## Updated at UTC 2026-06-29T21:54:48.471913

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-13763 9.8 0.00% 4 0 2026-06-29T21:16:43.300000 Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer
CVE-2026-13762 9.8 0.00% 4 0 2026-06-29T21:16:43.183000 Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF
CVE-2026-48558 10.0 0.72% 7 0 2026-06-29T20:17:38.077000 SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an aut
CVE-2026-22078 7.3 0.09% 2 0 2026-06-29T19:07:03.733000 Because O+ Connect's IPC service does not authenticate clients, external applica
CVE-2025-2902 8.3 0.19% 2 0 2026-06-29T18:52:40.497000 Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual S
CVE-2026-13500 7.3 0.31% 1 0 2026-06-29T18:46:31.617000 A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unkn
CVE-2026-57346 7.1 0.00% 2 0 2026-06-29T18:39:20.080000 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v
CVE-2026-10083 7.5 0.16% 1 0 2026-06-29T15:33:13 The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache
CVE-2026-46331 7.8 0.23% 5 5 2026-06-29T15:32:00 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-32833 8.8 1.34% 1 0 2026-06-29T14:16:49.310000 Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command i
CVE-2026-13564 8.8 0.00% 2 0 2026-06-29T12:31:51 A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function fo
CVE-2026-13553 7.3 0.00% 1 0 2026-06-29T12:31:50 A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affect
CVE-2026-13601 7.1 0.00% 2 0 2026-06-29T12:31:50 A flaw was found in Yelp due to an overly permissive Content Security Policy (CS
CVE-2026-13539 8.8 0.47% 2 0 2026-06-29T09:30:32 A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impact
CVE-2026-13517 8.8 0.47% 1 0 2026-06-29T03:30:58 A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the fu
CVE-2026-13516 8.8 0.47% 1 0 2026-06-29T00:31:46 A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is
CVE-2026-13485 7.3 0.41% 1 0 2026-06-28T12:30:28 A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.
CVE-2026-55975 7.2 0.65% 1 0 2026-06-27T00:30:34 A vulnerability exists in H.View IP cameras that could allow an authenticated us
CVE-2026-48769 9.9 0.00% 1 0 2026-06-26T19:13:19 ### Summary An arbitrary file write exists in the Incus client when a malicious
CVE-2026-43503 8.8 0.13% 4 8 2026-06-26T18:57:17.887000 In the Linux kernel, the following vulnerability has been resolved: net: skbuff
CVE-2026-48752 9.9 0.00% 1 0 2026-06-26T18:46:32 ### Summary A specially crafted image or instance backup can be used to read or
CVE-2026-48750 9.9 0.00% 1 0 2026-06-26T18:32:53 ### Summary The `record-output` parameter of the `/instances/$name/exec` endpoi
CVE-2026-48749 9.9 0.00% 1 0 2026-06-26T18:31:23 ### Summary A specially crafted image can be used to read or create/write arbit
CVE-2026-20230 8.6 41.69% 2 3 2026-06-25T21:31:23 A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco U
CVE-2026-12849 9.1 1.68% 2 0 2026-06-25T14:02:35.347000 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct
CVE-2026-9776 7.5 1.58% 2 0 2026-06-25T00:35:20 ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Discl
CVE-2026-55200 8.1 0.92% 6 2 2026-06-24T18:33:40 libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write
CVE-2026-12851 9.1 1.68% 2 0 2026-06-24T06:31:51 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct
CVE-2026-12850 9.1 1.72% 2 0 2026-06-24T06:31:51 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct
CVE-2026-12486 9.1 1.72% 2 0 2026-06-24T06:31:51 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct
CVE-2025-67038 9.8 1.13% 1 1 2026-06-24T05:17:25.670000 An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module exec
CVE-2026-56274 9.9 2.68% 2 0 2026-06-23T15:32:37 Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in t
CVE-2026-11374 9.0 1.24% 2 0 2026-06-23T09:32:28 In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and
CVE-2026-32315 5.5 2.90% 2 0 2026-06-22T17:11:37 # Security Advisory: World-Readable Configuration File Exposes Admin Password Ha
CVE-2026-20127 10.0 57.79% 2 8 2026-06-17T15:06:12.607000 A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controlle
CVE-2026-46529 0 0.56% 2 1 2026-06-17T13:20:41.280000 Atril Document Viewer is the default document reader of the MATE desktop environ
CVE-2026-8037 9.6 1.87% 2 0 2026-06-17T11:03:24.930000 OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC
CVE-2026-46215 7.8 0.13% 2 1 2026-06-17T10:53:20.720000 In the Linux kernel, the following vulnerability has been resolved: drm: Set ol
CVE-2026-35273 9.8 92.33% 1 4 template 2026-06-17T10:40:19.560000 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS
CVE-2026-33825 7.8 6.75% 2 5 2026-06-17T10:38:09.690000 Insufficient granularity of access control in Microsoft Defender allows an autho
CVE-2026-24418 6.5 0.36% 2 2 2026-06-17T10:23:02.487000 OpenSTAManager is an open source management software for technical assistance an
CVE-2025-60727 7.8 0.49% 1 0 2026-06-17T09:50:03.367000 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to
CVE-2026-54157 9.0 1.78% 2 0 template 2026-06-16T20:15:57 ## Unauthenticated SSRF in /webapi/proxy allows anyone to proxy requests and inj
CVE-2026-20251 8.8 0.57% 1 1 2026-06-10T18:31:53 In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk C
CVE-2026-20245 7.8 9.92% 2 3 2026-06-09T21:32:21 A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vMa
CVE-2026-46817 9.8 0.42% 4 0 2026-05-29T18:31:20 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone
CVE-2026-20182 10.0 87.69% 2 3 template 2026-05-14T18:33:03 May 2026: This security advisory provides the details and fix information for a
CVE-2026-6307 8.8 0.36% 2 0 2026-04-15T21:30:19 Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a re
CVE-2026-24294 7.8 2.73% 2 2 2026-03-27T21:32:39 Improper authentication in Windows SMB Server allows an authorized attacker to e
CVE-2026-3102 6.3 3.41% 1 2 2026-02-26T21:32:34 A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affe
CVE-2026-28496 0 1.89% 2 1 template N/A
CVE-2026-54066 0 1.89% 2 0 template N/A
CVE-2026-50160 0 0.00% 1 0 N/A
CVE-2026-47220 0 0.46% 2 0 N/A
CVE-2026-47193 0 0.25% 1 0 N/A
CVE-2026-46386 0 0.27% 1 0 N/A
CVE-2026-49991 0 0.27% 1 0 N/A
CVE-2026-48751 0 0.00% 1 0 N/A
CVE-2026-48755 0 0.00% 1 0 N/A
CVE-2026-55621 0 0.00% 1 0 N/A
CVE-2026-55622 0 0.00% 1 0 N/A

CVE-2026-13763
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-06-29T21:16:43.300000

4 posts

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue only impacts HTTP/2 ALB target groups. To remediate this issue, customers should enable the "Insp

nyanbinary at 2026-06-29T20:39:54.925Z ##

CVE-2026-13762/CVE-2026-13763 are not vulnerabilities and shouldn't have been assigned CVEs, fight me

##

awssecurityfeed at 2026-06-29T20:15:01.433Z ##

CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF

Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 11:15 PM PDT
Description:
AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded...

aws.amazon.com/security/securi

##

nyanbinary@infosec.exchange at 2026-06-29T20:39:54.000Z ##

CVE-2026-13762/CVE-2026-13763 are not vulnerabilities and shouldn't have been assigned CVEs, fight me

##

awssecurityfeed@infosec.exchange at 2026-06-29T20:15:01.000Z ##

CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF

Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 11:15 PM PDT
Description:
AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-13762
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-06-29T21:16:43.183000

4 posts

Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue was remediated server-side. No customer action is required.

nyanbinary at 2026-06-29T20:39:54.925Z ##

CVE-2026-13762/CVE-2026-13763 are not vulnerabilities and shouldn't have been assigned CVEs, fight me

##

awssecurityfeed at 2026-06-29T20:15:01.433Z ##

CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF

Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 11:15 PM PDT
Description:
AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded...

aws.amazon.com/security/securi

##

nyanbinary@infosec.exchange at 2026-06-29T20:39:54.000Z ##

CVE-2026-13762/CVE-2026-13763 are not vulnerabilities and shouldn't have been assigned CVEs, fight me

##

awssecurityfeed@infosec.exchange at 2026-06-29T20:15:01.000Z ##

CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF

Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 11:15 PM PDT
Description:
AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-48558
(10.0 CRITICAL)

EPSS: 0.72%

updated 2026-06-29T20:17:38.077000

7 posts

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary

secdb at 2026-06-29T21:01:57.072Z ##

🚨 [CISA-2026:0629] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48558 (secdb.nttzen.cloud/cve/detail/)
- Name: SimpleHelp Authentication Bypass Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SimpleHelp
- Product: SimpleHelp
- Notes: simple-help.com/security/simpl ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-06-29T20:00:51.000Z ##

CVE ID: CVE-2026-48558
Vendor: SimpleHelp
Product: SimpleHelp
Date Added: 2026-06-29
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

oversecurity@mastodon.social at 2026-06-29T14:30:37.000Z ##

Critical SimpleHelp flaw exploited to deploy new stealer malware

Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously...

