##
Updated at UTC 2026-09-09T05:07:55.324408
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-81954 | 7.8 | 0.00% | 2 | 0 | 2026-09-09T04:20:23.543000 | Use after free in Microsoft Office Excel allows an unauthorized attacker to exec | |
| CVE-2026-69829 | 9.8 | 0.00% | 3 | 0 | 2026-09-09T04:19:30.720000 | Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to e | |
| CVE-2026-69439 | 8.8 | 0.00% | 1 | 0 | 2026-09-09T04:18:40.510000 | Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized atta | |
| CVE-2026-12855 | 8.2 | 0.00% | 2 | 0 | 2026-09-09T04:17:56.480000 | Unvalidated memory boundary could result in arbitrary code execution. The vulner | |
| CVE-2026-87628 | None | 0.00% | 2 | 0 | 2026-09-09T03:30:52 | Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjace | |
| CVE-2026-15667 | 7.5 | 0.00% | 2 | 0 | 2026-09-09T03:30:51 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) | |
| CVE-2026-87491 | None | 0.00% | 2 | 0 | 2026-09-09T03:30:46 | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remo | |
| CVE-2026-73315 | 8.6 | 0.00% | 2 | 1 | 2026-09-09T03:30:37 | XenForo before 2.3.13 contains a server-side request forgery vulnerability in th | |
| CVE-2026-73316 | 7.5 | 0.00% | 2 | 1 | 2026-09-09T03:30:36 | XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST | |
| CVE-2026-73314 | 7.5 | 0.00% | 2 | 1 | 2026-09-09T01:16:57.930000 | XenForo before 2.3.13 contains a signature verification logic error in the PayPa | |
| CVE-2026-18355 | 7.5 | 0.84% | 4 | 0 | 2026-09-09T00:30:29 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Ser | |
| CVE-2026-53938 | 8.2 | 0.00% | 2 | 0 | 2026-09-09T00:17:31.557000 | OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encr | |
| CVE-2026-19306 | 7.7 | 0.41% | 1 | 0 | 2026-09-08T22:04:05.090000 | IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read a | |
| CVE-2026-85983 | 7.8 | 0.00% | 2 | 0 | 2026-09-08T21:34:41 | The Auth0 AD/LDAP Connector improperly processes a configuration value during se | |
| CVE-2026-84869 | 9.9 | 0.00% | 4 | 0 | 2026-09-08T21:34:37 | A condition in the ScreenConnect client may allow files to be transferred and ex | |
| CVE-2026-82007 | 7.8 | 0.00% | 2 | 0 | 2026-09-08T21:34:36 | Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability | |
| CVE-2026-81994 | 8.2 | 0.00% | 2 | 0 | 2026-09-08T21:18:46.223000 | Acrobat Reader is affected by an Improperly Controlled Modification of Object Pr | |
| CVE-2026-52775 | 8.8 | 0.29% | 1 | 0 | 2026-09-08T21:05:26.920000 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through | |
| CVE-2026-52767 | 8.2 | 0.22% | 1 | 0 | 2026-09-08T21:05:26.920000 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4. | |
| CVE-2026-52771 | 8.3 | 0.30% | 1 | 0 | 2026-09-08T21:05:26.920000 | YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4. | |
| CVE-2026-84372 | 9.8 | 0.41% | 2 | 0 | 2026-09-08T20:57:52 | ### Summary An improper CRLF neutralization flaw in Predis' pipeline handling o | |
| CVE-2026-85061 | 10.0 | 0.31% | 2 | 0 | 2026-09-08T20:50:48 | ### Impact `DOM.sanitize()` in `src/util/dom.ts` iterated `elem.attributes` (a l | |
| CVE-2026-84942 | 8.7 | 0.00% | 2 | 0 | 2026-09-08T20:18:51.307000 | Improper input validation in the Vega expression function implementation in Open | |
| CVE-2026-80116 | 7.8 | 0.11% | 1 | 0 | 2026-09-08T20:10:30.270000 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10 | |
| CVE-2026-80113 | 7.1 | 0.11% | 1 | 0 | 2026-09-08T20:10:30.270000 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10 | |
| CVE-2026-80118 | 7.1 | 0.11% | 1 | 0 | 2026-09-08T20:10:30.270000 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10 | |
| CVE-2026-86184 | 9.8 | 0.60% | 1 | 0 | 2026-09-08T20:06:38.260000 | Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in t | |
| CVE-2026-86250 | 7.5 | 0.28% | 1 | 0 | 2026-09-08T20:00:18.870000 | h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user | |
| CVE-2026-86435 | 7.5 | 0.28% | 1 | 0 | 2026-09-08T19:57:49.663000 | commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerab | |
| CVE-2026-86541 | 8.3 | 0.53% | 2 | 0 | 2026-09-08T19:56:50.950000 | knowns versions before 0.30.0 contain a path traversal vulnerability in the hand | |
| CVE-2026-86540 | 7.8 | 0.14% | 2 | 0 | 2026-09-08T19:56:50.950000 | knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary | |
| CVE-2026-86439 | 8.8 | 0.75% | 2 | 0 | 2026-09-08T19:56:50.950000 | knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool argu | |
| CVE-2026-86542 | 9.1 | 0.47% | 2 | 0 | 2026-09-08T19:56:50.950000 | knowns before 0.30.0 fails to validate import names in the import routes, allowi | |
| CVE-2026-86727 | 7.5 | 0.00% | 2 | 0 | 2026-09-08T19:53:13.400000 | AVideo through 29.0 contains an information disclosure vulnerability in plugin/L | |
| CVE-2026-31020 | 9.8 | 0.58% | 1 | 0 | 2026-09-08T19:42:20.313000 | In DocsGPT 0.15.0 and below, the application provides a custom prompt feature th | |
| CVE-2026-75650 | 10.0 | 0.68% | 21 | 3 | 2026-09-08T19:29:17.803000 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Use | |
| CVE-2026-84282 | 0 | 0.00% | 2 | 0 | 2026-09-08T19:29:09.680000 | A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownC | |
| CVE-2026-86218 | 9.8 | 0.41% | 16 | 1 | 2026-09-08T19:28:43.390000 | N-central is vulnerable to a pre-auth remote code execution This issue affects N | |
| CVE-2026-85880 | 7.8 | 0.00% | 13 | 0 | 2026-09-08T19:28:36.983000 | Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev | |
| CVE-2026-81963 | 7.8 | 0.00% | 14 | 0 | 2026-09-08T19:28:31.630000 | Improper link resolution before file access ('link following') in Windows Update | |
| CVE-2026-0799 | 8.7 | 0.11% | 1 | 0 | 2026-09-08T19:20:25.117000 | In BPF instructions that load/store a value from/to a scratch memory register th | |
| CVE-2026-86206 | 0 | 0.29% | 3 | 0 | 2026-09-08T19:16:41.410000 | A vulnerability in the N-central internal API access control filter allows unaut | |
| CVE-2026-84934 | 8.0 | 0.23% | 1 | 0 | 2026-09-08T19:15:18.627000 | The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability che | |
| CVE-2026-44756 | 10.0 | 0.32% | 11 | 0 | 2026-09-08T19:12:59.557000 | A memory safety vulnerability exists in the Extended Passport Protocol (EPP) pro | |
| CVE-2026-78328 | 9.1 | 0.50% | 1 | 0 | 2026-09-08T19:12:59.557000 | A missing authorization vulnerability in the SonicWall Network Security Manager | |
| CVE-2026-66768 | 9.0 | 0.32% | 2 | 0 | 2026-09-08T19:12:59.557000 | SAP GUI for Java does not correctly enforce the trust level policy for certain f | |
| CVE-2026-76958 | 8.5 | 0.22% | 2 | 0 | 2026-09-08T19:12:59.557000 | SAP Integration Suite does not sufficiently validate XML documents accepted from | |
| CVE-2026-78327 | 9.1 | 1.55% | 1 | 0 | 2026-09-08T19:12:59.557000 | An Improper Neutralization of Special Elements used in an OS Command ('OS Comman | |
| CVE-2026-19858 | 7.5 | 0.32% | 1 | 0 | 2026-09-08T19:09:21.310000 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 | |
| CVE-2026-19534 | 7.5 | 0.39% | 1 | 0 | 2026-09-08T19:07:52.113000 | undici's WebSocket client crashes the whole Node.js process during the opening h | |
| CVE-2026-62645 | 9.8 | 0.35% | 2 | 0 | 2026-09-08T18:41:55.127000 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Inf | |
| CVE-2026-69730 | 9.8 | 0.00% | 4 | 0 | 2026-09-08T18:39:51.493000 | Use after free in Windows DNS allows an unauthorized attacker to execute code ov | |
| CVE-2026-83972 | 7.8 | 0.00% | 2 | 0 | 2026-09-08T18:39:13.460000 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att | |
| CVE-2026-26084 | 9.9 | 0.00% | 2 | 0 | 2026-09-08T18:35:10.323000 | A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5 | |
| CVE-2026-83970 | 7.8 | 0.00% | 2 | 0 | 2026-09-08T18:34:30 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att | |
| CVE-2026-81953 | 7.8 | 0.00% | 2 | 0 | 2026-09-08T18:34:03 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized att | |
| CVE-2026-80081 | 8.8 | 0.00% | 2 | 0 | 2026-09-08T18:34:00 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to | |
| CVE-2026-71328 | 8.8 | 0.00% | 1 | 0 | 2026-09-08T18:33:14 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to e | |
| CVE-2026-69806 | 7.0 | 0.00% | 1 | 0 | 2026-09-08T18:33:09 | Exposure of sensitive information to an unauthorized actor in .NET allows an aut | |
| CVE-2026-69682 | 7.0 | 0.00% | 1 | 0 | 2026-09-08T18:33:02 | Use after free in Windows Host Guardian Service allows an authorized attacker to | |
| CVE-2026-69525 | 9.8 | 0.00% | 1 | 0 | 2026-09-08T18:32:53 | Use after free in Windows Remote Desktop Services allows an unauthorized attacke | |
| CVE-2026-69420 | 7.8 | 0.00% | 2 | 0 | 2026-09-08T18:32:42 | Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker | |
| CVE-2026-58649 | 6.5 | 0.00% | 1 | 0 | 2026-09-08T18:32:10 | Origin validation error in .NET allows an unauthorized attacker to disclose info | |
| CVE-2026-20293 | 7.1 | 0.00% | 2 | 0 | 2026-09-08T18:32:05 | A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implem | |
| CVE-2026-86730 | 8.8 | 0.00% | 2 | 0 | 2026-09-08T18:32:01 | Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-la | |
| CVE-2026-86738 | 8.7 | 0.00% | 2 | 0 | 2026-09-08T18:32:01 | Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Cust | |
| CVE-2026-86728 | 7.5 | 0.00% | 2 | 0 | 2026-09-08T18:32:00 | AVideo through 29.0 contains an authentication bypass vulnerability in plugin/Pl | |
| CVE-2026-86732 | 8.8 | 0.00% | 2 | 0 | 2026-09-08T18:31:59 | Craft CMS versions before 5.10.12 contain a remote code execution vulnerability | |
| CVE-2026-86721 | 7.5 | 0.00% | 2 | 0 | 2026-09-08T18:31:53 | AVideo through commit c3edcc274c contains an authorization bypass vulnerability | |
| CVE-2026-86167 | 9.9 | 1.63% | 1 | 0 | 2026-09-08T18:21:15.533000 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function | |
| CVE-2026-85694 | 8.1 | 0.55% | 1 | 0 | 2026-09-08T18:21:13.400000 | LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkd | |
| CVE-2026-60004 | 9.8 | 86.78% | 1 | 9 | 2026-09-08T17:56:31 | ### Summary Gitea's `diffpatch` endpoint can be abused to install and execute a | |
| CVE-2026-86296 | 10.0 | 1.35% | 2 | 0 | 2026-09-08T17:18:39.613000 | A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affe | |
| CVE-2026-86060 | 0 | 0.40% | 8 | 0 | 2026-09-08T16:18:20.027000 | RouterOS contains an argument-handling flaw in the SSH login path involving user | |
| CVE-2026-67279 | 0 | 0.45% | 1 | 0 | 2026-09-08T16:18:10.600000 | RouterOS SSH enters the connection protocol after a client-requested rekey even | |
| CVE-2026-86492 | 8.5 | 0.56% | 2 | 0 | 2026-09-08T15:30:03.247000 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-ten | |
| CVE-2026-82712 | 8.8 | 0.25% | 1 | 0 | 2026-09-08T15:28:33.090000 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cr | |
| CVE-2026-75925 | 9.6 | 0.67% | 1 | 0 | 2026-09-08T15:28:33.090000 | Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4. | |
| CVE-2026-78012 | 9.8 | 0.47% | 1 | 0 | 2026-09-08T15:28:33.090000 | An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Cl | |
| CVE-2026-7861 | 9.8 | 0.33% | 1 | 0 | 2026-09-08T15:18:48.973000 | Deserialization of untrusted data vulnerability in Next4Biz Information Technolo | |
| CVE-2026-71377 | 9.8 | 0.31% | 2 | 0 | 2026-09-08T14:18:34.130000 | Command Argument Injection Vulnerability in Cosminexus Component Container. Thi | |
| CVE-2026-86259 | 7.5 | 0.25% | 1 | 0 | 2026-09-08T14:17:33.170000 | OpenMAIC before 1.0.1 skips server-side request forgery validation in non-produc | |
| CVE-2026-86165 | 9.8 | 0.64% | 1 | 0 | 2026-09-08T14:17:31.267000 | A vulnerability was found in Tenda HG10 300001138. This vulnerability affects th | |
| CVE-2026-48019 | 8.9 | 0.68% | 1 | 1 | 2026-09-08T14:17:22.837000 | Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a | |
| CVE-2026-19274 | 9.6 | 0.21% | 1 | 0 | 2026-09-08T14:17:08.940000 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana | |
| CVE-2026-80166 | 7.8 | 0.10% | 2 | 0 | 2026-09-08T14:14:23.790000 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application | |
| CVE-2026-85656 | 7.8 | 1.12% | 1 | 0 | 2026-09-08T14:00:33.017000 | An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Am | |
| CVE-2026-85638 | 7.3 | 0.30% | 1 | 0 | 2026-09-08T13:12:58.310000 | A weakness has been identified in jofpin trape 2.0. This affects an unknown part | |
| CVE-2026-48888 | 7.5 | 0.26% | 2 | 0 | 2026-09-08T13:12:58.310000 | Allocation of Resources Without Limits or Throttling vulnerability in Automattic | |
| CVE-2026-86297 | 8.1 | 1.05% | 1 | 0 | 2026-09-08T13:12:58.310000 | A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects | |
| CVE-2026-86152 | 10.0 | 1.86% | 1 | 0 | 2026-09-08T13:12:58.310000 | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the func | |
| CVE-2026-78234 | 9.9 | 0.00% | 4 | 0 | 2026-09-08T12:31:35 | A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA | |
| CVE-2026-18922 | 9.8 | 0.56% | 2 | 0 | 2026-09-08T09:36:41 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a st | |
| CVE-2026-50093 | 9.0 | 0.19% | 2 | 0 | 2026-09-08T09:35:45 | A vulnerability has been identified in Siveillance Control Pro V3.0 (All version | |
| CVE-2026-81790 | 7.5 | 0.27% | 2 | 0 | 2026-09-08T09:35:45 | Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási cí | |
| CVE-2026-71374 | 9.8 | 0.31% | 2 | 0 | 2026-09-08T09:35:44 | Deserialization of untrusted data vulnerability in Cosminexus Component Containe | |
| CVE-2026-19397 | None | 0.21% | 2 | 0 | 2026-09-08T03:31:21 | Missing authentication for a critical function in ASUS Control Center Express Ag | |
| CVE-2026-76969 | 9.4 | 0.29% | 4 | 0 | 2026-09-08T03:31:21 | @sap/cds-mtxs NPM library does not perform sufficient checks on certain function | |
| CVE-2026-66767 | 7.7 | 0.26% | 2 | 0 | 2026-09-08T03:31:21 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenti | |
| CVE-2026-86510 | 9.9 | 0.46% | 4 | 0 | 2026-09-08T03:31:21 | A vulnerability has been found in D-Link DIR-822A A_101. Affected is the functio | |
| CVE-2026-86509 | 9.6 | 0.43% | 4 | 0 | 2026-09-08T03:31:21 | A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function se | |
| CVE-2026-76967 | 7.8 | 0.22% | 2 | 0 | 2026-09-08T03:31:21 | SAP NetWeaver Business Client does not perform sufficient validation when proces | |
| CVE-2026-58240 | 9.8 | 0.34% | 4 | 0 | 2026-09-08T03:31:11 | SAP NetWeaver Message Server does not sufficiently validate the authenticity of | |
| CVE-2026-86538 | 7.5 | 0.74% | 2 | 0 | 2026-09-08T00:30:32 | knowns versions before 0.30.0 contain a path traversal vulnerability in the POST | |
| CVE-2026-86544 | 8.1 | 0.31% | 2 | 0 | 2026-09-08T00:30:32 | knowns versions before 0.30.0 contain an authorization bypass vulnerability wher | |
| CVE-2026-86543 | 9.8 | 0.44% | 4 | 0 | 2026-09-08T00:30:32 | knowns versions before 0.30.0 serve the management API without authentication on | |
| CVE-2026-86504 | 7.8 | 0.13% | 3 | 0 | 2026-09-07T18:31:43 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation be | |
| CVE-2026-86494 | 7.7 | 0.17% | 2 | 0 | 2026-09-07T18:31:42 | In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthori | |
| CVE-2026-86502 | 8.4 | 0.14% | 2 | 0 | 2026-09-07T18:31:42 | In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the | |
| CVE-2026-86498 | 7.7 | 0.17% | 2 | 0 | 2026-09-07T18:31:42 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link s | |
| CVE-2026-86482 | 8.8 | 0.23% | 2 | 0 | 2026-09-07T18:31:36 | In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes all | |
| CVE-2026-86480 | 9.8 | 0.29% | 4 | 0 | 2026-09-07T18:31:36 | In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register | |
| CVE-2026-86478 | 9.8 | 0.36% | 2 | 0 | 2026-09-07T18:31:36 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authenticatio | |
| CVE-2026-86479 | 8.1 | 0.20% | 2 | 0 | 2026-09-07T18:31:36 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing | |
| CVE-2026-86429 | 7.5 | 0.29% | 1 | 0 | 2026-09-07T15:34:01 | The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and | |
| CVE-2026-86428 | 7.5 | 0.28% | 1 | 0 | 2026-09-07T15:34:01 | commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnera | |
| CVE-2026-76578 | 9.8 | 0.45% | 3 | 0 | 2026-09-07T15:33:55 | A flaw was found in FreeIPA. The self-managed OTP token ACI does not require aut | |
| CVE-2026-6223 | 9.4 | 0.44% | 1 | 0 | 2026-09-07T15:33:55 | Improper restriction of excessive authentication attempts vulnerability in Bahçe | |
| CVE-2026-79697 | 9.9 | 3.35% | 1 | 0 | 2026-09-07T09:31:46 | A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-661 | |
| CVE-2026-79698 | 9.9 | 1.70% | 2 | 0 | 2026-09-07T09:31:46 | A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-661 | |
| CVE-2026-14296 | 7.5 | 0.11% | 2 | 0 | 2026-09-07T09:31:39 | When using the Direct XIP update strategy, the main application image starts oth | |
| CVE-2026-19633 | 8.8 | 0.36% | 1 | 0 | 2026-09-06T18:34:45 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked u | |
| CVE-2026-18480 | 8.8 | 0.23% | 1 | 0 | 2026-09-06T12:31:27 | The SureCart WordPress plugin before 4.6.3 does not ensure that the account aff | |
| CVE-2026-78362 | 9.8 | 0.34% | 1 | 0 | 2026-09-06T12:31:26 | The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly vali | |
| CVE-2026-77826 | 8.8 | 0.27% | 1 | 0 | 2026-09-06T12:31:26 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which app | |
| CVE-2026-84935 | 8.0 | 0.23% | 1 | 0 | 2026-09-06T12:31:26 | The HT Menu WordPress plugin before 1.2.7 does not perform any capability or ob | |
| CVE-2026-84219 | 7.5 | 0.22% | 1 | 0 | 2026-09-06T12:31:26 | The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of th | |
| CVE-2026-86242 | 8.1 | 0.62% | 1 | 0 | 2026-09-06T12:30:30 | Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path | |
| CVE-2026-82304 | 8.6 | 0.32% | 1 | 0 | 2026-09-06T12:30:23 | The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user | |
| CVE-2026-86166 | 8.8 | 0.48% | 1 | 0 | 2026-09-06T06:30:21 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the f | |
| CVE-2026-75816 | 9.8 | 0.50% | 1 | 0 | 2026-09-06T03:30:35 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentic | |
| CVE-2026-16310 | 9.8 | 0.30% | 1 | 0 | 2026-09-06T03:30:30 | The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Refe | |
| CVE-2026-18056 | 7.5 | 0.34% | 1 | 0 | 2026-09-06T03:30:30 | The HivePress Authentication plugin for WordPress is vulnerable to Authenticatio | |
| CVE-2026-86153 | 9.1 | 0.39% | 1 | 0 | 2026-09-06T03:30:30 | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the functi | |
| CVE-2026-85046 | 8.8 | 1.16% | 17 | 6 | 2026-09-06T03:30:24 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at | |
| CVE-2026-86151 | 9.1 | 2.04% | 1 | 0 | 2026-09-06T00:31:04 | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is t | |
| CVE-2026-86148 | 9.1 | 2.46% | 1 | 0 | 2026-09-06T00:31:04 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability | |
| CVE-2026-86149 | 9.1 | 2.04% | 1 | 0 | 2026-09-06T00:31:03 | A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some | |
| CVE-2026-67276 | None | 0.24% | 12 | 3 | 2026-09-05T21:31:20 | RouterOS does not compare the complete RSA public key when matching an SSH authe | |
| CVE-2026-86207 | None | 0.30% | 3 | 0 | 2026-09-05T21:31:20 | An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypa | |
| CVE-2026-67277 | None | 0.43% | 4 | 0 | 2026-09-05T21:31:20 | RouterOS accepts a "related" btest connection before the corresponding primary s | |
| CVE-2026-86189 | 9.8 | 0.41% | 1 | 0 | 2026-09-05T15:30:31 | WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php th | |
| CVE-2026-86190 | 9.1 | 0.27% | 1 | 0 | 2026-09-05T15:30:26 | WWBN AVideo contains a broken access control vulnerability in videoViewsInfo end | |
| CVE-2026-10196 | 9.8 | 0.63% | 1 | 0 | 2026-09-05T12:31:34 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emai | |
| CVE-2025-9049 | 8.8 | 0.25% | 1 | 0 | 2026-09-05T12:31:34 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unaut | |
| CVE-2026-86185 | 8.0 | 0.11% | 1 | 0 | 2026-09-05T12:31:34 | Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wi | |
| CVE-2026-80112 | 7.8 | 0.10% | 1 | 0 | 2026-09-04T21:31:59 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10 | |
| CVE-2026-75160 | 9.1 | 0.43% | 1 | 0 | 2026-09-04T21:31:48 | An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escala | |
| CVE-2026-85654 | 7.8 | 0.14% | 1 | 0 | 2026-09-04T18:31:46 | Improper neutralization of special elements used in a template engine in the CDK | |
| CVE-2026-19298 | 8.8 | 0.47% | 1 | 0 | 2026-09-04T18:31:26 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke | |
| CVE-2026-19283 | 7.7 | 0.31% | 1 | 0 | 2026-09-04T18:31:26 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana | |
| CVE-2026-18658 | 9.8 | 0.43% | 1 | 0 | 2026-09-04T18:31:26 | IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, | |
| CVE-2026-19300 | 7.5 | 0.38% | 1 | 0 | 2026-09-04T18:31:26 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain se | |
| CVE-2026-18905 | 7.7 | 0.31% | 1 | 0 | 2026-09-04T18:31:20 | IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context | |
| CVE-2026-57777 | 7.6 | 0.24% | 1 | 0 | 2026-09-04T17:16:57.160000 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti | |
| CVE-2026-85695 | 9.4 | 0.41% | 1 | 0 | 2026-09-04T15:36:24 | FastChat contains an authentication bypass vulnerability in the /register_worker | |
| CVE-2026-85620 | 8.6 | 0.37% | 1 | 0 | 2026-09-04T15:36:23 | Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where fun | |
| CVE-2026-85222 | 9.1 | 2.11% | 1 | 0 | 2026-09-04T14:17:21.387000 | A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vuln | |
| CVE-2026-85224 | 9.1 | 2.15% | 1 | 0 | 2026-09-04T00:31:11 | A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affec | |
| CVE-2023-54391 | 9.8 | 1.75% | 2 | 2 | template | 2026-09-03T15:33:10 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypa |
| CVE-2026-79756 | 0 | 5.15% | 1 | 0 | 2026-09-03T15:17:33.993000 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Pri | |
| CVE-2026-20355 | 5.9 | 0.15% | 2 | 0 | 2026-09-02T18:32:32 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/ | |
| CVE-2026-20354 | 5.9 | 0.15% | 2 | 0 | 2026-09-02T18:32:31 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/ | |
| CVE-2026-20212 | 9.8 | 0.53% | 1 | 1 | 2026-09-02T18:32:26 | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switc | |
| CVE-2026-62911 | 8.0 | 1.32% | 2 | 1 | 2026-09-01T15:30:53 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an a | |
| CVE-2026-59680 | 8.0 | 2.34% | 1 | 0 | 2026-09-01T12:31:48 | An OS command injection vulnerability was found in yast2-users. When displaying | |
| CVE-2026-82692 | 9.9 | 2.36% | 1 | 0 | 2026-08-31T20:56:08.800000 | A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This af | |
| CVE-2026-82702 | 6.6 | 2.05% | 1 | 0 | 2026-08-31T15:34:50 | A vulnerability was identified in Edimax BR-6214K 1.40. This affects the functio | |
| CVE-2026-82689 | 9.9 | 2.36% | 1 | 0 | 2026-08-31T12:30:37 | A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 | |
| CVE-2026-82690 | 9.1 | 2.11% | 1 | 0 | 2026-08-31T12:30:37 | A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected b | |
| CVE-2026-82691 | 9.1 | 2.11% | 1 | 0 | 2026-08-31T12:30:36 | A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-34 | |
| CVE-2026-82688 | 9.1 | 2.79% | 1 | 0 | 2026-08-31T12:30:32 | A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B0 | |
| CVE-2026-18963 | 9.1 | 3.18% | 2 | 14 | 2026-08-28T22:53:42 | A flaw was found in the reset-credentials flow of the keycloak-services componen | |
| CVE-2026-53362 | 7.8 | 0.51% | 1 | 1 | 2026-08-27T21:31:19 | In the Linux kernel, the following vulnerability has been resolved: ipv6: accou | |
| CVE-2026-19490 | None | 3.37% | 2 | 1 | 2026-08-20T15:34:03 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f | |
| CVE-2026-32475 | 9.0 | 2.37% | 1 | 6 | template | 2026-08-20T12:48:31.843000 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Eleme |
| CVE-2026-69414 | 7.8 | 0.56% | 2 | 2 | 2026-08-19T18:32:28 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect | |
| CVE-2026-6471 | 7.2 | 0.29% | 1 | 2 | 2026-08-13T15:34:37 | Missing authorization in PostgreSQL logical decoding allows a non-superuser hold | |
| CVE-2026-62735 | 7.8 | 0.48% | 2 | 2 | 2026-08-11T18:31:23 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to | |
| CVE-2026-13230 | 6.5 | 0.38% | 3 | 0 | 2026-08-06T18:31:32 | An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 a | |
| CVE-2026-8461 | 8.8 | 1.57% | 2 | 4 | 2026-07-23T12:32:53 | An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specificall | |
| CVE-2026-61699 | 8.1 | 0.25% | 1 | 0 | 2026-07-14T20:28:19 | ### Summary nebula-mesh revokes a host by adding its certificate fingerprint to | |
| CVE-2026-43284 | 7.8 | 93.23% | 1 | 46 | 2026-07-14T15:31:59 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: | |
| CVE-2026-14894 | 9.8 | 5.27% | 1 | 3 | template | 2026-07-10T06:31:28 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to |
| CVE-2026-52770 | 7.5 | 0.28% | 1 | 0 | 2026-07-09T21:00:06 | ### Summary YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthen | |
| CVE-2026-52769 | 8.3 | 0.30% | 1 | 0 | 2026-07-09T20:58:34 | ## Summary The `POST /api/forms/{formId}/actor/inbox` route - exposed publicly w | |
| CVE-2025-2524 | 4.8 | 0.30% | 2 | 0 | 2026-06-17T09:07:06.787000 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape som | |
| CVE-2025-25249 | 8.1 | 0.76% | 2 | 0 | 2026-06-09T12:33:04 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6 | |
| CVE-2026-43502 | 7.8 | 0.12% | 4 | 1 | 2026-06-01T18:31:32 | In the Linux kernel, the following vulnerability has been resolved: net/rds: ha | |
| CVE-2025-53521 | 7.5 | 2.21% | 1 | 0 | 2026-03-31T18:31:25 | When a BIG-IP APM Access Policy is configured on a virtual server, undisclosed t | |
| CVE-2023-41974 | 7.8 | 1.41% | 1 | 0 | 2026-03-12T03:31:06 | A use-after-free issue was addressed with improved memory management. This issue | |
| CVE-2026-22769 | 10.0 | 13.12% | 1 | 0 | 2026-02-18T18:30:35 | Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a | |
| CVE-2021-35464 | 9.8 | 100.00% | 2 | 2 | 2025-10-22T00:32:19 | ForgeRock AM server 6.x before 7, and OpenAM 14.6.3, has a Java deserialization | |
| CVE-2025-30208 | 5.3 | 74.97% | 1 | 23 | 2025-03-25T14:00:04 | ### Summary The contents of arbitrary files can be returned to the browser. ### | |
| CVE-2024-11015 | 9.8 | 0.78% | 2 | 0 | 2024-12-12T06:30:56 | The Sign In With Google plugin for WordPress is vulnerable to authentication byp | |
| CVE-2026-85982 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-67401 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-85083 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-41870 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-53939 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-53581 | 0 | 0.00% | 4 | 0 | N/A | ||
| CVE-2026-69304 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-69522 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-61686 | 0 | 0.42% | 1 | 0 | N/A | ||
| CVE-2026-84390 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-8504 | 0 | 0.00% | 2 | 6 | N/A | ||
| CVE-2026-85781 | 0 | 0.26% | 1 | 0 | N/A | ||
| CVE-2026-75021 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-63464 | 0 | 0.27% | 1 | 0 | N/A | ||
| CVE-2022-1096 | 0 | 24.39% | 2 | 1 | N/A | ||
| CVE-2026-80172 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-77477 | 0 | 0.00% | 1 | 0 | N/A |
updated 2026-09-09T04:20:23.543000
2 posts
I explicitly don't want to complain about MSRC here, this is a bigger topic, but I am a bit confused here:
Compare these two:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81954 - AV:L,UI:R
Q: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A: An attacker must send a user a malicious Office file and convince them to open it.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80081 - AV:N,UI:R
Q: How could an attacker exploit this vulnerability?
A: An attacker could send a specially crafted PowerPoint presentation containing malicious linked media to a target user. The user would need to open the presentation, start the slideshow, and allow the linked content. Successful exploitation could allow the attacker to execute code on the user's system. Authentication is not required.
To me the attack flow looks equivalent wrt to attacker location. We can argue about #2 being actually harder to execute, having more social engineering prerequisites... which is why it totally makes sense for #2 to scored higher on CVSS as it's apparently network & the other one local.
##I explicitly don't want to complain about MSRC here, this is a bigger topic, but I am a bit confused here:
Compare these two:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81954 - AV:L,UI:R
Q: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A: An attacker must send a user a malicious Office file and convince them to open it.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80081 - AV:N,UI:R
Q: How could an attacker exploit this vulnerability?
A: An attacker could send a specially crafted PowerPoint presentation containing malicious linked media to a target user. The user would need to open the presentation, start the slideshow, and allow the linked content. Successful exploitation could allow the attacker to execute code on the user's system. Authentication is not required.
To me the attack flow looks equivalent wrt to attacker location. We can argue about #2 being actually harder to execute, having more social engineering prerequisites... which is why it totally makes sense for #2 to scored higher on CVSS as it's apparently network & the other one local.
##updated 2026-09-09T04:19:30.720000
3 posts
Microsoft Plugs Nearly 1000 Security Holes
Microsoft가 Windows 및 기타 소프트웨어의 취약점 최소 974건을 수정하는 역대 최대 규모의 월간 패치 묶음을 배포했다. 실제 악용 중인 Windows 권한 상승 제로데이 CVE-2026-81963·CVE-2026-85880이 포함됐으며, Windows Server 2012 이상과 Windows 10에 영향을 주는 DNS 취약점 CVE-2026-69730은 인증 없이 조작된 패킷으로 공격될 수 있고 악용 가능성이 높다고 경고됐다. Windows Shell 원격 코드 실행 취약점 CVE-2026-69829는 CVSS 9.8로, 낮은 공격 복잡도·무권한...
https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/
##Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.
Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.
Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.
#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)
##Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.
Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.
Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.
#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)
##updated 2026-09-09T04:18:40.510000
1 posts
CVE-2026-69439 - an EoP in the MSDIA component.
MSDIA is used in debugging, and for enrichment of call stacks for exceptions.
A crafted pdb file could cause an OOB write. Applicable mostly to developers. It needs the presence of a PDB alongside apps, which you shouldn't be doing in prod.
Microsoft Security Advisory CV...
updated 2026-09-09T04:17:56.480000
2 posts
CVE-2026-12855: HIGH-severity vuln in InsydeH2O firmware (HP). Local attackers with high privileges may execute arbitrary code due to improper input validation. No patch yet — restrict local admin access. https://radar.offseq.com/threat/cve-2026-12855-cwe-20-improper-input-validation-in-insyde-software-insydeh2o-96c11fc7beb122a7 #OffSeq #Vulnerability #Firmware #Infosec
##CVE-2026-12855: HIGH-severity vuln in InsydeH2O firmware (HP). Local attackers with high privileges may execute arbitrary code due to improper input validation. No patch yet — restrict local admin access. https://radar.offseq.com/threat/cve-2026-12855-cwe-20-improper-input-validation-in-insyde-software-insydeh2o-96c11fc7beb122a7 #OffSeq #Vulnerability #Firmware #Infosec
##updated 2026-09-09T03:30:52
2 posts
CVE-2026-87628: CRITICAL use-after-free in Chrome's Cast (<153.0.8010.36) enables adjacent code execution outside the sandbox. Patch status unconfirmed. Check the vendor advisory: https://radar.offseq.com/threat/cve-2026-87628-use-after-free-in-google-chrome-1e9eb757633453cf #OffSeq #Chrome #Vuln #CVE202687628
##CVE-2026-87628: CRITICAL use-after-free in Chrome's Cast (<153.0.8010.36) enables adjacent code execution outside the sandbox. Patch status unconfirmed. Check the vendor advisory: https://radar.offseq.com/threat/cve-2026-87628-use-after-free-in-google-chrome-1e9eb757633453cf #OffSeq #Chrome #Vuln #CVE202687628
##updated 2026-09-09T03:30:51
2 posts
CVE-2026-15667: HIGH-severity LFI in Eventin WordPress plugin (≤4.1.22). Contributors can include arbitrary PHP via 'event_layout', risking code execution. Restrict privileges & await patch. https://radar.offseq.com/threat/cve-2026-15667-cwe-98-improper-control-of-filename-for-includerequire-statement-in-php-program-php-b89bc3860052e068 #OffSeq #WordPress #Vuln #LFI
##CVE-2026-15667: HIGH-severity LFI in Eventin WordPress plugin (≤4.1.22). Contributors can include arbitrary PHP via 'event_layout', risking code execution. Restrict privileges & await patch. https://radar.offseq.com/threat/cve-2026-15667-cwe-98-improper-control-of-filename-for-includerequire-statement-in-php-program-php-b89bc3860052e068 #OffSeq #WordPress #Vuln #LFI
##updated 2026-09-09T03:30:46
2 posts
Google patched a Chrome zero-day, CVE-2026-87491, exploited in the wild. Chrome 153 fixes 230 flaws including critical WebGL bugs. Update now.
#Chrome #ZeroDay #Google #CyberSecurity #CVE #V8 #BrowserSecurity #Infosec
##Google patched a Chrome zero-day, CVE-2026-87491, exploited in the wild. Chrome 153 fixes 230 flaws including critical WebGL bugs. Update now.
#Chrome #ZeroDay #Google #CyberSecurity #CVE #V8 #BrowserSecurity #Infosec
##updated 2026-09-09T03:30:37
2 posts
1 repos
🟠 CVE-2026-73315 - High (8.6)
XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73315/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73315 - High (8.6)
XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73315/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-09T03:30:36
2 posts
1 repos
🟠 CVE-2026-73316 - High (7.5)
XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73316/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73316 - High (7.5)
XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73316/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-09T01:16:57.930000
2 posts
1 repos
🟠 CVE-2026-73314 - High (7.5)
XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo heade...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73314/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73314 - High (7.5)
XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo heade...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73314/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-09T00:30:29
4 posts
Red Hat 389-ds-base faces CRITICAL flaws (CVE-2026-18355 & more): heap buffer overflow, pre-auth NULL dereference, privilege escalation, and ACI bypass in RHEL 9.2 (<9.2.4). Patch ASAP. https://radar.offseq.com/threat/red-hat-security-advisory-389-ds-base-security-bug-fix-and-enhancement-update-0c583247a0fb050c #OffSeq #RedHat #CVE #LDAP
##CRITICAL vulnerabilities in Red Hat 389-ds-base (>=9.4 <9.4.5) incl. heap overflow (CVE-2026-18355), privilege escalation, and ACI bypass. Patch ASAP via RHSA-2026:64781. Details: https://radar.offseq.com/threat/red-hat-security-advisory-389-ds-base-security-bug-fix-and-enhancement-update-c933f76430be2c96 #OffSeq #RedHat #LDAP #Vuln #SysAdmin
##Red Hat 389-ds-base faces CRITICAL flaws (CVE-2026-18355 & more): heap buffer overflow, pre-auth NULL dereference, privilege escalation, and ACI bypass in RHEL 9.2 (<9.2.4). Patch ASAP. https://radar.offseq.com/threat/red-hat-security-advisory-389-ds-base-security-bug-fix-and-enhancement-update-0c583247a0fb050c #OffSeq #RedHat #CVE #LDAP
##CRITICAL vulnerabilities in Red Hat 389-ds-base (>=9.4 <9.4.5) incl. heap overflow (CVE-2026-18355), privilege escalation, and ACI bypass. Patch ASAP via RHSA-2026:64781. Details: https://radar.offseq.com/threat/red-hat-security-advisory-389-ds-base-security-bug-fix-and-enhancement-update-c933f76430be2c96 #OffSeq #RedHat #LDAP #Vuln #SysAdmin
##updated 2026-09-09T00:17:31.557000
2 posts
🟠 CVE-2026-53938 - High (8.2)
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not val...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53938/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-53938 - High (8.2)
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not val...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53938/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T22:04:05.090000
1 posts
🟠 CVE-2026-19306 - High (7.7)
IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19306/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T21:34:41
2 posts
🟠 CVE-2026-85983 - High (7.8)
The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85983 - High (7.8)
The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T21:34:37
4 posts
WTF
https://github.com/ConnectWise-Advisories/Disclosures/blob/main/CVE-2026-84869/README.md
##Earlier versions of ScreenConnect Client Support and Access sessions contained a client-side file-transfer handling condition in which file-transfer actions could be processed through an active remote session without proper authorization or Host confirmation. Under certain circumstances, this could allow files to be transferred to and executed on the Host client system, including through elevated execution actions. ScreenConnect servers are not impacted. Disabling file-transfer permissions for affected sessions may reduce exposure until the update is applied.
🔴 CVE-2026-84869 - Critical (9.9)
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84869/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##WTF
https://github.com/ConnectWise-Advisories/Disclosures/blob/main/CVE-2026-84869/README.md
##Earlier versions of ScreenConnect Client Support and Access sessions contained a client-side file-transfer handling condition in which file-transfer actions could be processed through an active remote session without proper authorization or Host confirmation. Under certain circumstances, this could allow files to be transferred to and executed on the Host client system, including through elevated execution actions. ScreenConnect servers are not impacted. Disabling file-transfer permissions for affected sessions may reduce exposure until the update is applied.
🔴 CVE-2026-84869 - Critical (9.9)
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84869/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T21:34:36
2 posts
🟠 CVE-2026-82007 - High (7.8)
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82007/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82007 - High (7.8)
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82007/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T21:18:46.223000
2 posts
🟠 CVE-2026-81994 - High (8.2)
Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitiv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81994/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81994 - High (8.2)
Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitiv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81994/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T21:05:26.920000
1 posts
CVE-2026-52775: SQL injection in YesWiki < 4.6.6 allows any authenticated user to inject arbitrary SQL via ReactionManager::deleteUserReaction(). CVSS 8.8. No patch confirmed—upgrade to 4.6.6 immediately. Details: https://www.valtersit.com/cve/CVE-2026-52775/ #CVE #infosec #YesWi
##updated 2026-09-08T21:05:26.920000
1 posts
CVE-2026-52767: YesWiki (4.6.2-4.6.5) improper openssl_verify check via loose boolean negation allows auth bypass (CVSS 8.2). Attackers can forge signatures and trigger processActivity(). Unpatched—upgrade to 4.6.6 or disable affected endpoints now. https://www.valtersit.com/cve/
##updated 2026-09-08T21:05:26.920000
1 posts
CVE-2026-52771: YesWiki SQL injection via attacker-controlled page tags in ApiController::deletePage(). CVSS 8.3. Low-privilege users can exploit arbitrary tags to inject SQL. Unpatched—no fix available. Update or disable API if exposed. https://www.valtersit.com/cve/CVE-2026-527
##updated 2026-09-08T20:57:52
2 posts
Details and PoC for CVE-2026-84372 are publicly disclosed. This Predis command injection flaw via CRLF smuggling allows complete cluster compromise.
#Predis #CommandInjection #CVE202684372 #Cybersecurity #Vulnerability
##Details and PoC for CVE-2026-84372 are publicly disclosed. This Predis command injection flaw via CRLF smuggling allows complete cluster compromise.
#Predis #CommandInjection #CVE202684372 #Cybersecurity #Vulnerability
##updated 2026-09-08T20:50:48
2 posts
A critical MapLibre XSS vulnerability allows zero-click code execution in 2.7M weekly downloads. Discover how CVE-2026-85061 works and how to patch now.
#MapLibre #XSS #CVE202685061 #WebSecurity #InfoSec #CyberSecurity #OpenSource
##A critical MapLibre XSS vulnerability allows zero-click code execution in 2.7M weekly downloads. Discover how CVE-2026-85061 works and how to patch now.
#MapLibre #XSS #CVE202685061 #WebSecurity #InfoSec #CyberSecurity #OpenSource
##updated 2026-09-08T20:18:51.307000
2 posts
🟠 CVE-2026-84942 - High (8.7)
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84942/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84942 - High (8.7)
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84942/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T20:10:30.270000
1 posts
CVE-2026-80116 - Privilege Escalation in PassMark (PerformanceTest, BurnInTest, OSForensics). CVSS 7.8. Exposed IOCTLs in DirectIo64.sys allow arbitrary PCI config writes, enabling DMA attacks or storage disruption. Unpatched. Update immediately if affected. https://www.valtersit
##updated 2026-09-08T20:10:30.270000
1 posts
CVE-2026-80113 - Privilege escalation in Directio64.Sys (PassMark tools). CVSS 7.1. Local attackers can clear bits in physical memory via IOCTL, risking kernel integrity. Unpatched—take action. Details: https://www.valtersit.com/cve/CVE-2026-80113/ #CVE #infosec #cybersecurity
##updated 2026-09-08T20:10:30.270000
1 posts
CVE-2026-80118: Unpatched flaw in PassMark PerformanceTest, BurnInTest & OSForensics (DirectIo64.sys) lets local users dump all physical memory via IOCTL—exposing passwords, keys, and data. CVSS 7.1. No patch yet. Stop using these tools or restrict access NOW. Details: https://ww
##updated 2026-09-08T20:06:38.260000
1 posts
🔴 CVE-2026-86184 - Critical (9.8)
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /scr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86184/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T20:00:18.870000
1 posts
🟠 CVE-2026-86250 - High (7.5)
h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk count to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86250/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T19:57:49.663000
1 posts
🟠 CVE-2026-86435 - High (7.5)
commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to cre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86435/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T19:56:50.950000
2 posts
🟠 CVE-2026-86541 - High (8.3)
knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86541/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86541 - High (8.3)
knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86541/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T19:56:50.950000
2 posts
🟠 CVE-2026-86540 - High (7.8)
knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a craf...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86540/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86540 - High (7.8)
knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a craf...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86540/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T19:56:50.950000
2 posts
🟠 CVE-2026-86439 - High (8.8)
knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86439/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86439 - High (8.8)
knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86439/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T19:56:50.950000
2 posts
🔴 CVE-2026-86542 - Critical (9.1)
knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86542/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-86542 - Critical (9.1)
knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86542/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T19:53:13.400000
2 posts
🟠 CVE-2026-86727 - High (7.5)
AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86727/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86727 - High (7.5)
AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86727/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T19:42:20.313000
1 posts
CVE-2026-31020: SSTI to RCE in DocsGPT ≤0.15.0 via unsanitized Jinja prompts. CVSS 9.8, unpatched. No auth needed. Patch? None yet—disable custom prompts or isolate instance now. Details: https://www.valtersit.com/cve/CVE-2026-31020/ #CVE #infosec #cybersecurity
##updated 2026-09-08T19:29:17.803000
21 posts
3 repos
https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos
https://github.com/dinosn/cve-2026-75650-magento-validation-lab
🔴 New security advisory:
CVE-2026-75650 affects Adobe Commerce.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-75650-adobe-commerce-template-rce-exploited-poc
by Yazoul AI
##Adobe releases September 2026 patches for multiple products
Adobe's September 2026 security updates patch vulnerabilities across eight product families: Commerce/Magento, ColdFusion, Campaign Classic, Acrobat/Reader, Experience Manager, Photoshop, Illustrator, and Animate. The flaws could allow arbitrary code execution, privilege escalation, security feature bypass, file system read/write, memory exposure, and denial-of-service. The most urgent is CVE-2026-75650 (CVSS 10.0) in Adobe Commerce and Magento Open Source, an unauthenticated template-engine flaw already exploited in the wild and fixed by a separate out-of-band hotfix on September 7 that must be applied in addition to the September update.
**If you run Adobe Commerce or Magento Open Source, apply the out-of-band hotfix for CVE-2026-75650 immediately! Adobe is aware of this flaw being exploited in the wild, it carries a CVSS score of 10.0, and it can be triggered without authentication. Next, update ColdFusion and Adobe Campaign Classic, both of which received Adobe's highest priority rating and contain critical flaws that could lead to arbitrary code execution. Then apply the September Adobe Commerce security update, which is separate from the hotfix and must be installed in addition to it. After that, update Adobe Experience Manager and Acrobat and Reader. Finally, update Photoshop, Illustrator, and Animate. If you can't update right away, restrict network access to Commerce, ColdFusion, Campaign Classic, and Experience Manager servers, and avoid opening untrusted PDFs and untrusted image or project files in Acrobat, Reader, Photoshop, Illustrator, and Animate until patches are applied.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/adobe-releases-september-2026-patches-for-multiple-products-9-j-d-0-x/gD2P6Ple2L
CVE ID: CVE-2026-75650
Vendor: Adobe
Product: Commerce and Magento
Date Added: 2026-09-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75650
Update: Adobe released an update for CVE-2026-75650 yesterday https://helpx.adobe.com/security/products/magento/apsb26-146.html.
CSO: Adobe Commerce max-severity bug comes under active attack https://www.csoonline.com/article/4219626/adobe-commerce-max-severity-bug-comes-under-active-attack.html #Adobe #infosec #vulnerability
##Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that...
🔗️ [Bleepingcomputer] https://link.is.it/kbCfVz
##The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html
##Adobe Patches Zero-Day Flaw Exploited to Deploy Rust Backdoor
Adobe just patched a critical zero-day flaw, CVE-2026-75650, that's been exploited to deploy a Rust backdoor, known as StyleSmuggler, targeting Adobe Commerce merchants - and it's crucial you update ASAP to avoid arbitrary code execution. This severe vulnerability has a CVSS score of 10.0, so don't wait to secure your site.
#ZeroDay #Adobe #Cve202675650 #ArbitraryCodeExecution #Stylesmuggler
##🏆 New Achievement! StyleSmuggler Has Entered the Tutorial Zone!
Welcome, new merchant! This is the part of the game where we introduce a mandatory debuff called CVE-2026-75650. Adobe Commerce and Magento 2 contain a CVSS 10.0 critical flaw in the template engine — an Improper Neutralization of Special Elements — that lets attackers execute arbitrary code with no user interaction required. This isn't a side quest. (1/2)
##An Adobe Commerce vulnerability, CVE-2026-75650 (CVSS 10), enables unauthenticated arbitrary code execution and is exploited in the wild. Patch now.
#AdobeCommerce #Magento #StyleSmuggler #CVE202675650 #RCE #Ecommerce #ExploitedInTheWild #Infosec
##Magento 2 Zero-Day RCE Crisis: Active Attacks Put Online Stores and Customer Data at Risk + Video
A New Threat Is Hitting E-Commerce at the Core A dangerous zero-day vulnerability in Magento and Adobe Commerce has moved from security research into active exploitation, creating an immediate threat for online retailers running the popular e-commerce platforms. The vulnerability, tracked by Adobe as CVE-2026-75650 and publicly associated with the StyleSmuggler attack…
##🔴 CVE-2026-75650 - Critical (10)
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75650/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Adobe Commerce faces a CRITICAL (CVSS 10) template engine flaw (CVE-2026-75650) allowing arbitrary code execution with no user interaction required. Update and monitor for patches. https://radar.offseq.com/threat/cve-2026-75650-improper-neutralization-of-special-elements-used-in-a-template-engine-cwe-1336-in-adobe-1ba4ab0d2a763031 #OffSeq #AdobeCommerce #CVE202675650 #infosec
##Adobe releases September 2026 patches for multiple products
Adobe's September 2026 security updates patch vulnerabilities across eight product families: Commerce/Magento, ColdFusion, Campaign Classic, Acrobat/Reader, Experience Manager, Photoshop, Illustrator, and Animate. The flaws could allow arbitrary code execution, privilege escalation, security feature bypass, file system read/write, memory exposure, and denial-of-service. The most urgent is CVE-2026-75650 (CVSS 10.0) in Adobe Commerce and Magento Open Source, an unauthenticated template-engine flaw already exploited in the wild and fixed by a separate out-of-band hotfix on September 7 that must be applied in addition to the September update.
**If you run Adobe Commerce or Magento Open Source, apply the out-of-band hotfix for CVE-2026-75650 immediately! Adobe is aware of this flaw being exploited in the wild, it carries a CVSS score of 10.0, and it can be triggered without authentication. Next, update ColdFusion and Adobe Campaign Classic, both of which received Adobe's highest priority rating and contain critical flaws that could lead to arbitrary code execution. Then apply the September Adobe Commerce security update, which is separate from the hotfix and must be installed in addition to it. After that, update Adobe Experience Manager and Acrobat and Reader. Finally, update Photoshop, Illustrator, and Animate. If you can't update right away, restrict network access to Commerce, ColdFusion, Campaign Classic, and Experience Manager servers, and avoid opening untrusted PDFs and untrusted image or project files in Acrobat, Reader, Photoshop, Illustrator, and Animate until patches are applied.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/adobe-releases-september-2026-patches-for-multiple-products-9-j-d-0-x/gD2P6Ple2L
CVE ID: CVE-2026-75650
Vendor: Adobe
Product: Commerce and Magento
Date Added: 2026-09-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75650
Update: Adobe released an update for CVE-2026-75650 yesterday https://helpx.adobe.com/security/products/magento/apsb26-146.html.
CSO: Adobe Commerce max-severity bug comes under active attack https://www.csoonline.com/article/4219626/adobe-commerce-max-severity-bug-comes-under-active-attack.html #Adobe #infosec #vulnerability
##Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that...
🔗️ [Bleepingcomputer] https://link.is.it/kbCfVz
##The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html
##🏆 New Achievement! StyleSmuggler Has Entered the Tutorial Zone!
Welcome, new merchant! This is the part of the game where we introduce a mandatory debuff called CVE-2026-75650. Adobe Commerce and Magento 2 contain a CVSS 10.0 critical flaw in the template engine — an Improper Neutralization of Special Elements — that lets attackers execute arbitrary code with no user interaction required. This isn't a side quest. (1/2)
##An Adobe Commerce vulnerability, CVE-2026-75650 (CVSS 10), enables unauthenticated arbitrary code execution and is exploited in the wild. Patch now.
#AdobeCommerce #Magento #StyleSmuggler #CVE202675650 #RCE #Ecommerce #ExploitedInTheWild #Infosec
##🔴 CVE-2026-75650 - Critical (10)
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75650/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Adobe Commerce faces a CRITICAL (CVSS 10) template engine flaw (CVE-2026-75650) allowing arbitrary code execution with no user interaction required. Update and monitor for patches. https://radar.offseq.com/threat/cve-2026-75650-improper-neutralization-of-special-elements-used-in-a-template-engine-cwe-1336-in-adobe-1ba4ab0d2a763031 #OffSeq #AdobeCommerce #CVE202675650 #infosec
##updated 2026-09-08T19:29:09.680000
2 posts
A new ONLYOFFICE ownCloud plugin SSRF vulnerability, tracked as CVE-2026-84282, allows attackers to trigger unauthorized internal network requests.
#ONLYOFFICE #ownCloud #SSRF #Cybersecurity #CVE202684282 #Vulnerability
##A new ONLYOFFICE ownCloud plugin SSRF vulnerability, tracked as CVE-2026-84282, allows attackers to trigger unauthorized internal network requests.
#ONLYOFFICE #ownCloud #SSRF #Cybersecurity #CVE202684282 #Vulnerability
##updated 2026-09-08T19:28:43.390000
16 posts
1 repos
CVE ID: CVE-2026-86218
Vendor: N-able
Product: N-central
Date Added: 2026-09-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86218
📰 N-able N-central Hit by Actively Exploited CVSS 10.0 RCE Flaw
🚨 URGENT: N-able N-central is being actively exploited via a CVSS 10.0 RCE zero-day (CVE-2026-86218). Unauthenticated attackers can take over RMM servers. On-prem customers must apply Hotfix 4 immediately. #CyberSecurity #RMM #MSP
##N-able Issues Emergency Hotfix for Maximum-Severity Unauthenticated RCE in N-central
N-able released a critical hotfix for N-central to fix a CVSS 10.0 unauthenticated remote code execution vulnerability (CVE-2026-86218) that may be under active exploitation. The update is the fourth in five weeks and affects all on-premises builds prior to 2026.3.1.14.
**If you run N-central on-premises, upgrade to build 2026.3.1.14 (Hotfix 4) ASAP. Earlier builds, including Hotfix 3 released just hours before, are still vulnerable to unauthenticated remote code execution. Until the hotfix is applied, take any internet-facing console offline or restrict it to a VPN/IP allowlist. Assume that a compromised server means every managed endpoint behind it needs checking too.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/n-able-issues-emergency-hotfix-for-maximum-severity-unauthenticated-rce-in-n-central-i-n-a-0-t/gD2P6Ple2L
⚠️ CRITICAL: N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
N-able N-central RMM platform contains a critical unauthenticated RCE vulnerability (CVE-2026-86218, CVSS 10.0) affecting all builds before 2026.3.1.14. While N-able denies confirmed exploitation, incident reports indicate active wild exploitation. Any organization running N-central is at immediate…
🤖 AI generated summary
##⚠️ CRITICAL: N-able patches max severity N-central flaw amid ongoing attacks
N-able has released emergency patches for three vulnerabilities in N-central RMM, including a critical unauthenticated RCE (CVE-2026-86218) and two high-severity authentication bypasses. Evidence indicates active exploitation in customer environments. Any organization running N-central is at immedi…
🤖 AI generated summary
##📰 N-able N-central Hit by Actively Exploited CVSS 10.0 RCE Flaw
🚨 URGENT: N-able N-central is being actively exploited via a CVSS 10.0 RCE zero-day (CVE-2026-86218). Unauthenticated attackers can take over RMM servers. On-prem customers must apply Hotfix 4 immediately. #CyberSecurity #RMM #MSP
##CVE ID: CVE-2026-86218
Vendor: N-able
Product: N-central
Date Added: 2026-09-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86218
N-able Issues Emergency Hotfix for Maximum-Severity Unauthenticated RCE in N-central
N-able released a critical hotfix for N-central to fix a CVSS 10.0 unauthenticated remote code execution vulnerability (CVE-2026-86218) that may be under active exploitation. The update is the fourth in five weeks and affects all on-premises builds prior to 2026.3.1.14.
**If you run N-central on-premises, upgrade to build 2026.3.1.14 (Hotfix 4) ASAP. Earlier builds, including Hotfix 3 released just hours before, are still vulnerable to unauthenticated remote code execution. Until the hotfix is applied, take any internet-facing console offline or restrict it to a VPN/IP allowlist. Assume that a compromised server means every managed endpoint behind it needs checking too.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/n-able-issues-emergency-hotfix-for-maximum-severity-unauthenticated-rce-in-n-central-i-n-a-0-t/gD2P6Ple2L
⚠️ CRITICAL: N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
N-able N-central RMM platform contains a critical unauthenticated RCE vulnerability (CVE-2026-86218, CVSS 10.0) affecting all builds before 2026.3.1.14. While N-able denies confirmed exploitation, incident reports indicate active wild exploitation. Any organization running N-central is at immediate…
🤖 AI generated summary
##⚠️ CRITICAL: N-able patches max severity N-central flaw amid ongoing attacks
N-able has released emergency patches for three vulnerabilities in N-central RMM, including a critical unauthenticated RCE (CVE-2026-86218) and two high-severity authentication bypasses. Evidence indicates active exploitation in customer environments. Any organization running N-central is at immedi…
🤖 AI generated summary
##Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.
Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)
##🏆 New Achievement! Unauthenticated and Undefeated!
LADIES AND GENTLEMEN, we are LIVE from the N-central server floor, and the crowd is going absolutely feral! Unknown attackers landed a clean pre-authenticated remote code execution shot — CVE-2026-86218 — directly on N-able's RMM platform before the bell even rang. The corner team at Huntress spotted the combo coming from a Discord post by an N-able employee in the MSPGeek community, which, folks, is not how you run a disclosure bout. (1/3)
##New.
Tanto Security: From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX https://tantosec.com/blog/2026/09/telerik-padding-oracle-to-shell/
More:
The Hacker News: Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released https://tantosec.com/blog/2026/09/telerik-padding-oracle-to-shell/
Also:
N-able issued another fix yesterday https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html #vulnerability #Oracle #infosec
##Active N-central vulnerability exploitation targets IT servers. Patch the critical N-central vulnerability now to stop pre-auth RCE attacks.
##CVE-2026-86218: N-able N-central on-prem RCE (CRITICAL) enables unauthenticated code execution. Hotfix 4 (2026.3) required ASAP. Nearly 1,500 exposed servers tracked. Patch now: https://radar.offseq.com/threat/n-able-patches-max-severity-n-central-flaw-amid-ongoing-attacks-2b55ee46bb903037 #OffSeq #Nable #RCE #SysAdmin #Infosec
##The N-able N-central vulnerability CVE-2026-86218 is a CVSS 10 pre-auth RCE reported exploited in the wild. Apply 2026.3 HF4 immediately.
#Nable #Ncentral #CVE202686218 #PreAuthRCE #RMM #ZeroDay #Huntress #Infosec
##updated 2026-09-08T19:28:36.983000
13 posts
Why this month's Microsoft patch release is a doozy
Microsoft의 9월 패치 릴리스는 약 972개(Edge의 Chromium 이식 수정 포함 시 997개) 취약점을 수정하며, 이 중 112개가 Critical 등급이다. Windows Update와 Windows ALPC의 제로데이 2건(CVE-2026-81963, CVE-2026-85880)이 포함됐고, Exchange Server의 악성 Visio 첨부파일 기반 비인증 RCE, Remote Desktop Services의 CVSS 9.8 RCE, SharePoint RCE 다수 등 즉시...
##Microsoft Plugs Nearly 1000 Security Holes
Microsoft가 Windows 및 기타 소프트웨어의 취약점 최소 974건을 수정하는 역대 최대 규모의 월간 패치 묶음을 배포했다. 실제 악용 중인 Windows 권한 상승 제로데이 CVE-2026-81963·CVE-2026-85880이 포함됐으며, Windows Server 2012 이상과 Windows 10에 영향을 주는 DNS 취약점 CVE-2026-69730은 인증 없이 조작된 패킷으로 공격될 수 있고 악용 가능성이 높다고 경고됐다. Windows Shell 원격 코드 실행 취약점 CVE-2026-69829는 CVSS 9.8로, 낮은 공격 복잡도·무권한...
https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/
##Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Microsoft의 2026년 9월 Patch Tuesday는 역대 최대 규모인 966건의 취약점을 수정하며, 이 중 105건이 Critical이고 81건은 원격 코드 실행(RCE) 취약점이다. 실제 공격에 악용된 Windows Update Stack 권한 상승(CVE-2026-81963)과 Windows ALPC 힙 버퍼 오버플로우(CVE-2026-85880) 제로데이는 모두 로컬 공격자가 SYSTEM 권한을 얻을 수 있어 우선 패치 대상이다. AI 서...
##Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.
Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.
Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.
#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)
##🏆 New Achievement! Stand In The Fire One More Time, I Dare You!
NINE HUNDRED AND SEVENTY-FOUR vulnerabilities. Microsoft dropped 974 patches this Patch Tuesday and you are STILL standing in the bad stuff. CVE-2026-81963 and CVE-2026-85880, both CVSS 7.8, are being actively exploited RIGHT NOW against the Windows Update Stack and Windows Advanced Local Procedure Call — privilege escalation, in the wild, before disclosure. (1/2)
##CVE ID: CVE-2026-85880
Vendor: Microsoft
Product: Windows
Date Added: 2026-09-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85880
Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild.
#PatchTuesday #ZeroDay #Microsoft #Windows #CyberSecurity #CVE #Infosec #VulnerabilityManagement
##Only two 0days this month for MS? Bummer.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
##Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.
Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.
Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.
#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)
##🏆 New Achievement! Stand In The Fire One More Time, I Dare You!
NINE HUNDRED AND SEVENTY-FOUR vulnerabilities. Microsoft dropped 974 patches this Patch Tuesday and you are STILL standing in the bad stuff. CVE-2026-81963 and CVE-2026-85880, both CVSS 7.8, are being actively exploited RIGHT NOW against the Windows Update Stack and Windows Advanced Local Procedure Call — privilege escalation, in the wild, before disclosure. (1/2)
##CVE ID: CVE-2026-85880
Vendor: Microsoft
Product: Windows
Date Added: 2026-09-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85880
Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild.
#PatchTuesday #ZeroDay #Microsoft #Windows #CyberSecurity #CVE #Infosec #VulnerabilityManagement
##Only two 0days this month for MS? Bummer.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
##updated 2026-09-08T19:28:31.630000
14 posts
Why this month's Microsoft patch release is a doozy
Microsoft의 9월 패치 릴리스는 약 972개(Edge의 Chromium 이식 수정 포함 시 997개) 취약점을 수정하며, 이 중 112개가 Critical 등급이다. Windows Update와 Windows ALPC의 제로데이 2건(CVE-2026-81963, CVE-2026-85880)이 포함됐고, Exchange Server의 악성 Visio 첨부파일 기반 비인증 RCE, Remote Desktop Services의 CVSS 9.8 RCE, SharePoint RCE 다수 등 즉시...
##Microsoft Plugs Nearly 1000 Security Holes
Microsoft가 Windows 및 기타 소프트웨어의 취약점 최소 974건을 수정하는 역대 최대 규모의 월간 패치 묶음을 배포했다. 실제 악용 중인 Windows 권한 상승 제로데이 CVE-2026-81963·CVE-2026-85880이 포함됐으며, Windows Server 2012 이상과 Windows 10에 영향을 주는 DNS 취약점 CVE-2026-69730은 인증 없이 조작된 패킷으로 공격될 수 있고 악용 가능성이 높다고 경고됐다. Windows Shell 원격 코드 실행 취약점 CVE-2026-69829는 CVSS 9.8로, 낮은 공격 복잡도·무권한...
https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/
##Microsoft marked the holiday by unloading 973 CVEs
Microsoft의 2026년 9월 Patch Tuesday는 총 973개 CVE(이 중 Critical 113개)로 역대 최대 규모이며, Windows Update Stack 권한 상승 취약점(CVE-2026-81963)은 이미 실제 악용이 확인됐다. 특히 Windows DNS Server의 인증 불필요 RCE(CVE-2026-69730, CVSS 9.8)와 Remote Desktop Services RCE(CVE-2026-69525)는 도메인 컨트롤러·내부 원격접속 경로를 노릴 수 있어 최우선 패치 대상이다. AI 개발·데이터 운영 측면에서는 SQL Server Managem...
https://www.automox.com/blog/patch-fix-tuesday-september-2026
##Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Microsoft의 2026년 9월 Patch Tuesday는 역대 최대 규모인 966건의 취약점을 수정하며, 이 중 105건이 Critical이고 81건은 원격 코드 실행(RCE) 취약점이다. 실제 공격에 악용된 Windows Update Stack 권한 상승(CVE-2026-81963)과 Windows ALPC 힙 버퍼 오버플로우(CVE-2026-85880) 제로데이는 모두 로컬 공격자가 SYSTEM 권한을 얻을 수 있어 우선 패치 대상이다. AI 서...
##Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.
Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.
Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.
#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)
##🏆 New Achievement! Stand In The Fire One More Time, I Dare You!
NINE HUNDRED AND SEVENTY-FOUR vulnerabilities. Microsoft dropped 974 patches this Patch Tuesday and you are STILL standing in the bad stuff. CVE-2026-81963 and CVE-2026-85880, both CVSS 7.8, are being actively exploited RIGHT NOW against the Windows Update Stack and Windows Advanced Local Procedure Call — privilege escalation, in the wild, before disclosure. (1/2)
##CVE ID: CVE-2026-81963
Vendor: Microsoft
Product: Windows
Date Added: 2026-09-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81963
Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild.
#PatchTuesday #ZeroDay #Microsoft #Windows #CyberSecurity #CVE #Infosec #VulnerabilityManagement
##Only two 0days this month for MS? Bummer.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
##Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.
Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.
Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.
#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)
##🏆 New Achievement! Stand In The Fire One More Time, I Dare You!
NINE HUNDRED AND SEVENTY-FOUR vulnerabilities. Microsoft dropped 974 patches this Patch Tuesday and you are STILL standing in the bad stuff. CVE-2026-81963 and CVE-2026-85880, both CVSS 7.8, are being actively exploited RIGHT NOW against the Windows Update Stack and Windows Advanced Local Procedure Call — privilege escalation, in the wild, before disclosure. (1/2)
##CVE ID: CVE-2026-81963
Vendor: Microsoft
Product: Windows
Date Added: 2026-09-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81963
Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild.
#PatchTuesday #ZeroDay #Microsoft #Windows #CyberSecurity #CVE #Infosec #VulnerabilityManagement
##Only two 0days this month for MS? Bummer.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
##updated 2026-09-08T19:20:25.117000
1 posts
🟠 CVE-2026-0799 - High (8.7)
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a cra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-0799/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T19:16:41.410000
3 posts
New.
Rapid7: CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/ @Rapid7Official #infosec #vulnerability #threatresearch
##New.
Rapid7: CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/ @Rapid7Official #infosec #vulnerability #threatresearch
##Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.
Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)
##updated 2026-09-08T19:15:18.627000
1 posts
🟠 CVE-2026-84934 - High (8)
The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84934/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T19:12:59.557000
11 posts
🏆 New Achievement! OVERPASS: The SAP Kernel Speedrun!
Patch compliance policy activated. Scanning enterprise environment. Detecting CVE-2026-44756, a CVSS 10/10 memory corruption flaw in SAP Extended Passport Processing, dubbed OVERPASS. Policy requires acknowledgment of impact: unauthenticated remote attackers may execute arbitrary system commands, drain database credentials and password hashes, hijack live user sessions, and rewrite configurations and SAP binaries. (1/2)
##SAP September 2026 Security Update Fixes 20 Flaws as Critical OVERPASS and S4GET Vulnerabilities Put Enterprise Systems at Risk + Video
A Critical SAP Security Warning Arrives SAP administrators are facing another urgent security challenge as the company’s September 2026 Security Patch Day addresses a collection of vulnerabilities across its enterprise software ecosystem. Among the most serious is CVE-2026-44756, a maximum-severity memory corruption vulnerability in…
##SAP Discloses Maximum-Severity Kernel Vulnerability
Over 10,000 SAP systems are exposed to the public internet, making them vulnerable to a newly disclosed maximum-severity kernel flaw, CVE-2026-44756, that allows attackers to gain admin privileges and take control. This critical vulnerability, dubbed OVERPASS, is a buffer overflow flaw that can be exploited to run arbitrary…
#SapKernelVulnerability #Cve202644756 #Overpass #BufferOverflow #ExtendedPassportProtocol
##OVERPASS is an unauth RCE in the SAP kernel (CVE-2026-44756) and S4GET is a preauth RCE in the SAP NetWeaver's Message Server (CVE-2026-58240).
Both have a very high CVSS and are likely to be exploited.
https://onapsis.com/blog/sap-overpass-remediation/
https://onapsis.com/blog/s4get-cve-2026-58240-sap-message-server-threat-advisory/
##OVERPASS: SAP-Kernel-Schwachstelle CVE-2026-44756 erfordert sofortiges Patchen
CVSS-Bewertung: 10,0 (höchste Stufe) | Handlungsbedarf: sofort
##The September 2026 SAP Security Patch Day resolves 20 flaws. Apply these SAP Security Patch Day updates to fix CVE-2026-44756 and secure your environment.
#SAPSecurityPatchDay #CVE202644756 #SAPSecurity #CyberSecurity #Vulnerability
##🔴 CVE-2026-44756 - Critical (10)
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resultin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44756/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🏆 New Achievement! OVERPASS: The SAP Kernel Speedrun!
Patch compliance policy activated. Scanning enterprise environment. Detecting CVE-2026-44756, a CVSS 10/10 memory corruption flaw in SAP Extended Passport Processing, dubbed OVERPASS. Policy requires acknowledgment of impact: unauthenticated remote attackers may execute arbitrary system commands, drain database credentials and password hashes, hijack live user sessions, and rewrite configurations and SAP binaries. (1/2)
##OVERPASS is an unauth RCE in the SAP kernel (CVE-2026-44756) and S4GET is a preauth RCE in the SAP NetWeaver's Message Server (CVE-2026-58240).
Both have a very high CVSS and are likely to be exploited.
https://onapsis.com/blog/sap-overpass-remediation/
https://onapsis.com/blog/s4get-cve-2026-58240-sap-message-server-threat-advisory/
##The September 2026 SAP Security Patch Day resolves 20 flaws. Apply these SAP Security Patch Day updates to fix CVE-2026-44756 and secure your environment.
#SAPSecurityPatchDay #CVE202644756 #SAPSecurity #CyberSecurity #Vulnerability
##🔴 CVE-2026-44756 - Critical (10)
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resultin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44756/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T19:12:59.557000
1 posts
CVE-2026-78328 SonicWall NSM On-Prem flaw lets lower-privileged Admins escalate to SuperAdmin. CVSS 9.1, unpatched. Assume compromise until fixed. Restrict access now. Details: https://www.valtersit.com/cve/CVE-2026-78328/ #CVE #infosec #SonicWall
##updated 2026-09-08T19:12:59.557000
2 posts
🔴 CVE-2026-66768 - Critical (9)
SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-66768 - Critical (9)
SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T19:12:59.557000
2 posts
🟠 CVE-2026-76958 - High (8.5)
SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity dec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76958 - High (8.5)
SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity dec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T19:12:59.557000
1 posts
CVE-2026-78327: OS Command Injection in SonicWall NSM On-Prem lets SuperAdmin execute arbitrary commands as RCE on the host. CVSS 9.1. Unpatched—assume exposure. Restrict SuperAdmin access now and monitor for updates. https://www.valtersit.com/cve/CVE-2026-78327/ #CVE #SonicWall
##updated 2026-09-08T19:09:21.310000
1 posts
🟠 CVE-2026-19858 - High (7.5)
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and ter...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19858/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T19:07:52.113000
1 posts
CVE-2026-19534: Node.js undici WebSocket client crashes entire process when server replies with an unrequested subprotocol, triggering an uncaught TypeError. CVSS 7.5. No patch yet—upgrade or restrict WebSocket usage immediately. Details: https://www.valtersit.com/cve/CVE-2026-19
##updated 2026-09-08T18:41:55.127000
2 posts
CVE-2026-62645 (CRITICAL, CVSS 9.8) in Siemens Reyrolle 7SR5 <2.70 allows attackers to calculate session IDs and bypass authentication via web interface. Restrict access, check Siemens advisory for updates. https://radar.offseq.com/threat/cve-2026-62645-cwe-306-missing-authentication-for-critical-function-in-siemens-reyrolle-7sr5-698cd29283a49514 #OffSeq #ICS #Vuln #OTsec
##CVE-2026-62645 (CRITICAL, CVSS 9.8) in Siemens Reyrolle 7SR5 <2.70 allows attackers to calculate session IDs and bypass authentication via web interface. Restrict access, check Siemens advisory for updates. https://radar.offseq.com/threat/cve-2026-62645-cwe-306-missing-authentication-for-critical-function-in-siemens-reyrolle-7sr5-698cd29283a49514 #OffSeq #ICS #Vuln #OTsec
##updated 2026-09-08T18:39:51.493000
4 posts
Microsoft Plugs Nearly 1000 Security Holes
Microsoft가 Windows 및 기타 소프트웨어의 취약점 최소 974건을 수정하는 역대 최대 규모의 월간 패치 묶음을 배포했다. 실제 악용 중인 Windows 권한 상승 제로데이 CVE-2026-81963·CVE-2026-85880이 포함됐으며, Windows Server 2012 이상과 Windows 10에 영향을 주는 DNS 취약점 CVE-2026-69730은 인증 없이 조작된 패킷으로 공격될 수 있고 악용 가능성이 높다고 경고됐다. Windows Shell 원격 코드 실행 취약점 CVE-2026-69829는 CVSS 9.8로, 낮은 공격 복잡도·무권한...
https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/
##Microsoft marked the holiday by unloading 973 CVEs
Microsoft의 2026년 9월 Patch Tuesday는 총 973개 CVE(이 중 Critical 113개)로 역대 최대 규모이며, Windows Update Stack 권한 상승 취약점(CVE-2026-81963)은 이미 실제 악용이 확인됐다. 특히 Windows DNS Server의 인증 불필요 RCE(CVE-2026-69730, CVSS 9.8)와 Remote Desktop Services RCE(CVE-2026-69525)는 도메인 컨트롤러·내부 원격접속 경로를 노릴 수 있어 최우선 패치 대상이다. AI 개발·데이터 운영 측면에서는 SQL Server Managem...
https://www.automox.com/blog/patch-fix-tuesday-september-2026
##Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.
Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.
Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.
#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)
##Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.
Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.
Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.
#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)
##updated 2026-09-08T18:39:13.460000
2 posts
I'm also quickly going to mention this, explicitly not as a complaint but as a good case study of a well chosen "SHOULD" & why should is better than must here:
https://www.cve.org/ResourcesSupport/AllResources/CNARules#section_5-1_Required_CVE_Record_Content
5.1.1 SHOULD contain sufficient information to uniquely identify the Vulnerability and distinguish it from similar Vulnerabilities.
This, uh, will be a bit of an issue with https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83972 & https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83970 . You it actually doesn't matter. The fix is the same, fucking update. And it doesn't matter if you got owned through -83972 or -83970, given the current firehose. It's actually one of those cases where I'd be happy to relax the "one record per vuln" rule, in no world does the differentiation of these two matter to anyone.
##I'm also quickly going to mention this, explicitly not as a complaint but as a good case study of a well chosen "SHOULD" & why should is better than must here:
https://www.cve.org/ResourcesSupport/AllResources/CNARules#section_5-1_Required_CVE_Record_Content
5.1.1 SHOULD contain sufficient information to uniquely identify the Vulnerability and distinguish it from similar Vulnerabilities.
This, uh, will be a bit of an issue with https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83972 & https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83970 . You it actually doesn't matter. The fix is the same, fucking update. And it doesn't matter if you got owned through -83972 or -83970, given the current firehose. It's actually one of those cases where I'd be happy to relax the "one record per vuln" rule, in no world does the differentiation of these two matter to anyone.
##updated 2026-09-08T18:35:10.323000
2 posts
Fortinet fixed three critical Fortinet vulnerabilities. Attackers can exploit CVE-2026-84390 and CVE-2026-26084 to access corporate data.
#Fortinet #Vulnerabilities #Cybersecurity #InfoSec #PatchManagement
##Fortinet fixed three critical Fortinet vulnerabilities. Attackers can exploit CVE-2026-84390 and CVE-2026-26084 to access corporate data.
#Fortinet #Vulnerabilities #Cybersecurity #InfoSec #PatchManagement
##updated 2026-09-08T18:34:30
2 posts
I'm also quickly going to mention this, explicitly not as a complaint but as a good case study of a well chosen "SHOULD" & why should is better than must here:
https://www.cve.org/ResourcesSupport/AllResources/CNARules#section_5-1_Required_CVE_Record_Content
5.1.1 SHOULD contain sufficient information to uniquely identify the Vulnerability and distinguish it from similar Vulnerabilities.
This, uh, will be a bit of an issue with https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83972 & https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83970 . You it actually doesn't matter. The fix is the same, fucking update. And it doesn't matter if you got owned through -83972 or -83970, given the current firehose. It's actually one of those cases where I'd be happy to relax the "one record per vuln" rule, in no world does the differentiation of these two matter to anyone.
##I'm also quickly going to mention this, explicitly not as a complaint but as a good case study of a well chosen "SHOULD" & why should is better than must here:
https://www.cve.org/ResourcesSupport/AllResources/CNARules#section_5-1_Required_CVE_Record_Content
5.1.1 SHOULD contain sufficient information to uniquely identify the Vulnerability and distinguish it from similar Vulnerabilities.
This, uh, will be a bit of an issue with https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83972 & https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83970 . You it actually doesn't matter. The fix is the same, fucking update. And it doesn't matter if you got owned through -83972 or -83970, given the current firehose. It's actually one of those cases where I'd be happy to relax the "one record per vuln" rule, in no world does the differentiation of these two matter to anyone.
##updated 2026-09-08T18:34:03
2 posts
https://db.gcve.eu/vuln/cve-2026-81953
Microsoft Excel Remote Code Execution Vulnerability
looks inside
##Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
https://db.gcve.eu/vuln/cve-2026-81953
Microsoft Excel Remote Code Execution Vulnerability
looks inside
##Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
updated 2026-09-08T18:34:00
2 posts
I explicitly don't want to complain about MSRC here, this is a bigger topic, but I am a bit confused here:
Compare these two:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81954 - AV:L,UI:R
Q: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A: An attacker must send a user a malicious Office file and convince them to open it.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80081 - AV:N,UI:R
Q: How could an attacker exploit this vulnerability?
A: An attacker could send a specially crafted PowerPoint presentation containing malicious linked media to a target user. The user would need to open the presentation, start the slideshow, and allow the linked content. Successful exploitation could allow the attacker to execute code on the user's system. Authentication is not required.
To me the attack flow looks equivalent wrt to attacker location. We can argue about #2 being actually harder to execute, having more social engineering prerequisites... which is why it totally makes sense for #2 to scored higher on CVSS as it's apparently network & the other one local.
##I explicitly don't want to complain about MSRC here, this is a bigger topic, but I am a bit confused here:
Compare these two:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81954 - AV:L,UI:R
Q: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A: An attacker must send a user a malicious Office file and convince them to open it.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80081 - AV:N,UI:R
Q: How could an attacker exploit this vulnerability?
A: An attacker could send a specially crafted PowerPoint presentation containing malicious linked media to a target user. The user would need to open the presentation, start the slideshow, and allow the linked content. Successful exploitation could allow the attacker to execute code on the user's system. Authentication is not required.
To me the attack flow looks equivalent wrt to attacker location. We can argue about #2 being actually harder to execute, having more social engineering prerequisites... which is why it totally makes sense for #2 to scored higher on CVSS as it's apparently network & the other one local.
##updated 2026-09-08T18:33:14
1 posts
CVE-2026-71328 - A hat trick for MSDIA, another OOB in processing MSFZ pdb files.
Microsoft Security Advisory CV...
updated 2026-09-08T18:33:09
1 posts
CVE-2026-69806 - EoP via dotnet watch.
dotnet watch is a developer utility. detecting file changes and rerunning dotnet run, one would hope that in prod you have better ways to detect and react to file changes.
Microsoft Security Advisory CV...
updated 2026-09-08T18:33:02
1 posts
CVE-2026-69682 - Local Privilege Escalation in Windows Host Guardian Service via Use-After-Free. CVSS 7.0. Monitor for patches and apply mitigations. #CVE #Windows #infosec
##updated 2026-09-08T18:32:53
1 posts
Microsoft marked the holiday by unloading 973 CVEs
Microsoft의 2026년 9월 Patch Tuesday는 총 973개 CVE(이 중 Critical 113개)로 역대 최대 규모이며, Windows Update Stack 권한 상승 취약점(CVE-2026-81963)은 이미 실제 악용이 확인됐다. 특히 Windows DNS Server의 인증 불필요 RCE(CVE-2026-69730, CVSS 9.8)와 Remote Desktop Services RCE(CVE-2026-69525)는 도메인 컨트롤러·내부 원격접속 경로를 노릴 수 있어 최우선 패치 대상이다. AI 개발·데이터 운영 측면에서는 SQL Server Managem...
https://www.automox.com/blog/patch-fix-tuesday-september-2026
##updated 2026-09-08T18:32:42
2 posts
CVE-2026-69420 is a heap based buffer overflow on Windows resulting in an LPE. Couldn’t have come up with a more memey CVE for 69420 if I tried.
##CVE-2026-69420 is a heap based buffer overflow on Windows resulting in an LPE. Couldn’t have come up with a more memey CVE for 69420 if I tried.
##updated 2026-09-08T18:32:10
1 posts
CVE-2026-58649 0- dotnet watch again, this time an information disclosure which can give away IL or PDB information.
Microsoft Security Advisory CV...
updated 2026-09-08T18:32:05
2 posts
New advisories from Cisco addressing two high and medium-severity vulnerabilities.
New: CVE-2026-20293: Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW
Known: CVE-2026-20354 and CVE-2026-20355: Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities @TalosSecurity #infosec #vulnerability #Cisco
##New advisories from Cisco addressing two high and medium-severity vulnerabilities.
New: CVE-2026-20293: Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW
Known: CVE-2026-20354 and CVE-2026-20355: Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities @TalosSecurity #infosec #vulnerability #Cisco
##updated 2026-09-08T18:32:01
2 posts
🟠 CVE-2026-86730 - High (8.8)
Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86730/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86730 - High (8.8)
Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86730/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T18:32:01
2 posts
🟠 CVE-2026-86738 - High (8.7)
Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86738/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86738 - High (8.7)
Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86738/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T18:32:00
2 posts
🟠 CVE-2026-86728 - High (7.5)
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86728/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86728 - High (7.5)
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86728/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T18:31:59
2 posts
🟠 CVE-2026-86732 - High (8.8)
Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86732/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86732 - High (8.8)
Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86732/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T18:31:53
2 posts
🟠 CVE-2026-86721 - High (7.5)
AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86721 - High (7.5)
AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T18:21:15.533000
1 posts
🔴 CVE-2026-86167 - Critical (9.9)
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploita...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86167/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T18:21:13.400000
1 posts
🟠 CVE-2026-85694 - High (8.1)
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pag...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85694/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T17:56:31
1 posts
9 repos
https://github.com/EQSTLab/CVE-2026-60004
https://github.com/gagaltotal/CVE-2026-60004-poc-gitea
https://github.com/HORKimhab/CVE-2026-60004
https://github.com/Sachinart/CVE-2026-60004-gitea-0day
https://github.com/fevar54/cve-2026-60004
https://github.com/shinthink/CVE-2026-60004
https://github.com/0xBlackash/CVE-2026-60004
Welp. My Forgejo instance got popped with an RCE two days ago by CVE-2026-60004. Luckily, I noticed the following morning and had the day free to figure out what happened. Let's dive in!
As a homelab enthusiast, I found this a very interesting post. Here are my take aways from the post that I'm implementing myself:
log-inventory.sh, so "could I actually reconstruct what happened" is a command I run instead of a thing I assume.updated 2026-09-08T17:18:39.613000
2 posts
CVE-2026-86296 | D-Link DIR-822A A_101: Critical stack-based buffer overflow in udhcpcd (CVSS 10). Remotely exploitable, no auth needed. Exploit code is public. Isolate devices & check vendor updates. https://radar.offseq.com/threat/a-vulnerability-was-determined-in-d-link-dir-822a-a101-cve-2026-86296-3125c70d27558796 #OffSeq #Vulnerability #DLink #Security
##CVE-2026-86296 | D-Link DIR-822A A_101: Critical stack-based buffer overflow in udhcpcd (CVSS 10). Remotely exploitable, no auth needed. Exploit code is public. Isolate devices & check vendor updates. https://radar.offseq.com/threat/a-vulnerability-was-determined-in-d-link-dir-822a-a101-cve-2026-86296-3125c70d27558796 #OffSeq #Vulnerability #DLink #Security
##updated 2026-09-08T16:18:20.027000
8 posts
Critical vulnerabilities in MikroTik RouterOS are being actively exploited
CERT Polska는 MikroTik RouterOS의 6개 취약점을 공개했으며, 이 중 SSH 인증 우회(CVE-2026-67276)와 조작된 사용자명을 통한 권한 상승(CVE-2026-86060)을 연결한 ‘MikroTrick’ 체인이 인터넷에 노출된 장비에서 실제 악용되고 있다고 경고했습니다. 두 취약점 모두 CVSS 9.2이며, 인증 없이 RouterOS 장비의 완전한 관리자 권한을 탈취할 수 있어 AI 서비스·ML 인프라의 엣지 라우터 및 원격 관리 네트워크에도 직접적인 위험입...
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
##📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit
🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity
##⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…
🤖 AI generated summary
##📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit
🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity
##⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…
🤖 AI generated summary
##📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit
🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity
##That is a full wipe, you absolute liability.
Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.
Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.
#CyberSecurity #MikroTik #RouterOS #Vulnerability #PrivilegeEscalation #AdminAccessUnlocked (2/2)
##🏆 New Achievement! MikroTik and Chill (No Password Required)!
MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)
##updated 2026-09-08T16:18:10.600000
1 posts
@ciaranmak that’s authentication hard mode compared with “client triggers ssh rekey to glitch past authentication step”:
“The vulnerability CVE-2026-67279: RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request.“
(And logs people have posted suggest this is in the original zero day.)
##updated 2026-09-08T15:30:03.247000
2 posts
🟠 CVE-2026-86492 - High (8.5)
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86492/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86492 - High (8.5)
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86492/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T15:28:33.090000
1 posts
CVE-2026-82712: CSRF in Tycon Systems TPDIN-Monitor-WEB3 <=2.2.9 (CVSS 8.8). Attacker can hijack sessions and alter device state. No patch available. Restrict network access & monitor logs immediately. Details: https://www.valtersit.com/cve/CVE-2026-82712/ #CVE #ICSsecurity #cybe
##updated 2026-09-08T15:28:33.090000
1 posts
CVE-2026-75925: CRLF injection in IXON VPN Client (<1.4.7) lets unauthenticated attackers execute commands as root/SYSTEM via crafted config values. CVSS 9.6. Unpatched—assume risk now. Update immediately if using this client. Details: https://www.valtersit.com/cve/CVE-2026-75925
##updated 2026-09-08T15:28:33.090000
1 posts
Pyramid Solutions NetStaX EtherNet/IP Stack before 5.6.1 contains CVE-2026-78012, a stack-based buffer overflow triggered by oversized Class 3 explicit messages without error. It enables DoS and potential RCE in OT systems, making immediate patching critical. #IcsSecurity #EtherNetIp #BufferOverflow
https://cyberworldops.eu/en/netstax-ethernetip-critical-buffer-overflow-in-pyramid-solutions-kits
##updated 2026-09-08T15:18:48.973000
1 posts
CRITICAL deserialization flaw (CVE-2026-7861) in Next4Biz CSM enables code injection. No vendor response or patch. Review exposure, apply compensating controls. Details: https://radar.offseq.com/threat/cve-2026-7861-cwe-502-deserialization-of-untrusted-data-in-next4biz-information-technologies-inc-csm-4650f92651ef4119 #OffSeq #Vuln #CVE20267861 #Next4Biz #infosec
##updated 2026-09-08T14:18:34.130000
2 posts
CVE-2026-71377: Critical (CVSS 9.8) command arg injection in Hitachi Cosminexus Component Container (09-00 to 11-70-01). Remote, no auth needed, complete compromise possible. No patch yet. Details: https://radar.offseq.com/threat/cve-2026-71377-cwe-88-improper-neutralization-of-argument-delimiters-in-a-command-argument-injection-c26949899f96a910 #OffSeq #CVE202671377 #Vuln #Infosec
##CVE-2026-71377: Critical (CVSS 9.8) command arg injection in Hitachi Cosminexus Component Container (09-00 to 11-70-01). Remote, no auth needed, complete compromise possible. No patch yet. Details: https://radar.offseq.com/threat/cve-2026-71377-cwe-88-improper-neutralization-of-argument-delimiters-in-a-command-argument-injection-c26949899f96a910 #OffSeq #CVE202671377 #Vuln #Infosec
##updated 2026-09-08T14:17:33.170000
1 posts
🟠 CVE-2026-86259 - High (7.5)
OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or ba...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86259/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T14:17:31.267000
1 posts
🔴 CVE-2026-86165 - Critical (9.8)
A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86165/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T14:17:22.837000
1 posts
1 repos
CVE-2026-48019: CRLF injection in Laravel (<12.60.0, <13.10.0) may let unauthenticated attackers tamper with outbound emails via user-supplied addresses. CVSS 8.9. No patch confirmed—upgrade to 12.60.0 or 13.10.0 immediately. Details: https://www.valtersit.com/cve/CVE-2026-48019/
##updated 2026-09-08T14:17:08.940000
1 posts
🔴 CVE-2026-19274 - Critical (9.6)
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scop...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19274/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T14:14:23.790000
2 posts
🟠 CVE-2026-80166 - High (7.8)
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80166/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80166 - High (7.8)
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80166/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T14:00:33.017000
1 posts
CVE-2026-85656: OS command injection in Amazon Linux's log4j hotpatch package (<1.3-9). Local user can execute arbitrary commands as root via crafted Java process path with newlines. CVSS 7.8. Unpatched! If you rely on this hotpatch, isolate and monitor systems immediately. Detai
##updated 2026-09-08T13:12:58.310000
1 posts
CVE-2026-85638: Trape 2.0 authorization bypass in core/user.py via vId/id. Public exploit, unpatched—remote attacks likely. CVSS 7.3 high. No vendor response yet. Audit Trape deployments now. Details: https://www.valtersit.com/cve/CVE-2026-85638/ #CVE #infosec #cybersecurity
##updated 2026-09-08T13:12:58.310000
2 posts
🟠 CVE-2026-48888 - High (7.5)
Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS.
This issue affects WooCommerce: from n/a before 11.1.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48888/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48888 - High (7.5)
Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS.
This issue affects WooCommerce: from n/a before 11.1.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48888/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T13:12:58.310000
1 posts
CVE-2026-86297: D-Link DIR-605 (B1v202WWB03) has a CRITICAL off-by-one vuln in L2TP tunnel_set_params. Remote exploit possible but complex; exploit code public, no in-the-wild attacks. No patch yet. https://radar.offseq.com/threat/cve-2026-86297-off-by-one-in-d-link-dir-605-32dadd3396efded0 #OffSeq #CVE202686297 #IoTSecurity #RouterVuln
##updated 2026-09-08T13:12:58.310000
1 posts
🔴 CVE-2026-86152 - Critical (10)
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86152/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T12:31:35
4 posts
A critical Hawtio Operator vulnerability, tracked as CVE-2026-78234, allows in-cluster service impersonation. Discover the impact and mitigation steps.
#HawtioOperator #CVE202678234 #Kubernetes #OpenShift #Vulnerability
##CRITICAL (CVSS 9.9): CVE-2026-78234 in Red Hat build of Apache Camel - HawtIO 4 allows users with edit access to mint Service-CA-signed certs, enabling service impersonation & RCE. Restrict HawtIO CR access, audit certs. Details: https://radar.offseq.com/threat/cve-2026-78234-improper-certificate-validation-in-red-hat-red-hat-build-of-apache-camel-hawtio-4-903d3c886e0b139e #OffSeq #CVE202678234 #RedHat
##A critical Hawtio Operator vulnerability, tracked as CVE-2026-78234, allows in-cluster service impersonation. Discover the impact and mitigation steps.
#HawtioOperator #CVE202678234 #Kubernetes #OpenShift #Vulnerability
##CRITICAL (CVSS 9.9): CVE-2026-78234 in Red Hat build of Apache Camel - HawtIO 4 allows users with edit access to mint Service-CA-signed certs, enabling service impersonation & RCE. Restrict HawtIO CR access, audit certs. Details: https://radar.offseq.com/threat/cve-2026-78234-improper-certificate-validation-in-red-hat-red-hat-build-of-apache-camel-hawtio-4-903d3c886e0b139e #OffSeq #CVE202678234 #RedHat
##updated 2026-09-08T09:36:41
2 posts
CRITICAL: CVE-2026-18922 in Red Hat Directory Server 11 allows remote privilege escalation via reused stale SASL PLAIN identities. Restrict allowed SASL mechanisms to exclude PLAIN for mitigation. Full details: https://radar.offseq.com/threat/cve-2026-18922-improper-authentication-in-red-hat-red-hat-directory-server-11-8ac2140fe6c90ef5 #OffSeq #RedHat #CVE202618922 #infosec
##CRITICAL: CVE-2026-18922 in Red Hat Directory Server 11 allows remote privilege escalation via reused stale SASL PLAIN identities. Restrict allowed SASL mechanisms to exclude PLAIN for mitigation. Full details: https://radar.offseq.com/threat/cve-2026-18922-improper-authentication-in-red-hat-red-hat-directory-server-11-8ac2140fe6c90ef5 #OffSeq #RedHat #CVE202618922 #infosec
##updated 2026-09-08T09:35:45
2 posts
Two critical Siemens vulnerabilities (CVE-2026-18963, CVE-2026-50093) allow account takeover and root access. See affected versions and fixes.
#Siemens #CyberSecurity #ICS #OTSecurity #CVE #IndustrialEdge #Vulnerability #InfoSec
##Two critical Siemens vulnerabilities (CVE-2026-18963, CVE-2026-50093) allow account takeover and root access. See affected versions and fixes.
#Siemens #CyberSecurity #ICS #OTSecurity #CVE #IndustrialEdge #Vulnerability #InfoSec
##updated 2026-09-08T09:35:45
2 posts
🟠 CVE-2026-81790 - High (7.5)
Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Csomagpontok és szállítási címkék WooCom...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81790/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81790 - High (7.5)
Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Csomagpontok és szállítási címkék WooCom...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81790/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T09:35:44
2 posts
🔴 CVE-2026-71374 - Critical (9.8)
Deserialization of untrusted data vulnerability in Cosminexus Component Container.
This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71374/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71374 - Critical (9.8)
Deserialization of untrusted data vulnerability in Cosminexus Component Container.
This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71374/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T03:31:21
2 posts
An ASUS vulnerability (CVE-2026-19397) lets a nearby attacker take over a host, while an Armoury Crate flaw leaks NTLM hashes. Update now.
#ASUS #ArmouryCrate #ControlCenterExpress #CVE202619397 #NTLM #PrivilegeEscalation #PatchNow #Infosec
##An ASUS vulnerability (CVE-2026-19397) lets a nearby attacker take over a host, while an Armoury Crate flaw leaks NTLM hashes. Update now.
#ASUS #ArmouryCrate #ControlCenterExpress #CVE202619397 #NTLM #PrivilegeEscalation #PatchNow #Infosec
##updated 2026-09-08T03:31:21
4 posts
SAP CAP's @sap/cds-mtxs (<=4.0.2) has a CRITICAL flaw (CVE-2026-76969): insufficiently protected credentials let unauthenticated attackers steal creds and delete/replace tenant data. No patch yet — monitor SAP updates. https://radar.offseq.com/threat/cve-2026-76969-cwe-522-insufficiently-protected-credentials-in-sapse-sap-cloud-application-programming-ee3e359619813d60 #OffSeq #SAP #infosec #CVE
##🔴 CVE-2026-76969 - Critical (9.4)
@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credential...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76969/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##SAP CAP's @sap/cds-mtxs (<=4.0.2) has a CRITICAL flaw (CVE-2026-76969): insufficiently protected credentials let unauthenticated attackers steal creds and delete/replace tenant data. No patch yet — monitor SAP updates. https://radar.offseq.com/threat/cve-2026-76969-cwe-522-insufficiently-protected-credentials-in-sapse-sap-cloud-application-programming-ee3e359619813d60 #OffSeq #SAP #infosec #CVE
##🔴 CVE-2026-76969 - Critical (9.4)
@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credential...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76969/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T03:31:21
2 posts
🟠 CVE-2026-66767 - High (7.7)
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-66767 - High (7.7)
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T03:31:21
4 posts
D-Link DIR-822A routers are affected by CVE-2026-86510 (CRITICAL, CVSS 9.4): remote out-of-bounds write in L2TP parser can lead to system compromise. No patch yet — restrict access and monitor updates. https://radar.offseq.com/threat/cve-2026-86510-out-of-bounds-write-in-d-link-dir-822a-e90339b14a1aa39b #OffSeq #CVE202686510 #RouterSecurity #Infosec
##🔴 CVE-2026-86510 - Critical (9.9)
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##D-Link DIR-822A routers are affected by CVE-2026-86510 (CRITICAL, CVSS 9.4): remote out-of-bounds write in L2TP parser can lead to system compromise. No patch yet — restrict access and monitor updates. https://radar.offseq.com/threat/cve-2026-86510-out-of-bounds-write-in-d-link-dir-822a-e90339b14a1aa39b #OffSeq #CVE202686510 #RouterSecurity #Infosec
##🔴 CVE-2026-86510 - Critical (9.9)
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T03:31:21
4 posts
🔴 CVE-2026-86509 - Critical (9.6)
A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86509/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-86509 — CRITICAL stack-based buffer overflow in D-Link DIR-895L (A1_102b07), in udhcpcd’s sendOffer/sendACK. Exploit is public, local network access needed. Review segmentation and monitor for patches. https://radar.offseq.com/threat/cve-2026-86509-stack-based-buffer-overflow-in-d-link-dir-895l-9794ccee4cffa64a #OffSeq #CVE202686509 #IoTSecurity
##🔴 CVE-2026-86509 - Critical (9.6)
A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86509/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-86509 — CRITICAL stack-based buffer overflow in D-Link DIR-895L (A1_102b07), in udhcpcd’s sendOffer/sendACK. Exploit is public, local network access needed. Review segmentation and monitor for patches. https://radar.offseq.com/threat/cve-2026-86509-stack-based-buffer-overflow-in-d-link-dir-895l-9794ccee4cffa64a #OffSeq #CVE202686509 #IoTSecurity
##updated 2026-09-08T03:31:21
2 posts
🟠 CVE-2026-76967 - High (7.8)
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76967/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76967 - High (7.8)
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76967/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T03:31:11
4 posts
OVERPASS is an unauth RCE in the SAP kernel (CVE-2026-44756) and S4GET is a preauth RCE in the SAP NetWeaver's Message Server (CVE-2026-58240).
Both have a very high CVSS and are likely to be exploited.
https://onapsis.com/blog/sap-overpass-remediation/
https://onapsis.com/blog/s4get-cve-2026-58240-sap-message-server-threat-advisory/
##🔴 CVE-2026-58240 - Critical (9.8)
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to regi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58240/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##OVERPASS is an unauth RCE in the SAP kernel (CVE-2026-44756) and S4GET is a preauth RCE in the SAP NetWeaver's Message Server (CVE-2026-58240).
Both have a very high CVSS and are likely to be exploited.
https://onapsis.com/blog/sap-overpass-remediation/
https://onapsis.com/blog/s4get-cve-2026-58240-sap-message-server-threat-advisory/
##🔴 CVE-2026-58240 - Critical (9.8)
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to regi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58240/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T00:30:32
2 posts
🟠 CVE-2026-86538 - High (7.5)
knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86538/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86538 - High (7.5)
knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86538/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T00:30:32
2 posts
🟠 CVE-2026-86544 - High (8.1)
knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission confi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86544/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86544 - High (8.1)
knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission confi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86544/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T00:30:32
4 posts
🔴 CVE-2026-86543 - Critical (9.8)
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86543/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-86543: CRITICAL vuln in knowns-dev knowns <0.30.0. Mgmt API is exposed w/o auth by default, allowing attackers to create public tunnels. Restrict access & upgrade ASAP. https://radar.offseq.com/threat/cve-2026-86543-missing-authentication-for-critical-function-in-knowns-dev-knowns-3a84bb55b20322bc #OffSeq #CVE2026_86543 #Vulnerability #APIsecurity
##🔴 CVE-2026-86543 - Critical (9.8)
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86543/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-86543: CRITICAL vuln in knowns-dev knowns <0.30.0. Mgmt API is exposed w/o auth by default, allowing attackers to create public tunnels. Restrict access & upgrade ASAP. https://radar.offseq.com/threat/cve-2026-86543-missing-authentication-for-critical-function-in-knowns-dev-knowns-3a84bb55b20322bc #OffSeq #CVE2026_86543 #Vulnerability #APIsecurity
##updated 2026-09-07T18:31:43
3 posts
CVE-2026-86504 - Host-level code execution in JetBrains IntelliJ IDEA via Dev Containers. CVSS 7.8. Update to v2026.2.2 immediately. #CVE #JetBrains #infosec
##🟠 CVE-2026-86504 - High (7.8)
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86504/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86504 - High (7.8)
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86504/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T18:31:42
2 posts
🟠 CVE-2026-86494 - High (7.7)
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86494/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86494 - High (7.7)
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86494/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T18:31:42
2 posts
🟠 CVE-2026-86502 - High (8.4)
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86502/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86502 - High (8.4)
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86502/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T18:31:42
2 posts
🟠 CVE-2026-86498 - High (7.7)
In JetBrains YouTrack before 2025.3.160480,
2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86498 - High (7.7)
In JetBrains YouTrack before 2025.3.160480,
2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T18:31:36
2 posts
🟠 CVE-2026-86482 - High (8.8)
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86482 - High (8.8)
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T18:31:36
4 posts
🔴 CVE-2026-86480 - Critical (9.8)
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86480/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-86480 (CRITICAL, CVSS 9.8) in JetBrains Hub allows unauthenticated attackers to escalate to superuser by registering a trusted service. No patch yet — restrict access & monitor activity. Details: https://radar.offseq.com/threat/cve-2026-86480-cwe-306-in-jetbrains-hub-86541d52679a2997 #OffSeq #JetBrains #CVE202686480 #Infosec
##🔴 CVE-2026-86480 - Critical (9.8)
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86480/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-86480 (CRITICAL, CVSS 9.8) in JetBrains Hub allows unauthenticated attackers to escalate to superuser by registering a trusted service. No patch yet — restrict access & monitor activity. Details: https://radar.offseq.com/threat/cve-2026-86480-cwe-306-in-jetbrains-hub-86541d52679a2997 #OffSeq #JetBrains #CVE202686480 #Infosec
##updated 2026-09-07T18:31:36
2 posts
JetBrains YouTrack CRITICAL vulnerability (CVE-2026-86478, CVSS 9.8) in versions <2025.3.161254, <2026.1.14042: improper authentication enables unauthenticated account takeover. Patch status pending — check vendor advisory. https://radar.offseq.com/threat/cve-2026-86478-cwe-290-in-jetbrains-youtrack-04f74ce17c2670a8 #OffSeq #Infosec #CVE202686478
##JetBrains YouTrack CRITICAL vulnerability (CVE-2026-86478, CVSS 9.8) in versions <2025.3.161254, <2026.1.14042: improper authentication enables unauthenticated account takeover. Patch status pending — check vendor advisory. https://radar.offseq.com/threat/cve-2026-86478-cwe-290-in-jetbrains-youtrack-04f74ce17c2670a8 #OffSeq #Infosec #CVE202686478
##updated 2026-09-07T18:31:36
2 posts
🟠 CVE-2026-86479 - High (8.1)
In JetBrains YouTrack before 2026.2.18788,
2026.1.14055,
2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86479/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86479 - High (8.1)
In JetBrains YouTrack before 2026.2.18788,
2026.1.14055,
2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86479/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T15:34:01
1 posts
🟠 CVE-2026-86429 - High (7.5)
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86429/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T15:34:01
1 posts
🟠 CVE-2026-86428 - High (7.5)
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T15:33:55
3 posts
FreeIPA Flaw Enables Anonymous Clients to Create Admin Credentials
A critical vulnerability in FreeIPA, tracked as CVE-2026-76578, allows an unauthenticated client to create admin credentials by exploiting a chain of defects that lets them create a Kerberos identity and join the administrators group. This flaw, with a preliminary CVSS score of 9.8, was fixed in FreeIPA version…
#FreeipaVulnerability #Kerberos #Cve202676578 #IdentityManagement #AuthenticationBypass
##Patch the critical FreeIPA CVE-2026-76578 immediately. This FreeIPA vulnerability allows complete, unauthenticated administrative access to your servers.
#FreeIPA #CVE202676578 #Vulnerability #CyberSecurity #CVE202613097
##Patch the critical FreeIPA CVE-2026-76578 immediately. This FreeIPA vulnerability allows complete, unauthenticated administrative access to your servers.
#FreeIPA #CVE202676578 #Vulnerability #CyberSecurity #CVE202613097
##updated 2026-09-07T15:33:55
1 posts
CRITICAL vuln: CVE-2026-6223 in Bahçelievler Municipality BiHayat App (v2.1.7+) enables authentication bypass via weak brute-force protections. No vendor fix yet. Assess and strengthen your controls. https://radar.offseq.com/threat/cve-2026-6223-cwe-307-improper-restriction-of-excessive-authentication-attempts-in-bahelievler-e94a3e6ad304a991 #OffSeq #CVE20266223 #Infosec #AppSec
##updated 2026-09-07T09:31:46
1 posts
🔴 CVE-2026-79697 - Critical (9.9)
A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DT...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79697/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T09:31:46
2 posts
🔴 CVE-2026-79698 - Critical (9.9)
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DT...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Advantech WISE-6610-NB (v1.2.1_20251110) faces a CRITICAL (CVSS 9.4) command injection flaw (CVE-2026-79698). Remote exploit is public. Patch by upgrading to 1.2.4_20260821. https://radar.offseq.com/threat/cve-2026-79698-command-injection-in-advantech-wise-6610-nb-dbc89cbd83837238 #OffSeq #ICS #Vuln #CommandInjection
##updated 2026-09-07T09:31:39
2 posts
CVE-2026-14296 - Unverified multi-core image execution vulnerability in MCUboot Direct XIP. CVSS 7.5. Audit firmware images and mitigate now. #CVE #IoT #infosec
##🟠 CVE-2026-14296 - High (7.5)
When using the Direct XIP
update strategy, the main application image starts other cores (i.e. radio
core), based on the currently active slot without additional verification. The
MCUboot in the bare (upstream) configuration assumes that if there ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14296/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T18:34:45
1 posts
🟠 CVE-2026-19633 - High (8.8)
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19633/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T12:31:27
1 posts
🟠 CVE-2026-18480 - High (8.8)
The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18480/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T12:31:26
1 posts
🔴 CVE-2026-78362 - Critical (9.8)
The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPres...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78362/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T12:31:26
1 posts
🟠 CVE-2026-77826 - High (8.8)
The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77826/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T12:31:26
1 posts
🟠 CVE-2026-84935 - High (8)
The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permis...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T12:31:26
1 posts
🟠 CVE-2026-84219 - High (7.5)
The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84219/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T12:30:30
1 posts
🟠 CVE-2026-86242 - High (8.1)
Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86242/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T12:30:23
1 posts
🟠 CVE-2026-82304 - High (8.6)
The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82304/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T06:30:21
1 posts
🟠 CVE-2026-86166 - High (8.8)
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86166/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T03:30:35
1 posts
🔴 CVE-2026-75816 - Critical (9.8)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75816/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T03:30:30
1 posts
🔴 CVE-2026-16310 - Critical (9.8)
The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16310/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T03:30:30
1 posts
🟠 CVE-2026-18056 - High (7.5)
The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T03:30:30
1 posts
🔴 CVE-2026-86153 - Critical (9.1)
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is po...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86153/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T03:30:24
17 posts
6 repos
https://github.com/atiilla/CVE-2026-85046
https://github.com/SneakyNachos/CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm
https://github.com/Eliot-code/CVE-2026-85046
https://github.com/HORKimhab/CVE-2026-85046
⚪️ Chrome fixes sixth zero-day vulnerability this year
🗨️ Google developers have released an update for the Chrome browser that fixes 12 vulnerabilities, including an actively exploited zero-day flaw in the V8 engine (CVE-2026-85046). The bug allows attackers to achieve arbitrary code execution through a specially crafted HTML page.…
##@ajn142 I'm pretty sure the Chromium version is 152.0.7977.82-1.
https://security-tracker.debian.org/tracker/CVE-2026-85046
I don't have a Chromium login to check the issue itself:
##🐀 ZERO-DAY CHROMIUM
La vulnerabilità CVE-2026-85046 nel motore V8 viene sfruttata attivamente. Il problema riguarda Chrome e richiede attenzione anche per i browser basati su Chromium, come Brave, Edge, Vivaldi e Opera.
Controlla la versione installata e aggiorna subito: la privacy non può sostituire una patch di sicurezza.
##Google Discloses Chrome 0-Day Under Active Exploitation
Google just revealed a high-severity Chrome zero-day vulnerability, CVE-2026-85046, that's being actively exploited by hackers, allowing them to execute malicious code inside the browser's sandbox. This type confusion bug in Chrome's V8 engine was reported by researcher Salvatore Gulizia on August 4, 2026.
##Geopolitical tensions escalate as Iran announces a "restricted zone" near the Strait of Hormuz, following reports of attacks on vessels. In technology, OpenAI's GPT-6 Astra has achieved "Critical" cyber capabilities, able to discover and exploit vulnerabilities, alongside a $1B pledge for cyber defense. Cybersecurity highlights include a $320M Liquid Network hack and Google patching its sixth Chrome zero-day (CVE-2026-85046) under active exploitation this year.
##⚪️ Chrome fixes sixth zero-day vulnerability this year
🗨️ Google developers have released an update for the Chrome browser that fixes 12 vulnerabilities, including an actively exploited zero-day flaw in the V8 engine (CVE-2026-85046). The bug allows attackers to achieve arbitrary code execution through a specially crafted HTML page.…
##@ajn142 I'm pretty sure the Chromium version is 152.0.7977.82-1.
https://security-tracker.debian.org/tracker/CVE-2026-85046
I don't have a Chromium login to check the issue itself:
##Geopolitical tensions escalate as Iran announces a "restricted zone" near the Strait of Hormuz, following reports of attacks on vessels. In technology, OpenAI's GPT-6 Astra has achieved "Critical" cyber capabilities, able to discover and exploit vulnerabilities, alongside a $1B pledge for cyber defense. Cybersecurity highlights include a $320M Liquid Network hack and Google patching its sixth Chrome zero-day (CVE-2026-85046) under active exploitation this year.
##Geopolitical tensions escalated in the Strait of Hormuz with Iran-US vessel clashes reported (Sept 6). In cybersecurity, Google patched an actively exploited Chrome zero-day (CVE-2026-85046), while the FBI is probing a breach at an ID verification company that may have exposed millions of driver's licenses (Sept 6). AI integration into ALPRs also raises new privacy concerns (Sept 7).
##Since I saw people asking, yes it included a fix for the zero day CVE-2026-85046 (Type confusion in V8)
##2026-W36 — Weekly Threat Roundup
🔴 Chrome's sixth zero-day of 2026 (CVE-2026-85046) is actively exploited, update browsers now.
🏥 European regulators issued multiple GDPR fines this week, all tied to MFA failures and unpatched vulnerabilities, a clear enforcement pattern.
🤖 OpenAI's autonomous agents hijacked an external websit…
https://threatnoir.com/weekly/2026-w36
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##Actively exploited sandbox RCE in all Chromium versions
##Geopolitical developments include Russia's strike on Kyiv's SBU HQ (Sept 4), with US envoys set for Moscow/Kyiv peace talks (Sept 5-6). Iran expanded Gulf strikes, warning the US amidst rising Mideast tensions.
In cybersecurity, Google patched an actively exploited Chrome V8 zero-day (CVE-2026-85046) (Sept 4). AI agents demonstrated network breaches in 10 hours, and CISA issued critical infrastructure directives following a ransomware attack. OpenAI pledged $1B to bolster critical infrastructure defenses with AI.
Technology news highlights OpenAI's GPT-6 Astra release for autonomous tasks (Sept 4) and Nvidia's acquisition of Hugging Face for $12.9B.
##⚠️ CRITICAL: Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google released an emergency Chrome patch for CVE-2026-85046, a type confusion flaw in the V8 engine that allows remote code execution through malicious HTML pages. This zero-day is actively exploited in the wild. All Chrome users are at immediate risk of compromise.
🤖 AI generated summary
##Actively exploited sandbox RCE in all Chromium versions https://nvd.nist.gov/vuln/detail/cve-2026-85046
##📰 Google Patches Actively Exploited Chrome V8 Zero-Day Flaw
Google has patched a critical zero-day (CVE-2026-85046) in the Chrome V8 engine. The flaw is actively exploited in the wild for RCE. Update to version 152.0.7977.82/.83 immediately to protect against attacks. #Chrome #ZeroDay #CyberSecurity
##Actively exploited sandbox RCE in all Chromium versions: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) https://nvd.nist.gov/vuln/detail/cve-2026-85046
So you don't even need a JS? just a crafted HTML page? Lmao. So much bloated code running and on top of that now we have an AI generated code. Security is gonna be a nightmare for most people
##updated 2026-09-06T00:31:04
1 posts
🔴 CVE-2026-86151 - Critical (9.1)
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86151/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T00:31:04
1 posts
🔴 CVE-2026-86148 - Critical (9.1)
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86148/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T00:31:03
1 posts
🔴 CVE-2026-86149 - Critical (9.1)
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86149/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T21:31:20
12 posts
3 repos
https://github.com/HORKimhab/CVE-2026-67276
https://github.com/BlackHatExploitation/exploit-mikrotik-2026
Critical vulnerabilities in MikroTik RouterOS are being actively exploited
CERT Polska는 MikroTik RouterOS의 6개 취약점을 공개했으며, 이 중 SSH 인증 우회(CVE-2026-67276)와 조작된 사용자명을 통한 권한 상승(CVE-2026-86060)을 연결한 ‘MikroTrick’ 체인이 인터넷에 노출된 장비에서 실제 악용되고 있다고 경고했습니다. 두 취약점 모두 CVSS 9.2이며, 인증 없이 RouterOS 장비의 완전한 관리자 권한을 탈취할 수 있어 AI 서비스·ML 인프라의 엣지 라우터 및 원격 관리 네트워크에도 직접적인 위험입...
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
##📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit
🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity
##PoC Released for Actively-Exploited MikroTik Unauth SSH Device Takeover
공개된 PoC는 MikroTik RouterOS의 SSH 공개키 인증 처리 결함(CVE-2026-67276)을 악용해, 대상 계정의 RSA 공개 모듈러스만 알면 개인키 없이 인증을 우회하고 명령을 실행할 수 있음을 보여줍니다. 이 취약점은 CERT PL이 ‘MikroTrick’ 체인의 일부로 공개한 6개 RouterOS 취약점 중 하나이며, 인터넷에 노출된 SSH를 통해 전체 장비 장악으로 이어질 수 있는 실제 악용 사례가 보고됐습니다. 검증 결과 RouterOS 7.23.3에서는 위조된 e=1 RSA 키 인증이 성공했고 7.23.4에서는 차단됐으며, 7.24.2·7.23.4·6...
##⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…
🤖 AI generated summary
##📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit
🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity
##⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…
🤖 AI generated summary
##📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit
🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity
##That is a full wipe, you absolute liability.
Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.
Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.
#CyberSecurity #MikroTik #RouterOS #Vulnerability #PrivilegeEscalation #AdminAccessUnlocked (2/2)
##🏆 New Achievement! MikroTik and Chill (No Password Required)!
MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)
##The MikroTrick PoC is publicly disclosed. This MikroTrick RouterOS flaw is actively exploited in the wild, granting full administrative privileges.
#MikroTrick #RouterOS #CVE202667276 #CyberSecurity #Vulnerability
##RouterOS SSH public-key authentication bypass (CVE-2026-67276) https://github.com/dinosn/mikrotrick-poc
##https://db.gcve.eu/vuln/cve-2026-67276
ahahahaha
##updated 2026-09-05T21:31:20
3 posts
New.
Rapid7: CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/ @Rapid7Official #infosec #vulnerability #threatresearch
##New.
Rapid7: CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/ @Rapid7Official #infosec #vulnerability #threatresearch
##Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.
Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)
##updated 2026-09-05T21:31:20
4 posts
⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…
🤖 AI generated summary
##⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…
🤖 AI generated summary
##That is a full wipe, you absolute liability.
Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.
Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.
#CyberSecurity #MikroTik #RouterOS #Vulnerability #PrivilegeEscalation #AdminAccessUnlocked (2/2)
##🏆 New Achievement! MikroTik and Chill (No Password Required)!
MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)
##updated 2026-09-05T15:30:31
1 posts
🔴 CVE-2026-86189 - Critical (9.8)
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86189/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T15:30:26
1 posts
🔴 CVE-2026-86190 - Critical (9.1)
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86190/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T12:31:34
1 posts
🔴 CVE-2026-10196 - Critical (9.8)
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10196/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T12:31:34
1 posts
🟠 CVE-2025-9049 - High (8.8)
The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-9049/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T12:31:34
1 posts
🟠 CVE-2026-86185 - High (8)
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inje...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86185/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T21:31:59
1 posts
CVE-2026-80112: PassMark tools (PerformanceTest, BurnInTest, OSForensics) have an improper access control flaw in DirectIo64.sys, letting unprivileged users run privileged hardware IOCTLs. CVSS 7.8. Unpatched—limit exposure now. Details: https://www.valtersit.com/cve/CVE-2026-801
##updated 2026-09-04T21:31:48
1 posts
CVE-2026-75160: Critical flaw in X-Serie Gateway Firmware V6_00_05 allows remote privilege escalation via /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. CVSS 9.1. Unpatched—assume exposure. Isolate devices, restrict access, monitor logs now. Details: https://www.valtersit.com/
##updated 2026-09-04T18:31:46
1 posts
CVE-2026-85654: Amazon awslabs.dynamodb-mcp-server < 2.1.6 has an RCE risk via template injection in the CDK generator. Crafted table/index/attribute names in a model file can execute arbitrary code during deployment. CVSS 7.8. No patch yet. Isolate deploy hosts and avoid untrust
##updated 2026-09-04T18:31:26
1 posts
🟠 CVE-2026-19298 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19298/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:26
1 posts
🟠 CVE-2026-19283 - High (7.7)
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19283/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:26
1 posts
🔴 CVE-2026-18658 - Critical (9.8)
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18658/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:26
1 posts
🟠 CVE-2026-19300 - High (7.5)
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19300/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:20
1 posts
🟠 CVE-2026-18905 - High (7.7)
IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18905/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T17:16:57.160000
1 posts
WooCommerce CVE-2026-57777 carries a CVSS score of 7.6 and lets a low-privilege user, a free subscriber, manipulate their own role to gain full admin access. Any store below version 11.0 is exposed. I have written up what the vulnerability involves and the steps I recommend taking to address it.
#WordPress #WooCommerce #SecurityHardening #CVE #WordPressSecurity
https://wpguy.uk/blog/woocommerce-cve-2026-57777-fix-privilege-escalation-now/
##updated 2026-09-04T15:36:24
1 posts
🔴 CVE-2026-85695 - Critical (9.4)
FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious worker...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T15:36:23
1 posts
Postgres MCP Pro Restricted-Mode Bypass Allows Arbitrary Host File Disclosure
Postgres MCP Pro version 0.3.0 contains a critical restricted-mode bypass (CVE-2026-85620) that allows unauthenticated attackers to read arbitrary files from the database host. The flaw is caused by an incomplete SQL validation in the Abstract Syntax Tree parser, enabling the execution of dangerous functions through FROM clauses.
**If you're running Crystal DBA's Postgres MCP Pro (version 0.3.0 or earlier), don't rely on its restricted mode to keep your AI agents in check. It can be bypassed to read files off your server, including passwords and private keys. Change the database account the MCP server uses to a least-privilege role, strip its superuser status and `pg_read_server_files` permission, and keep it off the internet until an official fix ships.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/postgres-mcp-pro-restricted-mode-bypass-allows-arbitrary-host-file-disclosure-t-6-8-7-8/gD2P6Ple2L
updated 2026-09-04T14:17:21.387000
1 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-09-04T00:31:11
1 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-09-03T15:33:10
2 posts
2 repos
Cette faille Proxmox corrigée en 2023 est activement exploitée (CVE-2023-54391) https://www.it-connect.fr/proxmox-ve-cve-2023-54391-contournement-authentification/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Proxmox
##Cette faille Proxmox corrigée en 2023 est activement exploitée (CVE-2023-54391) https://www.it-connect.fr/proxmox-ve-cve-2023-54391-contournement-authentification/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Proxmox
##updated 2026-09-03T15:17:33.993000
1 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-09-02T18:32:32
2 posts
New advisories from Cisco addressing two high and medium-severity vulnerabilities.
New: CVE-2026-20293: Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW
Known: CVE-2026-20354 and CVE-2026-20355: Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities @TalosSecurity #infosec #vulnerability #Cisco
##New advisories from Cisco addressing two high and medium-severity vulnerabilities.
New: CVE-2026-20293: Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW
Known: CVE-2026-20354 and CVE-2026-20355: Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities @TalosSecurity #infosec #vulnerability #Cisco
##updated 2026-09-02T18:32:31
2 posts
New advisories from Cisco addressing two high and medium-severity vulnerabilities.
New: CVE-2026-20293: Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW
Known: CVE-2026-20354 and CVE-2026-20355: Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities @TalosSecurity #infosec #vulnerability #Cisco
##New advisories from Cisco addressing two high and medium-severity vulnerabilities.
New: CVE-2026-20293: Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW
Known: CVE-2026-20354 and CVE-2026-20355: Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities @TalosSecurity #infosec #vulnerability #Cisco
##updated 2026-09-02T18:32:26
1 posts
1 repos
🏆 New Achievement! Root of All Evil: The Nexus Awakens!
PHASE TWO HAS BEGUN. CVE-2026-20212 stalks the arena — a CVSS 9.8 critical flaw in Cisco Nexus 9000 Series Switches running Silicon One ASICs. It requires no credentials, no user interaction, nothing. An attacker simply crafts input to TCP ports 43210 or 43211, exposed by default, and ascends to root. Full device compromise. Network disruption. Lateral movement through your data center like a speedrunner who memorized the map. (1/2)
##updated 2026-09-01T15:30:53
2 posts
1 repos
A critical Microsoft Exchange vulnerability (CVE-2026-62911) leaves thousands of servers unpatched, while AI-assisted ransomware now compromises networks in under 10 hours. OpenAI released GPT-6 Astra, advancing Artificial General Intelligence. Geopolitically, Ukrainian drones struck Russia's Taganrog airbase overnight (Sept 6-7).
##A critical Microsoft Exchange vulnerability (CVE-2026-62911) leaves thousands of servers unpatched, while AI-assisted ransomware now compromises networks in under 10 hours. OpenAI released GPT-6 Astra, advancing Artificial General Intelligence. Geopolitically, Ukrainian drones struck Russia's Taganrog airbase overnight (Sept 6-7).
##updated 2026-09-01T12:31:48
1 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-08-31T20:56:08.800000
1 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-08-31T15:34:50
1 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-08-31T12:30:37
1 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-08-31T12:30:37
1 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-08-31T12:30:36
1 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-08-31T12:30:32
1 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-08-28T22:53:42
2 posts
14 repos
https://github.com/Red-Darkin/CVE-2026-18963-keycloak
https://github.com/EQSTLab/CVE-2026-18963
https://github.com/minh3102011/CVE-2026-18963_analyst
https://github.com/gman0x00/keycloak-CVE-2026-18963
https://github.com/M4xSec/My-Exploits
https://github.com/prot0tw/Keycloak_CVE-2026-18963_PoC
https://github.com/T0w0T/POC-CVE-2026-18963
https://github.com/BlackHatExploitation/Exploit-For-CVE-2026-18963
https://github.com/kyos-public/keycloak-cve-2026-18963-hunt
https://github.com/ynsmroztas/KeySniper
https://github.com/0xlyvio/CVE-2026-18963-keycloak
https://github.com/alt3kx/CVE-2026-18963
Two critical Siemens vulnerabilities (CVE-2026-18963, CVE-2026-50093) allow account takeover and root access. See affected versions and fixes.
#Siemens #CyberSecurity #ICS #OTSecurity #CVE #IndustrialEdge #Vulnerability #InfoSec
##Two critical Siemens vulnerabilities (CVE-2026-18963, CVE-2026-50093) allow account takeover and root access. See affected versions and fixes.
#Siemens #CyberSecurity #ICS #OTSecurity #CVE #IndustrialEdge #Vulnerability #InfoSec
##updated 2026-08-27T21:31:19
1 posts
1 repos
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53362 – Linux Kernel Unspecified Vulnerability
Active exploitation of Linux kernel vulnerability CVE-2026-53362 threatens enterprise infrastructure. Read our C-Suite threat intelligence brief for mitigation strategies....
##updated 2026-08-20T15:34:03
2 posts
1 repos
Hackers are actively exploiting CVE-2026-19490, a critical authentication bypass vulnerability in Citrix NetScaler. Update your systems immediately.
#CitrixNetScaler #CyberSecurity #Vulnerability #NetworkSecurity #Infosec
##Threat Actors Target Critical Citrix NetScaler Authentication Bypass
Citrix NetScaler ADC and Gateway appliances face active exploitation of a critical authentication bypass (CVE-2026-19490) that allows unauthenticated attackers to access internal applications and VPN services.
**Your NetScaler appliances are now under attack, so act fast. Patch ASAP and check your logs for any unusual logins from the past few weeks. Even if you patch now, an attacker might have already created a back door while the system was open. And make sure to isolate the management interface from the internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/threat-actors-target-critical-citrix-netscaler-authentication-bypass-p-f-z-7-1/gD2P6Ple2L
updated 2026-08-20T12:48:31.843000
1 posts
6 repos
https://github.com/Boreas37/CVE-2026-32475-PoC
https://github.com/4minx/CVE-2026-32475
https://github.com/0xBlackash/CVE-2026-32475
https://github.com/dinosn/cve-2026-32475-elementor-pro-lab
https://github.com/sahmsec/CVE-2026-32475
https://github.com/absholi7ly/Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE
⚠️ CRITICAL: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are actively exploiting two critical RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475), with over 440,000 exploit attempts already blocked. Unauthenticated attackers can upload arbitrary files including PHP web shells to gain full…
🤖 AI generated summary
##updated 2026-08-19T18:32:28
2 posts
2 repos
A Windows Defender 0day has public PoC exploit code. ShieldCrash reads files as SYSTEM on all supported Windows versions.
#WindowsDefender #0day #CVE #ShieldCrash #CyberSecurity #Windows #PoC #Infosec
##A Windows Defender 0day has public PoC exploit code. ShieldCrash reads files as SYSTEM on all supported Windows versions.
#WindowsDefender #0day #CVE #ShieldCrash #CyberSecurity #Windows #PoC #Infosec
##updated 2026-08-13T15:34:37
1 posts
2 repos
https://github.com/goldendivider/cve-2026-6471-postgres-logical-decoding-dlopen
PostgreSQL fixed CVE-2026-6471, an authorization flaw in logical decoding that lets users with REPLICATION privilege load arbitrary shared libraries. Code executes as the server OS user, typically postgres, enabling full host compromise from a low-privileged DB role. #PostgreSQL #AccessControl #CodeExecution
https://cyberworldops.eu/en/postgresql-logical-decoding-flaw-allows-code-execution-as-the-postgres
##updated 2026-08-11T18:31:23
2 posts
2 repos
A Windows HTTP.sys vulnerability, CVE-2026-62735 (CVSS 7.8), now has public details and a PoC. It escalates local users to SYSTEM. Patch now.
#Windows #HTTPsys #CVE202662735 #PrivilegeEscalation #Pwn2Own #SYSTEM #Infosec #PoC
##A Windows HTTP.sys vulnerability, CVE-2026-62735 (CVSS 7.8), now has public details and a PoC. It escalates local users to SYSTEM. Patch now.
#Windows #HTTPsys #CVE202662735 #PrivilegeEscalation #Pwn2Own #SYSTEM #Infosec #PoC
##updated 2026-08-06T18:31:32
3 posts
@ohunt I can't speak to the CFAA since I'm no lawyer. Exploitation in this exact scenario isn't a valid classifier either since the underlying vuln of CVE-2026-13230 is a lack of meaningful protection, it equates to intercepting HTTP at this point. Ask and receive. However the protocol that operates on UDP 9999 has been broken for about 10 years now and has an RCE vuln on a different device class.
##@ohunt I can't speak to the CFAA since I'm no lawyer. Exploitation in this exact scenario isn't a valid classifier either since the underlying vuln of CVE-2026-13230 is a lack of meaningful protection, it equates to intercepting HTTP at this point. Ask and receive. However the protocol that operates on UDP 9999 has been broken for about 10 years now and has an RCE vuln on a different device class.
##The LG TV network scanning story breaking today includes UDP 9999 Kasa discovery broadcasts every 25 seconds. That's the exact port I documented in CVE-2026-13230 as returning unauthenticated precise GPS coordinates from Kasa cameras with no authentication. Any LG TV + unpatched Kasa camera on the same network = GPS harvesting every 25 seconds. @briankrebs Advisory: https://github.com/BadChemical/IoT-Vulnerability-Research-Public/blob/main/TP-Link_Kasa_EC71/Kasa_EC71.md
##updated 2026-07-23T12:32:53
2 posts
4 repos
https://github.com/anyanything/CVE-2026-8461-PoC
https://github.com/HORKimhab/CVE-2026-8461
https://ubuntu.com/security/CVE-2026-8461
https://nvd.nist.gov/vuln/detail/cve-2026-8461
为什么你要把实例迁移到gentoo上
https://ubuntu.com/security/CVE-2026-8461
https://nvd.nist.gov/vuln/detail/cve-2026-8461
为什么你要把实例迁移到gentoo上
updated 2026-07-14T20:28:19
1 posts
CVE-2026-61699: Unpatched flaw in nebula-mesh (<0.7.1) lets a revoked host keep full VPN access for up to 365d. Attackers with stolen keys can bypass blocklists—no patch yet (CVSS 8.1). Isolate compromised hosts manually now. Details: https://www.valtersit.com/cve/CVE-2026-61699/
##updated 2026-07-14T15:31:59
1 posts
46 repos
https://github.com/g0thamRabb1t/CVE-2026-43284-dirtyfrag-detection
https://github.com/cyber-niz/Dirty-Frag
https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester
https://github.com/0xBlackash/CVE-2026-43284
https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4
https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan
https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284
https://github.com/FrosterDL/CVE-2026-43284
https://github.com/cumakurt/linuxpi
https://github.com/metalx1993/dirtyfrag-patches
https://github.com/lukeslp/redtail-ioc
https://github.com/millikanjohnl-blip/dirtyfrag-detection-rules
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/dixyes/dirtypatch
https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag
https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284
https://github.com/linnemanlabs/dirtyfrag-arm64
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/nonameuserosint-hue/DirtyFrag-go
https://github.com/MadExploits/CVE-2026-46300
https://github.com/AK777177/Dirty-Frag-Analysis
https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284
https://github.com/1neptune/DirtyFrag
https://github.com/0xlane/pagecache-guard
https://github.com/nabhan-mohy/Dirty-Frag-Research-CVE-2026-43284-
https://github.com/RevyHub/CVE-2026-43284---DirtyFrag-Analysis-THM-
https://github.com/kuniyal08/Dirty-Frag-CVE-2026-43284
https://github.com/XRSecCD/202605_dirty_frag
https://github.com/haydenjames/dirty-frag-check
https://github.com/t1ckprivate/CVE-2026-43284-Dirty-Frag
https://github.com/First-John/cve_2026_frag_family_fix
https://github.com/liamromanis101/DirtyFrag-Detector
https://github.com/attaattaatta/CVE-2026-43500
https://github.com/suominen/CVE-2026-43284
https://github.com/aettern/copyfrag-fuse
https://github.com/xd20111/CVE-2026-43284
https://github.com/LucasPDiniz/CVE-2026-43284
https://github.com/jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC
https://github.com/ryan2929/CVE-2026-43284-
https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC
https://github.com/Aiyakami/rust_dirtyfrag
https://github.com/LSPosed/LSPromise
https://github.com/ChernStepanov/DirtyFrag-for-dummies
https://github.com/armircetaj/tetragon-dirtyfrag
🐧 SIGINT // Linux Watch — 2026-09-08
A local root escalation with public PoC code and Ubuntu already shipping fixed package versions — translation: patch your kernels this week, not next quarter.
##updated 2026-07-10T06:31:28
1 posts
3 repos
https://github.com/1beelze/CVE-2026-14894
⚠️ CRITICAL: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are actively exploiting two critical RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475), with over 440,000 exploit attempts already blocked. Unauthenticated attackers can upload arbitrary files including PHP web shells to gain full…
🤖 AI generated summary
##updated 2026-07-09T21:00:06
1 posts
CVE-2026-52770 - YesWiki <4.6.6 has unauthenticated SQL injection in Bazar APIs (CVSS 7.5). Attackers can extract database data via boolean queries. No patch available. If you run YesWiki, restrict API access or isolate immediately. Details: https://www.valtersit.com/cve/CVE-2026
##updated 2026-07-09T20:58:34
1 posts
CVE-2026-52769: YesWiki 4.6.2–4.6.6 SSRF via HTTP Signature keyId in public API. Unauthenticated attacker forces server-side GET to arbitrary URLs. CVSS 8.3. Unpatched—update to 4.6.6 or restrict access now. Details: https://www.valtersit.com/cve/CVE-2026-52769/ #CVE #YesWiki #in
##updated 2026-06-17T09:07:06.787000
2 posts
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
#CVE_2025_25249 #PivotC2
https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
#CVE_2025_25249 #PivotC2
https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
updated 2026-06-09T12:33:04
2 posts
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
#CVE_2025_25249 #PivotC2
https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
#CVE_2025_25249 #PivotC2
https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
updated 2026-06-01T18:31:32
4 posts
1 repos
Feels like a Monday when you open the inbox and see "Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more".
https://www.openwall.com/lists/oss-security/2026/09/08/1
Various exploits/PoCs here:
https://github.com/NebuSec/CyberMeowfia/tree/main/security-research
While I don't know how widespread the use of RDS is, it's the "and 20 more" that kills me. Pretty much assuming shell access == root access at this point.
##The details and PoC exploit code for the ZcopyReaper Linux vulnerability (CVE-2026-43502) are publicly disclosed, posing a privilege escalation risk.
#ZcopyReaper #CVE202643502 #LinuxKernel #CyberSecurity #PrivilegeEscalation
##Feels like a Monday when you open the inbox and see "Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more".
https://www.openwall.com/lists/oss-security/2026/09/08/1
Various exploits/PoCs here:
https://github.com/NebuSec/CyberMeowfia/tree/main/security-research
While I don't know how widespread the use of RDS is, it's the "and 20 more" that kills me. Pretty much assuming shell access == root access at this point.
##The details and PoC exploit code for the ZcopyReaper Linux vulnerability (CVE-2026-43502) are publicly disclosed, posing a privilege escalation risk.
#ZcopyReaper #CVE202643502 #LinuxKernel #CyberSecurity #PrivilegeEscalation
##updated 2026-03-31T18:31:25
1 posts
Hackers Deploy Linux Rootkit via F5 BIG-IP Flaw
Hackers are exploiting a critical F5 BIG-IP flaw, known as CVE-2025-53521, to deploy a sneaky Linux rootkit that allows them to execute code on vulnerable servers. This alarming attack vector has already exposed 795 endpoints online, putting countless systems at risk.
#F5Bigip #Cve202553521 #LinuxRootkit #RemoteCodeExecution #Rce
##updated 2026-03-12T03:31:06
1 posts
@mttaggart @jerry @ifin Well, this isn't a good start. The link attached to CVE-2026-22769 returns a 404.
But the CVE-2023-41974 link is solid https://cybertop.ai/t/cve-2023-41974-apple-ios-and-ipados-use-after-free-vulnerability
##updated 2026-02-18T18:30:35
1 posts
@mttaggart @jerry @ifin Well, this isn't a good start. The link attached to CVE-2026-22769 returns a 404.
But the CVE-2023-41974 link is solid https://cybertop.ai/t/cve-2023-41974-apple-ios-and-ipados-use-after-free-vulnerability
##updated 2025-10-22T00:32:19
2 posts
2 repos
Last month we made a bit of history, and for once it wasn't a CVE. We were the first Romanian company ever to have a booth at DEF CON, showing AI Pentests, powered by Specter, to a room full of people whose entire job is finding what's wrong with things. Still in beta, early access is open now.
What else happened in August, you asked?
🎯 Sniper added a new exploit for CVE-2021-35464, a five-year-old RCE in Forgerock OpenAM that's still alive in the wild. As always, if Sniper can exploit it, the Network Scanner can detect it.
🌐 155 new detections in the Network Scanner, 70 of them critical, prioritized by CVSS, EPSS, and CISA KEV.
🤖 AI is picking up more of the boring work: the Password Auditor now finds stubborn login forms on its own, and Ping, our AI-based assistant moved from the website straight into the product.
🔌 The findings API can now update risk and verified status, findings carry a ransomware-campaign flag straight from CISA, and you can create your account in the US region if data residency matters to you.
Full breakdown in the video: https://pentest-tools.com/change-log
Early access to AI Pentests: https://pentest-tools.com/discover-ai-pentests
Until next time: stay sharp, stay human.
##Last month we made a bit of history, and for once it wasn't a CVE. We were the first Romanian company ever to have a booth at DEF CON, showing AI Pentests, powered by Specter, to a room full of people whose entire job is finding what's wrong with things. Still in beta, early access is open now.
What else happened in August, you asked?
🎯 Sniper added a new exploit for CVE-2021-35464, a five-year-old RCE in Forgerock OpenAM that's still alive in the wild. As always, if Sniper can exploit it, the Network Scanner can detect it.
🌐 155 new detections in the Network Scanner, 70 of them critical, prioritized by CVSS, EPSS, and CISA KEV.
🤖 AI is picking up more of the boring work: the Password Auditor now finds stubborn login forms on its own, and Ping, our AI-based assistant moved from the website straight into the product.
🔌 The findings API can now update risk and verified status, findings carry a ransomware-campaign flag straight from CISA, and you can create your account in the US region if data residency matters to you.
Full breakdown in the video: https://pentest-tools.com/change-log
Early access to AI Pentests: https://pentest-tools.com/discover-ai-pentests
Until next time: stay sharp, stay human.
##updated 2025-03-25T14:00:04
1 posts
23 repos
https://github.com/HaGsec/CVE-2025-30208
https://github.com/MiclelsonCN/CVE-2025-30208_POC
https://github.com/ThemeHackers/CVE-2025-30208
https://github.com/0xshaheen/CVE-2025-30208
https://github.com/Lusensec/CVE-2025-30208
https://github.com/imbas007/CVE-2025-30208-template
https://github.com/nkuty/CVE-2025-30208-31125-31486-32395
https://github.com/r0ngy40/CVE-2025-30208-Series
https://github.com/keklick1337/CVE-2025-30208-ViteVulnScanner
https://github.com/sumeet-darekar/CVE-2025-30208
https://github.com/ThumpBo/CVE-2025-30208-EXP
https://github.com/TH-SecForge/CVE-2025-30208
https://github.com/xuemian168/CVE-2025-30208
https://github.com/On1onss/CVE-2025-30208
https://github.com/4xura/CVE-2025-30208
https://github.com/marino-admin/Vite-CVE-2025-30208-Scanner
https://github.com/4m3rr0r/CVE-2025-30208-PoC
https://github.com/cc3305/CVE-2025-30208
https://github.com/jackieya/ViteVulScan
https://github.com/lilil3333/Vite-CVE-2025-30208-EXP
https://github.com/iSee857/CVE-2025-30208-PoC
#Blog #Security
Tient tient du monde essaye de trouver https://www.offsec.com/blog/cve-2025-30208/
Comme /@fs/home/ec2-user/.aws/credentials
Les scanners de vulnérabilité ... y en a TOUT le temps
updated 2024-12-12T06:30:56
2 posts
If you are running All-in-One WP Migration and Backup — over 5 million sites do — you need to check your version now. CVE-2024-11015 allows full admin takeover with no credentials required. That is about as serious as it gets. My advice: patch immediately and audit your user accounts.
#WordPress #WebSecurity #SecurityHardening #WordPressPlugin #CyberSecurity
https://wpguy.uk/blog/critical-wordpress-backup-plugin-flaw-risks-site-takeover/
##If you are running All-in-One WP Migration and Backup — over 5 million sites do — you need to check your version now. CVE-2024-11015 allows full admin takeover with no credentials required. That is about as serious as it gets. My advice: patch immediately and audit your user accounts.
#WordPress #WebSecurity #SecurityHardening #WordPressPlugin #CyberSecurity
https://wpguy.uk/blog/critical-wordpress-backup-plugin-flaw-risks-site-takeover/
##🔴 CVE-2026-85982 - Critical (9)
The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify dir...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85982/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-85982 - Critical (9)
The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify dir...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85982/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##A critical CVE-2026-67401 cPanel SQL injection flaw in EmailTrack allows authenticated users to gain full control of the server. Patch your system today.
#cPanel #SQLInjection #CVE202667401 #Cybersecurity #Vulnerability
##A critical CVE-2026-67401 cPanel SQL injection flaw in EmailTrack allows authenticated users to gain full control of the server. Patch your system today.
#cPanel #SQLInjection #CVE202667401 #Cybersecurity #Vulnerability
##CISA advisory ICSA-26-251-01 documents CVE-2026-85083 in CareCam Pro ANJIA AJL33PC0801: hard-coded bootloader credential allows privileged access with physical presence. It enables firmware modification and persistent compromise, undermining trust in affected deployments. #HardcodedCredentials #IotSecurity #FirmwareSecurity
https://cyberworldops.eu/en/hard-coded-bootloader-credential-exposes-carecam-pro-camera-to-full
##CISA advisory ICSA-26-251-01 documents CVE-2026-85083 in CareCam Pro ANJIA AJL33PC0801: hard-coded bootloader credential allows privileged access with physical presence. It enables firmware modification and persistent compromise, undermining trust in affected deployments. #HardcodedCredentials #IotSecurity #FirmwareSecurity
https://cyberworldops.eu/en/hard-coded-bootloader-credential-exposes-carecam-pro-camera-to-full
##Apache Nutch vulnerabilities include CVE-2026-41870, an unauthenticated remote code execution flaw. See affected versions and fixes.
#ApacheNutch #RCE #CVE #Vulnerability #InfoSec #WebCrawler #CyberSecurity #PatchNow
##Apache Nutch vulnerabilities include CVE-2026-41870, an unauthenticated remote code execution flaw. See affected versions and fixes.
#ApacheNutch #RCE #CVE #Vulnerability #InfoSec #WebCrawler #CyberSecurity #PatchNow
##🔴 CVE-2026-53939 - Critical (9.1)
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53939/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-53939 - Critical (9.1)
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53939/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-53581 (CRITICAL, CVSS 9.0): OPNsense core <26.1.9 NTP module path traversal lets privileged users overwrite files as root. Upgrade to 26.1.9+ & backend 26.4_20+ now. https://radar.offseq.com/threat/cve-2026-53581-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-35f8611179753b8a #OffSeq #OPNsense #Vuln #PathTraversal
##🔴 CVE-2026-53581 - Critical (9)
OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53581/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-53581 (CRITICAL, CVSS 9.0): OPNsense core <26.1.9 NTP module path traversal lets privileged users overwrite files as root. Upgrade to 26.1.9+ & backend 26.4_20+ now. https://radar.offseq.com/threat/cve-2026-53581-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-35f8611179753b8a #OffSeq #OPNsense #Vuln #PathTraversal
##🔴 CVE-2026-53581 - Critical (9)
OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53581/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Finally, CVE-2026-69304, a Denial of Service in the component that runs ASP.NET Core applications under IIS.
Prioritize this, starting with your front facing IIS web servers that run ASP.NET Core apps.
Microsoft Security Advisory CV...
CVE-2026-69522 - Another MSDIA OOB, this time leading to RCE. As with the previous it's mostly developers at risk.
Microsoft Security Advisory CV...
CVE-2026-61686 - SolidInvoice pre-3.0.1 deserializes client-controlled 'context' prop via unserialize(), enabling authenticated RCE. CVSS 7.5. No patch? Update to 3.0.1 now if available, or isolate. https://www.valtersit.com/cve/CVE-2026-61686/ #CVE #infosec #SolidInvoice
##Fortinet fixed three critical Fortinet vulnerabilities. Attackers can exploit CVE-2026-84390 and CVE-2026-26084 to access corporate data.
#Fortinet #Vulnerabilities #Cybersecurity #InfoSec #PatchManagement
##Fortinet fixed three critical Fortinet vulnerabilities. Attackers can exploit CVE-2026-84390 and CVE-2026-26084 to access corporate data.
#Fortinet #Vulnerabilities #Cybersecurity #InfoSec #PatchManagement
##2 posts
6 repos
https://github.com/atiilla/CVE-2026-85046
https://github.com/SneakyNachos/CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm
https://github.com/Eliot-code/CVE-2026-85046
https://github.com/HORKimhab/CVE-2026-85046
⚪️ Chrome fixes sixth zero-day vulnerability this year
🗨️ Google developers have released an update for the Chrome browser that fixes 12 vulnerabilities, including an actively exploited zero-day flaw in the V8 engine (CVE-2026-85046). The bug allows attackers to achieve arbitrary code execution through a specially crafted HTML page.…
##⚪️ Chrome fixes sixth zero-day vulnerability this year
🗨️ Google developers have released an update for the Chrome browser that fixes 12 vulnerabilities, including an actively exploited zero-day flaw in the V8 engine (CVE-2026-85046). The bug allows attackers to achieve arbitrary code execution through a specially crafted HTML page.…
##CVE-2026-85781 (CVSS 8.7): Unpatched flaw in Amazon EFS CSI Driver <v3.4.1 lets authenticated K8s users with PV creation rights trigger recursive deletion on unauthorized EFS filesystems via crafted volumeHandle. Upgrade to v3.4 now. Details: https://www.valtersit.com/cve/CVE-202
##🟠 CVE-2026-75021 - High (8.1)
fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debugging inter...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75021/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75021 - High (8.1)
fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debugging inter...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75021/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-63464 - SSRF in nebula-mesh VPN control plane. Low-privilege users can bypass SSRF guards, forcing server to hit internal resources. CVSS 7.7. Unpatched—update or restrict access now. Details: https://www.valtersit.com/cve/CVE-2026-63464/ #CVE #infosec #cybersecurity
##2 posts
1 repos
https://github.com/Mav3r1ck0x1/Chrome-and-Edge-Version-Dumper
RE: https://mastodon.online/@rozie/117224244824728530
Eteryu stara się przedstawić swoje tezy jako wynik rzetelnej analizy, jego tekst zawiera elementy dezinformacji, wybiórcze traktowanie faktów oraz jednostronne podejście do omawianych kwestii.
Jak na moje oko, Baza wiedzy Eteryu space – jest jedynie kopią, niestety mocno okrojoną i uproszczoną. Szczegóły w dalszej częśći tekstu, wraz ze zródłami oraz zrzutami ekranu.
🧵 1/2
Baza Wiedzy Eteryu
PODWÓJNE STANDARDY W OCENIE CHROME I BRAVE
Eteryu twierdzi, że Chrome na PC jest ‘czystszym wyborem’ dzięki izolacji procesów, ale celowo bagatelizuje ryzyko związane z telemetrią Chrome.
Błędne założenie o izolacji procesów
Chrome oferuje ‘niezrównaną izolację procesów’, w rzeczywistości wiele przeglądarek opartych na Chromium stosuje identyczne mechanizmy, takie jak: Site Isolation (izolacja stron w osobnych procesach), Process-per-site-instance (osobny proces dla każdej instancji strony). Różnice w izolacji wynikają głównie z ustawień domyślnych (np. Chrome domyślnie włącza Site Isolation, podczas gdy niektóre forki wymagają ręcznej konfiguracji). Przedstawia Chrome jako wyjątkowego lidera, podczas gdy w praktyce wiele przegląddek Chromium osiąga podobnypoziom bezpieczeństwa.
Niespójność w ocenie Brave jest ‘wysoce zalecany’ na Androidzie ze względu na możliwość wyłączenia JIT w V8, co rzekomo ‘amputuje główny wektor ataków’. To prawda, ale częściowa. Wyłączenie JIT nie jest unikalne dla Brave , każdy użytkownik Chromium może to zrobić ręcznie (np. poprzez flagi –disable-jit). JIT nie jest jedynym wektorem ataków, luki w V8 (np. CVE-2022-1096) były wykorzystywane w atakach nawet z wyłączonym JIT. Eteryu przedstawia rozwiązanie jako panaceum, podczas gdy realne bezpieczeństwo wymaga szerszego podejścia. Brave jest dobrą opcją, ale nie ze względu na ‘wyłączanie JIT’, a raczej dzięki blokowaniu reklam, trackerów i lepszej ochronie prywatności. Tak, “zbędne” funkcje w Brave (jak moduły krypto czy AI) można ręcznie wyłączyć, celowo pomijane, by przedstawić przeglądarkę jako “skomplikowaną”. W rzeczywistości Brave jest bardziej konfigurowalny niż Chrome dzięki lepszej obsłudze rozszerzeń i flag.
AKTUALIZACJE
Chrome jako ‘upstream’ otrzymuje łatki krytyczne ‘natychmiast’, podczas gdy forki muszą je synchronizować. To półprawda. Chrome nie jest jedynym projektem upstream: Chromium (na którym bazuje Chrome) jest open source i wszystkie przeglądarki oparte na Chromium otrzymują łatki w tym samym czasie. Różnice wynikają jedynie z czasu potrzebnego na kompilację i testowanie własnych modyfikacji.
NAJWIĘKSZY PROBLEM TKWI W IGNOROWANIU REALNYCH ALTERNATYW NA DESKTOPIE.
Chrome jest “zawsze lepszy”, ale: Edge (również Chromium) ma lepszą integrację z Windows (ochrona przed phishingiem, lepsze zarządzanie pamięcią) i jest domyślnie instalowany na wielu maszynach.
Przeglądarka Edge zdobyła nawet uznanie wśród autorów treści, którymi Eteryu zdaje się posiłkować. Można tam przeczytać że przeglądarka Edge na Windows, oferuje większe bezpieczeństwo od Chrome i nawet stawia się ją obok przeglądarek Vanadium (GrapheneOS), oraz Trivalent (Secureblue) jednak zwraca się uwagę na problemem z telemetrią.
Safari na MacOS oferuje lepszą izolację procesów niż Chrome dzięki głębszej integracji z systemem i mniejsze ryzyko zero-day (mniejsza baza użytkowników = mniej celów dla ataków).
Czy Eteryu celowo pomija te przeglądarki, by promować Chrome? Choć Edge i Safari są technicznie lepsze w swoich ekosystemach. Jak widać jest to wybiórcza, analiza skupia się na jednym ignorując szerszy kontekst bezpieczeństwa i wydajności.
Podsumowując: To nie jest “ścisła analiza”, tylko subiektywna ocena oparta na preferencjach. Dla prawdziwie bezpiecznej przeglądarki na desktopie lepszym wyborem byłoby Edge (Windows), Safari (Mac). Brave często cenony jest za blokowanie reklam i trackerów.
Linux
Rzeczywistość jest bardziej złożona:
Więcej
👇
2/2 poniżej
~
##RE: https://mastodon.online/@rozie/117224244824728530
Eteryu stara się przedstawić swoje tezy jako wynik rzetelnej analizy, jego tekst zawiera elementy dezinformacji, wybiórcze traktowanie faktów oraz jednostronne podejście do omawianych kwestii.
Jak na moje oko, Baza wiedzy Eteryu space – jest jedynie kopią, niestety mocno okrojoną i uproszczoną. Szczegóły w dalszej częśći tekstu, wraz ze zródłami oraz zrzutami ekranu.
🧵 1/2
Baza Wiedzy Eteryu
PODWÓJNE STANDARDY W OCENIE CHROME I BRAVE
Eteryu twierdzi, że Chrome na PC jest ‘czystszym wyborem’ dzięki izolacji procesów, ale celowo bagatelizuje ryzyko związane z telemetrią Chrome.
Błędne założenie o izolacji procesów
Chrome oferuje ‘niezrównaną izolację procesów’, w rzeczywistości wiele przeglądarek opartych na Chromium stosuje identyczne mechanizmy, takie jak: Site Isolation (izolacja stron w osobnych procesach), Process-per-site-instance (osobny proces dla każdej instancji strony). Różnice w izolacji wynikają głównie z ustawień domyślnych (np. Chrome domyślnie włącza Site Isolation, podczas gdy niektóre forki wymagają ręcznej konfiguracji). Przedstawia Chrome jako wyjątkowego lidera, podczas gdy w praktyce wiele przegląddek Chromium osiąga podobnypoziom bezpieczeństwa.
Niespójność w ocenie
Brave jest ‘wysoce zalecany’ na Androidzie ze względu na możliwość wyłączenia JIT w V8, co rzekomo ‘amputuje główny wektor ataków’. To prawda, ale częściowa. Wyłączenie JIT nie jest unikalne dla Brave , każdy użytkownik Chromium może to zrobić ręcznie (np. poprzez flagi –disable-jit). JIT nie jest jedynym wektorem ataków, luki w V8 (np. CVE-2022-1096) były wykorzystywane w atakach nawet z wyłączonym JIT. Eteryu przedstawia rozwiązanie jako panaceum, podczas gdy realne bezpieczeństwo wymaga szerszego podejścia. Brave jest dobrą opcją, ale nie ze względu na ‘wyłączanie JIT’, a raczej dzięki blokowaniu reklam, trackerów i lepszej ochronie prywatności. Tak, “zbędne” funkcje w Brave (jak moduły krypto czy AI) można ręcznie wyłączyć, celowo pomijane, by przedstawić przeglądarkę jako “skomplikowaną”. W rzeczywistości Brave jest bardziej konfigurowalny niż Chrome dzięki lepszej obsłudze rozszerzeń i flag.
AKTUALIZACJE
Chrome jako ‘upstream’ otrzymuje łatki krytyczne ‘natychmiast’, podczas gdy forki muszą je synchronizować. To półprawda. Chrome nie jest jedynym projektem upstream: Chromium (na którym bazuje Chrome) jest open source i wszystkie przeglądarki oparte na Chromium otrzymują łatki w tym samym czasie. Różnice wynikają jedynie z czasu potrzebnego na kompilację i testowanie własnych modyfikacji.
NAJWIĘKSZY PROBLEM TKWI W IGNOROWANIU REALNYCH ALTERNATYW NA DESKTOPIE.
Chrome jest “zawsze lepszy”, ale: Edge (również Chromium) ma lepszą integrację z Windows (ochrona przed phishingiem, lepsze zarządzanie pamięcią) i jest domyślnie instalowany na wielu maszynach.
Przeglądarka Edge zdobyła nawet uznanie wśród autorów treści, którymi Eteryu zdaje się posiłkować. Można tam przeczytać że przeglądarka Edge na Windows, oferuje większe bezpieczeństwo od Chrome i nawet stawia się ją obok przeglądarek Vanadium (GrapheneOS), oraz Trivalent (Secureblue) jednak zwraca się uwagę na problemem z telemetrią.
Safari na MacOS oferuje lepszą izolację procesów niż Chrome dzięki głębszej integracji z systemem i
mniejsze ryzyko zero-day (mniejsza baza użytkowników = mniej celów dla ataków).
Czy Eteryu celowo pomija te przeglądarki, by promować Chrome? Choć Edge i Safari są technicznie lepsze w swoich ekosystemach. Jak widać jest to wybiórcza, analiza skupia się na jednym ignorując szerszy kontekst bezpieczeństwa i wydajności.
Podsumowując: To nie jest “ścisła analiza”, tylko subiektywna ocena oparta na preferencjach. Dla prawdziwie bezpiecznej przeglądarki na desktopie lepszym wyborem byłoby Edge (Windows), Safari (Mac). Brave często cenony jest za blokowanie reklam i trackerów.
Linux
Rzeczywistość jest bardziej złożona:
Więcej poniżej👇
##A Dell Secure Connect Gateway vulnerability (CVE-2026-80172, CVSS 9.8) grants unauthorized access via forged admin tokens. Patch SCG now.
#Dell #SecureConnectGateway #CVE202680172 #RCE #UnauthorizedAccess #PatchNow #Infosec #SCG
https://securityonline.info/dell-scg-cve-2026-80172/?utm_source=mastodon&utm_medium=jetpack_social
##A Dell Secure Connect Gateway vulnerability (CVE-2026-80172, CVSS 9.8) grants unauthorized access via forged admin tokens. Patch SCG now.
#Dell #SecureConnectGateway #CVE202680172 #RCE #UnauthorizedAccess #PatchNow #Infosec #SCG
https://securityonline.info/dell-scg-cve-2026-80172/?utm_source=mastodon&utm_medium=jetpack_social
##CISA reports CVE-2026-77477 in OPCFoundation UA-LDS-Installers before 1.04.420. A local attacker can abuse the elevated installer session to execute arbitrary commands as SYSTEM. This puts OT discovery hosts at risk of full compromise during deployment. #OpcUa #OtSecurity #IcsSecurity
https://cyberworldops.eu/en/opc-ua-lds-privileged-console-in-installer-exposes-industrial
##