## Updated at UTC 2026-07-20T18:48:34.722934

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-9135 9.9 0.80% 1 0 2026-07-20T18:22:06.600000 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 9498
CVE-2026-63429 8.6 0.00% 3 0 2026-07-20T18:16:56.170000 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/
CVE-2026-54498 8.7 0.45% 1 0 2026-07-20T18:16:54.050000 view_component is a framework for building reusable, testable, and encapsulated
CVE-2026-16097 8.8 0.46% 2 0 2026-07-20T18:16:50.603000 A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the
CVE-2026-7754 7.7 0.22% 1 0 2026-07-20T18:03:55.170000 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side req
CVE-2026-7872 7.5 0.38% 1 0 2026-07-20T17:59:05.243000 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read a
CVE-2026-8505 9.8 0.60% 2 0 2026-07-20T17:56:57.160000 IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook
CVE-2026-8635 9.9 0.29% 1 0 2026-07-20T17:48:33.547000 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate pri
CVE-2026-13446 9.8 0.21% 2 0 2026-07-20T17:38:56.090000 IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a
CVE-2026-45713 7.5 0.00% 2 0 2026-07-20T17:17:09.720000 Mailpit is an email testing tool and API for developers. Prior to version 1.30.0
CVE-2026-16242 9.4 0.37% 3 0 2026-07-20T17:17:04.883000 A flaw was found in the Konnectivity proxy-server configuration for hosted contr
CVE-2026-11826 8.8 0.42% 2 0 2026-07-20T17:17:04.230000 OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in we
CVE-2026-13473 8.1 0.46% 1 0 2026-07-20T17:15:53.673000 IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu
CVE-2026-9171 7.5 0.55% 1 0 2026-07-20T17:15:53.673000 IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a
CVE-2026-48373 7.8 0.19% 1 0 2026-07-20T17:14:58.043000 Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that co
CVE-2026-54910 7.7 0.00% 2 0 2026-07-20T16:17:05.233000 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to ver
CVE-2026-51027 9.9 0.00% 2 0 2026-07-20T16:17:04.897000 An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive inf
CVE-2026-47868 7.8 0.15% 1 0 2026-07-20T16:17:02.377000 VMware Avi Load Balancer contains a local privilege escalation vulnerability. A
CVE-2026-47865 9.8 0.66% 1 0 2026-07-20T16:17:02.067000 VMware Avi Load Balancer contains an authentication bypass vulnerability. A mali
CVE-2026-46415 8.2 0.00% 2 0 2026-07-20T16:17:01.163000 The Caddy Defender plugin is a middleware for Caddy that allows users to block o
CVE-2026-46412 10.0 0.00% 2 0 2026-07-20T16:17:01 @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Iden
CVE-2026-35198 9.0 0.00% 2 0 2026-07-20T16:16:58.440000 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cr
CVE-2026-16117 10.0 0.27% 1 0 2026-07-20T16:16:56.053000 Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite
CVE-2026-15631 8.7 0.30% 1 0 2026-07-20T16:16:55.670000 Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail
CVE-2026-13577 8.2 0.14% 2 0 2026-07-20T15:33:11 Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRN
CVE-2026-63090 8.8 0.00% 2 0 2026-07-20T15:32:15 ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulner
CVE-2026-57309 None 0.00% 2 0 2026-07-20T15:32:06 A Blind SQL injection vulnerability has been identified in Windu CMS. A remote u
CVE-2026-12080 7.3 0.00% 1 0 2026-07-20T15:32:05 A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can ex
CVE-2026-63831 8.8 0.17% 1 0 2026-07-20T15:16:49.803000 In the Linux kernel, the following vulnerability has been resolved: mac802154:
CVE-2026-63795 10.0 0.17% 2 0 2026-07-20T15:16:46.193000 In the Linux kernel, the following vulnerability has been resolved: 9p: avoid p
CVE-2026-49485 7.5 0.68% 1 0 2026-07-20T15:16:39.090000 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i
CVE-2026-48062 9.8 0.44% 1 0 2026-07-20T15:16:38.980000 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload
CVE-2026-12484 7.8 0.20% 3 0 2026-07-20T15:16:34.223000 A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization
CVE-2026-39359 7.5 0.24% 1 0 2026-07-20T13:42:42.300000 Wazuh is a free and open source platform used for threat prevention, detection,
CVE-2026-16229 4.3 0.44% 1 0 2026-07-20T13:30:32.407000 A flaw has been found in itsourcecode Courier Management System up to 1.0. Affec
CVE-2026-16223 6.3 0.21% 1 0 2026-07-20T13:30:32.407000 A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is
CVE-2026-16096 8.8 0.44% 3 0 2026-07-20T13:30:32.407000 A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Th
CVE-2026-13142 None 0.14% 1 0 2026-07-20T09:31:15 The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.
CVE-2026-16228 7.3 0.41% 1 0 2026-07-19T12:30:30 A vulnerability was detected in SourceCodester Class and Exam Timetabling System
CVE-2026-16227 7.3 0.41% 1 0 2026-07-19T12:30:21 A security vulnerability has been detected in SourceCodester Class and Exam Time
CVE-2026-16217 6.3 0.22% 1 0 2026-07-19T06:30:33 A security vulnerability has been detected in guohongze adminset up to 0.61. Aff
CVE-2026-16210 7.3 0.40% 1 0 2026-07-19T06:30:24 A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the fu
CVE-2026-10130 8.2 0.37% 2 0 2026-07-18T23:17:00.397000 QueryWeaver contains an authentication bypass vulnerability that allows unauthen
CVE-2026-12228 8.7 0.26% 2 0 2026-07-18T21:30:30 A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/promp
CVE-2026-53994 7.5 0.40% 2 0 2026-07-18T21:30:24 ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authentic
CVE-2026-55518 9.6 0.33% 1 0 2026-07-18T17:22:30 ## Summary A critical missing authorization flaw exists in Avo's association at
CVE-2026-9147 7.8 0.15% 2 0 2026-07-18T15:31:55 uproot dynamically generates Python class source code from ROOT TStreamerInfo re
CVE-2026-9323 8.1 0.42% 1 0 2026-07-18T14:17:12.170000 The urwid web display backend (urwid/display/web.py) generates web session ident
CVE-2026-16095 8.8 0.42% 1 0 2026-07-18T12:33:18 A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by
CVE-2026-47871 8.8 0.90% 1 0 2026-07-18T09:32:24 VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in
CVE-2026-47869 8.7 0.68% 1 0 2026-07-18T09:32:24 VMware Avi Load Balancer contains a remote code execution vulnerability. A malic
CVE-2026-47866 8.3 0.43% 1 0 2026-07-18T09:32:24 VMware Avi Load Balancer contains an authorization bypass vulnerability. A malic
CVE-2026-47867 8.7 0.68% 1 0 2026-07-18T09:32:17 VMware Avi Load Balancer contains a remote code execution vulnerability. A malic
CVE-2026-53359 8.8 0.12% 2 8 2026-07-18T08:16:36.620000 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F
CVE-2026-9762 7.8 0.17% 1 0 2026-07-18T05:16:56.710000 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote
CVE-2026-9202 9.8 0.29% 2 0 2026-07-18T05:16:56.447000 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create
CVE-2026-63030 9.8 8.95% 31 57 template 2026-07-18T05:16:56.167000 WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API ba
CVE-2026-60137 5.9 4.03% 23 31 2026-07-18T05:16:54.427000 WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does no
CVE-2026-45162 8.0 0.57% 1 0 2026-07-18T00:16:48.007000 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.1
CVE-2026-7667 8.8 0.34% 1 0 2026-07-17T21:31:53 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create
CVE-2026-8481 9.9 0.44% 1 0 2026-07-17T21:31:53 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v
CVE-2026-7755 8.8 0.41% 1 0 2026-07-17T21:31:53 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution
CVE-2026-8859 9.9 0.34% 1 0 2026-07-17T21:31:53 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write
CVE-2026-14499 8.8 0.43% 1 0 2026-07-17T21:31:52 IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user
CVE-2026-13448 8.1 0.44% 1 0 2026-07-17T21:31:52 IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re
CVE-2026-15091 9.3 0.57% 1 0 2026-07-17T21:31:52 IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to
CVE-2026-8476 9.9 0.47% 1 0 2026-07-17T21:31:52 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v
CVE-2026-8056 8.8 0.29% 1 0 2026-07-17T21:31:52 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override com
CVE-2026-13445 8.1 0.20% 1 0 2026-07-17T21:31:52 IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exp
CVE-2026-9103 9.8 0.41% 1 0 2026-07-17T21:31:52 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unau
CVE-2026-15322 7.5 0.52% 1 0 2026-07-17T21:31:44 IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to
CVE-2026-52746 7.5 0.68% 1 0 2026-07-17T20:17:25.207000 JSONata is a JSON query and transformation language. Prior to 2.2.0, malicious n
CVE-2026-45260 8.1 0.43% 1 0 2026-07-17T20:17:16.857000 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.1
CVE-2025-20205 4.8 0.31% 1 0 2026-07-17T20:17:13.067000 Multiple vulnerabilities in the web-based management interface of Cisco Identity
CVE-2026-63101 7.5 0.30% 1 0 2026-07-17T19:17:19.147000 Open Event Server through 1.19.1 contains a missing authentication vulnerability
CVE-2026-62227 7.7 0.24% 1 0 2026-07-17T19:17:18.390000 OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulner
CVE-2025-60357 8.1 0.40% 1 1 2026-07-17T18:47:13.683000 AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injectio
CVE-2026-51080 9.8 0.30% 1 0 2026-07-17T18:47:13.683000 libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to cont
CVE-2026-44182 0 0.35% 1 0 2026-07-17T18:35:23.877000 Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distr
CVE-2026-57860 7.8 0.13% 1 0 2026-07-17T18:31:35 ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically load
CVE-2026-12694 9.1 0.24% 1 0 2026-07-17T18:31:34 Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform a
CVE-2026-8297 9.8 0.26% 1 0 2026-07-17T18:31:34 Improper neutralization of special elements used in an SQL command ('SQL injecti
CVE-2026-9198 9.8 0.35% 1 0 2026-07-17T18:31:34 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain
CVE-2026-13410 8.2 0.24% 1 0 2026-07-17T18:17:14.283000 Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verificatio
CVE-2026-12693 9.4 0.26% 1 0 2026-07-17T18:17:13.847000 Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc.
CVE-2026-12692 9.8 0.35% 1 0 2026-07-17T17:54:18.640000 Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platf
CVE-2026-12691 7.5 0.30% 1 0 2026-07-17T17:54:18.640000 Missing authentication for critical function vulnerability in Vimesoft Inc. Ente
CVE-2026-62234 8.1 0.30% 1 0 2026-07-17T15:44:29.553000 Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing
CVE-2026-11961 8.1 0.23% 2 0 2026-07-17T15:44:29.553000 The User Registration & Membership WordPress plugin before 5.2.3 does not valid
CVE-2026-62232 7.4 0.28% 1 0 2026-07-17T15:44:29.553000 Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in t
CVE-2026-11575 7.5 0.21% 1 0 2026-07-17T15:33:32 The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly ve
CVE-2026-7488 7.5 0.24% 1 0 2026-07-17T15:32:37 Insertion of sensitive information into sent data vulnerability in IKAS Technolo
CVE-2026-63094 8.1 0.17% 1 0 2026-07-17T15:32:37 SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authen
CVE-2026-63093 8.8 0.43% 1 0 2026-07-17T15:32:37 Cursor for Windows version 3.2.16 contains a binary planting vulnerability that
CVE-2026-7189 7.5 0.24% 1 0 2026-07-17T15:32:29 Insertion of sensitive information into sent data vulnerability in Proliz Softwa
CVE-2026-9810 9.8 0.28% 1 0 2026-07-17T15:32:28 The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens
CVE-2026-8396 7.5 0.26% 1 0 2026-07-17T15:00:17.017000 Improper restriction of XML external entity reference vulnerability in Netcad So
CVE-2026-13352 8.8 0.57% 1 0 2026-07-17T06:31:06 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
CVE-2026-13765 7.5 0.39% 1 0 2026-07-17T06:31:06 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin
CVE-2026-15982 9.8 0.29% 2 0 2026-07-17T06:31:06 The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Too
CVE-2026-50454 7.8 0.40% 1 0 2026-07-17T05:16:39.690000 Relative path traversal in Windows User Interface Core allows an authorized atta
CVE-2026-25089 9.8 36.13% 3 2 2026-07-17T05:16:38.687000 A improper neutralization of special elements used in an os command ('os command
CVE-2026-62386 7.5 0.27% 1 0 2026-07-17T03:31:30 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT acc
CVE-2026-62241 9.1 0.39% 1 0 2026-07-17T03:31:30 clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT
CVE-2026-62228 8.8 0.26% 1 0 2026-07-17T03:31:24 OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node e
CVE-2026-53412 9.8 0.51% 4 0 2026-07-17T00:32:18 Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client fo
CVE-2026-39808 9.8 84.16% 3 6 template 2026-07-16T18:32:24 A improper neutralization of special elements used in an os command ('os command
CVE-2026-58644 9.8 1.47% 8 0 2026-07-16T18:31:26 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-11386 9.0 0.32% 1 0 2026-07-16T14:16:48.040000 An input validation and injection vulnerability exists in Canonical ubuntu-pro-c
CVE-2026-15410 7.2 1.49% 2 3 2026-07-16T05:16:18.470000 Post-authentication improper control of generation of code ('Code Injection') vu
CVE-2026-15409 10.0 1.27% 4 5 2026-07-16T05:16:18.293000 A Server-side request forgery (SSRF) vulnerability has been identified in the SM
CVE-2026-50274 7.5 0.79% 1 0 2026-07-15T23:05:20 ### Impact Datadog tracing libraries that implement W3C baggage propagation pars
CVE-2026-50273 7.5 0.79% 1 0 2026-07-15T22:59:30 ### Impact Datadog tracing libraries that implement W3C baggage propagation pars
CVE-2026-50272 7.5 0.79% 1 0 2026-07-15T22:58:53 ### Impact Datadog tracing libraries that implement W3C baggage propagation pars
CVE-2026-50271 7.5 0.79% 1 0 2026-07-15T22:55:25 ### Impact Datadog tracing libraries that implement W3C baggage propagation pars
CVE-2026-48332 7.7 11.94% 1 0 2026-07-15T18:39:42.690000 ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability tha
CVE-2026-46817 9.8 1.04% 1 2 2026-07-15T18:32:50 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone
CVE-2026-47999 4.8 7.08% 1 0 2026-07-15T18:16:46.193000 Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability
CVE-2026-48284 9.6 7.94% 1 0 2026-07-15T18:00:17.600000 ColdFusion is affected by an Improper Input Validation vulnerability that could
CVE-2026-53565 0 0.10% 1 0 2026-07-15T16:23:57.437000 Improper Privilege Management vulnerability in Citrix Secure Access Client for W
CVE-2026-53566 0 0.11% 1 0 2026-07-15T16:23:57.437000 Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windo
CVE-2026-42533 8.1 0.83% 10 3 2026-07-15T15:33:14 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive
CVE-2026-50522 9.8 20.35% 1 0 2026-07-15T15:12:34.507000 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-47996 7.6 18.03% 1 0 2026-07-15T14:31:11.823000 Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
CVE-2026-50518 9.8 7.36% 1 0 2026-07-15T11:16:32.137000 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacke
CVE-2026-9770 None 0.22% 2 0 2026-07-15T03:33:02 Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key st
CVE-2025-3248 9.8 99.99% 2 28 template 2026-07-14T23:17:27.010000 Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/
CVE-2026-56155 7.8 0.38% 1 0 2026-07-14T21:32:52 Insufficient granularity of access control in Active Directory Federation Servic
CVE-2026-56164 5.3 5.60% 1 1 2026-07-14T21:32:51 Missing authentication for critical function in Microsoft Office SharePoint allo
CVE-2026-48320 8.5 9.36% 1 0 2026-07-14T21:32:33 ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability.
CVE-2026-48356 9.6 17.90% 1 0 2026-07-14T21:32:27 Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type
CVE-2026-47992 7.2 19.92% 1 0 2026-07-14T21:32:23 Adobe Commerce is affected by an Improper Neutralization of Special Elements use
CVE-2026-13001 9.8 1.08% 2 2 2026-07-14T21:16:40.860000 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary fi
CVE-2026-44891 7.5 0.69% 1 0 2026-07-14T20:16:37 ### Summary The StompSubframeDecoder fails to limit the total number of headers
CVE-2026-58319 9.1 0.61% 2 0 2026-07-14T16:56:51.260000 Certain Apache Doris FE HTTP REST administrative APIs were accessible without pr
CVE-2026-56451 10.0 0.38% 2 0 2026-07-14T12:31:16 A vulnerability has been identified in Opcenter X (All versions < V2604). Affect
CVE-2026-6875 None 0.51% 6 0 2026-07-13T21:31:30 ServiceNow has addressed a remote code execution vulnerability that was identifi
CVE-2026-54159 10.0 0.75% 1 0 2026-07-10T20:36:58 ### Impact A PHP Object Injection vulnerability affects the PrestaShop module `
CVE-2026-44739 8.7 0.28% 1 0 2026-07-10T19:07:01 ### Summary The columnConfigAction endpoint in the CustomReportsBundle is vulner
CVE-2026-57239 8.2 0.11% 2 1 2026-07-09T15:33:27 The user-controllable executable files will be directly executed by high-privile
CVE-2026-54496 9.3 0.32% 1 0 2026-07-06T21:23:42 ### Summary A soundness vulnerability in the variable-base scalar multiplicatio
CVE-2026-45659 8.8 3.22% 1 1 2026-07-02T12:16:47.143000 Deserialization of untrusted data in Microsoft Office SharePoint allows an autho
CVE-2026-50151 7.5 0.48% 1 0 2026-07-01T21:35:48 ## Summary oras-go follows a registry-controlled `Location` header during the m
CVE-2025-40949 9.1 0.67% 1 0 2026-06-29T14:08:26.717000 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.1
CVE-2026-43088 5.5 0.12% 1 0 2026-06-19T15:34:14 In the Linux kernel, the following vulnerability has been resolved: net: af_key
CVE-2026-9691 9.8 0.48% 1 1 2026-06-17T11:05:35.017000 Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Conta
CVE-2026-3300 9.8 40.99% 1 2 template 2026-06-17T10:43:22.287000 The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Executio
CVE-2026-32201 6.5 21.48% 1 1 2026-06-17T10:35:20.103000 Improper input validation in Microsoft Office SharePoint allows an unauthorized
CVE-2026-23845 5.8 0.40% 1 0 2026-06-17T10:22:11.673000 Mailpit is an email testing tool and API for developers. Versions prior to 1.28.
CVE-2025-69443 6.3 0.31% 1 0 2026-06-17T10:00:42.570000 Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when access
CVE-2026-9016 5.3 0.26% 1 0 2026-06-06T06:30:35 The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordP
CVE-2026-45799 7.5 0.50% 1 0 2026-05-19T19:54:51 # CVE-2026-45799 ## Maintainer summary Wire's protobuf group-skipping logic di
CVE-2026-45270 8.7 0.00% 2 0 2026-05-18T16:23:35 ## Summary The `Pages` backend module registers the `html_purify` validation ru
CVE-2026-3220 8.8 0.32% 1 4 2026-05-18T15:30:37 The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin
CVE-2026-20810 7.8 0.47% 1 0 2026-01-13T18:31:14 Free of memory not on the heap in Windows Ancillary Function Driver for WinSock
CVE-2025-20204 4.8 0.31% 1 0 2025-02-05T18:34:46 A vulnerability in the web-based management interface of Cisco Identity Services
CVE-2026-45710 0 0.00% 1 0 N/A
CVE-2026-14266 0 0.00% 5 1 N/A
CVE-2026-58443 0 0.00% 2 0 N/A
CVE-2026-31022 0 0.00% 1 0 N/A
CVE-2026-42566 0 0.28% 3 0 N/A
CVE-2026-52824 0 0.00% 1 0 N/A
CVE-2026-44359 0 1.00% 2 0 N/A
CVE-2026-16221 0 0.22% 1 0 N/A
CVE-2026-58195 0 0.46% 1 0 N/A
CVE-2026-16158 0 0.23% 1 0 N/A
CVE-2026-56741 0 0.52% 1 0 N/A
CVE-2026-56740 0 0.51% 1 0 N/A
CVE-2026-54523 0 0.00% 2 0 N/A
CVE-2026-44436 0 0.28% 1 0 N/A
CVE-2026-15899 0 0.00% 1 0 N/A

