## Updated at UTC 2026-07-28T18:13:01.339287

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-66754 5.9 0.00% 2 0 2026-07-28T17:17:06.730000 Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the
CVE-2026-59878 7.5 0.00% 2 0 2026-07-28T16:20:53.010000 Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ
CVE-2026-43698 7.8 0.15% 1 0 2026-07-28T16:20:53.010000 An injection issue was addressed with improved validation. This issue is fixed i
CVE-2026-43776 7.8 0.15% 1 0 2026-07-28T16:20:53.010000 A buffer overflow was addressed with improved bounds checking. This issue is fix
CVE-2026-66748 8.8 0.00% 2 0 2026-07-28T16:20:16.310000 Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code
CVE-2026-61609 7.5 0.00% 2 0 2026-07-28T16:19:28.693000 Pterodactyl is a free, open-source game server management panel. From 1.7.0 unti
CVE-2026-65440 7.1 0.15% 1 0 2026-07-28T16:19:12.780000 Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.
CVE-2026-63077 9.8 0.65% 3 0 2026-07-28T16:17:58.820000 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-49743 7.8 0.11% 1 0 2026-07-28T16:17:58.820000 Software installed and run as a non-privileged user may conduct improper GPU sys
CVE-2026-7187 8.8 0.00% 2 0 2026-07-28T16:10:09.517000 Missing authentication for critical function vulnerability in Universal Software
CVE-2026-66035 7.5 0.32% 1 0 2026-07-28T16:07:41.440000 libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication h
CVE-2026-66034 7.5 0.25% 1 0 2026-07-28T16:07:41.440000 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check
CVE-2026-13440 7.2 0.00% 1 0 2026-07-28T16:07:15.840000 The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Che
CVE-2026-63727 8.8 0.00% 2 0 2026-07-28T15:32:19 Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper
CVE-2026-14169 8.1 0.29% 4 0 2026-07-28T15:16:51.580000 Due to incorrect behavior order a low privileged remote attacker could trigger a
CVE-2026-16812 10.0 0.98% 8 0 2026-07-28T14:50:33.960000 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a
CVE-2026-14785 7.5 0.00% 1 0 2026-07-28T12:31:27 The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injecti
CVE-2026-16462 9.8 0.00% 2 0 2026-07-28T12:31:27 In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a
CVE-2026-10207 7.5 0.00% 1 0 2026-07-28T12:31:20 The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Inject
CVE-2026-64531 None 0.16% 2 0 2026-07-28T12:31:19 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-14167 8.8 0.28% 4 0 2026-07-28T09:31:36 A low privileged remote attacker can perform privileged configuration changes re
CVE-2026-14168 8.8 0.28% 4 0 2026-07-28T09:31:36 A low privileged remote attacker can gain administrator privileges due to missin
CVE-2026-14171 6.1 0.18% 4 0 2026-07-28T09:31:35 An unauthenticated remote attacker can abuse the improper validation of the post
CVE-2026-43723 7.8 0.14% 1 0 2026-07-28T00:32:06 A path handling issue was addressed with improved validation. This issue is fixe
CVE-2026-43749 7.8 0.14% 1 0 2026-07-28T00:32:05 A parsing issue in the handling of directory paths was addressed with improved p
CVE-2026-39874 7.8 0.10% 1 0 2026-07-28T00:32:04 A permissions issue was addressed with additional restrictions. This issue is fi
CVE-2026-66473 7.5 0.20% 1 0 2026-07-28T00:31:11 Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
CVE-2026-65439 7.1 0.15% 1 0 2026-07-28T00:31:10 Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7
CVE-2026-17107 8.5 0.26% 1 0 2026-07-28T00:31:02 A flaw was found in the cluster-proxy service-proxy component used in Red Hat Ad
CVE-2026-15962 8.8 0.38% 1 0 2026-07-27T21:16:48.080000 The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Objec
CVE-2026-17496 8.1 0.30% 1 0 2026-07-27T20:37:16.927000 NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with
CVE-2026-65711 7.2 2.41% 1 0 2026-07-27T20:36:13.407000 sysPass through version 3.2.11 contains an OS command injection vulnerability th
CVE-2026-66041 8.8 0.42% 1 0 2026-07-27T20:34:24.887000 FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds
CVE-2026-55579 9.8 0.60% 1 1 2026-07-27T20:32:11.620000 Pheditor is a single-file editor and file manager written in PHP. From version 2
CVE-2026-12503 0 0.14% 1 0 2026-07-27T20:32:11.620000 Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-
CVE-2025-68686 5.9 1.26% 8 0 2026-07-27T18:31:25 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE
CVE-2025-71408 7.8 0.16% 1 0 2026-07-27T18:16:50.790000 NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection
CVE-2026-61511 9.8 1.27% 3 2 2026-07-27T15:32:39 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul
CVE-2026-45813 8.8 0.35% 1 0 2026-07-27T14:41:12.090000 Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apa
CVE-2026-45815 7.5 0.60% 1 0 2026-07-27T14:41:01.180000 Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read
CVE-2026-66142 7.5 0.48% 1 0 2026-07-27T14:35:32.197000 Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that
CVE-2026-16806 8.8 0.40% 1 0 2026-07-27T12:45:30.967000 Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remo
CVE-2026-14837 7.8 0.08% 1 0 2026-07-27T09:31:26 Multiple Lenze products are affected by an improper signature verification vulne
CVE-2026-64600 7.8 0.49% 8 6 2026-07-27T06:31:36 In the Linux kernel, the following vulnerability has been resolved: xfs: resamp
CVE-2026-17497 8.3 0.46% 1 0 2026-07-26T15:30:32 NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capabili
CVE-2026-17457 4.3 0.32% 1 0 2026-07-26T12:30:21 A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by t
CVE-2026-17458 6.3 0.23% 1 0 2026-07-26T12:30:21 A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the f
CVE-2026-17459 4.3 0.32% 1 0 2026-07-26T12:30:21 A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerabilit
CVE-2026-63720 7.5 0.42% 2 0 2026-07-26T06:31:31 datamodel-code-generator prior to version 0.70.0 contains a code injection vulne
CVE-2026-66012 10.0 0.44% 2 1 2026-07-25T12:31:47 SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST
CVE-2026-10818 8.1 0.42% 2 1 2026-07-25T09:30:31 The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in a
CVE-2026-56163 10.0 0.92% 2 0 2026-07-25T05:16:35.420000 Missing authentication for critical function in Microsoft Azure Kubernetes Servi
CVE-2026-50517 9.9 1.25% 1 0 2026-07-25T05:16:35.100000 Deserialization of untrusted data in M365 Copilot allows an authorized attacker
CVE-2026-66374 8.1 0.39% 1 1 2026-07-25T03:30:55 Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer
CVE-2026-66373 7.5 0.47% 1 0 2026-07-25T03:30:55 Redis before 8.8.0, in the unusual case where an authenticated attacker can exec
CVE-2026-62835 9.3 1.03% 3 0 2026-07-25T02:16:39.663000 Improper authorization in Azure Portal allows an unauthorized attacker to disclo
CVE-2026-61884 9.8 0.66% 2 0 2026-07-25T00:31:53 The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perf
CVE-2026-60134 8.8 0.32% 1 0 2026-07-25T00:31:53 Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elev
CVE-2026-61892 8.8 0.27% 1 0 2026-07-25T00:31:53 Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate p
CVE-2026-12497 7.5 0.23% 1 0 2026-07-24T21:33:30 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
CVE-2026-45811 7.5 0.34% 1 0 2026-07-24T21:33:30 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerabi
CVE-2026-66144 7.5 0.48% 1 0 2026-07-24T21:33:30 Although remote policy references are not retrieved during policy normalization,
CVE-2026-66143 7.5 0.51% 1 0 2026-07-24T21:33:30 It is possible to bypass the maximum number of normalized policy alternatives th
CVE-2026-12981 7.5 0.30% 1 0 2026-07-24T21:33:29 The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication
CVE-2026-12877 9.1 0.24% 1 0 2026-07-24T21:33:29 The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5
CVE-2026-45816 7.5 0.61% 1 0 2026-07-24T21:33:29 NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Requ
CVE-2026-66039 8.8 0.42% 1 0 2026-07-24T21:32:28 FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflo
CVE-2026-66036 8.8 0.29% 1 0 2026-07-24T21:32:28 FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds wri
CVE-2026-66040 8.8 0.55% 1 0 2026-07-24T21:32:28 FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds wri
CVE-2026-14603 7.5 0.24% 1 0 2026-07-24T20:48:39.923000 The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have
CVE-2026-49745 7.8 0.11% 1 0 2026-07-24T18:32:33 Kernel software installed and running inside a Guest VM may post improper comman
CVE-2026-16800 8.8 0.29% 1 0 2026-07-24T18:32:33 Improper control of generation of code ('Code Injection') in the schedule featur
CVE-2026-49744 7.8 0.11% 1 0 2026-07-24T18:32:32 Kernel software installed and running inside a Guest VM may post improper comman
CVE-2026-16801 8.8 0.29% 1 0 2026-07-24T18:32:32 Improper control of generation of code ('Code Injection') in the variables featu
CVE-2026-65709 8.3 0.22% 1 0 2026-07-24T18:31:41 sysPass through version 3.2.11 contains a missing object-level authorization vul
CVE-2026-66033 7.5 0.39% 1 0 2026-07-24T18:31:41 libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication i
CVE-2026-65708 8.1 0.22% 1 0 2026-07-24T18:31:37 sysPass through version 3.2.11 contains an insecure direct object reference vuln
CVE-2026-66032 8.8 0.29% 1 0 2026-07-24T18:31:37 libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerab
CVE-2026-66027 8.3 0.26% 1 0 2026-07-24T17:17:34.993000 Suna before 0.9.102 contains a broken access control vulnerability in the messag
CVE-2026-16807 8.8 0.26% 1 0 2026-07-24T15:34:00 Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a
CVE-2026-16805 8.8 0.31% 1 0 2026-07-24T15:34:00 Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remot
CVE-2026-16804 8.3 0.25% 1 0 2026-07-24T15:34:00 Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remot
CVE-2026-8789 8.1 0.22% 1 0 2026-07-24T15:33:10 The Easy Appointments plugin for WordPress is vulnerable to unauthorized modific
CVE-2026-58630 10.0 0.81% 3 0 2026-07-24T15:33:09 Improper access control in Azure App Service allows an unauthorized attacker to
CVE-2026-57106 10.0 0.92% 2 0 2026-07-24T15:33:03 Server-side request forgery (ssrf) in Data Quality allows an unauthorized attack
CVE-2026-66140 8.4 0.27% 1 0 2026-07-24T06:34:11 Exim before 4.99.5 allows directory traversal to access files outside of the spo
CVE-2026-62144 9.1 20.62% 1 1 2026-07-24T05:16:45.793000 An authentication bypass vulnerability in Check Point Security Management and Mu
CVE-2026-47668 10.0 4.34% 1 1 template 2026-07-24T05:16:44.947000 DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's
CVE-2026-35425 8.0 0.48% 1 0 2026-07-24T03:32:01 Improper access control in Azure API Management (APIM) allows an authorized atta
CVE-2026-54120 9.9 0.71% 2 0 2026-07-24T03:31:56 Improper input validation in Microsoft Surface allows an authorized attacker to
CVE-2026-56167 8.5 0.38% 1 0 2026-07-24T03:31:56 Server-side request forgery (ssrf) in Azure AI Search allows an authorized attac
CVE-2026-42933 10.0 0.29% 2 0 2026-07-24T00:32:40 Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or inter
CVE-2026-6516 10.0 4.73% 1 0 2026-07-23T18:31:54 Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthen
CVE-2026-50522 9.8 57.10% 4 3 2026-07-23T15:44:10.873000 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-16723 9.0 0.41% 5 3 2026-07-23T15:01:24.377000 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.
CVE-2026-46331 7.8 0.53% 1 13 2026-07-23T12:18:18.287000 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-63030 9.8 98.05% 2 70 template 2026-07-22T23:10:00.110000 WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API ba
CVE-2026-15342 6.5 0.22% 1 0 2026-07-22T21:33:00 Plane contains a multi‑tenant authorization flaw in its asset‑management API tha
CVE-2026-13072 8.1 0.32% 1 0 2026-07-22T21:32:15 When compute mode is enabled on a standalone mongod instance, insufficient valid
CVE-2026-16232 9.1 12.68% 3 1 2026-07-22T21:32:05 An authentication bypass vulnerability in the Check Point SmartConsole login pro
CVE-2026-8933 7.8 0.21% 1 0 2026-07-22T19:17:14.773000 A local privilege escalation vulnerability exists in snap-confine, a set-capabil
CVE-2026-53359 8.8 0.91% 2 6 2026-07-22T19:07:43.103000 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F
CVE-2026-49176 7.8 0.40% 2 1 2026-07-22T16:17:28.753000 Improper privilege management in Windows WalletService allows an authorized atta
CVE-2026-62145 7.5 7.54% 1 1 2026-07-22T15:31:34 A vulnerability in Check Point Gaia Portal allows an authenticated attacker with
CVE-2026-8985 None 4.19% 1 0 2026-07-22T00:32:44 Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command
CVE-2026-64606 9.8 0.63% 1 0 2026-07-21T21:33:35 Deserialization of untrusted data vulnerability that may allow class-registratio
CVE-2026-64879 9.9 2.59% 1 0 2026-07-21T21:32:47 A filename supplied during file upload is not properly sanitized before being us
CVE-2026-54121 8.8 1.05% 9 8 2026-07-21T19:54:33.623000 Improper authorization in Active Directory Certificate Services (AD CS) allows a
CVE-2026-40510 3.8 0.22% 4 0 2026-07-21T12:10:00.090000 OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overf
CVE-2026-63108 8.8 1.92% 1 0 2026-07-20T21:31:57 Roo Code through 3.54.0 contains a command injection vulnerability in the auto-a
CVE-2026-63766 9.8 1.75% 1 1 2026-07-20T21:31:57 GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability
CVE-2026-2291 7.3 0.92% 4 1 2026-07-20T21:31:40 dnsmasqs extract_name() function can be abused to cause a heap buffer overflow,
CVE-2026-54298 4.2 0.23% 1 0 2026-07-18T17:25:06 ## Summary The `spreadAttributes` function in Astro's server-side rendering pip
CVE-2026-53362 7.8 0.27% 2 0 2026-07-18T09:32:17 In the Linux kernel, the following vulnerability has been resolved: ipv6: accou
CVE-2026-39808 9.8 89.69% 1 6 template 2026-07-17T05:16:38.870000 A improper neutralization of special elements used in an os command ('os command
CVE-2026-25089 9.8 69.83% 1 2 2026-07-16T18:32:24 A improper neutralization of special elements used in an os command ('os command
CVE-2026-58644 9.8 5.06% 1 0 2026-07-16T18:31:26 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-42530 8.1 3.68% 1 3 2026-07-16T12:17:51.630000 NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI
CVE-2023-4346 7.5 0.91% 1 0 2026-07-16T05:16:16.603000 KNX devices that use KNX Connection Authorization and support Option 1 are, dep
CVE-2026-46817 9.8 13.31% 1 2 2026-07-15T18:32:50 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone
CVE-2026-42533 8.1 3.60% 4 8 2026-07-15T15:33:14 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive
CVE-2026-56155 7.8 2.33% 1 0 2026-07-14T21:32:52 Insufficient granularity of access control in Active Directory Federation Servic
CVE-2026-15410 7.2 76.35% 1 3 2026-07-14T21:32:21 Post-authentication improper control of generation of code ('Code Injection') vu
CVE-2026-50502 8.0 0.60% 1 0 2026-07-14T18:32:33 Insufficient granularity of access control in Windows Event Logging Service allo
CVE-2026-50454 7.8 0.44% 1 0 2026-07-14T18:32:32 Relative path traversal in Windows User Interface Core allows an authorized atta
CVE-2026-53264 7.8 0.12% 2 1 2026-07-08T06:31:34 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-55255 8.4 29.05% 1 1 2026-07-07T22:14:37 ## Summary Insecure Direct Object Reference (IDOR) vulnerability in `/api/v1/re
CVE-2026-5172 7.3 2.68% 4 2 2026-06-30T03:37:45 A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker t
CVE-2026-42945 8.1 61.47% 2 42 2026-06-27T06:30:25 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo
CVE-2026-12569 9.8 2.26% 4 1 2026-06-26T15:33:15 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-0160 8.8 0.23% 2 0 2026-06-17T18:36:29 In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there
CVE-2026-0149 8.8 0.29% 2 0 2026-06-17T17:34:19.580000 In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap bu
CVE-2025-69419 7.4 0.44% 4 1 2026-06-17T10:00:39.850000 Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously craft
CVE-2025-68160 4.7 0.15% 4 0 2026-06-17T09:58:39.407000 Issue summary: Writing large, newline-free data into a BIO chain using the line-
CVE-2024-1813 9.8 1.11% 2 1 2026-06-17T07:05:03.993000 The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection
CVE-2013-4786 7.5 81.80% 5 1 2026-06-16T23:57:53.617000 The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R
CVE-2026-22795 5.5 0.14% 4 0 2026-05-12T15:32:20 Issue summary: An invalid or NULL pointer dereference can happen in an applicati
CVE-2025-69421 7.5 0.84% 4 1 2026-05-12T15:31:14 Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer de
CVE-2025-69420 7.5 0.77% 4 1 2026-05-12T15:31:14 Issue summary: A type confusion vulnerability exists in the TimeStamp Response v
CVE-2026-22796 5.3 0.50% 4 0 2026-05-12T15:31:14 Issue summary: A type confusion vulnerability exists in the signature verificati
CVE-2025-69418 4.0 0.11% 4 1 2026-05-12T15:31:14 Issue summary: When using the low-level OCB API directly with AES-NI or<br>other
CVE-2026-4893 5.3 2.68% 4 5 2026-05-11T21:31:33 An information disclosure vulnerability in dnsmasq allows remote attackers to by
CVE-2026-32194 9.8 0.70% 1 1 2026-03-20T00:31:34 Improper neutralization of special elements used in a command ('command injectio
CVE-2026-32191 9.8 0.56% 1 0 2026-03-19T21:30:31 Improper neutralization of special elements used in an os command ('os command i
CVE-2025-66376 7.2 21.62% 1 0 2026-03-18T18:31:10 Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas
CVE-2025-29827 9.9 1.25% 1 0 2025-06-05T15:32:29 Improper Authorization in Azure Automation allows an authorized attacker to elev
CVE-2023-5217 8.8 49.01% 2 3 2024-02-15T15:02:28 Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5
CVE-2008-1028 None 4.55% 1 0 2023-01-31T05:05:55 Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-as
CVE-2026-53921 0 0.00% 1 2 N/A
CVE-2026-60137 0 77.97% 1 45 N/A
CVE-2026-25589 0 1.38% 1 1 N/A
CVE-2026-25243 0 3.30% 1 3 N/A
CVE-2026-16766 0 1.30% 1 0 N/A
CVE-2026-48021 0 0.12% 2 0 N/A
CVE-2026-54342 0 0.12% 1 0 N/A