🔗️ [Bleepingcomputer] link.is.it/O1CzjD

##

Analyst207@mastodon.social at 2026-06-29T14:14:09.000Z ##

Hackers Exploit SimpleHelp Flaw to Deploy Djinn Stealer Malware

Hackers have found a way to exploit a flaw in SimpleHelp, using it as a trusted channel to deploy the Djinn Stealer malware and wreak havoc on managed systems. This critical vulnerability, CVE-2026-48558, allows attackers to create highly privileged accounts without authentication, putting thousands of systems at risk.

osintsights.com/hackers-exploi

#Cve202648558 #Simplehelp #Oidc #DjinnStealer #MalwareOperations

##

secdb@infosec.exchange at 2026-06-29T21:01:57.000Z ##

🚨 [CISA-2026:0629] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48558 (secdb.nttzen.cloud/cve/detail/)
- Name: SimpleHelp Authentication Bypass Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SimpleHelp
- Product: SimpleHelp
- Notes: simple-help.com/security/simpl ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260629 #cisa20260629 #cve_2026_48558 #cve202648558

##

cisakevtracker@mastodon.social at 2026-06-29T20:00:51.000Z ##

CVE ID: CVE-2026-48558
Vendor: SimpleHelp
Product: SimpleHelp
Date Added: 2026-06-29
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

oversecurity@mastodon.social at 2026-06-29T14:30:37.000Z ##

Critical SimpleHelp flaw exploited to deploy new stealer malware

Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously...

🔗️ [Bleepingcomputer] link.is.it/O1CzjD

##

CVE-2026-22078
(7.3 HIGH)

EPSS: 0.09%

updated 2026-06-29T19:07:03.733000

2 posts

Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel.

offseq at 2026-06-29T09:00:27.143Z ##

OPPO O+ Connect v16.0.33 is vulnerable (CVE-2026-22078, HIGH). Lack of IPC client authentication lets external apps escalate privileges — potential for sensitive actions. Patch unavailable. Monitor and restrict app permissions. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-29T09:00:27.000Z ##

OPPO O+ Connect v16.0.33 is vulnerable (CVE-2026-22078, HIGH). Lack of IPC client authentication lets external apps escalate privileges — potential for sensitive actions. Patch unavailable. Monitor and restrict app permissions. #OffSeq #CVE202622078 #OPPO radar.offseq.com/threat/cve-20

##

CVE-2025-2902
(8.3 HIGH)

EPSS: 0.19%

updated 2026-06-29T18:52:40.497000

2 posts

Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H: before DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90

thehackerwire@mastodon.social at 2026-06-29T08:00:29.000Z ##

🟠 CVE-2025-2902 - High (8.3)

Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform.

This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, G...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-29T08:00:29.000Z ##

🟠 CVE-2025-2902 - High (8.3)

Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform.

This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, G...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13500
(7.3 HIGH)

EPSS: 0.31%

updated 2026-06-29T18:46:31.617000

1 posts

A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action Block Handler. Executing a manipulation can lead to code injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted

hugovalters@mastodon.social at 2026-06-29T17:05:31.000Z ##

CVE-2026-13500 - Code Injection in ANTLR4 up to 4.13.2. CVSS 7.3. Remote exploit public, vendor unresponsive. Mitigate immediately. #CVE #infosec #ANTLR

valtersit.com/cve/CVE-2026-135

##

CVE-2026-57346
(7.1 HIGH)

EPSS: 0.00%

updated 2026-06-29T18:39:20.080000

2 posts

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.

offseq at 2026-06-29T10:30:27.111Z ##

Epiphyt Embed Privacy ≤1.12.3 is affected by CVE-2026-57346 (HIGH, CVSS 7.1): path traversal via improper pathname checks. Assess your deployments and watch for mitigations. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-29T10:30:27.000Z ##

Epiphyt Embed Privacy ≤1.12.3 is affected by CVE-2026-57346 (HIGH, CVSS 7.1): path traversal via improper pathname checks. Assess your deployments and watch for mitigations. radar.offseq.com/threat/cve-20 #OffSeq #CVE202657346 #Vuln #PathTraversal

##

CVE-2026-10083
(7.5 HIGH)

EPSS: 0.16%

updated 2026-06-29T15:33:13

1 posts

The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in an admin-area page, leading to a Stored Cross-Site Scripting vulnerability. When a persistent object cache is enabled, cache keys derived from unsanitised user input (e.g. a transient name created by another APCu Manager WordPress plugin before 4.5.0 from an unauthenticated request) are o

offseq at 2026-06-29T07:30:26.746Z ##

Stored XSS (CVE-2026-10083, HIGH) found in APCu Manager <4.5.0 for WordPress. Persistent object caching lets attackers inject JS via crafted cache keys, compromising admin sessions. Disable object caching or update plugin. radar.offseq.com/threat/cve-20

##

CVE-2026-46331
(7.8 HIGH)

EPSS: 0.23%

updated 2026-06-29T15:32:00

5 posts

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb

5 repos

https://github.com/douglasmun/pagecache-lpe-containment-kit

https://github.com/vulnquest58/dirtyclone-exploit

https://github.com/sgkdev/packet_edit_meme

https://github.com/0xBlackash/CVE-2026-46331

https://github.com/HORKimhab/CVE-2026-46331

cyberveille@mastobot.ping.moi at 2026-06-29T17:30:20.000Z ##

📢 CVE-2026-46331 ' pedit COW ' : élévation de privilèges root dans le noyau Linux
📝 ## 🔍 Contexte

Source : The Hacker News, publiée le 26 juin 2026.
📖 cyberveille : cyberveille.ch/posts/2026-06-2
🌐 source : thehackernews.com/2026/06/new-
#CVE_2026_46331 #IOC #Cyberveille

##

data0@indieweb.social at 2026-06-29T13:25:09.000Z ##

There's another #Linux page cache corruption bug making the rounds, assigned CVE-2026-46331. And again, I couldn't find a list of #kernel versions that include the fix. I wonder why? Anyway, here's the list:

7.1.x stable: 7.1
7.0.x stable: 7.0.13
6.18.x lts: 6.18.36
6.12.x lts: 6.12.94

##

teezeh@ieji.de at 2026-06-29T05:54:45.000Z ##

"Sicherheitsforscher sind auf eine neue, pedit COW genannte, Schwachstelle CVE-2026-46331 gestoßen, es erlaubt, Speicherinhalte zu missbrauchen, um normalen Nutzern Root-Rechte zu verschaffen."

borncity.com/blog/2026/06/28/p

##

cyberveille@mastobot.ping.moi at 2026-06-29T17:30:20.000Z ##

📢 CVE-2026-46331 ' pedit COW ' : élévation de privilèges root dans le noyau Linux
📝 ## 🔍 Contexte

Source : The Hacker News, publiée le 26 juin 2026.
📖 cyberveille : cyberveille.ch/posts/2026-06-2
🌐 source : thehackernews.com/2026/06/new-
#CVE_2026_46331 #IOC #Cyberveille

##

data0@indieweb.social at 2026-06-29T13:25:09.000Z ##

There's another #Linux page cache corruption bug making the rounds, assigned CVE-2026-46331. And again, I couldn't find a list of #kernel versions that include the fix. I wonder why? Anyway, here's the list:

7.1.x stable: 7.1
7.0.x stable: 7.0.13
6.18.x lts: 6.18.36
6.12.x lts: 6.12.94

##

CVE-2026-32833
(8.8 HIGH)

EPSS: 1.34%

updated 2026-06-29T14:16:49.310000

1 posts

Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the cbid.system.ntp.current POST parameter in the system time configuration interface. Attackers can submit malicious payloads through the NTP settings endpoint to achieve remote code executio

thehackerwire@mastodon.social at 2026-06-29T07:00:22.000Z ##

🟠 CVE-2026-32833 - High (8.8)

Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the cbid.system.ntp.current POST parame...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13564
(8.8 HIGH)

EPSS: 0.00%

updated 2026-06-29T12:31:51

2 posts

A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclos

offseq at 2026-06-29T13:30:30.609Z ##

CVE-2026-13564: HIGH (CVSS 8.7) stack-based buffer overflow in Edimax EW-7478APC v1.04. Remote exploit via pppUserName; public PoC, no patch. Disable remote access or segment device. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-29T13:30:30.000Z ##

CVE-2026-13564: HIGH (CVSS 8.7) stack-based buffer overflow in Edimax EW-7478APC v1.04. Remote exploit via pppUserName; public PoC, no patch. Disable remote access or segment device. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE202613564

##

CVE-2026-13553
(7.3 HIGH)

EPSS: 0.00%

updated 2026-06-29T12:31:50

1 posts

A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been published and may be used.

hugovalters@mastodon.social at 2026-06-29T14:06:24.000Z ##

CVE-2026-13553 - Unrestricted file upload in itsourcecode Online Hotel Management System 1.0 via controller.php. CVSS 7.3. Exploit published. No patch available. Restrict access or disable uploads immediately. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-135

##

CVE-2026-13601
(7.1 HIGH)

EPSS: 0.00%

updated 2026-06-29T12:31:50

2 posts

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML in

offseq at 2026-06-29T12:00:33.381Z ##

CVE-2026-13601 (HIGH, CVSS 7.1) in Red Hat Enterprise Linux 10: Yelp’s help viewer can leak sensitive files via crafted Flatpak apps due to weak Content Security Policy. No patch yet — restrict untrusted Flatpaks. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-29T12:00:33.000Z ##

CVE-2026-13601 (HIGH, CVSS 7.1) in Red Hat Enterprise Linux 10: Yelp’s help viewer can leak sensitive files via crafted Flatpak apps due to weak Content Security Policy. No patch yet — restrict untrusted Flatpaks. radar.offseq.com/threat/cve-20 #OffSeq #Linux #Vuln #RedHat

##

CVE-2026-13539
(8.8 HIGH)

EPSS: 0.47%

updated 2026-06-29T09:30:32

2 posts

A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. Such manipulation of the argument Guest_ssid leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. It is suggested to upgrade the aff

thehackerwire@mastodon.social at 2026-06-29T08:00:16.000Z ##

🟠 CVE-2026-13539 - High (8.8)

A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. Such manipulation of the argument Guest_ssid leads to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-29T08:00:16.000Z ##

🟠 CVE-2026-13539 - High (8.8)

A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. Such manipulation of the argument Guest_ssid leads to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13517
(8.8 HIGH)

EPSS: 0.47%

updated 2026-06-29T03:30:58

1 posts

A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a manipulation of the argument security_5g can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.

offseq at 2026-06-29T04:30:29.749Z ##

CVE-2026-13517: HIGH severity stack buffer overflow in Tenda JD12L (16.03.53.23). Exploitable remotely via security_5g argument in formWifiBasicSet. No patch yet — restrict access & monitor for threats. radar.offseq.com/threat/cve-20

##

CVE-2026-13516
(8.8 HIGH)

EPSS: 0.47%

updated 2026-06-29T00:31:46

1 posts

A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument shareSpeed results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.

offseq at 2026-06-29T06:00:25.131Z ##

Tenda JD12L routers (fw 16.03.53.23) face HIGH severity stack-based buffer overflow (CVE-2026-13516, CVSS 8.7). Remote code execution possible — exploit code is public. Restrict remote access, monitor endpoints. radar.offseq.com/threat/cve-20

##

CVE-2026-13485
(7.3 HIGH)

EPSS: 0.41%

updated 2026-06-28T12:30:28

1 posts

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of the argument course_year_section results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

hugovalters@mastodon.social at 2026-06-29T09:01:59.000Z ##

CVE-2026-13485 - SQLi in SourceCodester Class & Exam Timetabling System 1.0. Unpatched, exploit public. CVSS 7.3. Update or mitigate immediately. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-134

##

CVE-2026-55975
(7.2 HIGH)

EPSS: 0.65%

updated 2026-06-27T00:30:34

1 posts

A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate creation command without proper input validation. This may allow for command execution with elevated privileges during certificate generation.

hugovalters@mastodon.social at 2026-06-29T12:01:41.000Z ##

CVE-2026-55975 - Command Injection in H.View IP cameras. Authenticated users can exploit unsanitized XML fields for elevated command execution. CVSS 7.2. No patch available. Isolate affected devices immediately. #CVE #infosec #HView

valtersit.com/cve/CVE-2026-559

##

CVE-2026-48769
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-06-26T19:13:19

1 posts

### Summary An arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. ### Details - `cmd/incusd/images.go:611-684` handles `source.type=url` by HEADing the user-supplied URL, reading `Incus-Image-Hash` and `Incus-Image-URL`, and passing them to `imageDownload(

blog@stgraber.org at 2026-06-29T04:32:40.000Z ##

Announcing Incus 7.2

The Incus team is pleased to announce the release of Incus 7.2!

It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-48749 (critical) – Arbitrary file read+write on host via rootfs/ symlink in malicious image
  • CVE-2026-48750 (critical) – Arbitrary file write on host via exec-output symlink in crafted image
  • CVE-2026-48751 (critical) – Restricted project bypass leading to arbitrary command execution
  • CVE-2026-48752 (critical) – Arbitrary file read+write on host via templates/ symlink in malicious image
  • CVE-2026-48755 (critical) – Argument injection in backup compression algorithm leading to arbitrary file write and command execution
  • CVE-2026-48769 (critical) – Arbitrary file write on client due to trusted image hash
  • CVE-2026-55621 (high) – Project restriction bypass for custom volume copy across projects
  • CVE-2026-55622 (high) – Project restriction bypass in instance copy across projects

On the feature front, the highlights for this release are:

  • Per-instance SELinux integration
  • New incus default CLI command
  • Filtered server info by default
  • Keepalive timeout from the CLI
  • Better OS-specific handling of CLI configuration
  • Standalone server certificate update
  • Static network configuration for OCI containers
  • Per-instance BGP route advertisement
  • Dynamic addresses in proxy NAT mode
  • Expanded NBD access to VMs
  • Btrfs compression for storage volumes
  • InfiniBand SR-IOV GUID configuration
  • Websocket origin restriction

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=rcldqF6SpXA

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

CVE-2026-43503
(8.8 HIGH)

EPSS: 0.13%

updated 2026-06-26T18:57:17.887000

4 posts

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when moving frags from source to destination. __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header(

8 repos

https://github.com/douglasmun/pagecache-lpe-containment-kit

https://github.com/gl1tch0x1/DirtyClone

https://github.com/aexdyhaxor/CVE-2026-43503-DirtyClone

https://github.com/SecureWithUmer/CVE-2026-43503

https://github.com/sec0x/CVE-2026-43503

https://github.com/mooder1/dirtyclone-CVE-2026-43503

https://github.com/0xBlackash/CVE-2026-43503

https://github.com/entra1337/DirtyClone

DarkWebInformer at 2026-06-29T18:49:01.614Z ##

‼️ CVE-2026-43503: Python PoC for DirtyClone, a Linux kernel LPE via page-cache corruption exploit

GitHub: github.com/entra1337/DirtyClone

##

cyberveille@mastobot.ping.moi at 2026-06-29T17:00:20.000Z ##

📢 DirtyClone (CVE-2026-43503) : LPE Linux via corruption du page cache par IPsec
📝 ## 🔍 Contexte

Publié le 25 juin 2026 par les chercheurs Eddy Tsalolikhin et Or Peles de JFrog Security...
📖 cyberveille : cyberveille.ch/posts/2026-06-2
🌐 source : research.jfrog.com/post/dissec
#CVE_2026_43284 #CVE_2026_43500 #Cyberveille

##

pertho@bsd.cafe at 2026-06-29T07:47:14.000Z ##

ANOTHER #Linux LPE: CVE-2026-43503

If only Linus wasn't so obsessed with calling #OpenBSD developers "masturbating monkeys" 18 years ago and actually took security seriously. 🤔

cnet.com/tech/tech-industry/to

##

DarkWebInformer@infosec.exchange at 2026-06-29T18:49:01.000Z ##

‼️ CVE-2026-43503: Python PoC for DirtyClone, a Linux kernel LPE via page-cache corruption exploit

GitHub: github.com/entra1337/DirtyClone

##

CVE-2026-48752
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-06-26T18:46:32

1 posts

### Summary A specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. ### Details For container images, `internal/server/storage/utils.go` calls `archive.Unpack(imageFile, destPath, ...)`. The tar extraction path in `shared/archive/archive.go` excludes device nodes, but it does not reject a top

blog@stgraber.org at 2026-06-29T04:32:40.000Z ##

Announcing Incus 7.2

The Incus team is pleased to announce the release of Incus 7.2!

It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-48749 (critical) – Arbitrary file read+write on host via rootfs/ symlink in malicious image
  • CVE-2026-48750 (critical) – Arbitrary file write on host via exec-output symlink in crafted image
  • CVE-2026-48751 (critical) – Restricted project bypass leading to arbitrary command execution
  • CVE-2026-48752 (critical) – Arbitrary file read+write on host via templates/ symlink in malicious image
  • CVE-2026-48755 (critical) – Argument injection in backup compression algorithm leading to arbitrary file write and command execution
  • CVE-2026-48769 (critical) – Arbitrary file write on client due to trusted image hash
  • CVE-2026-55621 (high) – Project restriction bypass for custom volume copy across projects
  • CVE-2026-55622 (high) – Project restriction bypass in instance copy across projects

On the feature front, the highlights for this release are:

  • Per-instance SELinux integration
  • New incus default CLI command
  • Filtered server info by default
  • Keepalive timeout from the CLI
  • Better OS-specific handling of CLI configuration
  • Standalone server certificate update
  • Static network configuration for OCI containers
  • Per-instance BGP route advertisement
  • Dynamic addresses in proxy NAT mode
  • Expanded NBD access to VMs
  • Btrfs compression for storage volumes
  • InfiniBand SR-IOV GUID configuration
  • Websocket origin restriction

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=rcldqF6SpXA

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

CVE-2026-48750
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-06-26T18:32:53

1 posts

### Summary The `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named `exec_UUID.stdout` and `exec_UUID.stderr` can be written to an arbitrary location where the `.stdout` file will contain arbitrary content. This behavior can be abused for arbitrary command execu

blog@stgraber.org at 2026-06-29T04:32:40.000Z ##

Announcing Incus 7.2

The Incus team is pleased to announce the release of Incus 7.2!

It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-48749 (critical) – Arbitrary file read+write on host via rootfs/ symlink in malicious image
  • CVE-2026-48750 (critical) – Arbitrary file write on host via exec-output symlink in crafted image
  • CVE-2026-48751 (critical) – Restricted project bypass leading to arbitrary command execution
  • CVE-2026-48752 (critical) – Arbitrary file read+write on host via templates/ symlink in malicious image
  • CVE-2026-48755 (critical) – Argument injection in backup compression algorithm leading to arbitrary file write and command execution
  • CVE-2026-48769 (critical) – Arbitrary file write on client due to trusted image hash
  • CVE-2026-55621 (high) – Project restriction bypass for custom volume copy across projects
  • CVE-2026-55622 (high) – Project restriction bypass in instance copy across projects

On the feature front, the highlights for this release are:

  • Per-instance SELinux integration
  • New incus default CLI command
  • Filtered server info by default
  • Keepalive timeout from the CLI
  • Better OS-specific handling of CLI configuration
  • Standalone server certificate update
  • Static network configuration for OCI containers
  • Per-instance BGP route advertisement
  • Dynamic addresses in proxy NAT mode
  • Expanded NBD access to VMs
  • Btrfs compression for storage volumes
  • InfiniBand SR-IOV GUID configuration
  • Websocket origin restriction

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=rcldqF6SpXA

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

CVE-2026-48749
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-06-26T18:31:23

1 posts

### Summary A specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. ### Details Incus validates an image as soon as it sees a normal `metadata.yaml` and a `rootfs/` entry, but full extraction can later process a duplicate top-level `rootfs` symlink. Later, the stopped-container file API opens `d.RootfsPath()` a

blog@stgraber.org at 2026-06-29T04:32:40.000Z ##

Announcing Incus 7.2

The Incus team is pleased to announce the release of Incus 7.2!

It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-48749 (critical) – Arbitrary file read+write on host via rootfs/ symlink in malicious image
  • CVE-2026-48750 (critical) – Arbitrary file write on host via exec-output symlink in crafted image
  • CVE-2026-48751 (critical) – Restricted project bypass leading to arbitrary command execution
  • CVE-2026-48752 (critical) – Arbitrary file read+write on host via templates/ symlink in malicious image
  • CVE-2026-48755 (critical) – Argument injection in backup compression algorithm leading to arbitrary file write and command execution
  • CVE-2026-48769 (critical) – Arbitrary file write on client due to trusted image hash
  • CVE-2026-55621 (high) – Project restriction bypass for custom volume copy across projects
  • CVE-2026-55622 (high) – Project restriction bypass in instance copy across projects

On the feature front, the highlights for this release are:

  • Per-instance SELinux integration
  • New incus default CLI command
  • Filtered server info by default
  • Keepalive timeout from the CLI
  • Better OS-specific handling of CLI configuration
  • Standalone server certificate update
  • Static network configuration for OCI containers
  • Per-instance BGP route advertisement
  • Dynamic addresses in proxy NAT mode
  • Expanded NBD access to VMs
  • Btrfs compression for storage volumes
  • InfiniBand SR-IOV GUID configuration
  • Websocket origin restriction

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=rcldqF6SpXA

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

CVE-2026-20230
(8.6 HIGH)

EPSS: 41.69%

updated 2026-06-25T21:31:23

2 posts

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this

3 repos

https://github.com/HalilDeniz/CVE-2026-20230-Scanner

https://github.com/HORKimhab/CVE-2026-20230

https://github.com/W5M1n9/Cisco-Unified-Communications-Manager-Server-Side-Forgery-Request-Vulnerability-CVE-2026-20230

netsecio@mastodon.social at 2026-06-29T17:06:08.000Z ##

📰 Attackers Actively Exploit Critical Cisco Unified CM Flaw to Deploy Webshells

⚠️ ACTIVE EXPLOITATION: A critical SSRF flaw in Cisco Unified CM (CVE-2026-20230) is being used to drop webshells. Attackers are scanning from Tor. Disable the WebDialer service or patch immediately! #Cisco #CyberAttack #Infosec #SSRF

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ac

##

netsecio@mastodon.social at 2026-06-29T17:06:08.000Z ##

📰 Attackers Actively Exploit Critical Cisco Unified CM Flaw to Deploy Webshells

⚠️ ACTIVE EXPLOITATION: A critical SSRF flaw in Cisco Unified CM (CVE-2026-20230) is being used to drop webshells. Attackers are scanning from Tor. Disable the WebDialer service or patch immediately! #Cisco #CyberAttack #Infosec #SSRF

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ac

##

CVE-2026-12849
(9.1 CRITICAL)

EPSS: 1.68%

updated 2026-06-25T14:02:35.347000

2 posts

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi

secdb at 2026-06-29T12:56:53.325Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-06-29T12:56:53.000Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-9776
(7.5 HIGH)

EPSS: 1.58%

updated 2026-06-25T00:35:20

2 posts

ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the writeFileToHttpServletResponse method. The issue results from the lack of proper

secdb at 2026-06-29T12:56:53.325Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-06-29T12:56:53.000Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-55200
(8.1 HIGH)

EPSS: 0.92%

updated 2026-06-24T18:33:40

6 posts

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.

2 repos

https://github.com/0xBlackash/CVE-2026-55200

https://github.com/xd20111/CVE-2026-55200

veit@mastodon.social at 2026-06-29T12:27:03.000Z ##

Critical libssh2 vulnerability with a proof-of-concept exploit already published. curl, PHP and libgit2 are also affected.
nvd.nist.gov/vuln/detail/CVE-2
#ssh #Vulnerability #ITSecurity #curl

##

allaboutsecurity@mastodon.social at 2026-06-29T10:27:48.000Z ##

CVE-2026-55200: Öffentlicher Exploit-Code für libssh2-Schwachstelle veröffentlicht

all-about-security.de/cve-2026

#cve #cybersecurity

##

posthole@social.posthole.net at 2026-06-29T09:10:37.000Z ##

https://posthole.net/

THE POSTHOLE
Monday, 29 June 2026  ·  Overnight Edition  ·  Vol. 1 No. 201
MJD 61220.38

LEAD — HEALTH

Florida Hospitals Act Fast To Discharge Gun Victims — Especially if They’re Not Insured
-- KFF Health News

Uninsured patients made up about 1 in 4 of the more than 20,000 gunshot wound inpatient hospitalizations in Florida from 2018 to 2024, an analysis of state data by KFF Health News and The Trace found. They also had shorter hospital stays than those with any...

#posthole

HEALTH

She Struggled To Get a Lifesaving Drug Even After Insurers Vowed To Help
-- KFF Health News
Margaret Hvatum ended up in the hospital after her insurer denied coverage of a medicine she relies on to boost her immune...

#posthole

INTERNATIONAL

À gauche, les partis tentent d’étouffer en interne l’appel d’air insoumis
-- Mediapart
Craignant une hémorragie militante et des annonces en série d’un soutien à la candidature de Jean-Luc Mélenchon à la...

Les saisonniers exposés aux pesticides, grands absents du débat public
-- Mediapart

«Il y a eu comme une bascule»: en Île-de-France, les funérariums débordés par la canicule
-- Mediapart

#posthole

NATIONAL

Trump’s Sons Stand To Profit From The Critical Minerals Arms Race
-- Mother Jones
Donald Trump’s network of family businesses—and network of US government deals with those businesses—is mind-bogglingly wide. A...

Trump’s Next ICE Pick: A Trooper Poised to Turn Local Cops Into Deportation Agents
-- Mother Jones

#posthole

CULTURE & SPORT

Dublin Pulls Off Comeback To Beat Galway In All-Ireland Quarterfinal
-- Defector
Dublin closed out a thrilling All-Ireland football quarterfinal weekend with a massive and penalty-aided comeback to beat Galway...

Boots Ennis KO’s Zayas In Brooklyn Thriller
-- Defector

#posthole

SECURITY

Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
-- The Hacker News
A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH...

#infosec #cybersecurity #posthole

IN BRIEF

AI Tools Accelerates Coding, but Not Overall Software Delivery, GitLab Research Finds -- InfoQ
Swift 6.4 Brings New Language Features and Swift Testing/XCTest Interop -- InfoQ
AWS Previews FinOps Agent for Cost Analysis and Optimization -- InfoQ
AWS Introduces Workload Credentials Provider for Automated Certificate and Secret... -- InfoQ
Vercel Introduces Eve, an Open-Source Framework for Building AI Agents -- InfoQ

#news #posthole

SECTIONS

Gaming Greatness: Marvel Tōkon: Fighting Souls Reveals Last 3 Playable Characters... #gaming
Tech Talk: [US Grid Constr...

##

Analyst207@mastodon.social at 2026-06-29T08:42:49.000Z ##

libssh2 Flaw Exposes Clients to Code Execution Risk

A critical flaw in libssh2, known as CVE-2026-55200, can be exploited by a malicious SSH server to trigger memory corruption on a connecting client, with no credentials or user interaction required. This vulnerability can be easily triggered with a public proof-of-concept now available.

osintsights.com/libssh2-flaw-e

#Libssh2 #CodeExecution #Cve202655200 #Ssh #MemoryCorruption

##

undercodenews@mastodon.social at 2026-06-29T07:26:21.000Z ##

Critical libssh2 Memory Corruption Flaw Exposes Millions of SSH Clients to Potential Remote Code Execution + Video

Critical libssh2 Memory Corruption Flaw Exposes Millions of SSH Clients to Potential Remote Code Execution Introduction A newly disclosed vulnerability in libssh2 has sent a fresh warning across the cybersecurity industry, exposing a fundamental weakness inside one of the world's most widely embedded SSH client libraries. Tracked as CVE-2026-55200, the…

undercodenews.com/critical-lib

##

veit@mastodon.social at 2026-06-29T12:27:03.000Z ##

Critical libssh2 vulnerability with a proof-of-concept exploit already published. curl, PHP and libgit2 are also affected.
nvd.nist.gov/vuln/detail/CVE-2
#ssh #Vulnerability #ITSecurity #curl

##

CVE-2026-12851
(9.1 CRITICAL)

EPSS: 1.68%

updated 2026-06-24T06:31:51

2 posts

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi

secdb at 2026-06-29T12:56:53.325Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-06-29T12:56:53.000Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12850
(9.1 CRITICAL)

EPSS: 1.72%

updated 2026-06-24T06:31:51

2 posts

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi

secdb at 2026-06-29T12:56:53.325Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-06-29T12:56:53.000Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12486
(9.1 CRITICAL)

EPSS: 1.72%

updated 2026-06-24T06:31:51

2 posts

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi

secdb at 2026-06-29T12:56:53.325Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-06-29T12:56:53.000Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2025-67038
(9.8 CRITICAL)

EPSS: 1.13%

updated 2026-06-24T05:17:25.670000

1 posts

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

1 repos

https://github.com/HORKimhab/CVE-2025-67038

darses@mastodon.nl at 2026-06-29T19:19:26.000Z ##

#Lantronix released new a bunch of new firmware, fixing both CVE-2025-67038 and the second actively exploited vulnerability without #CVE identifier.

I did not check all the firmware uploads nor do I have devices to actually test the fixed code, but from the looks of it this should all be good.

You can follow the discussion on #ifin : discourse.ifin.network/t/lantr

##

CVE-2026-56274
(9.9 CRITICAL)

EPSS: 2.68%

updated 2026-06-23T15:32:37

2 posts

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any role, or API access with view/update permissions for chatflows, can configure a malicious MCP server to bypass the validateCommandFlags blocklist (for ex

secdb at 2026-06-29T12:56:53.325Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-06-29T12:56:53.000Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-11374
(9.0 None)

EPSS: 1.24%

updated 2026-06-23T09:32:28

2 posts

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

threatcodex at 2026-06-29T14:08:34.626Z ##

CVE-2026-11374: Account takeover vulnerability in ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus

manageengine.com/products/self

##

threatcodex@infosec.exchange at 2026-06-29T14:08:34.000Z ##

CVE-2026-11374: Account takeover vulnerability in ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus
#CVE_2026_11374 #ManageEngine
manageengine.com/products/self

##

CVE-2026-32315
(5.5 MEDIUM)

EPSS: 2.90%

updated 2026-06-22T17:11:37

2 posts

# Security Advisory: World-Readable Configuration File Exposes Admin Password Hash in motionEye ## Summary motionEye v0.43.1 and prior versions create the configuration file `/etc/motioneye/motion.conf` with `644` permissions (`-rw-r--r--`), making it readable by any local user on the system. This file contains sensitive data including the admin password hash, which can be leveraged by other vul

secdb at 2026-06-29T12:56:53.325Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-06-29T12:56:53.000Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-20127
(10.0 CRITICAL)

EPSS: 57.79%

updated 2026-06-17T15:06:12.607000

2 posts

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the pee

8 repos

https://github.com/BugFor-Pings/CVE-2026-20127_EXP

https://github.com/0xBlackash/CVE-2026-20127

https://github.com/randeepajayasekara/CVE-2026-20127

https://github.com/gigachadusers/cve-2026-20127

https://github.com/yonathanpy/CVE-2026-20127-Cisco-SD-WAN-Preauth-RCE

https://github.com/abrahamsurf/sdwan-scanner-CVE-2026-20127

https://github.com/sfewer-r7/CVE-2026-20127

https://github.com/zerozenxlabs/CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE

pentesttools at 2026-06-29T11:53:17.867Z ##

Exploitation started in March. Cisco disclosed in June. Patch landed June 10.

For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.

Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:

""Whoever used this vulnerability had working knowledge of it in this period while defenders had none.""

🏴‍☠️ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.

That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.

From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.

The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.

If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.

📍Read the full article by Kevin Poireault: infosecurity-magazine.com/news

##

pentesttools@infosec.exchange at 2026-06-29T11:53:17.000Z ##

Exploitation started in March. Cisco disclosed in June. Patch landed June 10.

For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.

Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:

""Whoever used this vulnerability had working knowledge of it in this period while defenders had none.""

🏴‍☠️ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.

That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.

From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.

The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.

If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.

📍Read the full article by Kevin Poireault: infosecurity-magazine.com/news

#vulnerabilityassessment #ethicalhacking #pentesting

##

CVE-2026-46529
(0 None)

EPSS: 0.56%

updated 2026-06-17T13:20:41.280000

2 posts

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PD

1 repos

https://github.com/N1et/CVE-2026-46529

tux@arram.senta-la.cloud at 2026-06-29T16:22:02.000Z ##

Michael Catanzaro: Single-Click Code Execution Exploit for Evince, Atril, and Xreader

“CVE-2026-46529 is an argument injection vulnerability in Evince, Atril, and Xreader caused by missing shell quoting when composing a command line. The reporter, João Medeiros, has published a GitHub repo for the CVE and a blog post with the story of how he discovered the flaw and developed the exploit. (…)”

#RSSBridge via Planet GNOME

blogs.gnome.org/mcatanzaro/202

##

tux@arram.senta-la.cloud at 2026-06-29T16:22:02.000Z ##

Michael Catanzaro: Single-Click Code Execution Exploit for Evince, Atril, and Xreader

“CVE-2026-46529 is an argument injection vulnerability in Evince, Atril, and Xreader caused by missing shell quoting when composing a command line. The reporter, João Medeiros, has published a GitHub repo for the CVE and a blog post with the story of how he discovered the flaw and developed the exploit. (…)”

#RSSBridge via Planet GNOME

blogs.gnome.org/mcatanzaro/202

##

CVE-2026-8037
(9.6 CRITICAL)

EPSS: 1.87%

updated 2026-06-17T11:03:24.930000

2 posts

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

_r_netsec at 2026-06-29T19:28:05.150Z ##

Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs labs.watchtowr.com/enterprise-

##

_r_netsec@infosec.exchange at 2026-06-29T19:28:05.000Z ##

Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs labs.watchtowr.com/enterprise-

##

CVE-2026-46215
(7.8 HIGH)

EPSS: 0.13%

updated 2026-06-17T10:53:20.720000

2 posts

In the Linux kernel, the following vulnerability has been resolved: drm: Set old handle to NULL before prime swap in change_handle There was a potential race condition in change_handle. The ioctl briefly had a single object with two idr entries; a concurrent gem_close could delete the object and remove one of the handles while leaving the other one dangling, which could subsequently be dereferen

1 repos

https://github.com/0xCyberstan/CVE-2026-46215-POC

lobsters@mastodon.social at 2026-06-29T20:15:10.000Z ##

Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215) lobste.rs/s/hh5yyq #linux #security
cyberstan.co.uk/drm-lpe-linux/

##

lobsters@mastodon.social at 2026-06-29T20:15:10.000Z ##

Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215) lobste.rs/s/hh5yyq #linux #security
cyberstan.co.uk/drm-lpe-linux/

##

CVE-2026-35273
(9.8 CRITICAL)

EPSS: 92.33%

updated 2026-06-17T10:40:19.560000

1 posts

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of Peopl

Nuclei template

4 repos

https://github.com/ekomsSavior/POC_cve_2026_35273

https://github.com/0xBlackash/CVE-2026-35273

https://github.com/HORKimhab/CVE-2026-35273

https://github.com/12hrformat/CVE-2026-35273-POC

Analyst207@mastodon.social at 2026-06-29T20:42:53.000Z ##

ShinyHunters Breach Exposes NAIC's Public Data

The National Association of Insurance Commissioners (NAIC) revealed that a breach exposed its public data after an unauthorized third party exploited a PeopleSoft vulnerability, identified as CVE-2026-35273, tied to the notorious ShinyHunters extortion group. This security issue allowed attackers to gain access to a portion of NAIC's IT systems, compromising…

osintsights.com/shinyhunters-b

#Shinyhunters #Peoplesoft #Cve202635273 #ZeroDay #Oracle

##

CVE-2026-33825
(7.8 HIGH)

EPSS: 6.75%

updated 2026-06-17T10:38:09.690000

2 posts

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

5 repos

https://github.com/Letlaka/redsun-bluehammer-undefend-detection-pack

https://github.com/0xBlackash/CVE-2026-33825

https://github.com/kaleth4/CVE-2026-33825

https://github.com/Joe1sn/CVE-2026-33825

https://github.com/Bilal3755/Detecting_blue_hammer_vuln

kev_Stalker at 2026-06-29T20:46:18.093Z ##

CVE-2026-33825 - Changed to Known Ransomware Status

Microsoft Defender Insufficient Granularity of Access Control VulnerabilityVendor: MicrosoftProduct: DefenderMicrosoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: June 29, 2026 at 20:00:35 UTCDate Added nvd.nist.gov/vuln/detail/CVE-2

##

kev_Stalker@infosec.exchange at 2026-06-29T20:46:18.000Z ##

CVE-2026-33825 - Changed to Known Ransomware Status

Microsoft Defender Insufficient Granularity of Access Control VulnerabilityVendor: MicrosoftProduct: DefenderMicrosoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: June 29, 2026 at 20:00:35 UTCDate Added nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-24418
(6.5 MEDIUM)

EPSS: 0.36%

updated 2026-06-17T10:23:02.487000

2 posts

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario (Payment Schedule) module. The application fails to validate that elements of the id_records array are integers before using them in an SQL IN() clause, allowing a

2 repos

https://github.com/BridgerAlderson/CVE-2026-24418

https://github.com/lukasz-rybak/CVE-2026-24418

DarkWebInformer at 2026-06-29T18:55:30.820Z ##

‼️ CVE-2026-24418: OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario (Payment Schedule) module.

GitHub: github.com/BridgerAlderson/CVE

##

DarkWebInformer@infosec.exchange at 2026-06-29T18:55:30.000Z ##

‼️ CVE-2026-24418: OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario (Payment Schedule) module.

GitHub: github.com/BridgerAlderson/CVE

##

CVE-2025-60727
(7.8 HIGH)

EPSS: 0.49%

updated 2026-06-17T09:50:03.367000

1 posts

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

undercodenews@mastodon.social at 2026-06-29T07:21:36.000Z ##

Microsoft Patches Critical Excel Flaw That Could Let Attackers Take Over PCs Through Malicious Spreadsheets + Video

Microsoft has moved quickly to address a dangerous security vulnerability in Microsoft Excel that could allow cybercriminals to execute malicious code simply by convincing a victim to open a specially crafted spreadsheet. Tracked as CVE-2025-60727, the flaw affects multiple generations of Microsoft Office products and has been rated as a high-severity…

undercodenews.com/microsoft-pa

##

CVE-2026-54157
(9.0 None)

EPSS: 1.78%

updated 2026-06-16T20:15:57

2 posts

## Unauthenticated SSRF in /webapi/proxy allows anyone to proxy requests and inject cookies on lobehub.com ## Summary The `/webapi/proxy` endpoint on app.lobehub.com accepts a URL in the POST body and fetches it server-side without any authentication. This is the same proxy code that was vulnerable in CVE-2024-32964, where `/api/proxy` was fixed by adding auth middleware. The `/webapi/proxy` rou

Nuclei template

secdb at 2026-06-29T12:56:53.325Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-06-29T12:56:53.000Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-20251
(8.8 HIGH)

EPSS: 0.57%

updated 2026-06-10T18:31:53

1 posts

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.<br

1 repos

https://github.com/reactivezero/CVE-2026-20251

cyberveille@mastobot.ping.moi at 2026-06-29T17:30:21.000Z ##

📢 CVE-2026-20251 : RCE via désérialisation jsonpickle dans Splunk Secure Gateway (CVSS 8.8)
📝 ## 🔍 Contexte

Publié le 29 juin 2026 sur GitHub par le chercheur **Fady Oueslati** (ReactiveZero Security Research), ce dépôt documente...
📖 cyberveille : cyberveille.ch/posts/2026-06-2
🌐 source : github.com/reactivezero/CVE-20
#CVE_2026_20251 #CVE_2026_20253 #Cyberveille

##

CVE-2026-20245
(7.8 HIGH)

EPSS: 9.92%

updated 2026-06-09T21:32:21

2 posts

A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A su

3 repos

https://github.com/0xBlackash/CVE-2026-20245

https://github.com/HORKimhab/CVE-2026-20245

https://github.com/fevar54/CVE-2026-20245---Cisco-SD-WAN-Privilege-Escalation-Exploit

pentesttools at 2026-06-29T11:53:17.867Z ##

Exploitation started in March. Cisco disclosed in June. Patch landed June 10.

For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.

Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:

""Whoever used this vulnerability had working knowledge of it in this period while defenders had none.""

🏴‍☠️ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.

That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.

From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.

The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.

If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.

📍Read the full article by Kevin Poireault: infosecurity-magazine.com/news

##

pentesttools@infosec.exchange at 2026-06-29T11:53:17.000Z ##

Exploitation started in March. Cisco disclosed in June. Patch landed June 10.

For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.

Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:

""Whoever used this vulnerability had working knowledge of it in this period while defenders had none.""

🏴‍☠️ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.

That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.

From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.

The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.

If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.

📍Read the full article by Kevin Poireault: infosecurity-magazine.com/news

#vulnerabilityassessment #ethicalhacking #pentesting

##

CVE-2026-46817
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-05-29T18:31:20

4 posts

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Con

undercodenews@mastodon.social at 2026-06-29T15:42:51.000Z ##

Critical Oracle E-Business Suite Vulnerability Under Active Attack: Organizations Face Immediate Risk as Hackers Exploit CVE-2026-46817 + Video

Critical Oracle E-Business Suite Vulnerability Under Active Attack: Organizations Face Immediate Risk as Hackers Exploit CVE-2026-46817 Introduction: A Patch Released Too Late for Many Organizations The cybersecurity landscape has once again highlighted a familiar and costly lesson: releasing security patches is only half the…

undercodenews.com/critical-ora

##

oversecurity@mastodon.social at 2026-06-29T14:34:39.000Z ##

Hackers now exploit critical Oracle E-Business flaw in attacks

Attackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to...

🔗️ [Bleepingcomputer] link.is.it/6jsPkq

##

Analyst207@mastodon.social at 2026-06-29T14:15:11.000Z ##

Hackers Exploit Oracle E-Business Flaw in Targeted Attacks

Hackers are actively exploiting a critical Oracle E-Business flaw, CVE-2026-46817, with a near-perfect CVSS score of 9.8, in targeted attacks, allowing for unauthenticated HTTP takeover. This alarming vulnerability has no known previous exploitation and no public proof-of-concept code exists, making it a high-risk threat.

osintsights.com/hackers-exploi

#Cve202646817 #OracleEbusinessSuite #EmergingThreats #SupplyChain #ZeroDay

##

oversecurity@mastodon.social at 2026-06-29T14:34:39.000Z ##

Hackers now exploit critical Oracle E-Business flaw in attacks

Attackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to...

🔗️ [Bleepingcomputer] link.is.it/6jsPkq

##

CVE-2026-20182
(10.0 CRITICAL)

EPSS: 87.69%

updated 2026-05-14T18:33:03

2 posts

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.&nbsp; A vulnerability in the peering authentica

Nuclei template

3 repos

https://github.com/Nxploited/CVE-2026-20182

https://github.com/portbuster1337/CVE-2026-20182

https://github.com/HORKimhab/CVE-2026-20182

pentesttools at 2026-06-29T11:53:17.867Z ##

Exploitation started in March. Cisco disclosed in June. Patch landed June 10.

For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.

Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:

""Whoever used this vulnerability had working knowledge of it in this period while defenders had none.""

🏴‍☠️ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.

That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.

From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.

The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.

If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.

📍Read the full article by Kevin Poireault: infosecurity-magazine.com/news

##

pentesttools@infosec.exchange at 2026-06-29T11:53:17.000Z ##

Exploitation started in March. Cisco disclosed in June. Patch landed June 10.

For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.

Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:

""Whoever used this vulnerability had working knowledge of it in this period while defenders had none.""

🏴‍☠️ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.

That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.

From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.

The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.

If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.

📍Read the full article by Kevin Poireault: infosecurity-magazine.com/news

#vulnerabilityassessment #ethicalhacking #pentesting

##

CVE-2026-6307
(8.8 HIGH)

EPSS: 0.36%

updated 2026-04-15T21:30:19

2 posts

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

lobsters@mastodon.social at 2026-06-29T15:10:11.000Z ##

Longinus: 2 Boundaries in One Bug, Piercing Chrome’s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307 lobste.rs/s/uaoe9y #security #web
nebusec.ai/research/v8-cve-202

##

lobsters@mastodon.social at 2026-06-29T15:10:11.000Z ##

Longinus: 2 Boundaries in One Bug, Piercing Chrome’s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307 lobste.rs/s/uaoe9y #security #web
nebusec.ai/research/v8-cve-202

##

CVE-2026-24294
(7.8 HIGH)

EPSS: 2.73%

updated 2026-03-27T21:32:39

2 posts

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/jonaslejon/ad-autopwn

https://github.com/0xNDI/CVE-2026-24294

DailyCyberSecurity at 2026-06-29T08:56:26.274Z ##

Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now.

securityonline.info/ntlm-refle

##

DailyCyberSecurity@infosec.exchange at 2026-06-29T08:56:26.000Z ##

Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now.

#NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec

securityonline.info/ntlm-refle

##

CVE-2026-3102
(6.3 MEDIUM)

EPSS: 3.41%

updated 2026-02-26T21:32:34

1 posts

A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 13.

2 repos

https://github.com/ErikDervishi03/CVE-2026-31024

https://github.com/HORKimhab/CVE-2026-3102

cvedatabase@techhub.social at 2026-06-29T10:30:03.000Z ##

🛡️ Weekly CVE Roundup is here! We're highlighting a critical path traversal bypass in Node.js (CVE-2026-3102) and discussing why experimental features can be a liability in production. Stay ahead of the latest security trends. 🔒 Read more: cvedatabase.com/blog/weekly-cv #NodeJS #CyberSecurity #CVE #Infosec #VulnerabilityManagement

##

secdb at 2026-06-29T12:56:53.325Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-06-29T12:56:53.000Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-54066
(0 None)

EPSS: 1.89%

2 posts

N/A

Nuclei template

secdb at 2026-06-29T12:56:53.325Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-06-29T12:56:53.000Z ##

📈 CVE Published in last days (2026-06-22 - 2026-06-22)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 179
- High: 735
- Medium: 619
- Low: 105
- None: 418

Status:
- : 153
- Analyzed: 447
- Awaiting Analysis: 135
- Deferred: 685
- Modified: 12
- Received: 523
- Rejected: 8
- Undergoing Analysis: 93

CISA KEVs:
- CISA-2026:0623 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0625 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 500
- kernel.org: 413
- Patchstack: 158
- N/A: 153
- VulnCheck: 143
- Wordfence: 70
- MITRE: 53
- Red Hat, Inc.: 34
- wolfSSL Inc.: 32
- VulDB: 31

Top Affected Products:
- UNKNOWN: 1526
- Wolfssl: 32
- N8n: 25
- Google Chrome: 21
- Openwebui Open Webui: 15
- Flowiseai Flowise: 14
- Angularjs: 13
- Gitlab: 13
- Langflow: 12
- Frappe Framework: 12

Top EPSS Score:
- CVE-2026-32315 - 2.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56274 - 2.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-28496 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54066 - 1.89 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54157 - 1.78 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12486 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12850 - 1.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12849 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12851 - 1.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-9776 - 1.58 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-50160
(0 None)

EPSS: 0.00%

1 posts

N/A

undercodenews@mastodon.social at 2026-06-29T12:46:43.000Z ##

Critical 100 CVSS Flaw Lets Attackers Take Over Hoppscotch Servers in a Single Request + Video

A Silent Opening in the API Layer That Turned Into Full Server Compromise A devastating security vulnerability has been uncovered in the self-hosted version of Hoppscotch, exposing how a single overlooked validation rule can escalate into full system takeover. Assigned CVE-2026-50160 and rated CVSS 10.0, this flaw represents the highest severity class of vulnerability:…

undercodenews.com/critical-100

##

CVE-2026-47220
(0 None)

EPSS: 0.46%

2 posts

N/A

thehackerwire@mastodon.social at 2026-06-29T08:00:40.000Z ##

🟠 CVE-2026-47220 - High (7.5)

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host related options is specified, like HOST_FIRST, SNI_FIR...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-06-29T08:00:40.000Z ##

🟠 CVE-2026-47220 - High (7.5)

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host related options is specified, like HOST_FIRST, SNI_FIR...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47193
(0 None)

EPSS: 0.25%

1 posts

N/A

thehackerwire@mastodon.social at 2026-06-29T07:00:12.000Z ##

🟠 CVE-2026-47193 - High (7.5)

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46386
(0 None)

EPSS: 0.27%

1 posts

N/A

thehackerwire@mastodon.social at 2026-06-29T07:00:01.000Z ##

🔴 CVE-2026-46386 - Critical (9.9)

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49991
(0 None)

EPSS: 0.27%

1 posts

N/A

hugovalters@mastodon.social at 2026-06-29T05:10:38.000Z ##

CVE-2026-49991 - Critical path traversal in RustFS. Authenticated users can write objects to other tenants' buckets via Snowball auto-extract, breaking isolation. CVSS 8.6. Unpatched. Mitigate immediately. #CVE #infosec #RustFS

valtersit.com/cve/CVE-2026-499

##

CVE-2026-48751
(0 None)

EPSS: 0.00%

1 posts

N/A

blog@stgraber.org at 2026-06-29T04:32:40.000Z ##

Announcing Incus 7.2

The Incus team is pleased to announce the release of Incus 7.2!

It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-48749 (critical) – Arbitrary file read+write on host via rootfs/ symlink in malicious image
  • CVE-2026-48750 (critical) – Arbitrary file write on host via exec-output symlink in crafted image
  • CVE-2026-48751 (critical) – Restricted project bypass leading to arbitrary command execution
  • CVE-2026-48752 (critical) – Arbitrary file read+write on host via templates/ symlink in malicious image
  • CVE-2026-48755 (critical) – Argument injection in backup compression algorithm leading to arbitrary file write and command execution
  • CVE-2026-48769 (critical) – Arbitrary file write on client due to trusted image hash
  • CVE-2026-55621 (high) – Project restriction bypass for custom volume copy across projects
  • CVE-2026-55622 (high) – Project restriction bypass in instance copy across projects

On the feature front, the highlights for this release are:

  • Per-instance SELinux integration
  • New incus default CLI command
  • Filtered server info by default
  • Keepalive timeout from the CLI
  • Better OS-specific handling of CLI configuration
  • Standalone server certificate update
  • Static network configuration for OCI containers
  • Per-instance BGP route advertisement
  • Dynamic addresses in proxy NAT mode
  • Expanded NBD access to VMs
  • Btrfs compression for storage volumes
  • InfiniBand SR-IOV GUID configuration
  • Websocket origin restriction

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=rcldqF6SpXA

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

CVE-2026-48755
(0 None)

EPSS: 0.00%

1 posts

N/A

blog@stgraber.org at 2026-06-29T04:32:40.000Z ##

Announcing Incus 7.2

The Incus team is pleased to announce the release of Incus 7.2!

It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-48749 (critical) – Arbitrary file read+write on host via rootfs/ symlink in malicious image
  • CVE-2026-48750 (critical) – Arbitrary file write on host via exec-output symlink in crafted image
  • CVE-2026-48751 (critical) – Restricted project bypass leading to arbitrary command execution
  • CVE-2026-48752 (critical) – Arbitrary file read+write on host via templates/ symlink in malicious image
  • CVE-2026-48755 (critical) – Argument injection in backup compression algorithm leading to arbitrary file write and command execution
  • CVE-2026-48769 (critical) – Arbitrary file write on client due to trusted image hash
  • CVE-2026-55621 (high) – Project restriction bypass for custom volume copy across projects
  • CVE-2026-55622 (high) – Project restriction bypass in instance copy across projects

On the feature front, the highlights for this release are:

  • Per-instance SELinux integration
  • New incus default CLI command
  • Filtered server info by default
  • Keepalive timeout from the CLI
  • Better OS-specific handling of CLI configuration
  • Standalone server certificate update
  • Static network configuration for OCI containers
  • Per-instance BGP route advertisement
  • Dynamic addresses in proxy NAT mode
  • Expanded NBD access to VMs
  • Btrfs compression for storage volumes
  • InfiniBand SR-IOV GUID configuration
  • Websocket origin restriction

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=rcldqF6SpXA

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

CVE-2026-55621
(0 None)

EPSS: 0.00%

1 posts

N/A

blog@stgraber.org at 2026-06-29T04:32:40.000Z ##

Announcing Incus 7.2

The Incus team is pleased to announce the release of Incus 7.2!

It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-48749 (critical) – Arbitrary file read+write on host via rootfs/ symlink in malicious image
  • CVE-2026-48750 (critical) – Arbitrary file write on host via exec-output symlink in crafted image
  • CVE-2026-48751 (critical) – Restricted project bypass leading to arbitrary command execution
  • CVE-2026-48752 (critical) – Arbitrary file read+write on host via templates/ symlink in malicious image
  • CVE-2026-48755 (critical) – Argument injection in backup compression algorithm leading to arbitrary file write and command execution
  • CVE-2026-48769 (critical) – Arbitrary file write on client due to trusted image hash
  • CVE-2026-55621 (high) – Project restriction bypass for custom volume copy across projects
  • CVE-2026-55622 (high) – Project restriction bypass in instance copy across projects

On the feature front, the highlights for this release are:

  • Per-instance SELinux integration
  • New incus default CLI command
  • Filtered server info by default
  • Keepalive timeout from the CLI
  • Better OS-specific handling of CLI configuration
  • Standalone server certificate update
  • Static network configuration for OCI containers
  • Per-instance BGP route advertisement
  • Dynamic addresses in proxy NAT mode
  • Expanded NBD access to VMs
  • Btrfs compression for storage volumes
  • InfiniBand SR-IOV GUID configuration
  • Websocket origin restriction

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=rcldqF6SpXA

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

CVE-2026-55622
(0 None)

EPSS: 0.00%

1 posts

N/A

blog@stgraber.org at 2026-06-29T04:32:40.000Z ##

Announcing Incus 7.2

The Incus team is pleased to announce the release of Incus 7.2!

It’s another pretty busy release for us with a varied set of new features across the board as well as the usual set of performance improvements and bugfixes.

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-48749 (critical) – Arbitrary file read+write on host via rootfs/ symlink in malicious image
  • CVE-2026-48750 (critical) – Arbitrary file write on host via exec-output symlink in crafted image
  • CVE-2026-48751 (critical) – Restricted project bypass leading to arbitrary command execution
  • CVE-2026-48752 (critical) – Arbitrary file read+write on host via templates/ symlink in malicious image
  • CVE-2026-48755 (critical) – Argument injection in backup compression algorithm leading to arbitrary file write and command execution
  • CVE-2026-48769 (critical) – Arbitrary file write on client due to trusted image hash
  • CVE-2026-55621 (high) – Project restriction bypass for custom volume copy across projects
  • CVE-2026-55622 (high) – Project restriction bypass in instance copy across projects

On the feature front, the highlights for this release are:

  • Per-instance SELinux integration
  • New incus default CLI command
  • Filtered server info by default
  • Keepalive timeout from the CLI
  • Better OS-specific handling of CLI configuration
  • Standalone server certificate update
  • Static network configuration for OCI containers
  • Per-instance BGP route advertisement
  • Dynamic addresses in proxy NAT mode
  • Expanded NBD access to VMs
  • Btrfs compression for storage volumes
  • InfiniBand SR-IOV GUID configuration
  • Websocket origin restriction

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=rcldqF6SpXA

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

##

Visit counter For Websites