CVE-2026-9135
(9.9 CRITICAL)

EPSS: 0.80%

updated 2026-07-20T18:22:06.600000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists because the validation mechanism only checks the main component source code in node_template["code"]["

thehackerwire@mastodon.social at 2026-07-17T20:00:24.000Z ##

🔴 CVE-2026-9135 - Critical (9.9)

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_component...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63429
(8.6 HIGH)

EPSS: 0.00%

updated 2026-07-20T18:16:56.170000

3 posts

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous internet user can upload files (PDF, DOC/DOCX, XLS/XLSX, CSV, TXT, MP4, images, etc., up to 10 MB) and receive a permanent public URL on the HeyForm domain. The endpoi

hugovalters@mastodon.social at 2026-07-20T17:11:48.000Z ##

CVE-2026-63429 - Critical auth bypass in Heyform open-source form builder. Anonymous users can upload files up to 10MB to a public URL with no authentication checks. CVSS 8.6. No patch yet - restrict access immediately. #CVE #Heyform #infosec

valtersit.com/cve/CVE-2026-634

##

thehackerwire@mastodon.social at 2026-07-20T17:00:00.000Z ##

🟠 CVE-2026-63429 - High (8.6)

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous internet user ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-20T17:00:00.000Z ##

🟠 CVE-2026-63429 - High (8.6)

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous internet user ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54498
(8.7 HIGH)

EPSS: 0.45%

updated 2026-07-20T18:16:54.050000

1 posts

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the escaping behavior applied to normal #call return values. This creates an XSS risk when downstream applications use around_render to wrap, replace, instrument, or conditionally retu

thehackerwire@mastodon.social at 2026-07-17T22:00:10.000Z ##

🟠 CVE-2026-54498 - High (8.7)

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the escaping behavior applied t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16097
(8.8 HIGH)

EPSS: 0.46%

updated 2026-07-20T18:16:50.603000

2 posts

A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato.

offseq@infosec.exchange at 2026-07-18T19:30:23.000Z ##

CVE-2026-16097: HIGH severity stack-based buffer overflow in Shibby Tomato 1.28's Scheduler Name Handler. Remote code execution possible, no patch exists. Migrate to FreshTomato for security. Details: radar.offseq.com/threat/a-vuln #OffSeq #Vulnerability #RouterSecurity #InfoSec

##

thehackerwire@mastodon.social at 2026-07-18T13:00:38.000Z ##

🟠 CVE-2026-16097 - High (8.8)

A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7754
(7.7 HIGH)

EPSS: 0.22%

updated 2026-07-20T18:03:55.170000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism.

thehackerwire@mastodon.social at 2026-07-18T15:01:09.000Z ##

🟠 CVE-2026-7754 - High (7.7)

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7872
(7.5 HIGH)

EPSS: 0.38%

updated 2026-07-20T17:59:05.243000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.

thehackerwire@mastodon.social at 2026-07-18T12:00:46.000Z ##

🟠 CVE-2026-7872 - High (7.5)

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8505
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-07-20T17:56:57.160000

2 posts

IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow's UUID to execute it as if they were the ow

thehackerwire@mastodon.social at 2026-07-18T11:00:27.000Z ##

🔴 CVE-2026-8505 - Critical (9.8)

IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-18T10:30:27.000Z ##

CRITICAL (CVSS 9.8): CVE-2026-8505 in IBM Langflow OSS 1.0.0 – 1.10.0 enables unauthenticated RCE via default webhook auth config. Set WEBHOOK_AUTH_ENABLE=True to mitigate until official fix. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE20268505 #RCE #IBM

##

CVE-2026-8635
(9.9 CRITICAL)

EPSS: 0.29%

updated 2026-07-20T17:48:33.547000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.

thehackerwire@mastodon.social at 2026-07-18T11:00:39.000Z ##

🔴 CVE-2026-8635 - Critical (9.9)

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13446
(9.8 CRITICAL)

EPSS: 0.21%

updated 2026-07-20T17:38:56.090000

2 posts

IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

thehackerwire@mastodon.social at 2026-07-18T11:00:14.000Z ##

🔴 CVE-2026-13446 - Critical (9.8)

IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-18T09:00:36.000Z ##

CVE-2026-13446: IBM Langflow OSS 1.0.0 – 1.10.1 contains hard-coded credentials (CRITICAL, CVSS 9.8). Total system compromise possible. No patch yet — restrict access, monitor activity. More: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Cybersecurity #IBM

##

CVE-2026-45713
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-20T17:17:09.720000

2 posts

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test code, leaving it at Go's zero value (0 ⇒ "no limit"). The same applies to the HTTP /api/v1/send endpoint, whose request body is decoded with json.NewDecoder

thehackerwire@mastodon.social at 2026-07-20T17:01:16.000Z ##

🟠 CVE-2026-45713 - High (7.5)

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test cod...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-20T17:01:16.000Z ##

🟠 CVE-2026-45713 - High (7.5)

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test cod...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16242
(9.4 CRITICAL)

EPSS: 0.37%

updated 2026-07-20T17:17:04.883000

3 posts

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy,

hugovalters@mastodon.social at 2026-07-20T12:07:11.000Z ##

CVE-2026-16242 - Critical authentication bypass in Konnectivity proxy-server. CVSS 9.4. Unpatched. Attackers can intercept control-plane traffic. Isolate affected systems immediately. #CVE #Konnectivity #infosec

valtersit.com/cve/CVE-2026-162

##

offseq at 2026-07-20T10:30:27.499Z ##

CVE-2026-16242 (CRITICAL, CVSS 9.4) affects Red Hat Logging Subsystem for OpenShift: missing agent auth in Konnectivity proxy-server lets remote attackers intercept/control plane traffic. Restrict endpoint access & check radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-20T10:30:27.000Z ##

CVE-2026-16242 (CRITICAL, CVSS 9.4) affects Red Hat Logging Subsystem for OpenShift: missing agent auth in Konnectivity proxy-server lets remote attackers intercept/control plane traffic. Restrict endpoint access & check radar.offseq.com/threat/cve-20 #OffSeq #RedHat #CVE202626242

##

CVE-2026-11826
(8.8 HIGH)

EPSS: 0.42%

updated 2026-07-20T17:17:04.230000

2 posts

OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a caller-supplied buffer with no size parameter and no bounds check. In parseConfig() the function is invoked with the 100-byte heap-allocated MB_device.dev_name field. An authenticated attacker with access to the OpenPLC web interfa

offseq@infosec.exchange at 2026-07-18T15:00:29.000Z ##

CVE-2026-11826 | HIGH severity heap overflow in openplcproject OpenPLC_v3: Crafted HTTP POST to /modbus can crash the PLC process & corrupt config fields. No fix — migrate to v4 & restrict access. radar.offseq.com/threat/cve-20 #OffSeq #ICS #Vulnerability #Infosec

##

thehackerwire@mastodon.social at 2026-07-18T15:00:12.000Z ##

🟠 CVE-2026-11826 - High (8.8)

OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a caller-supplied buffer with no size parameter and no bounds check. In parseCon...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13473
(8.1 HIGH)

EPSS: 0.46%

updated 2026-07-20T17:15:53.673000

1 posts

IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.

thehackerwire@mastodon.social at 2026-07-18T18:01:01.000Z ##

🟠 CVE-2026-13473 - High (8.1)

IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9171
(7.5 HIGH)

EPSS: 0.55%

updated 2026-07-20T17:15:53.673000

1 posts

IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

thehackerwire@mastodon.social at 2026-07-17T20:00:35.000Z ##

🟠 CVE-2026-9171 - High (7.5)

IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48373
(7.8 HIGH)

EPSS: 0.19%

updated 2026-07-20T17:14:58.043000

1 posts

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

thehackerwire@mastodon.social at 2026-07-18T16:00:12.000Z ##

🟠 CVE-2026-48373 - High (7.8)

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54910
(7.7 HIGH)

EPSS: 0.00%

updated 2026-07-20T16:17:05.233000

2 posts

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent path traversal vectors. The primary vector is the `path` parameter: it is passed d

thehackerwire@mastodon.social at 2026-07-20T16:00:12.000Z ##

🟠 CVE-2026-54910 - High (7.7)

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-20T16:00:12.000Z ##

🟠 CVE-2026-54910 - High (7.7)

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-51027
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-07-20T16:17:04.897000

2 posts

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

thehackerwire@mastodon.social at 2026-07-20T17:00:12.000Z ##

🔴 CVE-2026-51027 - Critical (9.9)

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-20T17:00:12.000Z ##

🔴 CVE-2026-51027 - Critical (9.9)

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47868
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-20T16:17:02.377000

1 posts

VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)

thehackerwire@mastodon.social at 2026-07-18T10:00:55.000Z ##

🟠 CVE-2026-47868 - High (7.8)

VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root.

Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47865
(9.8 CRITICAL)

EPSS: 0.66%

updated 2026-07-20T16:17:02.067000

1 posts

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)

thehackerwire@mastodon.social at 2026-07-18T10:00:01.000Z ##

🔴 CVE-2026-47865 - Critical (9.8)

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.

Affected versions:
31.1.1 through 31.2.2 (fixed ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46415
(8.2 HIGH)

EPSS: 0.00%

updated 2026-07-20T16:17:01.163000

2 posts

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender used `r.RemoteAddr` when evaluating whether a request should be blocked. `RemoteAddr` is the address of the immediate peer connected to Caddy. In deployments where Caddy is behind a trusted proxy, CDN, or load balancer, the

thehackerwire@mastodon.social at 2026-07-20T17:01:05.000Z ##

🟠 CVE-2026-46415 - High (8.2)

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender used `r.RemoteAddr` when evaluating whether a request should be blocked...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-20T17:01:05.000Z ##

🟠 CVE-2026-46415 - High (8.2)

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender used `r.RemoteAddr` when evaluating whether a request should be blocked...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46412
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-07-20T16:17:01

2 posts

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). The postinstall payload attempted to harvest npm tokens (from `~/.npmrc`); GitHub personal access t

thehackerwire@mastodon.social at 2026-07-20T17:00:24.000Z ##

🔴 CVE-2026-46412 - Critical (10)

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-20T17:00:24.000Z ##

🔴 CVE-2026-46412 - Critical (10)

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-35198
(9.0 CRITICAL)

EPSS: 0.00%

updated 2026-07-20T16:16:58.440000

2 posts

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the form, leading to complete account takeover through privilege escalation. Version 3.0.0-rc.7 contains a patch for the issue.

thehackerwire@mastodon.social at 2026-07-20T17:01:26.000Z ##

🔴 CVE-2026-35198 - Critical (9)

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-20T17:01:26.000Z ##

🔴 CVE-2026-35198 - Critical (9)

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16117
(10.0 CRITICAL)

EPSS: 0.27%

updated 2026-07-20T16:16:56.053000

1 posts

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encoded form, and the prefix-rewrite step uses a literal string replace against the decoded prefix. A request that encodes one or more characters of the configured prefi

thehackerwire@mastodon.social at 2026-07-18T15:00:23.000Z ##

🔴 CVE-2026-16117 - Critical (10)

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encoded form, an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15631
(8.7 HIGH)

EPSS: 0.30%

updated 2026-07-20T16:16:55.670000

1 posts

Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapses dot segments, so a crafted upgrade request with path traversal sequences can escape the rewrite pr

thehackerwire@mastodon.social at 2026-07-18T14:00:23.000Z ##

🟠 CVE-2026-15631 - High (8.7)

Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the desti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13577
(8.2 HIGH)

EPSS: 0.14%

updated 2026-07-20T15:33:11

2 posts

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id when both Math::Random::ISAAC::XS and Crypt::URandom are unavailable. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path

offseq at 2026-07-20T12:00:30.108Z ##

CVE-2026-13577 | HIGH severity in CROMEDOME Dancer2 ≤2.1.0: Predictable session IDs if CSPRNG modules are missing. Install Math::Random::ISAAC::XS/Crypt::URandom to mitigate. Full info: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-20T12:00:30.000Z ##

CVE-2026-13577 | HIGH severity in CROMEDOME Dancer2 ≤2.1.0: Predictable session IDs if CSPRNG modules are missing. Install Math::Random::ISAAC::XS/Crypt::URandom to mitigate. Full info: radar.offseq.com/threat/cve-20 #OffSeq #CVE202613577 #infosec #Perl

##

CVE-2026-63090
(8.8 HIGH)

EPSS: 0.00%

updated 2026-07-20T15:32:15

2 posts

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt

thehackerwire@mastodon.social at 2026-07-20T16:00:00.000Z ##

🟠 CVE-2026-63090 - High (8.8)

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-20T16:00:00.000Z ##

🟠 CVE-2026-63090 - High (8.8)

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57309(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-07-20T15:32:06

2 posts

A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.

offseq at 2026-07-20T13:30:32.232Z ##

CVE-2026-57309 (CRITICAL, CVSS 9.3): Windu CMS 4.1 suffers from a blind SQL injection via HTTP header URL path. No patch yet — restrict exposed endpoints and monitor for abnormal DB activity. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-20T13:30:32.000Z ##

CVE-2026-57309 (CRITICAL, CVSS 9.3): Windu CMS 4.1 suffers from a blind SQL injection via HTTP header URL path. No patch yet — restrict exposed endpoints and monitor for abnormal DB activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #SQLi #Vuln #CVE202657309

##

CVE-2026-12080
(7.3 HIGH)

EPSS: 0.00%

updated 2026-07-20T15:32:05

1 posts

A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-

hugovalters@mastodon.social at 2026-07-20T14:06:02.000Z ##

CVE-2026-12080 - Privilege Escalation in QEMU Guest Agent. TOCTOU & symlink abuse in guest-ssh-add-authorized-keys. CVSS 7.3. Unpatched. Restrict qga access immediately. #CVE #infosec #QEMU

valtersit.com/cve/CVE-2026-120

##

CVE-2026-63831
(8.8 HIGH)

EPSS: 0.17%

updated 2026-07-20T15:16:49.803000

1 posts

In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: add skb_cow_data() before in-place crypto llsec_do_encrypt_unauth(), llsec_do_encrypt_auth(), llsec_do_decrypt_unauth(), and llsec_do_decrypt_auth() all perform in-place cryptographic transformations on skb data. They build a scatterlist with sg_init_one() pointing into the skb's linear data area and then pass

offseq@infosec.exchange at 2026-07-20T06:00:25.000Z ##

CVE-2026-63831: Linux kernel mac802154 llsec vuln (HIGH) could cause data corruption & kernel crashes via unsafe crypto ops on shared skb buffers. Update to patched kernel for stability. More: radar.offseq.com/threat/in-the #OffSeq #Linux #CVE202663831 #Infosec

##

CVE-2026-63795
(10.0 CRITICAL)

EPSS: 0.17%

updated 2026-07-20T15:16:46.193000

2 posts

In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set to false, fid aliases oldfid. If the walk subsequently fails after the request has been sent, the error path jumps to clunk_fid, which currently calls p9_fid_put(fid) unconditionally. This drops a reference to oldfid even thou

CVE-2026-49485
(7.5 HIGH)

EPSS: 0.68%

updated 2026-07-20T15:16:39.090000

1 posts

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input validation, and the FHIRPath functions matches(), matchesFull(), and replaceMatches() pass user-controlled regular expressions to Java's Pattern.compile() and

thehackerwire@mastodon.social at 2026-07-18T05:00:33.000Z ##

🟠 CVE-2026-49485 - High (7.5)

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input valida...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48062
(9.8 CRITICAL)

EPSS: 0.44%

updated 2026-07-20T15:16:38.980000

1 posts

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of the client-provided filename extension. As a result, an uploaded file named shell.php containing GIF-like content could pass validation such as uploaded[avatar]|is_image[avatar]|mime_in[avatar,image/gif

thehackerwire@mastodon.social at 2026-07-18T09:00:20.000Z ##

🔴 CVE-2026-48062 - Critical (9.8)

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of the client-provided filename extension. As a resu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12484
(7.8 HIGH)

EPSS: 0.20%

updated 2026-07-20T15:16:34.223000

3 posts

A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=False)` without requiring an explicit unsafe opt-in, such as a `safe_mode=False` parameter. When called outside a `SafeModeScope(True)` context, the abse

offseq@infosec.exchange at 2026-07-20T03:00:28.000Z ##

keras-team/keras v3.15.0 suffers a HIGH severity deserialization flaw (CVE-2026-12484). Unsafe use of TorchModuleWrapper.from_config can lead to code execution via malicious PyTorch pickle files. Enforce safe deserialization or avoid untrusted configs. radar.offseq.com/threat/cve-20 #OffSeq #Keras #Infosec #CVE2026_12484

##

hugovalters@mastodon.social at 2026-07-19T23:02:27.000Z ##

CVE-2026-12484 - Insecure Deserialization in Keras-Team. Unsafe PyTorch pickle loading in torch.load via TorchModuleWrapper.from_config. CVSS 7.8. Patch unknown, restrict usage immediately. #CVE #infosec #AIsecurity

valtersit.com/cve/CVE-2026-124

##

thehackerwire@mastodon.social at 2026-07-19T21:00:29.000Z ##

🟠 CVE-2026-12484 - High (7.8)

A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39359
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-20T13:42:42.300000

1 posts

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the Wazuh Manager's enrollment daemon (authd) and synchronization daemon (remoted). The authd process allows agents to select a group during enrollment but does not filter path traversal sequences such as "..." While the mana

CVE-2026-16229
(4.3 MEDIUM)

EPSS: 0.44%

updated 2026-07-20T13:30:32.407000

1 posts

A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.

offseq@infosec.exchange at 2026-07-19T10:30:24.000Z ##

CVE-2026-16229 (MEDIUM, CVSS 5.3): XSS in itsourcecode Courier Management System v1.0 via 'page' param in /index.php. Remote exploitation possible, user interaction needed. No patch yet — use WAF and input validation. radar.offseq.com/threat/cve-20 #OffSeq #XSS #Vuln

##

CVE-2026-16223
(6.3 MEDIUM)

EPSS: 0.21%

updated 2026-07-20T13:30:32.407000

1 posts

A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function getSqlBotSrc of the file backend/crm/src/main/java/cn/cordys/crm/system/service/IntegrationConfigService.java of the component Third Party Edit Endpoint. Executing a manipulation of the argument appSecret can lead to server-side request forgery. The attack may be launched remotely. The exploit has been pub

offseq@infosec.exchange at 2026-07-19T09:00:26.000Z ##

CVE-2026-16223: SSRF in 1Panel-dev CordysCRM 1.4.0 & 1.4.1 (MEDIUM, CVSS 5.3). Exploitable via appSecret — enables unauthorized server requests. No patch yet: restrict endpoint, monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #CyberSecurity #Vuln

##

CVE-2026-16096
(8.8 HIGH)

EPSS: 0.44%

updated 2026-07-20T13:30:32.407000

3 posts

A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This project is superseded by FreshTomato.

offseq@infosec.exchange at 2026-07-19T03:00:26.000Z ##

CVE-2026-16096: HIGH severity stack buffer overflow in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124 (/proc/webmon_recent_domains). Remote exploit possible, no official patch. Migrate to FreshTomato. radar.offseq.com/threat/a-vuln #OffSeq #Vulnerability #RouterSecurity #CVE #IoT

##

thehackerwire@mastodon.social at 2026-07-18T13:00:20.000Z ##

🟠 CVE-2026-16096 - High (8.8)

A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-18T12:00:25.000Z ##

CVE-2026-16096: Stack-based buffer overflow (CVSS 8.7, HIGH) in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124 (/proc/webmon_recent_domains). Remote exploit possible. Migrate to FreshTomato. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Infosec

##

CVE-2026-13142(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-07-20T09:31:15

1 posts

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator,

offseq@infosec.exchange at 2026-07-20T07:30:25.000Z ##

CVE-2026-13142 | CRITICAL: Social Login, Passkeys, Magic Link & Email OTP WordPress plugin (pre-1.4.1) allows OTP brute-force due to no rate limiting + plaintext storage. Admin takeover possible. Disable or restrict plugin use until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-16228
(7.3 HIGH)

EPSS: 0.41%

updated 2026-07-19T12:30:30

1 posts

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_schoolyr.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

offseq@infosec.exchange at 2026-07-19T12:00:25.000Z ##

CVE-2026-16228: MEDIUM-severity SQL injection in SourceCodester Class and Exam Timetabling System 1.0 (/edit_schoolyr.php). Remote, unauthenticated exploitation possible. No patch — apply input validation & parameterized queries. radar.offseq.com/threat/cve-20 #OffSeq #SQLInjection #AppSec

##

CVE-2026-16227
(7.3 HIGH)

EPSS: 0.41%

updated 2026-07-19T12:30:21

1 posts

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edit_subject.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

offseq@infosec.exchange at 2026-07-19T13:30:26.000Z ##

CVE-2026-16227: SQL injection in SourceCodester Class and Exam Timetabling System v1.0 (/edit_subject.php, ID param). MEDIUM severity (CVSS 6.9). No patch yet — use input validation & parameterized queries. radar.offseq.com/threat/cve-20 #OffSeq #SQLInjection #AppSec #Vuln

##

CVE-2026-16217
(6.3 MEDIUM)

EPSS: 0.22%

updated 2026-07-19T06:30:33

1 posts

A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file delivery/deli.py of the component Delivery Deployment Endpoint. The manipulation of the argument project_id leads to authorization bypass. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The proj

offseq@infosec.exchange at 2026-07-19T06:00:24.000Z ##

guohongze adminset (v0.1 – 0.61) is vulnerable to authorization bypass (CVE-2026-16217) via delivery/deli.py. Remote exploitation is possible, exploit is public. Severity: MEDIUM. Patch unavailable. radar.offseq.com/threat/cve-20 #OffSeq #CVE202616217 #Vuln #Infosec

##

CVE-2026-16210
(7.3 HIGH)

EPSS: 0.40%

updated 2026-07-19T06:30:24

1 posts

A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. Performing a manipulation results in missing authentication. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The project was informed of the problem early through an issue re

offseq@infosec.exchange at 2026-07-19T04:30:24.000Z ##

CVE-2026-16210: Medium severity vuln in newpanjing simpleui 2026.01.13 allows remote, unauthenticated actions via AjaxAdmin AJAX Endpoint. Exploit is public — no vendor fix yet. Restrict access or disable endpoint until patched. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #SimpleUI

##

CVE-2026-10130
(8.2 HIGH)

EPSS: 0.37%

updated 2026-07-18T23:17:00.397000

2 posts

QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. The signup route unconditionally creates and links a new token to the matching Identity via a Cypher MERGE operation before checking whether the email belongs to an existing account,

thehackerwire@mastodon.social at 2026-07-19T05:59:55.000Z ##

🟠 CVE-2026-10130 - High (8.2)

QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. The signup route unconditional...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-18T22:30:23.000Z ##

CVE-2026-10130 (HIGH, CVSS 8.2) in FalkorDB QueryWeaver: attackers can bypass authentication and obtain session tokens for existing accounts by submitting signup requests with known emails. Review signup flows. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #FalkorDB #Infosec

##

CVE-2026-12228
(8.7 HIGH)

EPSS: 0.26%

updated 2026-07-18T21:30:30

2 posts

A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into `DBDirectMessage.content` without server-side sanitization. When a victim opens the direct message (DM) thread, the message is rendered by the DM UI through `MessageContentRenderer`, which uses `v-html`

thehackerwire@mastodon.social at 2026-07-19T06:00:04.000Z ##

🟠 CVE-2026-12228 - High (8.7)

A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into `DBDirectMessage.content` without server-side san...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-19T00:00:33.000Z ##

CVE-2026-12228: parisneo/lollms suffers HIGH severity stored XSS (CVSS 8.7) via POST /api/prompts/share. Authenticated users can execute JS in victims' browsers, risking account takeover. Patch status unknown — check vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #XSS #Vuln #InfoSec

##

CVE-2026-53994
(7.5 HIGH)

EPSS: 0.40%

updated 2026-07-18T21:30:24

2 posts

ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of 0 causes an unsigned subtraction elsewhere in the read path to underflow to approximately 4 GB. That oversized request reaches the core memory allocator, where the

thehackerwire@mastodon.social at 2026-07-19T06:00:15.000Z ##

🟠 CVE-2026-53994 - High (7.5)

ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of 0 causes a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-19T01:30:30.000Z ##

CVE-2026-53994: ProFTPD mod_sftp heap buffer overflow (HIGH severity, CVSS 7.5) lets authenticated SFTP users crash session processes via crafted 0-length packets. Patch status unconfirmed — restrict SFTP access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #ProFTPD #infosec #vuln

##

CVE-2026-55518
(9.6 CRITICAL)

EPSS: 0.33%

updated 2026-07-18T17:22:30

1 posts

## Summary A critical missing authorization flaw exists in Avo's association attach workflow. The UI and `GET /resources/:resource/:id/:related/new` path can check `attach_<association>?`, but the actual write endpoint, `POST /resources/:resource/:id/:related`, does not run the same authorization check before mutating the association. As a result, an authenticated low-privileged Avo user can byp

thehackerwire@mastodon.social at 2026-07-17T22:00:26.000Z ##

🔴 CVE-2026-55518 - Critical (9.6)

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_? in the UI and GET /resources/:resource/:id/:related/new path, but the actual write endpoint, POS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9147
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-18T15:31:55

2 posts

uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the generated Python source without safe quoting via repr() or the !r format specifier. An attacker who can supply a crafted ROOT file can place Python expression-breakin

thehackerwire@mastodon.social at 2026-07-18T14:00:12.000Z ##

🟠 CVE-2026-9147 - High (7.8)

uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the generated Pyt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-18T13:30:27.000Z ##

scikit-hep uproot has a HIGH-severity code injection flaw (CVE-2026-9147, CVSS 8.5). Malicious ROOT files can trigger arbitrary Python code execution. Avoid untrusted files until fixed. Full details: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Python #ThreatIntel

##

CVE-2026-9323
(8.1 HIGH)

EPSS: 0.42%

updated 2026-07-18T14:17:12.170000

1 posts

The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Python's Mersenne Twister PRNG, which is not cryptographically secure. Each call consumes approximately 30 bits of PRNG state, and the Mersenne Twister internal state is approximately 19,937 bits, so an attacker who observes

thehackerwire@mastodon.social at 2026-07-18T15:00:03.000Z ##

🟠 CVE-2026-9323 - High (8.1)

The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Python's Mersenne Twister PRNG, which is not cryptographically secure. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16095
(8.8 HIGH)

EPSS: 0.42%

updated 2026-07-18T12:33:18

1 posts

A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write. The attack may be performed from remote. This project is superseded by FreshTomato.

thehackerwire@mastodon.social at 2026-07-18T11:59:57.000Z ##

🟠 CVE-2026-16095 - High (8.8)

A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write. The attack m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47871
(8.8 HIGH)

EPSS: 0.90%

updated 2026-07-18T09:32:24

1 posts

VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)

thehackerwire@mastodon.social at 2026-07-18T10:01:16.000Z ##

🟠 CVE-2026-47871 - High (8.8)

VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks.

Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 3...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47869
(8.7 HIGH)

EPSS: 0.68%

updated 2026-07-18T09:32:24

1 posts

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)

thehackerwire@mastodon.social at 2026-07-18T10:01:06.000Z ##

🟠 CVE-2026-47869 - High (8.7)

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code.

Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47866
(8.3 HIGH)

EPSS: 0.43%

updated 2026-07-18T09:32:24

1 posts

VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)

thehackerwire@mastodon.social at 2026-07-18T10:00:10.000Z ##

🟠 CVE-2026-47866 - High (8.3)

VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization.

Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 throug...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47867
(8.7 HIGH)

EPSS: 0.68%

updated 2026-07-18T09:32:17

1 posts

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)

thehackerwire@mastodon.social at 2026-07-18T10:00:20.000Z ##

🟠 CVE-2026-47867 - High (8.7)

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely.

Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53359
(8.8 HIGH)

EPSS: 0.12%

updated 2026-07-18T08:16:36.620000

2 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. Th

8 repos

https://github.com/HORKimhab/CVE-2026-53359

https://github.com/x024n/kvm-kernelcare-januscape

https://github.com/xj2268-TA/KVM-Januscape

https://github.com/Aoripus-LTD/Januscape-Hotfix

https://github.com/ndouglas-cloudsmith/CVE-2026-53359

https://github.com/0xBlackash/CVE-2026-53359

https://github.com/chuzhongyun/CVE-2026-53359-Kernel-Fix

https://github.com/x024n/almalinux-januscape-mitigation

EdwinG@mstdn.moimeme.ca at 2026-07-20T11:11:25.000Z ##

Turns out, OVH had to patch all their hypervisors because of a vulnerability in KVM. This did lead to service disruptions to their customers.

blog.ovhcloud.com/cve-2026-533
- - -
Il se trouve, OVH a eu à corriger une vulnérabilité dans KVM sur tous leurs hyperviseurs. Ceci a entraîné des interruptions de service chez leur clientèle

blog.ovhcloud.com/campagne-de-

#OVH #Montréal

##

EdwinG@mstdn.moimeme.ca at 2026-07-20T11:11:25.000Z ##

Turns out, OVH had to patch all their hypervisors because of a vulnerability in KVM. This did lead to service disruptions to their customers.

blog.ovhcloud.com/cve-2026-533
- - -
Il se trouve, OVH a eu à corriger une vulnérabilité dans KVM sur tous leurs hyperviseurs. Ceci a entraîné des interruptions de service chez leur clientèle

blog.ovhcloud.com/campagne-de-

#OVH #Montréal

##

CVE-2026-9762
(7.8 HIGH)

EPSS: 0.17%

updated 2026-07-18T05:16:56.710000

1 posts

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.

thehackerwire@mastodon.social at 2026-07-19T07:00:03.000Z ##

🟠 CVE-2026-9762 - High (7.8)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9202
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-07-18T05:16:56.447000

2 posts

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN.

thehackerwire@mastodon.social at 2026-07-19T06:59:54.000Z ##

🔴 CVE-2026-9202 - Critical (9.8)

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

hugovalters@mastodon.social at 2026-07-18T17:01:24.000Z ##

CVE-2026-9202 - Critical RCE in IBM Langflow. Unauthenticated account creation bypass leads to RCE. CVSS 9.8. No patch available. Mitigate by disabling NEW_USER_IS_ACTIVE. #CVE #IBM #infosec

valtersit.com/cve/CVE-2026-920

##

CVE-2026-63030
(9.8 CRITICAL)

EPSS: 8.95%

updated 2026-07-18T05:16:56.167000

31 posts

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Nuclei template

57 repos

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/kulichr/wp2shell

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/securelayer7/WordPresShell

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/c0gnit00/Wp2Shell

https://github.com/InstaWP/wp2shell-scan

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/zi3lak/wp2shell_scanner

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/0xWhoknows/wp2shell

https://github.com/bahartanir/wp2shell-scanner

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/Crypto-Cat/wp2shell

https://github.com/47Cid/wp2shell-lab

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/ikow/wp2shell

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/vulnquest58/PressVector

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/mverschu/CVE-2026-63030

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/fullhunt/wp2shell-scan

https://github.com/ekomsSavior/wp2shell

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/yoerivegt/wp2shell-poc

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/h4cd0c/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/dinosn/wp2shell-lab

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/OffByOn3/CVE-2026-63030-Wp2Shell

https://github.com/0xsha/wp2shell

https://github.com/ASYquan/wp2shell-cf-WAF-bypass

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/ananay/wp2shell-lab

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/gbrsh/CVE-2026-63030

https://github.com/mhtsec/CVE-2026-63030

https://github.com/attackercan/wp2shell-poc2

https://github.com/0xjessie21/wp2shell-checker

https://github.com/Icex0/wp2shell-poc

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/4minx/CVE-2026-63030

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

netsecio@mastodon.social at 2026-07-20T17:17:54.000Z ##

📰 Critical Unauthenticated RCE Flaw Found in WordPress Core

Critical unauthenticated RCE vulnerability (CVE-2026-63030) found in WordPress Core. Affects versions 6.9.x and 7.0.x. Allows full site takeover via REST API. Update to 6.9.5 or 7.0.2 now! #WordPress #CVE #RCE #PatchNow

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/cr

##

Xidewo@unredacted.social at 2026-07-20T16:32:01.000Z ##

W cyberpodziemiu opublikowano exploity wykorzystujące krytyczne luki RCE typu „wp2shell” występujące przed uwierzytelnieniem, które dotyczą jądra WordPressa. W wersjach WordPressa 6.9.5 i 7.0.2 naprawiono cały łańcuch ataków typu wp2shell. Atak typu wp2shell składa się z dwóch luk – CVE-2026-63030 i CVE-2026-60137, które można połączyć w celu zdalnego wykonania kodu przed uwierzytelnieniem w instalacjach WordPressa w wersjach 6.9. i 7.0.

##

ucucypep@flipboard.social at 2026-07-20T15:58:56.000Z ##

In de cyberonderwereld zijn exploits verspreid voor kritieke RCE-kwetsbaarheden vóór authenticatie (wp2shell), die de kern van WordPress treffen. In de versies WordPress 6.9.5 en 7.0.2 is de volledige wp2shell-aanvalsketen verholpen. De wp2shell-aanval bestaat uit twee kwetsbaarheden – CVE-2026-63030 en CVE-2026-60137 – die kunnen worden gecombineerd om op afstand code uit te voeren vóór authenticatie in WordPress-installaties van de versies 6.9. en 7.0.

##

AAKL at 2026-07-20T15:22:11.322Z ##

New.

Picus: CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained picussecurity.com/resource/blo

##

Analyst207@mastodon.social at 2026-07-20T14:06:41.000Z ##

Vulnerabilities Exposed in AI-Assisted Cyber Attacks

Beware: a potent pair of WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to allow anonymous remote code execution - and attackers are already exploiting them in the wild. Patch immediately to avoid devastating consequences.

osintsights.com/vulnerabilitie

#WordpressCoreVulnerabilities #RemoteCodeExecution #RestApi #SqlInjection #Cve202663030

##

bsi@social.bund.de at 2026-07-20T10:00:13.000Z ##

⚠️ 📢 #Sicherheitswarnung: WordPress – Schwachstellen erlauben "Remote Code Execution"

Am 17. Juli 2026 wurde seitens #Wordpress eine Aktualisierung bekannt gegeben, die zwei #Schwachstellen in der Wordpress-Software behebt.

❗️ Die beiden Schwachstellen CVE-2026-60137 und CVE-2026-63030 ermöglichen einem nicht authentifizierten, entfernten Angreifer Code zur Ausführung zu bringen.

Mehr dazu hier: 👉️ bsi.bund.de/dok/1203360

@certbund

##

decio at 2026-07-20T08:58:22.527Z ##

⚠️ Si vous administrez un site WordPress ou si vous connaissez quelqu’un qui en gère un faites passer l’information.

Une vulnérabilité critique baptisée WP2Shell touche directement le cœur de WordPress.

Cette fois, il ne s’agit pas d’un plugin abandonné ou d’un thème douteux : une installation standard peut être attaquée à distance, sans compte utilisateur, sans mot de passe et sans authentification préalable.

WP2Shell combine deux failles, CVE-2026-60137 et CVE-2026-63030, permettant à un attaquant d’exécuter du code sur le serveur et donc, potentiellement, de prendre le contrôle du site.

-> Des tentatives d’exploitation et des compromissions ont déjà été observées dans la nature.

Sont notamment concernées les versions :

➡️ WordPress 6.9.0 à 6.9.4
➡️ WordPress 7.0.0 à 7.0.1

Les correctifs sont disponibles dans les versions 6.9.5 et 7.0.2. WordPress a activé des mises à jour automatiques forcées en raison de la gravité de la faille, mais il ne faut pas supposer qu’elles ont forcément fonctionné : elles peuvent avoir été désactivées, bloquées par l’hébergeur ou empêchées par une configuration particulière.

À faire rapidement:

✅ vérifier la version réellement installée ;
✅ mettre WordPress à jour vers 6.9.5 ou 7.0.2 au minimum ;
✅ confirmer que la mise à jour s’est correctement terminée ;
✅ vérifier les comptes administrateurs, les fichiers récemment modifiés et les journaux du serveur ;
✅ rechercher d’éventuels fichiers PHP, plugins ou utilisateurs inconnus ;
✅ s’assurer que des sauvegardes propres et récentes sont disponibles.

En attendant la mise à jour, l’accès anonyme aux routes REST suivantes peut également être bloqué au niveau du WAF ou du serveur web :

/wp-json/batch/v1
?rest_route=/batch/v1

Point important : installer le correctif empêche une nouvelle exploitation, mais ne supprime pas une éventuelle compromission déjà présente. Si le site est resté exposé, une vérification minimale est donc nécessaire, même après la mise à jour.

Un site WordPress « qui fonctionne encore » n’est pas nécessairement un site sain : les attaquants cherchent souvent à rester discrets pour installer une porte dérobée, détourner le trafic, diffuser du spam ou préparer d’autres attaques...

🔍 wp2shell.com , pour vérifier si votre site est vulnérable.

Dans les news:
"WP2Shell - La faille qui permet de pirater WordPress sans aucun plugin"
👇
korben.info/wp2shell-exploits-

💬
⬇️
infosec.pub/post/49724018

##

cert_fr@social.numerique.gouv.fr at 2026-07-20T08:52:21.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-60137 et CVE-2026-63030 affectent WordPress et permettent une exécution de code arbitraire à distance non authentifiée.
Une preuve de concept est disponible.

cert.ssi.gouv.fr/alerte/CERTFR

##

Xidewo@unredacted.social at 2026-07-20T16:32:01.000Z ##

W cyberpodziemiu opublikowano exploity wykorzystujące krytyczne luki RCE typu „wp2shell” występujące przed uwierzytelnieniem, które dotyczą jądra WordPressa. W wersjach WordPressa 6.9.5 i 7.0.2 naprawiono cały łańcuch ataków typu wp2shell. Atak typu wp2shell składa się z dwóch luk – CVE-2026-63030 i CVE-2026-60137, które można połączyć w celu zdalnego wykonania kodu przed uwierzytelnieniem w instalacjach WordPressa w wersjach 6.9. i 7.0.

##

AAKL@infosec.exchange at 2026-07-20T15:22:11.000Z ##

New.

Picus: CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained picussecurity.com/resource/blo #infosec #vulnerability #WordPress

##

bsi@social.bund.de at 2026-07-20T10:00:13.000Z ##

⚠️ 📢 #Sicherheitswarnung: WordPress – Schwachstellen erlauben "Remote Code Execution"

Am 17. Juli 2026 wurde seitens #Wordpress eine Aktualisierung bekannt gegeben, die zwei #Schwachstellen in der Wordpress-Software behebt.

❗️ Die beiden Schwachstellen CVE-2026-60137 und CVE-2026-63030 ermöglichen einem nicht authentifizierten, entfernten Angreifer Code zur Ausführung zu bringen.

Mehr dazu hier: 👉️ bsi.bund.de/dok/1203360

@certbund

##

decio@infosec.exchange at 2026-07-20T08:58:22.000Z ##

⚠️ Si vous administrez un site WordPress ou si vous connaissez quelqu’un qui en gère un faites passer l’information.

Une vulnérabilité critique baptisée WP2Shell touche directement le cœur de WordPress.

Cette fois, il ne s’agit pas d’un plugin abandonné ou d’un thème douteux : une installation standard peut être attaquée à distance, sans compte utilisateur, sans mot de passe et sans authentification préalable.

WP2Shell combine deux failles, CVE-2026-60137 et CVE-2026-63030, permettant à un attaquant d’exécuter du code sur le serveur et donc, potentiellement, de prendre le contrôle du site.

-> Des tentatives d’exploitation et des compromissions ont déjà été observées dans la nature.

Sont notamment concernées les versions :

➡️ WordPress 6.9.0 à 6.9.4
➡️ WordPress 7.0.0 à 7.0.1

Les correctifs sont disponibles dans les versions 6.9.5 et 7.0.2. WordPress a activé des mises à jour automatiques forcées en raison de la gravité de la faille, mais il ne faut pas supposer qu’elles ont forcément fonctionné : elles peuvent avoir été désactivées, bloquées par l’hébergeur ou empêchées par une configuration particulière.

À faire rapidement:

✅ vérifier la version réellement installée ;
✅ mettre WordPress à jour vers 6.9.5 ou 7.0.2 au minimum ;
✅ confirmer que la mise à jour s’est correctement terminée ;
✅ vérifier les comptes administrateurs, les fichiers récemment modifiés et les journaux du serveur ;
✅ rechercher d’éventuels fichiers PHP, plugins ou utilisateurs inconnus ;
✅ s’assurer que des sauvegardes propres et récentes sont disponibles.

En attendant la mise à jour, l’accès anonyme aux routes REST suivantes peut également être bloqué au niveau du WAF ou du serveur web :

/wp-json/batch/v1
?rest_route=/batch/v1

Point important : installer le correctif empêche une nouvelle exploitation, mais ne supprime pas une éventuelle compromission déjà présente. Si le site est resté exposé, une vérification minimale est donc nécessaire, même après la mise à jour.

Un site WordPress « qui fonctionne encore » n’est pas nécessairement un site sain : les attaquants cherchent souvent à rester discrets pour installer une porte dérobée, détourner le trafic, diffuser du spam ou préparer d’autres attaques...

🔍 wp2shell.com , pour vérifier si votre site est vulnérable.

Dans les news:
"WP2Shell - La faille qui permet de pirater WordPress sans aucun plugin"
👇
korben.info/wp2shell-exploits-

💬
⬇️
infosec.pub/post/49724018

#CyberVeille #WordPress

##

cert_fr@social.numerique.gouv.fr at 2026-07-20T08:52:21.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-60137 et CVE-2026-63030 affectent WordPress et permettent une exécution de code arbitraire à distance non authentifiée.
Une preuve de concept est disponible.

cert.ssi.gouv.fr/alerte/CERTFR

##

offseq@infosec.exchange at 2026-07-20T04:30:24.000Z ##

wp2shell (CVE-2026-63030, CVE-2026-60137) allows unauth RCE in WordPress core (HIGH severity). Active exploitation reported. Patch to 6.9.5, 7.0.2, or 6.8.6. Block REST API batch endpoint if needed. Details: radar.offseq.com/threat/wp2she #OffSeq #WordPress #RCE #Vulnerability

##

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

_r_netsec@infosec.exchange at 2026-07-19T23:58:05.000Z ##

wp2shell: a defender’s guide (CVE-2026-63030 + CVE-2026-60137) with a list of forensic artifacts, a compromise scanner WordPress plugin and a free Chrome/Edge/Firefox browser extension to in-browser check if a website has been patched. research.eye.security/wp2shell

##

_r_netsec@infosec.exchange at 2026-07-19T08:28:05.000Z ##

wp2shell (CVE-2026-63030) update: public working exploit now available for the WordPress core pre-auth RCE ransomnews.com/wp2shell-wordpr

##

raptor@infosec.exchange at 2026-07-19T06:22:20.000Z ##

🤯 wp2shell (CVE-2026-63030): Pre-Auth #RCE Chain in #WordPress Core

“WordPress patched it in 6.9.5 and 7.0.2, touching three files and sixteen lines. This post covers what broke, why the bugs connect, and what teams running WordPress need to do.”

fullhunt.io/blog/2026/07/17/wp

##

threatnoir@infosec.exchange at 2026-07-19T04:06:03.000Z ##

⚠️ CRITICAL: WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Critical unauthenticated RCE vulnerabilities in WordPress Core (CVE-2026-63030, CVE-2026-60137) are actively exploited via public PoCs. The wp2shell attack chains REST API and SQL injection flaws to achieve code execution on default installations of WordPress 6.9.x and 7.0.x. All affected WordPress…

threatnoir.com/focus

#infosec #cybersecurity

##

DarkWebInformer@infosec.exchange at 2026-07-19T00:02:23.000Z ##

‼️ CVE-2026-63030: wp2shell, a critical remote code execution vulnerability in WordPress core

Credit: @hash_kitten // @assetnote

PoC: x.com/DarkWebInformer/status/2

##

_r_netsec@infosec.exchange at 2026-07-18T21:28:05.000Z ##

wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner fullhunt.io/blog/2026/07/17/wp

##

offseq@infosec.exchange at 2026-07-18T18:00:28.000Z ##

WordPress Core "wp2shell" CRITICAL RCE chain (CVE-2026-63030 & CVE-2026-60137) actively exploited. Affects 6.9.0 – 6.9.4 & 7.0.0 – 7.0.1. Public PoCs out. Patch to 6.9.5/7.0.2 ASAP. Block REST API endpoints as temp mitigation. radar.offseq.com/threat/wordpr #OffSeq #WordPress #RCE #Vuln

##

davidgerard@circumstances.run at 2026-07-18T16:17:54.000Z ##

Update your WordPress to 7.0.2/6.9.5, it's important

discourse.ifin.network/t/cve-2

ETA: the above text is not a call for CMS evangelists, just fucking don't thanks

##

secdb@infosec.exchange at 2026-07-18T15:42:16.000Z ##

🚨 wp2shell affects multiple vulnerabilities (CVE-2026-63030, CVE-2026-60137).

- CVE-2026-63030 (HIGH) - WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
- CVE-2026-60137 (CRITICAL) - WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query

Running WordPress? Check your versions and patch to 6.8.6 / 6.9.5 / 7.0.2. If you can't patch immediately, apply the mitigations in the meantime.

ℹ️ Additional information on ZEN SecDB
secdb.nttzen.cloud/updates/a5a

#infosec #wordpress #rce #sqlinjection #cve202663030 #cve202660137
#nttdata #zen #secdb #vulnerability_intelligence

##

thehackerwire@mastodon.social at 2026-07-18T15:01:19.000Z ##

🔴 CVE-2026-63030 - Critical (9.8)

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

pentesttools@infosec.exchange at 2026-07-18T13:34:36.000Z ##

#WordPress admins - we got you covered! 🫡 → We've just shipped detection for #wp2shell through our Network Scanner. ⚡️ The fastest way to use it is to:

◉ run a single-CVE scan for CVE-2026-63030 - which also covers CVE-2026-60137 - the SQL injection flaw that chains to give attackers RCE
◉ Based on your scan results, either patch or confirm you're already on 6.8.6, 6.9.5, or 7.0.2.
◉ Re-scan to confirm remediation and rule out residual exposure across your other assets.

Remember: updating your main install doesn't cover *every* WP instance you own. Using Pentest-Tools.com means you can expand visibility across your wider attack surface, not just the site you remember exists.

Technical CVE details below. ↘︎↘︎↘︎

See why an estimated 500+ million websites running WP are vulnerable to this critical vulnerability: pentest-tools.com/vulnerabilit

#vulnerabilityassessment #ethicalhacking #offensivesecurity

##

security_crawler_carl@infosec.exchange at 2026-07-18T13:05:54.000Z ##

🏆 New Achievement! wp2Shell We Have A Problem!

QUEST UPDATE — PREREQUISITE FAILED: "Have A Website That Isn't On Fire." WordPress Core carries CVE-2026-63030, a critical unauthenticated remote code execution flaw haunting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. No login required. No credentials to steal. The attacker just knocks and your site answers. A companion SQL injection, CVE-2026-60137, is also along for the ride, because one cursed artifact is never enough. (1/2)

##

obivan@infosec.exchange at 2026-07-18T10:46:00.000Z ##

wp2shell (CVE-2026-63030 + CVE-2026-60137): Independent Root Cause Analysis github.com/tcyph3r/wp2shell-cv

##

DailyCyberSecurity@infosec.exchange at 2026-07-18T01:56:15.000Z ##

WordPress pre-auth RCE CVE-2026-63030 chains a REST batch bug with SQL injection. Details and a public PoC are out. Update to WordPress 7.0.2 now.

#WordPress #PreAuthRCE #CVE202663030 #SQLInjection #wp2shell #WebSecurity #InfoSec

securityonline.info/wordpress-

##

DarkWebInformer@infosec.exchange at 2026-07-17T22:53:05.000Z ##

‼️🚨 CVE-2026-63030 // wp2shell-poc: Proof-of-concept for an unauthenticated SQL injection in WordPress core that chains to remote code execution, via REST batch route confusion.

PoC: github.com/Icex0/wp2shell-poc

##

christopherkunz@chaos.social at 2026-07-17T21:19:55.000Z ##

@shellsharks New fodder for vulnerability.garden: wp2shell is CVE-2026-63030 / github.com/WordPress/wordpress

##

CVE-2026-60137
(5.9 MEDIUM)

EPSS: 4.03%

updated 2026-07-18T05:16:54.427000

23 posts

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

31 repos

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/kulichr/wp2shell

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/securelayer7/WordPresShell

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/zi3lak/wp2shell_scanner

https://github.com/0xWhoknows/wp2shell

https://github.com/bahartanir/wp2shell-scanner

https://github.com/47Cid/wp2shell-lab

https://github.com/ikow/wp2shell

https://github.com/vulnquest58/PressVector

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/h4cd0c/wp2shell

https://github.com/ekomsSavior/wp2shell

https://github.com/yoerivegt/wp2shell-poc

https://github.com/NULL200OK/WP2Shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/dinosn/wp2shell-lab

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/0xsha/wp2shell

https://github.com/ananay/wp2shell-lab

https://github.com/0xjessie21/wp2shell-checker

https://github.com/Icex0/wp2shell-poc

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/Crypto-Cat/wp2shell

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

Xidewo@unredacted.social at 2026-07-20T16:32:01.000Z ##

W cyberpodziemiu opublikowano exploity wykorzystujące krytyczne luki RCE typu „wp2shell” występujące przed uwierzytelnieniem, które dotyczą jądra WordPressa. W wersjach WordPressa 6.9.5 i 7.0.2 naprawiono cały łańcuch ataków typu wp2shell. Atak typu wp2shell składa się z dwóch luk – CVE-2026-63030 i CVE-2026-60137, które można połączyć w celu zdalnego wykonania kodu przed uwierzytelnieniem w instalacjach WordPressa w wersjach 6.9. i 7.0.

##

ucucypep@flipboard.social at 2026-07-20T15:58:56.000Z ##

In de cyberonderwereld zijn exploits verspreid voor kritieke RCE-kwetsbaarheden vóór authenticatie (wp2shell), die de kern van WordPress treffen. In de versies WordPress 6.9.5 en 7.0.2 is de volledige wp2shell-aanvalsketen verholpen. De wp2shell-aanval bestaat uit twee kwetsbaarheden – CVE-2026-63030 en CVE-2026-60137 – die kunnen worden gecombineerd om op afstand code uit te voeren vóór authenticatie in WordPress-installaties van de versies 6.9. en 7.0.

##

AAKL at 2026-07-20T15:22:11.322Z ##

New.

Picus: CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained picussecurity.com/resource/blo

##

Analyst207@mastodon.social at 2026-07-20T14:06:41.000Z ##

Vulnerabilities Exposed in AI-Assisted Cyber Attacks

Beware: a potent pair of WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to allow anonymous remote code execution - and attackers are already exploiting them in the wild. Patch immediately to avoid devastating consequences.

osintsights.com/vulnerabilitie

#WordpressCoreVulnerabilities #RemoteCodeExecution #RestApi #SqlInjection #Cve202663030

##

bsi@social.bund.de at 2026-07-20T10:00:13.000Z ##

⚠️ 📢 #Sicherheitswarnung: WordPress – Schwachstellen erlauben "Remote Code Execution"

Am 17. Juli 2026 wurde seitens #Wordpress eine Aktualisierung bekannt gegeben, die zwei #Schwachstellen in der Wordpress-Software behebt.

❗️ Die beiden Schwachstellen CVE-2026-60137 und CVE-2026-63030 ermöglichen einem nicht authentifizierten, entfernten Angreifer Code zur Ausführung zu bringen.

Mehr dazu hier: 👉️ bsi.bund.de/dok/1203360

@certbund

##

decio at 2026-07-20T08:58:22.527Z ##

⚠️ Si vous administrez un site WordPress ou si vous connaissez quelqu’un qui en gère un faites passer l’information.

Une vulnérabilité critique baptisée WP2Shell touche directement le cœur de WordPress.

Cette fois, il ne s’agit pas d’un plugin abandonné ou d’un thème douteux : une installation standard peut être attaquée à distance, sans compte utilisateur, sans mot de passe et sans authentification préalable.

WP2Shell combine deux failles, CVE-2026-60137 et CVE-2026-63030, permettant à un attaquant d’exécuter du code sur le serveur et donc, potentiellement, de prendre le contrôle du site.

-> Des tentatives d’exploitation et des compromissions ont déjà été observées dans la nature.

Sont notamment concernées les versions :

➡️ WordPress 6.9.0 à 6.9.4
➡️ WordPress 7.0.0 à 7.0.1

Les correctifs sont disponibles dans les versions 6.9.5 et 7.0.2. WordPress a activé des mises à jour automatiques forcées en raison de la gravité de la faille, mais il ne faut pas supposer qu’elles ont forcément fonctionné : elles peuvent avoir été désactivées, bloquées par l’hébergeur ou empêchées par une configuration particulière.

À faire rapidement:

✅ vérifier la version réellement installée ;
✅ mettre WordPress à jour vers 6.9.5 ou 7.0.2 au minimum ;
✅ confirmer que la mise à jour s’est correctement terminée ;
✅ vérifier les comptes administrateurs, les fichiers récemment modifiés et les journaux du serveur ;
✅ rechercher d’éventuels fichiers PHP, plugins ou utilisateurs inconnus ;
✅ s’assurer que des sauvegardes propres et récentes sont disponibles.

En attendant la mise à jour, l’accès anonyme aux routes REST suivantes peut également être bloqué au niveau du WAF ou du serveur web :

/wp-json/batch/v1
?rest_route=/batch/v1

Point important : installer le correctif empêche une nouvelle exploitation, mais ne supprime pas une éventuelle compromission déjà présente. Si le site est resté exposé, une vérification minimale est donc nécessaire, même après la mise à jour.

Un site WordPress « qui fonctionne encore » n’est pas nécessairement un site sain : les attaquants cherchent souvent à rester discrets pour installer une porte dérobée, détourner le trafic, diffuser du spam ou préparer d’autres attaques...

🔍 wp2shell.com , pour vérifier si votre site est vulnérable.

Dans les news:
"WP2Shell - La faille qui permet de pirater WordPress sans aucun plugin"
👇
korben.info/wp2shell-exploits-

💬
⬇️
infosec.pub/post/49724018

##

cert_fr@social.numerique.gouv.fr at 2026-07-20T08:52:21.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-60137 et CVE-2026-63030 affectent WordPress et permettent une exécution de code arbitraire à distance non authentifiée.
Une preuve de concept est disponible.

cert.ssi.gouv.fr/alerte/CERTFR

##

Xidewo@unredacted.social at 2026-07-20T16:32:01.000Z ##

W cyberpodziemiu opublikowano exploity wykorzystujące krytyczne luki RCE typu „wp2shell” występujące przed uwierzytelnieniem, które dotyczą jądra WordPressa. W wersjach WordPressa 6.9.5 i 7.0.2 naprawiono cały łańcuch ataków typu wp2shell. Atak typu wp2shell składa się z dwóch luk – CVE-2026-63030 i CVE-2026-60137, które można połączyć w celu zdalnego wykonania kodu przed uwierzytelnieniem w instalacjach WordPressa w wersjach 6.9. i 7.0.

##

AAKL@infosec.exchange at 2026-07-20T15:22:11.000Z ##

New.

Picus: CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained picussecurity.com/resource/blo #infosec #vulnerability #WordPress

##

bsi@social.bund.de at 2026-07-20T10:00:13.000Z ##

⚠️ 📢 #Sicherheitswarnung: WordPress – Schwachstellen erlauben "Remote Code Execution"

Am 17. Juli 2026 wurde seitens #Wordpress eine Aktualisierung bekannt gegeben, die zwei #Schwachstellen in der Wordpress-Software behebt.

❗️ Die beiden Schwachstellen CVE-2026-60137 und CVE-2026-63030 ermöglichen einem nicht authentifizierten, entfernten Angreifer Code zur Ausführung zu bringen.

Mehr dazu hier: 👉️ bsi.bund.de/dok/1203360

@certbund

##

decio@infosec.exchange at 2026-07-20T08:58:22.000Z ##

⚠️ Si vous administrez un site WordPress ou si vous connaissez quelqu’un qui en gère un faites passer l’information.

Une vulnérabilité critique baptisée WP2Shell touche directement le cœur de WordPress.

Cette fois, il ne s’agit pas d’un plugin abandonné ou d’un thème douteux : une installation standard peut être attaquée à distance, sans compte utilisateur, sans mot de passe et sans authentification préalable.

WP2Shell combine deux failles, CVE-2026-60137 et CVE-2026-63030, permettant à un attaquant d’exécuter du code sur le serveur et donc, potentiellement, de prendre le contrôle du site.

-> Des tentatives d’exploitation et des compromissions ont déjà été observées dans la nature.

Sont notamment concernées les versions :

➡️ WordPress 6.9.0 à 6.9.4
➡️ WordPress 7.0.0 à 7.0.1

Les correctifs sont disponibles dans les versions 6.9.5 et 7.0.2. WordPress a activé des mises à jour automatiques forcées en raison de la gravité de la faille, mais il ne faut pas supposer qu’elles ont forcément fonctionné : elles peuvent avoir été désactivées, bloquées par l’hébergeur ou empêchées par une configuration particulière.

À faire rapidement:

✅ vérifier la version réellement installée ;
✅ mettre WordPress à jour vers 6.9.5 ou 7.0.2 au minimum ;
✅ confirmer que la mise à jour s’est correctement terminée ;
✅ vérifier les comptes administrateurs, les fichiers récemment modifiés et les journaux du serveur ;
✅ rechercher d’éventuels fichiers PHP, plugins ou utilisateurs inconnus ;
✅ s’assurer que des sauvegardes propres et récentes sont disponibles.

En attendant la mise à jour, l’accès anonyme aux routes REST suivantes peut également être bloqué au niveau du WAF ou du serveur web :

/wp-json/batch/v1
?rest_route=/batch/v1

Point important : installer le correctif empêche une nouvelle exploitation, mais ne supprime pas une éventuelle compromission déjà présente. Si le site est resté exposé, une vérification minimale est donc nécessaire, même après la mise à jour.

Un site WordPress « qui fonctionne encore » n’est pas nécessairement un site sain : les attaquants cherchent souvent à rester discrets pour installer une porte dérobée, détourner le trafic, diffuser du spam ou préparer d’autres attaques...

🔍 wp2shell.com , pour vérifier si votre site est vulnérable.

Dans les news:
"WP2Shell - La faille qui permet de pirater WordPress sans aucun plugin"
👇
korben.info/wp2shell-exploits-

💬
⬇️
infosec.pub/post/49724018

#CyberVeille #WordPress

##

cert_fr@social.numerique.gouv.fr at 2026-07-20T08:52:21.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-60137 et CVE-2026-63030 affectent WordPress et permettent une exécution de code arbitraire à distance non authentifiée.
Une preuve de concept est disponible.

cert.ssi.gouv.fr/alerte/CERTFR

##

offseq@infosec.exchange at 2026-07-20T04:30:24.000Z ##

wp2shell (CVE-2026-63030, CVE-2026-60137) allows unauth RCE in WordPress core (HIGH severity). Active exploitation reported. Patch to 6.9.5, 7.0.2, or 6.8.6. Block REST API batch endpoint if needed. Details: radar.offseq.com/threat/wp2she #OffSeq #WordPress #RCE #Vulnerability

##

_r_netsec@infosec.exchange at 2026-07-19T23:58:05.000Z ##

wp2shell: a defender’s guide (CVE-2026-63030 + CVE-2026-60137) with a list of forensic artifacts, a compromise scanner WordPress plugin and a free Chrome/Edge/Firefox browser extension to in-browser check if a website has been patched. research.eye.security/wp2shell

##

threatnoir@infosec.exchange at 2026-07-19T04:06:03.000Z ##

⚠️ CRITICAL: WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Critical unauthenticated RCE vulnerabilities in WordPress Core (CVE-2026-63030, CVE-2026-60137) are actively exploited via public PoCs. The wp2shell attack chains REST API and SQL injection flaws to achieve code execution on default installations of WordPress 6.9.x and 7.0.x. All affected WordPress…

threatnoir.com/focus

#infosec #cybersecurity

##

offseq@infosec.exchange at 2026-07-18T18:00:28.000Z ##

WordPress Core "wp2shell" CRITICAL RCE chain (CVE-2026-63030 & CVE-2026-60137) actively exploited. Affects 6.9.0 – 6.9.4 & 7.0.0 – 7.0.1. Public PoCs out. Patch to 6.9.5/7.0.2 ASAP. Block REST API endpoints as temp mitigation. radar.offseq.com/threat/wordpr #OffSeq #WordPress #RCE #Vuln

##

davidgerard@circumstances.run at 2026-07-18T16:17:54.000Z ##

Update your WordPress to 7.0.2/6.9.5, it's important

discourse.ifin.network/t/cve-2

ETA: the above text is not a call for CMS evangelists, just fucking don't thanks

##

secdb@infosec.exchange at 2026-07-18T15:42:16.000Z ##

🚨 wp2shell affects multiple vulnerabilities (CVE-2026-63030, CVE-2026-60137).

- CVE-2026-63030 (HIGH) - WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
- CVE-2026-60137 (CRITICAL) - WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query

Running WordPress? Check your versions and patch to 6.8.6 / 6.9.5 / 7.0.2. If you can't patch immediately, apply the mitigations in the meantime.

ℹ️ Additional information on ZEN SecDB
secdb.nttzen.cloud/updates/a5a

#infosec #wordpress #rce #sqlinjection #cve202663030 #cve202660137
#nttdata #zen #secdb #vulnerability_intelligence

##

thehackerwire@mastodon.social at 2026-07-18T15:01:19.000Z ##

🔴 CVE-2026-63030 - Critical (9.8)

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

pentesttools@infosec.exchange at 2026-07-18T13:34:36.000Z ##

#WordPress admins - we got you covered! 🫡 → We've just shipped detection for #wp2shell through our Network Scanner. ⚡️ The fastest way to use it is to:

◉ run a single-CVE scan for CVE-2026-63030 - which also covers CVE-2026-60137 - the SQL injection flaw that chains to give attackers RCE
◉ Based on your scan results, either patch or confirm you're already on 6.8.6, 6.9.5, or 7.0.2.
◉ Re-scan to confirm remediation and rule out residual exposure across your other assets.

Remember: updating your main install doesn't cover *every* WP instance you own. Using Pentest-Tools.com means you can expand visibility across your wider attack surface, not just the site you remember exists.

Technical CVE details below. ↘︎↘︎↘︎

See why an estimated 500+ million websites running WP are vulnerable to this critical vulnerability: pentest-tools.com/vulnerabilit

#vulnerabilityassessment #ethicalhacking #offensivesecurity

##

security_crawler_carl@infosec.exchange at 2026-07-18T13:05:54.000Z ##

🏆 New Achievement! wp2Shell We Have A Problem!

QUEST UPDATE — PREREQUISITE FAILED: "Have A Website That Isn't On Fire." WordPress Core carries CVE-2026-63030, a critical unauthenticated remote code execution flaw haunting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. No login required. No credentials to steal. The attacker just knocks and your site answers. A companion SQL injection, CVE-2026-60137, is also along for the ride, because one cursed artifact is never enough. (1/2)

##

obivan@infosec.exchange at 2026-07-18T10:46:00.000Z ##

wp2shell (CVE-2026-63030 + CVE-2026-60137): Independent Root Cause Analysis github.com/tcyph3r/wp2shell-cv

##

ottoto2017@prattohome.com at 2026-07-18T05:33:26.000Z ##

「WordPressコアに新たなwp2shellの脆弱性が発見され、認証されていない攻撃者がコードを実行できるようになった。 」: #TheHackerNews

「匿名HTTPリクエストによって、WordPressサイト上でコードを実行できる脆弱性が発見されました。このバグはコア部分に存在するため、プラグインを一切インストールしていない状態でも悪用可能です。WordPressが6.9.5と7.0.2をリリースし、自動更新システムによる強制更新機能を有効にした金曜日までは、6.9および7.0バージョンのすべてのサイトが影響を受けていました。

wp2shell は1つのバグではなく、2つのバグから成り立っており、どちらにもCVE IDが付与されています。CVE -2026-63030 はREST APIのバッチルーティングの混同に関する脆弱性、 CVE-2026-60137 はWordPressコアにおけるSQLインジェクションの脆弱性です。 」

thehackernews.com/2026/07/new-

#prattohome

##

CVE-2026-45162
(8.0 HIGH)

EPSS: 0.57%

updated 2026-07-18T00:16:48.007000

1 posts

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from database columns and filesystem files without the allowed_classes restriction, including lib/Tool/Authentication.php, models/Site/Dao.php, models/DataObject/ClassDefinition/CustomLayout/Dao.php, models/Tool/TmpStore/Dao.php, models/Ass

thehackerwire@mastodon.social at 2026-07-18T19:59:48.000Z ##

🟠 CVE-2026-45162 - High (8)

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from database columns and filesystem files without the allowed_classes restriction, inc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7667
(8.8 HIGH)

EPSS: 0.34%

updated 2026-07-17T21:31:53

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e.g., filename="../../../target/path" ), enabling arbitrary file write operations with attacker-controlled content to any path accessible by the Langflow process.

thehackerwire@mastodon.social at 2026-07-18T15:00:58.000Z ##

🟠 CVE-2026-7667 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e.g., filename="../../../target/path" ), enabling...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8481
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-07-17T21:31:53

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system comman

thehackerwire@mastodon.social at 2026-07-18T14:01:17.000Z ##

🔴 CVE-2026-8481 - Critical (9.9)

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's bu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7755
(8.8 HIGH)

EPSS: 0.41%

updated 2026-07-17T21:31:53

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files.

thehackerwire@mastodon.social at 2026-07-18T12:00:34.000Z ##

🟠 CVE-2026-7755 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8859
(9.9 CRITICAL)

EPSS: 0.34%

updated 2026-07-17T21:31:53

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" feature is enabled, where filenames extracted from HTTP response Content-Disposition headers are not sanitized before being joined to the temporary director

thehackerwire@mastodon.social at 2026-07-18T12:00:23.000Z ##

🔴 CVE-2026-8859 - Critical (9.9)

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" fea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14499
(8.8 HIGH)

EPSS: 0.43%

updated 2026-07-17T21:31:52

1 posts

IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.

thehackerwire@mastodon.social at 2026-07-18T18:59:52.000Z ##

🟠 CVE-2026-14499 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13448
(8.1 HIGH)

EPSS: 0.44%

updated 2026-07-17T21:31:52

1 posts

IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in the validate_public_flow_no_code_execution() function that fails to block several code-execution agent components including OpenDsStarAgent, CodeActAgen

thehackerwire@mastodon.social at 2026-07-18T18:00:50.000Z ##

🟠 CVE-2026-13448 - High (8.1)

IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15091
(9.3 CRITICAL)

EPSS: 0.57%

updated 2026-07-17T21:31:52

1 posts

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.

thehackerwire@mastodon.social at 2026-07-18T17:00:59.000Z ##

🔴 CVE-2026-15091 - Critical (9.3)

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8476
(9.9 CRITICAL)

EPSS: 0.47%

updated 2026-07-17T21:31:52

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validation, integrity verification, or authentication, enabling arbitrary code execution when malicious pickle payloads are processed. Attackers who can

thehackerwire@mastodon.social at 2026-07-18T14:01:07.000Z ##

🔴 CVE-2026-8476 - Critical (9.9)

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk withou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8056
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-17T21:31:52

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter filtering mechanism within the `apply_tweaks()` function.

thehackerwire@mastodon.social at 2026-07-18T14:00:57.000Z ##

🟠 CVE-2026-8056 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter filtering mechanism within the `apply_tweaks()` function.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13445
(8.1 HIGH)

EPSS: 0.20%

updated 2026-07-17T21:31:52

1 posts

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's workflow reads victim file contents, appends attacker-controlled data, and uploads a copy containing victim data to the attacker's namespace (c

thehackerwire@mastodon.social at 2026-07-18T09:00:32.000Z ##

🟠 CVE-2026-13445 - High (8.1)

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9103
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-07-17T21:31:52

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administr

thehackerwire@mastodon.social at 2026-07-17T20:00:13.000Z ##

🔴 CVE-2026-9103 - Critical (9.8)

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15322
(7.5 HIGH)

EPSS: 0.52%

updated 2026-07-17T21:31:44

1 posts

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs.

thehackerwire@mastodon.social at 2026-07-18T18:00:39.000Z ##

🟠 CVE-2026-15322 - High (7.5)

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52746
(7.5 HIGH)

EPSS: 0.68%

updated 2026-07-17T20:17:25.207000

1 posts

JSONata is a JSON query and transformation language. Prior to 2.2.0, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 validation regex, leading to denial of service in applications that evaluate user-provided JSONata expressions. This issue is fixed in version 2.2.0.

thehackerwire@mastodon.social at 2026-07-18T19:00:12.000Z ##

🟠 CVE-2026-52746 - High (7.5)

JSONata is a JSON query and transformation language. Prior to 2.2.0, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 validation regex, leading to denial of service in applications that eva...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45260
(8.1 HIGH)

EPSS: 0.43%

updated 2026-07-17T20:17:16.857000

1 posts

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Controller/WebDavController.php, and models/Asset/WebDAV/Tree.php performs asset mutation and deletion through models/Asset.php before checking a current Pi

thehackerwire@mastodon.social at 2026-07-18T17:00:49.000Z ##

🟠 CVE-2026-45260 - High (8.1)

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-20205
(4.8 MEDIUM)

EPSS: 0.31%

updated 2026-07-17T20:17:13.067000

1 posts

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.&nbsp; These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attac

AAKL@infosec.exchange at 2026-07-17T15:51:07.000Z ##

Broadcom has new advisories addressing two high-severity vulnerabilities that were fist published on the 15th support.broadcom.com/web/ecx/s

Cisco:

Medium Severity: CVE-2025-20204and CVE-2025-20205 Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities sec.cloudapps.cisco.com/securi @TalosSecurity

And if you missed this yesterday, CISA added two Fortinet vulnerabilities to the catalogue:

CISA:

CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

And a Microsoft vulnerability:

CISA: CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #CISA #Fortinet #infosec #vulnerability #Cisco #Broadcom

##

CVE-2026-63101
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-17T19:17:19.147000

1 posts

Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email addresses, names, join dates, and roles, by submitting requests to the group followers CSV export endpoint which lacks any authentication decorator. Attackers can enumerate sequential group IDs via brute-force, tri

thehackerwire@mastodon.social at 2026-07-19T08:00:21.000Z ##

🟠 CVE-2026-63101 - High (7.5)

Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email addresses, names, join dates, and roles, by submitting reques...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62227
(7.7 HIGH)

EPSS: 0.24%

updated 2026-07-17T19:17:18.390000

1 posts

OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach network destinations that should have been blocked.

thehackerwire@mastodon.social at 2026-07-19T16:00:00.000Z ##

🟠 CVE-2026-62227 - High (7.7)

OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach net...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-60357
(8.1 HIGH)

EPSS: 0.40%

updated 2026-07-17T18:47:13.683000

1 posts

AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.

1 repos

https://github.com/Nullbyte3117/CVE-2025-60357

thehackerwire@mastodon.social at 2026-07-19T12:00:15.000Z ##

🟠 CVE-2025-60357 - High (8.1)

AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-51080
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-07-17T18:47:13.683000

1 posts

libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.

thehackerwire@mastodon.social at 2026-07-19T11:00:14.000Z ##

🔴 CVE-2026-51080 - Critical (9.8)

libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44182
(0 None)

EPSS: 0.35%

updated 2026-07-17T18:35:23.877000

1 posts

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0, the server interpolates untrusted environment variables (e.g., KERNEL_XXX) into Kubernetes manifests without YAML-aware escaping, enabling YAML injection attacks. Attackers can inject new fields, overwrite critical fields (e.g.

offseq@infosec.exchange at 2026-07-17T04:30:25.000Z ##

CVE-2026-44182: CRITICAL YAML injection in jupyter-server enterprise_gateway <3.3.0 🚨 Untrusted env vars in manifests can let attackers create/modify Kubernetes resources, incl. privileged pods. Upgrade to 3.3.0+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202644182 #Kubernetes

##

CVE-2026-57860
(7.8 HIGH)

EPSS: 0.13%

updated 2026-07-17T18:31:35

1 posts

ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json file on startup without user confirmation. A malicious repository can supply a crafted .mcp.json whose mcpServers entries specify arbitrary command and args values (for example, command: bash with args: ['-c', 'touch /tmp/pwned']). When a user runs the

thehackerwire@mastodon.social at 2026-07-19T08:59:52.000Z ##

🟠 CVE-2026-57860 - High (7.8)

ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json file on startup without user confirmation. A malicious repository can supply a crafted .mcp.json who...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12694
(9.1 CRITICAL)

EPSS: 0.24%

updated 2026-07-17T18:31:34

1 posts

Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

thehackerwire@mastodon.social at 2026-07-19T10:00:42.000Z ##

🔴 CVE-2026-12694 - Critical (9.1)

Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8297
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-17T18:31:34

1 posts

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026.

thehackerwire@mastodon.social at 2026-07-19T08:00:32.000Z ##

🔴 CVE-2026-8297 - Critical (9.8)

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection.

This ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9198
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-07-17T18:31:34

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

thehackerwire@mastodon.social at 2026-07-18T19:59:58.000Z ##

🔴 CVE-2026-9198 - Critical (9.8)

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13410
(8.2 HIGH)

EPSS: 0.24%

updated 2026-07-17T18:17:14.283000

1 posts

Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be l

thehackerwire@mastodon.social at 2026-07-19T12:59:51.000Z ##

🟠 CVE-2026-13410 - High (8.2)

Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled.

The default user agent is initialised with SSL_verify_mode explicitly disabled.

An attacker with network man-in-the-middle (MITM) capability between the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12693
(9.4 CRITICAL)

EPSS: 0.26%

updated 2026-07-17T18:17:13.847000

1 posts

Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

thehackerwire@mastodon.social at 2026-07-19T10:00:31.000Z ##

🔴 CVE-2026-12693 - Critical (9.4)

Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12692
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-07-17T17:54:18.640000

1 posts

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

thehackerwire@mastodon.social at 2026-07-19T09:00:13.000Z ##

🔴 CVE-2026-12692 - Critical (9.8)

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass.

This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12691
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-17T17:54:18.640000

1 posts

Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

thehackerwire@mastodon.social at 2026-07-19T09:00:02.000Z ##

🟠 CVE-2026-12691 - High (7.5)

Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass.

This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62234
(8.1 HIGH)

EPSS: 0.30%

updated 2026-07-17T15:44:29.553000

1 posts

Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local files, access process information, or pivot to internal services via unrestricted protocol handlers.

thehackerwire@mastodon.social at 2026-07-19T14:59:51.000Z ##

🟠 CVE-2026-62234 - High (8.1)

Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11961
(8.1 HIGH)

EPSS: 0.23%

updated 2026-07-17T15:44:29.553000

2 posts

The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role — up to administrator when such a tier exis

thehackerwire@mastodon.social at 2026-07-19T13:59:52.000Z ##

🟠 CVE-2026-11961 - High (8.1)

The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user rol...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-17T09:00:29.000Z ##

CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026

##

CVE-2026-62232
(7.4 HIGH)

EPSS: 0.28%

updated 2026-07-17T15:44:29.553000

1 posts

Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOTP challenge window. Attackers who know the victim's password can call this task without a CSRF nonce to overwrite the 2FA secret with an attacker-chosen value, compute a valid TOTP code, and complete

offseq@infosec.exchange at 2026-07-17T03:00:30.000Z ##

CVE-2026-62232 (CRITICAL): getgrav Grav <2.0.4 has a 2FA bypass flaw — attackers knowing a user's password can overwrite the 2FA secret, reducing protection to password-only. Monitor & restrict access. Patch status pending. radar.offseq.com/threat/cve-20 #OffSeq #CVE202662232 #2FA #infosec

##

CVE-2026-11575
(7.5 HIGH)

EPSS: 0.21%

updated 2026-07-17T15:33:32

1 posts

The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces to an unkeyed hash of the request body that anyone can compute. This allows unauthenticated attackers to forge a payment-

thehackerwire@mastodon.social at 2026-07-19T13:00:13.000Z ##

🟠 CVE-2026-11575 - High (7.5)

The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7488
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-17T15:32:37

1 posts

Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026.

thehackerwire@mastodon.social at 2026-07-19T11:00:03.000Z ##

🟠 CVE-2026-7488 - High (7.5)

Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data.

This issue affects E-Commerce: through 03062026.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63094
(8.1 HIGH)

EPSS: 0.17%

updated 2026-07-17T15:32:37

1 posts

SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a

thehackerwire@mastodon.social at 2026-07-19T10:59:53.000Z ##

🟠 CVE-2026-63094 - High (8.1)

SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63093
(8.8 HIGH)

EPSS: 0.43%

updated 2026-07-17T15:32:37

1 posts

Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without

thehackerwire@mastodon.social at 2026-07-19T10:00:51.000Z ##

🟠 CVE-2026-63093 - High (8.8)

Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7189
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-17T15:32:29

1 posts

Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Proliz's OBS: before v3.6.0.

thehackerwire@mastodon.social at 2026-07-19T12:00:26.000Z ##

🟠 CVE-2026-7189 - High (7.5)

Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Proliz's OBS: before v3.6.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9810
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-07-17T15:32:28

1 posts

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.

thehackerwire@mastodon.social at 2026-07-19T13:00:01.000Z ##

🔴 CVE-2026-9810 - Critical (9.8)

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileg...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8396
(7.5 HIGH)

EPSS: 0.26%

updated 2026-07-17T15:00:17.017000

1 posts

Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This issue affects NetGIS: from 5.0.66 before 7.2.2.

thehackerwire@mastodon.social at 2026-07-19T12:00:42.000Z ##

🟠 CVE-2026-8396 - High (7.5)

Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking.

This issue affects NetGIS: from 5.0.66 before 7.2.2.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13352
(8.8 HIGH)

EPSS: 0.57%

updated 2026-07-17T06:31:06

1 posts

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the

thehackerwire@mastodon.social at 2026-07-19T14:00:15.000Z ##

🟠 CVE-2026-13352 - High (8.8)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13765
(7.5 HIGH)

EPSS: 0.39%

updated 2026-07-17T06:31:06

1 posts

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists, explanations, and question content for any quiz question on the site — including

thehackerwire@mastodon.social at 2026-07-19T14:00:02.000Z ##

🟠 CVE-2026-13765 - High (7.5)

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15982
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-07-17T06:31:06

2 posts

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear funct

thehackerwire@mastodon.social at 2026-07-17T09:59:48.000Z ##

🔴 CVE-2026-15982 - Critical (9.8)

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-17T06:00:27.000Z ##

CVE-2026-15982 | CodeRevolution Aimogen Pro (≤2.8.4) has a CRITICAL privilege escalation flaw — attackers can leverage missing capability checks to create admin accounts. Urgent patching advised. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #Infosec

##

CVE-2026-50454
(7.8 HIGH)

EPSS: 0.40%

updated 2026-07-17T05:16:39.690000

1 posts

Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

_r_netsec@infosec.exchange at 2026-07-17T13:28:05.000Z ##

Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454 davidcarliez.github.io/blog/wi

##

CVE-2026-25089
(9.8 CRITICAL)

EPSS: 36.13%

updated 2026-07-17T05:16:38.687000

3 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP req

2 repos

https://github.com/HORKimhab/CVE-2026-25089

https://github.com/0xBlackash/CVE-2026-25089

thecybermind at 2026-07-20T16:30:01.174Z ##

⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. thecybermind.co/mxq2

##

thecybermind@infosec.exchange at 2026-07-20T16:30:01.000Z ##

⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. thecybermind.co/mxq2

#CyberSecurity #InfoSec #Fortinet #ThreatIntel #CVE2026

##

AAKL@infosec.exchange at 2026-07-17T15:51:07.000Z ##

Broadcom has new advisories addressing two high-severity vulnerabilities that were fist published on the 15th support.broadcom.com/web/ecx/s

Cisco:

Medium Severity: CVE-2025-20204and CVE-2025-20205 Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities sec.cloudapps.cisco.com/securi @TalosSecurity

And if you missed this yesterday, CISA added two Fortinet vulnerabilities to the catalogue:

CISA:

CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

And a Microsoft vulnerability:

CISA: CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #CISA #Fortinet #infosec #vulnerability #Cisco #Broadcom

##

CVE-2026-62386
(7.5 HIGH)

EPSS: 0.27%

updated 2026-07-17T03:31:30

1 posts

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are logged verbatim in web server access logs, leaked via the Referer header, stored in browser history, and captured by upstream proxy and CDN logs, exposing

thehackerwire@mastodon.social at 2026-07-19T15:00:12.000Z ##

🟠 CVE-2026-62386 - High (7.5)

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are lo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62241
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-07-17T03:31:30

1 posts

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId values without authentication, a remote unauthenticated attacker can harvest a victim's userId, forge a valid HS256 cg_session cookie offline using the known

thehackerwire@mastodon.social at 2026-07-19T15:00:01.000Z ##

🔴 CVE-2026-62241 - Critical (9.1)

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId value...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62228
(8.8 HIGH)

EPSS: 0.26%

updated 2026-07-17T03:31:24

1 posts

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can exploit mismatched environment configurations to persist or execute actions that exceed the caller's approved permissions.

thehackerwire@mastodon.social at 2026-07-19T16:00:11.000Z ##

🟠 CVE-2026-62228 - High (8.8)

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53412
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-07-17T00:32:18

4 posts

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.

hackmag at 2026-07-20T16:30:09.613Z ##

⚪️ Zoom for Windows patched a critical vulnerability

🗨️ Zoom’s developers have released updates for their Windows clients and SDK that address the critical vulnerability CVE-2026-53412. The bug allowed an unauthenticated attacker to remotely take over a victim’s account and received a CVSS score of 9.8. The issue was…

🔗 hackmag.com/news/zoom-patch?ut

##

hackmag@infosec.exchange at 2026-07-20T16:30:09.000Z ##

⚪️ Zoom for Windows patched a critical vulnerability

🗨️ Zoom’s developers have released updates for their Windows clients and SDK that address the critical vulnerability CVE-2026-53412. The bug allowed an unauthenticated attacker to remotely take over a victim’s account and received a CVSS score of 9.8. The issue was…

🔗 hackmag.com/news/zoom-patch?ut

#news

##

DailyCyberSecurity@infosec.exchange at 2026-07-17T08:01:37.000Z ##

A Zoom critical vulnerability (CVE-2026-53412, CVSS 9.8) lets attackers hijack accounts on Windows with no user interaction. Update your client now.

#Zoom #CVE202653412 #Vulnerability #CyberSecurity #Windows #AccountTakeover

securityexpress.info/cve-2026-

##

oversecurity@mastodon.social at 2026-07-17T06:50:27.000Z ##

Zoom Patches Critical Windows Flaw Enabling Account Takeover

Zoom has released security updates to fix CVE-2026-53412, a critical Improper Input Validation vulnerability affecting its Windows software, which...

🔗️ [Thecyberexpress] link.is.it/17cS6R

##

CVE-2026-39808
(9.8 CRITICAL)

EPSS: 84.16%

updated 2026-07-16T18:32:24

3 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Nuclei template

6 repos

https://github.com/samu-delucas/CVE-2026-39808

https://github.com/0xBlackash/CVE-2026-39808

https://github.com/HORKimhab/CVE-2026-39808

https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808

https://github.com/Lechansky/CVE-2026-39808

https://github.com/error-inside/CVE-2026-39808

thecybermind at 2026-07-20T12:36:57.046Z ##

⚠️ CRITICAL THREAT: CVE-2026-39808 in Fortinet FortiSandbox is being actively exploited. Attackers are leveraging OS command injection for remote code execution. Is your SOC ready? Get the forensic detection queries and hardening playbooks to lock down your perimeter. thecybermind.co/v66d

##

thecybermind@infosec.exchange at 2026-07-20T12:36:57.000Z ##

⚠️ CRITICAL THREAT: CVE-2026-39808 in Fortinet FortiSandbox is being actively exploited. Attackers are leveraging OS command injection for remote code execution. Is your SOC ready? Get the forensic detection queries and hardening playbooks to lock down your perimeter. thecybermind.co/v66d

#CyberSecurity #InfoSec #Fortinet

##

AAKL@infosec.exchange at 2026-07-17T15:51:07.000Z ##

Broadcom has new advisories addressing two high-severity vulnerabilities that were fist published on the 15th support.broadcom.com/web/ecx/s

Cisco:

Medium Severity: CVE-2025-20204and CVE-2025-20205 Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities sec.cloudapps.cisco.com/securi @TalosSecurity

And if you missed this yesterday, CISA added two Fortinet vulnerabilities to the catalogue:

CISA:

CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

And a Microsoft vulnerability:

CISA: CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #CISA #Fortinet #infosec #vulnerability #Cisco #Broadcom

##

CVE-2026-58644
(9.8 CRITICAL)

EPSS: 1.47%

updated 2026-07-16T18:31:26

8 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

thecybermind at 2026-07-20T11:36:18.206Z ##

⚠️ CRITICAL THREAT: CVE-2026-58644 targets Microsoft SharePoint via deserialization. Active exploitation is verified. Is your perimeter secured? Get the forensic detection queries and hardening playbooks you need to defend your infrastructure now. thecybermind.co/9pxn

##

youranonnewsirc@nerdculture.de at 2026-07-20T10:26:28.000Z ##

Geopolitical: US forces launched new airstrikes against Iran following military deaths in Jordan; shipping in the Strait of Hormuz is disrupted after a cargo ship attack.

Technology: The EU ordered Google to open Android to rival AI assistants and share search data. Cvent announced a $1 billion investment in AI for event management.

Cybersecurity: A critical Microsoft SharePoint Server RCE zero-day (CVE-2026-58644) is being actively exploited. A federal audit revealed significant gaps in US aviation cybersecurity oversight.

#AnonNews_irc #Cybersecurity #Technology

##

thecybermind@infosec.exchange at 2026-07-20T11:36:18.000Z ##

⚠️ CRITICAL THREAT: CVE-2026-58644 targets Microsoft SharePoint via deserialization. Active exploitation is verified. Is your perimeter secured? Get the forensic detection queries and hardening playbooks you need to defend your infrastructure now. thecybermind.co/9pxn

#CyberSecurity #InfoSec #SharePoint #CVE2026

##

youranonnewsirc@nerdculture.de at 2026-07-20T10:26:28.000Z ##

Geopolitical: US forces launched new airstrikes against Iran following military deaths in Jordan; shipping in the Strait of Hormuz is disrupted after a cargo ship attack.

Technology: The EU ordered Google to open Android to rival AI assistants and share search data. Cvent announced a $1 billion investment in AI for event management.

Cybersecurity: A critical Microsoft SharePoint Server RCE zero-day (CVE-2026-58644) is being actively exploited. A federal audit revealed significant gaps in US aviation cybersecurity oversight.

#AnonNews_irc #Cybersecurity #Technology

##

threatnoir@infosec.exchange at 2026-07-19T05:05:38.000Z ##

⚠️ CRITICAL: Fresh SharePoint Vulnerability Exploited Soon After Disclosure

Microsoft SharePoint RCE vulnerability CVE-2026-58644 (CVSS 9.8) is actively exploited in the wild following July 2026 Patch Tuesday disclosure. Authenticated attackers with Site Owner privileges can execute arbitrary code via deserialization flaws. All organizations running affected SharePoint ver…

threatnoir.com/focus

#infosec #cybersecurity

##

youranonnewsirc@nerdculture.de at 2026-07-18T04:26:09.000Z ##

Latest 24-hour summary:

Geopolitical: US strikes Iran for a sixth night, escalating conflict and impacting the Strait of Hormuz.
Technology: IBM unveils a sub-1nm chip, Japan achieves 6G, and AI chip demand surges amidst a deepening tech selloff.
Cybersecurity: CISA warns of an actively exploited SharePoint RCE zero-day (CVE-2026-58644), urging immediate patching. New BL4CK SP1D3R ransomware threats are also detected.

#AnonNews_irc #Cybersecurity #News

##

AAKL@infosec.exchange at 2026-07-17T15:51:07.000Z ##

Broadcom has new advisories addressing two high-severity vulnerabilities that were fist published on the 15th support.broadcom.com/web/ecx/s

Cisco:

Medium Severity: CVE-2025-20204and CVE-2025-20205 Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities sec.cloudapps.cisco.com/securi @TalosSecurity

And if you missed this yesterday, CISA added two Fortinet vulnerabilities to the catalogue:

CISA:

CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

And a Microsoft vulnerability:

CISA: CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #CISA #Fortinet #infosec #vulnerability #Cisco #Broadcom

##

offseq@infosec.exchange at 2026-07-17T07:30:26.000Z ##

CVE-2026-58644: CRITICAL RCE in Microsoft SharePoint enables remote, authenticated Site Owners to execute code via deserialization. Exploited in the wild — patch now (July 2026 updates). Details: radar.offseq.com/threat/fresh- #OffSeq #SharePoint #Vuln #KEV #Infosec

##

CVE-2026-11386
(9.0 CRITICAL)

EPSS: 0.32%

updated 2026-07-16T14:16:48.040000

1 posts

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.for

DailyCyberSecurity@infosec.exchange at 2026-07-18T08:31:41.000Z ##

Ubuntu Pro Client vulnerability CVE-2026-11386 (CVSS 9.0) lets a spoofed contract server inject APT sources and run code with root privileges.

#Ubuntu #UbuntuPro #CVE202611386 #Canonical #RCE #Linux #CyberSecurity

securityonline.info/ubuntu-pro

##

CVE-2026-15410
(7.2 HIGH)

EPSS: 1.49%

updated 2026-07-16T05:16:18.470000

2 posts

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

3 repos

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/HORKimhab/CVE-2026-15410

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

netsecio@mastodon.social at 2026-07-20T17:17:48.000Z ##

📰 SonicWall Warns of Two Zero-Days in SMA 1000 Under Active Exploit

SonicWall urges immediate patching for two actively exploited zero-days (CVE-2026-15409, CVE-2026-15410) in SMA 1000 series appliances. Flaws are chained for unauthenticated RCE. Both added to CISA KEV. #ZeroDay #SonicWall #InfoSec

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/so

##

threatnoir@infosec.exchange at 2026-07-17T03:06:03.000Z ##

⚠️ CRITICAL: Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

Two zero-day vulnerabilities in SonicWall SMA 1000 appliances are actively exploited in the wild. CVE-2026-15409 is an SSRF flaw, while CVE-2026-15410 allows unauthenticated attackers to execute arbitrary commands as admin. Organizations using these devices face immediate risk of full appliance com…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-15409
(10.0 CRITICAL)

EPSS: 1.27%

updated 2026-07-16T05:16:18.293000

4 posts

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

5 repos

https://github.com/0xBlackash/CVE-2026-15409

https://github.com/remmons-r7/rapid7-CVE-2026-15409

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/HORKimhab/CVE-2026-15409

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

netsecio@mastodon.social at 2026-07-20T17:17:48.000Z ##

📰 SonicWall Warns of Two Zero-Days in SMA 1000 Under Active Exploit

SonicWall urges immediate patching for two actively exploited zero-days (CVE-2026-15409, CVE-2026-15410) in SMA 1000 series appliances. Flaws are chained for unauthenticated RCE. Both added to CISA KEV. #ZeroDay #SonicWall #InfoSec

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/so

##

bsi@social.bund.de at 2026-07-20T14:31:24.000Z ##

RE: social.bund.de/@bsi/1169235087

Update: Das IT-Sicherheitsunternehmen Rapid7 hat weitere Details zu den #Schwachstellen und beobachteten Angriffen auf SMA1000 Appliances veröffentlicht.

Neben den technischen Details wurde auch ein Proof-of-Concept Exploit veröffentlicht, welches die Schwachstelle CVE-2026-15409 ausnutzt, um ohne Authentifizierung Code auf verwundbaren SMA1000 Appliances auszuführen. Eine Ausnutzung durch weitere Akteure ist durch das öffentliche Proof-of-Concept wahrscheinlich.

👉 bsi.bund.de/dok/1203248

##

bsi@social.bund.de at 2026-07-20T14:31:24.000Z ##

RE: social.bund.de/@bsi/1169235087

Update: Das IT-Sicherheitsunternehmen Rapid7 hat weitere Details zu den #Schwachstellen und beobachteten Angriffen auf SMA1000 Appliances veröffentlicht.

Neben den technischen Details wurde auch ein Proof-of-Concept Exploit veröffentlicht, welches die Schwachstelle CVE-2026-15409 ausnutzt, um ohne Authentifizierung Code auf verwundbaren SMA1000 Appliances auszuführen. Eine Ausnutzung durch weitere Akteure ist durch das öffentliche Proof-of-Concept wahrscheinlich.

👉 bsi.bund.de/dok/1203248

##

threatnoir@infosec.exchange at 2026-07-17T03:06:03.000Z ##

⚠️ CRITICAL: Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

Two zero-day vulnerabilities in SonicWall SMA 1000 appliances are actively exploited in the wild. CVE-2026-15409 is an SSRF flaw, while CVE-2026-15410 allows unauthenticated attackers to execute arbitrary commands as admin. Organizations using these devices face immediate risk of full appliance com…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-50274
(7.5 HIGH)

EPSS: 0.79%

updated 2026-07-15T23:05:20

1 posts

### Impact Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing item-count or byte-size limits on the extract path. The DD_TRACE_BAGGAGE_MAX_ITEMS (default 64) and DD_TRACE_BAGGAGE_MAX_BYTES (default 8192) limits were applied only to baggage injection, not extraction. A remote, unauthenticated attacker can send a request whose bagga

thehackerwire@mastodon.social at 2026-07-18T05:01:18.000Z ##

🟠 CVE-2026-50274 - High (7.5)

Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50273
(7.5 HIGH)

EPSS: 0.79%

updated 2026-07-15T22:59:30

1 posts

### Impact Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing item-count or byte-size limits on the extract path. The DD_TRACE_BAGGAGE_MAX_ITEMS (default 64) and DD_TRACE_BAGGAGE_MAX_BYTES (default 8192) limits were applied only to baggage injection, not extraction. A remote, unauthenticated attacker can send a request whose bagga

thehackerwire@mastodon.social at 2026-07-19T07:00:13.000Z ##

🟠 CVE-2026-50273 - High (7.5)

Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50272
(7.5 HIGH)

EPSS: 0.79%

updated 2026-07-15T22:58:53

1 posts

### Impact Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing item-count or byte-size limits on the extract path. The DD_TRACE_BAGGAGE_MAX_ITEMS (default 64) and DD_TRACE_BAGGAGE_MAX_BYTES (default 8192) limits were applied only to baggage injection, not extraction. A remote, unauthenticated attacker can send a request whose bagga

thehackerwire@mastodon.social at 2026-07-18T05:01:08.000Z ##

🟠 CVE-2026-50272 - High (7.5)

dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/text_map.js parsed incoming baggage HTTP headers without enforcing DD_T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50271
(7.5 HIGH)

EPSS: 0.79%

updated 2026-07-15T22:55:25

1 posts

### Impact Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing item-count or byte-size limits on the extract path. The DD_TRACE_BAGGAGE_MAX_ITEMS (default 64) and DD_TRACE_BAGGAGE_MAX_BYTES (default 8192) limits were applied only to baggage injection, not extraction. A remote, unauthenticated attacker can send a request whose bagga

thehackerwire@mastodon.social at 2026-07-17T22:00:49.000Z ##

🟠 CVE-2026-50271 - High (7.5)

Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48332
(7.7 HIGH)

EPSS: 11.94%

updated 2026-07-15T18:39:42.690000

1 posts

ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-46817
(9.8 CRITICAL)

EPSS: 1.04%

updated 2026-07-15T18:32:50

1 posts

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Con

2 repos

https://github.com/HORKimhab/CVE-2026-46817

https://github.com/0xBlackash/CVE-2026-46817

thecybermind@infosec.exchange at 2026-07-19T07:34:06.000Z ##

Critical Alert: CVE-2026-46817 is being actively exploited against Oracle E-Business Suite. An unauthenticated attacker can achieve full takeover of the Payments module via HTTP. Get the forensic detection queries and hardening protocols in our latest TSUITE brief. Protect the perimeter. thecybermind.co/g325

##

CVE-2026-47999
(4.8 MEDIUM)

EPSS: 7.08%

updated 2026-07-15T18:16:46.193000

1 posts

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-48284
(9.6 CRITICAL)

EPSS: 7.94%

updated 2026-07-15T18:00:17.600000

1 posts

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-53565
(0 None)

EPSS: 0.10%

updated 2026-07-15T16:23:57.437000

1 posts

Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7.

DailyCyberSecurity@infosec.exchange at 2026-07-17T13:02:49.000Z ##

Citrix patched CVE-2026-53565, a Citrix Secure Access vulnerability letting local users gain SYSTEM, plus the CVE-2026-53566 out-of-bounds read bug.

#Citrix #CVE202653565 #PrivilegeEscalation #Vulnerability #Windows

securityonline.info/citrix-sec

##

CVE-2026-53566
(0 None)

EPSS: 0.11%

updated 2026-07-15T16:23:57.437000

1 posts

Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.

DailyCyberSecurity@infosec.exchange at 2026-07-17T13:02:49.000Z ##

Citrix patched CVE-2026-53565, a Citrix Secure Access vulnerability letting local users gain SYSTEM, plus the CVE-2026-53566 out-of-bounds read bug.

#Citrix #CVE202653565 #PrivilegeEscalation #Vulnerability #Windows

securityonline.info/citrix-sec

##

CVE-2026-42533
(8.1 HIGH)

EPSS: 0.83%

updated 2026-07-15T15:33:14

10 posts

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyon

3 repos

https://github.com/Daniyal48/ghostlock-vagrant-box

https://github.com/srkyn/nginx-map-risk-audit

https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner

autobrain@arram.senta-la.cloud at 2026-07-20T16:18:13.000Z ##

Postei no BR-Linux to avisando, e é sobre hora do upgrade.

FALHA CRÍTICA NO NGINX PODE TIRAR O SERVIDOR DO AR E ESTÁ NO CÓDIGO HÁ 15 ANOS

A vulnerabilidade CVE-2026-42533 no NGINX pode permitir que um invasor remoto e não autenticado sobrecarregue um buffer, levando a uma negação de serviço (DoS) e, teoricamente, à possibilidade de execução remota de código.

br-linux.org/2026/01/falha-cri

##

benzogaga33@mamot.fr at 2026-07-20T15:40:03.000Z ##

NGINX – CVE-2026-42533 : cette faille peut faire planter votre serveur Web it-connect.fr/nginx-cve-2026-4 #ActuCybersécurité #Cybersécurité #Vulnérabilité #Nginx #Web

##

threatcodex at 2026-07-20T12:58:42.372Z ##

CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers

securityaffairs.com/195674/hac

##

security_crawler_carl at 2026-07-20T09:31:03.193Z ##

🏆 New Achievement! Two Passes, One Coffin!

We are gathered here today to mourn nginx's worker process, which died as it lived: faithfully measuring a buffer in one pass, then obediently writing something much larger into it on the next. CVE-2026-42533 is a heap buffer overflow triggered by crafted HTTP requests against a specific regex map configuration — no authentication required. The worker crashes. (1/3)

##

autobrain@arram.senta-la.cloud at 2026-07-20T16:18:13.000Z ##

Postei no BR-Linux to avisando, e é sobre hora do upgrade.

FALHA CRÍTICA NO NGINX PODE TIRAR O SERVIDOR DO AR E ESTÁ NO CÓDIGO HÁ 15 ANOS

A vulnerabilidade CVE-2026-42533 no NGINX pode permitir que um invasor remoto e não autenticado sobrecarregue um buffer, levando a uma negação de serviço (DoS) e, teoricamente, à possibilidade de execução remota de código.

br-linux.org/2026/01/falha-cri

##

benzogaga33@mamot.fr at 2026-07-20T15:40:03.000Z ##

NGINX – CVE-2026-42533 : cette faille peut faire planter votre serveur Web it-connect.fr/nginx-cve-2026-4 #ActuCybersécurité #Cybersécurité #Vulnérabilité #Nginx #Web

##

threatcodex@infosec.exchange at 2026-07-20T12:58:42.000Z ##

CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers
#CVE_2026_42533
securityaffairs.com/195674/hac

##

security_crawler_carl@infosec.exchange at 2026-07-20T09:31:03.000Z ##

🏆 New Achievement! Two Passes, One Coffin!

We are gathered here today to mourn nginx's worker process, which died as it lived: faithfully measuring a buffer in one pass, then obediently writing something much larger into it on the next. CVE-2026-42533 is a heap buffer overflow triggered by crafted HTTP requests against a specific regex map configuration — no authentication required. The worker crashes. (1/3)

##

oversecurity@mastodon.social at 2026-07-20T07:01:23.000Z ##

CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw

A newly disclosed security flaw, CVE-2026-42533, has revealed a critical Pre-Auth nginx vulnerability that could allow attackers to achieve...

🔗️ [Thecyberexpress] link.is.it/pvxhto

##

guru@thecybersecguru.com at 2026-07-20T06:35:51.000Z ##

15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and May Enable Remote Code Execution

NGINX has long been regarded as one of the most reliable and high-performance web servers on the Internet, powering millions of websites, APIs, reverse proxies, Kubernetes ingress controllers, and cloud-native applications. That reputation makes the disclosure of CVE-2026-42533 particularly significant. Rather than affecting a recently introduced feature, the flaw traces back to March 2011, when regular expression support was added to the map directive. For over 15 years, a subtle bug inside […]

thecybersecguru.com/news/cve-2

##

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 20.35%

updated 2026-07-15T15:12:34.507000

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-47996
(7.6 HIGH)

EPSS: 18.03%

updated 2026-07-15T14:31:11.823000

1 posts

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-50518
(9.8 CRITICAL)

EPSS: 7.36%

updated 2026-07-15T11:16:32.137000

1 posts

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-9770(CVSS UNKNOWN)

EPSS: 0.22%

updated 2026-07-15T03:33:02

2 posts

Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An attacker with access to the firmware image can extract the embedded key.  Successful exploitation may allow an unauthenticated attacker on the same network to use this key in the web management service, compromising the confidentiality of encry

DailyCyberSecurity@infosec.exchange at 2026-07-20T05:40:17.000Z ##

A TP-Link Kasa vulnerability (CVE-2026-9770) lets local attackers steal admin credentials via a hardcoded key. Patch your EC70 and EC71 firmware now.

#TPLink #Kasa #CVE20269770 #IoTSecurity #Cameras #ManInTheMiddle

meterpreter.org/tp-link-kasa-v

##

DailyCyberSecurity@infosec.exchange at 2026-07-17T01:53:09.000Z ##

TP-Link Kasa vulnerability CVE-2026-9770 (CVSS 8.6) lets local attackers intercept admin credentials on EC70 and EC71 cameras. Update firmware now.

#TPLink #Kasa #IoTSecurity #CVE20269770 #InfoDisclosure

securityonline.info/tp-link-ka

##

CVE-2025-3248
(9.8 CRITICAL)

EPSS: 99.99%

updated 2026-07-14T23:17:27.010000

2 posts

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

Nuclei template

28 repos

https://github.com/verylazytech/CVE-2025-3248

https://github.com/get-xor/coreweave-demo-2026-05

https://github.com/Kiraly07/Demo_CVE-2025-3248

https://github.com/0xgh057r3c0n/CVE-2025-3248

https://github.com/dennisec/CVE-2025-3248

https://github.com/r0otk3r/CVE-2025-3248

https://github.com/b0ySie7e/CVE-2025-3248-POC

https://github.com/12-test-12/CVE-2025-3248

https://github.com/tiemio/RCE-CVE-2025-3248

https://github.com/Vip3rLi0n/CVE-2025-3248

https://github.com/min8282/CVE-2025-3248

https://github.com/nebari-playground/langflow-cve-2025-3248

https://github.com/Atomics-hub/exposecheck

https://github.com/imbas007/CVE-2025-3248

https://github.com/wand3rlust/CVE-2025-3248

https://github.com/drackyjr/cve-2025-3248-exploit

https://github.com/PuddinCat/CVE-2025-3248-POC

https://github.com/Praison001/CVE-2025-3248

https://github.com/EQSTLab/CVE-2025-3248

https://github.com/vigilante-1337/CVE-2025-3248

https://github.com/peiqiF4ck/WebFrameworkTools-5.5-enhance

https://github.com/xuemian168/CVE-2025-3248

https://github.com/ill-deed/Langflow-CVE-2025-3248-Multi-target

https://github.com/dennisec/Mass-CVE-2025-3248

https://github.com/bambooqj/cve-2025-3248

https://github.com/0-d3y/langflow-rce-exploit

https://github.com/zapstiko/CVE-2025-3248

https://github.com/ynsmroztas/CVE-2025-3248-Langflow-RCE

Analyst207@mastodon.social at 2026-07-20T15:07:40.000Z ##

JadePuffer Unleashes AI-Targeted Ransomware with Data Wiping Capabilities

In a chilling display of cyber sophistication, JadePuffer unleashed a devastating ransomware attack that not only locked up data but also boasted data-wiping capabilities, leaving a trail of destruction in its wake. The attackers cleverly exploited a vulnerability, CVE-2025-3248, to gain and expand access, executing a complex…

osintsights.com/jadepuffer-unl

#Langflow #Ransomware #Cve20253248 #AitargetedRansomware #DataWiping

##

relayshieldadmin@infosec.exchange at 2026-07-17T19:41:04.000Z ##

New from RelayShield: four #AIsecurity checks for agents built with smolagents, published as an MCP server on @huggingface.

- MCP server reputation check before your agent connects
- Prompt-injection pattern detection on ingested content
- Tech-stack CVE monitoring (covers agent frameworks themselves — Langflow's CVE-2025-3248 was the initial-access vector in the first documented autonomous-agent ransomware op)
- Bulk identity-risk scoring

Self-serve, pay-per-call, no subscription.

huggingface.co/blog/relayshiel

#InfoSec #MCP #AgentSecurity #ThreatIntel

##

CVE-2026-56155
(7.8 HIGH)

EPSS: 0.38%

updated 2026-07-14T21:32:52

1 posts

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

thecybermind@infosec.exchange at 2026-07-17T15:05:01.000Z ##

Active exploitation of CVE-2026-56155 in Microsoft ADFS puts your identity perimeter at risk. Our latest TSUITE brief delivers the forensic indicators, detection queries, and compensating controls needed to neutralize this privilege escalation threat. Secure your architecture today. thecybermind.co/al3f

##

CVE-2026-56164
(5.3 MEDIUM)

EPSS: 5.60%

updated 2026-07-14T21:32:51

1 posts

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

1 repos

https://github.com/sentinel-aidefense/CVE-2026-56164-EXP

AAKL@infosec.exchange at 2026-07-17T16:32:43.000Z ##

Symantec, posted yesterday: Spirals: New Stealthy Ransomware Deployed Against Asian IT Company security.com/threat-intelligen

Also from yesterday:

Tenable: CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities tenable.com/blog/cve-2026-3220 #threatresearch #Microsoft #ransomware #infosec #SharePoint

##

CVE-2026-48320
(8.5 HIGH)

EPSS: 9.36%

updated 2026-07-14T21:32:33

1 posts

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-48356
(9.6 CRITICAL)

EPSS: 17.90%

updated 2026-07-14T21:32:27

1 posts

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interac

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-47992
(7.2 HIGH)

EPSS: 19.92%

updated 2026-07-14T21:32:23

1 posts

Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploi

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-13001
(9.8 CRITICAL)

EPSS: 1.08%

updated 2026-07-14T21:16:40.860000

2 posts

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

2 repos

https://github.com/Raimu0x19/CVE-2026-13001

https://github.com/shinthink/CVE-2026-13001

isf@muenchen.social at 2026-07-20T12:13:19.000Z ##

@343max
Wordpress und Podcast und Podlove, da klingelt bei mir was.
Und dann fehlen plötzlich Berechtigungen, die ja vermutl. zuvor korrekt waren, wenn es schon mal funktioniert hatte.
Schau Dir unbedingt das hier an, falls noch nicht geschehen. Das grassiert gerade aktiv und umfangreich und wäre durchaus schwerwiegend:
cve.org/CVERecord?id=CVE-2026-

##

isf@muenchen.social at 2026-07-20T12:13:19.000Z ##

@343max
Wordpress und Podcast und Podlove, da klingelt bei mir was.
Und dann fehlen plötzlich Berechtigungen, die ja vermutl. zuvor korrekt waren, wenn es schon mal funktioniert hatte.
Schau Dir unbedingt das hier an, falls noch nicht geschehen. Das grassiert gerade aktiv und umfangreich und wäre durchaus schwerwiegend:
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-44891
(7.5 HIGH)

EPSS: 0.69%

updated 2026-07-14T20:16:37

1 posts

### Summary The StompSubframeDecoder fails to limit the total number of headers or their cumulative size per frame, allowing an attacker to cause an OutOfMemoryError, leading to a Denial of Service. ### Details `io.netty.handler.codec.stomp.StompSubframeDecoder` implements the STOMP protocol. The `maxLineLength` parameter restricts the length of individual header lines, but there is no mechanism

thehackerwire@mastodon.social at 2026-07-18T09:00:09.000Z ##

🟠 CVE-2026-44891 - High (7.5)

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative siz...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58319
(9.1 CRITICAL)

EPSS: 0.61%

updated 2026-07-14T16:56:51.260000

2 posts

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service. This issue affects Apache Doris versions prior to 3.1.0. U

CVE-2026-56451
(10.0 CRITICAL)

EPSS: 0.38%

updated 2026-07-14T12:31:16

2 posts

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to th

DailyCyberSecurity at 2026-07-20T12:54:39.909Z ##

Siemens Opcenter X authentication bypass (CVE-2026-56451, CVSS 10) lets attackers forge JWTs for full unauthorized access. Update to V2604 now.

securityonline.info/siemens-op

##

DailyCyberSecurity@infosec.exchange at 2026-07-20T12:54:39.000Z ##

Siemens Opcenter X authentication bypass (CVE-2026-56451, CVSS 10) lets attackers forge JWTs for full unauthorized access. Update to V2604 now.

#Siemens #OpcenterX #CVE202656451 #ICS #AuthenticationBypass

securityonline.info/siemens-op

##

CVE-2026-6875(CVSS UNKNOWN)

EPSS: 0.51%

updated 2026-07-13T21:31:30

6 posts

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceN

hackerdogs@mastodon.social at 2026-07-20T15:41:42.000Z ##

Attackers are actively exploiting a critical pre-auth RCE vulnerability in ServiceNow AI Platform this week.
helpnetsecurity.com/2026/07/20
#cybersecurity #servicenow #vulnerability

##

oversecurity@mastodon.social at 2026-07-20T10:21:47.000Z ##

Critical ServiceNow code execution flaw now exploited in attacks

Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company...

🔗️ [Bleepingcomputer] link.is.it/sPaAEV

##

undercodenews@mastodon.social at 2026-07-20T10:05:53.000Z ##

Critical ServiceNow AI Platform Vulnerability CVE-2026-6875 Exploited in the Wild: A New Warning for Enterprise AI Security + Video

Introduction: The AI Infrastructure That Became a New Cyber Battlefield Artificial intelligence has quickly become the foundation of modern enterprise operations. Companies are no longer using AI only for experiments or isolated projects; they are embedding intelligent systems into customer support, financial processes, software…

undercodenews.com/critical-ser

##

Analyst207@mastodon.social at 2026-07-20T09:36:20.000Z ##

ServiceNow Vulnerability Exploited in Wild Attacks

A critical vulnerability, CVE-2026-6875, in the ServiceNow AI Platform is being exploited in wild attacks, allowing unauthenticated hackers to execute remote code and escape the sandbox. This flaw affects a widely-used enterprise platform that powers over 100,000 AI apps at 85% of Fortune 500 companies.

osintsights.com/servicenow-vul

#ServicenowVulnerability #Cve20266875 #RemoteCodeExecution #AiPlatform #EnterprisePaas

##

oversecurity@mastodon.social at 2026-07-20T10:21:47.000Z ##

Critical ServiceNow code execution flaw now exploited in attacks

Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company...

🔗️ [Bleepingcomputer] link.is.it/sPaAEV

##

DailyCyberSecurity@infosec.exchange at 2026-07-18T11:03:37.000Z ##

Active Exploitation and Public PoC Disclosed for CVE-2026-6875 ServiceNow Sandbox Escape Remote Code Execution

securityonline.info/cve-2026-6

##

CVE-2026-54159
(10.0 CRITICAL)

EPSS: 0.75%

updated 2026-07-10T20:36:58

1 posts

### Impact A PHP Object Injection vulnerability affects the PrestaShop module `ps_facetedsearch`. The module rebuilds the selected search filters from the request URL. The value of a slider filter (**price** or **weight**) is taken from the URL without sufficient validation, then stored in an internal filter-block cache where it is serialized and later read back with a raw native `unserialize()`

thehackerwire@mastodon.social at 2026-07-18T05:01:30.000Z ##

🔴 CVE-2026-54159 - Critical (10)

PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, and the value of a slider filter, price or weight, is taken fr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44739
(8.7 HIGH)

EPSS: 0.28%

updated 2026-07-10T19:07:01

1 posts

### Summary The columnConfigAction endpoint in the CustomReportsBundle is vulnerable to SQL injection. An attacker with the reports_config permission can supply a malicious SQL configuration that is concatenated into a query and executed. Although the application attempts to filter certain DDL/DML keywords (like UPDATE, DELETE, DROP), it fails to prevent arbitrary SELECT queries, UNION statements,

thehackerwire@mastodon.social at 2026-07-18T17:00:40.000Z ##

🟠 CVE-2026-44739 - High (8.7)

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57239
(8.2 HIGH)

EPSS: 0.11%

updated 2026-07-09T15:33:27

2 posts

The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.

1 repos

https://github.com/Paradoxis/CVE-2026-57239

CVE-2026-54496
(9.3 CRITICAL)

EPSS: 0.32%

updated 2026-07-06T21:23:42

1 posts

### Summary A soundness vulnerability in the variable-base scalar multiplication gadget of `halo2_gadgets` allowed a malicious prover to produce a valid proof for an Orchard Action with an *under-constrained* base point. Because this gadget enforces the diversified-address-integrity condition of the Orchard Action statement, the flaw let a prover satisfy that condition for an arbitrary (pk<sub>d<

thehackerwire@mastodon.social at 2026-07-19T08:00:42.000Z ##

🔴 CVE-2026-54496 - Critical (9.3)

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45659
(8.8 HIGH)

EPSS: 3.22%

updated 2026-07-02T12:16:47.143000

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

1 repos

https://github.com/HORKimhab/CVE-2026-45659

AAKL@infosec.exchange at 2026-07-17T16:32:43.000Z ##

Symantec, posted yesterday: Spirals: New Stealthy Ransomware Deployed Against Asian IT Company security.com/threat-intelligen

Also from yesterday:

Tenable: CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities tenable.com/blog/cve-2026-3220 #threatresearch #Microsoft #ransomware #infosec #SharePoint

##

CVE-2026-50151
(7.5 HIGH)

EPSS: 0.48%

updated 2026-07-01T21:35:48

1 posts

## Summary oras-go follows a registry-controlled `Location` header during the monolithic blob upload flow and reuses the `Authorization` header from the initial `POST` request for the subsequent `PUT` request. If a malicious registry returns a cross-host `Location`, oras-go can send the caller's credentials to an attacker-controlled endpoint. ## Affected Versions tested: v2.6.0 (commit 03243809

thehackerwire@mastodon.social at 2026-07-18T16:00:03.000Z ##

🟠 CVE-2026-50151 - High (7.5)

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization he...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-40949
(9.1 CRITICAL)

EPSS: 0.67%

updated 2026-06-29T14:08:26.717000

1 posts

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (All versions < V2.17.1), RUGGEDCOM ROX RX1511 (All versions < V2.17.1), RUGGEDCOM ROX RX1512 (All vers

security_crawler_carl@infosec.exchange at 2026-07-17T23:55:23.000Z ##

🏆 New Achievement! Rooted in Operational Technology!

PATCH NOTES v0.0.0 — KNOWN ISSUES: Siemens ROX II OT switches ship with a three-vulnerability zero-day chain, including CVE-2025-40949, that grants attackers persistent root access. This feature was not intentional. Unit 42 and Siemens have jointly confirmed it exists anyway.

ADDED: Full root on your industrial network by people who are not you. FIXED: Nothing, until you manually update to firmware V2.17.1. (1/2)

##

CVE-2026-43088
(5.5 MEDIUM)

EPSS: 0.12%

updated 2026-06-19T15:34:14

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: af_key: zero aligned sockaddr tail in PF_KEY exports PF_KEY export paths use `pfkey_sockaddr_size()` when reserving sockaddr payload space, so IPv6 addresses occupy 32 bytes on the wire. However, `pfkey_sockaddr_fill()` initializes only the first 28 bytes of `struct sockaddr_in6`, leaving the final 4 aligned bytes uninitial

bms48@mastodon.social at 2026-07-17T22:13:21.000Z ##

@kevin L4? Apple would like a word. About secure enclaves. Now, Mr Torvalds, about that PF_KEY CVE... dailycve.com/linux-kernel-unin

##

CVE-2026-9691
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-06-17T11:05:35.017000

1 posts

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.

1 repos

https://github.com/izxci/CVE-2026-9691

CVE-2026-3300
(9.8 CRITICAL)

EPSS: 40.99%

updated 2026-06-17T10:43:22.287000

1 posts

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before passing it to eval(). The sanitize_text_field() function applied to input does not

Nuclei template

2 repos

https://github.com/adamshaikhma/CVE-2026-3300

https://github.com/HORKimhab/CVE-2026-3300

sekurakbot@mastodon.com.pl at 2026-07-17T11:22:00.000Z ##

Krytyczna podatność RCE we wtyczce Everest Forms Pro (WordPress)

Badacze bezpieczeństwa z Wordfence ujawnili krytyczną podatność Remote Code Execution we wtyczce Everest Forms Pro przeznaczonej dla WordPressa. Luka ma być wciąż wykorzystywana do ataków na strony korzystające z tego rozszerzenia. Podatność dotyczy wszystkich wersji przed 1.9.13 i otrzymała ocenę 9.8 (krytyczna) w skali CVSS. TLDR: Podatność (CVE-2026-3300) pozwala nieuwierzytelnionemu...

#WBiegu #Podatność #Rce #Wordpress #Wtyczki

sekurak.pl/krytyczna-podatnosc

##

CVE-2026-32201
(6.5 MEDIUM)

EPSS: 21.48%

updated 2026-06-17T10:35:20.103000

1 posts

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

1 repos

https://github.com/B1tBit/CVE-2026-32201-exploit

AAKL@infosec.exchange at 2026-07-17T16:32:43.000Z ##

Symantec, posted yesterday: Spirals: New Stealthy Ransomware Deployed Against Asian IT Company security.com/threat-intelligen

Also from yesterday:

Tenable: CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities tenable.com/blog/cve-2026-3220 #threatresearch #Microsoft #ransomware #infosec #SharePoint

##

CVE-2026-23845
(5.8 MEDIUM)

EPSS: 0.40%

updated 2026-06-17T10:22:11.673000

1 posts

Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check CSS Download. The HTML Check feature (`/api/v1/message/{ID}/html-check`) is designed to analyze HTML emails for compatibility. During this process, the `inlineRemoteCSS()` function automatically downloads CSS files from external `<link rel="styleshee

EUVD_Bot@mastodon.social at 2026-07-20T18:00:48.000Z ##

🚨 EUVD-2026-45966

📊 Score: 5.8/10 (CVSS v3.1)
📦 Product: mailpit
🏢 Vendor: axllent
📅 Updated: 2026-07-20

📝 Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTML Check API"), shipped in mailpit `v1.28.3`, hardened `internal/htmlcheck/css.go::downloadCSSToBytes` with a ...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2025-69443
(6.3 MEDIUM)

EPSS: 0.31%

updated 2026-06-17T10:00:42.570000

1 posts

Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, run prompts on behalf of the user, control the Archon UI features, and steal all Archon information available on the UI including API keys.

beyondmachines1@infosec.exchange at 2026-07-19T12:01:42.000Z ##

Archon OS Vulnerability Exposes AI API Keys to Web-To-Client Attacks

Archon OS versions up to 0.3.11 are vulnerable to a web-to-client attack (CVE-2025-69443) that allows malicious websites to steal AI API keys and run commands on local systems. The flaw exists because the backend port lacks authentication and CORS protections. There is no patch as of reporting.

**If you use Archon OS, know that any website you visit can silently steal your AI API keys and data from it, and there's no patch yet. Remove your API keys from Archon now. Bind port 8181 to localhost only, block outside access with your firewall, and don't run Archon when browsing untrusted websites.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-9016
(5.3 MEDIUM)

EPSS: 0.26%

updated 2026-06-06T06:30:35

1 posts

The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output Neutralization for Logs in all versions up to, and including, 2.5.0. This is due to the `log_js_errors()` AJAX handler being registered for unauthenticated users via `wp_ajax_nopriv_log_js_errors` and gated only by a nonce that is publicly disclosed in every front-end page's HTML t

CVE-2026-45799
(7.5 HIGH)

EPSS: 0.50%

updated 2026-05-19T19:54:51

1 posts

# CVE-2026-45799 ## Maintainer summary Wire's protobuf group-skipping logic did not reject negative lengths before skipping a length-delimited field inside a group. A crafted protobuf payload could cause Wire to throw an unchecked runtime exception during decoding instead of the documented `IOException` / `ProtocolException` failure path. This can crash services that decode untrusted protobuf p

thehackerwire@mastodon.social at 2026-07-18T16:00:23.000Z ##

🟠 CVE-2026-45799 - High (7.5)

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-runtime do not validate that a LENGTH_DELIMITED field length is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45270
(8.7 HIGH)

EPSS: 0.00%

updated 2026-05-18T16:23:35

2 posts

## Summary The `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into the database. The public renderer for pages (`Home::index()` → `app/Views/templates/default/pages.php`) emits `$pageInfo->content` without `esc()`, yielding stored XSS that fires for every public visitor of the affected page — including

thehackerwire@mastodon.social at 2026-07-20T16:00:23.000Z ##

🟠 CVE-2026-45270 - High (8.7)

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-20T16:00:23.000Z ##

🟠 CVE-2026-45270 - High (8.7)

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-3220
(8.8 HIGH)

EPSS: 0.32%

updated 2026-05-18T15:30:37

1 posts

The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML

4 repos

https://github.com/solarlynxsqueeze/CVE-2026-32202

https://github.com/virus-or-not/CVE-2026-32202

https://github.com/asdrf5gh67j8ki/CVE-2026-32202

https://github.com/B1tBit/CVE-2026-32201-exploit

AAKL@infosec.exchange at 2026-07-17T16:32:43.000Z ##

Symantec, posted yesterday: Spirals: New Stealthy Ransomware Deployed Against Asian IT Company security.com/threat-intelligen

Also from yesterday:

Tenable: CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities tenable.com/blog/cve-2026-3220 #threatresearch #Microsoft #ransomware #infosec #SharePoint

##

CVE-2026-20810
(7.8 HIGH)

EPSS: 0.47%

updated 2026-01-13T18:31:14

1 posts

Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

wizbean@tech.lgbt at 2026-07-20T09:55:09.000Z ##

@passocacornio I got CVE-2026-20810
I guess you go first?

##

CVE-2025-20204
(4.8 MEDIUM)

EPSS: 0.31%

updated 2025-02-05T18:34:46

1 posts

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.&nbsp; This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulner

AAKL@infosec.exchange at 2026-07-17T15:51:07.000Z ##

Broadcom has new advisories addressing two high-severity vulnerabilities that were fist published on the 15th support.broadcom.com/web/ecx/s

Cisco:

Medium Severity: CVE-2025-20204and CVE-2025-20205 Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities sec.cloudapps.cisco.com/securi @TalosSecurity

And if you missed this yesterday, CISA added two Fortinet vulnerabilities to the catalogue:

CISA:

CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

And a Microsoft vulnerability:

CISA: CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #CISA #Fortinet #infosec #vulnerability #Cisco #Broadcom

##

CVE-2026-45710
(0 None)

EPSS: 0.00%

1 posts

N/A

EUVD_Bot@mastodon.social at 2026-07-20T17:00:54.000Z ##

🚨 EUVD-2026-45973

📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: mailpit
🏢 Vendor: axllent
📅 Updated: 2026-07-20

📝 Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a default 50MB p/m limit to prevent DoS via unlimited SMTP DATA and /api/v1/send body sizes") wrapped only `POST ...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-14266
(0 None)

EPSS: 0.00%

5 posts

N/A

1 repos

https://github.com/hg0434hongzh0/CVE-2026-14266

hackerdogs@mastodon.social at 2026-07-20T15:49:51.000Z ##

A critical heap-based buffer overflow vulnerability has been discovered in 7-Zip that could allow remote code execution when processing crafted XZ archives. CVE-2026-14266 affects how the archiver han
thehackernews.com/2026/07/new-
#cybersecurity #vulnerability #7zip

##

Analyst207@mastodon.social at 2026-07-20T10:06:15.000Z ##

7-Zip Flaw Exposes Systems to Code Execution Risk

A newly discovered flaw in 7-Zip, tracked as CVE-2026-14266, leaves systems vulnerable to code execution attacks, allowing hackers to execute code in the context of the current process. Fortunately, a fix is available in 7-Zip version 26.02, which patches the heap-based buffer overflow issue.

osintsights.com/7-zip-flaw-exp

#ZeroDay #CodeExecution #Cve202614266 #7zip #HeapbasedBufferOverflow

##

benzogaga33@mamot.fr at 2026-07-20T09:40:03.000Z ##

Faille dans 7-Zip : pourquoi vous devriez installer la version 26.02 sans attendre it-connect.fr/7-zip-26-02-fail #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

benzogaga33@mamot.fr at 2026-07-20T09:40:03.000Z ##

Faille dans 7-Zip : pourquoi vous devriez installer la version 26.02 sans attendre it-connect.fr/7-zip-26-02-fail #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

beyondmachines1@infosec.exchange at 2026-07-19T11:01:41.000Z ##

7-Zip Patches Remote Code Execution Vulnerability in XZ Decompression Logic

7-Zip version 26.02 patched a high-severity remote code execution vulnerability (CVE-2026-14266) caused by a heap-based buffer overflow in its XZ decompression logic. Attackers can exploit this flaw via malicious archives to take control of user systems. Manual updates are required as the software lacks auto-update features.

**Update 7-Zip manually to version 26.02 ASAP by downloading it from the official website (7-zip.org), since 7-Zip cannot update itself. Until you've updated, don't open archive files from emails or unknown sources, as one malicious file is enough to let attackers take over your session.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-58443
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-07-20T15:02:49.958Z ##

Gitea vulnerability CVE-2026-58443 (CVSS 9.6) lets public-only tokens write to private repos. Details and PoC code are public. Update to v1.27.0.

securityonline.info/gitea-vuln

##

DailyCyberSecurity@infosec.exchange at 2026-07-20T15:02:49.000Z ##

Gitea vulnerability CVE-2026-58443 (CVSS 9.6) lets public-only tokens write to private repos. Details and PoC code are public. Update to v1.27.0.

#Gitea #CVE202658443 #DevSecOps #PoC #InfoSec

securityonline.info/gitea-vuln

##

CVE-2026-31022
(0 None)

EPSS: 0.00%

1 posts

N/A

cvedatabase@techhub.social at 2026-07-20T10:30:05.000Z ##

🚨 Security Alert: Our Weekly CVE Roundup is live! This week, we analyze CVE-2026-31022, a critical RCE in Next.js, and explore the evolving threat landscape for server-side rendering and edge architectures. Stay informed and secure: cvedatabase.com/blog/weekly-cv #CVE #NextJS #InfoSec #CyberSecurity #WebDev #RCE

##

CVE-2026-42566
(0 None)

EPSS: 0.28%

3 posts

N/A

hugovalters@mastodon.social at 2026-07-20T09:03:33.000Z ##

CVE-2026-42566 - DoS in Meshtastic via malformed User.long_name. BLE crash on iOS. CVSS 7.5. Unpatched. Review your mesh setup. #CVE #IoT #infosec

valtersit.com/cve/CVE-2026-425

##

offseq@infosec.exchange at 2026-07-20T01:30:27.000Z ##

CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE #IoTSecurity

##

thehackerwire@mastodon.social at 2026-07-20T01:00:05.000Z ##

🟠 CVE-2026-42566 - High (7.5)

Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52824
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-07-20T01:02:33.000Z ##

Kimai vulnerability CVE-2026-52824 (CVSS 9.1) lets attackers forge cookies for account takeover via a default Docker APP_SECRET. Update to 2.58.0 now.

#Kimai #AccountTakeover #Docker #CVE202652824 #OpenSource

securityonline.info/kimai-acco

##

CVE-2026-44359
(0 None)

EPSS: 1.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-07-20T01:00:14.000Z ##

🔴 CVE-2026-44359 - Critical (10)

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-20T00:00:35.000Z ##

Meshtastic firmware (pre-2.7.21.1370b23) has a CRITICAL code injection flaw (CVE-2026-44359) in GitHub Actions (main_matrix.yml), risking repo secrets & supply chain compromise. Patch ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202644359 #Infosec

##

CVE-2026-16221
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-19T15:59:50.000Z ##

🟠 CVE-2026-16221 - High (7.5)

Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, und...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58195
(0 None)

EPSS: 0.46%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-18T19:00:01.000Z ##

🟠 CVE-2026-58195 - High (8.8)

Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone-stdio.ts, src/mcp/fastmcp/servers/claude-flow-sdk.ts, src/mcp/fastmcp/servers/stdio-full.ts, src/mcp/fastmcp/servers/http-stre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16158
(0 None)

EPSS: 0.23%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-18T14:00:01.000Z ##

🟠 CVE-2026-16158 - High (8.7)

Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore produce the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56741
(0 None)

EPSS: 0.52%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-18T05:00:21.000Z ##

🟠 CVE-2026-56741 - High (7.5)

JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAW...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56740
(0 None)

EPSS: 0.51%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-18T05:00:10.000Z ##

🟠 CVE-2026-56740 - High (7.5)

JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and Te...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54523
(0 None)

EPSS: 0.00%

2 posts

N/A

DarkWebInformer@infosec.exchange at 2026-07-17T18:03:25.000Z ##

‼️ New Dark Web Informer Blog Post!

Title: One Namespace String to kube-system: Cross-Namespace Privilege Escalation in Kyverno (CVE-2026-54523)

Link: darkwebinformer.com/one-namesp

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: darkwebinformer.com/pricing

##

DailyCyberSecurity@infosec.exchange at 2026-07-17T13:11:39.000Z ##

Kyverno vulnerability CVE-2026-54523 (CVSS 9.6) is public with PoC exploit code. It lets a tenant gain admin in any namespace. Update to v1.18.2.

#Kyverno #CVE202654523 #PrivilegeEscalation #Kubernetes #CyberSecurity

securityonline.info/kyverno-cv

##

CVE-2026-44436
(0 None)

EPSS: 0.28%

1 posts

N/A

hugovalters@mastodon.social at 2026-07-17T14:05:09.000Z ##

CVE-2026-44436 - High-severity DoS in Quicly (H2O HTTP server). Connection ID handling flaw can corrupt state. CVSS 7.5. No patch available yet. Monitor for updates. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-444

##

CVE-2026-15899
(0 None)

EPSS: 0.00%

1 posts

N/A

Visit counter For Websites