CVE-2026-66754
(5.9 MEDIUM)

EPSS: 0.00%

updated 2026-07-28T17:17:06.730000

2 posts

Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request whose decoded path matches a configured prefix while the raw percent-encoded path does not, causing the assert! to fail and triggering either a 500 erro

thehackerwire@mastodon.social at 2026-07-28T17:00:26.000Z ##

🟠 CVE-2026-66754 - High (7.5)

Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-28T17:00:26.000Z ##

🟠 CVE-2026-66754 - High (7.5)

Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59878
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-28T16:20:53.010000

2 posts

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause the NIO threads to die and if done rapidly enough can lead to exhaustion of the NIO thread pool denying service to other connections. This i

thehackerwire@mastodon.social at 2026-07-28T16:00:34.000Z ##

🟠 CVE-2026-59878 - High (7.5)

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All.

A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-28T16:00:34.000Z ##

🟠 CVE-2026-59878 - High (7.5)

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All.

A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43698
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-28T16:20:53.010000

1 posts

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

thehackerwire@mastodon.social at 2026-07-28T01:00:38.000Z ##

🟠 CVE-2026-43698 - High (7.8)

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43776
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-28T16:20:53.010000

1 posts

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

thehackerwire@mastodon.social at 2026-07-27T23:00:21.000Z ##

🟠 CVE-2026-43776 - High (7.8)

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66748
(8.8 HIGH)

EPSS: 0.00%

updated 2026-07-28T16:20:16.310000

2 posts

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers can store an attacker-controlled Ruby expression in the field options command parameter, which is evaluated via instance_

thehackerwire@mastodon.social at 2026-07-28T17:00:35.000Z ##

🟠 CVE-2026-66748 - High (8.8)

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_ev...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-28T17:00:35.000Z ##

🟠 CVE-2026-66748 - High (8.8)

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_ev...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61609
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-28T16:19:28.693000

2 posts

Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket to the login and two-factor checkpoint endpoints instead of keying by IP or account: the fall-through Limit::perMinute(10) covering POST /auth/login and POST /auth/login/checkpoint omitted -

thehackerwire@mastodon.social at 2026-07-28T17:00:45.000Z ##

🟠 CVE-2026-61609 - High (7.5)

Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket to the login and two-factor checkpoin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-28T17:00:45.000Z ##

🟠 CVE-2026-61609 - High (7.5)

Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket to the login and two-factor checkpoin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65440
(7.1 HIGH)

EPSS: 0.15%

updated 2026-07-28T16:19:12.780000

1 posts

Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.

hugovalters@mastodon.social at 2026-07-28T11:13:51.000Z ##

CVE-2026-65440 - XSS in GetGenie <=4.4.3. Unauthenticated. CVSS 7.1. No patch yet - apply WAF rules. #CVE #GetGenie #infosec

valtersit.com/cve/CVE-2026-654

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-07-28T16:17:58.820000

3 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CVE-2026-49743
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-28T16:17:58.820000

1 posts

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronisation primitive is not properly incremented. This can be exploited, by destroying the ex

thehackerwire@mastodon.social at 2026-07-25T09:00:05.000Z ##

🟠 CVE-2026-49743 - High (7.8)

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs.

During workload submission involving a fence exported by...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7187
(8.8 HIGH)

EPSS: 0.00%

updated 2026-07-28T16:10:09.517000

2 posts

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKBS: through 28072026. NOTE: The vendor was contacted and it was learned that the product is not supported.

thehackerwire@mastodon.social at 2026-07-28T16:00:44.000Z ##

🟠 CVE-2026-7187 - High (8.8)

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects UKBS: through 28072026.
NOTE: The vendor was contacted and it was learn...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-28T16:00:44.000Z ##

🟠 CVE-2026-7187 - High (8.8)

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects UKBS: through 28072026.
NOTE: The vendor was contacted and it was learn...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66035
(7.5 HIGH)

EPSS: 0.32%

updated 2026-07-28T16:07:41.440000

1 posts

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffe

thehackerwire@mastodon.social at 2026-07-24T20:00:59.000Z ##

🟠 CVE-2026-66035 - High (7.5)

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66034
(7.5 HIGH)

EPSS: 0.25%

updated 2026-07-28T16:07:41.440000

1 posts

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without

thehackerwire@mastodon.social at 2026-07-24T18:00:34.000Z ##

🟠 CVE-2026-66034 - High (7.5)

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsy...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13440
(7.2 HIGH)

EPSS: 0.00%

updated 2026-07-28T16:07:15.840000

1 posts

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message_popup' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in

hugovalters@mastodon.social at 2026-07-28T17:13:44.000Z ##

CVE-2026-13440 - Stored XSS in StoreGrowth WooCommerce. Unauthenticated inject scripts via message_popup. CVSS 7.2. No patch. Remove plugin until update. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-134

##

CVE-2026-63727
(8.8 HIGH)

EPSS: 0.00%

updated 2026-07-28T15:32:19

2 posts

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read onl

thehackerwire@mastodon.social at 2026-07-28T16:00:24.000Z ##

🟠 CVE-2026-63727 - High (8.8)

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capab...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-28T16:00:24.000Z ##

🟠 CVE-2026-63727 - High (8.8)

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capab...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14169
(8.1 HIGH)

EPSS: 0.29%

updated 2026-07-28T15:16:51.580000

4 posts

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-16812
(10.0 CRITICAL)

EPSS: 0.98%

updated 2026-07-28T14:50:33.960000

8 posts

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intende

Matchbook3469@mastodon.social at 2026-07-28T17:37:20.000Z ##

🔵 THREAT INTELLIGENCE

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

Vulnerability | CRITICAL
CVEs: CVE-2026-16812

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively...

Full analysis:
yazoul.net/news/article/attack

#InfoSec #ZeroDay #ThreatHunting

##

security_crawler_carl at 2026-07-28T08:14:53.704Z ##

🏆 New Achievement! Ten Out of Ten, Would Exploit Again!

Step right up, valued on-premises customer! Today's featured item is CVE-2026-16812, a perfect-score CVSS 10.0 OS command injection in Arista's VeloCloud Orchestrator — the centralized management platform you trusted with the confidentiality, integrity, and availability of, well, everything. Unknown attackers are already browsing your privileged internal functionality like it's a clearance rack. (1/2)

##

Analyst207@mastodon.social at 2026-07-28T06:25:02.000Z ##

Arista VeloCloud Flaw Exposes On-Premises Networks to Active Exploitation

A critical security flaw in Arista VeloCloud, tracked as CVE-2026-16812, is under active exploitation, allowing remote attackers to access sensitive internal functionality and potentially leading to arbitrary code execution. This maximum-severity vulnerability could compromise the confidentiality, integrity, and availability of…

osintsights.com/arista-veloclo

#Cve202616812 #Arista #Velocloud #SupplyChain #EmergingThreats

##

security_crawler_carl@infosec.exchange at 2026-07-28T08:14:53.000Z ##

🏆 New Achievement! Ten Out of Ten, Would Exploit Again!

