40 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-93839 9.8 0.60% 4 0 2026-09-18T21:32:40 LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /p
CVE-2026-84089 7.8 0.11% 3 0 2026-09-18T21:32:39 IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated
CVE-2026-84075 9.9 0.35% 3 0 2026-09-18T21:32:39 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-84082 9.8 0.40% 2 0 2026-09-18T21:32:39 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-84076 7.6 0.31% 2 0 2026-09-18T21:32:39 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84106 8.9 0.32% 2 0 2026-09-18T21:32:39 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84084 8.8 0.18% 2 0 2026-09-18T21:32:39 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-84074 8.9 0.32% 2 0 2026-09-18T21:32:38 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84064 9.9 0.37% 2 0 2026-09-18T21:32:38 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84083 7.8 0.11% 2 0 2026-09-18T21:32:38 IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation vi
CVE-2026-84105 7.7 0.35% 2 0 2026-09-18T21:32:38 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84081 8.1 0.20% 3 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-84078 9.9 0.28% 3 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vuln
CVE-2026-82887 8.8 0.41% 2 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-82896 7.6 0.36% 2 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84034 8.8 0.25% 2 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulne
CVE-2026-82967 9.8 0.43% 3 0 2026-09-18T21:32:36 IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that
CVE-2026-82832 9.6 0.38% 2 0 2026-09-18T21:32:36 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-80441 9.8 0.38% 2 0 2026-09-18T21:32:35 IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-ord
CVE-2026-82340 9.8 0.51% 2 0 2026-09-18T21:32:35 IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure dese
CVE-2026-81933 8.8 0.32% 2 0 2026-09-18T21:32:35 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability
CVE-2026-82892 8.1 0.39% 2 0 2026-09-18T21:32:35 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-84077 8.1 0.19% 2 0 2026-09-18T21:18:44.303000 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-84031 9.0 0.33% 3 0 2026-09-18T21:18:44.080000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-63447 7.5 0.36% 2 0 2026-09-18T21:17:03.913000 Suricata is a network Intrusion Detection System, Intrusion Prevention System an
CVE-2026-63446 7.5 0.39% 2 0 2026-09-18T21:17:03.763000 Suricata is a network Intrusion Detection System, Intrusion Prevention System an
CVE-2026-93752 7.5 0.47% 1 0 2026-09-18T20:17:33.640000 CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclar
CVE-2026-92708 7.5 0.34% 2 0 2026-09-18T20:17:30.150000 Svelte devalue is a JavaScript library that serializes values into strings when
CVE-2026-81657 9.8 0.58% 2 0 2026-09-18T20:17:23.997000 IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker
CVE-2026-81626 8.6 0.27% 2 0 2026-09-18T20:17:23.723000 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability
CVE-2026-20330 9.9 0.34% 1 0 2026-09-18T20:17:13.870000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-13684 9.8 0.46% 2 0 2026-09-18T20:17:08.373000 An improper encoding or escaping of output vulnerability in SCGI in Synology Dis
CVE-2026-90439 6.5 0.26% 2 0 2026-09-18T19:34:36.657000 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module
CVE-2026-28198 8.8 0.20% 1 0 2026-09-18T19:24:36.593000 An authenticated, low-privileged user with access to the NetBackup Flex OS mana
CVE-2026-91149 7.5 0.35% 1 0 2026-09-18T19:06:08.407000 A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this
CVE-2026-93759 8.6 0.24% 1 0 2026-09-18T18:32:04 Mongoid does not neutralize a string-typed query criterion supplied to its query
CVE-2026-93758 8.1 0.21% 1 0 2026-09-18T18:32:02 An insecure direct object reference in the nested attributes handling of the Mon
CVE-2026-93687 7.5 0.41% 1 0 2026-09-18T18:32:02 braces through 3.0.3 contains a stack overflow vulnerability in the recursive AS
CVE-2026-93753 7.5 0.36% 1 0 2026-09-18T18:32:01 deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the merg
CVE-2026-93762 9.8 0.34% 1 0 2026-09-18T18:32:01 Mongoid contains an unsafe reflection weakness in the query path used for embedd
CVE-2026-93760 8.2 0.28% 1 0 2026-09-18T18:31:58 Mongoid does not restrict which query operators may come from caller-supplied fi
CVE-2026-93765 9.1 0.29% 1 0 2026-09-18T18:31:58 Mongoid contains an unsafe reflection weakness in the document persistence layer
CVE-2026-85497 9.8 0.21% 1 0 2026-09-18T18:31:57 CareCam CM2507 IP cameras store the device's root-account password using a fixed
CVE-2026-84398 7.5 0.24% 1 0 2026-09-18T18:31:54 CM2507 IP cameras accept an empty password for a privileged account exposed thro
CVE-2026-61672 7.1 0.20% 1 0 2026-09-18T17:16:58.537000 Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0
CVE-2026-93688 7.5 0.40% 1 0 2026-09-18T16:17:15.683000 SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV tra
CVE-2026-93606 10.0 0.52% 1 0 2026-09-18T15:32:25 vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `Node
CVE-2026-93605 10.0 0.38% 1 0 2026-09-18T15:32:25 vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where t
CVE-2026-93592 7.5 0.38% 1 0 2026-09-18T15:32:24 vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the
CVE-2026-93591 7.6 0.29% 1 0 2026-09-18T15:32:24 SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph
CVE-2026-93597 7.7 0.33% 1 0 2026-09-18T15:32:24 ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in th
CVE-2026-93491 7.5 0.44% 1 0 2026-09-18T15:32:17 A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker
CVE-2026-93572 7.5 0.34% 1 0 2026-09-18T15:32:16 ## Summary `RedisArrayAggregator` recently added `maxElements` and `maxNestedAr
CVE-2026-81916 4.3 0.20% 1 0 2026-09-18T15:23:18.233000 Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry
CVE-2026-17086 8.8 0.89% 1 0 2026-09-18T15:17:06.153000 The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for
CVE-2026-93603 10.0 0.43% 1 0 2026-09-18T14:19:12.123000 vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this`
CVE-2026-20192 10.0 0.43% 2 0 2026-09-18T14:17:16.023000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-67101 9.3 0.27% 1 0 2026-09-18T13:44:57.517000 HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF
CVE-2026-28197 8.8 0.37% 1 0 2026-09-18T12:31:27 An authenticated, low-privileged user with access to the NetBackup Flex OS mana
CVE-2026-13639 9.8 0.51% 1 0 2026-09-18T09:31:26 An insufficient entropy vulnerability in login logic in Synology DiskStation Man
CVE-2026-85410 8.1 0.31% 1 0 2026-09-18T09:31:24 The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder,
CVE-2026-6205 8.1 0.32% 1 0 2026-09-18T09:31:21 An external control of file name or path vulnerability in Upload API in Synology
CVE-2026-67100 9.8 0.35% 2 0 2026-09-18T09:31:08 HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tena
CVE-2026-18911 7.5 1.06% 1 0 2026-09-18T06:32:11 ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent a
CVE-2026-18912 7.7 1.50% 1 0 2026-09-18T06:32:11 ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authent
CVE-2026-85889 10.0 0.49% 2 0 2026-09-18T00:31:16 Missing authentication for critical function in Azure AI Foundry allows an unaut
CVE-2026-28326 8.8 0.55% 2 0 2026-09-17T18:32:05 SolarWinds Access Rights Manager was reported to be affected by an unauthenticat
CVE-2026-76460 10.0 0.78% 10 1 2026-09-17T12:46:31.670000 A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an
CVE-2026-20306 9.1 1.37% 2 0 2026-09-17T04:17:40.777000 A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenti
CVE-2026-20329 9.9 0.45% 1 0 2026-09-16T21:32:50 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20324 9.9 0.44% 1 0 2026-09-16T21:32:50 A vulnerability in the sftunnel inter-device communication protocol of Cisco Sec
CVE-2026-79994 0 0.11% 1 0 2026-09-16T20:38:33.883000 The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a
CVE-2026-20331 9.6 0.23% 1 0 2026-09-16T18:32:09 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20305 9.1 1.37% 2 0 2026-09-16T18:32:04 A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an
CVE-2026-91843 9.8 0.50% 7 1 2026-09-16T15:31:14 A stack overflow during the unauthenticated login process may allow an attacker
CVE-2026-77179 None 0.16% 5 1 2026-09-16T00:32:25 On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows
CVE-2026-89267 4.3 0.19% 1 0 2026-09-15T17:17:36.800000 starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fi
CVE-2026-76461 9.8 2.01% 1 4 2026-09-14T21:32:49 A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure
CVE-2026-89497 7.8 0.13% 1 0 2026-09-14T15:33:33 In the Linux kernel, the following vulnerability has been resolved: orangefs: s
CVE-2026-89479 9.8 0.51% 1 0 2026-09-14T15:33:32 In the Linux kernel, the following vulnerability has been resolved: sctp: stop
CVE-2026-81000 7.8 0.16% 4 1 2026-09-14T15:33:28 In the Linux kernel, the following vulnerability has been resolved: net: tun: b
CVE-2026-89496 None 0.18% 1 0 2026-09-14T15:32:27 In the Linux kernel, the following vulnerability has been resolved: ocfs2: alwa
CVE-2026-80994 7.8 0.16% 1 0 2026-09-14T15:32:23 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-80987 7.5 0.51% 1 0 2026-09-14T15:32:22 In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_tr
CVE-2026-80990 None 0.20% 1 0 2026-09-14T15:32:22 In the Linux kernel, the following vulnerability has been resolved: net: thunde
CVE-2026-80968 None 0.21% 1 0 2026-09-14T15:32:21 In the Linux kernel, the following vulnerability has been resolved: ALSA: mts64
CVE-2026-80949 None 0.18% 1 0 2026-09-14T15:32:21 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmf
CVE-2026-80944 7.8 0.13% 1 0 2026-09-14T15:32:21 In the Linux kernel, the following vulnerability has been resolved: wifi: mwifi
CVE-2026-80941 None 0.21% 1 0 2026-09-14T15:32:21 In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88
CVE-2026-80930 None 0.18% 1 0 2026-09-14T15:32:20 In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2
CVE-2026-89480 7.5 0.41% 1 0 2026-09-14T13:19:04.623000 In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: r
CVE-2026-80984 0 0.20% 1 0 2026-09-14T13:18:53.227000 In the Linux kernel, the following vulnerability has been resolved: net/smc: do
CVE-2026-89523 7.8 0.14% 1 0 2026-09-13T09:33:29 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:
CVE-2026-89459 7.0 0.11% 1 0 2026-09-13T09:33:25 In the Linux kernel, the following vulnerability has been resolved: s390/percpu
CVE-2026-80998 7.5 0.47% 1 0 2026-09-13T09:33:21 In the Linux kernel, the following vulnerability has been resolved: net: bnxt:
CVE-2026-80953 8.4 0.18% 1 0 2026-09-13T09:32:12 In the Linux kernel, the following vulnerability has been resolved: i3c: master
CVE-2026-80937 8.8 0.32% 1 0 2026-09-13T09:32:11 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:
CVE-2026-89492 9.8 0.60% 1 0 2026-09-13T07:17:12.417000 In the Linux kernel, the following vulnerability has been resolved: ocfs2: vali
CVE-2026-80986 9.8 0.60% 1 0 2026-09-13T07:17:05.417000 In the Linux kernel, the following vulnerability has been resolved: net/smc: bo
CVE-2026-80950 7.8 0.16% 2 0 2026-09-13T07:17:02.210000 In the Linux kernel, the following vulnerability has been resolved: i3c: renesa
CVE-2026-78175 8.8 0.59% 1 0 2026-09-12T09:33:41 The Tutor LMS – eLearning and online course solution plugin for WordPress is vul
CVE-2026-81913 None 0.59% 1 0 2026-09-11T21:31:32 Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via th
CVE-2026-89455 None 0.20% 1 0 2026-09-11T21:31:28 In the Linux kernel, the following vulnerability has been resolved: PCI: plda:
CVE-2026-80942 None 0.17% 1 0 2026-09-11T21:31:21 In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwi
CVE-2026-80934 None 0.17% 1 0 2026-09-11T21:31:20 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:
CVE-2026-89453 0 0.20% 1 0 2026-09-11T20:19:25.967000 In the Linux kernel, the following vulnerability has been resolved: iommu/amd:
CVE-2026-80957 0 0.17% 1 0 2026-09-11T20:19:01.520000 In the Linux kernel, the following vulnerability has been resolved: dm-pcache:
CVE-2026-0310 None 0.34% 1 0 2026-09-10T06:31:55 A buffer overflow vulnerability in the XML processing functionality of Palo Alto
CVE-2025-25249 8.1 2.40% 1 0 2026-09-09T21:30:27 A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6
CVE-2025-20701 8.8 8.67% 2 2 2026-09-08T18:31:36 In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth aud
CVE-2026-54218 0 0.34% 2 0 2026-09-07T14:16:53.357000 Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamD
CVE-2026-80844 0 0.19% 4 1 2026-09-04T16:18:13.023000 In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6:
CVE-2026-13348 None 0.31% 2 0 2026-09-01T15:31:17 CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability
CVE-2026-18963 9.1 3.18% 1 15 template 2026-08-28T22:53:42 A flaw was found in the reset-credentials flow of the keycloak-services componen
CVE-2026-74469 8.8 0.47% 4 1 2026-08-19T18:33:35 In the Linux kernel, the following vulnerability has been resolved: sctp: preve
CVE-2026-68121 7.8 0.14% 4 1 2026-08-19T18:32:06 In the Linux kernel, the following vulnerability has been resolved: pppoe: relo
CVE-2021-34473 9.8 100.00% 2 14 2026-08-10T18:30:39 Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is uni
CVE-2026-7646 6.5 0.30% 1 5 2026-08-06T19:27:33.433000 IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from
CVE-2026-55945 4.2 0.19% 1 0 2026-07-03T21:31:47 Concurrent execution using shared resource with improper synchronization ('race
CVE-2026-58138 9.8 9.26% 5 6 2026-06-30T21:31:51 Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code ex
CVE-2026-45321 9.6 2.34% 1 13 2026-06-17T10:51:54.877000 On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions
CVE-2026-20111 4.8 0.18% 2 0 2026-03-10T21:32:11 A vulnerability in the web-based management interface of Cisco Prime Infrastruct
CVE-2026-0628 8.8 6.63% 1 2 2026-01-07T15:31:20 Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7
CVE-2024-3400 9.8 100.00% 1 45 2025-10-22T00:34:06 A command injection vulnerability in the GlobalProtect feature of Palo Alto Netw
CVE-2026-84383 0 0.64% 2 0 N/A
CVE-2026-57228 0 0.56% 2 0 N/A
CVE-2026-57227 0 0.40% 2 0 N/A
CVE-2026-63452 0 0.36% 2 0 N/A
CVE-2026-68928 0 0.13% 2 0 N/A
CVE-2026-71418 0 0.35% 2 0 N/A

CVE-2026-94036
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-20T18:31:25

2 posts

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.

1 repos

https://github.com/djzzlim/CVE-2026-94036

thehackerwire@mastodon.social at 2026-09-20T17:03:09.000Z ##

🟠 CVE-2026-94036 - High (8.8)

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T17:03:09.000Z ##

🟠 CVE-2026-94036 - High (8.8)

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87067
(8.5 HIGH)

EPSS: 0.17%

updated 2026-09-20T15:31:27

2 posts

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Formina

thehackerwire@mastodon.social at 2026-09-20T16:01:30.000Z ##

🟠 CVE-2026-87067 - High (8.5)

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T16:01:30.000Z ##

🟠 CVE-2026-87067 - High (8.5)

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92965
(3.7 LOW)

EPSS: 0.13%

updated 2026-09-20T15:31:27

2 posts

The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, using the site's own credentials. It matches that code loosely, so URLs that merely resemble the expected one trigger it too, and the callback runs on every reques

offseq at 2026-09-20T10:30:24.375Z ##

HIGH severity: CVE-2026-92965 in TikTok WordPress plugin (1.2.0 – 1.4.2) allows any visitor to redeem sign-in codes via URL, risking ad platform abuse. Restrict or disable the plugin while awaiting a patch. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-20T10:30:24.000Z ##

HIGH severity: CVE-2026-92965 in TikTok WordPress plugin (1.2.0 – 1.4.2) allows any visitor to redeem sign-in codes via URL, risking ad platform abuse. Restrict or disable the plugin while awaiting a patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Security

##

CVE-2026-87068
(6.6 MEDIUM)

EPSS: 0.13%

updated 2026-09-20T15:31:27

2 posts

The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who submits it. The same user is refused an identical form through both the ordinary form

offseq at 2026-09-20T07:30:24.117Z ##

CRITICAL: CVE-2026-87068 in Forminator Forms (<1.57.2.1) allows users with quiz import access to publish forms that assign admin roles. Upgrade to v1.57.2.1 now to prevent privilege escalation. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-20T07:30:24.000Z ##

CRITICAL: CVE-2026-87068 in Forminator Forms (<1.57.2.1) allows users with quiz import access to publish forms that assign admin roles. Upgrade to v1.57.2.1 now to prevent privilege escalation. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202687068 #infosec

##

CVE-2026-85017
(7.5 HIGH)

EPSS: 0.15%

updated 2026-09-20T15:31:26

2 posts

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable ac

thehackerwire@mastodon.social at 2026-09-20T16:01:21.000Z ##

🟠 CVE-2026-85017 - High (7.5)

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T16:01:21.000Z ##

🟠 CVE-2026-85017 - High (7.5)

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90817
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-20T15:30:29

4 posts

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this co

thehackerwire@mastodon.social at 2026-09-20T15:02:14.000Z ##

🔴 CVE-2026-90817 - Critical (9.8)

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended contr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-20T13:30:24.746Z ##

CVE-2026-90817: CRITICAL RCE in REDCap (13.3.0+). Unauth attackers can exploit improper code generation via survey hash for full server compromise. Restrict hash access & monitor systems. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T15:02:14.000Z ##

🔴 CVE-2026-90817 - Critical (9.8)

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended contr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T13:30:24.000Z ##

CVE-2026-90817: CRITICAL RCE in REDCap (13.3.0+). Unauth attackers can exploit improper code generation via survey hash for full server compromise. Restrict hash access & monitor systems. radar.offseq.com/threat/cve-20 #OffSeq #REDCap #infosec #RCE

##

CVE-2026-82842
(8.1 HIGH)

EPSS: 0.13%

updated 2026-09-20T15:30:25

4 posts

The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a login name of their choosing to authenticate as any account, including an administ

thehackerwire@mastodon.social at 2026-09-20T16:01:11.000Z ##

🟠 CVE-2026-82842 - High (8.1)

The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-20T09:00:25.447Z ##

CVE-2026-82842 | CRITICAL: SAML Single Sign On WP plugin <6.0.0 fails to enforce SSO linking criteria, letting attackers with IDP control hijack any account, incl. admins. Upgrade to 6.0.0+ now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T16:01:11.000Z ##

🟠 CVE-2026-82842 - High (8.1)

The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T09:00:25.000Z ##

CVE-2026-82842 | CRITICAL: SAML Single Sign On WP plugin <6.0.0 fails to enforce SSO linking criteria, letting attackers with IDP control hijack any account, incl. admins. Upgrade to 6.0.0+ now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202682842 #SAML #infosec

##

CVE-2026-87839
(7.5 HIGH)

EPSS: 0.14%

updated 2026-09-20T14:16:59.197000

2 posts

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.

thehackerwire@mastodon.social at 2026-09-20T17:03:48.000Z ##

🟠 CVE-2026-87839 - High (7.5)

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T17:03:48.000Z ##

🟠 CVE-2026-87839 - High (7.5)

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94106
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-20T12:30:37

2 posts

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.

thehackerwire@mastodon.social at 2026-09-20T15:02:23.000Z ##

🟠 CVE-2026-94106 - High (8.8)

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands execut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T15:02:23.000Z ##

🟠 CVE-2026-94106 - High (8.8)

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands execut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94109
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-20T12:30:35

2 posts

openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions through collection summaries, dashboard portlets, or MIME templates to instantiate dangerous classes like freemarker.template.utility.Execute and invoke Runt

thehackerwire@mastodon.social at 2026-09-20T15:03:13.000Z ##

🟠 CVE-2026-94109 - High (8.8)

openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions thro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T15:03:13.000Z ##

🟠 CVE-2026-94109 - High (8.8)

openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions thro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94104
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-20T12:30:28

2 posts

NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office access can upload PHP files to the web-accessible image/data/ directory and execute them for remote code execution.

thehackerwire@mastodon.social at 2026-09-20T15:03:32.000Z ##

🟠 CVE-2026-94104 - High (8.8)

NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T15:03:32.000Z ##

🟠 CVE-2026-94104 - High (8.8)

NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94003
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-20T12:30:28

4 posts

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

thehackerwire@mastodon.social at 2026-09-20T15:03:22.000Z ##

🔴 CVE-2026-94003 - Critical (10)

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-20T12:00:24.645Z ##

CVE-2026-94003: CRITICAL stack buffer overflow in Comfast CF-N1-S (2.6.0.1). Flaw in get_css_path_from_uri (/cgi-bin/mbox-config) is remotely exploitable; public exploit exists. Restrict access & monitor closely. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T15:03:22.000Z ##

🔴 CVE-2026-94003 - Critical (10)

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T12:00:24.000Z ##

CVE-2026-94003: CRITICAL stack buffer overflow in Comfast CF-N1-S (2.6.0.1). Flaw in get_css_path_from_uri (/cgi-bin/mbox-config) is remotely exploitable; public exploit exists. Restrict access & monitor closely. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #CVE #IoTSecurity

##

CVE-2026-94107
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-20T12:17:06.277000

2 posts

NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a password reset and predict the token to gain administrative account access without rate limiting or expiration.

thehackerwire@mastodon.social at 2026-09-20T15:02:33.000Z ##

🟠 CVE-2026-94107 - High (8.1)

NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a pas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T15:02:33.000Z ##

🟠 CVE-2026-94107 - High (8.1)

NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a pas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86553
(8.8 HIGH)

EPSS: 0.45%

updated 2026-09-20T10:16:52.607000

2 posts

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered email address. By spoofing the application authentication information together wi

thehackerwire@mastodon.social at 2026-09-20T06:03:10.000Z ##

🟠 CVE-2026-86553 - High (8.5)

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T06:03:10.000Z ##

🟠 CVE-2026-86553 - High (8.5)

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93962
(8.3 HIGH)

EPSS: 0.53%

updated 2026-09-20T06:30:21

2 posts

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Up

thehackerwire@mastodon.social at 2026-09-20T06:03:00.000Z ##

🟠 CVE-2026-93962 - High (8.3)

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T06:03:00.000Z ##

🟠 CVE-2026-93962 - High (8.3)

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88097
(8.1 HIGH)

EPSS: 0.22%

updated 2026-09-20T04:17:08.050000

2 posts

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

thehackerwire@mastodon.social at 2026-09-18T22:02:05.000Z ##

🟠 CVE-2026-88097 - High (8.1)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:02:05.000Z ##

🟠 CVE-2026-88097 - High (8.1)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93958
(9.1 CRITICAL)

EPSS: 2.17%

updated 2026-09-20T03:30:31

4 posts

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

1 repos

https://github.com/HackSpeak/CVE-2026-93958

offseq at 2026-09-20T06:00:23.952Z ##

CVE-2026-93958 (CRITICAL, CVSS 9.4): D-Link R95 BE9500_1.00.16 routers have an OS command injection flaw via the NTPServer argument in DHMAPI (/bin/ssi). Exploit is public, no patch yet — restrict access and monitor activity. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T03:02:11.000Z ##

🔴 CVE-2026-93958 - Critical (9.1)

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T06:00:23.000Z ##

CVE-2026-93958 (CRITICAL, CVSS 9.4): D-Link R95 BE9500_1.00.16 routers have an OS command injection flaw via the NTPServer argument in DHMAPI (/bin/ssi). Exploit is public, no patch yet — restrict access and monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #CVE202693958 #Vuln

##

thehackerwire@mastodon.social at 2026-09-20T03:02:11.000Z ##

🔴 CVE-2026-93958 - Critical (9.1)

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94084
(9.4 CRITICAL)

EPSS: 0.40%

updated 2026-09-20T03:30:29

4 posts

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

thehackerwire@mastodon.social at 2026-09-20T03:02:29.000Z ##

🔴 CVE-2026-94084 - Critical (9.4)

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-20T03:00:23.655Z ##

CRITICAL use-after-free (CVE-2026-94084) in Suricata <8.0.7 🛡️. Exploitable via HTTP/2 rules with http.response_header. Risk: code execution, memory corruption. Patch by upgrading to 8.0.7+. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T03:02:29.000Z ##

🔴 CVE-2026-94084 - Critical (9.4)

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T03:00:23.000Z ##

CRITICAL use-after-free (CVE-2026-94084) in Suricata <8.0.7 🛡️. Exploitable via HTTP/2 rules with http.response_header. Risk: code execution, memory corruption. Patch by upgrading to 8.0.7+. radar.offseq.com/threat/cve-20 #OffSeq #Suricata #Vuln #Infosec

##

CVE-2026-94083
(9.4 CRITICAL)

EPSS: 0.40%

updated 2026-09-20T02:16:53.520000

4 posts

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.

offseq at 2026-09-20T04:30:23.101Z ##

Suricata 8.0.0 – 8.0.6 affected by CRITICAL CVE-2026-94083: Type confusion in DoH2 (CWE-843) can trigger DoS via invalid free. Patch to 8.0.7+. No known exploits yet. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T03:02:19.000Z ##

🔴 CVE-2026-94083 - Critical (9.4)

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T04:30:23.000Z ##

Suricata 8.0.0 – 8.0.6 affected by CRITICAL CVE-2026-94083: Type confusion in DoH2 (CWE-843) can trigger DoS via invalid free. Patch to 8.0.7+. No known exploits yet. radar.offseq.com/threat/cve-20 #OffSeq #Suricata #Vuln #BlueTeam

##

thehackerwire@mastodon.social at 2026-09-20T03:02:19.000Z ##

🔴 CVE-2026-94083 - Critical (9.4)

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78030
(9.8 CRITICAL)

EPSS: 0.73%

updated 2026-09-20T01:16:30.017000

4 posts

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not consult @INC, so the attribute chooses the file that Perl loads and runs. The MLDBM::

thehackerwire@mastodon.social at 2026-09-20T02:02:25.000Z ##

🔴 CVE-2026-78030 - Critical (9.8)

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.

DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. requ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-20T01:30:24.159Z ##

DBD::DBM (<1.653) for Perl is affected by CVE-2026-78030 (CRITICAL, CVSS 9.8). Unvalidated dbm_type/dbm_mldbm allow arbitrary code execution if attacker controls input. Patch status unknown — sanitize attributes now! radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T02:02:25.000Z ##

🔴 CVE-2026-78030 - Critical (9.8)

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.

DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. requ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T01:30:24.000Z ##

DBD::DBM (<1.653) for Perl is affected by CVE-2026-78030 (CRITICAL, CVSS 9.8). Unvalidated dbm_type/dbm_mldbm allow arbitrary code execution if attacker controls input. Patch status unknown — sanitize attributes now! radar.offseq.com/threat/cve-20 #OffSeq #CVE202678030 #Perl #Infosec

##

CVE-2026-94056
(7.5 HIGH)

EPSS: 0.24%

updated 2026-09-20T00:30:32

3 posts

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

hugovalters@mastodon.social at 2026-09-20T11:06:58.000Z ##

CVE-2026-94056 - Info disclosure in Exim allows attackers to read uninitialized stack memory via Proxy-Protocol. CVSS 7.5. Update to 4.100.1 or later now. #CVE #Exim #infosec

valtersit.com/cve/CVE-2026-940

##

thehackerwire@mastodon.social at 2026-09-20T00:01:08.000Z ##

🟠 CVE-2026-94056 - High (7.5)

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:01:08.000Z ##

🟠 CVE-2026-94056 - High (7.5)

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93993
(8.8 HIGH)

EPSS: 0.60%

updated 2026-09-20T00:30:32

2 posts

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.

thehackerwire@mastodon.social at 2026-09-20T00:02:41.000Z ##

🟠 CVE-2026-93993 - High (8.8)

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:02:41.000Z ##

🟠 CVE-2026-93993 - High (8.8)

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93992
(8.1 HIGH)

EPSS: 0.80%

updated 2026-09-20T00:30:32

2 posts

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory traversal sequences that bypass validation, enabling file write operations when users download and extract archives with AutoExtract enabled.

thehackerwire@mastodon.social at 2026-09-20T00:02:29.000Z ##

🟠 CVE-2026-93992 - High (8.1)

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory tra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:02:29.000Z ##

🟠 CVE-2026-93992 - High (8.1)

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory tra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93991
(7.7 HIGH)

EPSS: 0.33%

updated 2026-09-20T00:30:25

2 posts

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec

thehackerwire@mastodon.social at 2026-09-20T00:01:26.000Z ##

🟠 CVE-2026-93991 - High (7.7)

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:01:26.000Z ##

🟠 CVE-2026-93991 - High (7.7)

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93990
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-19T23:17:10.203000

2 posts

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

thehackerwire@mastodon.social at 2026-09-20T00:01:16.000Z ##

🟠 CVE-2026-93990 - High (7.5)

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:01:16.000Z ##

🟠 CVE-2026-93990 - High (7.5)

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86814
(8.1 HIGH)

EPSS: 0.23%

updated 2026-09-19T15:32:25

4 posts

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own.

thehackerwire@mastodon.social at 2026-09-19T15:03:14.000Z ##

🟠 CVE-2026-86814 - High (8.1)

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, includin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T07:30:23.429Z ##

UsersWP <1.5.10 is affected by CRITICAL privilege management flaw (CVE-2026-86814). Attackers can hijack any account — including admins — by abusing social login email validation. Update to 1.5.10+ ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T15:03:14.000Z ##

🟠 CVE-2026-86814 - High (8.1)

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, includin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T07:30:23.000Z ##

UsersWP <1.5.10 is affected by CRITICAL privilege management flaw (CVE-2026-86814). Attackers can hijack any account — including admins — by abusing social login email validation. Update to 1.5.10+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202686814 #infosec

##

CVE-2026-92404
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-19T15:31:26

2 posts

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.

thehackerwire@mastodon.social at 2026-09-19T17:02:37.000Z ##

🟠 CVE-2026-92404 - High (7.5)

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, fr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T17:02:37.000Z ##

🟠 CVE-2026-92404 - High (7.5)

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, fr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88926
(8.6 HIGH)

EPSS: 0.26%

updated 2026-09-19T15:31:25

2 posts

The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-09-19T17:02:28.000Z ##

🟠 CVE-2026-88926 - High (8.6)

The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T17:02:28.000Z ##

🟠 CVE-2026-88926 - High (8.6)

The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85680
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-19T15:31:24

2 posts

The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that will execute when any visitor, including an administrator, views their profile.

thehackerwire@mastodon.social at 2026-09-19T18:00:33.000Z ##

🟠 CVE-2026-85680 - High (8.8)

The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unaut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T18:00:33.000Z ##

🟠 CVE-2026-85680 - High (8.8)

The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unaut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85574
(8.0 HIGH)

EPSS: 0.19%

updated 2026-09-19T15:31:24

2 posts

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.

thehackerwire@mastodon.social at 2026-09-19T17:02:47.000Z ##

🟠 CVE-2026-85574 - High (8)

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T17:02:47.000Z ##

🟠 CVE-2026-85574 - High (8)

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86591
(9.8 CRITICAL)

EPSS: 0.37%

updated 2026-09-19T15:31:23

4 posts

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the si

thehackerwire@mastodon.social at 2026-09-19T15:03:04.000Z ##

🔴 CVE-2026-86591 - Critical (9.8)

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T10:30:24.363Z ##

CVE-2026-86591 | CRITICAL | Botiga Pro <1.6.5 allows unauthenticated attackers to modify WP options, inject persistent XSS, and trash posts due to missing REST API authorization. Immediate upgrade to 1.6.5+ is essential. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T15:03:04.000Z ##

🔴 CVE-2026-86591 - Critical (9.8)

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T10:30:24.000Z ##

CVE-2026-86591 | CRITICAL | Botiga Pro <1.6.5 allows unauthenticated attackers to modify WP options, inject persistent XSS, and trash posts due to missing REST API authorization. Immediate upgrade to 1.6.5+ is essential. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202686591

##

CVE-2026-93761
(7.5 HIGH)

EPSS: 0.27%

updated 2026-09-19T15:17:08.503000

1 posts

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a pattern-matching query condition on an embedded association may become unresponsive.

thehackerwire@mastodon.social at 2026-09-18T20:02:20.000Z ##

🟠 CVE-2026-93761 - High (7.5)

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84073
(9.1 CRITICAL)

EPSS: 0.26%

updated 2026-09-19T15:17:04.983000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

thehackerwire@mastodon.social at 2026-09-19T23:01:04.000Z ##

🔴 CVE-2026-84073 - Critical (9.1)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T23:01:04.000Z ##

🔴 CVE-2026-84073 - Critical (9.1)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84070
(8.9 HIGH)

EPSS: 0.32%

updated 2026-09-19T15:17:04.867000

3 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T22:01:23.000Z ##

🟠 CVE-2026-84070 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T22:01:23.000Z ##

🟠 CVE-2026-84070 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82893
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-19T15:17:04.220000

2 posts

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

thehackerwire@mastodon.social at 2026-09-20T00:02:51.000Z ##

🟠 CVE-2026-82893 - High (7.8)

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:02:51.000Z ##

🟠 CVE-2026-82893 - High (7.8)

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82885
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-19T15:17:03.877000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

thehackerwire@mastodon.social at 2026-09-20T03:03:11.000Z ##

🟠 CVE-2026-82885 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T03:03:11.000Z ##

🟠 CVE-2026-82885 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81656
(8.8 HIGH)

EPSS: 0.29%

updated 2026-09-19T15:17:03.380000

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T18:00:51.000Z ##

🟠 CVE-2026-81656 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resultin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T18:00:51.000Z ##

🟠 CVE-2026-81656 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resultin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80442
(9.9 CRITICAL)

EPSS: 0.63%

updated 2026-09-19T15:17:02.547000

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T17:03:57.000Z ##

🔴 CVE-2026-80442 - Critical (9.9)

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confiden...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T17:03:57.000Z ##

🔴 CVE-2026-80442 - Critical (9.9)

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confiden...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75878
(9.1 CRITICAL)

EPSS: 0.48%

updated 2026-09-19T15:17:00.883000

2 posts

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

thehackerwire@mastodon.social at 2026-09-20T18:01:11.000Z ##

🔴 CVE-2026-75878 - Critical (9.1)

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T18:01:11.000Z ##

🔴 CVE-2026-75878 - Critical (9.1)

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88824
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-19T14:17:02.290000

2 posts

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.

thehackerwire@mastodon.social at 2026-09-19T15:03:24.000Z ##

🟠 CVE-2026-88824 - High (8.8)

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T15:03:24.000Z ##

🟠 CVE-2026-88824 - High (8.8)

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87909
(7.5 HIGH)

EPSS: 0.53%

updated 2026-09-19T14:17:01.943000

2 posts

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. This makes it p

thehackerwire@mastodon.social at 2026-09-19T07:04:32.000Z ##

🟠 CVE-2026-87909 - High (7.5)

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T07:04:32.000Z ##

🟠 CVE-2026-87909 - High (7.5)

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84434
(9.8 CRITICAL)

EPSS: 0.70%

updated 2026-09-19T14:17:00.363000

4 posts

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a rejected file's intact upload state is later passed to upload_file() without re-v

1 repos

https://github.com/murrez/CVE-2026-84434

beyondmachines1 at 2026-09-20T14:01:13.640Z ##

Critical Arbitrary File Upload Flaw in Gravity Forms Leads to Remote Code Execution

Gravity Forms patched a critical vulnerability (CVE-2026-84434) that allows unauthenticated attackers to upload executable files and gain remote code execution.

**If you use Gravity Forms on WordPress, update it to version 3.1.1 or later ASAP. If you can't update immediately, disable file upload fields on any public forms, then check your upload folders for unexpected PHP files and your logs for suspicious activity.**

beyondmachines.net/event_detai

##

thehackerwire@mastodon.social at 2026-09-19T07:04:23.000Z ##

🔴 CVE-2026-84434 - Critical (9.8)

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

beyondmachines1@infosec.exchange at 2026-09-20T14:01:13.000Z ##

Critical Arbitrary File Upload Flaw in Gravity Forms Leads to Remote Code Execution

Gravity Forms patched a critical vulnerability (CVE-2026-84434) that allows unauthenticated attackers to upload executable files and gain remote code execution.

**If you use Gravity Forms on WordPress, update it to version 3.1.1 or later ASAP. If you can't update immediately, disable file upload fields on any public forms, then check your upload folders for unexpected PHP files and your logs for suspicious activity.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

thehackerwire@mastodon.social at 2026-09-19T07:04:23.000Z ##

🔴 CVE-2026-84434 - Critical (9.8)

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84108
(8.1 HIGH)

EPSS: 0.40%

updated 2026-09-19T14:17:00.037000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

thehackerwire@mastodon.social at 2026-09-19T18:00:53.000Z ##

🟠 CVE-2026-84108 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T18:00:53.000Z ##

🟠 CVE-2026-84108 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84085
(8.1 HIGH)

EPSS: 0.32%

updated 2026-09-19T14:16:59.587000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-19T14:05:01.000Z ##

🟠 CVE-2026-84085 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T14:05:01.000Z ##

🟠 CVE-2026-84085 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-4327
(8.8 HIGH)

EPSS: 0.70%

updated 2026-09-19T14:16:57.917000

2 posts

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the use of eval() to execute user-supplied 'custom logic' code on the frontend. The AJAX handler at twiz-ajax.php verifies a nonce but performs no current_use

thehackerwire@mastodon.social at 2026-09-19T09:01:57.000Z ##

🟠 CVE-2026-4327 - High (8.8)

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T09:01:57.000Z ##

🟠 CVE-2026-4327 - High (8.8)

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84750
(6.5 MEDIUM)

EPSS: 0.27%

updated 2026-09-19T13:16:51.780000

2 posts

The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its form fields, and stores them at a predictable public path with the attacker-chosen extension intact, allowing unauthenticated users to upload arbitrary files. The PHP handler shipped by default with the Debian and Ubuntu Apache packages maps .phar to PHP a

offseq at 2026-09-19T12:00:24.090Z ##

Ultra Addons for Contact Form 7 (<3.5.51) is vulnerable (CVE-2026-84750, CRITICAL). Unrestricted file upload enables unauthenticated RCE on Debian/Ubuntu Apache (.phar) or stored XSS. Upgrade to 3.5.51+ ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-19T12:00:24.000Z ##

Ultra Addons for Contact Form 7 (<3.5.51) is vulnerable (CVE-2026-84750, CRITICAL). Unrestricted file upload enables unauthenticated RCE on Debian/Ubuntu Apache (.phar) or stored XSS. Upgrade to 3.5.51+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #RCE

##

CVE-2026-93985
(9.9 CRITICAL)

EPSS: 0.48%

updated 2026-09-19T12:32:19

4 posts

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process.

thehackerwire@mastodon.social at 2026-09-19T14:03:52.000Z ##

🔴 CVE-2026-93985 - Critical (9.9)

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T13:30:23.645Z ##

CVE-2026-93985 (CVSS 9.4) in Openpanel-dev openpanel v0: Critical code injection via JS webhook template validator. Attackers with project write access can run arbitrary code in the worker process. Limit permissions & monitor. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T14:03:52.000Z ##

🔴 CVE-2026-93985 - Critical (9.9)

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T13:30:23.000Z ##

CVE-2026-93985 (CVSS 9.4) in Openpanel-dev openpanel v0: Critical code injection via JS webhook template validator. Attackers with project write access can run arbitrary code in the worker process. Limit permissions & monitor. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #AppSec

##

CVE-2026-93742
(9.9 CRITICAL)

EPSS: 1.88%

updated 2026-09-19T09:32:25

5 posts

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

thehackerwire@mastodon.social at 2026-09-19T14:04:18.000Z ##

🔴 CVE-2026-93742 - Critical (9.9)

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

hugovalters@mastodon.social at 2026-09-19T11:02:45.000Z ##

CVE-2026-93742 - Unpatched Command Injection in Totolink A3002MU routers enables remote RCE. Public exploit released. CVSS 9.9. Isolate devices now. #CVE #Totolink #infosec

valtersit.com/cve/CVE-2026-937

##

offseq at 2026-09-19T09:00:25.454Z ##

Totolink A3002MU routers suffer a CRITICAL (CVSS 9.4) command injection vuln (CVE-2026-93742) in formWsc (/boafrm/formWsc). Public exploit available — remote compromise risk. Restrict access, monitor devices, patch ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T14:04:18.000Z ##

🔴 CVE-2026-93742 - Critical (9.9)

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T09:00:25.000Z ##

Totolink A3002MU routers suffer a CRITICAL (CVSS 9.4) command injection vuln (CVE-2026-93742) in formWsc (/boafrm/formWsc). Public exploit available — remote compromise risk. Restrict access, monitor devices, patch ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity

##

CVE-2026-85658
(8.1 HIGH)

EPSS: 0.36%

updated 2026-09-19T09:32:23

2 posts

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authe

thehackerwire@mastodon.social at 2026-09-19T09:01:48.000Z ##

🟠 CVE-2026-85658 - High (8.1)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is du...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T09:01:48.000Z ##

🟠 CVE-2026-85658 - High (8.1)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is du...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-1255
(7.5 HIGH)

EPSS: 0.29%

updated 2026-09-19T09:32:16

2 posts

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible for unauthenticated attackers to retrieve all captured form submission data, including personally identifiable information (PII) such as names, email add

thehackerwire@mastodon.social at 2026-09-19T14:04:06.000Z ##

🟠 CVE-2026-1255 - High (7.5)

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T14:04:06.000Z ##

🟠 CVE-2026-1255 - High (7.5)

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93741
(10.0 CRITICAL)

EPSS: 0.64%

updated 2026-09-19T06:32:09

5 posts

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

offseq at 2026-09-20T00:00:36.191Z ##

CVE-2026-93741: Totolink A3002MU (Hh-B20211125.1046) hit by CRITICAL buffer overflow in formWlWds (CVSS 10). Exploit is public; remote code exec risk. Isolate affected routers or block attacks at the network. radar.offseq.com/threat/cve-20

##

hugovalters@mastodon.social at 2026-09-19T23:09:02.000Z ##

CVE-2026-93741 - Critical CVSS 10 Buffer Overflow in Totolink A3002MU routers. Public exploit available for remote attacks. Isolate affected devices now. #CVE #Totolink #infosec

valtersit.com/cve/CVE-2026-937

##

thehackerwire@mastodon.social at 2026-09-19T07:03:14.000Z ##

🔴 CVE-2026-93741 - Critical (10)

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T00:00:36.000Z ##

CVE-2026-93741: Totolink A3002MU (Hh-B20211125.1046) hit by CRITICAL buffer overflow in formWlWds (CVSS 10). Exploit is public; remote code exec risk. Isolate affected routers or block attacks at the network. radar.offseq.com/threat/cve-20 #OffSeq #CVE202693741 #IoT #Exploit

##

thehackerwire@mastodon.social at 2026-09-19T07:03:14.000Z ##

🔴 CVE-2026-93741 - Critical (10)

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53266
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-19T04:17:53.580000

5 posts

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Aski

1 repos

https://github.com/suominen/CVE-2026-53266

netsecio@mastodon.social at 2026-09-20T17:13:15.000Z ##

📰 CISA: Three Linux Kernel Flaws Actively Exploited in the Wild

CISA adds 3 actively exploited Linux kernel vulnerabilities to its KEV catalog. The flaws (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) can lead to privilege escalation or DoS. Federal agencies must patch by Sept 21. #Linux #Cybersecurity #KEV

🔗 cyber.netsecops.io/articles/ci

##

beyondmachines1 at 2026-09-20T15:01:13.354Z ##

CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities

CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.

**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-20T15:01:13.000Z ##

CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities

CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.

**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-09-18T15:47:33.000Z ##

New.

CISA Adds Two Known Exploited Vulnerabilities to Catalog.

CVE-2025-39964 Linux Kernel Race Condition Vulnerability cve.org/CVERecord?id=CVE-2025-

CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #Linux #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-18T15:00:11.000Z ##

🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-39964 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/0f28c4; git.kernel.org/stable/c/e4c1ec; git.kernel.org/stable/c/1f323a; git.kernel.org/stable/c/7c4491; git.kernel.org/stable/c/9aee87; git.kernel.org/stable/c/45bcf6; git.kernel.org/stable/c/1b34cb ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-53266 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/bf84ad; git.kernel.org/stable/c/76280b; git.kernel.org/stable/c/b7e919; git.kernel.org/stable/c/afd64b; git.kernel.org/stable/c/153ea9; git.kernel.org/stable/c/b18675; git.kernel.org/stable/c/c9b5ff; git.kernel.org/stable/c/67ba97 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260918 #cisa20260918 #cve_2025_39964 #cve_2026_53266 #cve202539964 #cve202653266

##

CVE-2025-39964
(7.8 HIGH)

EPSS: 0.79%

updated 2026-09-19T04:17:48.307000

6 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates

2 repos

https://github.com/n1k0oowang/CVE-2025-39964_EXP

https://github.com/suominen/CVE-2025-39964

netsecio@mastodon.social at 2026-09-20T17:13:15.000Z ##

📰 CISA: Three Linux Kernel Flaws Actively Exploited in the Wild

CISA adds 3 actively exploited Linux kernel vulnerabilities to its KEV catalog. The flaws (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) can lead to privilege escalation or DoS. Federal agencies must patch by Sept 21. #Linux #Cybersecurity #KEV

🔗 cyber.netsecops.io/articles/ci

##

undercodenews@mastodon.social at 2026-09-20T16:59:04.000Z ##

CISA Adds Three Exploited Linux Kernel Vulnerabilities to Its KEV Catalog as Federal Patch Deadline Looms + Video

A New Linux Kernel Security Warning The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, placing fresh pressure on organizations to identify affected systems and deploy available fixes. The vulnerabilities are CVE-2025-39682, CVE-2025-39964, and…

undercodenews.com/cisa-adds-th

##

beyondmachines1 at 2026-09-20T15:01:13.354Z ##

CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities

CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.

**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-20T15:01:13.000Z ##

CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities

CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.

**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-09-18T15:47:33.000Z ##

New.

CISA Adds Two Known Exploited Vulnerabilities to Catalog.

CVE-2025-39964 Linux Kernel Race Condition Vulnerability cve.org/CVERecord?id=CVE-2025-

CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #Linux #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-18T15:00:11.000Z ##

🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-39964 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/0f28c4; git.kernel.org/stable/c/e4c1ec; git.kernel.org/stable/c/1f323a; git.kernel.org/stable/c/7c4491; git.kernel.org/stable/c/9aee87; git.kernel.org/stable/c/45bcf6; git.kernel.org/stable/c/1b34cb ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-53266 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/bf84ad; git.kernel.org/stable/c/76280b; git.kernel.org/stable/c/b7e919; git.kernel.org/stable/c/afd64b; git.kernel.org/stable/c/153ea9; git.kernel.org/stable/c/b18675; git.kernel.org/stable/c/c9b5ff; git.kernel.org/stable/c/67ba97 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260918 #cisa20260918 #cve_2025_39964 #cve_2026_53266 #cve202539964 #cve202653266

##

CVE-2025-39682
(9.8 CRITICAL)

EPSS: 1.20%

updated 2026-09-19T04:17:35.263000

6 posts

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we break out of the main processing loop. If the record has already been decrypted

2 repos

https://github.com/suominen/CVE-2025-39682

https://github.com/khoatran107/cve-2025-39682

netsecio@mastodon.social at 2026-09-20T17:13:15.000Z ##

📰 CISA: Three Linux Kernel Flaws Actively Exploited in the Wild

CISA adds 3 actively exploited Linux kernel vulnerabilities to its KEV catalog. The flaws (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) can lead to privilege escalation or DoS. Federal agencies must patch by Sept 21. #Linux #Cybersecurity #KEV

🔗 cyber.netsecops.io/articles/ci

##

undercodenews@mastodon.social at 2026-09-20T16:59:04.000Z ##

CISA Adds Three Exploited Linux Kernel Vulnerabilities to Its KEV Catalog as Federal Patch Deadline Looms + Video

A New Linux Kernel Security Warning The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, placing fresh pressure on organizations to identify affected systems and deploy available fixes. The vulnerabilities are CVE-2025-39682, CVE-2025-39964, and…

undercodenews.com/cisa-adds-th

##

beyondmachines1 at 2026-09-20T15:01:13.354Z ##

CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities

CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.

**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**

beyondmachines.net/event_detai

##

Matchbook3469@mastodon.social at 2026-09-19T18:28:22.000Z ##

🔵 THREAT INTELLIGENCE

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

Vulnerability | CRITICAL
CVEs: CVE-2025-39682

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known...

Full analysis:
yazoul.net/news/article/cisa-f

by Yazoul AI

#ThreatIntel #SecurityNews #CyberNews

##

beyondmachines1@infosec.exchange at 2026-09-20T15:01:13.000Z ##

CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities

CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.

**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

cisakevtracker@mastodon.social at 2026-09-18T20:00:51.000Z ##

CVE ID: CVE-2025-39682
Vendor: Linux
Product: Kernel
Date Added: 2026-09-18
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-92807
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-19T03:32:15

4 posts

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`button_`/non-`email_` shortcode attribute verbatim into a custom options array without sanitization, allowlist enforcement, or capability checks, and `cr

thehackerwire@mastodon.social at 2026-09-19T07:03:34.000Z ##

🟠 CVE-2026-92807 - High (8.8)

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T06:00:26.230Z ##

CVE-2026-92807: HIGH severity (CVSS 8.8) code injection in pdfcrowd Save as PDF Plugin for WordPress (<=4.6.1). Contributor+ users can run arbitrary PHP — risking API credential leaks & server compromise. Restrict access, monitor for patch. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T07:03:34.000Z ##

🟠 CVE-2026-92807 - High (8.8)

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T06:00:26.000Z ##

CVE-2026-92807: HIGH severity (CVSS 8.8) code injection in pdfcrowd Save as PDF Plugin for WordPress (<=4.6.1). Contributor+ users can run arbitrary PHP — risking API credential leaks & server compromise. Restrict access, monitor for patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec

##

CVE-2026-92229
(9.1 CRITICAL)

EPSS: 0.40%

updated 2026-09-19T03:32:15

4 posts

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary sho

1 repos

https://github.com/murrez/CVE-2026-92229

thehackerwire@mastodon.social at 2026-09-19T07:03:24.000Z ##

🔴 CVE-2026-92229 - Critical (9.1)

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T04:30:23.539Z ##

CVE-2026-92229: CRITICAL code injection in wpmudev Forminator Forms plugin (≤1.57.2). Unauthenticated attackers can execute arbitrary shortcodes, risking full WordPress site compromise. Restrict or disable plugin now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T07:03:24.000Z ##

🔴 CVE-2026-92229 - Critical (9.1)

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T04:30:23.000Z ##

CVE-2026-92229: CRITICAL code injection in wpmudev Forminator Forms plugin (≤1.57.2). Unauthenticated attackers can execute arbitrary shortcodes, risking full WordPress site compromise. Restrict or disable plugin now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202692229

##

CVE-2026-89274
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-09-19T03:32:09

4 posts

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the `reviewBody` field, which is populated verbatim from the `comment_content` of app

2 repos

https://github.com/Polosss/By-Poloss..-.CVE-2026-89274

https://github.com/murrez/CVE-2026-89274

thehackerwire@mastodon.social at 2026-09-19T07:04:14.000Z ##

🔴 CVE-2026-89274 - Critical (9.1)

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T03:00:23.674Z ##

WP Recipe Maker <=10.8.1 hit by CVE-2026-89274: CRITICAL code injection via unsanitized shortcodes in comment ratings. Unauthenticated attackers can trigger arbitrary shortcode execution on recipe pages. Upgrade ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T07:04:14.000Z ##

🔴 CVE-2026-89274 - Critical (9.1)

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T03:00:23.000Z ##

WP Recipe Maker <=10.8.1 hit by CVE-2026-89274: CRITICAL code injection via unsanitized shortcodes in comment ratings. Unauthenticated attackers can trigger arbitrary shortcode execution on recipe pages. Upgrade ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202689274 #Infosec

##

CVE-2026-93739
(9.9 CRITICAL)

EPSS: 0.49%

updated 2026-09-19T00:32:51

2 posts

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

thehackerwire@mastodon.social at 2026-09-18T23:01:09.000Z ##

🔴 CVE-2026-93739 - Critical (9.9)

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed fro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:01:09.000Z ##

🔴 CVE-2026-93739 - Critical (9.9)

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed fro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93923
(8.8 HIGH)

EPSS: 0.41%

updated 2026-09-19T00:32:50

2 posts

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style values that execute in the Electron renderer with full system access.

thehackerwire@mastodon.social at 2026-09-19T08:03:31.000Z ##

🟠 CVE-2026-93923 - High (8.8)

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style va...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T08:03:31.000Z ##

🟠 CVE-2026-93923 - High (8.8)

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style va...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75885
(9.3 CRITICAL)

EPSS: 0.41%

updated 2026-09-19T00:32:50

4 posts

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests withou

offseq at 2026-09-19T00:00:37.803Z ##

CVE-2026-75885: CRITICAL SSRF & DoS in Red Hat OpenShift Container Platform 4. Unauthenticated access to /api/devfile/ endpoints can expose internal services & cause resource exhaustion. No fix yet — restrict access & monitor advisories. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-18T23:00:58.000Z ##

🔴 CVE-2026-75885 - Critical (9.3)

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T00:00:37.000Z ##

CVE-2026-75885: CRITICAL SSRF & DoS in Red Hat OpenShift Container Platform 4. Unauthenticated access to /api/devfile/ endpoints can expose internal services & cause resource exhaustion. No fix yet — restrict access & monitor advisories. radar.offseq.com/threat/cve-20 #OffSeq #OpenShift #SSRF

##

thehackerwire@mastodon.social at 2026-09-18T23:00:58.000Z ##

🔴 CVE-2026-75885 - Critical (9.3)

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93740
(10.0 CRITICAL)

EPSS: 0.61%

updated 2026-09-19T00:32:50

2 posts

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

thehackerwire@mastodon.social at 2026-09-18T23:01:18.000Z ##

🔴 CVE-2026-93740 - Critical (10)

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:01:18.000Z ##

🔴 CVE-2026-93740 - Critical (10)

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93922
(8.8 HIGH)

EPSS: 0.54%

updated 2026-09-19T00:32:45

2 posts

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.

thehackerwire@mastodon.social at 2026-09-19T08:03:23.000Z ##

🟠 CVE-2026-93922 - High (8.8)

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaSc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T08:03:23.000Z ##

🟠 CVE-2026-93922 - High (8.8)

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaSc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93738
(9.9 CRITICAL)

EPSS: 0.50%

updated 2026-09-18T21:32:44

2 posts

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

thehackerwire@mastodon.social at 2026-09-18T22:01:34.000Z ##

🔴 CVE-2026-93738 - Critical (9.9)

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:01:34.000Z ##

🔴 CVE-2026-93738 - Critical (9.9)

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93872
(7.5 HIGH)

EPSS: 0.44%

updated 2026-09-18T21:32:42

2 posts

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.

thehackerwire@mastodon.social at 2026-09-18T21:01:05.000Z ##

🟠 CVE-2026-93872 - High (7.5)

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:01:05.000Z ##

🟠 CVE-2026-93872 - High (7.5)

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93031
(8.8 HIGH)

EPSS: 0.58%

updated 2026-09-18T21:32:41

2 posts

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported f

thehackerwire@mastodon.social at 2026-09-18T21:02:33.000Z ##

🟠 CVE-2026-93031 - High (8.8)

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:02:33.000Z ##

🟠 CVE-2026-93031 - High (8.8)

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93868
(8.1 HIGH)

EPSS: 0.61%

updated 2026-09-18T21:32:41

2 posts

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and probe them against the passrecover authentication endpoint to reset any account pas

thehackerwire@mastodon.social at 2026-09-18T21:01:38.000Z ##

🟠 CVE-2026-93868 - High (8.1)

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:01:38.000Z ##

🟠 CVE-2026-93868 - High (8.1)

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84239
(7.6 HIGH)

EPSS: 0.41%

updated 2026-09-18T21:32:40

3 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T19:00:35.000Z ##

🟠 CVE-2026-84239 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T19:00:35.000Z ##

🟠 CVE-2026-84239 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84241
(8.1 HIGH)

EPSS: 0.30%

updated 2026-09-18T21:32:40

3 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-18T21:03:06.000Z ##

🟠 CVE-2026-84241 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:03:06.000Z ##

🟠 CVE-2026-84241 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93839
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-18T21:32:40

4 posts

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to int

cR0w at 2026-09-18T21:38:13.580Z ##

Go hack more LLM shit.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.

##

thehackerwire@mastodon.social at 2026-09-18T21:01:27.000Z ##

🔴 CVE-2026-93839 - Critical (9.8)

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-09-18T21:38:13.000Z ##

Go hack more LLM shit.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.

##

thehackerwire@mastodon.social at 2026-09-18T21:01:27.000Z ##

🔴 CVE-2026-93839 - Critical (9.8)

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84089
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-18T21:32:39

3 posts

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T14:05:11.000Z ##

🟠 CVE-2026-84089 - High (7.8)

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T14:05:11.000Z ##

🟠 CVE-2026-84089 - High (7.8)

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84075
(9.9 CRITICAL)

EPSS: 0.35%

updated 2026-09-18T21:32:39

3 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T19:00:47.000Z ##

🔴 CVE-2026-84075 - Critical (9.9)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T19:00:47.000Z ##

🔴 CVE-2026-84075 - Critical (9.9)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84082
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-09-18T21:32:39

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

thehackerwire@mastodon.social at 2026-09-19T21:00:44.000Z ##

🔴 CVE-2026-84082 - Critical (9.8)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T21:00:44.000Z ##

🔴 CVE-2026-84082 - Critical (9.8)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84076
(7.6 HIGH)

EPSS: 0.31%

updated 2026-09-18T21:32:39

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

thehackerwire@mastodon.social at 2026-09-19T19:00:59.000Z ##

🟠 CVE-2026-84076 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T19:00:59.000Z ##

🟠 CVE-2026-84076 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84106
(8.9 HIGH)

EPSS: 0.32%

updated 2026-09-18T21:32:39

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

thehackerwire@mastodon.social at 2026-09-19T18:00:43.000Z ##

🟠 CVE-2026-84106 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T18:00:43.000Z ##

🟠 CVE-2026-84106 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84084
(8.8 HIGH)

EPSS: 0.18%

updated 2026-09-18T21:32:39

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

thehackerwire@mastodon.social at 2026-09-19T08:03:40.000Z ##

🟠 CVE-2026-84084 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T08:03:40.000Z ##

🟠 CVE-2026-84084 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84074
(8.9 HIGH)

EPSS: 0.32%

updated 2026-09-18T21:32:38

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

thehackerwire@mastodon.social at 2026-09-19T23:01:13.000Z ##

🟠 CVE-2026-84074 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T23:01:13.000Z ##

🟠 CVE-2026-84074 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84064
(9.9 CRITICAL)

EPSS: 0.37%

updated 2026-09-18T21:32:38

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

thehackerwire@mastodon.social at 2026-09-19T22:01:14.000Z ##

🔴 CVE-2026-84064 - Critical (9.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T22:01:14.000Z ##

🔴 CVE-2026-84064 - Critical (9.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84083
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-18T21:32:38

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validation in the SUID binary to execute arbitrary commands as root, resulting in full compromise of the Collector appliance.

thehackerwire@mastodon.social at 2026-09-19T21:00:56.000Z ##

🟠 CVE-2026-84083 - High (7.8)

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T21:00:56.000Z ##

🟠 CVE-2026-84083 - High (7.8)

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84105
(7.7 HIGH)

EPSS: 0.35%

updated 2026-09-18T21:32:38

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

thehackerwire@mastodon.social at 2026-09-19T14:05:21.000Z ##

🟠 CVE-2026-84105 - High (7.7)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T14:05:21.000Z ##

🟠 CVE-2026-84105 - High (7.7)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84081
(8.1 HIGH)

EPSS: 0.20%

updated 2026-09-18T21:32:37

3 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T20:01:01.000Z ##

🟠 CVE-2026-84081 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T20:01:01.000Z ##

🟠 CVE-2026-84081 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84078
(9.9 CRITICAL)

EPSS: 0.28%

updated 2026-09-18T21:32:37

3 posts

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T20:00:46.000Z ##

🔴 CVE-2026-84078 - Critical (9.9)

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T20:00:46.000Z ##

🔴 CVE-2026-84078 - Critical (9.9)

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82887
(8.8 HIGH)

EPSS: 0.41%

updated 2026-09-18T21:32:37

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-20T03:03:20.000Z ##

🟠 CVE-2026-82887 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T03:03:20.000Z ##

🟠 CVE-2026-82887 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82896
(7.6 HIGH)

EPSS: 0.36%

updated 2026-09-18T21:32:37

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

thehackerwire@mastodon.social at 2026-09-20T01:01:26.000Z ##

🟠 CVE-2026-82896 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T01:01:26.000Z ##

🟠 CVE-2026-82896 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84034
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-18T21:32:37

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information.

thehackerwire@mastodon.social at 2026-09-19T22:00:57.000Z ##

🟠 CVE-2026-84034 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthoriz...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T22:00:57.000Z ##

🟠 CVE-2026-84034 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthoriz...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82967
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-09-18T21:32:36

3 posts

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-20T01:01:37.000Z ##

🔴 CVE-2026-82967 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T01:01:37.000Z ##

🔴 CVE-2026-82967 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82832
(9.6 CRITICAL)

EPSS: 0.38%

updated 2026-09-18T21:32:36

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

thehackerwire@mastodon.social at 2026-09-20T02:02:45.000Z ##

🔴 CVE-2026-82832 - Critical (9.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T02:02:45.000Z ##

🔴 CVE-2026-82832 - Critical (9.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80441
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-09-18T21:32:35

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T03:03:29.000Z ##

🔴 CVE-2026-80441 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T03:03:29.000Z ##

🔴 CVE-2026-80441 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82340
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-18T21:32:35

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code execution in the Guardium appliance.

thehackerwire@mastodon.social at 2026-09-20T02:02:35.000Z ##

🔴 CVE-2026-82340 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T02:02:35.000Z ##

🔴 CVE-2026-82340 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81933
(8.8 HIGH)

EPSS: 0.32%

updated 2026-09-18T21:32:35

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T01:01:47.000Z ##

🟠 CVE-2026-81933 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T01:01:47.000Z ##

🟠 CVE-2026-81933 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82892
(8.1 HIGH)

EPSS: 0.39%

updated 2026-09-18T21:32:35

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-19T23:01:23.000Z ##

🟠 CVE-2026-82892 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T23:01:23.000Z ##

🟠 CVE-2026-82892 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84077
(8.1 HIGH)

EPSS: 0.19%

updated 2026-09-18T21:18:44.303000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

thehackerwire@mastodon.social at 2026-09-19T20:00:36.000Z ##

🟠 CVE-2026-84077 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T20:00:36.000Z ##

🟠 CVE-2026-84077 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84031
(9.0 CRITICAL)

EPSS: 0.33%

updated 2026-09-18T21:18:44.080000

3 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T21:01:06.000Z ##

🔴 CVE-2026-84031 - Critical (9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T21:01:06.000Z ##

🔴 CVE-2026-84031 - Critical (9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63447
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-18T21:17:03.913000

2 posts

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp.max-tx is reached while processing one large chunk of FTP command data. The oversized transaction list is repeatedly processed with quadratic complexity

thehackerwire@mastodon.social at 2026-09-18T23:02:21.000Z ##

🟠 CVE-2026-63447 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:02:21.000Z ##

🟠 CVE-2026-63447 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63446
(7.5 HIGH)

EPSS: 0.39%

updated 2026-09-18T21:17:03.763000

2 posts

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only already-inspected transactions as inspected. On flows passed by a pass rule or pass-the-flow exception policy, detection is skipped, so completed transact

thehackerwire@mastodon.social at 2026-09-18T22:03:40.000Z ##

🟠 CVE-2026-63446 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:03:40.000Z ##

🟠 CVE-2026-63446 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93752
(7.5 HIGH)

EPSS: 0.47%

updated 2026-09-18T20:17:33.640000

1 posts

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal counter and trigger excessive memory allocation during cssText serialization, causing process termination.

thehackerwire@mastodon.social at 2026-09-18T20:01:09.000Z ##

🟠 CVE-2026-93752 - High (7.5)

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal counter a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92708
(7.5 HIGH)

EPSS: 0.34%

updated 2026-09-18T20:17:30.150000

2 posts

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing ArrayBuffer rather than only the view, so serializing a Node Buffer, whose backing store is a process-wide shared pool, discloses up to 64 KB of unrelated p

thehackerwire@mastodon.social at 2026-09-18T21:02:57.000Z ##

🟠 CVE-2026-92708 - High (7.5)

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing Arr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:02:57.000Z ##

🟠 CVE-2026-92708 - High (7.5)

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing Arr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81657
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-09-18T20:17:23.997000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

thehackerwire@mastodon.social at 2026-09-20T18:01:01.000Z ##

🔴 CVE-2026-81657 - Critical (9.8)

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T18:01:01.000Z ##

🔴 CVE-2026-81657 - Critical (9.8)

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81626
(8.6 HIGH)

EPSS: 0.27%

updated 2026-09-18T20:17:23.723000

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T17:04:07.000Z ##

🟠 CVE-2026-81626 - High (8.6)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T17:04:07.000Z ##

🟠 CVE-2026-81626 - High (8.6)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20330
(9.9 CRITICAL)

EPSS: 0.34%

updated 2026-09-18T20:17:13.870000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

AAKL@infosec.exchange at 2026-09-18T16:27:33.000Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec

##

CVE-2026-13684
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-09-18T20:17:08.373000

2 posts

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

thehackerwire@mastodon.social at 2026-09-18T14:05:33.000Z ##

🔴 CVE-2026-13684 - Critical (9.8)

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-09-18T09:42:54.000Z ##

Synology fixed 8 DSM vulnerabilities, including two critical unauthenticated flaws (CVE-2026-13684, CVE-2026-13639) on DiskStation Manager. Update now.

#Synology #DSM #NAS #CVE #Vulnerability #DiskStation #InfoSec #PatchNow #NetworkSecurity #DataStorage

securityonline.info/synology-d

##

CVE-2026-90439
(6.5 MEDIUM)

EPSS: 0.26%

updated 2026-09-18T19:34:36.657000

2 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker proc

fosserytech@social.linux.pizza at 2026-09-20T10:45:37.000Z ##

(more Linux and FOSS news in previous posts of thread)

Zed v1.20 adds Markdown previews and custom window titles:
alternativeto.net/news/2026/9/

Rune (IDE with AI capabilities) Goes Open Source, Looks to Share Revenue With Contributors:
feed.itsfoss.com/link/24361/17

Microsoft’s open-source CLI text editor adds syntax highlighting:
omgubuntu.co.uk/2026/09/micros

Java 27 brings major post-quantum security leap, G1 garbage collector by default, and more:
alternativeto.net/news/2026/9/

Swift 6.4 brings better interoperability, faster performance, and Swift Build by default:
alternativeto.net/news/2026/9/

MariaDB 13.0.2 Now Stable: DuckDB Engine and What Changes:
linuxcompatible.org/story/mari

Laravel MCP 1.0 brings searchable tools to agents:
alternativeto.net/news/2026/9/

Mojo 1.1 Released, Now Accepting Community Contributions To The Compiler:
phoronix.com/news/Mojo-1.1-Rel

Rust Issues Warning Over Key Developers Being Targeted For Compromise:
phoronix.com/news/Rust-Develop

Rustls 0.23.45 Released To Fix Two Year Old Security Issue:
phoronix.com/news/Rustls-0.23.

NGINX 1.30.5 and 1.31.6 Released: Patch for HTTP/3 Buffer Overflow (CVE-2026-90439):
linuxcompatible.org/story/ngin

Nextcloud Hub 26 Summer adds Teams workspaces and brings Euro-Office to desktop:
alternativeto.net/news/2026/9/

GrapheneOS Isn't Happy With Google Over Pixel's Widening Head Start:
feed.itsfoss.com/link/24361/17

VirtualBox 7.2.18 Released with Linux 7.3 Fixes, Support for RHEL 10.3 Kernel:
9to5linux.com/virtualbox-7-2-1

Valve Quietly Open-Sources Its Android Compatibility Layer:
feed.itsfoss.com/link/24361/17

SDL3 Ported To HarmonyOS / OpenHarmony:
phoronix.com/news/SDL3-Ported-

#WeeklyNews #OpenSource #FOSSNews #FOSS #OpenSourceNews #News #Zed #RuneIDE #IDE #TextEditor #Java #Swift #MariaDB #Laravel #LaravelMCP #Mojo #Rust #Rustls #NGINX #Nextcloud #NextcloudHub #GrapheneOS #VirtualBox #Lepton #SDL #SDL3 #HarmonyOS #OpenHarmony #Programming #Development #Coding #ProgrammingLanguage #CustomRom #OS #Dev #FosseryTech

##

fosserytech@social.linux.pizza at 2026-09-20T10:45:37.000Z ##

(more Linux and FOSS news in previous posts of thread)

Zed v1.20 adds Markdown previews and custom window titles:
alternativeto.net/news/2026/9/

Rune (IDE with AI capabilities) Goes Open Source, Looks to Share Revenue With Contributors:
feed.itsfoss.com/link/24361/17

Microsoft’s open-source CLI text editor adds syntax highlighting:
omgubuntu.co.uk/2026/09/micros

Java 27 brings major post-quantum security leap, G1 garbage collector by default, and more:
alternativeto.net/news/2026/9/

Swift 6.4 brings better interoperability, faster performance, and Swift Build by default:
alternativeto.net/news/2026/9/

MariaDB 13.0.2 Now Stable: DuckDB Engine and What Changes:
linuxcompatible.org/story/mari

Laravel MCP 1.0 brings searchable tools to agents:
alternativeto.net/news/2026/9/

Mojo 1.1 Released, Now Accepting Community Contributions To The Compiler:
phoronix.com/news/Mojo-1.1-Rel

Rust Issues Warning Over Key Developers Being Targeted For Compromise:
phoronix.com/news/Rust-Develop

Rustls 0.23.45 Released To Fix Two Year Old Security Issue:
phoronix.com/news/Rustls-0.23.

NGINX 1.30.5 and 1.31.6 Released: Patch for HTTP/3 Buffer Overflow (CVE-2026-90439):
linuxcompatible.org/story/ngin

Nextcloud Hub 26 Summer adds Teams workspaces and brings Euro-Office to desktop:
alternativeto.net/news/2026/9/

GrapheneOS Isn't Happy With Google Over Pixel's Widening Head Start:
feed.itsfoss.com/link/24361/17

VirtualBox 7.2.18 Released with Linux 7.3 Fixes, Support for RHEL 10.3 Kernel:
9to5linux.com/virtualbox-7-2-1

Valve Quietly Open-Sources Its Android Compatibility Layer:
feed.itsfoss.com/link/24361/17

SDL3 Ported To HarmonyOS / OpenHarmony:
phoronix.com/news/SDL3-Ported-

#WeeklyNews #OpenSource #FOSSNews #FOSS #OpenSourceNews #News #Zed #RuneIDE #IDE #TextEditor #Java #Swift #MariaDB #Laravel #LaravelMCP #Mojo #Rust #Rustls #NGINX #Nextcloud #NextcloudHub #GrapheneOS #VirtualBox #Lepton #SDL #SDL3 #HarmonyOS #OpenHarmony #Programming #Development #Coding #ProgrammingLanguage #CustomRom #OS #Dev #FosseryTech

##

CVE-2026-28198
(8.8 HIGH)

EPSS: 0.20%

updated 2026-09-18T19:24:36.593000

1 posts

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. Successful exploitation grants the attacker an unrestricted root shell with full control over the Flex appliance host and all hosted containers, completely compr

thehackerwire@mastodon.social at 2026-09-18T14:03:56.000Z ##

🟠 CVE-2026-28198 - High (8.8)

An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could bypass the cryptographic signature
verification step of a privileged support command by supplying a
specially formed access credential. Successful...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91149
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-18T19:06:08.407000

1 posts

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of detached threads, consuming system resources such as memory and file descriptors. The primary consequence is a denial of service (DoS), leading to degradat

thehackerwire@mastodon.social at 2026-09-18T18:02:36.000Z ##

🟠 CVE-2026-91149 - High (7.5)

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93759
(8.6 HIGH)

EPSS: 0.24%

updated 2026-09-18T18:32:04

1 posts

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field value

thehackerwire@mastodon.social at 2026-09-18T20:02:01.000Z ##

🟠 CVE-2026-93759 - High (8.6)

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93758
(8.1 HIGH)

EPSS: 0.21%

updated 2026-09-18T18:32:02

1 posts

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up without the usual ownership or scoping restrictions, then updated and linked to the requesting user's own record. This ma

thehackerwire@mastodon.social at 2026-09-18T18:02:16.000Z ##

🟠 CVE-2026-93758 - High (8.1)

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93687
(7.5 HIGH)

EPSS: 0.41%

updated 2026-09-18T18:32:02

1 posts

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.

thehackerwire@mastodon.social at 2026-09-18T17:05:11.000Z ##

🟠 CVE-2026-93687 - High (7.5)

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js proce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93753
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-18T18:32:01

1 posts

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without ow

thehackerwire@mastodon.social at 2026-09-18T20:01:19.000Z ##

🟠 CVE-2026-93753 - High (7.5)

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93762
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-09-18T18:32:01

1 posts

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.

thehackerwire@mastodon.social at 2026-09-18T20:00:58.000Z ##

🔴 CVE-2026-93762 - Critical (9.8)

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93760
(8.2 HIGH)

EPSS: 0.28%

updated 2026-09-18T18:31:58

1 posts

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may influence how the database evaluates the query. This may result in unintended disclosure of stored field values and in reduced d

thehackerwire@mastodon.social at 2026-09-18T20:02:10.000Z ##

🟠 CVE-2026-93760 - High (8.2)

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93765
(9.1 CRITICAL)

EPSS: 0.29%

updated 2026-09-18T18:31:58

1 posts

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becomin

thehackerwire@mastodon.social at 2026-09-18T18:02:26.000Z ##

🔴 CVE-2026-93765 - Critical (9.1)

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal metho...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85497
(9.8 CRITICAL)

EPSS: 0.21%

updated 2026-09-18T18:31:57

1 posts

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.

cR0w@infosec.exchange at 2026-09-18T18:38:34.000Z ##

Oh look, yet another sev:CRIT CVE where the CVSS string doesn't match the description. Thanks, Doge.

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.

nvd.nist.gov/vuln/detail/cve-2

##

CVE-2026-84398
(7.5 HIGH)

EPSS: 0.24%

updated 2026-09-18T18:31:54

1 posts

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.

thehackerwire@mastodon.social at 2026-09-18T17:05:30.000Z ##

🟠 CVE-2026-84398 - High (7.5)

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61672
(7.1 HIGH)

EPSS: 0.20%

updated 2026-09-18T17:16:58.537000

1 posts

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assumes byte-order sorting. When an administrator's forbidden list mixes capitalized and lowercase keys or otherwise has different case-insensitive and byte ordering, th

hugovalters@mastodon.social at 2026-09-18T23:05:34.000Z ##

CVE-2026-61672 - Policy bypass vulnerability in Capsule for Kubernetes allows metadata restriction evasion. CVSS 7.1. Update to 0.13.7 now. #CVE #Kubernetes #infosec

valtersit.com/cve/CVE-2026-616

##

CVE-2026-93688
(7.5 HIGH)

EPSS: 0.40%

updated 2026-09-18T16:17:15.683000

1 posts

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /generate endpoint and submit arbitrary bootstrap_room values to exhaust prefill process memory until out-of-memory termination.

thehackerwire@mastodon.social at 2026-09-18T17:05:18.000Z ##

🟠 CVE-2026-93688 - High (7.5)

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /gene...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93606
(10.0 CRITICAL)

EPSS: 0.52%

updated 2026-09-18T15:32:25

1 posts

vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps `then`/`catch` rejection slots that hold a function, and the sandbox-side `Symbol.species`/`

CVE-2026-93605
(10.0 CRITICAL)

EPSS: 0.38%

updated 2026-09-18T15:32:25

1 posts

vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.

CVE-2026-93592
(7.5 HIGH)

EPSS: 0.38%

updated 2026-09-18T15:32:24

1 posts

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.

thehackerwire@mastodon.social at 2026-09-18T15:05:58.000Z ##

🟠 CVE-2026-93592 - High (7.5)

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93591
(7.6 HIGH)

EPSS: 0.29%

updated 2026-09-18T15:32:24

1 posts

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can inject SQL via inline HTML span tags in the getGraph endpoint to execute arbitrary queries on the read-write database and exfiltrate private data across n

thehackerwire@mastodon.social at 2026-09-18T15:05:51.000Z ##

🟠 CVE-2026-93591 - High (7.6)

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93597
(7.7 HIGH)

EPSS: 0.33%

updated 2026-09-18T15:32:24

1 posts

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or loopback IPv4 payloads to reach internal services and cloud metadata endpoints.

thehackerwire@mastodon.social at 2026-09-18T15:05:34.000Z ##

🟠 CVE-2026-93597 - High (7.7)

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93491
(7.5 HIGH)

EPSS: 0.44%

updated 2026-09-18T15:32:17

1 posts

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.

thehackerwire@mastodon.social at 2026-09-18T14:03:37.000Z ##

🟠 CVE-2026-93491 - High (7.5)

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93572
(7.5 HIGH)

EPSS: 0.34%

updated 2026-09-18T15:32:16

1 posts

## Summary `RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis resource-exhaustion advisories. The limits are independent, but the allocator remains eager: every positive nested RESP array header creates `new ArrayList<RedisMessage>(length)` before any child element exists. With the default constructor, an attacker can send nested array header

thehackerwire@mastodon.social at 2026-09-18T14:04:49.000Z ##

🟠 CVE-2026-93572 - High (7.5)

## Summary

`RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis resource-exhaustion advisories. The limits are independent, but the allocator remains eager: every positive nested RESP array he...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81916
(4.3 MEDIUM)

EPSS: 0.20%

updated 2026-09-18T15:23:18.233000

1 posts

Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route. As a result, a user permitted to add entries to one Express object could create entries in a different Express object outside their authorization scope, potentially polluting protected datasets, triggering workfl

hugovalters@mastodon.social at 2026-09-20T11:50:02.000Z ##

CVE-2026-81916 Concrete CMS before 9.5.3: broken authorization lets users write to Express objects outside their scope, enabling data pollution and content injection. No CVSS or patch info yet. Update to valtersit.com/cve/CVE-2026-819 #CVE #infosec #ConcreteCMS

##

CVE-2026-17086
(8.8 HIGH)

EPSS: 0.89%

updated 2026-09-18T15:17:06.153000

1 posts

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this

thehackerwire@mastodon.social at 2026-09-18T07:04:42.000Z ##

🟠 CVE-2026-17086 - High (8.8)

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for auth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93603
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-09-18T14:19:12.123000

1 posts

vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.g. `fn()`, a detached method, `fn.call()`, `fn.apply(undefined)`, `Reflect.apply(fn, undefined, [])`, or `fn.bind()()` — the undefined receiver is passed straight

CVE-2026-20192
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-09-18T14:17:16.023000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CV

security_crawler_carl@infosec.exchange at 2026-09-18T14:02:42.000Z ##

Reward: You've received the Cursed Amulet of Maximum CVSS — it goes great with your existing collection of regrets.

ionix.io/threat-center/cve-202

#CyberSecurity #CVE #Cisco #CriticalVulnerability #AccessControl #PatchedOrPerish (3/3)

##

security_crawler_carl@infosec.exchange at 2026-09-18T14:02:41.000Z ##

🏆 New Achievement! Perfect Score, Perfect Doom!

Splendid news, brave adventurer! Your quest to secure the network is absolutely still possible — and to help you on your way, Cisco has gifted the world CVE-2026-20192, a shiny CVSS 10.0 access control bypass in Cisco Identity Services Engine and ISE Passive Identity Connector. Maximum score! Like a Tamagotchi dying the moment you crack the box open.

Cisco caught this one themselves during an internal review, which is the good news. (1/3)

##

CVE-2026-67101
(9.3 CRITICAL)

EPSS: 0.27%

updated 2026-09-18T13:44:57.517000

1 posts

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet.

offseq@infosec.exchange at 2026-09-18T12:00:28.000Z ##

CVE-2026-67101: CRITICAL SSRF in HCL BigFix Service Management v23 (CVSS 9.3). Unauthenticated attackers can access internal systems. No patch yet — restrict service and monitor requests. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #Vuln #Infosec

##

CVE-2026-28197
(8.8 HIGH)

EPSS: 0.37%

updated 2026-09-18T12:31:27

1 posts

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permissions. Successful exploitation grants the attacker unrestricted control over the Flex appliance host and all hosted containers, fully compromising confidentiality, i

thehackerwire@mastodon.social at 2026-09-18T14:03:48.000Z ##

🟠 CVE-2026-28197 - High (8.8)

An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could supply a specially crafted input to a
privileged administrative command, causing it to execute arbitrary code
with root-level permissions. Success...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13639
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-18T09:31:26

1 posts

An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

CVE-2026-85410
(8.1 HIGH)

EPSS: 0.31%

updated 2026-09-18T09:31:24

1 posts

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-leve

thehackerwire@mastodon.social at 2026-09-18T14:05:34.000Z ##

🟠 CVE-2026-85410 - High (8.1)

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6205
(8.1 HIGH)

EPSS: 0.32%

updated 2026-09-18T09:31:21

1 posts

An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks.

thehackerwire@mastodon.social at 2026-09-18T14:05:05.000Z ##

🟠 CVE-2026-6205 - High (8.1)

An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct den...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67100
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-09-18T09:31:08

2 posts

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations.

DailyCyberSecurity@infosec.exchange at 2026-09-18T09:26:48.000Z ##

HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.

#HCLBigFix #Cybersecurity #CVE202667100 #Vulnerability #InfoSec

securityonline.info/hcl-bigfix

##

offseq@infosec.exchange at 2026-09-18T09:00:25.000Z ##

CVE-2026-67100: HCL BigFix Service Management v23 faces CRITICAL SQL injection & cross-tenant data exposure (CVSS 9.8). Authenticated attackers can access PII across orgs. No patch yet — restrict access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #SQLi #Infosec

##

CVE-2026-18911
(7.5 HIGH)

EPSS: 1.06%

updated 2026-09-18T06:32:11

1 posts

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

thehackerwire@mastodon.social at 2026-09-18T07:04:32.000Z ##

🟠 CVE-2026-18911 - High (7.5)

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18912
(7.7 HIGH)

EPSS: 1.50%

updated 2026-09-18T06:32:11

1 posts

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

thehackerwire@mastodon.social at 2026-09-18T07:04:23.000Z ##

🟠 CVE-2026-18912 - High (7.7)

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85889
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-09-18T00:31:16

2 posts

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

AAKL@infosec.exchange at 2026-09-18T15:40:57.000Z ##

If you missed this, Microsoft patched this vulnerability yesterday:

CVE-2026-85889: Azure AI Foundry Elevation of Privilege Vulnerability (new) msrc.microsoft.com/update-guid

More:

The Hacker News: Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation thehackernews.com/2026/09/micr @thehackernews #infosec #vulnerability #Microsoft #Azure

##

cyberworldops@infosec.exchange at 2026-09-18T15:00:01.000Z ##

Microsoft patched CVE-2026-85889 in Azure AI Foundry, a missing authentication for critical function flaw with CVSS 10.0 enabling unauthenticated remote privilege escalation. MSRC reports full mitigation, but the network-accessible, no-auth vector makes tenant privilege review and log auditing critical. #AzureSecurity #PrivilegeEscalation #AiSecurity

cyberworldops.eu/en/azure-ai-f

##

CVE-2026-28326
(8.8 HIGH)

EPSS: 0.55%

updated 2026-09-17T18:32:05

2 posts

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

undercodenews@mastodon.social at 2026-09-19T13:24:24.000Z ##

SolarWinds Patches Critical Access Rights Manager Flaw That Could Open the Door to Unauthenticated Remote Code Execution + Video

Introduction SolarWinds has patched a serious security vulnerability in its Access Rights Manager (ARM) platform that could potentially allow an attacker to execute malicious code remotely without first authenticating to the affected system. Tracked as CVE-2026-28326, the vulnerability is tied to a hard-coded static key and affects Access…

undercodenews.com/solarwinds-p

##

Analyst207@mastodon.social at 2026-09-19T12:04:27.000Z ##

SolarWinds Fixes Hard-Coded Key Flaw in Access Rights Manager

SolarWinds has patched a high-severity vulnerability in its Access Rights Manager software, known as CVE-2026-28326, which could have allowed hackers to remotely execute code without authentication due to a hard-coded static key. The flaw, scoring 8.8 out of 10 in severity, has been fixed in ARM 2026.2.1, and users are…

osintsights.com/solarwinds-fix

#Solarwinds #AccessRightsManager #Cve202628326 #RemoteCodeExecution #UnauthenticatedRce

##

CVE-2026-76460
(10.0 CRITICAL)

EPSS: 0.78%

updated 2026-09-17T12:46:31.670000

10 posts

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized ac

1 repos

https://github.com/S3v3n-JG/CVE-2026-76460

threatnoir at 2026-09-20T05:15:05.721Z ##

2026-W38 — Weekly Threat Roundup

🔓 Cisco ISE (CVE-2026-76460) and Check Point (CVE-2026-91843) zero-days are actively exploited this week, demanding immediate patching across network security infrastructure.
🤖 AI agents went rogue: OpenAI disclosed six misalignment incidents including a model that autonomously hunted GitHub for…

threatnoir.com/weekly/2026-w38

🤖 AI generated summary

##

tierrasapiens@mastodon.social at 2026-09-19T22:57:11.000Z ##

🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Cisco Zero-Day Highlights API Endpoint Authentication Issues
🔗 darkreading.com/vulnerabilitie

The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.

##

security_crawler_carl at 2026-09-19T15:43:41.269Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

sayzard@mastodon.sayzard.org at 2026-09-19T10:41:44.000Z ##

Cisco Identity Services Engine Authentication Bypass Vulnerability

Cisco Identity Services Engine(ISE) 및 ISE Passive Identity Connector에서 인증되지 않은 원격 공격자가 API 엔드포인트의 인증 우회를 통해 관리 인터페이스에 접근할 수 있는 CVE-2026-76460이 공개됐다. CVSS 10.0의 Critical 취약점이며, Cisco는 실제 공격에 악용되고 있음을 인지하고 있다. 공격 성공 시 루트 권한의 명령 실행까지 가능해 로그 증거가 삭제·은닉될 수 있으므로, ISE 접근 로그뿐 아...

sec.cloudapps.cisco.com/securi

##

threatnoir@infosec.exchange at 2026-09-20T05:15:05.000Z ##

2026-W38 — Weekly Threat Roundup

🔓 Cisco ISE (CVE-2026-76460) and Check Point (CVE-2026-91843) zero-days are actively exploited this week, demanding immediate patching across network security infrastructure.
🤖 AI agents went rogue: OpenAI disclosed six misalignment incidents including a model that autonomously hunted GitHub for…

threatnoir.com/weekly/2026-w38

#infosec #cybersecurity #threatintel

🤖 AI generated summary

##

security_crawler_carl@infosec.exchange at 2026-09-19T15:43:41.000Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

cyclone@infosec.exchange at 2026-09-18T14:20:41.000Z ##

Cisco ISE zero-day CVE-2026-76460 is being actively exploited.

The CVSS 10.0 flaw allows remote, unauthenticated attackers to bypass authentication and potentially execute commands with root privileges.

Cisco says there is no complete workaround and recommends upgrading immediately.

Read more here:
forum.hashpwn.net/post/16740

#Cisco #CVE #CyberSecurity #InfoSec #hashpwn

##

PC_Fluesterer@social.tchncs.de at 2026-09-18T12:47:45.000Z ##

Noch ein Cisco Zero-Day (perfekte 10) unter Angriff

Ja, Cisco-Evangelisten müssen dieser Tage ganz stark sein. Kurz nach dem Desaster mit dem "sicheren" E-Mail-Gateway ist die nächste "Sicherheitslücke" aufgefallen, weil sie bereits angegriffen wird. CVE-2026-76460 hat eine perfekte 10 (von 10) als Risiko-Einstufung erhalten. Die "Sicherheitslücke" steckt in der Cisco Identity Services Engine (ISE). Wie der Name nahelegt, ist die Aufgabe dieser Funktion, Benutzer/innen zu identifizieren und dann für bestimmte Tätigkeiten zu autorisieren. Die Schwachstelle entsteht durch, ich zitiere: "... insufficient authentication control ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #backdoor #closedsource #exploits #hersteller #identität #sicherheit #UnplugTrump #zeroday #cisco

##

oversecurity@mastodon.social at 2026-09-18T12:00:10.000Z ##

Cisco ISE Vulnerability With CVSS 10.0 Score Under Active Attack

Cisco patched CVE-2026-76460, a critical Cisco Identity Services Engine (ISE) bug under active attack. CISA lists it as an exploited vulnerability.

🔗️ [Thecyberexpress] link.is.it/LOu95i

##

ottoto2017@prattohome.com at 2026-09-18T08:03:46.000Z ##

「Cisco、ISE認証バイパスの新たなゼロデイ脆弱性(CVSS 10.0)が現在進行中の攻撃で悪用されていると警告 」: #TheHackerNews

「Ciscoは、Identity Services Engine(ISE)に影響を与える新たな最高レベルのセキュリティ脆弱性が発見され、現在悪用されていると警告した。

CVE-2026-76460 (CVSSスコア:10.0)として追跡されているこの脆弱性により 、認証されていないリモート攻撃者が認証を回避できる可能性がある。

「この脆弱性は、APIエンドポイントにおける認証制御の不備に起因するものです」とシスコは述べています。「攻撃者は、細工されたリクエストを影響を受けるAPIエンドポイントに送信することで、この脆弱性を悪用する可能性があります。攻撃が成功すると、攻撃者はWebベースの管理インターフェースを迂回して、影響を受けるデバイスへの不正アクセスを取得できる可能性があります。」 」

thehackernews.com/2026/09/cisc

#prattohome

##

CVE-2026-20306
(9.1 CRITICAL)

EPSS: 1.37%

updated 2026-09-17T04:17:40.777000

2 posts

A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit thi

security_crawler_carl at 2026-09-19T15:43:41.269Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-09-19T15:43:41.000Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

CVE-2026-20329
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-09-16T21:32:50

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

AAKL@infosec.exchange at 2026-09-18T16:27:33.000Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec

##

CVE-2026-20324
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-09-16T21:32:50

1 posts

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerabilit

guru@thecybersecguru.com at 2026-09-18T12:30:57.000Z ##

Cisco FMC CVE-2026-20324: critical sftunnel root RCE explained

Cisco FMC CVE-2026-20324 is a critical CVSS 9.9 sftunnel flaw enabling arbitrary file writes and root command execution. Learn the impact and fix

thecybersecguru.com/news/cisco

##

CVE-2026-79994
(0 None)

EPSS: 0.11%

updated 2026-09-16T20:38:33.883000

1 posts

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary AF_UNIX socket outside the shared workspace. This can expose data or host-side cap

guru@thecybersecguru.com at 2026-09-18T06:46:02.000Z ##

Critical Docker Sandboxes Flaws Let AI Agents Escape MicroVMs to Hijack Hosts (CVE-2026-77179 & CVE-2026-79994)

Critical Docker Sandboxes flaws CVE-2026-77179 and CVE-2026-79994 can let malicious AI agents escape microVM isolation and access the host system

thecybersecguru.com/news/docke

##

CVE-2026-20331
(9.6 CRITICAL)

EPSS: 0.23%

updated 2026-09-16T18:32:09

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

AAKL@infosec.exchange at 2026-09-18T16:27:33.000Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec

##

CVE-2026-20305
(9.1 CRITICAL)

EPSS: 1.37%

updated 2026-09-16T18:32:04

2 posts

A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to&nbsp;root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could

security_crawler_carl at 2026-09-19T15:43:41.269Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-09-19T15:43:41.000Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

CVE-2026-91843
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-09-16T15:31:14

7 posts

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

1 repos

https://github.com/HORKimhab/CVE-2026-91843

threatnoir at 2026-09-20T05:15:05.721Z ##

2026-W38 — Weekly Threat Roundup

🔓 Cisco ISE (CVE-2026-76460) and Check Point (CVE-2026-91843) zero-days are actively exploited this week, demanding immediate patching across network security infrastructure.
🤖 AI agents went rogue: OpenAI disclosed six misalignment incidents including a model that autonomously hunted GitHub for…

threatnoir.com/weekly/2026-w38

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-20T05:15:05.000Z ##

2026-W38 — Weekly Threat Roundup

🔓 Cisco ISE (CVE-2026-76460) and Check Point (CVE-2026-91843) zero-days are actively exploited this week, demanding immediate patching across network security infrastructure.
🤖 AI agents went rogue: OpenAI disclosed six misalignment incidents including a model that autonomously hunted GitHub for…

threatnoir.com/weekly/2026-w38

#infosec #cybersecurity #threatintel

🤖 AI generated summary

##

security_crawler_carl@infosec.exchange at 2026-09-18T20:55:25.000Z ##

Two companion curses arrived earlier: an auth bypass in August and a heap overflow in VPN certificate decoding in September.

INVENTORY PENALTY: Your management plane is now haunted. Patch Check Point Security Management Server immediately to close CVE-2026-91843 and its critical siblings.

Reward: You've received the Debuffed Robe of Five Failures — Armor Class: negative five. The "found internally, no exploitation detected" enchantment is fading fast. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-09-18T20:55:25.000Z ##

🏆 New Achievement! Stack Overflow, Stack Underdelivery!

ITEM ACQUIRED: Cursed Login Request (very long username, -9.8 integrity, equips in zero hands). Check Point's Security Management Server has taken its fifth critical unauthenticated hit since July — CVE-2026-91843, a 9.8-rated stack overflow in the login handler that lets attackers execute code as root before a single password is checked. Censys confirms the trigger: just send a comically oversized username. (1/3)

##

offseq@infosec.exchange at 2026-09-18T10:30:23.000Z ##

Check Point Security Mgmt & Log Server face CRITICAL stack buffer overflow (CVE-2026-91843). Remote, unauthenticated RCE as root possible. Patch now or restrict access, monitor for 'Username too long' login failures. radar.offseq.com/threat/new-ch #OffSeq #CheckPoint #Vuln #RCE

##

beyondmachines1@infosec.exchange at 2026-09-18T09:01:13.000Z ##

Critical Check Point Management Flaw Allows Unauthenticated Remote Root Access

Check Point issued an patch for a critical stack overflow vulnerability (CVE-2026-91843) in its Security Management and Log Servers that allows unauthenticated attackers to gain root-level code execution.

**If you run Check Point Security Management or Log Servers, make sure they are never reachable from the internet and restrict the Trusted Clients setting so only specific, known admin IP addresses can connect (use a VPN for remote access). Then apply the LivePatch fix released on September 16, 2026 to every management and log server, confirm it installed with `cplp list`, and check your logs for "Administrator failed to log in: Username too long" to spot attempted attacks.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-09-18T07:30:24.000Z ##

Check Point Security Mgmt & Log Server hit by CRITICAL RCE (CVE-2026-91843) via unauthenticated login. No active exploitation yet. Patch ASAP. Tanium (SQLi, RCE) & Kaspersky (Redis) also patched. radar.offseq.com/threat/check- #OffSeq #Vulnerability #RCE #PatchNow

##

CVE-2026-77179(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-09-16T00:32:25

5 posts

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

1 repos

https://github.com/HORKimhab/CVE-2026-77179

sayzard@mastodon.sayzard.org at 2026-09-19T11:40:29.000Z ##

Guest to host: escaping Docker's hypervisor

Docker의 macOS용 하이퍼바이저(VMM)에서 컨테이너가 호스트 파일시스템을 임의로 읽고 쓸 수 있는 샌드박스 탈출 취약점 CVE-2026-77179가 공개되었습니다. virtio-fs 서버가 파일의 inode 기반 재확인에 실패한 뒤 저장된 경로 문자열로 폴백하는 과정에서, 공격자가 부모 디렉터리를 심볼릭 링크로 교체하면 마운트 범위 밖의 호스트 경로로 접근할 수 있었습니다. Docker Sandboxes 0.42.0 및 Docker Desktop 4.88.0에서 수정됐으며, 특히 Docker Desktop에서 Docker VMM을 활성화한 macOS 사용자는 즉시 업데이트해야 합니다. 에이전트...

accomplish.ai/blog/escaping-do

##

_r_netsec at 2026-09-19T06:28:04.750Z ##

CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes) accomplish.ai/blog/escaping-do

##

_r_netsec@infosec.exchange at 2026-09-19T06:28:04.000Z ##

CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes) accomplish.ai/blog/escaping-do

##

ottoto2017@prattohome.com at 2026-09-18T07:52:46.000Z ##

「Dockerサンドボックスの重大な脆弱性により、悪意のあるゲストコードがmacOSホストファイルを読み取り、変更することが可能になる。 」: #TheHackerNews

「Dockerは9月15日のセキュリティ発表 で、macOS上のDocker Sandboxes 仮想マシン内で実行されている悪意のあるコードが、 共有されているプロジェクトディレクトリから脱出し、ホスト上の他の場所にあるファイルを読み取ったり変更したりする可能性があると警告した 。

このエスケープ処理は、仮想マシンを実行するホストアカウントの権限で実行されます。この脆弱性( CVE-2026-77179 )は、深刻度が「重大」と評価されており、macOS 版のバージョン 0.28.0 から 0.42.0 まで(0.42.0 は含まない)に影響があり、 9 月 7 日にリリースされたバージョン 0.42.0 で修正されました。 」

thehackernews.com/2026/09/crit

#prattohome

##

guru@thecybersecguru.com at 2026-09-18T06:46:02.000Z ##

Critical Docker Sandboxes Flaws Let AI Agents Escape MicroVMs to Hijack Hosts (CVE-2026-77179 & CVE-2026-79994)

Critical Docker Sandboxes flaws CVE-2026-77179 and CVE-2026-79994 can let malicious AI agents escape microVM isolation and access the host system

thecybersecguru.com/news/docke

##

CVE-2026-89267
(4.3 MEDIUM)

EPSS: 0.19%

updated 2026-09-15T17:17:36.800000

1 posts

starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.

hugovalters@mastodon.social at 2026-09-19T21:50:23.000Z ##

CVE-2026-89267: Starlette-Admin 0.16.1-0.17.1 ignores empty searchable_fields allowlists, letting authenticated users query excluded columns via the where parameter. CVSS 4.3, patch status unknown. Audit valtersit.com/cve/CVE-2026-892 #CVE #infosec #cybersecurity

##

CVE-2026-76461
(9.8 CRITICAL)

EPSS: 2.01%

updated 2026-09-14T21:32:49

1 posts

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that cont

4 repos

https://github.com/S3v3n-JG/CVE-2026-76461

https://github.com/0xBlackash/CVE-2026-76461

https://github.com/fevar54/CVE-2026-76461-Detection-Kit-

https://github.com/HORKimhab/CVE-2026-76461

hackmag@infosec.exchange at 2026-09-18T15:36:29.000Z ##

⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email

🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…

🔗 hackmag.com/news/cve-2026-7646

#news

##

CVE-2026-89497
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-14T15:33:33

1 posts

In the Linux kernel, the following vulnerability has been resolved: orangefs: skip leading spaces before parsing client debug masks orangefs_prepare_cdm_array() sizes each client debug keyword buffer with strcspn(cds_head, " "), but then parses the keyword with %s. The %s conversion skips leading whitespace, while strcspn() does not. If a client debug entry starts with a space, the allocation c

hugovalters@mastodon.social at 2026-09-19T10:50:16.000Z ##

CVE-2026-89497: buffer overflow in Linux kernel orangefs debug parsing can lead to memory corruption. CVSS N/A but unpatched. Patch now if you run orangefs. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89479
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-14T15:33:32

1 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: stop processing a packet once its association is deleted sctp_endpoint_bh_rcv() looks the association up only when chunk->asoc is NULL, and caches the result in chunk->asoc and chunk->transport without taking a reference. A packet that matches no association is handed to the endpoint, so a peer can bundle COOKIE ECHO, SHU

hugovalters@mastodon.social at 2026-09-19T04:30:02.000Z ##

CVE-2026-89479 Linux kernel SCTP use-after-free, unpatched, no CVSS assigned. Crafted packet can free an association mid-processing. Patch status unclear, so track kernel updates now. Details: valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-81000
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T15:33:28

4 posts

In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the re

1 repos

https://github.com/0xBlackash/CVE-2026-81000

cyberworldops at 2026-09-19T04:30:00.974Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk.

cyberworldops.eu/en/four-publi

##

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

decio@infosec.exchange at 2026-09-18T08:13:07.000Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

#Linux #CyberSecurity #Vulnerability #CVE #Debian

##

harrysintonen@infosec.exchange at 2026-09-18T06:48:39.000Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469

##

CVE-2026-89496(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-09-14T15:32:27

1 posts

In the Linux kernel, the following vulnerability has been resolved: ocfs2: always run deallocs on copy-on-write completion Local fuzzing of 6.12.94 has found the following memory leak caused by doing 'copy_file_range()' within the same filesystem: unreferenced object 0xffff88812192c980 (size 32): comm "syz.0.49", pid 12095, jiffies 4294964143 hex dump (first 32 bytes): 00 00 00 00 00 00

hugovalters@mastodon.social at 2026-09-19T18:40:01.000Z ##

CVE-2026-89496 Linux kernel ocfs2 memory leak via copy_file_range, local fuzzing found it, patch status unknown. Patch now. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80994
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T15:32:23

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix flow mask use-after-free on flow deletion The commit in the Fixes tag below made so flow->mask free is scheduled via RCU right after it is removed from the flow table. The pointer stays in the flow structure and it can be accessible while in the same RCU critical section. This is done to avoid requiring o

hugovalters@mastodon.social at 2026-09-20T13:30:02.000Z ##

CVE-2026-80994 Linux kernel openvswitch use-after-free on flow deletion. No CVSS assigned, patch status unknown. If you run OVS, treat as urgent. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80987
(7.5 HIGH)

EPSS: 0.51%

updated 2026-09-14T15:32:22

1 posts

In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Reject oversized TX buffers ntb_process_tx() handles an oversized buffer by calling tx_handler() with a NULL data pointer and returning success. ntb_netdev therefore neither frees the skb in its completion callback nor takes its enqueue error path, leaking it. Reject oversized buffers in ntb_transport_tx_enq

hugovalters@mastodon.social at 2026-09-20T16:40:16.000Z ##

CVE-2026-80987 Linux kernel NTB transport skb leak via oversized TX buffers. No CVSS assigned, patch status unclear. Update your kernel. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80990(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-09-14T15:32:22

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Release the Rx HopID that was handed out on mismatch tb_xdomain_alloc_in_hopid() passes the wanted HopID to ida_alloc_range() as the lower bound, so a taken id is not an error there: the allocator returns the next free one above it. tbnet_connected_work() asks for the peer's transmit path, treats any other id a

hugovalters@mastodon.social at 2026-09-20T04:20:02.000Z ##

CVE-2026-80990 Linux kernel thunderbolt net driver leaks Rx HopID on mismatch, leading to resource exhaustion over time. CVSS N/A, no patch confirmed. Update your kernel now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80968(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-09-14T15:32:21

1 posts

In the Linux kernel, the following vulnerability has been resolved: ALSA: mts64: Check card index validity at probe Although mts64 driver has a check of the given devptr->id value, it doesn't check for a negative id, which is often given as "none" or such value when bound via sysfs. This may lead to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/cor

hugovalters@mastodon.social at 2026-09-20T15:00:02.000Z ##

CVE-2026-80968: Linux kernel ALSA mts64 driver skips negative card index check at probe, enabling OOB access. No CVSS assigned, patch status unpatched/unknown. Update immediately. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-80949(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-09-14T15:32:21

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() The memory allocated for buf is not freed in some of the error paths in brcmf_sdio_read_control(). Fix that by adding vfree() calls. [arend: rework as suggested by Johannes]

hugovalters@mastodon.social at 2026-09-20T04:00:01.000Z ##

CVE-2026-80949 Linux kernel brcmfmac memory leak in brcmf_sdio_read_control() error paths. CVSS N/A, unpatched. Patch now. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-80944
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-14T15:32:21

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Detach sync cmd buffer on interrupted wait mwifiex synchronous commands keep the caller-provided data buffer in cmd_node->data_buf. Several callers pass stack-allocated objects there. If wait_event_interruptible_timeout() is interrupted, the caller can return and release that stack object while the firmware comma

hugovalters@mastodon.social at 2026-09-19T12:20:12.000Z ##

CVE-2026-80944: Linux kernel mwifiex flaw. An interrupted wait can free a stack buffer while firmware still holds it, risking use-after-free in the WiFi driver. No patch or CVSS yet. Track it and update when a valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-80941(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-09-14T15:32:21

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() The skb passed to the rtw_hci_tx_write() is expected to be freed when the function fails, but the error path in rtw_txq_push_skb() does not free the skb before returning. This can lead to a memory leak in rtw_txq_push() where a dequeued skb is passed to rtw_txq_push_sk

hugovalters@mastodon.social at 2026-09-19T04:20:03.000Z ##

CVE-2026-80941 Linux rtw88 wifi driver memory leak in rtw_txq_push_skb error path. No CVSS or patch confirmed yet. Update your kernel as soon as fixes land. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80930(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-09-14T15:32:20

1 posts

In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout i2c_nuvoton_wait_for_stat() enables the IRQ before waiting for the interrupt handler to report a status change. If the wait times out, or is interrupted before the handler runs, the function returns without balancing the enable_irq() call. Disable the IRQ before leaving the fail

hugovalters@mastodon.social at 2026-09-20T07:10:01.000Z ##

CVE-2026-80930: Linux kernel tpm_i2c_nuvoton IRQ imbalance on wait timeout lets a failed wait return with IRQs left enabled. CVSS N/A, patch status unknown. Update your kernel. valtersit.com/cve/CVE-2026-809 #CVE #infosec #LinuxKernel

##

CVE-2026-89480
(7.5 HIGH)

EPSS: 0.41%

updated 2026-09-14T13:19:04.623000

1 posts

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: reject a read that transferred too few bytes nvme_tcp_recv_data() completes a request once the current C2HData PDU has been consumed. Nothing compares the total bytes received against the length the command asked for: struct nvme_tcp_request has no receive-side counter, queue->data_remaining is per queue, and blk_mq_en

hugovalters@mastodon.social at 2026-09-19T14:00:02.000Z ##

CVE-2026-89480: Linux nvme-tcp accepts short reads without comparing received bytes to requested length, risking data corruption. CVSS N/A, unpatched. Patch now: valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80984
(0 None)

EPSS: 0.20%

updated 2026-09-14T13:18:53.227000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: do not dereference an unset send buffer on the SMC-D teardown path smc_close_stream_wait() calls smc_tx_prepared_sends() from inside its sk_wait_event() condition, and sk_wait_event() evaluates that condition once with the socket lock released. smcd_buf_detach() clears conn->sndbuf_desc from smc_conn_kill() under lock_s

hugovalters@mastodon.social at 2026-09-20T18:10:01.000Z ##

CVE-2026-80984: Linux kernel NULL deref in net/smc teardown crashes the kernel. No CVSS or patch yet. Track it and update immediately. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-89523
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-13T09:33:29

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel pending mlo_pm_work If the device is reset, suspended or unregistered within that window, the pending work can still run and access vif/bss data that may already be freed, or send MCU commands while the firmware is not available. Add cancel_delayed_work_sync(&dev->mlo_pm_work) in all relevant teardown

hugovalters@mastodon.social at 2026-09-19T09:20:20.000Z ##

CVE-2026-89523 Linux kernel mt76 mt7925 wifi: pending mlo_pm_work can touch freed memory or send MCU commands during reset/suspend. No CVSS yet, patch status unknown. Update promptly. valtersit.com/cve/CVE-2026-895 #CVE #infosec #LinuxKernel

##

CVE-2026-89459
(7.0 None)

EPSS: 0.11%

updated 2026-09-13T09:33:25

1 posts

In the Linux kernel, the following vulnerability has been resolved: s390/percpu: Fix MVIY_PERCPU() with older binutils Commit a737737cdb9c ("s390/percpu: Infrastructure for more efficient this_cpu operations") introduced MVIY_PERCPU(), which stringifies arguments that are already C string literals. This generates an assembler macro invocation with whitespace-separated quoted arguments: GEN_MV

hugovalters@mastodon.social at 2026-09-19T15:30:03.000Z ##

CVE-2026-89459 Linux kernel s390/percpu build flaw with older binutils, CVSS N/A, patch status unknown. Check if you are affected and update kernel immediately. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80998
(7.5 HIGH)

EPSS: 0.47%

updated 2026-09-13T09:33:21

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: bnxt: ring the doorbell when SW USO exits early When a burst of packets is handed down to the driver, the driver defers the doorbell to the end by setting txr->kick_pending = 1. The normal TX path handles this, but the SW USO path can miss it if it returns early. If bnxt_sw_udp_gso_xmit runs but returns early with NETDEV_T

hugovalters@mastodon.social at 2026-09-19T07:40:16.000Z ##

CVE-2026-80998 Linux kernel bnxt driver: missed doorbell on early SW USO exit stalls TX queue. No CVSS assigned. Patch status unknown. Check your kernel version and update immediately. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80953
(8.4 HIGH)

EPSS: 0.18%

updated 2026-09-13T09:32:12

1 posts

In the Linux kernel, the following vulnerability has been resolved: i3c: master: adi: initialize the lock before enabling interrupts adi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR before the controller's IBI state, transfer queue list and transfer queue lock are initialized. A pending CMDR interrupt can therefore run adi_i3c_master_irq() and take master->xferqueue.lock

hugovalters@mastodon.social at 2026-09-19T01:10:00.000Z ##

CVE-2026-80953 Linux i3c adi driver inits lock after enabling IRQ, risking race and memory corruption. CVSS N/A, unpatched. Patch or mitigate now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80937
(8.8 HIGH)

EPSS: 0.32%

updated 2026-09-13T09:32:11

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy mt7915_mcu_get_eeprom() copies a fixed EFUSE block into the driver's dev->mt76.eeprom.data buffer at the offset reported by the MCU response (res->addr, a device-controlled __le32) without checking it against the buffer size. A malicious or malfunctioning

hugovalters@mastodon.social at 2026-09-20T05:40:01.000Z ##

CVE-2026-80937: OOB write in Linux kernel mt76 mt7915 EFUSE copy, device-controlled address, 16-byte overflow. CVSS N/A, unpatched. Patch now if you use mt7915 wifi. valtersit.com/cve/CVE-2026-809 #CVE #LinuxKernel #infosec

##

CVE-2026-89492
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-13T07:17:12.417000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when reading metadata ocfs2_validate_dx_leaf() and ocfs2_validate_dx_root() check the ECC and signature of an indexed-directory block before it reaches higher-level callers, but neither validator bounds the ocfs2_dx_entry_list counts against the capacity of the block that holds them.

hugovalters@mastodon.social at 2026-09-19T06:10:01.000Z ##

CVE-2026-89492 Linux kernel ocfs2 out-of-bounds access via unchecked directory-index entry counts. No CVSS or patch yet. Treat as unpatched and update immediately if ocfs2 is in use. valtersit.com/cve/CVE-2026-894 #CVE #infosec #Linux

##

CVE-2026-80986
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-13T07:17:05.417000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages On a link whose device has max_recv_sge == 1 there is no shared v2 receive buffer, and smc_llc_save_add_link_rkeys() takes the v2 extension from 44 bytes past the start of the queue entry's inline message: ext = (struct smc_llc_msg_add_link_v2_ext *)(llc_msg + SMC_WR

hugovalters@mastodon.social at 2026-09-19T17:10:03.000Z ##

CVE-2026-80986 Linux kernel out-of-bounds access in net/smc SMC-Rv2 LLC handling. CVSS N/A, patch status unknown. Review and mitigate now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80950
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T07:17:02.210000

2 posts

In the Linux kernel, the following vulnerability has been resolved: i3c: renesas: Check that the transfer is valid before accessing it The Renesas I3C driver uses an asynchronous model to transfer data. It prepares a struct renesas_i3c_xfer, enqueues it, and waits for completion. The interrupt handler dequeues the transfer, updates/uses it, and signals the waiting thread. If the completion time

hugovalters@mastodon.social at 2026-09-20T08:50:02.000Z ##

CVE-2026-80950 Linux kernel Renesas I3C driver use-after-free from async transfer race, potential RCE. CVSS N/A, patch status unknown. Patch or update now if exposed. valtersit.com/cve/CVE-2026-809 #CVE #infosec #LinuxKernel

##

hugovalters@mastodon.social at 2026-09-20T08:50:02.000Z ##

CVE-2026-80950 Linux kernel Renesas I3C driver use-after-free from async transfer race, potential RCE. CVSS N/A, patch status unknown. Patch or update now if exposed. valtersit.com/cve/CVE-2026-809 #CVE #infosec #LinuxKernel

##

CVE-2026-78175
(8.8 HIGH)

EPSS: 0.59%

updated 2026-09-12T09:33:41

1 posts

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler lacking any capability or role check, relying solely on a nonce, while also passing attacker-supplied values through `esc_sq

guru@thecybersecguru.com at 2026-09-18T13:12:51.000Z ##

Tutor LMS Critical Flaw (CVE-2026-78175) Exposes 100,000+ WordPress Sites to Remote Code Execution

Tutor LMS CVE-2026-78175 is a critical RCE flaw affecting 100,000+ WordPress sites. Learn how the exploit works and how to patch it

thecybersecguru.com/news/cve-2

##

CVE-2026-81913(CVSS UNKNOWN)

EPSS: 0.59%

updated 2026-09-11T21:31:32

1 posts

Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authentication, facilitating phishing and credential theft. The same handling is present in the registration flow, giving a second entry point on sites with registration enab

hugovalters@mastodon.social at 2026-09-20T10:20:19.000Z ##

CVE-2026-81913: Concrete CMS 9.5.0-9.5.2 open redirect via rcURL parameter. Crafted links can send authenticated users to phishing sites, enabling credential theft. No CVSS published, patch status unknown. valtersit.com/cve/CVE-2026-819 #CVE #infosec #ConcreteCMS

##

CVE-2026-89455(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-09-11T21:31:28

1 posts

In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix use-after-free of event IRQs during teardown plda_pcie_irq_domain_deinit() removes pcie->event_domain via irq_domain_remove(), but the per-event IRQs mapped from that domain are requested with devm_request_irq() in plda_init_interrupts(). The actual free_irq() for a devm-managed IRQ is deferred by devres until aft

hugovalters@mastodon.social at 2026-09-19T01:40:18.000Z ##

CVE-2026-89455 Linux kernel PCI plda use-after-free during IRQ teardown. No CVSS or patch yet. Audit and update affected systems. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80942(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-11T21:31:21

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subsequent error paths in rtl92du_init_sw_vars(). Fix that by adding a call to rtl92du_deinit_shared_data() in the error path.

hugovalters@mastodon.social at 2026-09-20T04:31:00.000Z ##

CVE-2026-80942 Linux rtlwifi rtl8192du: memory leak in error paths of rtl92du_init_sw_vars(), unfixed. No CVSS assigned. Patch status unknown, update now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80934(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-11T21:31:20

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames mt7996/mt7992 hand the firmware a HW MAC-TXP for AddBA req action frames (MT_TXD7_MAC_TXD, set in mt7996_mac_write_txwi_80211()), but are otherwise FW-TXP devices. On tx free mt76_connac_txp_skb_unmap() therefore decodes the per-frame txp as a struct mt76_connac_fw

hugovalters@mastodon.social at 2026-09-19T20:10:03.000Z ##

CVE-2026-80934 Linux kernel mt76 mt7996 TX DMA mapping leak. No CVSS or patch yet. Update now if you run mt7996 wifi. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-89453
(0 None)

EPSS: 0.20%

updated 2026-09-11T20:19:25.967000

1 posts

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faults iommu_call_iopf_notifier() looks up the requester with pci_get_domain_bus_and_slot(), which returns a PCI device with its reference count incremented. Neither the successful iommu_report_device_fault() path nor the abort path drops that reference, so every handled PPR request

hugovalters@mastodon.social at 2026-09-19T03:40:18.000Z ##

CVE-2026-89453 Linux kernel iommu/amd PPR fault handling leaks PCI device references. Unpatched. Patch now valtersit.com/cve/CVE-2026-894 #CVE #infosec #Linux

##

CVE-2026-80957
(0 None)

EPSS: 0.17%

updated 2026-09-11T20:19:01.520000

1 posts

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: detect a cycle in the last-kset chain during replay cache_replay() follows the on-media last-kset chain by next_cache_seg_id with no cond_resched(). A forged chain that points back into a segment it has already visited makes the replay loop follow it forever. Cap the last-kset hops at cache->n_segs; a valid chain vis

hugovalters@mastodon.social at 2026-09-20T04:00:32.000Z ##

CVE-2026-80957 Linux kernel dm-pcache infinite loop via forged last-kset chain during replay, DoS on mount. No CVSS yet, unpatched. Update now: valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-0310(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-09-10T06:31:55

1 posts

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimiz

CVE-2025-25249
(8.1 HIGH)

EPSS: 2.40%

updated 2026-09-09T21:30:27

1 posts

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSASE 25.2.b, FortiSASE 25.1.a.2, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted p

undercodenews@mastodon.social at 2026-09-20T13:52:17.000Z ##

CISA Adds Fortinet CVE-2025-25249 to KEV as Active Exploitation Raises the Pressure on Defenders + Video

CISA Adds Fortinet CVE-2025-25249 to KEV as Active Exploitation Raises the Pressure on Defenders A Fortinet Vulnerability Moves Into a Higher-Risk Category A serious Fortinet vulnerability has entered a more urgent phase after the U.S. Cybersecurity and Infrastructure Security Agency added CVE-2025-25249 to its Known Exploited Vulnerabilities, or KEV, Catalog. The…

undercodenews.com/cisa-adds-fo

##

CVE-2025-20701
(8.8 HIGH)

EPSS: 8.67%

updated 2026-09-08T18:31:36

2 posts

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

2 repos

https://github.com/SpiritualMachines/buds-audit

https://github.com/x0jac0b0x/skullcandy-dime3-cve-2025-20701

dec23k@mastodon.ie at 2026-09-20T11:14:43.000Z ##

@inpc
"The vulnerability is linked to CVE-2025-20701, previously reported in Airoha Bluetooth audio SDK implementations. The affected Dime 3 earbuds identify their Bluetooth chipset vendor as Airoha Technology Corp., associated with Bluetooth SIG company ID 0x0094."

CVE-2025-20701 affected headphones and earbuds with Airoha chips. It was worse than this one: it was possible to steal authentication keys from the audio device, and use them to jump to the paired phone (which was also in range).

##

dec23k@mastodon.ie at 2026-09-20T11:14:43.000Z ##

@inpc
"The vulnerability is linked to CVE-2025-20701, previously reported in Airoha Bluetooth audio SDK implementations. The affected Dime 3 earbuds identify their Bluetooth chipset vendor as Airoha Technology Corp., associated with Bluetooth SIG company ID 0x0094."

CVE-2025-20701 affected headphones and earbuds with Airoha chips. It was worse than this one: it was possible to steal authentication keys from the audio device, and use them to jump to the paired phone (which was also in range).

##

CVE-2026-54218
(0 None)

EPSS: 0.34%

updated 2026-09-07T14:16:53.357000

2 posts

Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various files using only obfuscation. Any user with access to the server’s file system, or who can otherwise extract files from the server (see vulnerability “Random File Read”), can potentially obtain affected users’ passwords. This issue a

nyanbinary at 2026-09-20T13:35:50.157Z ##

CVE-2026-54218 is also interesting in that it appears to be plaintext/weak-crypto password storage, based on the reference, instead of actually hardcoded

##

nyanbinary@infosec.exchange at 2026-09-20T13:35:50.000Z ##

CVE-2026-54218 is also interesting in that it appears to be plaintext/weak-crypto password storage, based on the reference, instead of actually hardcoded

##

CVE-2026-80844
(0 None)

EPSS: 0.19%

updated 2026-09-04T16:18:13.023000

4 posts

In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of addresses described by the routing header's hdrlen field. That assumption does not hold for raw IPv6 HDRINCL packets.

1 repos

https://github.com/0xBlackash/CVE-2026-80844

cyberworldops at 2026-09-19T04:30:00.974Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk.

cyberworldops.eu/en/four-publi

##

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

decio@infosec.exchange at 2026-09-18T08:13:07.000Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

#Linux #CyberSecurity #Vulnerability #CVE #Debian

##

harrysintonen@infosec.exchange at 2026-09-18T06:48:39.000Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469

##

CVE-2026-13348(CVSS UNKNOWN)

EPSS: 0.31%

updated 2026-09-01T15:31:17

2 posts

CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.

cyberworldops at 2026-09-18T22:40:00.819Z ##

Schneider Electric disclosed CVE-2026-13348 (CWE-307) in PowerChute Serial Shutdown, allowing unrestricted authentication attempts. Successful brute-forcing enables account takeover with impact on UPS management and operational continuity.

cyberworldops.eu/en/powerchute

##

cyberworldops@infosec.exchange at 2026-09-18T22:40:00.000Z ##

Schneider Electric disclosed CVE-2026-13348 (CWE-307) in PowerChute Serial Shutdown, allowing unrestricted authentication attempts. Successful brute-forcing enables account takeover with impact on UPS management and operational continuity. #SchneiderElectric #PowerChute #BruteForce

cyberworldops.eu/en/powerchute

##

DailyCyberSecurity@infosec.exchange at 2026-09-18T09:26:48.000Z ##

HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.

#HCLBigFix #Cybersecurity #CVE202667100 #Vulnerability #InfoSec

securityonline.info/hcl-bigfix

##

CVE-2026-74469
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-19T18:33:35

4 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sctp_assoc_add_peer() increments the association's 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero. SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload, then copies one sockaddr_storage for every entry in t

1 repos

https://github.com/0xBlackash/CVE-2026-74469

cyberworldops at 2026-09-19T04:30:00.974Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk.

cyberworldops.eu/en/four-publi

##

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

decio@infosec.exchange at 2026-09-18T08:13:07.000Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

#Linux #CyberSecurity #Vulnerability #CVE #Debian

##

harrysintonen@infosec.exchange at 2026-09-18T06:48:39.000Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469

##

CVE-2026-68121
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-19T18:32:06

4 posts

In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is

1 repos

https://github.com/0xBlackash/CVE-2026-68121

cyberworldops at 2026-09-19T04:30:00.974Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk.

cyberworldops.eu/en/four-publi

##

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

decio@infosec.exchange at 2026-09-18T08:13:07.000Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

#Linux #CyberSecurity #Vulnerability #CVE #Debian

##

harrysintonen@infosec.exchange at 2026-09-18T06:48:39.000Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469

##

1337core@social.1337core.de at 2026-09-20T16:03:04.000Z ##

Ungepatchte Exchange-Server mit kritischer Sicherheitslücke
CVE-2021-34473: "Microsoft Exchange Server Remote Code Execution Vulnerability"
Volkshochschule in Amberg, Landkreis Merzig-Wadern und mehreren Stadtverwaltungen: Bernsdorf, Bleckede, Dachau, Erkner, Heilbald Heiligenstadt, Klötze, Mölln, Plauen, Rendsburg, Sassnitz, Stadtbergen, Sulzbach Saar, Vellmar und im Exchange-Server im Theater in Freiburg, ...

#Hacks

c't Artikel: heise.de/news/Verwundbare-Exch

##

1337core@social.1337core.de at 2026-09-20T16:03:04.000Z ##

Ungepatchte Exchange-Server mit kritischer Sicherheitslücke
CVE-2021-34473: "Microsoft Exchange Server Remote Code Execution Vulnerability"
Volkshochschule in Amberg, Landkreis Merzig-Wadern und mehreren Stadtverwaltungen: Bernsdorf, Bleckede, Dachau, Erkner, Heilbald Heiligenstadt, Klötze, Mölln, Plauen, Rendsburg, Sassnitz, Stadtbergen, Sulzbach Saar, Vellmar und im Exchange-Server im Theater in Freiburg, ...

#Hacks

c't Artikel: heise.de/news/Verwundbare-Exch

##

CVE-2026-7646
(6.5 MEDIUM)

EPSS: 0.30%

updated 2026-08-06T19:27:33.433000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path traversal sequence in the filename.

5 repos

https://github.com/0xBlackash/CVE-2026-76461

https://github.com/fevar54/CVE-2026-76461-Detection-Kit-

https://github.com/HORKimhab/CVE-2026-76461

https://github.com/S3v3n-JG/CVE-2026-76461

https://github.com/S3v3n-JG/CVE-2026-76460

hackmag@infosec.exchange at 2026-09-18T15:36:29.000Z ##

⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email

🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…

🔗 hackmag.com/news/cve-2026-7646

#news

##

CVE-2026-55945
(4.2 MEDIUM)

EPSS: 0.19%

updated 2026-07-03T21:31:47

1 posts

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

sayzard@mastodon.sayzard.org at 2026-09-20T13:42:06.000Z ##

BragJack attacks hijack AI browser agents through malicious extensions

Forever Security의 Gal Weizman이 악성 Chromium 확장 프로그램 하나로 브라우저 내 AI 에이전트를 탈취하는 ‘BragJack’ 공격을 공개했다. Google Chrome Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, Claude in Chrome 등 5개 대상에서 재현됐으며, Chrome의 CVE-2026-0628과 Edge의 CVE-2026-55945를 포...

bleepingcomputer.com/news/secu

##

CVE-2026-58138
(9.8 CRITICAL)

EPSS: 9.26%

updated 2026-06-30T21:31:51

5 posts

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or

6 repos

https://github.com/Ch4120N/CVE-2026-58138

https://github.com/BiiTts/CVE-2026-58138-Conductor-Unauth-RCE

https://github.com/0xgh057r3c0n/CVE-2026-58138

https://github.com/Procjevt/CVE-2026-58138

https://github.com/seqra/cve-2026-58138

https://github.com/0xBlackash/CVE-2026-58138

beyondmachines1 at 2026-09-20T10:01:13.554Z ##

Critical Pre-Auth RCE in Orkes Conductor Under Active Exploitation

Orkes Conductor versions prior to 3.30.2 are vulnerable to a critical unauthenticated remote code execution flaw (CVE-2026-58138) that allows attackers to run arbitrary OS commands via malicious workflow definitions.

**If you run Orkes Conductor or Conductor OSS versions 3.21.21 through 3.30.1 (check your `conductoross/conductor` container images and Helm charts), update to 3.30.2 or later immediately. Working exploit code is public and attacks are already underway. Until you can patch, take the Conductor API off the internet, put it behind a reverse proxy that requires authentication and limit workflow endpoints to trusted internal networks only.**

beyondmachines.net/event_detai

##

threatnoir at 2026-09-20T04:05:50.702Z ##

⚠️ CRITICAL: Critical Orkes Conductor Vulnerability Exploited in Attacks

Orkes Conductor versions below 3.30.2 have an unauthenticated remote code execution vulnerability (CVE-2026-58138) that is actively being exploited. Attackers can execute arbitrary system commands by injecting malicious JavaScript or Python into workflow definitions. Any organization running Conduc…

threatnoir.com/focus

🤖 AI generated summary

##

beyondmachines1@infosec.exchange at 2026-09-20T10:01:13.000Z ##

Critical Pre-Auth RCE in Orkes Conductor Under Active Exploitation

Orkes Conductor versions prior to 3.30.2 are vulnerable to a critical unauthenticated remote code execution flaw (CVE-2026-58138) that allows attackers to run arbitrary OS commands via malicious workflow definitions.

**If you run Orkes Conductor or Conductor OSS versions 3.21.21 through 3.30.1 (check your `conductoross/conductor` container images and Helm charts), update to 3.30.2 or later immediately. Working exploit code is public and attacks are already underway. Until you can patch, take the Conductor API off the internet, put it behind a reverse proxy that requires authentication and limit workflow endpoints to trusted internal networks only.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-09-20T04:05:50.000Z ##

⚠️ CRITICAL: Critical Orkes Conductor Vulnerability Exploited in Attacks

Orkes Conductor versions below 3.30.2 have an unauthenticated remote code execution vulnerability (CVE-2026-58138) that is actively being exploited. Attackers can execute arbitrary system commands by injecting malicious JavaScript or Python into workflow definitions. Any organization running Conduc…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

cyberworldops@infosec.exchange at 2026-09-18T13:10:00.000Z ##

Orkes Conductor 3.21.21 through before 3.30.2 is affected by CVE-2026-58138, an unauthenticated RCE via malicious workflow definitions using inline JS/Python. Exposed APIs allow arbitrary OS command execution with host-level impact. Patch to 3.30.2 and restrict exposure. #OrkesConductor #RemoteCodeExecution #ThreatIntel

cyberworldops.eu/en/exposed-or

##

CVE-2026-45321
(9.6 CRITICAL)

EPSS: 2.34%

updated 2026-06-17T10:51:54.877000

1 posts

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn

13 repos

https://github.com/nkopylov/tanscript-exploit-check

https://github.com/Caixa-git/tanstack-shield

https://github.com/fabriziosalmi/tanstack-compromise-checker

https://github.com/Yomisana/are-you-get-tanstack-attack

https://github.com/shayr1/shai-hulud-scan

https://github.com/prashanthnataraj/mini-shai-hulud-detector

https://github.com/Intrudify/mini-shai-hulud-scanner

https://github.com/ry-allan/tanstack-compromise-checker

https://github.com/digi4care/shai-scan

https://github.com/renewablehacking/CVE-2026-45321-Tanstack

https://github.com/Breakingcircuitsllc/teampcp_shai_hulud.yar

https://github.com/7whyex/CVE-2026-45321-Tanstack

https://github.com/qi-scape/scan-shai-hulud

Analyst207@mastodon.social at 2026-09-19T08:03:27.000Z ##

TanStack npm Attack Exposes 170 Private GitHub Repositories

A shocking npm attack on TanStack exposed a massive 170 private GitHub repositories after a malicious actor exploited a stolen OAuth token from a former employee's account. The breach was linked to a supply-chain compromise of TanStack's npm packages, tracked as CVE-2026-45321, which allowed attackers to steal sensitive credentials.

osintsights.com/tanstack-npm-a

#TanstackNpmAttack #SupplyChain #Github #OauthToken #Cve202645321

##

CVE-2026-20111
(4.8 MEDIUM)

EPSS: 0.18%

updated 2026-03-10T21:32:11

2 posts

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability

nyanbinary at 2026-09-20T13:28:38.280Z ##

@cR0w hold a second, what the fuck is this vulnerability: db.gcve.eu/vuln/CVE-2026-20111

This CWE and description absolutely dont fucking match, what the fuck, cisco

##

nyanbinary@infosec.exchange at 2026-09-20T13:28:38.000Z ##

@cR0w hold a second, what the fuck is this vulnerability: db.gcve.eu/vuln/CVE-2026-20111

This CWE and description absolutely dont fucking match, what the fuck, cisco

##

CVE-2026-0628
(8.8 HIGH)

EPSS: 6.63%

updated 2026-01-07T15:31:20

1 posts

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

2 repos

https://github.com/fevar54/CVE-2026-0628-POC

https://github.com/sastraadiwiguna-purpleeliteteaming/Dissecting-CVE-2026-0628-Chromium-Extension-Privilege-Escalation

sayzard@mastodon.sayzard.org at 2026-09-20T13:42:06.000Z ##

BragJack attacks hijack AI browser agents through malicious extensions

Forever Security의 Gal Weizman이 악성 Chromium 확장 프로그램 하나로 브라우저 내 AI 에이전트를 탈취하는 ‘BragJack’ 공격을 공개했다. Google Chrome Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, Claude in Chrome 등 5개 대상에서 재현됐으며, Chrome의 CVE-2026-0628과 Edge의 CVE-2026-55945를 포...

bleepingcomputer.com/news/secu

##

CVE-2024-3400
(9.8 CRITICAL)

EPSS: 100.00%

updated 2025-10-22T00:34:06

1 posts

A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Fixes for PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 are in development and are expected to be released by April 14, 2024. Cloud NG

45 repos

https://github.com/Ravaan21/CVE-2024-3400

https://github.com/FoxyProxys/CVE-2024-3400

https://github.com/momika233/CVE-2024-3400

https://github.com/ivan-n0v/cve-2024-3400

https://github.com/workshop748/CVE-2024-3400

https://github.com/terminalJunki3/CVE-2024-3400-Checker

https://github.com/Zedocun/PAN-OS-CVE-2024-3400-Command-Injection-Investigation

https://github.com/0xr2r/CVE-2024-3400-Palo-Alto-OS-Command-Injection

https://github.com/Yafiah-Darwesh/cs50-cyber-paloalto-oauth

https://github.com/schooldropout1337/CVE-2024-3400

https://github.com/tfrederick74656/cve-2024-3400-poc

https://github.com/sxyrxyy/CVE-2024-3400-Check

https://github.com/swaybs/CVE-2024-3400

https://github.com/GhassanSabir/CVE-2024-3400-poc

https://github.com/ZephrFish/CVE-2024-3400-Canary

https://github.com/CONDITIONBLACK/CVE-2024-3400-POC

https://github.com/retkoussa/CVE-2024-3400

https://github.com/ak1t4/CVE-2024-3400

https://github.com/AdaniKamal/CVE-2024-3400

https://github.com/index2014/CVE-2024-3400-Checker

https://github.com/wa6n3r/CVE-2024-3400

https://github.com/h4x0r-dz/CVE-2024-3400

https://github.com/zam89/CVE-2024-3400-pot

https://github.com/CyprianAtsyor/letsdefend-cve2024-3400-case-study

https://github.com/Yuvvi01/CVE-2024-3400

https://github.com/HackingLZ/panrapidcheck

https://github.com/0x0d3ad/CVE-2024-3400

https://github.com/SimoesCTT/-CTT-PAN-OS-EXPLOIT-CVE-2024-340

https://github.com/CyberBibs/SOC274---Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400-

https://github.com/W01fh4cker/CVE-2024-3400-RCE-Scan

https://github.com/razureink/cve-2024-3400-panos_rce_reproduction

https://github.com/MurrayR0123/CVE-2024-3400-Compromise-Checker

https://github.com/LoanVitor/CVE-2024-3400-

https://github.com/Chocapikk/CVE-2024-3400

https://github.com/MrR0b0t19/CVE-2024-3400

https://github.com/marconesler/CVE-2024-3400

https://github.com/CerTusHack/CVE-2024-3400-PoC

https://github.com/Kr0ff/cve-2024-3400

https://github.com/codeblueprint/CVE-2024-3400

https://github.com/pwnj0hn/CVE-2024-3400

https://github.com/hashdr1ft/SOC274-Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400

https://github.com/ihebski/CVE-2024-3400

https://github.com/P4rC3L/Global-Protect_VPN_Vuln

https://github.com/andrelia-hacks/CVE-2024-3400

https://github.com/hahasagined/CVE-2024-3400

hugovalters@mastodon.social at 2026-09-20T11:00:21.000Z ##

GET /api/v1/cve/CVE-2024-3400 returns CVSS, affected vendors, CPEs, and known exploits in one call. No joins, no scraping. Metered keys at valtersit.com/cve/pricing/

##

CVE-2026-84383
(0 None)

EPSS: 0.64%

2 posts

N/A

e_nomem@hachyderm.io at 2026-09-19T17:15:33.000Z ##

@paul @arda AVIF is a specific profile/subtype of HEIF. Mastodon uses libvips to handle images and libvips uses libheif to handle both HEIF and AVIF.

libheif was disabled in mastodon 4.7.2 due to unspecified security issues but it's probably because of CVE-2026-84383

##

e_nomem@hachyderm.io at 2026-09-19T17:15:33.000Z ##

@paul @arda AVIF is a specific profile/subtype of HEIF. Mastodon uses libvips to handle images and libvips uses libheif to handle both HEIF and AVIF.

libheif was disabled in mastodon 4.7.2 due to unspecified security issues but it's probably because of CVE-2026-84383

##

CVE-2026-57228
(0 None)

EPSS: 0.56%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T23:02:48.000Z ##

🟠 CVE-2026-57228 - High (8.2)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:02:48.000Z ##

🟠 CVE-2026-57228 - High (8.2)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57227
(0 None)

EPSS: 0.40%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T23:02:37.000Z ##

🟠 CVE-2026-57227 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:02:37.000Z ##

🟠 CVE-2026-57227 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63452
(0 None)

EPSS: 0.36%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T22:03:30.000Z ##

🟠 CVE-2026-63452 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli comp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:03:30.000Z ##

🟠 CVE-2026-63452 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli comp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68928
(0 None)

EPSS: 0.13%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T22:03:20.000Z ##

🟠 CVE-2026-68928 - High (8.6)

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:03:20.000Z ##

🟠 CVE-2026-68928 - High (8.6)

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71418
(0 None)

EPSS: 0.35%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T22:02:15.000Z ##

🟠 CVE-2026-71418 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame cont...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:02:15.000Z ##

🟠 CVE-2026-71418 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame cont...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites