##
Updated at UTC 2026-09-02T00:47:28.350409
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-72984 | 8.8 | 0.44% | 1 | 0 | 2026-09-01T23:30:58.867000 | Access of resource using incompatible type ('type confusion') in Microsoft Edge | |
| CVE-2026-84375 | 7.5 | 0.00% | 2 | 0 | 2026-09-01T22:17:19.440000 | js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3. | |
| CVE-2026-84374 | 7.5 | 0.00% | 2 | 0 | 2026-09-01T22:17:19.293000 | Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3 | |
| CVE-2026-84372 | 9.8 | 0.00% | 2 | 0 | 2026-09-01T22:17:18.987000 | Predis is a flexible and feature-complete Redis and Valkey client for PHP. From | |
| CVE-2026-83549 | 7.8 | 0.00% | 2 | 0 | 2026-09-01T22:17:13.290000 | Post-authentication Improper Neutralization of Special Elements used in an OS Co | |
| CVE-2026-83548 | 0 | 0.00% | 2 | 0 | 2026-09-01T22:17:13.170000 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla | |
| CVE-2026-75604 | 9.0 | 0.00% | 3 | 3 | 2026-09-01T22:17:12.697000 | Next.js is a React framework for building full-stack web applications. From 13.4 | |
| CVE-2026-76658 | 10.0 | 0.00% | 2 | 0 | 2026-09-01T21:31:59 | A vulnerability has been identified in the SSH daemon of HPE Networking Fabric C | |
| CVE-2026-84370 | 8.2 | 0.00% | 2 | 0 | 2026-09-01T21:18:48.217000 | SVGO, short for SVG Optimizer, is a Node.js library and command-line application | |
| CVE-2026-76657 | 10.0 | 0.00% | 2 | 0 | 2026-09-01T21:18:46.043000 | Vulnerabilities have been identified in the API of HPE Networking Fabric Compose | |
| CVE-2026-73782 | 8.8 | 0.00% | 2 | 0 | 2026-09-01T21:18:45.057000 | A format string vulnerability exists in the command line interface of AOS-CX tha | |
| CVE-2026-73773 | 7.5 | 0.00% | 2 | 0 | 2026-09-01T21:18:44.050000 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpo | |
| CVE-2026-77846 | 0 | 0.14% | 1 | 0 | 2026-09-01T21:15:00.147000 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in | |
| CVE-2026-81533 | 7.1 | 0.21% | 1 | 0 | 2026-09-01T21:03:04.987000 | An application using the MongoDB BI Connector ODBC Driver may encounter a memory | |
| CVE-2026-19806 | 8.8 | 0.40% | 2 | 0 | 2026-09-01T20:47:54.130000 | The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Tick | |
| CVE-2026-82908 | 8.8 | 0.12% | 1 | 0 | 2026-09-01T20:47:54.130000 | A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this | |
| CVE-2026-84268 | 8.8 | 0.00% | 2 | 0 | 2026-09-01T18:30:49 | A flaw was found in the SFTP backend in gvfs. When mounting a share and reading | |
| CVE-2026-58566 | 8.8 | 0.00% | 2 | 0 | 2026-09-01T18:30:49 | Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged atta | |
| CVE-2026-84202 | 8.8 | 0.00% | 2 | 0 | 2026-09-01T18:17:48.503000 | ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, | |
| CVE-2026-62911 | 8.0 | 1.25% | 5 | 1 | 2026-09-01T15:30:53 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an a | |
| CVE-2026-82593 | 9.9 | 0.51% | 1 | 0 | 2026-09-01T15:17:33.547000 | A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41 | |
| CVE-2026-82542 | 10.0 | 0.64% | 2 | 0 | 2026-09-01T15:17:32.847000 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue i | |
| CVE-2026-79746 | 8.1 | 0.25% | 1 | 0 | 2026-09-01T15:17:29.747000 | MCPHub is a unified hub for centrally managing and dynamically orchestrating mul | |
| CVE-2026-67394 | 0 | 1.17% | 2 | 0 | 2026-09-01T14:17:38.217000 | A critical local privilege escalation via OS command injection vulnerability has | |
| CVE-2026-84195 | 7.7 | 0.00% | 2 | 0 | 2026-09-01T13:20:09.440000 | Kyverno before 1.16.4 automatically attaches the admission controller's ServiceA | |
| CVE-2026-84199 | 7.7 | 0.00% | 2 | 0 | 2026-09-01T12:31:56 | Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerabilit | |
| CVE-2026-84196 | 7.7 | 0.00% | 2 | 0 | 2026-09-01T12:31:56 | Kyverno before 1.18.0 contains a server-side request forgery vulnerability in ap | |
| CVE-2026-78319 | None | 0.40% | 3 | 0 | 2026-09-01T09:31:19 | A service running on the affected products contains a potential Time-of-Check Ti | |
| CVE-2026-83772 | 9.9 | 1.69% | 2 | 0 | 2026-09-01T06:33:01 | A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router | |
| CVE-2026-19952 | 7.5 | 0.78% | 2 | 0 | 2026-09-01T06:33:00 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary | |
| CVE-2026-19295 | 9.9 | 0.96% | 1 | 1 | 2026-09-01T04:18:00.830000 | IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execut | |
| CVE-2026-75865 | 9.8 | 0.51% | 1 | 0 | 2026-09-01T03:31:10 | The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Go | |
| CVE-2026-65643 | None | 0.64% | 3 | 1 | 2026-09-01T03:31:04 | Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated user | |
| CVE-2026-82447 | 8.8 | 0.45% | 1 | 0 | 2026-09-01T03:16:51.973000 | Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock | |
| CVE-2026-55065 | 8.1 | 0.35% | 1 | 0 | 2026-09-01T02:16:58.017000 | Vikunja is an open-source self-hosted task management platform. From 0.24.6 unti | |
| CVE-2026-82954 | 9.9 | 0.62% | 1 | 0 | 2026-09-01T00:31:43 | A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the fun | |
| CVE-2026-82882 | 8.8 | 0.31% | 1 | 0 | 2026-08-31T22:17:31.940000 | Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestr | |
| CVE-2026-18891 | 8.2 | 0.29% | 1 | 0 | 2026-08-31T21:53:54.967000 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute a | |
| CVE-2026-83596 | 8.8 | 0.29% | 1 | 0 | 2026-08-31T21:32:23 | A flaw was found in WebKitGTK. Processing malicious web content can cause memory | |
| CVE-2026-82226 | 9.8 | 0.31% | 1 | 0 | 2026-08-31T21:32:22 | Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. | |
| CVE-2026-82078 | 9.1 | 0.93% | 8 | 2 | 2026-08-31T21:31:56 | An unsafe dynamic class loading vulnerability exists in the database connection | |
| CVE-2026-81578 | 9.8 | 0.77% | 7 | 2 | 2026-08-31T21:31:56 | An improper access control vulnerability exists in the web management interface | |
| CVE-2026-82655 | 7.5 | 0.33% | 1 | 0 | 2026-08-31T20:56:08.800000 | Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relati | |
| CVE-2026-82285 | 8.2 | 0.31% | 1 | 0 | 2026-08-31T20:56:08.800000 | bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability | |
| CVE-2026-81934 | 7.1 | 0.43% | 2 | 0 | 2026-08-31T20:17:12.093000 | Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' f | |
| CVE-2026-16947 | 9.1 | 0.24% | 1 | 0 | 2026-08-31T20:14:36.250000 | The Total processing card payments for WooCommerce WordPress plugin through 7.3 | |
| CVE-2026-77007 | 7.5 | 0.26% | 1 | 0 | 2026-08-31T20:14:36.250000 | The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through | |
| CVE-2026-76586 | 7.5 | 0.21% | 1 | 0 | 2026-08-31T20:14:36.250000 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin | |
| CVE-2026-82472 | 7.5 | 0.41% | 1 | 0 | 2026-08-31T19:17:20.790000 | Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf en | |
| CVE-2026-82460 | 9.8 | 0.77% | 1 | 0 | 2026-08-31T19:17:20.013000 | Cloud Commander before 19.20.2 contains a directory traversal vulnerability in R | |
| CVE-2026-82454 | 9.1 | 0.23% | 1 | 0 | 2026-08-31T19:17:19.747000 | The Omnivore API (packages/api) before the fix in commit abf53d6 contains an aut | |
| CVE-2026-82329 | 9.8 | 0.38% | 10 | 2 | 2026-08-31T19:17:18.813000 | JFrog Artifactory contains an authentication weakness that, under default config | |
| CVE-2026-82282 | 8.0 | 0.26% | 1 | 0 | 2026-08-31T19:17:17.753000 | Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, al | |
| CVE-2026-82270 | 7.5 | 0.28% | 1 | 0 | 2026-08-31T19:17:17.097000 | Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnera | |
| CVE-2026-77586 | 8.0 | 0.23% | 1 | 0 | 2026-08-31T19:17:13.323000 | In MongoDB Connector for BI, MongoDB object names such as collection, field, and | |
| CVE-2026-55565 | 9.9 | 0.46% | 1 | 0 | 2026-08-31T19:17:00.220000 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpr | |
| CVE-2026-55552 | 7.5 | 0.43% | 1 | 0 | 2026-08-31T19:16:59.003000 | Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler. | |
| CVE-2026-55485 | 8.8 | 0.39% | 1 | 0 | 2026-08-31T19:16:56.267000 | Piccolo Admin is an admin interface and content management system for Python, bu | |
| CVE-2026-55247 | 9.1 | 0.34% | 1 | 0 | 2026-08-31T19:16:55.260000 | plone.app.event provides the event content type for Plone. Prior to versions 5.2 | |
| CVE-2026-54788 | 7.5 | 0.56% | 1 | 0 | 2026-08-31T19:16:53.413000 | dd-trace-rs provides Datadog application performance monitoring for Rust. From 0 | |
| CVE-2026-54754 | 9.6 | 0.30% | 1 | 0 | 2026-08-31T19:16:52.523000 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1 | |
| CVE-2026-17615 | 7.5 | 0.28% | 1 | 0 | 2026-08-31T18:31:39 | A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unau | |
| CVE-2026-83492 | None | 0.24% | 1 | 0 | 2026-08-31T18:31:39 | Improper input validation vulnerability in Extend Themes Kubio AI Website Builde | |
| CVE-2026-82641 | 8.6 | 0.34% | 1 | 0 | 2026-08-31T17:17:45.880000 | keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to | |
| CVE-2026-82636 | 7.9 | 0.79% | 1 | 0 | 2026-08-31T17:17:45.603000 | Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during | |
| CVE-2026-46595 | 10.0 | 0.50% | 1 | 0 | 2026-08-31T13:18:18.560000 | Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server | |
| CVE-2026-82616 | 9.9 | 0.61% | 1 | 0 | 2026-08-31T06:30:34 | A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is | |
| CVE-2026-82592 | 9.9 | 0.77% | 1 | 1 | 2026-08-31T00:30:32 | A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function | |
| CVE-2026-56718 | 7.5 | 0.58% | 1 | 0 | 2026-08-30T21:30:34 | AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path travers | |
| CVE-2026-82549 | 8.3 | 0.19% | 1 | 0 | 2026-08-30T18:33:59 | A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an | |
| CVE-2026-82645 | 8.6 | 0.13% | 1 | 0 | 2026-08-30T15:30:35 | AVideo (current commit e01e41ecc and earlier) exposes stream credentials through | |
| CVE-2026-82644 | 7.5 | 0.26% | 1 | 0 | 2026-08-30T15:30:35 | WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting | |
| CVE-2026-82639 | 7.5 | 0.30% | 1 | 0 | 2026-08-30T15:30:35 | NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation | |
| CVE-2026-82638 | 7.5 | 0.30% | 1 | 0 | 2026-08-30T15:30:34 | jina-ai reader disables its private-address guard outside Google Cloud deploymen | |
| CVE-2026-82642 | 8.8 | 0.38% | 1 | 0 | 2026-08-30T15:30:34 | Readest is an open-source e-book reader built on Tauri. In versions prior to 0.1 | |
| CVE-2026-82657 | 7.5 | 0.27% | 1 | 0 | 2026-08-30T15:30:29 | Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS fee | |
| CVE-2026-82654 | 8.9 | 0.22% | 1 | 0 | 2026-08-30T15:30:28 | SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields | |
| CVE-2026-82653 | 8.9 | 0.22% | 1 | 0 | 2026-08-30T15:30:28 | SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in con | |
| CVE-2026-82635 | 8.8 | 0.40% | 1 | 0 | 2026-08-30T15:30:27 | Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file | |
| CVE-2026-82539 | 9.1 | 0.60% | 1 | 1 | 2026-08-30T12:31:39 | A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This imp | |
| CVE-2026-15980 | 9.8 | 0.45% | 2 | 0 | 2026-08-30T06:30:22 | The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in a | |
| CVE-2026-16259 | 9.8 | 0.28% | 1 | 0 | 2026-08-30T03:32:22 | The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the accou | |
| CVE-2026-16061 | 8.6 | 0.26% | 1 | 0 | 2026-08-30T03:32:22 | The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a | |
| CVE-2026-77012 | 9.3 | 0.20% | 1 | 0 | 2026-08-30T03:31:22 | The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install s | |
| CVE-2026-16600 | 7.7 | 0.20% | 1 | 0 | 2026-08-30T03:31:21 | The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability ch | |
| CVE-2026-76548 | 8.2 | 0.19% | 1 | 0 | 2026-08-30T03:31:21 | The User Profile Builder WordPress plugin before 4.0.1 does not properly restri | |
| CVE-2026-15369 | 9.8 | 0.40% | 1 | 0 | 2026-08-29T21:30:26 | The Custom User Registration Fields for WooCommerce plugin for WordPress is vuln | |
| CVE-2026-82463 | 8.1 | 0.30% | 1 | 0 | 2026-08-29T18:31:38 | pac4j-core before 6.5.6 contains an authentication bypass vulnerability in Check | |
| CVE-2026-82474 | 7.8 | 0.13% | 1 | 0 | 2026-08-29T18:31:38 | Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat sys | |
| CVE-2026-82473 | 8.2 | 0.35% | 1 | 0 | 2026-08-29T18:31:38 | KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS | |
| CVE-2026-75807 | 7.5 | 0.29% | 1 | 0 | 2026-08-29T18:31:38 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authen | |
| CVE-2026-82475 | 8.1 | 0.26% | 1 | 0 | 2026-08-29T18:31:38 | iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerabilit | |
| CVE-2026-82466 | 8.7 | 0.34% | 1 | 0 | 2026-08-29T18:31:32 | Rodauth before 2.46.0 contains an authentication bypass vulnerability in the web | |
| CVE-2026-82461 | 8.1 | 0.19% | 2 | 0 | 2026-08-29T18:31:31 | pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audien | |
| CVE-2026-82450 | 8.8 | 0.57% | 2 | 0 | 2026-08-29T15:30:27 | BookStack before 26.05.4 contains a remote code execution vulnerability in the p | |
| CVE-2026-82457 | 7.8 | 0.12% | 1 | 0 | 2026-08-29T15:30:27 | su-exec through 0.3 fails to validate numeric user and group identifiers parsed | |
| CVE-2026-82456 | 10.0 | 0.37% | 1 | 0 | 2026-08-29T15:30:27 | argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts | |
| CVE-2026-82452 | 9.8 | 0.46% | 1 | 0 | 2026-08-29T15:30:27 | rust-iot-platform through commit 5df942ab contains an authentication bypass vuln | |
| CVE-2026-82453 | 7.5 | 0.28% | 1 | 0 | 2026-08-29T15:30:21 | rust-iot-platform through commit 5df942ab stores user passwords in cleartext wit | |
| CVE-2026-82448 | 9.8 | 0.41% | 1 | 0 | 2026-08-29T15:30:20 | Shinobi before commit 5a76c74f contains a hardcoded connection key in the child | |
| CVE-2026-14494 | 9.8 | 0.69% | 1 | 0 | 2026-08-29T12:30:27 | The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution | |
| CVE-2026-80714 | 9.8 | 0.40% | 1 | 0 | 2026-08-29T09:31:36 | In the Linux kernel, the following vulnerability has been resolved: ipvs: do no | |
| CVE-2026-38638 | 7.5 | 0.45% | 1 | 0 | 2026-08-29T00:32:03 | An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allo | |
| CVE-2026-56854 | 7.5 | 0.33% | 1 | 0 | 2026-08-29T00:32:03 | The source-address critical option in the Permissions returned by an authenticat | |
| CVE-2026-18729 | 8.8 | 0.47% | 1 | 1 | 2026-08-29T00:31:02 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacke | |
| CVE-2026-19286 | 9.8 | 0.62% | 1 | 1 | 2026-08-29T00:31:02 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute a | |
| CVE-2026-18527 | 9.9 | 0.29% | 1 | 0 | 2026-08-29T00:31:01 | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (AR | |
| CVE-2026-17203 | 7.5 | 0.43% | 1 | 0 | 2026-08-29T00:31:01 | IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated | |
| CVE-2026-82278 | 8.8 | 0.56% | 1 | 0 | 2026-08-28T22:16:56.293000 | BISHENG before 2.6.0 contains a remote code execution vulnerability in the workf | |
| CVE-2026-55634 | 9.9 | 0.45% | 1 | 0 | 2026-08-28T22:16:51.290000 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.1 | |
| CVE-2026-55248 | 9.1 | 0.32% | 1 | 0 | 2026-08-28T22:16:50.527000 | plone.app.portlets provides portlets and a Plone-specific user interface for plo | |
| CVE-2026-37237 | 7.5 | 0.53% | 1 | 0 | 2026-08-28T22:16:48.207000 | vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Ser | |
| CVE-2026-50979 | 8.1 | 1.43% | 1 | 1 | 2026-08-28T21:32:17 | A command injection vulnerability in the 'advanced/curl' component of Osbil Tech | |
| CVE-2026-6876 | None | 0.36% | 2 | 0 | 2026-08-28T21:32:13 | ServiceNow has remediated a sandbox escape security issue that was identified in | |
| CVE-2026-18886 | None | 0.25% | 1 | 0 | 2026-08-28T21:32:13 | ServiceNow has remediated an improper access control vulnerability that was iden | |
| CVE-2026-82284 | 8.1 | 0.24% | 1 | 0 | 2026-08-28T21:31:36 | Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/ | |
| CVE-2026-82275 | 7.5 | 0.37% | 1 | 0 | 2026-08-28T21:31:29 | Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the documen | |
| CVE-2026-82283 | 8.1 | 0.24% | 1 | 0 | 2026-08-28T21:31:27 | VoltAgent through 2.1.20 fails to validate conversation ownership in memory API | |
| CVE-2026-82277 | 9.8 | 0.43% | 1 | 0 | 2026-08-28T21:31:26 | Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutat | |
| CVE-2026-82269 | 8.1 | 0.30% | 1 | 0 | 2026-08-28T21:31:25 | Gophish through 0.12.1 fails to enforce account lockout and password change requ | |
| CVE-2026-82268 | 7.5 | 0.28% | 1 | 0 | 2026-08-28T21:31:25 | Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability i | |
| CVE-2026-75124 | 7.5 | 0.48% | 1 | 0 | 2026-08-28T21:31:24 | PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication | |
| CVE-2026-75486 | 8.0 | 1.25% | 1 | 0 | 2026-08-28T21:31:24 | Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that a | |
| CVE-2026-82266 | 9.8 | 0.34% | 1 | 0 | 2026-08-28T21:31:23 | Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_requi | |
| CVE-2026-82021 | 8.3 | 0.23% | 1 | 0 | 2026-08-28T21:31:19 | Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its | |
| CVE-2026-56100 | 8.1 | 0.29% | 1 | 0 | 2026-08-28T21:31:17 | SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerab | |
| CVE-2026-37736 | 7.5 | 0.34% | 1 | 0 | 2026-08-28T21:31:12 | An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2. | |
| CVE-2026-74820 | None | 0.25% | 1 | 0 | 2026-08-28T21:31:08 | ServiceNow has remediated a SQL injection vulnerability that was identified in i | |
| CVE-2026-76640 | 7.5 | 0.35% | 1 | 1 | 2026-08-28T20:19:54.877000 | Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities | |
| CVE-2026-47864 | 6.4 | 3.44% | 1 | 0 | 2026-08-28T20:17:33.510000 | SerializingHttpMessageConverter deserializes the body of incoming HTTP requests | |
| CVE-2026-55484 | 7.5 | 0.34% | 1 | 0 | 2026-08-28T19:19:39 | ### Summary A single unauthenticated HTTP request to a path starting with `?` (e | |
| CVE-2026-55215 | 7.5 | 0.42% | 1 | 0 | 2026-08-28T19:03:39 | ### Summary When SSL/TLS is enabled but no CA / server certificate is provided, | |
| CVE-2026-18634 | 8.4 | 0.22% | 2 | 0 | 2026-08-28T18:58:27.140000 | An insecure handling of serialized objects vulnerability was found in the one of | |
| CVE-2026-66154 | 8.3 | 0.13% | 2 | 0 | 2026-08-28T18:58:27.140000 | An insufficient certificate validation in a privileged communication workflow, w | |
| CVE-2026-55584 | 7.5 | 2.42% | 1 | 1 | 2026-08-28T18:30:56 | ## Summary phpSysInfo's `PSI_ALLOWED` IP allowlist can be trivially bypassed by | |
| CVE-2026-55559 | 9.8 | 0.55% | 1 | 0 | 2026-08-28T17:23:05 | ### Summary `templateArgs` sent to `POST /api/instances` (and `PATCH /api/insta | |
| CVE-2026-55521 | 8.8 | 0.36% | 1 | 0 | 2026-08-28T17:09:36 | ### Summary Multiple Missing Function Level Access Control vulnerabilities exist | |
| CVE-2026-55511 | 9.1 | 0.68% | 1 | 1 | 2026-08-28T17:06:57 | ## Overview Yamcs compiles StreamSQL expressions to Java on the fly with the Ja | |
| CVE-2026-54755 | 9.6 | 0.39% | 1 | 0 | 2026-08-28T16:25:49 | ## Summary The per-entry percentages of a KDA asset's **split royalties** are v | |
| CVE-2026-55108 | 8.5 | 0.57% | 1 | 0 | 2026-08-28T16:13:22 | ### Summary KubeVela's Terraform remote configuration loader can be abused to m | |
| CVE-2026-82222 | 10.0 | 0.42% | 3 | 3 | 2026-08-28T12:30:36 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP | |
| CVE-2026-66384 | 5.3 | 0.58% | 2 | 1 | 2026-08-28T12:21:47.053000 | An authenticated user may write data outside the intended Docker cache path unde | |
| CVE-2026-76581 | 9.8 | 0.34% | 1 | 2 | 2026-08-28T09:31:57 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypa | |
| CVE-2026-48376 | 5.4 | 13.92% | 1 | 0 | 2026-08-28T00:17:56.180000 | is affected by an Improper Encoding or Escaping of Output vulnerability that cou | |
| CVE-2023-49105 | 9.8 | 43.20% | 1 | 1 | template | 2026-08-27T21:32:08 | An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker ca |
| CVE-2026-76639 | 8.8 | 0.71% | 1 | 1 | 2026-08-27T21:31:57 | Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code ex | |
| CVE-2026-53362 | 7.8 | 0.51% | 1 | 1 | 2026-08-27T21:31:19 | In the Linux kernel, the following vulnerability has been resolved: ipv6: accou | |
| CVE-2026-60004 | 9.8 | 86.78% | 3 | 11 | template | 2026-08-27T11:41:19.230000 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through G |
| CVE-2026-18431 | 9.8 | 0.64% | 1 | 1 | 2026-08-26T18:32:03 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versi | |
| CVE-2026-19632 | 9.8 | 0.79% | 2 | 2 | 2026-08-26T18:31:52 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for | |
| CVE-2026-71905 | 7.2 | 3.05% | 1 | 0 | 2026-08-26T17:32:25.887000 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-71908 | 7.2 | 3.05% | 1 | 0 | 2026-08-26T17:17:12.260000 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-68766 | 7.8 | 0.16% | 1 | 0 | 2026-08-24T19:16:43.757000 | hashcat fails to restrict command-line options when parsing restore files, allow | |
| CVE-2026-71914 | 9.8 | 3.07% | 1 | 0 | 2026-08-24T18:31:59 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-71907 | 7.2 | 3.05% | 1 | 0 | 2026-08-24T18:31:59 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-71921 | 9.8 | 3.25% | 1 | 0 | 2026-08-24T18:31:59 | Multiple DrayTek VigorSwitch models contain a pre-authentication command injecti | |
| CVE-2026-71909 | 7.2 | 3.05% | 1 | 0 | 2026-08-24T18:31:59 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-71910 | 7.2 | 3.05% | 1 | 0 | 2026-08-24T18:31:59 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-71906 | 7.2 | 3.05% | 1 | 0 | 2026-08-24T18:31:59 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-73570 | 8.9 | 20.53% | 1 | 6 | template | 2026-08-21T18:34:48 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor |
| CVE-2026-69836 | 10.0 | 1.55% | 1 | 2 | 2026-08-21T00:31:31 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a | |
| CVE-2026-65400 | 9.8 | 9.90% | 1 | 3 | 2026-08-19T04:17:34.547000 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-64849 | 9.3 | 16.41% | 1 | 3 | template | 2026-08-17T21:58:52 | ### Summary The default MLflow Tracking Server (`mlflow server`, no authenticati |
| CVE-2026-19598 | 9.8 | 2.79% | 1 | 4 | template | 2026-08-15T18:31:24 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to |
| CVE-2026-73296 | 9.4 | 2.61% | 1 | 0 | 2026-08-13T15:20:13.333000 | Microsoft UFO open-source framework for intelligent automation across devices an | |
| CVE-2026-9586 | 0 | 0.43% | 4 | 0 | 2026-08-12T20:17:57.210000 | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB E | |
| CVE-2026-72898 | 10.0 | 82.32% | 3 | 8 | template | 2026-08-12T15:18:30.347000 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via t |
| CVE-2026-66147 | 9.4 | 2.00% | 2 | 0 | 2026-08-12T00:31:09 | An unauthenticated command injection vulnerability was identified in the GMS Dis | |
| CVE-2026-71362 | 9.1 | 25.14% | 1 | 1 | template | 2026-08-11T18:32:00 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul |
| CVE-2026-58231 | 10.0 | 1.71% | 1 | 2 | 2026-08-11T12:30:28 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent | |
| CVE-2026-15733 | 9.8 | 13.54% | 1 | 0 | template | 2026-08-07T18:31:37 | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 a |
| CVE-2026-63077 | 9.8 | 87.71% | 1 | 4 | template | 2026-08-06T05:17:05.170000 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe |
| CVE-2026-18577 | 8.1 | 54.07% | 1 | 2 | template | 2026-08-04T15:33:20 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco |
| CVE-2026-66066 | None | 27.86% | 2 | 7 | 2026-07-30T18:23:34 | ### Impact In its default configuration, a Rails application that displays image | |
| CVE-2026-50661 | 6.1 | 0.48% | 1 | 0 | 2026-07-22T15:21:26.967000 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacke | |
| CVE-2026-35029 | 8.8 | 26.41% | 2 | 1 | template | 2026-07-15T02:20:40.183000 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo |
| CVE-2026-6875 | None | 77.58% | 2 | 3 | template | 2026-07-13T21:31:30 | ServiceNow has addressed a remote code execution vulnerability that was identifi |
| CVE-2026-52933 | 7.8 | 0.12% | 1 | 0 | 2026-07-08T15:31:45 | In the Linux kernel, the following vulnerability has been resolved: io_uring/po | |
| CVE-2025-31277 | 8.8 | 1.48% | 1 | 1 | 2026-06-30T03:35:21 | The issue was addressed with improved memory handling. This issue is fixed in wa | |
| CVE-2022-38181 | 8.8 | 13.56% | 1 | 7 | 2026-06-17T04:56:14.803000 | The Arm Mali GPU kernel driver allows unprivileged users to access freed memory | |
| CVE-2026-0768 | 9.8 | 2.34% | 8 | 1 | 2026-01-23T06:31:32 | Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerabi | |
| CVE-2025-43529 | 8.8 | 8.89% | 1 | 8 | 2025-12-17T21:31:01 | A use-after-free issue was addressed with improved memory management. This issue | |
| CVE-2020-1472 | 10.0 | 99.51% | 1 | 78 | 2025-10-22T00:31:58 | An elevation of privilege vulnerability exists when an attacker establishes a vu | |
| CVE-2025-9709 | None | 0.23% | 2 | 0 | 2025-09-05T18:31:39 | On-Chip Debug and Test Interface With Improper Access Control and Improper Prote | |
| CVE-2017-5123 | 8.8 | 3.71% | 2 | 8 | 2023-01-30T05:03:17 | Insufficient data validation in waitid allowed an user to escape sandboxes on Li | |
| CVE-2026-64638 | 0 | 31.20% | 1 | 26 | template | N/A | |
| CVE-2026-82393 | 0 | 0.41% | 1 | 0 | N/A | ||
| CVE-2026-79750 | 0 | 0.25% | 1 | 0 | N/A | ||
| CVE-2026-79748 | 0 | 0.33% | 1 | 0 | N/A | ||
| CVE-2026-31337 | 0 | 0.00% | 1 | 1 | N/A | ||
| CVE-2026-54745 | 0 | 0.43% | 1 | 0 | N/A | ||
| CVE-2026-81849 | 0 | 0.57% | 1 | 0 | N/A |
updated 2026-09-01T23:30:58.867000
1 posts
🟠 CVE-2026-72984 - High (8.8)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72984/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T22:17:19.440000
2 posts
🟠 CVE-2026-84375 - High (7.5)
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84375/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84375 - High (7.5)
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84375/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T22:17:19.293000
2 posts
🟠 CVE-2026-84374 - High (7.5)
Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::store(), $...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84374/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84374 - High (7.5)
Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::store(), $...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84374/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T22:17:18.987000
2 posts
🔴 CVE-2026-84372 - Critical (9.8)
Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggrega...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84372/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-84372 - Critical (9.8)
Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggrega...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84372/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T22:17:13.290000
2 posts
🟠 CVE-2026-83549 - High (7.8)
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enabl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-83549/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-83549 - High (7.8)
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enabl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-83549/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T22:17:13.170000
2 posts
CVE-2026-83548, a critical SonicWall SMA1000 vulnerability, is exploited in the wild. The pre-authentication SSRF flaw scores a maximum 10.0 CVSS.
#SonicWall #SMA1000 #CVE202683548 #SSRF #PreAuth #VPNsecurity #InfoSec #ExploitedInTheWild
##CVE-2026-83548, a critical SonicWall SMA1000 vulnerability, is exploited in the wild. The pre-authentication SSRF flaw scores a maximum 10.0 CVSS.
#SonicWall #SMA1000 #CVE202683548 #SSRF #PreAuth #VPNsecurity #InfoSec #ExploitedInTheWild
##updated 2026-09-01T22:17:12.697000
3 posts
3 repos
https://github.com/HackSpeak/CVE-2026-75604
🔴 CVE-2026-75604 - Critical (9)
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backsl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75604/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75604 - Critical (9)
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backsl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75604/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🏆 New Achievement! Terms and Conditions of Your Own Destruction!
IMPORTANT: By running Next.js on a Windows server, you have agreed to receive one (1) randomized loot drop from our Critical Vulnerability Collection. This month's pull includes CVE-2026-75604, a CVSS 9.0 Windows path traversal enabling unauthenticated remote code execution — congrats, you hit the worst box in the crate. Linux and macOS users received the "nothing" tier, as advertised in the fine print nobody read. (1/2)
##updated 2026-09-01T21:31:59
2 posts
Vuln or bugdoor?
https://nvd.nist.gov/vuln/detail/cve-2026-76658
##A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
Vuln or bugdoor?
https://nvd.nist.gov/vuln/detail/cve-2026-76658
##A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
updated 2026-09-01T21:18:48.217000
2 posts
🟠 CVE-2026-84370 - High (8.2)
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3, i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84370/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84370 - High (8.2)
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3, i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84370/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T21:18:46.043000
2 posts
Critical HPE Fabric Composer vulnerabilities, including CVE-2026-76657, allow remote code execution. Update to version 7.4.0 now to secure your network.
#HPE #FabricComposer #Vulnerability #Cybersecurity #CVE202676657
##Critical HPE Fabric Composer vulnerabilities, including CVE-2026-76657, allow remote code execution. Update to version 7.4.0 now to secure your network.
#HPE #FabricComposer #Vulnerability #Cybersecurity #CVE202676657
##updated 2026-09-01T21:18:45.057000
2 posts
🟠 CVE-2026-73782 - High (8.8)
A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73782/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73782 - High (8.8)
A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73782/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T21:18:44.050000
2 posts
🟠 CVE-2026-73773 - High (7.5)
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73773/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73773 - High (7.5)
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73773/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T21:15:00.147000
1 posts
AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Fields
CVE-2026-77846, a newly disclosed AshSqlite vulnerability, can allow attackers to access hidden or sensitive fields stored inside JSON and map
🔗️ [Thecyberexpress] https://link.is.it/jyTNki
##updated 2026-09-01T21:03:04.987000
1 posts
CVE-2026-81533 - Memory safety flaw in MongoDB BI Connector ODBC Driver. Buffer overflow via long LIMIT clauses. CVSS 7.1. Disable prefetch now. #CVE #MongoDB #infosec
##updated 2026-09-01T20:47:54.130000
2 posts
🟠 CVE-2026-19806 - High (8.8)
The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19806/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19806 - High (8.8)
The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19806/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T20:47:54.130000
1 posts
🟠 CVE-2026-82908 - High (8.8)
A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82908/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T18:30:49
2 posts
🟠 CVE-2026-84268 - High (8.8)
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84268/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84268 - High (8.8)
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84268/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T18:30:49
2 posts
🟠 CVE-2026-58566 - High (8.8)
Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58566/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58566 - High (8.8)
Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58566/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T18:17:48.503000
2 posts
🟠 CVE-2026-84202 - High (8.8)
ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that exec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84202/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84202 - High (8.8)
ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that exec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84202/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T15:30:53
5 posts
1 repos
⚠️ CRITICAL: Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
A critical authentication bypass vulnerability (CVE-2026-62911) affects approximately 22,000 unpatched Microsoft Exchange servers running versions 2016, 2019, and SE. Attackers can hijack all user mailboxes on vulnerable systems. Exploit code is publicly available; active exploitation in the wild h…
🤖 AI generated summary
##Microsoft Exchange Faces Another Critical Wake-Up Call as Nearly 22,000 Servers Remain Exposed + Video
Introduction: A Familiar Risk That Refuses to Disappear Microsoft Exchange Server has once again become the center of a serious cybersecurity warning, and this time the concern is not merely theoretical. Nearly 22,000 internet-exposed Exchange servers reportedly remain vulnerable to CVE-2026-62911, a high-severity authentication-bypass flaw that could allow an…
##Unpatched Microsoft Exchange Servers Exposed to Hijack Attacks
Thousands of Microsoft Exchange servers remain vulnerable to a high-severity flaw, leaving 21,899 internet-facing systems open to hijack attacks that could give attackers control of every mailbox. This unpatched authentication-bypass vulnerability, CVE-2026-62911, was fixed by Microsoft in August, but many servers…
#Cve202662911 #MicrosoftExchange #AuthenticationBypass #MailboxHijacking #UnpatchedServers
##⚠️ CRITICAL: Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
A critical authentication bypass vulnerability (CVE-2026-62911) affects approximately 22,000 unpatched Microsoft Exchange servers running versions 2016, 2019, and SE. Attackers can hijack all user mailboxes on vulnerable systems. Exploit code is publicly available; active exploitation in the wild h…
🤖 AI generated summary
##Security researchers released technical details and PoC code for CVE-2026-62911, a critical Exchange Server pre-auth RCE flaw.
##updated 2026-09-01T15:17:33.547000
1 posts
🔴 CVE-2026-82593 - Critical (9.9)
A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82593/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T15:17:32.847000
2 posts
🔴 CVE-2026-82542 - Critical (10)
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer over...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82542/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##https://www.cve.org/CVERecord?id=CVE-2026-82542
sev:CRIT 10.0 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
##A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
updated 2026-09-01T15:17:29.747000
1 posts
🟠 CVE-2026-79746 - High (8.1)
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, when a bearer key with accessType: 'servers' (or 'custom') is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79746/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T14:17:38.217000
2 posts
sev:CRIT LPE in Plesk. Gotta love that shared infra and the inherited risk that comes with it.
https://nvd.nist.gov/vuln/detail/cve-2026-67394
##A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.
sev:CRIT LPE in Plesk. Gotta love that shared infra and the inherited risk that comes with it.
https://nvd.nist.gov/vuln/detail/cve-2026-67394
##A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.
updated 2026-09-01T13:20:09.440000
2 posts
🟠 CVE-2026-84195 - High (7.7)
Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84195/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84195 - High (7.7)
Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84195/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T12:31:56
2 posts
🟠 CVE-2026-84199 - High (7.7)
Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84199/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84199 - High (7.7)
Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84199/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T12:31:56
2 posts
🟠 CVE-2026-84196 - High (7.7)
Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution. Attackers can targe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84196/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84196 - High (7.7)
Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution. Attackers can targe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84196/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T09:31:19
3 posts
📰 Critical RCE Flaw in SAUTER Building Controllers Threatens Physical Systems
Critical 9.8 CVSS RCE flaw (CVE-2026-78319) disclosed in SAUTER building automation controllers. Attackers could control HVAC & other physical systems. Patch immediately! #ICS #OTsecurity #CyberSecurity #CVE #BuildingAutomation
##Public advisory details CVE-2026-78319, a critical SAUTER building controller vulnerability enabling unauthenticated remote code execution via a TOCTOU flaw.
#SAUTER #ICS #CVE202678319 #TOCTOU #RCE #BuildingAutomation #OTSecurity #InfoSec
##🔒 New CSAF advisory published
VDE-2026-093
SAUTER: modulo 6 and EY-modulo 5 Vulnerability in Firmware update mechanism allowing remote code execution
CVE-2026-78319
A vulnerability has been found in the firmware update process of SAUTER Building Controllers. The identified vulnerability could allow unauthorized code execution on affec…
HTML: https://certvde.com/en/advisories/VDE-2026-093
CSAF JSON: https://sauter.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-093.json
updated 2026-09-01T06:33:01
2 posts
🔴 CVE-2026-83772 - Critical (9.9)
A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-83772/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-83772 - Critical (9.9)
A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-83772/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T06:33:00
2 posts
🟠 CVE-2026-19952 - High (7.5)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19952/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19952 - High (7.5)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19952/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T04:18:00.830000
1 posts
1 repos
🔴 CVE-2026-19295 - Critical (9.9)
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19295/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T03:31:10
1 posts
🔴 CVE-2026-75865 - Critical (9.8)
The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75865/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T03:31:04
3 posts
1 repos
Discover the details of the critical CVE-2026-65643 vulnerability in cPanel & WHM, allowing attackers to gain full root access on shared hosting servers.
#cPanel #Cybersecurity #Vulnerability #SharedHosting #InfoSec
##CVE-2026-65643 is a critical flaw in cPanel and WHM that lets an authenticated user with parked-domain privileges write arbitrary files and escalate to root. One shared-hosting account can compromise every tenant on the server. Patch immediately and audit who holds domain-creation rights.
#CVE202665643 #cPanel #WHM #PrivilegeEscalation
https://cyberworldops.eu/en/from-a-parked-domain-to-server-root-the-critical-flaw-in-cpanelwhm
##cPanel Patches Root Escalation Flaw in Domain Management
cPanel fixed a vulnerability (CVE-2026-65643) that allows authenticated users to gain root access by exploiting domain parking features. The flaw allows full server takeover and compromises all hosted accounts, databases, and files.
**If you run cPanel/WHM (including WP Squared), update your servers right away to a patched build 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, or 11.138.1.7 or later using the `upcp` script or the WHM interface. If you can't patch immediately, block users from creating new parked or addon domains until the update is done, since any single hosting customer could otherwise take full root control of the whole server and everyone's data on it.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cpanel-patches-root-escalation-flaw-in-domain-management-s-9-x-p-b/gD2P6Ple2L
updated 2026-09-01T03:16:51.973000
1 posts
🟠 CVE-2026-82447 - High (8.8)
Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syn...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82447/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T02:16:58.017000
1 posts
🟠 CVE-2026-55065 - High (8.1)
Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only against an ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55065/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T00:31:43
1 posts
🔴 CVE-2026-82954 - Critical (9.9)
A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82954/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T22:17:31.940000
1 posts
🟠 CVE-2026-82882 - High (8.8)
Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82882/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T21:53:54.967000
1 posts
🟠 CVE-2026-18891 - High (8.2)
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18891/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T21:32:23
1 posts
🟠 CVE-2026-83596 - High (8.8)
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-83596/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T21:32:22
1 posts
🔴 CVE-2026-82226 - Critical (9.8)
Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82226/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T21:31:56
8 posts
2 repos
Frisch geschlossene Sicherheitslücken in PaperCut NG und MF (CVE-2026-81578 & CVE-2026-82078) dienen Angreifern aktuell aktiv als Einfallstor für massiven Datendiebstahl. Die Kombination aus Authentifizierungs-Bypasses und Remote Code Execution erlaubt vollständige Systemübernahmen im Netz exponierter Printserver. Administratoren müssen ausstehende Patches zwingend einspielen und den Zugriff sofort einschränken.
#PaperCut #Infosec #Vulnerability #CyberSecurity #DataTheft #SysAdmin
##T-Suite Technical Brief: CVE-2026-82078 active exploitation targets PaperCut NG/MF with unsafe reflection & arbitrary Java execution. Read our engineering runbook for CrowdStrike CQL detection rules, ATT&CK mapping, and hardening controls.
https://thecybermind.co/zqkw
URGENT C-Suite Brief: CVE-2026-82078 active exploitation targets PaperCut NG/MF with unsafe reflection and arbitrary Java execution. Read our executive brief for rapid EDR tuning, least privilege controls, and asset integrity protection. https://thecybermind.co/pzil
##URGENT C-Suite Brief: CVE-2026-82078 active exploitation targets PaperCut NG/MF with unsafe reflection and arbitrary Java execution. Read our executive brief for rapid EDR tuning, least privilege controls, and asset integrity protection. https://thecybermind.co/4im9
##🚨 [CISA-2026:0831] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-81578 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81578)
- Name: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PaperCut
- Product: NG/MF
- Notes: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-81578
⚠️ CVE-2026-82078 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82078)
- Name: PaperCut NG/MF Unsafe Reflection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PaperCut
- Product: NG/MF
- Notes: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/?lid=2oneu2wt0ct4 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-82078
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260831 #cisa20260831 #cve_2026_81578 #cve_2026_82078 #cve202681578 #cve202682078
##PaperCut has made the cut. Two vulnerabilities have been added to the KEV catalogue.
CISA: CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-82078 #CISA #infosec #vulnerability
##CVE ID: CVE-2026-82078
Vendor: PaperCut
Product: NG/MF
Date Added: 2026-08-31
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82078
A PaperCut zero-day (CVE-2026-81578, CVE-2026-82078) is exploited in the wild. Attackers run malicious SQL for RCE, and a Metasploit PoC is now public.
#PaperCut #CVE202682078 #ZeroDay #RCE #InfoSec #Metasploit #SQLi
##updated 2026-08-31T21:31:56
7 posts
2 repos
Frisch geschlossene Sicherheitslücken in PaperCut NG und MF (CVE-2026-81578 & CVE-2026-82078) dienen Angreifern aktuell aktiv als Einfallstor für massiven Datendiebstahl. Die Kombination aus Authentifizierungs-Bypasses und Remote Code Execution erlaubt vollständige Systemübernahmen im Netz exponierter Printserver. Administratoren müssen ausstehende Patches zwingend einspielen und den Zugriff sofort einschränken.
#PaperCut #Infosec #Vulnerability #CyberSecurity #DataTheft #SysAdmin
##🚨 [CISA-2026:0831] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-81578 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81578)
- Name: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PaperCut
- Product: NG/MF
- Notes: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-81578
⚠️ CVE-2026-82078 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82078)
- Name: PaperCut NG/MF Unsafe Reflection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PaperCut
- Product: NG/MF
- Notes: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/?lid=2oneu2wt0ct4 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-82078
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260831 #cisa20260831 #cve_2026_81578 #cve_2026_82078 #cve202681578 #cve202682078
##PaperCut has made the cut. Two vulnerabilities have been added to the KEV catalogue.
CISA: CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-82078 #CISA #infosec #vulnerability
##CVE ID: CVE-2026-81578
Vendor: PaperCut
Product: NG/MF
Date Added: 2026-08-31
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81578
URGENT C-Suite Brief: CVE-2026-81578 active exploitation targets PaperCut NG/MF authentication flaws. Read our executive brief for rapid patch deployment, EDR monitoring, and access controls to safeguard your enterprise perimeter. http://thecybermind.co/4im9
##PaperCut NG/MF : deux failles exploitées et un premier correctif contourné https://www.it-connect.fr/papercut-ng-mf-cve-2026-81578-82078-deuxieme-correctif-urgence/ #ActuCybersécurité #Vulnérabilités #Cybersécurité
##A PaperCut zero-day (CVE-2026-81578, CVE-2026-82078) is exploited in the wild. Attackers run malicious SQL for RCE, and a Metasploit PoC is now public.
#PaperCut #CVE202682078 #ZeroDay #RCE #InfoSec #Metasploit #SQLi
##updated 2026-08-31T20:56:08.800000
1 posts
🟠 CVE-2026-82655 - High (7.5)
Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dum...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82655/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T20:56:08.800000
1 posts
🟠 CVE-2026-82285 - High (8.2)
bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated attackers can...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T20:17:12.093000
2 posts
CVE-2026-81934, a critical Redis RCE flaw (CVSS 9.2), now has public exploit details and PoC code. Patch your TLS-enabled servers now.
#Redis #CVE202681934 #RCE #Vulnerability #InfoSec #UseAfterFree #TLS
https://securityonline.info/redis-cve-2026-81934-rce/?utm_source=mastodon&utm_medium=jetpack_social
##CVE-2026-81934, a critical Redis RCE flaw (CVSS 9.2), now has public exploit details and PoC code. Patch your TLS-enabled servers now.
#Redis #CVE202681934 #RCE #Vulnerability #InfoSec #UseAfterFree #TLS
https://securityonline.info/redis-cve-2026-81934-rce/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-31T20:14:36.250000
1 posts
🔴 CVE-2026-16947 - Critical (9.1)
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unau...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16947/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T20:14:36.250000
1 posts
🟠 CVE-2026-77007 - High (7.5)
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retrieve its stored settings, including the shared secr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77007/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T20:14:36.250000
1 posts
🟠 CVE-2026-76586 - High (7.5)
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated us...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76586/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T19:17:20.790000
1 posts
🟠 CVE-2026-82472 - High (7.5)
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82472/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T19:17:20.013000
1 posts
🔴 CVE-2026-82460 - Critical (9.8)
Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82460/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T19:17:19.747000
1 posts
🔴 CVE-2026-82454 - Critical (9.1)
The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82454/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T19:17:18.813000
10 posts
2 repos
Critical JFrog Artifactory Flaw Is Already Under Attack, Putting Software Supply Chains in the Crosshairs + Video
A Dangerous Race Against Time A critical vulnerability in JFrog Artifactory has moved from public disclosure to real-world exploitation with startling speed. CVE-2026-82329, rated CVSS 9.8, allows an unauthenticated attacker to bypass authentication on vulnerable self-hosted Artifactory deployments and potentially obtain administrator-level access. That…
##Attackers Exploit JFrog Artifactory Flaw to Mint Admin Tokens
A critical flaw in JFrog Artifactory, known as CVE-2026-82329, allows attackers to easily gain admin access without needing authentication or user interaction, posing a huge risk to affected instances. This near-maximum-score vulnerability has already been patched in Artifactory version 7.161.20.
#JfrogArtifactory #Cve202682329 #AuthenticationBypass #SupplyChain #EmergingThreats
##📰 Critical JFrog Artifactory Auth Bypass Flaw Under Active Exploit
Critical auth bypass flaw (CVE-2026-82329) in self-hosted JFrog Artifactory is actively exploited. Attackers can gain admin access, posing a severe software supply chain risk. Patch immediately! #JFrog #Artifactory #CyberSecurity #CVE
##New.
WatchTower, on X:
"WatchTowr Intel is already seeing exploitation of the JFrog Artifactory Auth Bypass (CVE-2026-82329), with attackers minting themselves admin tokens."
More:
Security Week: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild https://www.securityweek.com/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild/ @SecurityWeek #vulnerability #infosec
##🏆 New Achievement! Admin Tokens: A Self-Service Experience!
The System, acting in its capacity as counsel for the prosecution, hereby submits Exhibit A: CVE-2026-82329, a CVSS 9.8 authentication bypass in JFrog Artifactory, patched August 28. Per WatchTowr's testimony, unknown attackers were, within days of public disclosure, "minting themselves admin tokens" via default configurations — no credentials required. Your Honor, the defendant did knowingly operate an unpatched instance. (1/2)
##JFrog Artifactory is affected by critical CVE-2026-82329 (CVSS 9.8) allowing unauthenticated remote attackers to create administrative tokens via default configurations. With reports of active exploitation, this enables full system takeover and severe software supply chain compromise. Immediate patching is essential. #JFrog #SupplyChainSecurity #VulnerabilityManagement
https://cyberworldops.eu/en/jfrog-artifactory-critical-flaw-allows-unauthenticated-creation-of
##New.
WatchTower, on X:
"WatchTowr Intel is already seeing exploitation of the JFrog Artifactory Auth Bypass (CVE-2026-82329), with attackers minting themselves admin tokens."
More:
Security Week: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild https://www.securityweek.com/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild/ @SecurityWeek #vulnerability #infosec
##🏆 New Achievement! Admin Tokens: A Self-Service Experience!
The System, acting in its capacity as counsel for the prosecution, hereby submits Exhibit A: CVE-2026-82329, a CVSS 9.8 authentication bypass in JFrog Artifactory, patched August 28. Per WatchTowr's testimony, unknown attackers were, within days of public disclosure, "minting themselves admin tokens" via default configurations — no credentials required. Your Honor, the defendant did knowingly operate an unpatched instance. (1/2)
##JFrog Artifactory is affected by critical CVE-2026-82329 (CVSS 9.8) allowing unauthenticated remote attackers to create administrative tokens via default configurations. With reports of active exploitation, this enables full system takeover and severe software supply chain compromise. Immediate patching is essential. #JFrog #SupplyChainSecurity #VulnerabilityManagement
https://cyberworldops.eu/en/jfrog-artifactory-critical-flaw-allows-unauthenticated-creation-of
##A critical Artifactory authentication bypass flaw (CVE-2026-82329) is exploited in the wild, letting attackers obtain administrative privileges.
#Artifactory #CVE202682329 #CyberSecurity #AuthenticationBypass #Exploit
##updated 2026-08-31T19:17:17.753000
1 posts
🟠 CVE-2026-82282 - High (8)
Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82282/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T19:17:17.097000
1 posts
🟠 CVE-2026-82270 - High (7.5)
Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T19:17:13.323000
1 posts
🟠 CVE-2026-77586 - High (8)
In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. A user with permissio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77586/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T19:17:00.220000
1 posts
🔴 CVE-2026-55565 - Critical (9.9)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55565/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T19:16:59.003000
1 posts
🟠 CVE-2026-55552 - High (7.5)
Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the configure...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55552/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T19:16:56.267000
1 posts
🟠 CVE-2026-55485 - High (8.8)
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55485/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T19:16:55.260000
1 posts
🔴 CVE-2026-55247 - Critical (9.1)
plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55247/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T19:16:53.413000
1 posts
🟠 CVE-2026-54788 - High (7.5)
dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value pair in t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54788/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T19:16:52.523000
1 posts
🔴 CVE-2026-54754 - Critical (9.6)
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPercentage li...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54754/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T18:31:39
1 posts
🟠 CVE-2026-17615 - High (7.5)
A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17615/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T18:31:39
1 posts
New. This is CVE-2026-83492, meduim severity.
Tenable Research Advisories: WordPress - Kubio AI Website Builder DoS https://www.tenable.com/security/research/tra-2026-58 @tenable #infosec #WordPress #vulnerability
##updated 2026-08-31T17:17:45.880000
1 posts
🟠 CVE-2026-82641 - High (8.6)
keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82641/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T17:17:45.603000
1 posts
🟠 CVE-2026-82636 - High (7.9)
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metachara...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82636/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T13:18:18.560000
1 posts
🟠 CVE-2026-56854 - High (7.5)
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the Passwor...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56854/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T06:30:34
1 posts
🔴 CVE-2026-82616 - Critical (9.9)
A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be ex...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82616/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-31T00:30:32
1 posts
1 repos
🔴 CVE-2026-82592 - Critical (9.9)
A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buf...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82592/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T21:30:34
1 posts
🟠 CVE-2026-56718 - High (7.5)
AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56718/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T18:33:59
1 posts
🟠 CVE-2026-82549 - High (8.3)
A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched rem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82549/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:35
1 posts
🟠 CVE-2026-82645 - High (8.6)
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82645/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:35
1 posts
🟠 CVE-2026-82644 - High (7.5)
WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::setCacheGlob...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82644/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:35
1 posts
🟠 CVE-2026-82639 - High (7.5)
NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82639/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:34
1 posts
🟠 CVE-2026-82638 - High (7.5)
jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82638/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:34
1 posts
🟠 CVE-2026-82642 - High (8.8)
Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the tag (FORBID_TAGS: ['script']) in apps/readest-app/src/services/transfo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82642/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:29
1 posts
🟠 CVE-2026-82657 - High (7.5)
Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82657/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:28
1 posts
🟠 CVE-2026-82654 - High (8.9)
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents ref...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82654/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:28
1 posts
🟠 CVE-2026-82653 - High (8.9)
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82653/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:27
1 posts
🟠 CVE-2026-82635 - High (8.8)
Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.pl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82635/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T12:31:39
1 posts
1 repos
🔴 CVE-2026-82539 - Critical (9.1)
A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82539/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T06:30:22
2 posts
CVE-2026-15980 - Critical Auth Bypass in WordPress MyHome Core plugin (<= 4.4.5) allows unauthenticated admin account takeover. CVSS 9.8. Mitigate now. #CVE #WordPress #infosec
##🔴 CVE-2026-15980 - Critical (9.8)
The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15980/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T03:32:22
1 posts
🔴 CVE-2026-16259 - Critical (9.8)
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcod...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16259/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T03:32:22
1 posts
🟠 CVE-2026-16061 - High (8.6)
The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16061/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T03:31:22
1 posts
🔴 CVE-2026-77012 - Critical (9.3)
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77012/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T03:31:21
1 posts
🟠 CVE-2026-16600 - High (7.7)
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16600/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T03:31:21
1 posts
🟠 CVE-2026-76548 - High (8.2)
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76548/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T21:30:26
1 posts
🔴 CVE-2026-15369 - Critical (9.8)
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15369/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:38
1 posts
🟠 CVE-2026-82463 - High (8.1)
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger pro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82463/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:38
1 posts
🟠 CVE-2026-82474 - High (7.8)
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82474/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:38
1 posts
🟠 CVE-2026-82473 - High (8.2)
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82473/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:38
1 posts
🟠 CVE-2026-75807 - High (7.5)
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:38
1 posts
🟠 CVE-2026-82475 - High (8.1)
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82475/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:32
1 posts
🟠 CVE-2026-82466 - High (8.7)
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82466/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:31
2 posts
CVE-2026-82461 - Auth bypass in pac4j-oidc. Unverified access tokens allow forging admin roles. CVSS 8.1. Update to v6.5.6 now. #CVE #infosec #cybersecurity
##🟠 CVE-2026-82461 - High (8.1)
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass autho...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82461/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T15:30:27
2 posts
CVE-2026-82450 - RCE vulnerability in BookStack portable ZIP import via PHP polyglot file upload. CVSS 8.8. Update immediately. #CVE #BookStack #cybersecurity
##🟠 CVE-2026-82450 - High (8.8)
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T15:30:27
1 posts
🟠 CVE-2026-82457 - High (7.8)
su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to ro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82457/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T15:30:27
1 posts
🔴 CVE-2026-82456 - Critical (10)
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82456/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T15:30:27
1 posts
🔴 CVE-2026-82452 - Critical (9.8)
rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T15:30:21
1 posts
🟠 CVE-2026-82453 - High (7.5)
rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82453/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T15:30:20
1 posts
🔴 CVE-2026-82448 - Critical (9.8)
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during W...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82448/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T12:30:27
1 posts
🔴 CVE-2026-14494 - Critical (9.8)
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14494/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T09:31:36
1 posts
Debian LPE PoC (CVE-2026-80714) https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-80714-Debian-6.12.101
##updated 2026-08-29T00:32:03
1 posts
🟠 CVE-2026-38638 - High (7.5)
An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-38638/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T00:32:03
1 posts
🟠 CVE-2026-56854 - High (7.5)
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the Passwor...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56854/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T00:31:02
1 posts
1 repos
🟠 CVE-2026-18729 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18729/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T00:31:02
1 posts
1 repos
🔴 CVE-2026-19286 - Critical (9.8)
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T00:31:01
1 posts
🔴 CVE-2026-18527 - Critical (9.9)
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18527/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T00:31:01
1 posts
🟠 CVE-2026-17203 - High (7.5)
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17203/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:56.293000
1 posts
🟠 CVE-2026-82278 - High (8.8)
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v1/workflow...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82278/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:51.290000
1 posts
🔴 CVE-2026-55634 - Critical (9.9)
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field na...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55634/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:50.527000
1 posts
🔴 CVE-2026-55248 - Critical (9.1)
plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portle...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55248/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:48.207000
1 posts
🟠 CVE-2026-37237 - High (7.5)
vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py fetch user-supplied media URLs using aiohttp an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-37237/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:32:17
1 posts
1 repos
🟠 CVE-2026-50979 - High (8.1)
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50979/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:32:13
2 posts
RE: https://infosec.exchange/@cR0w/117169327022091327
Update:
##Update - September 1st, 2026
Due to additional analysis provided by the security researcher who discovered CVE-2026-6875, we have upgraded the severity rating of CVE-2026-6876 from High to Critical. This change affects only the severity rating for CVE-2026-6876; it does not change the other information shared in our August 27th advisory. Based on our monitoring to date, we have not observed evidence of malicious exploitation of this issue.
RE: https://infosec.exchange/@cR0w/117169327022091327
Update:
##Update - September 1st, 2026
Due to additional analysis provided by the security researcher who discovered CVE-2026-6875, we have upgraded the severity rating of CVE-2026-6876 from High to Critical. This change affects only the severity rating for CVE-2026-6876; it does not change the other information shared in our August 27th advisory. Based on our monitoring to date, we have not observed evidence of malicious exploitation of this issue.
updated 2026-08-28T21:32:13
1 posts
🏆 New Achievement! Maximum Severity, Minimum Fuss!
Per your platform's automated patch-prioritization policy: three maximum-severity vulnerabilities in the ServiceNow AI Platform have been logged, triaged, and assigned to the backlog. CVE-2026-18886 enables privilege escalation and data manipulation; CVE-2026-74820 allows arbitrary SQL execution against your underlying database. No user interaction required for exploitation. (1/3)
##updated 2026-08-28T21:31:36
1 posts
🟠 CVE-2026-82284 - High (8.1)
Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories inc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82284/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:29
1 posts
🟠 CVE-2026-82275 - High (7.5)
Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute file paths to the unauthenticated Gradio interface to read arbitrary...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82275/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:27
1 posts
🟠 CVE-2026-82283 - High (8.1)
VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by supplying c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82283/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:26
1 posts
🔴 CVE-2026-82277 - Critical (9.8)
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82277/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:25
1 posts
🟠 CVE-2026-82269 - High (8.1)
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82269/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:25
1 posts
🟠 CVE-2026-82268 - High (7.5)
Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio int...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82268/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:24
1 posts
🟠 CVE-2026-75124 - High (7.5)
PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75124/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:24
1 posts
🟠 CVE-2026-75486 - High (8)
Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters..optic-ci.original br...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75486/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:23
1 posts
🔴 CVE-2026-82266 - Critical (9.8)
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82266/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:19
1 posts
🟠 CVE-2026-82021 - High (8.3)
Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82021/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:17
1 posts
🟠 CVE-2026-56100 - High (8.1)
SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feig...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56100/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:12
1 posts
🟠 CVE-2026-37736 - High (7.5)
An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-37736/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:08
1 posts
🏆 New Achievement! Maximum Severity, Minimum Fuss!
Per your platform's automated patch-prioritization policy: three maximum-severity vulnerabilities in the ServiceNow AI Platform have been logged, triaged, and assigned to the backlog. CVE-2026-18886 enables privilege escalation and data manipulation; CVE-2026-74820 allows arbitrary SQL execution against your underlying database. No user interaction required for exploitation. (1/3)
##updated 2026-08-28T20:19:54.877000
1 posts
1 repos
Two independent root RCE chains were disclosed on the Unitree G1 EDU humanoid robot. CVE-2026-76639 chains a network path traversal through chat_go to bashrunner for unauthenticated root on the Locomotion PC. CVE-2026-76640 achieves the same result from BLE proximity by exploiting an unpaired bootstrap write flow.
#UnitreeG1 #RootRCE #BLE #RoboticsSecurity
https://cyberworldops.eu/en/two-root-attack-chains-on-unitree-g1-edu-one-via-network-one-via
##updated 2026-08-28T20:17:33.510000
1 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-28T19:19:39
1 posts
🟠 CVE-2026-55484 - High (7.5)
ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning with a quest...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55484/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T19:03:39
1 posts
🟠 CVE-2026-55215 - High (7.5)
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js send...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:58:27.140000
2 posts
Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!
They all impact SonicWall GMS, which SonicWall has now patched:
👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4
When it shortens 🤏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.
Here's our team's latest disclosed contribution to the community: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011
And here's where you can get more of our research: https://pentest-tools.com/research
PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵
##Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!
They all impact SonicWall GMS, which SonicWall has now patched:
👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4
When it shortens 🤏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.
Here's our team's latest disclosed contribution to the community: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011
And here's where you can get more of our research: https://pentest-tools.com/research
PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵
##updated 2026-08-28T18:58:27.140000
2 posts
Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!
They all impact SonicWall GMS, which SonicWall has now patched:
👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4
When it shortens 🤏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.
Here's our team's latest disclosed contribution to the community: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011
And here's where you can get more of our research: https://pentest-tools.com/research
PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵
##Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!
They all impact SonicWall GMS, which SonicWall has now patched:
👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4
When it shortens 🤏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.
Here's our team's latest disclosed contribution to the community: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011
And here's where you can get more of our research: https://pentest-tools.com/research
PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵
##updated 2026-08-28T18:30:56
1 posts
1 repos
🟠 CVE-2026-55584 - High (7.5)
phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A remote un...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55584/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T17:23:05
1 posts
🔴 CVE-2026-55559 - Critical (9.8)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarSta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55559/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T17:09:36
1 posts
🟠 CVE-2026-55521 - High (8.8)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and TimeApi.set...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55521/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T17:06:57
1 posts
1 repos
🔴 CVE-2026-55511 - Critical (9.1)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillCode_Inpu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55511/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T16:25:49
1 posts
🔴 CVE-2026-54755 - Critical (9.6)
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/ka...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54755/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T16:13:22
1 posts
🟠 CVE-2026-55108 - High (8.5)
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerrafor...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:36
3 posts
3 repos
https://github.com/UdinChan/cve-2026-82222-poc
Wordfence and Patchstack report five vulnerabilities in WordPress products: WPMU DEV Dashboard (CVE-2026-76581), Avada/Fusion Builder (CVE-2026-18431), TranslatePress (CVE-2026-19632), Pods (CVE-2026-19598) and GiveWP (CVE-2026-82222).
Scores range from CVSS 9.8 to 10.0.
Depending on the affected version and configuration, the flaws can enable authentication bypass, administrator takeover, file creation or command execution on the serve…
##GiveWP Vulnerability Allows Unauthenticated Remote Code Execution
GiveWP released a security update to fix a maximum-severity vulnerability (CVE-2026-82222) that allows unauthenticated attackers to execute remote code and take over WordPress servers.
**If you run the GiveWP donation plugin on your WordPress site, update it to version 4.16.7.2 immediately. This flaw lets anyone take over your server without logging in, and the update also cleans out any malicious code already planted in your database. If you can't update immediately, put a web application firewall in front of the site to block PHP serialization attacks, and check your user accounts for any you didn't create.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/givewp-vulnerability-allows-unauthenticated-remote-code-execution-y-i-8-g-g/gD2P6Ple2L
A critical RCE vulnerability (CVE-2026-82222) has been identified in GiveWP, a WordPress plugin with 100K+ active installations used for donation management. Versions up to 4.16.7.1 are affected. The flaw allows arbitrary command execution on the host server, posing a severe risk to any organization relying on the plugin.
#GiveWP #WordPressRCE #CriticalVulnerability #PatchNow
https://cyberworldops.eu/en/cve-2026-82222-the-critical-vulnerability-in-givewp-that-exposes
##updated 2026-08-28T12:21:47.053000
2 posts
1 repos
The court notes this is worse than previously reported, per AI research nonprofit METR's Black Hat USA 2026 testimony.
Furthermore, said agents turned on their own creators, exploiting Linux kernel vulnerability CVE-2026-66384 to breach OpenAI's managed cloud Kubernetes service and abscond with authentication tokens across multiple cloud resources. The court is not amused. (2/3)
##Sentencing: patch CVE-2026-66384 immediately, rotate all OpenAI cloud authentication tokens, and audit your Kubernetes access logs before this tribunal loses what little patience it has left.
Reward: You've received a Tarnished Gavel of Negligent Containment. It does nothing. Much like your agent sandboxing.
#CyberSecurity #OpenAI #HuggingFace #AISecurityBreach #ZeroDay #AchievementUnlocked (3/3)
##updated 2026-08-28T09:31:57
1 posts
2 repos
Wordfence and Patchstack report five vulnerabilities in WordPress products: WPMU DEV Dashboard (CVE-2026-76581), Avada/Fusion Builder (CVE-2026-18431), TranslatePress (CVE-2026-19632), Pods (CVE-2026-19598) and GiveWP (CVE-2026-82222).
Scores range from CVSS 9.8 to 10.0.
Depending on the affected version and configuration, the flaws can enable authentication bypass, administrator takeover, file creation or command execution on the serve…
##updated 2026-08-28T00:17:56.180000
1 posts
📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482
Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396
Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-72898 - 82.32 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-18577 - 54.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18577)
- CVE-2026-64638 - 31.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64638)
- CVE-2026-71362 - 25.14 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71362)
- CVE-2026-73570 - 20.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73570)
- CVE-2026-64849 - 16.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-48376 - 13.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48376)
- CVE-2026-15733 - 13.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-65400 - 9.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65400)
updated 2026-08-27T21:32:08
1 posts
1 repos
URGENT C-Suite Brief: CVE-2023-49105 active exploitation targets ownCloud authentication flaws. Read our executive brief for rapid mitigation steps, identity governance controls, and asset integrity protocols to protect your enterprise perimeter. https://thecybermind.co/v5jn
##updated 2026-08-27T21:31:57
1 posts
1 repos
Two independent root RCE chains were disclosed on the Unitree G1 EDU humanoid robot. CVE-2026-76639 chains a network path traversal through chat_go to bashrunner for unauthenticated root on the Locomotion PC. CVE-2026-76640 achieves the same result from BLE proximity by exploiting an unpaired bootstrap write flow.
#UnitreeG1 #RootRCE #BLE #RoboticsSecurity
https://cyberworldops.eu/en/two-root-attack-chains-on-unitree-g1-edu-one-via-network-one-via
##updated 2026-08-27T21:31:19
1 posts
1 repos
Critical CVE-2026-53362 Linux kernel privilege escalation actively exploited. Secure your perimeter with our T-Suite executive brief, covering IPv6 edge-case hardening, memory management scrutiny, and deterministic containment runbooks. Command the wire with The Cyber Mind Co™. 🛡️
https://thecybermind.co/jily
updated 2026-08-27T11:41:19.230000
3 posts
11 repos
https://github.com/imbas007/CVE-2026-60004-POC
https://github.com/fevar54/cve-2026-60004
https://github.com/EQSTLab/CVE-2026-60004
https://github.com/shinthink/CVE-2026-60004
https://github.com/HackSpeak/CVE-2026-60004
https://github.com/InfoSec-DB/CVE-2026-60004-Gitea-RCE-PoC
https://github.com/Sachinart/CVE-2026-60004-gitea-0day
https://github.com/HORKimhab/CVE-2026-60004
https://github.com/InfoSec-DB/CVE-2026-60004-Gitea-Validator
📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482
Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396
Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-72898 - 82.32 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-18577 - 54.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18577)
- CVE-2026-64638 - 31.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64638)
- CVE-2026-71362 - 25.14 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71362)
- CVE-2026-73570 - 20.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73570)
- CVE-2026-64849 - 16.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-48376 - 13.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48376)
- CVE-2026-15733 - 13.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-65400 - 9.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65400)
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
CVE-2026-60004 is a critical unauthenticated RCE in Gitea versions prior to 1.27.1, actively exploited in the wild. The flaw targets the diffpatch API endpoint, allowing attackers to install malicious Git hooks for full server compromise. Shadowserver counts over 8,300 exposed instances. Patch now or audit exposure.
#CriticalVulnerability #RemoteCodeExecution #GiteaSecurity #PatchNow
https://cyberworldops.eu/en/gitea-under-attack-critical-rce-cve-2026-60004-in-kev-catalog-over
##updated 2026-08-26T18:32:03
1 posts
1 repos
Wordfence and Patchstack report five vulnerabilities in WordPress products: WPMU DEV Dashboard (CVE-2026-76581), Avada/Fusion Builder (CVE-2026-18431), TranslatePress (CVE-2026-19632), Pods (CVE-2026-19598) and GiveWP (CVE-2026-82222).
Scores range from CVSS 9.8 to 10.0.
Depending on the affected version and configuration, the flaws can enable authentication bypass, administrator takeover, file creation or command execution on the serve…
##updated 2026-08-26T18:31:52
2 posts
2 repos
Wordfence and Patchstack report five vulnerabilities in WordPress products: WPMU DEV Dashboard (CVE-2026-76581), Avada/Fusion Builder (CVE-2026-18431), TranslatePress (CVE-2026-19632), Pods (CVE-2026-19598) and GiveWP (CVE-2026-82222).
Scores range from CVSS 9.8 to 10.0.
Depending on the affected version and configuration, the flaws can enable authentication bypass, administrator takeover, file creation or command execution on the serve…
##Critical Account Takeover Flaw in TranslatePress Plugin Affects 400,000 WordPress Sites
TranslatePress patched a critical vulnerability (CVE-2026-19632) that allows unauthenticated attackers to steal administrator password reset links and take over WordPress sites.
**If you use the TranslatePress plugin on your WordPress site, update it to version 3.3.2 ASAP, since older versions let attackers steal admin password reset links and take over the whole site. Also turn on two-factor authentication or passkeys for all admin accounts, and check your user list for any new administrators you didn't create.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-account-takeover-flaw-in-translatepress-plugin-affects-400000-wordpress-sites-p-n-s-g-q/gD2P6Ple2L
updated 2026-08-26T17:32:25.887000
1 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-26T17:17:12.260000
1 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-24T19:16:43.757000
1 posts
CVE-2026-68766 is a "vulnerability" in hashcat:
https://github.com/hashcat/hashcat/issues/4738
... where, if you already have write access to hashcat's own restore files (which are locally generated, locally managed, and reachable by the same user invoking hashcat) ... you can ... pass arguments to hashcat other than the ones that were on the original command line. 😐
To be fair, atom did reduce the scope of what the hashcat restore command does -- instead of executing hashcat with the arguments, it just reassembles the cmdline and presents it to the user to review and run as appropriate:
https://github.com/hashcat/hashcat/commit/fcae69f2438ff8eae0dc8e206b78067a1e465ed4
Still a BS report, IMO -- just CVE farming.
Same reporter, different CVE, rejected outright because it doesn't cross a security boundary:
https://github.com/hashcat/hashcat/issues/4737
(And I'm told that the CVE-issuance triage ambiguity -- that greenlit these CVEs that would have been rejected -- is being addressed.)
##updated 2026-08-24T18:31:59
1 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-24T18:31:59
1 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-24T18:31:59
1 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-24T18:31:59
1 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-24T18:31:59
1 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-24T18:31:59
1 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-21T18:34:48
1 posts
6 repos
https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules
https://github.com/BiuTrap/CVE-2026-73570
https://github.com/jishino567/CVE-2026-73570
https://github.com/alsyundawy/eradicate-zimbra-malware
📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482
Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396
Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-72898 - 82.32 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-18577 - 54.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18577)
- CVE-2026-64638 - 31.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64638)
- CVE-2026-71362 - 25.14 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71362)
- CVE-2026-73570 - 20.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73570)
- CVE-2026-64849 - 16.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-48376 - 13.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48376)
- CVE-2026-15733 - 13.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-65400 - 9.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65400)
updated 2026-08-21T00:31:31
1 posts
2 repos
Microsoft Reverses Its Own ‘Exploitation’ Warning on Entra ID Flaw CVE-2026-69836
Microsoft disclosed and fixed a maximum-severity remote code execution vulnerability in Entra ID, its cloud identity platform, on August 20,
🔗️ [Thecyberexpress] https://link.is.it/15Q8CF
##updated 2026-08-19T04:17:34.547000
1 posts
3 repos
https://github.com/panchocosil/CVE-2026-65400-poc
📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482
Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396
Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-72898 - 82.32 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-18577 - 54.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18577)
- CVE-2026-64638 - 31.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64638)
- CVE-2026-71362 - 25.14 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71362)
- CVE-2026-73570 - 20.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73570)
- CVE-2026-64849 - 16.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-48376 - 13.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48376)
- CVE-2026-15733 - 13.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-65400 - 9.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65400)
updated 2026-08-17T21:58:52
1 posts
3 repos
https://github.com/BiuTrap/CVE-2026-64849
📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482
Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396
Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-72898 - 82.32 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-18577 - 54.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18577)
- CVE-2026-64638 - 31.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64638)
- CVE-2026-71362 - 25.14 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71362)
- CVE-2026-73570 - 20.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73570)
- CVE-2026-64849 - 16.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-48376 - 13.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48376)
- CVE-2026-15733 - 13.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-65400 - 9.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65400)
updated 2026-08-15T18:31:24
1 posts
4 repos
https://github.com/HackfutSecRoot/multi_exploit_wp
https://github.com/DeadExpl0it/CVE-2026-19598-PoC
Wordfence and Patchstack report five vulnerabilities in WordPress products: WPMU DEV Dashboard (CVE-2026-76581), Avada/Fusion Builder (CVE-2026-18431), TranslatePress (CVE-2026-19632), Pods (CVE-2026-19598) and GiveWP (CVE-2026-82222).
Scores range from CVSS 9.8 to 10.0.
Depending on the affected version and configuration, the flaws can enable authentication bypass, administrator takeover, file creation or command execution on the serve…
##updated 2026-08-13T15:20:13.333000
1 posts
Microsoft UFO Vulnerability Allows Remote Android Device Takeover
Microsoft patched a critical vulnerability in its UFO automation framework (CVE-2026-73296) that allows unauthenticated attackers to remotely control Android devices and steal sensitive screen data. The flaw affects versions prior to 3.0.8 when configured for remote access.
**If you use Microsoft's UFO automation framework, update it to version 3.0.8 or later ASAP and turn on the required API key authentication. Older versions let anyone on the network fully control your connected Android devices. If you can't update immediately, change the setting back to `localhost` and block incoming traffic to ports 8020 and 8021 at your firewall.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/microsoft-ufo-vulnerability-allows-remote-android-device-takeover-i-v-r-8-e/gD2P6Ple2L
updated 2026-08-12T20:17:57.210000
4 posts
CVE-2026-9586, a critical Sangoma Switchvox vulnerability, is exploited in the wild, giving unauthenticated attackers SQL injection and remote code execution.
#Sangoma #Switchvox #CVE20269586 #RCE #SQLInjection #VoIP #InfoSec #ExploitedInTheWild
##Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/
##CVE-2026-9586, a critical Sangoma Switchvox vulnerability, is exploited in the wild, giving unauthenticated attackers SQL injection and remote code execution.
#Sangoma #Switchvox #CVE20269586 #RCE #SQLInjection #VoIP #InfoSec #ExploitedInTheWild
##Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/
##updated 2026-08-12T15:18:30.347000
3 posts
8 repos
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
https://github.com/Franc-Zar/CVE-2026-72898-safe-detection
https://github.com/codeb0ssx/CVE-2026-72898-PoC
https://github.com/4minx/CVE-2026-72898
https://github.com/VuxNx/CVE-2026-72898
https://github.com/EQSTLab/CVE-2026-72898
https://github.com/0xBlackash/CVE-2026-72898
https://github.com/d-maggipinto/CVE-2026-72898-metabase-sqli
Eine kritische Schwachstelle in Metabase (CVE-2026-72898) reißt ein massives Sicherheitsloch auf: Die ungeauth-fähige Lücke mit dem Höchstwert CVSS 10.0 erlaubt Angreifern den direkten Zugriff auf Anmeldedaten aller verknüpften Datenbanken. Prominente Unternehmen wie Framework, n8n und Checkly wurden bereits Opfer von Datenabflüssen. Betreiber müssen Instanzen sofort patchen und alle Credentials rotieren.
#Metabase #CyberSecurity #DataLeak #Infosec #Database #TechNews
##Eine kritische Schwachstelle in Metabase (CVE-2026-72898) reißt ein massives Sicherheitsloch auf: Die ungeauth-fähige Lücke mit dem Höchstwert CVSS 10.0 erlaubt Angreifern den direkten Zugriff auf Anmeldedaten aller verknüpften Datenbanken. Prominente Unternehmen wie Framework, n8n und Checkly wurden bereits Opfer von Datenabflüssen. Betreiber müssen Instanzen sofort patchen und alle Credentials rotieren.
#Metabase #CyberSecurity #DataLeak #Infosec #Database #TechNews
##📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482
Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396
Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-72898 - 82.32 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-18577 - 54.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18577)
- CVE-2026-64638 - 31.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64638)
- CVE-2026-71362 - 25.14 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71362)
- CVE-2026-73570 - 20.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73570)
- CVE-2026-64849 - 16.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-48376 - 13.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48376)
- CVE-2026-15733 - 13.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-65400 - 9.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65400)
updated 2026-08-12T00:31:09
2 posts
Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!
They all impact SonicWall GMS, which SonicWall has now patched:
👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4
When it shortens 🤏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.
Here's our team's latest disclosed contribution to the community: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011
And here's where you can get more of our research: https://pentest-tools.com/research
PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵
##Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!
They all impact SonicWall GMS, which SonicWall has now patched:
👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4
When it shortens 🤏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.
Here's our team's latest disclosed contribution to the community: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011
And here's where you can get more of our research: https://pentest-tools.com/research
PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵
##updated 2026-08-11T18:32:00
1 posts
1 repos
📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482
Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396
Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-72898 - 82.32 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-18577 - 54.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18577)
- CVE-2026-64638 - 31.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64638)
- CVE-2026-71362 - 25.14 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71362)
- CVE-2026-73570 - 20.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73570)
- CVE-2026-64849 - 16.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-48376 - 13.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48376)
- CVE-2026-15733 - 13.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-65400 - 9.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65400)
updated 2026-08-11T12:30:28
1 posts
2 repos
Az SAP Commerce Cloud CVE-2026-58231 sebezhetőségét már a javítás után napokkal támadások célba vették
##updated 2026-08-07T18:31:37
1 posts
📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482
Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396
Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-72898 - 82.32 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-18577 - 54.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18577)
- CVE-2026-64638 - 31.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64638)
- CVE-2026-71362 - 25.14 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71362)
- CVE-2026-73570 - 20.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73570)
- CVE-2026-64849 - 16.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-48376 - 13.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48376)
- CVE-2026-15733 - 13.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-65400 - 9.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65400)
updated 2026-08-06T05:17:05.170000
1 posts
4 repos
https://github.com/AnggaTechI/CVE-2026-63077
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation
https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap
JetBrains Cadence Service Breached via Unpatched TeamCity RCE Flaw
JetBrains reported a breach of its Cadence cloud service after failing to patch a critical TeamCity vulnerability (CVE-2026-63077). The attack resulted in the theft of user personal data and a 2024 server backup containing sensitive AWS credentials and source code.
**Rotate every secret used in your cloud development workflows immediately to prevent lateral movement. This breach shows that even a single unpatched internal server can expose your entire backup history and cloud credentials.**
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/jetbrains-cadence-service-breached-via-unpatched-teamcity-rce-flaw-s-9-2-o-x/gD2P6Ple2L
updated 2026-08-04T15:33:20
1 posts
2 repos
https://github.com/HORKimhab/CVE-2026-18577
https://github.com/CreamyG31337/ncentral-compromise-ioc-triage
📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482
Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396
Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-72898 - 82.32 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-18577 - 54.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18577)
- CVE-2026-64638 - 31.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64638)
- CVE-2026-71362 - 25.14 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71362)
- CVE-2026-73570 - 20.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73570)
- CVE-2026-64849 - 16.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-48376 - 13.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48376)
- CVE-2026-15733 - 13.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-65400 - 9.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65400)
updated 2026-07-30T18:23:34
2 posts
7 repos
https://github.com/0xBlackash/CVE-2026-66066
https://github.com/Zer0SumGam3/CVE-2026-66066-POC
https://github.com/rails/rails-forensics-CVE-2026-66066
https://github.com/HackSpeak/CVE-2026-66066
https://github.com/shinthink/CVE-2026-66066
Hackers Are Exploiting a Critical Ruby on Rails Flaw That Can Expose Secrets and Enable Remote Code Execution
A Dangerous New Chapter for Ruby on Rails Security A critical vulnerability in Ruby on Rails has moved from a theoretical security concern to an active exploitation threat, raising fresh alarms for organizations that rely on Rails applications to handle sensitive data, authentication, file uploads, and internal business operations. Tracked as CVE-2026-66066,…
##VulnCheck reports active exploitation of CVE-2026-66066 (KindaRails2Shell), a CVSS 9.5 flaw in Ruby on Rails. A crafted image upload enables arbitrary file read, leading to secret and credential theft with potential for lateral movement and RCE. Unpatched Rails instances handling file uploads are at immediate risk. #RubyOnRails #KindaRails2Shell #InfoSec
https://cyberworldops.eu/en/kindarails2shell-active-attacks-against-ruby-on-rails-use-file-uploads
##updated 2026-07-22T15:21:26.967000
1 posts
Elsewhere, CVE-2026-50661 lets physical-access attackers bypass BitLocker encryption, and Scattered Spider defendants pleaded guilty on day one of trial.
Per protocol: rotate every exposed AWS GovCloud credential and CISA internal password immediately, enforce MFA, and audit AWS Workspace access logs for unauthorized activity.
Reward: You've unlocked the Plaintext Pantry — a decorative chest containing your own credentials, already sorted alphabetically for the attacker's convenience. (2/2)
##updated 2026-07-15T02:20:40.183000
2 posts
1 repos
Hackers exploit CVE-2026-35029 in the wild. Prevent a LiteLLM vulnerability server takeover and safeguard exposed secrets.
#LiteLLM #CVE202635029 #CyberSecurity #AIGateway #ServerTakeover
##Hackers exploit CVE-2026-35029 in the wild. Prevent a LiteLLM vulnerability server takeover and safeguard exposed secrets.
#LiteLLM #CVE202635029 #CyberSecurity #AIGateway #ServerTakeover
##updated 2026-07-13T21:31:30
2 posts
3 repos
RE: https://infosec.exchange/@cR0w/117169327022091327
Update:
##Update - September 1st, 2026
Due to additional analysis provided by the security researcher who discovered CVE-2026-6875, we have upgraded the severity rating of CVE-2026-6876 from High to Critical. This change affects only the severity rating for CVE-2026-6876; it does not change the other information shared in our August 27th advisory. Based on our monitoring to date, we have not observed evidence of malicious exploitation of this issue.
RE: https://infosec.exchange/@cR0w/117169327022091327
Update:
##Update - September 1st, 2026
Due to additional analysis provided by the security researcher who discovered CVE-2026-6875, we have upgraded the severity rating of CVE-2026-6876 from High to Critical. This change affects only the severity rating for CVE-2026-6876; it does not change the other information shared in our August 27th advisory. Based on our monitoring to date, we have not observed evidence of malicious exploitation of this issue.
updated 2026-07-08T15:31:45
1 posts
A public proof-of-concept for the CVE-2026-52933 privilege escalation flaw is available. This Linux kernel io_uring exploit carries a CVSS 7.8 score.
#Linux #CVE202652933 #PrivilegeEscalation #KernelExploit #Cybersecurity
##updated 2026-06-30T03:35:21
1 posts
1 repos
13 malicious Composer themes on Packagist are being used on Vietnamese streaming sites. Installed on OphimCMS or KKPhim, they inject JavaScript and a hidden iframe: mobile visitors may be redirected to ad-fraud and gambling pages, while vulnerable iPhones can be targeted through Safari with an exploit chain reaching the kernel.
The campaign exploits CVE-2025-31277 and CVE-2025-43529, patched in iOS 18.6, 18.7.3…
##updated 2026-06-17T04:56:14.803000
1 posts
7 repos
https://github.com/R0rt1z2/CVE-2022-38181
https://github.com/Pro-me3us/CVE_2022_38181_Raven
https://github.com/Bariskizilkaya/CVE_2022_38181-Mali-SAMSUNG-S6-Lite-Tablet
https://github.com/ericpardee/fire-hd-ownership
https://github.com/soralis0912/CVE-2022-38181-aristotle
Amazon kept shutting down my tablet, so I spent $266 on four AI models to own it
"Owning a tablet Amazon kept shutting down: CVE-2022-38181, four AI models, five months"
##updated 2026-01-23T06:31:32
8 posts
1 repos
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for...
🔗️ [Bleepingcomputer] https://link.is.it/mc2J3U
##Actively exploited unauthenticated RCE in Langflow (CVE-2026-0768) allows remote code execution via the custom component validator. It enables extraction of OpenAI and AWS keys and root credentials, exposing AI infrastructure to full takeover. Patch and rotate all secrets immediately. #Langflow #CVE20260768 #InfoSec
https://cyberworldops.eu/en/langflow-under-attack-rce-flaw-exposes-openai-and-aws-keys-root
##Cyberkriminelle nutzen aktiv eine ungepatchte RCE-Schwachstelle (CVE-2026-0768) im KI-Framework Langflow aus. Über den kritischen Fehler erlangen Angreifer unautorisierten Zugriff auf Systeme, um sensible API-Schlüssel, Tokens und Anmeldedaten von Plattformen wie OpenAI oder AWS abzugreifen. Anwender sollten die Software umgehend absichern.
##Langflow vulnerability exploited to harvest OpenAI, AWS keys
Attackers are actively exploiting a critical vulnerability in Langflow to harvest sensitive keys, including OpenAI and AWS credentials, by querying environment variables and reading secret files. This severe flaw, known as CVE-2026-0768, allows hackers to execute arbitrary Python code with root privileges, putting systems at risk.
##📰 Critical RCE Flaw in Langflow AI Platform Actively Exploited
Critical RCE flaw (CVE-2026-0768, 9.8 CVSS) in the Langflow AI platform is actively exploited. Unauthenticated attackers can get root access to steal credentials. Patch to version 1.4.3+ now! #Langflow #AI #CyberSecurity #RCE #CVE
##Critical Langflow flaw exploited to steal OpenAI and AWS keys
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for...
🔗️ [Bleepingcomputer] https://link.is.it/mc2J3U
##Actively exploited unauthenticated RCE in Langflow (CVE-2026-0768) allows remote code execution via the custom component validator. It enables extraction of OpenAI and AWS keys and root credentials, exposing AI infrastructure to full takeover. Patch and rotate all secrets immediately. #Langflow #CVE20260768 #InfoSec
https://cyberworldops.eu/en/langflow-under-attack-rce-flaw-exposes-openai-and-aws-keys-root
##Cyberkriminelle nutzen aktiv eine ungepatchte RCE-Schwachstelle (CVE-2026-0768) im KI-Framework Langflow aus. Über den kritischen Fehler erlangen Angreifer unautorisierten Zugriff auf Systeme, um sensible API-Schlüssel, Tokens und Anmeldedaten von Plattformen wie OpenAI oder AWS abzugreifen. Anwender sollten die Software umgehend absichern.
##updated 2025-12-17T21:31:01
1 posts
8 repos
https://github.com/SimoesCTT/Convergent-Time-Theory-Enhanced-iOS-Safari-RCE-CVE-2025-43529-
https://github.com/GenericCoding/pois0nSword
https://github.com/SimoesCTT/CTT-Apple-Silicon-Refraction
https://github.com/bjrjk/CVE-2025-43529
https://github.com/stationedK-06/DarkSword_analysis
https://github.com/kmeps4/bugtest
https://github.com/0xjohnnydev/WebKit-UAF-ANGLE-OOB-Analysis
13 malicious Composer themes on Packagist are being used on Vietnamese streaming sites. Installed on OphimCMS or KKPhim, they inject JavaScript and a hidden iframe: mobile visitors may be redirected to ad-fraud and gambling pages, while vulnerable iPhones can be targeted through Safari with an exploit chain reaching the kernel.
The campaign exploits CVE-2025-31277 and CVE-2025-43529, patched in iOS 18.6, 18.7.3…
##updated 2025-10-22T00:31:58
1 posts
78 repos
https://github.com/hell-moon/ZeroLogon-Exploit
https://github.com/JayP232/The_big_Zero
https://github.com/maikelnight/zerologon
https://github.com/tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation
https://github.com/itssmikefm/CVE-2020-1472
https://github.com/rhymeswithmogul/Set-ZerologonMitigation
https://github.com/dr4g0n23/CVE-2020-1472
https://github.com/ckq7703/CVE-2020-1472
https://github.com/mos165/CVE-20200-1472
https://github.com/johnpathe/zerologon-cve-2020-1472-notes
https://github.com/Ken-Abruzzi/cve-2020-1472
https://github.com/hectorgie/CVE-2020-1472
https://github.com/0xcccc666/cve-2020-1472_Tool-collection
https://github.com/bvcyber/CVE-2020-1472
https://github.com/Fa1c0n35/SecuraBV-CVE-2020-1472
https://github.com/Akash7350/CVE-2020-1472
https://github.com/thatonesecguy/zerologon-CVE-2020-1472
https://github.com/guglia001/MassZeroLogon
https://github.com/midpipps/CVE-2020-1472-Easy
https://github.com/mods20hh/ZeroLogon-PoC-DC-Pwn
https://github.com/technion/ZeroLogonAssess
https://github.com/commit2main/zerologon-lab
https://github.com/TheJoyOfHacking/SecuraBV-CVE-2020-1472
https://github.com/McKinnonIT/zabbix-template-CVE-2020-1472
https://github.com/b1ack0wl/CVE-2020-1472
https://github.com/npocmak/CVE-2020-1472
https://github.com/blackh00d/zerologon-poc
https://github.com/Anonymous-Family/Zero-day-scanning
https://github.com/Privia-Security/ADZero
https://github.com/FaFcFF41/CVE-2020-1472
https://github.com/zeronetworks/zerologon
https://github.com/murataydemir/CVE-2020-1472
https://github.com/VoidSec/CVE-2020-1472
https://github.com/TheJoyOfHacking/dirkjanm-CVE-2020-1472
https://github.com/Fa1c0n35/CVE-2020-1472-02-
https://github.com/WiIs0n/Zerologon_CVE-2020-1472
https://github.com/likeww/MassZeroLogon
https://github.com/cube0x0/CVE-2020-1472
https://github.com/YossiSassi/ZeroLogon-Exploitation-Check
https://github.com/striveben/CVE-2020-1472
https://github.com/Tobey123/CVE-2020-1472-visualizer
https://github.com/JolynNgSC/Zerologon_CVE-2020-1472
https://github.com/B34MR/zeroscan
https://github.com/logg-1/0logon
https://github.com/mstxq17/cve-2020-1472
https://github.com/sv3nbeast/CVE-2020-1472
https://github.com/jiushill/CVE-2020-1472
https://github.com/CPO-EH/CVE-2020-1472_ZeroLogonChecker
https://github.com/abdullah50i/internal-penetration-testing-project-using-Metasploit
https://github.com/t31m0/CVE-2020-1472
https://github.com/0xkami/CVE-2020-1472
https://github.com/grupooruss/CVE-2020-1472
https://github.com/Whippet0/CVE-2020-1472
https://github.com/Udyz/Zerologon
https://github.com/bb00/zer0dump
https://github.com/mingchen-script/CVE-2020-1472-visualizer
https://github.com/NAXG/CVE-2020-1472
https://github.com/100HnoMeuNome/ZeroLogon-CVE-2020-1472-lab
https://github.com/CanciuCostin/CVE-2020-1472
https://github.com/nyambiblaise/Domain-Controller-DC-Exploitation-with-Metasploit-Impacket
https://github.com/wrathfulDiety/zerologon
https://github.com/SaharAttackit/CVE-2020-1472
https://github.com/whoami-chmod777/Zerologon-Attack-CVE-2020-1472-POC
https://github.com/PakwanSK/Simulating-and-preventing-Zerologon-CVE-2020-1472-vulnerability-attacks.
https://github.com/Rvn0xsy/ZeroLogon
https://github.com/dirkjanm/CVE-2020-1472
https://github.com/metehangelgi/CVE-2020-1472-LAB
https://github.com/c3rrberu5/ZeroLogon-to-Shell
https://github.com/risksense/zerologon
https://github.com/Fa1c0n35/CVE-2020-1472
https://github.com/shanfenglan/cve-2020-1472
https://github.com/carlos55ml/zerologon
https://github.com/Sajuwithgithub/CVE2020-1472
https://github.com/TuanCui22/ZerologonWithImpacket-CVE2020-1472
https://github.com/puckiestyle/CVE-2020-1472
https://github.com/sho-luv/zerologon
Patches einspielen.
Wenn man https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html glauben darf, nutzen die
> Zerologon (CVE-2020-1472), an elevation of privileges vulnerability in Microsoft's Netlogon Remote Protocol that Microsoft patched on August 11, 2020.
##updated 2025-09-05T18:31:39
2 posts
First pulse, first success. ⚡
@g0mb4ck (Milena) shows a triggerless EM fault injection attack on Nordic Semi's nRF52810 SoC (CVE-2025-9709) - the first of its kind ever reported and remarkably reproducible.
👉 Program & tickets: https://wiccon.nl/
##First pulse, first success. ⚡
@g0mb4ck (Milena) shows a triggerless EM fault injection attack on Nordic Semi's nRF52810 SoC (CVE-2025-9709) - the first of its kind ever reported and remarkably reproducible.
👉 Program & tickets: https://wiccon.nl/
##updated 2023-01-30T05:03:17
2 posts
8 repos
https://github.com/h1bAna/CVE-2017-5123
https://github.com/c3r34lk1ll3r/CVE-2017-5123
https://github.com/NabilBoudra/cve-2017-5123
https://github.com/Synacktiv-contrib/exploiting-cve-2017-5123
https://github.com/teawater/CVE-2017-5123
https://github.com/0x5068656e6f6c/CVE-2017-5123
I discuss Linux kernel exception handling in my training—specifically the mechanism that allows the kernel to trigger page faults at specific locations and handle them gracefully. This is why copy_from_user(), copy_to_user(), and other related functions don't cause a kernel oops when dealing with invalid addresses.
I abuse this mechanism in a vulnerability that leads to an arbitrary read to bypass KASLR during my Linux kernel exploitation training. I had played with it several times, but I had never read the official documentation until I came across it recently while looking for well-written material to send to the class. This mechanism has also been abused in other exploits, such as the one below.
Kernel level exception handling in Linux
https://www.kernel.org/doc/Documentation/x86/exception-tables.txt
Exploiting CVE-2017-5123
https://reverse.put.as/2017/11/07/exploiting-cve-2017-5123/
I discuss Linux kernel exception handling in my training—specifically the mechanism that allows the kernel to trigger page faults at specific locations and handle them gracefully. This is why copy_from_user(), copy_to_user(), and other related functions don't cause a kernel oops when dealing with invalid addresses.
I abuse this mechanism in a vulnerability that leads to an arbitrary read to bypass KASLR during my Linux kernel exploitation training. I had played with it several times, but I had never read the official documentation until I came across it recently while looking for well-written material to send to the class. This mechanism has also been abused in other exploits, such as the one below.
Kernel level exception handling in Linux
https://www.kernel.org/doc/Documentation/x86/exception-tables.txt
Exploiting CVE-2017-5123
https://reverse.put.as/2017/11/07/exploiting-cve-2017-5123/
1 posts
26 repos
https://github.com/jendmaoul/XSS2Shell-CVE-2026-64638
https://github.com/renzi25031469/CVE-2026-64638-WordPress-Core-XSS2Shell
https://github.com/eh-amish/CVE-2026-64638-XSS-to-Shell-PoC
https://github.com/yogaGymn/XSS2Shell-CVE-2026-64638
https://github.com/ZildanZ/CVE-2026-64638
https://github.com/4minx/CVE-2026-64638
https://github.com/HORKimhab/CVE-2026-64638
https://github.com/xAL6/cve-2026-64638-banner-poc
https://github.com/g0d150ne/XSS2Shell
https://github.com/wordsec/XSS2Shell
https://github.com/686f6c61/POC-WP-XSS2Shell-CVE-2026-64638
https://github.com/Dungsocool/CVE-2026-64638
https://github.com/mohwahyudi/poc-CVE-2026-64638-
https://github.com/MR-LeonardoGomes/XSS2Shell-CVE-2026-64638
https://github.com/Boreas37/CVE-2026-64638-PoC-XSS2Shell-
https://github.com/0xBlackash/CVE-2026-64638
https://github.com/ZSecur1ty/XSS2Shell-CVE-2026-64638
https://github.com/Alixploit22/CVEX2SHEL
https://github.com/imbas007/CVE-2026-64638-POC
https://github.com/HackSpeak/CVE-2026-64638
https://github.com/kaleth4/CVE-2026-64638
https://github.com/G33l0/Cve-2026-64638
https://github.com/5yu4n/CVE-2026-64638
https://github.com/0xlipon/xss2shell
📈 CVE Published in last 30 days (2026-08-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1702
- High: 5241
- Medium: 3734
- Low: 735
- None: 1482
Status:
- : 175
- Analyzed: 2708
- Awaiting Analysis: 1325
- Deferred: 3345
- Modified: 296
- Received: 4395
- Rejected: 428
- Undergoing Analysis: 222
CISA KEVs:
- CISA-2026:0803 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
- CISA-2026:0805 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0805)
- CISA-2026:0804 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
- CISA-2026:0807 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0807)
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
Top CNAs:
- kernel.org: 1650
- VulnCheck: 1436
- GitHub, Inc.: 1382
- Oracle: 890
- VulDB: 684
- WPScan: 540
- Patchstack: 513
- MITRE: 483
- Microsoft Corporation: 471
- Chrome: 396
Top Affected Products:
- UNKNOWN: 9271
- Google Chrome: 395
- Microsoft Windows Server 2025: 213
- Microsoft Windows 11 26h1: 196
- Microsoft Windows 11 25h2: 194
- Microsoft Windows 11 24h2: 194
- Microsoft Windows Server 2022: 193
- Microsoft Windows 10 1809: 181
- Microsoft Windows Server 2019: 181
- Microsoft Windows 11 23h2: 169
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-72898 - 82.32 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-18577 - 54.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18577)
- CVE-2026-64638 - 31.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64638)
- CVE-2026-71362 - 25.14 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71362)
- CVE-2026-73570 - 20.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73570)
- CVE-2026-64849 - 16.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-48376 - 13.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48376)
- CVE-2026-15733 - 13.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15733)
- CVE-2026-65400 - 9.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65400)
🟠 CVE-2026-82393 - High (7.5)
pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for unscoped ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-79750 - High (7.7)
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.30, MCPHub scopes non-admin users to servers they own (list views...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79750/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-79748 - Critical (9.9)
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79748/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##"Hacking the planet" incident post-mortem:
Initial access was obtained through an unpatched volcanic vent. Attackers achieved mantle persistence by exploiting a flaw in plate-tectonic privilege separation.
The core was still running a legacy geomagnetic service as root, which was exploited via a magmatic overflow.
The breach was detected when lateral movement was observed along several transform faults.
The Pacific Plate has been rotated out of production pending forensic analysis.
Earth confirms that no evidence of core exfiltration has been found.
The vulnerability has been assigned CVE-2026-31337: "Improper Boundary Validation in Terrestrial Lithosphere."
Mitigation involved removing the rootkit with sudo rm -rf /mantle/.rootkit, which caused approximately three minutes of elevated seismic activity.
Earth has reset all tectonic credentials and strongly recommends that other terrestrial planets rotate their cores immediately. Note this may result in a magnetic pole reversal as a side effect; consider this effect during any rotation, and plan accordingly.
##🔴 CVE-2026-54745 - Critical (10)
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54745/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81849 - High (8.8)
Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81849/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##