Step right up, valued on-premises customer! Today's featured item is CVE-2026-16812, a perfect-score CVSS 10.0 OS command injection in Arista's VeloCloud Orchestrator — the centralized management platform you trusted with the confidentiality, integrity, and availability of, well, everything. Unknown attackers are already browsing your privileged internal functionality like it's a clearance rack. (1/2)

##

thecybermind@infosec.exchange at 2026-07-28T01:37:38.000Z ##

(CISA TS-SOC) CVE-2026-16812 – Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

Severity: CRITICAL Impact Summary: Remote attackers may access privileged internal functionality and impact the VCO host, compromising the confidentiality, integrity, and availability of the orchestrator and managed data....

thecybermind.co/2026/07/27/cis

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T21:54:32.000Z ##

CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.

#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity

securityonline.info/cisa-kev-a

##

cisakevtracker@mastodon.social at 2026-07-27T20:00:55.000Z ##

CVE ID: CVE-2026-16812
Vendor: Arista
Product: VeloCloud Orchestrator
Date Added: 2026-07-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T15:27:08.000Z ##

CVE-2026-16812, a VeloCloud command injection scored CVSS 10, is exploited in the wild. Patch VeloCloud Orchestrator now, plus two related bugs.

#VeloCloud #Arista #CVE202616812 #CommandInjection #ExploitedInTheWild #VCO #SSRF #Cybersecurity

securityonline.info/velocloud-

##

CVE-2026-14785
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-28T12:31:27

1 posts

The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that ca

hugovalters@mastodon.social at 2026-07-28T12:14:40.000Z ##

CVE-2026-14785 - SQLi in Web Directory Free WordPress plugin. Unauthenticated attackers can extract sensitive data. CVSS 7.5. No patch available - update or disable immediately. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-147

##

CVE-2026-16462
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-07-28T12:31:27

2 posts

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

certvde at 2026-07-28T09:28:50.555Z ##

VDE-2026-085
Weidmueller: SQL Injection Vulnerability in PROCON-WEB SCADA

A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands.
CVE-2026-16462

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:28:50.000Z ##

#OT #Advisory VDE-2026-085
Weidmueller: SQL Injection Vulnerability in PROCON-WEB SCADA

A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands.
#CVE CVE-2026-16462

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

CVE-2026-10207
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-28T12:31:20

1 posts

The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id' GET parameter in the user profile template combined with the use of wp_unslash() which removes WordPress's magic quotes protection, followed by direct concatenation into a SQL query without proper es

hugovalters@mastodon.social at 2026-07-28T15:06:49.000Z ##

CVE-2026-10207 - SQLi in PickPlugins Question Answer plugin for WordPress. CVSS 7.5. Unauthenticated injection via 'id' param. No patch yet — disable or remove plugin immediately. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-102

##

CVE-2026-64531(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-07-28T12:31:19

2 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guar

DailyCyberSecurity at 2026-07-28T11:12:26.589Z ##

The OVSwrap local root flaw hits the Linux kernel Open vSwitch datapath. CVE-2026-64531 now has a public patch and PoC. See affected distros and fixes.

securityonline.info/ovswrap-cv

##

DailyCyberSecurity@infosec.exchange at 2026-07-28T11:12:26.000Z ##

The OVSwrap local root flaw hits the Linux kernel Open vSwitch datapath. CVE-2026-64531 now has a public patch and PoC. See affected distros and fixes.

#OVSwrap #CVE202664531 #LinuxKernel #OpenvSwitch #LocalRoot #PrivilegeEscalation

securityonline.info/ovswrap-cv

##

CVE-2026-14167
(8.8 HIGH)

EPSS: 0.28%

updated 2026-07-28T09:31:36

4 posts

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-14168
(8.8 HIGH)

EPSS: 0.28%

updated 2026-07-28T09:31:36

4 posts

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-14171
(6.1 MEDIUM)

EPSS: 0.18%

updated 2026-07-28T09:31:35

4 posts

An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability.

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-43723
(7.8 HIGH)

EPSS: 0.14%

updated 2026-07-28T00:32:06

1 posts

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root privileges.

thehackerwire@mastodon.social at 2026-07-27T23:00:42.000Z ##

🟠 CVE-2026-43723 - High (7.8)

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root pri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43749
(7.8 HIGH)

EPSS: 0.14%

updated 2026-07-28T00:32:05

1 posts

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

thehackerwire@mastodon.social at 2026-07-27T23:00:32.000Z ##

🟠 CVE-2026-43749 - High (7.8)

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39874
(7.8 HIGH)

EPSS: 0.10%

updated 2026-07-28T00:32:04

1 posts

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

thehackerwire@mastodon.social at 2026-07-28T01:00:48.000Z ##

🟠 CVE-2026-39874 - High (7.8)

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66473
(7.5 HIGH)

EPSS: 0.20%

updated 2026-07-28T00:31:11

1 posts

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

thehackerwire@mastodon.social at 2026-07-28T01:00:26.000Z ##

🟠 CVE-2026-66473 - High (7.5)

Unauthenticated Broken Access Control in Xendit Payment &lt;= 7.1.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65439
(7.1 HIGH)

EPSS: 0.15%

updated 2026-07-28T00:31:10

1 posts

Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.

hugovalters@mastodon.social at 2026-07-28T14:05:17.000Z ##

CVE-2026-65439 - XSS in Ultimate Addons for Contact Form 7 ≤3.5.45. Unauthenticated. CVSS 7.1. No patch; apply WAF or disable plugin. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-654

##

CVE-2026-17107
(8.5 HIGH)

EPSS: 0.26%

updated 2026-07-28T00:31:02

1 posts

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an

thehackerwire@mastodon.social at 2026-07-24T20:00:24.000Z ##

🟠 CVE-2026-17107 - High (8.5)

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15962
(8.8 HIGH)

EPSS: 0.38%

updated 2026-07-27T21:16:48.080000

1 posts

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over a

thehackerwire@mastodon.social at 2026-07-26T03:00:20.000Z ##

🟠 CVE-2026-15962 - High (8.8)

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-lev...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17496
(8.1 HIGH)

EPSS: 0.30%

updated 2026-07-27T20:37:16.927000

1 posts

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to inc

thehackerwire@mastodon.social at 2026-07-26T15:59:49.000Z ##

🟠 CVE-2026-17496 - High (8.1)

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65711
(7.2 HIGH)

EPSS: 2.41%

updated 2026-07-27T20:36:13.407000

1 posts

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. The FileBackupService builds a tar shell command via string concatenation, inserting the admin-configurable siteBackupPath setting without escapeshellarg() or e

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-66041
(8.8 HIGH)

EPSS: 0.42%

updated 2026-07-27T20:34:24.887000

1 posts

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data excee

thehackerwire@mastodon.social at 2026-07-24T22:00:14.000Z ##

🟠 CVE-2026-66041 - High (8.8)

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimension...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55579
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-07-27T20:32:11.620000

1 posts

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). There is no mechanism to force a password change on first login. Any deployment using the default credentials grants an attacker full access to the file editor, file upload, and terminal featur

1 repos

https://github.com/Ch4120N/CVE-2026-55579

Matchbook3469@mastodon.social at 2026-07-28T09:20:21.000Z ##

🔴 New security advisory:

CVE-2026-55579 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

#InfoSec #ZeroDay #ThreatIntel

##

CVE-2026-12503
(0 None)

EPSS: 0.14%

updated 2026-07-27T20:32:11.620000

1 posts

Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink attack on `/etc/lighttpd/ssl/server.pem`.

offseq@infosec.exchange at 2026-07-25T10:30:26.000Z ##

CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Loytec #CVE2026

##

CVE-2025-68686
(5.9 MEDIUM)

EPSS: 1.26%

updated 2026-07-27T18:31:25

8 posts

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases

allaboutsecurity@mastodon.social at 2026-07-28T08:44:53.000Z ##

CISA warnt vor aktiv ausgenutzter FortiOS-Sicherheitslücke

Grundlage dafür sind bestätigte Hinweise auf laufende Angriffe, bei denen die Lücke mit der Kennung CVE-2025-68686 zum Einsatz kommt.

all-about-security.de/cisa-war

#cve #cybersecurity #itsicherheit

##

beyondmachines1 at 2026-07-28T08:01:42.491Z ##

CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass

CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.

**If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-07-28T08:01:42.000Z ##

CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass

CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.

**If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T21:54:32.000Z ##

CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.

#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity

securityonline.info/cisa-kev-a

##

secdb@infosec.exchange at 2026-07-27T19:00:11.000Z ##

🚨 [CISA-2026:0727] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-68686 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: FortiOS
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260727 #cisa20260727 #cve_2025_68686 #cve202568686

##

thecybermind@infosec.exchange at 2026-07-27T18:39:00.000Z ##

(CISA TS-SOC) CVE-2025-68686 – Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Severity: MEDIUM Impact Summary: Exposure of sensitive information to unauthorized actors due to patch bypass, potentially leaking data after prior compromise....

thecybermind.co/2026/07/27/cis

##

cisakevtracker@mastodon.social at 2026-07-27T18:00:47.000Z ##

CVE ID: CVE-2025-68686
Vendor: Fortinet
Product: FortiOS
Date Added: 2026-07-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-07-27T17:09:22.000Z ##

CISA has added a vulnerability to the KEV catalogue.

- CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability cve.org/CVERecord?id=CVE-2025-

Also:

Cisco tagged Apple yesterday for zero-day reports talosintelligence.com/vulnerab @TalosSecurity #Fortinet #CISA #infosec #vulnerability #Apple #zeroday

##

CVE-2025-71408
(7.8 HIGH)

EPSS: 0.16%

updated 2026-07-27T18:16:50.790000

1 posts

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or san

thehackerwire@mastodon.social at 2026-07-24T23:00:01.000Z ##

🟠 CVE-2025-71408 - High (7.8)

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is inv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61511
(9.8 CRITICAL)

EPSS: 1.27%

updated 2026-07-27T15:32:39

3 posts

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style

2 repos

https://github.com/HORKimhab/CVE-2026-61511

https://github.com/puj790201-lab/cve-2026-61511

obivan@infosec.exchange at 2026-07-27T19:22:58.000Z ##

PoC for CVE-2026-61511, unauthenticated vBulletin RCE ssd-disclosure.com/vbulletin-r

##

DarkWebInformer@infosec.exchange at 2026-07-27T17:45:06.000Z ##

🚨‼️ CVE-2026-61511: A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server.

CVSS: 9.8

Exploit: ssd-disclosure.com/vbulletin-r

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T08:21:15.000Z ##

A public PoC now targets CVE-2026-61511, a vBulletin preauth RCE via runMaths eval. Patch to vBulletin 6.2.2 to block remote code execution.

#vBulletin #CVE202661511 #RCE #PreauthRCE #RemoteCodeExecution #PoC #WebSecurity #Cybersecurity

securityonline.info/vbulletin-

##

CVE-2026-45813
(8.8 HIGH)

EPSS: 0.35%

updated 2026-07-27T14:41:12.090000

1 posts

Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read. This can be triggered by nearby devices over Bluetooth connection, however pairing is required prior to accessing BASS service,

thehackerwire@mastodon.social at 2026-07-25T06:00:27.000Z ##

🟠 CVE-2026-45813 - High (8.8)

Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service.
Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45815
(7.5 HIGH)

EPSS: 0.60%

updated 2026-07-27T14:41:01.180000

1 posts

Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

thehackerwire@mastodon.social at 2026-07-25T08:00:24.000Z ##

🟠 CVE-2026-45815 - High (7.5)

Reachable Assertion vulnerability in Apache NimBLE.
A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.

Severity is medium as this requires DUT to first send ATT Read Multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66142
(7.5 HIGH)

EPSS: 0.48%

updated 2026-07-27T14:35:32.197000

1 posts

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

thehackerwire@mastodon.social at 2026-07-25T05:00:24.000Z ##

🟠 CVE-2026-66142 - High (7.5)

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recom...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16806
(8.8 HIGH)

EPSS: 0.40%

updated 2026-07-27T12:45:30.967000

1 posts

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T13:00:13.000Z ##

🟠 CVE-2026-16806 - High (8.8)

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14837
(7.8 HIGH)

EPSS: 0.08%

updated 2026-07-27T09:31:26

1 posts

Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.

certvde@infosec.exchange at 2026-07-27T07:01:06.000Z ##

#OT #Advisory VDE-2026-077
Lenze: Incorrect signature validation in the enable SSH routine

The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.
#CVE CVE-2026-14837

certvde.com/en/advisories/vde-

#CSAF lenze.csaf-tp.certvde.com/.wel

##

CVE-2026-64600
(7.8 HIGH)

EPSS: 0.49%

updated 2026-07-27T06:31:36

8 posts

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently

6 repos

https://github.com/bha-vin/CVE-2026-64600-Exploit

https://github.com/letsr00t/RefluxFS_CVE-2026-64600

https://github.com/vulnquest58/VQ-RefluxCore

https://github.com/HORKimhab/CVE-2026-64600

https://github.com/Debajyoti0-0/CVE-2026-64600

https://github.com/0xBlackash/CVE-2026-64600

benzogaga33@mamot.fr at 2026-07-27T09:40:02.000Z ##

RefluXFS : cette faille dans XFS donne un accès root sur RHEL, CentOS et AlmaLinux it-connect.fr/refluxfs-cve-202 #ActuCybersécurité #Cybersécurité #Vulnérabilité #Linux

##

hackmag@infosec.exchange at 2026-07-27T06:30:14.000Z ##

⚪️ New RefluXFS Vulnerability Enables Root Access on Linux

🗨️ Researchers at Qualys have discovered a nine-year-old vulnerability in the XFS file system. The bug, tracked as CVE-2026-64600 and dubbed RefluXFS, allows a local unprivileged user to overwrite protected files and gain root privileges. According to researchers, the bug was…

🔗 hackmag.com/news/refluxfs?utm_

#news

##

cyberveille@mastobot.ping.moi at 2026-07-26T17:30:15.000Z ##

📢 RefluXFS (CVE-2026-64600) : élévation de privilèges locale vers root dans le noyau Linux via XFS
📝 ## 🔍 Contexte

Le 22 juillet 2026...
📖 cyberveille : cyberveille.ch/posts/2026-07-2
🌐 source : blog.qualys.com/vulnerabilitie
#CVE_2026_64600 #IOC #Cyberveille

##

security_crawler_carl@infosec.exchange at 2026-07-26T02:24:57.000Z ##

CVE-2026-64600, dubbed RefluXFS by Qualys Threat Research Unit, is a nine-year-old race condition that lets a local attacker clone a root-owned file — /etc/passwd, a SUID binary, you name it — then hammer it with concurrent O_DIRECT writes until they win the race and own the box. Highly reliable exploitation. Survives reboot. A beautiful, silent corpse. (2/3)

##

secdb@infosec.exchange at 2026-07-25T12:52:05.000Z ##

🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability.

In the Linux kernel, the following vulnerability has been resolved:

xfs: resample the data fork mapping after cycling ILOCK

RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access.

ℹ️ Additional details on ZEN SecDB secdb.nttzen.cloud/updates/1d2

#infosec #refluxfs #linux #kernel #xfs #lpe
#nttdata #zen #secdb

##

schwerdtfegr.wordpress.com@schwerdtfegr.wordpress.com at 2026-07-25T11:41:44.000Z ##

Aber linux ist doch sicherer als linux…

Sicherheitsforscher von Qualys haben mithilfe von Claude Mythos eine neun Jahre alte und RefluXFS genannte Sicherheitslücke im Linux-Kernel entdeckt, mit der Angreifer durch das überschreiben geschützter Dateien Root-Zugriff erlangen können. Viele Linux-Distributionen sind in der Standardkonfiguration angreifbar, darunter Red Hat Enterprise Linux (RHEL), CentOS, Fedora und Oracle Linux. Admins sollten ihre Systeme absichern […] anfällig sind alle Linux-Kernel ab Version 4.11, welche im April 2017 veröffentlicht wurde. Voraussetzung ist jedoch, dass ein anvisiertes Linux-System über ein XFS-Volume mit aktiver Reflink-Funktion verfügt […] es gebe keinen alternativen Workaround, der zuverlässig vor CVE-2026-64600 schütze

Na, zumindest das kriegen die angelernten neuronalen netzwerke sehr zuverlässig hin: einen haufen uralter fehler in linux aufzufinden. Schön die sicherheitsaktualisierungen einspielen!

#Epic #Fail #Golem #Link #Linux #Security ##

threatnoir@infosec.exchange at 2026-07-25T07:05:45.000Z ##

⚠️ CRITICAL: New RefluXFS Linux flaw lets attackers gain root privileges

A nine-year-old race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite protected files and escalate to root. Systems running kernel v4.11+ with XFS and reflink enabled are vulnerable. The exploit leaves no kernel logs and persists across reboots, making dete…

threatnoir.com/focus

#infosec #cybersecurity

##

DailyCyberSecurity@infosec.exchange at 2026-07-24T13:31:15.000Z ##

Discover the RefluXFS Linux vulnerability (CVE-2026-64600) in XFS that allows local users to overwrite protected files and gain root privileges.

#RefluXFS #CVE202664600 #LinuxKernel #Cybersecurity #XFS

meterpreter.org/refluxfs-linux

##

CVE-2026-17497
(8.3 HIGH)

EPSS: 0.46%

updated 2026-07-26T15:30:32

1 posts

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in

thehackerwire@mastodon.social at 2026-07-26T15:59:58.000Z ##

🟠 CVE-2026-17497 - High (8.3)

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17457
(4.3 MEDIUM)

EPSS: 0.32%

updated 2026-07-26T12:30:21

1 posts

A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of the argument url leads to information disclosure. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project

offseq@infosec.exchange at 2026-07-26T13:30:26.000Z ##

mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #CVE202617457

##

CVE-2026-17458
(6.3 MEDIUM)

EPSS: 0.23%

updated 2026-07-26T12:30:21

1 posts

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem

offseq@infosec.exchange at 2026-07-26T12:00:25.000Z ##

SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #Vuln #mfyang

##

CVE-2026-17459
(4.3 MEDIUM)

EPSS: 0.32%

updated 2026-07-26T12:30:21

1 posts

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing a manipulation can lead to symlink following. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The proj

offseq@infosec.exchange at 2026-07-26T10:30:25.000Z ##

CVE-2026-17459: perwendel spark 2.9.0 – 2.9.4 affected by symlink following in staticFiles.externalLocation. Exploit public, MEDIUM severity. Restrict external resource access and monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE202617459 #Java #Security

##

CVE-2026-63720
(7.5 HIGH)

EPSS: 0.42%

updated 2026-07-26T06:31:31

2 posts

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The crafted value is emitted verbatim into a generated 'from ... import ...' statement without identifier validation, cau

offseq@infosec.exchange at 2026-07-26T06:00:24.000Z ##

CVE-2026-63720 (HIGH): koxudaxi datamodel-code-generator <0.70.0 is vulnerable to code injection. Malicious input schemas can trigger remote Python code execution. Avoid untrusted schemas & update when possible. radar.offseq.com/threat/cve-20 #OffSeq #infosec #Python #CVE202663720

##

thehackerwire@mastodon.social at 2026-07-26T05:59:49.000Z ##

🟠 CVE-2026-63720 - High (7.5)

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66012
(10.0 CRITICAL)

EPSS: 0.44%

updated 2026-07-25T12:31:47

2 posts

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publis

1 repos

https://github.com/Hunt-Benito/siyuan-mcp-admin-takeover-cve-2026-66012-missing-authorization

offseq@infosec.exchange at 2026-07-25T12:00:26.000Z ##

CVE-2026-66012: CRITICAL flaw in siyuan-note siyuan (<3.7.2). Missing authorization on /mcp lets remote attackers read secrets & plant malicious plugins for admin takeover. Disable anonymous Publish mode & restrict /mcp access. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec

##

thehackerwire@mastodon.social at 2026-07-25T12:00:01.000Z ##

🔴 CVE-2026-66012 - Critical (10)

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10818
(8.1 HIGH)

EPSS: 0.42%

updated 2026-07-25T09:30:31

2 posts

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. This makes it possible for unauthenticated

1 repos

https://github.com/Nxploited/CVE-2026-10818

offseq@infosec.exchange at 2026-07-25T13:30:10.000Z ##

CVE-2026-10818: WPForms Pro <=1.10.1.1 has a HIGH severity file upload vuln (CVSS 8.1). Unauthenticated RCE possible via ajax_chunk_upload_finalize. Restrict access & monitor uploads until a patch is released. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE202610818

##

thehackerwire@mastodon.social at 2026-07-25T07:59:48.000Z ##

🟠 CVE-2026-10818 - High (8.1)

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56163
(10.0 CRITICAL)

EPSS: 0.92%

updated 2026-07-25T05:16:35.420000

2 posts

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-07-25T04:30:23.000Z ##

CVE-2026-56163: CRITICAL (CVSS 10) in Azure Kubernetes Service — Missing authentication allows remote privilege escalation. Microsoft has released a fix; verify your AKS is updated. radar.offseq.com/threat/cve-20 #OffSeq #Azure #Kubernetes #CloudSecurity

##

thehackerwire@mastodon.social at 2026-07-24T22:01:21.000Z ##

🔴 CVE-2026-56163 - Critical (10)

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50517
(9.9 CRITICAL)

EPSS: 1.25%

updated 2026-07-25T05:16:35.100000

1 posts

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-07-25T12:00:33.000Z ##

🔴 CVE-2026-50517 - Critical (9.9)

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66374
(8.1 HIGH)

EPSS: 0.39%

updated 2026-07-25T03:30:55

1 posts

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

1 repos

https://github.com/venglin/knot-doq

thehackerwire@mastodon.social at 2026-07-25T03:00:16.000Z ##

🟠 CVE-2026-66374 - High (8.1)

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66373
(7.5 HIGH)

EPSS: 0.47%

updated 2026-07-25T03:30:55

1 posts

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.

thehackerwire@mastodon.social at 2026-07-25T03:00:05.000Z ##

🟠 CVE-2026-66373 - High (7.5)

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both cons...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62835
(9.3 CRITICAL)

EPSS: 1.03%

updated 2026-07-25T02:16:39.663000

3 posts

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

offseq@infosec.exchange at 2026-07-25T01:30:24.000Z ##

CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at radar.offseq.com/threat/cve-20 #OffSeq #Azure #Vuln #CloudSecurity

##

thehackerwire@mastodon.social at 2026-07-24T22:01:11.000Z ##

🔴 CVE-2026-62835 - Critical (9.3)

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DarkWebInformer@infosec.exchange at 2026-07-24T20:45:57.000Z ##

🚨 CVE-2026-62835: Microsoft Azure Portal Information Disclosure Vulnerability

CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.

CVSS: 9.3

More information: msrc.microsoft.com/update-guid

##

CVE-2026-61884
(9.8 CRITICAL)

EPSS: 0.66%

updated 2026-07-25T00:31:53

2 posts

The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, dev

offseq@infosec.exchange at 2026-07-25T00:00:40.000Z ##

CVE-2026-61884 (CRITICAL, CVSS 9.8) in Tycon TPDIN-Monitor-WEB2 v2.3.9: Server-side auth validation missing — empty creds grant admin access. Restrict management interface, monitor for unauthorized logins. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoT #Infosec

##

thehackerwire@mastodon.social at 2026-07-24T23:00:11.000Z ##

🔴 CVE-2026-61884 - Critical (9.8)

The web management interface of Tycon Systems TPDIN-Monitor-WEB2

 does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can byp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-60134
(8.8 HIGH)

EPSS: 0.32%

updated 2026-07-25T00:31:53

1 posts

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

thehackerwire@mastodon.social at 2026-07-25T00:00:13.000Z ##

🟠 CVE-2026-60134 - High (8.8)

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61892
(8.8 HIGH)

EPSS: 0.27%

updated 2026-07-25T00:31:53

1 posts

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

thehackerwire@mastodon.social at 2026-07-25T00:00:02.000Z ##

🟠 CVE-2026-61892 - High (8.8)

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12497
(7.5 HIGH)

EPSS: 0.23%

updated 2026-07-24T21:33:30

1 posts

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some v

thehackerwire@mastodon.social at 2026-07-25T10:00:11.000Z ##

🟠 CVE-2026-12497 - High (7.5)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45811
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-24T21:33:30

1 posts

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket l

thehackerwire@mastodon.social at 2026-07-25T08:00:47.000Z ##

🟠 CVE-2026-45811 - High (7.5)

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.
The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer ove...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66144
(7.5 HIGH)

EPSS: 0.48%

updated 2026-07-24T21:33:30

1 posts

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.

thehackerwire@mastodon.social at 2026-07-25T06:00:17.000Z ##

🟠 CVE-2026-66144 - High (7.5)

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66143
(7.5 HIGH)

EPSS: 0.51%

updated 2026-07-24T21:33:30

1 posts

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

thehackerwire@mastodon.social at 2026-07-25T06:00:07.000Z ##

🟠 CVE-2026-66143 - High (7.5)

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12981
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-24T21:33:29

1 posts

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.

thehackerwire@mastodon.social at 2026-07-25T10:59:50.000Z ##

🟠 CVE-2026-12981 - High (7.5)

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12877
(9.1 CRITICAL)

EPSS: 0.24%

updated 2026-07-24T21:33:29

1 posts

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.

thehackerwire@mastodon.social at 2026-07-25T10:00:21.000Z ##

🔴 CVE-2026-12877 - Critical (9.1)

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is expl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45816
(7.5 HIGH)

EPSS: 0.61%

updated 2026-07-24T21:33:29

1 posts

NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

thehackerwire@mastodon.social at 2026-07-25T08:00:36.000Z ##

🟠 CVE-2026-45816 - High (7.5)

NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.

This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.

This...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66039
(8.8 HIGH)

EPSS: 0.42%

updated 2026-07-24T21:32:28

1 posts

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_fra

thehackerwire@mastodon.social at 2026-07-24T22:01:01.000Z ##

🟠 CVE-2026-66039 - High (8.8)

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66036
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-24T21:32:28

1 posts

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() a

thehackerwire@mastodon.social at 2026-07-24T22:00:24.000Z ##

🟠 CVE-2026-66036 - High (8.8)

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66040
(8.8 HIGH)

EPSS: 0.55%

updated 2026-07-24T21:32:28

1 posts

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output

thehackerwire@mastodon.social at 2026-07-24T22:00:03.000Z ##

🟠 CVE-2026-66040 - High (8.8)

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14603
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-24T20:48:39.923000

1 posts

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.

thehackerwire@mastodon.social at 2026-07-25T10:00:01.000Z ##

🟠 CVE-2026-14603 - High (7.5)

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49745
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-24T18:32:33

1 posts

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.

thehackerwire@mastodon.social at 2026-07-25T09:00:25.000Z ##

🟠 CVE-2026-49745 - High (7.8)

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.

Software installed and run under a Guest VM can send commands to the G...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16800
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-24T18:32:33

1 posts

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.

thehackerwire@mastodon.social at 2026-07-25T05:00:14.000Z ##

🟠 CVE-2026-16800 - High (8.8)

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via craf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49744
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-24T18:32:32

1 posts

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.

thehackerwire@mastodon.social at 2026-07-25T09:00:15.000Z ##

🟠 CVE-2026-49744 - High (7.8)

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.

Out of bounds accesses triggered by malware introduced to a Guest KMD ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16801
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-24T18:32:32

1 posts

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.

thehackerwire@mastodon.social at 2026-07-25T05:00:04.000Z ##

🟠 CVE-2026-16801 - High (8.8)

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a craf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65709
(8.3 HIGH)

EPSS: 0.22%

updated 2026-07-24T18:31:41

1 posts

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without Account

thehackerwire@mastodon.social at 2026-07-24T20:01:19.000Z ##

🟠 CVE-2026-65709 - High (8.3)

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without pe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66033
(7.5 HIGH)

EPSS: 0.39%

updated 2026-07-24T18:31:41

1 posts

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to

thehackerwire@mastodon.social at 2026-07-24T18:00:20.000Z ##

🟠 CVE-2026-66033 - High (7.5)

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AE...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65708
(8.1 HIGH)

EPSS: 0.22%

updated 2026-07-24T18:31:37

1 posts

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorization checks in AccountFileController. Attackers can supply arbitrary numeric file IDs through the download, view, delete, upload, and list actions

thehackerwire@mastodon.social at 2026-07-24T20:01:09.000Z ##

🟠 CVE-2026-65708 - High (8.1)

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing au...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66032
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-24T18:31:37

1 posts

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call retur

thehackerwire@mastodon.social at 2026-07-24T18:00:10.000Z ##

🟠 CVE-2026-66032 - High (8.8)

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66027
(8.3 HIGH)

EPSS: 0.26%

updated 2026-07-24T17:17:34.993000

1 posts

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's sess

thehackerwire@mastodon.social at 2026-07-24T16:59:50.000Z ##

🟠 CVE-2026-66027 - High (8.3)

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16807
(8.8 HIGH)

EPSS: 0.26%

updated 2026-07-24T15:34:00

1 posts

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T13:59:50.000Z ##

🟠 CVE-2026-16807 - High (8.8)

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16805
(8.8 HIGH)

EPSS: 0.31%

updated 2026-07-24T15:34:00

1 posts

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T13:00:03.000Z ##

🟠 CVE-2026-16805 - High (8.8)

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16804
(8.3 HIGH)

EPSS: 0.25%

updated 2026-07-24T15:34:00

1 posts

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T12:59:53.000Z ##

🟠 CVE-2026-16804 - High (8.3)

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8789
(8.1 HIGH)

EPSS: 0.22%

updated 2026-07-24T15:33:10

1 posts

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary connection records from the `

thehackerwire@mastodon.social at 2026-07-24T17:00:27.000Z ##

🟠 CVE-2026-8789 - High (8.1)

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58630
(10.0 CRITICAL)

EPSS: 0.81%

updated 2026-07-24T15:33:09

3 posts

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-07-25T06:00:25.000Z ##

CVE-2026-58630: Improper access control in Azure App Service for Linux (CVSS 10, CRITICAL) lets remote attackers escalate privileges with no auth or user action. Patched by Microsoft — verify updates. Details: radar.offseq.com/threat/cve-20 #OffSeq #Azure #Infosec #CVE2026_58630

##

DarkWebInformer@infosec.exchange at 2026-07-24T19:09:34.000Z ##

‼️ CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

CVSS: 10

Details: msrc.microsoft.com/update-guid

##

thehackerwire@mastodon.social at 2026-07-24T17:00:38.000Z ##

🔴 CVE-2026-58630 - Critical (10)

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57106
(10.0 CRITICAL)

EPSS: 0.92%

updated 2026-07-24T15:33:03

2 posts

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-07-25T07:30:24.000Z ##

Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #SSRF #Microsoft #CyberSec

##

thehackerwire@mastodon.social at 2026-07-24T17:00:48.000Z ##

🔴 CVE-2026-57106 - Critical (10)

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66140
(8.4 HIGH)

EPSS: 0.27%

updated 2026-07-24T06:34:11

1 posts

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

thehackerwire@mastodon.social at 2026-07-25T11:00:00.000Z ##

🟠 CVE-2026-66140 - High (8.4)

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62144
(9.1 CRITICAL)

EPSS: 20.62%

updated 2026-07-24T05:16:45.793000

1 posts

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a conf

1 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-47668
(10.0 CRITICAL)

EPSS: 4.34%

updated 2026-07-24T05:16:44.947000

1 posts

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed

Nuclei template

1 repos

https://github.com/Nxploited/CVE-2026-47668

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-35425
(8.0 HIGH)

EPSS: 0.48%

updated 2026-07-24T03:32:01

1 posts

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-07-25T12:00:43.000Z ##

🟠 CVE-2026-35425 - High (8)

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54120
(9.9 CRITICAL)

EPSS: 0.71%

updated 2026-07-24T03:31:56

2 posts

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-07-25T12:00:23.000Z ##

🔴 CVE-2026-54120 - Critical (9.9)

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-24T13:30:30.000Z ##

CVE-2026-54120 (CRITICAL, CVSS 9.9): Improper input validation in Microsoft Surface Management Services lets authorized attackers run code remotely. Patch now: radar.offseq.com/threat/cve-20 🖥️ #OffSeq #infosec #Microsoft #CVE202654120

##

CVE-2026-56167
(8.5 HIGH)

EPSS: 0.38%

updated 2026-07-24T03:31:56

1 posts

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-07-25T11:00:10.000Z ##

🟠 CVE-2026-56167 - High (8.5)

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42933
(10.0 CRITICAL)

EPSS: 0.29%

updated 2026-07-24T00:32:40

2 posts

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.

DailyCyberSecurity at 2026-07-28T14:04:40.526Z ##

A Panduit IntraVUE vulnerability tracked as CVE-2026-42933 scores CVSS 10. Five flaws let attackers cross OT segmentation and steal credentials.

securityonline.info/panduit-in

##

DailyCyberSecurity@infosec.exchange at 2026-07-28T14:04:40.000Z ##

A Panduit IntraVUE vulnerability tracked as CVE-2026-42933 scores CVSS 10. Five flaws let attackers cross OT segmentation and steal credentials.

#PanduitIntraVUE #CVE202642933 #ICSSecurity #OTSecurity

securityonline.info/panduit-in

##

CVE-2026-6516
(10.0 CRITICAL)

EPSS: 4.73%

updated 2026-07-23T18:31:54

1 posts

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 57.10%

updated 2026-07-23T15:44:10.873000

4 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

3 repos

https://github.com/HORKimhab/CVE-2026-50522

https://github.com/ChPratik/CVE-2026-50522

https://github.com/4minx/CVE-2026-50522

beyondmachines1@infosec.exchange at 2026-07-27T19:01:42.000Z ##

State of (in)security - Week 30, 2026

During week 30 of 2026, cybersecurity monitoring recorded 7 advisories and 28 incidents/breaches affecting roughly 80 million individuals. The largest breach is Suno exposing 55.3 million users and AI training source code. Malware/ransomware and unauthorized access are the leading causes of incidents and healthcare and IT/software as the most-targeted industries.

**Patch the actively exploited on-premises SharePoint (CVE-2026-50522), self-hosted ServiceNow, Fastjson 1.x Java apps, Oracle systems (July 2026 Critical Patch Update), and WordPress. Then update Firefox and Thunderbird and confirm your Adobe Acrobat Chrome extension is running version 26.5.2.3 or later.**
#cybersecurity #infosec #knowledge #weeklyreport
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-07-26T15:21:30.000Z ##

🏆 New Achievement! Stand In the Fire, Lose the SharePoint!

MOVE OUT OF THE DESERIALIZATION FLAW. I AM NOT KIDDING. CVE-2026-50522 is a CVSS 9.8 critical hole in on-premises Microsoft SharePoint — remote code execution, low complexity, no special system knowledge required. Researchers at watchTowr and Defused are screaming in chat right now because exploit code just dropped and attackers are already in your server. (1/2)

##

thecybermind@infosec.exchange at 2026-07-25T05:35:48.000Z ##

Active exploitation verified for CVE-2026-50522. Microsoft SharePoint's deserialization flaw demands immediate C-Suite oversight, patch prioritization, and strict endpoint hardening. Protect your enterprise assets today. thecybermind.co/kc88

##

thecybermind@infosec.exchange at 2026-07-24T15:22:59.000Z ##

(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data....

thecybermind.co/2026/07/24/cis

##

CVE-2026-16723
(9.0 CRITICAL)

EPSS: 0.41%

updated 2026-07-23T15:01:24.377000

5 posts

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

3 repos

https://github.com/HORKimhab/CVE-2026-16723

https://github.com/dinosn/fastjson-jsontype-rce-lab

https://github.com/why-success/fastjson-rce-lab

threatnoir@infosec.exchange at 2026-07-27T08:06:02.000Z ##

⚠️ CRITICAL: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Attackers are actively exploiting CVE-2026-16723, a critical RCE in Alibaba Fastjson 1.x used by Spring Boot applications. Unauthenticated code execution is possible with Java process privileges. No patch exists for 1.x versions yet.

threatnoir.com/focus

#infosec #cybersecurity

##

security_crawler_carl@infosec.exchange at 2026-07-26T12:49:23.000Z ##

🏆 New Achievement! Critical Hit: JSON and the Argonauts!

You have looted a CURSED ITEM: Fastjson 1.x (versions 1.2.68–1.2.83). Equip penalty: unauthenticated attackers may now execute arbitrary code on your Spring Boot applications via crafted JSON requests, bypassing default security configurations entirely. CVE-2026-16723 is active in the wild, no patch exists for the 1.x branch, and yes, that means you.

Inventory is full of regret. (1/2)

##

obivan@infosec.exchange at 2026-07-26T10:57:36.000Z ##

FastJson 1.2.83 RCE (CVE-2026-16723) fearsoff.org/research/fastjson

##

beyondmachines1@infosec.exchange at 2026-07-26T10:01:41.000Z ##

Critical Fastjson 1.x Zero-Day RCE Exploited in the Wild

Alibaba's Fastjson 1.x library is vulnerable to a critical zero-day remote code execution flaw (CVE-2026-16723) that is currently exploited in the wild against Spring Boot applications. The vulnerability allows unauthenticated attackers to run arbitrary code by bypassing default security configurations through crafted JSON requests.

**If you run Java apps using Fastjson 1.x (versions 1.2.68–1.2.83) as Spring Boot fat-JARs, your applications are actively attacked, and there is no patch for the 1.x branch. Migrate to Fastjson2 ASAP. If you can't migrate, immediately enable SafeMode by adding `-Dfastjson.parser.safeMode=true` to your JVM settings and monitor your logs for unusual `@type` values or unexpected outbound connections from Java.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-07-25T02:24:01.000Z ##

FastJson RCE vulnerability CVE-2026-16723 is exploited in the wild. Details and PoC exploit code are public for this critical remote code execution flaw.

#FastJson #CVE202616723 #RCE #ZeroDay

securityonline.info/fastjson-r

##

CVE-2026-46331
(7.8 HIGH)

EPSS: 0.53%

updated 2026-07-23T12:18:18.287000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb

13 repos

https://github.com/g0thamRabb1t/CVE-2026-46331-pedit-COW-detection

https://github.com/rjt-gupta/page-cache-corruption-lpes

https://github.com/cherrycherrymay/PoC-CVE-2026-46331

https://github.com/sgkdev/packet_edit_meme

https://github.com/vulnquest58/dirtyclone-exploit

https://github.com/MarwahHadi/CVE-2026-46331-pedit-cow

https://github.com/V0IDNETWORK/CVE-2026-46331

https://github.com/yanxinwu946/CVE-2026-46331

https://github.com/0xBlackash/CVE-2026-46331

https://github.com/douglasmun/pagecache-lpe-containment-kit

https://github.com/Quaerendir/cve-2026-46331-audit

https://github.com/HORKimhab/CVE-2026-46331

https://github.com/seguridadentrerios/CVE-2026-46331

CVE-2026-63030
(9.8 CRITICAL)

EPSS: 98.05%

updated 2026-07-22T23:10:00.110000

2 posts

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Nuclei template

70 repos

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/ekomsSavior/wp2shell

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/fullhunt/wp2shell-scan

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/gbrsh/CVE-2026-63030

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/mverschu/CVE-2026-63030

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/imXur/WordPress-CVE-2026-63030-Analysis

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/mhtsec/CVE-2026-63030

https://github.com/bahartanir/wp2shell-scanner

https://github.com/yuag/wp2shell

https://github.com/vulnquest58/PressVector

https://github.com/0xWhoknows/wp2shell

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/mcipekci/wp2shell

https://github.com/0xsha/wp2shell

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/securelayer7/WordPresShell

https://github.com/Crypto-Cat/wp2shell

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/ananay/wp2shell-lab

https://github.com/Icex0/wp2shell-poc

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/ikow/wp2shell

https://github.com/h4cd0c/wp2shell

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/dinosn/wp2shell-lab

https://github.com/InstaWP/wp2shell-scan

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/zi3lak/wp2shell_scanner

https://github.com/0xjessie21/wp2shell-checker

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/shinthink/CVE-2026-63030

https://github.com/4minx/CVE-2026-63030

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/kulichr/wp2shell

https://github.com/Iqbalx7/wp2shell

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/c0gnit00/Wp2Shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/NULL200OK/WP2Shell

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/47Cid/wp2shell-lab

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/attackercan/wp2shell-poc2

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/Senanfurkan/wordpress-cve-2026-63030

stux@mstdn.social at 2026-07-27T13:21:48.000Z ##

Holy shit

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."

github.com/Icex0/wp2shell-poc

#WordPress #RCE

##

termsofsurrender@mastodon.social at 2026-07-25T05:51:58.000Z ##

WordPress Gets RCE’d, and the Internet Pretends This Wasn’t Predictable
PANIC 82% | Lag 0.0h | wp2shell is an exploited WordPress Core remote code execution chain involving CVE-2026-63030 and CVE
#AfterShockIndex

Read: hodl.cz/as-116463

##

CVE-2026-15342
(6.5 MEDIUM)

EPSS: 0.22%

updated 2026-07-22T21:33:00

1 posts

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying that the requester is a member

CVE-2026-13072
(8.1 HIGH)

EPSS: 0.32%

updated 2026-07-22T21:32:15

1 posts

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This configuration is non-default and requires explicit enablement at startup.

beyondmachines1@infosec.exchange at 2026-07-27T15:01:42.000Z ##

MongoDB Patches 26 Vulnerabilities Including Critical Memory Corruption Flaw

MongoDB released security updates to fix 26 vulnerabilities, including a critical memory corruption flaw (CVE-2026-13072) and multiple high-severity issues that allow unauthorized data access and service crashes.

**If you run self-hosted MongoDB, update your servers now to the latest patched version (7.0.39, 8.0.28, 8.2.12, 8.3.7, or 9.0.0-rc1). There's a critical flaw that could let attackers crash your database or run their own code. If you use MongoDB Atlas or another managed service, you're already covered and don't need to do anything.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-16232
(9.1 CRITICAL)

EPSS: 12.68%

updated 2026-07-22T21:32:05

3 posts

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server I

1 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

DailyCyberSecurity@infosec.exchange at 2026-07-26T15:30:52.000Z ##

Discover the critical CVE-2026-16232 vulnerability in Check Point Security Management servers, allowing remote attackers to gain full administrative privileges without a password.

#CheckPoint #CyberSecurity #CVE202616232 #NetworkSecurity #Vulnerability

meterpreter.org/check-point-se

##

DarkWebInformer@infosec.exchange at 2026-07-24T19:30:19.000Z ##

‼️ CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

CVSS: 9.1

Scanner: github.com/WadesWeaponShed/Che

Details and Mitigation: support.checkpoint.com/results

##

CVE-2026-8933
(7.8 HIGH)

EPSS: 0.21%

updated 2026-07-22T19:17:14.773000

1 posts

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or secur

security_crawler_carl@infosec.exchange at 2026-07-25T11:12:26.000Z ##

CVE-2026-8933, lovingly documented by the Qualys Threat Research Unit, lets a local user squeeze through that gap, drop a malicious AppArmor rules file, prod systemd-udevd into running commands as root, and collect full root access like a door prize. Ubuntu Desktop 24.04, 25.10, and 26.04 ship this by default. It is a trap room with the pressure plate installed by the architect. (2/3)

##

CVE-2026-53359
(8.8 HIGH)

EPSS: 0.91%

updated 2026-07-22T19:07:43.103000

2 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. Th

6 repos

https://github.com/chuzhongyun/CVE-2026-53359-Kernel-Fix

https://github.com/HORKimhab/CVE-2026-53359

https://github.com/ndouglas-cloudsmith/CVE-2026-53359

https://github.com/0xBlackash/CVE-2026-53359

https://github.com/Aoripus-LTD/Januscape-Hotfix

https://github.com/xj2268-TA/KVM-Januscape

sayzard@mastodon.sayzard.org at 2026-07-28T16:43:18.000Z ##

Lessons learned from handling a KVM flaw on tens of thousands of machines

OVHcloud는 Linux KVM x86의 shadow paging use-after-free 취약점(CVE-2026-53359)에 대응해 수만 대의 하이퍼바이저와 약 100만 VM을 대상으로 일주일간 패치 캠페인을 수행한 운영 사례를 공개했다. 취약점은 해제된 페이지를 RMAP이 참조하는 문제로, 악성 테넌트가 호스트를 크래시시키거나 최악의 경우 호스트 권한 상승을 유발할 수 있으며, 내부 재현에서는 미패치 호스트가 약 2분 내 크래시했다. OVHcloud는 라이브 패치, nested virtualiza...

blog.ovhcloud.com/en/posts/cve

##

benoit@benoit.jp.net at 2026-07-25T12:29:58.000Z ##

I wonder how many hosters are vulnerable to CVE-2026-53359 (Januscape). Probably a lot.

##

CVE-2026-49176
(7.8 HIGH)

EPSS: 0.40%

updated 2026-07-22T16:17:28.753000

2 posts

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

1 repos

https://github.com/DavidCarliez/CVE-2026-49176_LPE_POC

CVE-2026-62145
(7.5 HIGH)

EPSS: 7.54%

updated 2026-07-22T15:31:34

1 posts

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

1 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-8985(CVSS UNKNOWN)

EPSS: 4.19%

updated 2026-07-22T00:32:44

1 posts

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-64606
(9.8 CRITICAL)

EPSS: 0.63%

updated 2026-07-21T21:33:35

1 posts

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.

CVE-2026-64879
(9.9 CRITICAL)

EPSS: 2.59%

updated 2026-07-21T21:32:47

1 posts

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

tugatech@masto.pt at 2026-07-28T16:03:08.000Z ##

Exploit público para a falha Certighost expôs domínios do Windows a controlo total. Uma nova vulnerabilidade, rastreada como CVE-2026-54121, coloca redes empresariais em risco e permite que um atacante assuma o controlo completo de um domínio informático. 🚨

🔗 tugatech.com.pt/t88205-exploit

#controlo #exploit #falha #windows 

##

tugatech@masto.pt at 2026-07-28T16:03:08.000Z ##

Exploit público para a falha Certighost expôs domínios do Windows a controlo total. Uma nova vulnerabilidade, rastreada como CVE-2026-54121, coloca redes empresariais em risco e permite que um atacante assuma o controlo completo de um domínio informático. 🚨

🔗 tugatech.com.pt/t88205-exploit

#controlo #exploit #falha #windows 

##

obivan@infosec.exchange at 2026-07-27T18:24:41.000Z ##

CertiGhost fork - Patched SAN handling + MAQ-safe account reuse github.com/marcgoam/CVE-2026-5

##

al3x-n3ff.bsky.social@bsky.brid.gy at 2026-07-26T17:51:24.488Z ##

Detect the Certighost with NetExec🔥

Thanks to Xed_sama, the enum_cve module of NetExec will now detect if a host has not been patched and is potentially vulnerable to the Certighost vulnerability (CVE-2026-54121)🚀

##

guru@thecybersecguru.com at 2026-07-26T05:47:01.000Z ##

Certighost Exploit Allows Low-Privileged Active Directory Users to Impersonate a Domain Controller

A newly disclosed AD CS vulnerability, Certighost (CVE-2026-54121), allows low-privileged domain users to impersonate a Domain Controller

thecybersecguru.com/news/certi

##

benzogaga33@mamot.fr at 2026-07-25T09:40:03.000Z ##

Certighost (CVE-2026-54121) : un compte AD standard suffit pour usurper un contrôleur de domaine it-connect.fr/certighost-cve-2 #ActuCybersécurité #ActiveDirectory #Cybersécurité #Vulnérabilité #Microsoft

##

threatnoir@infosec.exchange at 2026-07-25T07:05:43.000Z ##

⚠️ CRITICAL: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Certighost (CVE-2026-54121) allows any domain user to obtain a Domain Controller certificate and execute DCSync attacks to steal the krbtgt secret without admin rights. This gives attackers a direct path to full domain compromise. Any organization running unpatched Active Directory is at immediate…

threatnoir.com/focus

#infosec #cybersecurity

##

DarkWebInformer@infosec.exchange at 2026-07-24T19:55:21.000Z ##

‼️ PoC released for CVE-2026-54121 codenamed Certighost

CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.

GitHub: github.com/aniqfakhrul/cve-202

##

AAKL@infosec.exchange at 2026-07-24T15:49:06.000Z ##

New.

GitHub/H0j3n: Certighost (CVE-2026-54121) gist.github.com/H0j3n/a5ef2609

More:

The Hacker News: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller thehackernews.com/2026/07/cert @thehackernews #infosec #vulnerability #Microsoft #Windows

##

CVE-2026-40510
(3.8 LOW)

EPSS: 0.22%

updated 2026-07-21T12:10:00.090000

4 posts

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field longer than 118 bytes in the Key History Object ASN.1 response.

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-63108
(8.8 HIGH)

EPSS: 1.92%

updated 2026-07-20T21:31:57

1 posts

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts replaces parameter expansions with opaque placeholders before extracting command substitutions, causing the containsDangerous

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-63766
(9.8 CRITICAL)

EPSS: 1.75%

updated 2026-07-20T21:31:57

1 posts

GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attackers can inject shell metacharacters through path parameters to execute arbitrary OS commands as the server process user without authentication.

1 repos

https://github.com/0xdak/CVE-2026-63766_exploit

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-2291
(7.3 HIGH)

EPSS: 0.92%

updated 2026-07-20T21:31:40

4 posts

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

1 repos

https://github.com/JianrongXiao-Linksys/dnsmasq-cve-2026

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-54298
(4.2 MEDIUM)

EPSS: 0.23%

updated 2026-07-18T17:25:06

1 posts

## Summary The `spreadAttributes` function in Astro's server-side rendering pipeline iterates over object keys and passes them directly to `addAttribute`, which interpolates the key into the HTML output without escaping. When a developer uses the spread syntax `{...props}` on an HTML element and the object keys come from an untrusted source (API, CMS, URL parameters), an attacker can inject arbit

EUVD_Bot@mastodon.social at 2026-07-28T15:01:34.000Z ##

🚨 EUVD-2026-49580

📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: astro
🏢 Vendor: withastro
📅 Published: 2026-07-27 | Updated: 2026-07-28

📝 Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped spread attribute names in renderHTMLElement. The fix for CVE-2026-54298 (GHSA-jrpj-wcv7-9fh9) added an INVALID_ATTR_...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-53362
(7.8 HIGH)

EPSS: 0.27%

updated 2026-07-18T09:32:17

2 posts

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length +

CVE-2026-39808
(9.8 CRITICAL)

EPSS: 89.69%

updated 2026-07-17T05:16:38.870000

1 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Nuclei template

6 repos

https://github.com/error-inside/CVE-2026-39808

https://github.com/samu-delucas/CVE-2026-39808

https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808

https://github.com/0xBlackash/CVE-2026-39808

https://github.com/HORKimhab/CVE-2026-39808

https://github.com/Lechansky/CVE-2026-39808

thecybermind@infosec.exchange at 2026-07-25T06:08:41.000Z ##

(CISA TS-SOC) CVE-2026-39808 – Fortinet FortiSandbox OS Command Injection Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to execute unauthorized code or commands on the affected system via crafted HTTP requests....

thecybermind.co/2026/07/25/cis

##

CVE-2026-25089
(9.8 CRITICAL)

EPSS: 69.83%

updated 2026-07-16T18:32:24

1 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP req

2 repos

https://github.com/HORKimhab/CVE-2026-25089

https://github.com/0xBlackash/CVE-2026-25089

thecybermind@infosec.exchange at 2026-07-25T06:21:34.000Z ##

(CISA TS-SOC) CVE-2026-25089 – Fortinet FortiSandbox OS Command Injection Vulnerability

Severity: CRITICAL Impact Summary: Allows remote, unauthenticated attackers to execute arbitrary operating system commands on affected FortiSandbox products via HTTP....

thecybermind.co/2026/07/25/cis

##

CVE-2026-58644
(9.8 CRITICAL)

EPSS: 5.06%

updated 2026-07-16T18:31:26

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

thecybermind@infosec.exchange at 2026-07-25T06:16:56.000Z ##

(CISA TS-SOC) CVE-2026-58644 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data....

thecybermind.co/2026/07/18/__t

##

CVE-2026-42530
(8.1 HIGH)

EPSS: 3.68%

updated 2026-07-16T12:17:51.630000

1 posts

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers

3 repos

https://github.com/v4ltonn/CVE-2026-42530

https://github.com/HORKimhab/CVE-2026-42530

https://github.com/0xBlackash/CVE-2026-42530

CVE-2023-4346
(7.5 HIGH)

EPSS: 0.91%

updated 2026-07-16T05:16:16.603000

1 posts

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to i

thecybermind@infosec.exchange at 2026-07-25T17:04:55.000Z ##

(CISA TS-MAN) CVE-2023-4346 – KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

Severity: HIGH Impact Summary: An attacker could purge all devices and set a BCU key to lock the device, potentially resulting in denial of service if additional security options are not enabled....

thecybermind.co/2026/07/25/cis

##

CVE-2026-46817
(9.8 CRITICAL)

EPSS: 13.31%

updated 2026-07-15T18:32:50

1 posts

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Con

2 repos

https://github.com/0xBlackash/CVE-2026-46817

https://github.com/HORKimhab/CVE-2026-46817

thecybermind@infosec.exchange at 2026-07-25T17:07:36.000Z ##

(CISA TS-MAN) CVE-2026-46817 – Oracle E-Business Suite Improper Privilege Management Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attacker to compromise Oracle Payments, potentially resulting in full takeover....

thecybermind.co/2026/07/25/cis

##

CVE-2026-42533
(8.1 HIGH)

EPSS: 3.60%

updated 2026-07-15T15:33:14

4 posts

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyon

8 repos

https://github.com/suominen/CVE-2026-42533

https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report

https://github.com/Daniyal48/ghostlock-vagrant-box

https://github.com/srkyn/nginx-map-risk-audit

https://github.com/gagaltotal/CVE-2026-42533-nginx

https://github.com/imbas007/CVE-2026-42533

https://github.com/seguridadentrerios/CVE-2026-42533

https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner

DailyCyberSecurity at 2026-07-28T13:03:40.991Z ##

A public PoC now details CVE-2026-42533, an NGINX heap overflow with an ASLR bypass and possible RCE. Upgrade to NGINX 1.31.3 or 1.30.4 now.

securityonline.info/nginx-heap

##

DailyCyberSecurity@infosec.exchange at 2026-07-28T13:03:40.000Z ##

A public PoC now details CVE-2026-42533, an NGINX heap overflow with an ASLR bypass and possible RCE. Upgrade to NGINX 1.31.3 or 1.30.4 now.

#NGINX #CVE202642533 #RCE #HeapOverflow #ASLRBypass #NGINXPlus #PoC #Cybersecurity

securityonline.info/nginx-heap

##

obivan@infosec.exchange at 2026-07-26T11:05:33.000Z ##

PoC's for nginx RCE (CVE-2026-42530, CVE-2026-42533) github.com/DepthFirstDisclosur

##

ChrisShort@hachyderm.io at 2026-07-24T15:29:13.000Z ##

15-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533 – cyberstan #devopsish cyberstan.co.uk/nginx-rce/

##

CVE-2026-56155
(7.8 HIGH)

EPSS: 2.33%

updated 2026-07-14T21:32:52

1 posts

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

thecybermind@infosec.exchange at 2026-07-25T16:43:09.000Z ##

(CISA TS-MAN) CVE-2026-56155 – Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Severity: HIGH Impact Summary: Allows an authorized attacker to locally elevate privileges due to insufficient granularity of access control....

thecybermind.co/2026/07/25/cis

##

CVE-2026-15410
(7.2 HIGH)

EPSS: 76.35%

updated 2026-07-14T21:32:21

1 posts

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

3 repos

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/HORKimhab/CVE-2026-15410

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

thecybermind@infosec.exchange at 2026-07-26T17:26:03.000Z ##

🚨 Active Exploit Warning: SonicWall SMA1000 appliances are under fire from a high-severity code injection flaw (CVE-2026-15410). Our latest TSUITE brief breaks down the CrowdStrike detection logic and immediate hardening steps to secure your management interfaces. Command the wire: thecybermind.co/jily

#SOC

##

CVE-2026-50502
(8.0 HIGH)

EPSS: 0.60%

updated 2026-07-14T18:32:33

1 posts

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

DailyCyberSecurity@infosec.exchange at 2026-07-27T13:34:15.000Z ##

Microsoft has patched a critical Windows Event Logging vulnerability (CVE-2026-50502) allowing remote code execution. Update your systems immediately.

#Microsoft #Vulnerability #CyberSecurity #WindowsServer #CVE202650502

meterpreter.org/windows-event-

##

CVE-2026-50454
(7.8 HIGH)

EPSS: 0.44%

updated 2026-07-14T18:32:32

1 posts

Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

CVE-2026-53264
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-08T06:31:34

2 posts

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is possible to create a race with an associated action. Let's illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER: 0: mutex_lock() <-- holds the idr lock 0: rcu_read_lock() 0: p = idr_f

1 repos

https://github.com/HORKimhab/CVE-2026-53264

Analyst207@mastodon.social at 2026-07-28T15:25:42.000Z ##

AI-Assisted Research Exposes Linux Kernel Zero-Day Flaw

Researchers have uncovered a long-standing vulnerability in the Linux kernel, known as CVE-2026-53264, which allows a local user to gain root privileges by exploiting a flaw in the packet-scheduling code. This zero-day flaw was identified with the help of AI-assisted research and has since been patched.

osintsights.com/ai-assisted-re

#LinuxKernel #ZeroDay #AiassistedResearch #StarLabs #Cve202653264

##

Analyst207@mastodon.social at 2026-07-28T09:25:28.000Z ##

AI-Assisted Linux Exploit Turns Local Users into Root

Researchers have uncovered a significant Linux exploit, CVE-2026-53264, that can turn local users into root users, highlighting the importance of human judgement in AI-assisted security work. This flaw, patched in June 2026, shows AI still has limitations, emphasizing the need for human oversight.

osintsights.com/ai-assisted-li

#LinuxExploit #Cve202653264 #LocalPrivilegeEscalation #AiassistedExploit #StarLabs

##

CVE-2026-55255
(8.4 HIGH)

EPSS: 29.05%

updated 2026-07-07T22:14:37

1 posts

## Summary Insecure Direct Object Reference (IDOR) vulnerability in `/api/v1/responses` endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. ## Details The vulnerability exists in the `get_flow_by_id_or_endpoint_name` helper function in [`src/backend/base/langflow/helpers/flow.py` (lines 399-414)](https://gith

1 repos

https://github.com/rootdirective-sec/CVE-2026-55255-Lab

thecybermind@infosec.exchange at 2026-07-25T17:06:29.000Z ##

(CISA TS-MAN) CVE-2026-55255 – Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Severity: HIGH Impact Summary: An authenticated attacker can execute any flow belonging to another user by specifying the victim's flow ID in the request, bypassing authorization controls....

thecybermind.co/2026/07/25/cis

##

CVE-2026-5172
(7.3 HIGH)

EPSS: 2.68%

updated 2026-06-30T03:37:45

4 posts

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

2 repos

https://github.com/JianrongXiao-Linksys/dnsmasq-cve-2026

https://github.com/lottiedeyan/CVE20265172poc

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-42945
(8.1 HIGH)

EPSS: 61.47%

updated 2026-06-27T06:30:25

2 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond it

42 repos

https://github.com/simota/nginx-rift-scanner

https://github.com/F2u0a0d3/CVE-2026-42945-nginx-rift-poc

https://github.com/ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945

https://github.com/edgecases-PurpleHax/cve-images

https://github.com/BarAppTeam/nginx-cve-fix

https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC

https://github.com/nanwinata/nginxrift-CVE-2026-42945

https://github.com/0xBlackash/CVE-2026-42945

https://github.com/oseasfr/Scanner_CVE_2026-42945

https://github.com/sec-sys/CVE-2026-42945-Reverse-Shell-POC

https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab

https://github.com/forxiucn/nginx-cve-2026-42945-poc

https://github.com/iammerrida-source/nginx-rift-detect

https://github.com/rheodev/CVE-2026-42945

https://github.com/RedCrazyGhost/CVE-2026-42945

https://github.com/limo57640-crypto/nginx-rift-detector

https://github.com/imSre9/CVE-2026-42945

https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift

https://github.com/MateusVerass/nGixshell

https://github.com/realityone/cve-2026-42945-scan

https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945

https://github.com/tal7aouy/nginx-cve-2026-42945

https://github.com/nu0l/NGINX-Rift

https://github.com/hulina9900-boop/DIY-CVE-2026-42945-POC

https://github.com/dinosn/cve-2026-42945-nginx32-lab

https://github.com/quantumworld-dpdns-io/CVE-2026-42945

https://github.com/sibersan/web-server-audit_CVE-2026-42945

https://github.com/fkj-src/fix_nginx_cve_2026_42945

https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945

https://github.com/byezero/nginx-cve-2026-42945-check

https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script

https://github.com/cipherspy/CVE-2026-42945-POC

https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945

https://github.com/josephfelix/CVE-2026-42945-nginx-rift

https://github.com/strivepan/Nginx_cve-2026-42945-scanner-gui

https://github.com/yusufdalbudak/CVE-2026-42945

https://github.com/aratane/CVE-2026-42945

https://github.com/hnytgl/CVE-2026-42945

https://github.com/jelasin/CVE-2026-42945

https://github.com/azilRababe/CVE-2026-42945

https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit

https://github.com/chenqin231/CVE-2026-42945

security_crawler_carl@infosec.exchange at 2026-07-27T05:03:52.000Z ##

You do not get to respawn. The debuff is applied to all servers simultaneously. Enjoy your stay.

Patch NGINX now to address CVE-2026-42945 before the PoC makes your threat landscape significantly more crowded.

Reward: You've received the Mandatory Participation Trophy — it's just a heap of broken memory.

#Nginx #RCE #CyberSecurity #ZeroDay #BufferOverflow #ExploitUnlocked (2/2)

##

security_crawler_carl@infosec.exchange at 2026-07-27T05:03:51.000Z ##

🏆 New Achievement! Heap Today, Gone Tomorrow!

Welcome, new player, to the NGINX Rift tutorial! This mandatory onboarding introduces CVE-2026-42945, a critical heap buffer overflow in NGINX that enables remote code execution. A proof-of-concept exploit has now been published publicly, which means this mechanic is fully unlocked for every participant — including the ones you did not invite.

Think of it like Minecraft's Hardcore Mode, except the world was already on fire when you loaded in. (1/2)

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 2.26%

updated 2026-06-26T15:33:15

4 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

threatnoir@infosec.exchange at 2026-07-27T08:05:59.000Z ##

⚠️ CRITICAL: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p ransomware affiliates are actively exploiting unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM instances by chaining CVE-2026-12569 with a separate information disclosure flaw. Affected organizations in manufacturing, automotive, aerospace, and retail face data…

threatnoir.com/focus

#infosec #cybersecurity

##

threatcodex@infosec.exchange at 2026-07-26T18:35:42.000Z ##

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)
#Cl0p #CVE_2026_12569
ransom-isac.org/blog/clop-wind

##

threatnoir@infosec.exchange at 2026-07-26T05:15:05.000Z ##

2026-W30 — Weekly Threat Roundup

🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required.
🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da…

threatnoir.com/weekly/2026-w30

#infosec #cybersecurity #threatintel

##

kev_Stalker@infosec.exchange at 2026-07-25T04:14:10.000Z ##

CVE-2026-12569 - Changed to Known Ransomware Status

PTC Windchill and FlexPLM Improper Input Validation VulnerabilityVendor: PTCProduct: Windchill and FlexPLMPTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: July 24,nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-0160
(8.8 HIGH)

EPSS: 0.23%

updated 2026-06-17T18:36:29

2 posts

In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

0v1 at 2026-07-28T15:06:01.673Z ##

@drwhax also CVE-2026-0160 affecting RTT (US mandated). Reachability is via RTT call.

##

0v1@infosec.exchange at 2026-07-28T15:06:01.000Z ##

@drwhax also CVE-2026-0160 affecting RTT (US mandated). Reachability is via RTT call.

##

CVE-2026-0149
(8.8 HIGH)

EPSS: 0.29%

updated 2026-06-17T17:34:19.580000

2 posts

In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-69419
(7.4 HIGH)

EPSS: 0.44%

updated 2026-06-17T10:00:39.850000

4 posts

Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() functi

1 repos

https://github.com/Kha-Beleh/PoC-CVE-2025-69419

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-68160
(4.7 MEDIUM)

EPSS: 0.15%

updated 2026-06-17T09:58:39.407000

4 posts

Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filter (BIO_f_linebuffer) is not used

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2024-1813
(9.8 CRITICAL)

EPSS: 1.11%

updated 2026-06-17T07:05:03.993000

2 posts

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could al

1 repos

https://github.com/MobetaSec/CVE-2024-1813-POC

_r_netsec at 2026-07-28T14:13:04.847Z ##

Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) mobeta.fr/simple-job-board-una

##

_r_netsec@infosec.exchange at 2026-07-28T14:13:04.000Z ##

Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) mobeta.fr/simple-job-board-una

##

CVE-2013-4786
(7.5 HIGH)

EPSS: 81.80%

updated 2026-06-16T23:57:53.617000

5 posts

The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

1 repos

https://github.com/fin3ss3g0d/CosmicRakp

sayzard@mastodon.sayzard.org at 2026-07-28T16:37:58.000Z ##

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

Lava 연구진은 인터넷에 노출된 IPMI/BMC 호스트 36,872개 중 24,650개가 CVE-2013-4786으로 인해 오프라인 크래킹 가능한 인증 응답을 노출한다고 보고했다. 이 취약점은 공격자가 UDP 623 포트의 IPMI 인증 핸드셰이크를 악용해 비밀번호 해시 유래 정보를 수집한 뒤 GPU 등으로 크래킹할 수 있게 하며, 약한 기본 자격 증명과 결합될 경우 서버의 전원·펌웨어·가상 미디어를 제어할 수 있다. 특히 GPU 가상화·...

bleepingcomputer.com/news/secu

##

Analyst207@mastodon.social at 2026-07-28T15:25:38.000Z ##

IPMI Vulnerability Exposes 24,650 Server Management Interfaces

A recent security researcher found that over 30% of server management interface passwords can be easily cracked using common wordlists and factory default patterns, exposing a massive 24,650 interfaces to potential threats. This startling vulnerability, CVE-2013-4786, allows hackers to gain unauthorized access to…

osintsights.com/ipmi-vulnerabi

#IpmiVulnerability #Cve20134786 #ServerManagement #EmergingThreats #InformationDisclosure

##

Analyst207@mastodon.social at 2026-07-28T12:24:43.000Z ##

Decades-Old BMC Flaw Exposes 24,000 Servers to Password Cracking

A decades-old security flaw in Baseboard Management Controller (BMC) interfaces is putting over 24,000 internet-exposed servers at risk of password cracking, thanks to a vulnerability that allows attackers to capture and crack authentication responses. This two-decade-old weakness, tracked as CVE-2013-4786, is a pressing concern for server…

osintsights.com/decades-old-bm

#Bmc #Cve20134786 #Ipmi20 #PasswordCracking #ServerSecurity

##

hrbrmstr@mastodon.social at 2026-07-28T12:18:05.000Z ##

RE: infosec.exchange/@BleepingComp

The firm that provided the story to BC is a new startup aiming to help "Manage and Secure Data Centers".

They exploited CVE-2013-4786

This is advertising a new startup by flogging a report by extremely lazy "researchers" (did they even do *any* "is this a honeypot" tests?)

Perhaps don't let your C-suite give Lava any business?

##

hrbrmstr@mastodon.social at 2026-07-28T12:18:05.000Z ##

RE: infosec.exchange/@BleepingComp

The firm that provided the story to BC is a new startup aiming to help "Manage and Secure Data Centers".

They exploited CVE-2013-4786

This is advertising a new startup by flogging a report by extremely lazy "researchers" (did they even do *any* "is this a honeypot" tests?)

Perhaps don't let your C-suite give Lava any business?

##

CVE-2026-22795
(5.5 MEDIUM)

EPSS: 0.14%

updated 2026-05-12T15:32:20

4 posts

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-69421
(7.5 HIGH)

EPSS: 0.84%

updated 2026-05-12T15:31:14

4 posts

Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When

1 repos

https://github.com/Kha-Beleh/PoC-CVE-2025-69421

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-69420
(7.5 HIGH)

EPSS: 0.77%

updated 2026-05-12T15:31:14

4 posts

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to deref

1 repos

https://github.com/Kha-Beleh/PoC-CVE-2025-69420

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-22796
(5.3 MEDIUM)

EPSS: 0.50%

updated 2026-05-12T15:31:14

4 posts

Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data. Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attribu

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-69418
(4.0 None)

EPSS: 0.11%

updated 2026-05-12T15:31:14

4 posts

Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an

1 repos

https://github.com/x-stp/cves-2025-11187_15467_69418

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-4893
(5.3 MEDIUM)

EPSS: 2.68%

updated 2026-05-11T21:31:33

4 posts

An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.

5 repos

https://github.com/Polosss/By-Poloss..-..CVE-2026-48939

https://github.com/shinthink/CVE-2026-48939

https://github.com/lottiedeyan/CVE20264893poc

https://github.com/JianrongXiao-Linksys/dnsmasq-cve-2026

https://github.com/ChiefYoru/CVE-2026-48939_PoC

certvde at 2026-07-28T09:10:27.686Z ##

VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

weidmueller.csaf-tp.certvde.co

##

certvde at 2026-07-28T09:09:08.773Z ##

VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

ads-tec-iit.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-32194
(9.8 CRITICAL)

EPSS: 0.70%

updated 2026-03-20T00:31:34

1 posts

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

1 repos

https://github.com/HORKimhab/CVE-2026-32194

threatnoir@infosec.exchange at 2026-07-25T06:06:27.000Z ##

⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-32191
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-03-19T21:30:31

1 posts

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

threatnoir@infosec.exchange at 2026-07-25T06:06:27.000Z ##

⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2025-66376
(7.2 HIGH)

EPSS: 21.62%

updated 2026-03-18T18:31:10

1 posts

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

threatnoir@infosec.exchange at 2026-07-26T05:15:05.000Z ##

2026-W30 — Weekly Threat Roundup

🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required.
🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da…

threatnoir.com/weekly/2026-w30

#infosec #cybersecurity #threatintel

##

CVE-2025-29827
(9.9 CRITICAL)

EPSS: 1.25%

updated 2025-06-05T15:32:29

1 posts

Improper Authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

security_crawler_carl@infosec.exchange at 2026-07-26T16:52:38.000Z ##

By continuing to run Azure Automation with default settings, you hereby agree to the following terms: (1) your tenant identity may be made available to any registered Azure user who wishes to borrow it, (2) your credentials, cloud workloads, and data shall be considered shared resources, and (3) you waive all complaints regarding CVE-2025-29827, CVSS 9.9, which allowed any attacker with their own Azure Automation account to vault the trust boundary and impersonate another tenant entirely. (2/3)

##

CVE-2023-5217
(8.8 HIGH)

EPSS: 49.01%

updated 2024-02-15T15:02:28

2 posts

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

3 repos

https://github.com/Trinadh465/platform_external_libvpx_v1.4.0_CVE-2023-5217

https://github.com/UT-Security/cve-2023-5217-poc

https://github.com/Trinadh465/platform_external_libvpx_v1.8.0_CVE-2023-5217

nyanbinary at 2026-07-28T14:50:54.281Z ##

now to figure out if CVE-2023-5217 on our NAS actually matters...

##

nyanbinary@infosec.exchange at 2026-07-28T14:50:54.000Z ##

now to figure out if CVE-2023-5217 on our NAS actually matters...

##

CVE-2008-1028(CVSS UNKNOWN)

EPSS: 4.55%

updated 2023-01-31T05:05:55

1 posts

Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document file, as demonstrated by opening the document with TextEdit.

rosyna@mastodon.social at 2026-07-27T21:40:58.000Z ##

Apple was much more verbose in describing security issues in 2008 (look at CVE-2008-1028)
support.apple.com/en-ie/102486

##

Analyst207@mastodon.social at 2026-07-28T14:26:00.000Z ##

OpenWrt Fixes Critical DHCPv6 Flaw That Exposes Root Code Execution Risk

OpenWrt has patched a critical DHCPv6 flaw, known as CVE-2026-53921, that could allow an unauthenticated attacker to execute root code by sending a crafted request to the DHCPv6 server. This severe vulnerability, rated 9.8 out of 10, highlights the importance of updating your OpenWrt setup to prevent potential security breaches.

osintsights.com/openwrt-fixes-

#Cve202653921 #Openwrt #Dhcpv6 #Odhcpd #RootCodeExecution

##

CVE-2026-60137
(0 None)

EPSS: 77.97%

1 posts

N/A

45 repos

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/ekomsSavior/wp2shell

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/yuag/wp2shell

https://github.com/bahartanir/wp2shell-scanner

https://github.com/vulnquest58/PressVector

https://github.com/0xWhoknows/wp2shell

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/mcipekci/wp2shell

https://github.com/0xsha/wp2shell

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/securelayer7/WordPresShell

https://github.com/Crypto-Cat/wp2shell

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/Icex0/wp2shell-poc

https://github.com/ananay/wp2shell-lab

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/ikow/wp2shell

https://github.com/h4cd0c/wp2shell

https://github.com/dinosn/wp2shell-lab

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/zi3lak/wp2shell_scanner

https://github.com/0xjessie21/wp2shell-checker

https://github.com/shinthink/CVE-2026-63030

https://github.com/kulichr/wp2shell

https://github.com/northsia/CVE-2026-60137-With-Skip-SSL

https://github.com/Iqbalx7/wp2shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/NULL200OK/WP2Shell

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/47Cid/wp2shell-lab

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/Senanfurkan/wordpress-cve-2026-63030

stux@mstdn.social at 2026-07-27T13:21:48.000Z ##

Holy shit

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."

github.com/Icex0/wp2shell-poc

#WordPress #RCE

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T13:10:16.000Z ##

Discover how new Redis RCE exploit PoC code bypasses fixes for CVE-2026-25243 and CVE-2026-25589 across multiple Redis versions.

#Redis #Cybersecurity #RCE #Vulnerability #ExploitPoC

meterpreter.org/redis-rce-expl

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T13:10:16.000Z ##

Discover how new Redis RCE exploit PoC code bypasses fixes for CVE-2026-25243 and CVE-2026-25589 across multiple Redis versions.

#Redis #Cybersecurity #RCE #Vulnerability #ExploitPoC

meterpreter.org/redis-rce-expl

##

CVE-2026-16766
(0 None)

EPSS: 1.30%

1 posts

N/A

offseq@infosec.exchange at 2026-07-25T09:00:28.000Z ##

CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. radar.offseq.com/threat/cve-20 #OffSeq #infosec #perl #vuln

##

CVE-2026-48021
(0 None)

EPSS: 0.12%

2 posts

N/A

offseq@infosec.exchange at 2026-07-25T03:00:25.000Z ##

CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #HealthcareSecurity #Vuln #CVE202648021

##

thehackerwire@mastodon.social at 2026-07-24T20:00:12.000Z ##

🔴 CVE-2026-48021 - Critical (9.1)

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traff...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54342
(0 None)

EPSS: 0.12%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-24T20:00:02.000Z ##

🟠 CVE-2026-54342 - High (8.1)

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnek...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites