## Updated at UTC 2026-09-26T16:42:55.983477

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-96533 0 0.14% 2 0 2026-09-26T07:17:03.630000 The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-
CVE-2026-18143 9.8 0.41% 4 1 2026-09-26T07:17:02.017000 The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitr
CVE-2026-89325 7.8 0.13% 1 0 2026-09-26T04:17:49.963000 An uncontrolled search path element in InsightVM assessment content in Rapid7 In
CVE-2026-87902 8.1 18.17% 6 20 2026-09-26T04:17:49.733000 An unauthenticated attacker can make `get_page_template()` page-template resolut
CVE-2026-67279 6.5 1.03% 4 2 2026-09-26T04:17:47.273000 RouterOS SSH enters the connection protocol after a client-requested rekey even
CVE-2026-65660 8.8 2.10% 6 2 2026-09-26T04:17:45.630000 Improper control of generation of code ('code injection') in Microsoft Office Sh
CVE-2026-100575 8.8 0.26% 4 0 2026-09-26T03:30:36 OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlis
CVE-2026-100596 8.8 0.25% 2 0 2026-09-26T03:30:36 OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users exe
CVE-2026-100560 7.5 0.58% 2 0 2026-09-26T03:30:35 OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability
CVE-2026-100567 8.2 0.25% 2 0 2026-09-26T03:30:35 OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versi
CVE-2026-100580 8.8 0.34% 2 0 2026-09-26T03:30:35 OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensit
CVE-2026-100578 7.6 0.23% 2 0 2026-09-26T03:30:35 OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only i
CVE-2026-100586 8.8 0.25% 2 0 2026-09-26T03:30:35 OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization whe
CVE-2026-100585 8.0 0.19% 2 0 2026-09-26T03:30:35 OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-onl
CVE-2026-100582 6.5 0.21% 1 0 2026-09-26T03:30:35 OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix,
CVE-2026-100559 8.0 0.25% 2 0 2026-09-26T03:30:34 OpenClaw versions before 2026.8.1 contain a command parser vulnerability where e
CVE-2026-100558 7.5 0.28% 2 0 2026-09-26T03:30:34 OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in
CVE-2026-100589 8.3 0.32% 2 0 2026-09-26T03:30:29 OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the
CVE-2026-100597 7.8 0.08% 2 0 2026-09-26T03:30:29 OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-che
CVE-2026-100532 8.1 0.27% 2 0 2026-09-26T03:30:28 @openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through
CVE-2026-100541 7.5 0.30% 2 0 2026-09-26T03:30:28 OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.
CVE-2026-100535 7.5 0.26% 2 0 2026-09-26T03:30:28 OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose t
CVE-2026-100544 8.8 0.25% 2 0 2026-09-26T03:30:28 openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured
CVE-2026-100587 8.8 0.25% 2 0 2026-09-26T03:30:28 OpenClaw versions before 2026.7.1 fail to properly validate owner authorization
CVE-2026-100543 7.5 0.35% 2 0 2026-09-26T03:30:25 OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hash
CVE-2026-100551 8.3 0.17% 4 0 2026-09-26T03:30:25 OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gatew
CVE-2026-100599 8.8 0.30% 2 0 2026-09-26T03:17:08.667000 OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec ap
CVE-2026-100588 8.3 0.30% 2 0 2026-09-26T03:17:06.963000 OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administr
CVE-2026-100579 7.6 0.23% 2 0 2026-09-26T03:17:05.633000 OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester p
CVE-2026-100570 7.8 0.13% 2 0 2026-09-26T03:17:04.177000 OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an
CVE-2026-100568 8.3 0.25% 2 0 2026-09-26T03:17:03.887000 OpenClaw versions before 2026.8.1 fail to properly restrict access to operator c
CVE-2026-100561 8.0 0.25% 2 0 2026-09-26T03:17:02.987000 OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain a
CVE-2026-100557 8.3 0.24% 2 0 2026-09-26T03:17:02.387000 OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability
CVE-2026-100552 8.8 0.26% 2 0 2026-09-26T03:17:01.640000 OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per
CVE-2026-100520 8.8 0.94% 2 0 2026-09-26T01:17:00.357000 Laranode versions before 1.2.1 contain a path traversal vulnerability in the POS
CVE-2026-96795 8.8 0.30% 1 0 2026-09-25T23:16:55.020000 Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data i
CVE-2026-100382 0 0.95% 3 0 2026-09-25T22:17:10.150000 Improper Neutralization of Special Elements used in an OS Command ('OS Command I
CVE-2026-100368 8.4 0.58% 2 0 2026-09-25T21:41:49 ### Impact An OS command injection vulnerability exists in the PowerShell and Cm
CVE-2026-100369 8.4 0.36% 2 0 2026-09-25T21:41:37 ### Impact An argument-injection vulnerability exists in the `CliInvoke` package
CVE-2026-100390 7.4 0.29% 1 0 2026-09-25T21:33:12 Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the
CVE-2026-10758 7.5 0.33% 1 0 2026-09-25T21:33:12 Esri LERC is an open-source image or raster format which supports rapid encoding
CVE-2026-5267 7.5 0.36% 2 0 2026-09-25T21:33:11 Ciena Navigator Network Control Suite (NCS) contains an information exposure vul
CVE-2026-100208 7.5 0.35% 2 0 2026-09-25T21:33:06 Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorize
CVE-2026-97063 9.1 0.29% 2 0 2026-09-25T21:33:06 X-SpringBoot through 6.0 returns login verification codes in HTTP responses from
CVE-2026-97064 9.1 0.30% 2 0 2026-09-25T21:33:03 X-SpringBoot through 6.0 ships with a hardcoded static master login verification
CVE-2026-91766 5.9 0.34% 1 0 2026-09-25T21:17:24.673000 When the http:// stream wrapper follows a redirect it forwards the user-supplied
CVE-2026-57443 7.5 0.57% 1 0 2026-09-25T21:17:23.413000 SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting
CVE-2026-100391 8.2 0.31% 1 0 2026-09-25T21:17:22.800000 MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerabili
CVE-2026-100389 8.1 0.57% 3 0 2026-09-25T21:17:22.483000 GestSup versions before 3.2.61 contain a remote code execution vulnerability in
CVE-2026-100387 8.1 0.32% 1 0 2026-09-25T21:17:22.163000 pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in d
CVE-2026-91841 7.8 0.19% 2 0 2026-09-25T18:31:36 A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A loca
CVE-2026-91840 7.8 0.19% 2 0 2026-09-25T18:31:36 A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unpri
CVE-2026-91839 7.8 0.20% 2 0 2026-09-25T18:31:36 A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for Netwo
CVE-2026-91838 7.8 0.10% 2 0 2026-09-25T18:31:36 A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager.
CVE-2026-91837 7.8 0.14% 2 0 2026-09-25T18:31:35 A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkMana
CVE-2026-89032 7.7 0.27% 2 0 2026-09-25T18:31:35 BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerabi
CVE-2026-94445 8.8 0.36% 2 0 2026-09-25T18:17:33.730000 A malicious txtar could escape the intended execution context and force arbitrar
CVE-2026-95699 9.6 0.30% 1 0 2026-09-25T17:17:20.097000 Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant auth
CVE-2026-92161 9.8 0.27% 2 0 2026-09-25T16:17:29.387000 FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Fac
CVE-2026-92573 6.5 0.29% 1 0 2026-09-25T15:32:45 Improper handling of compressed data in the shared GZIP decompressor used for AM
CVE-2026-92609 9.8 0.38% 1 0 2026-09-25T15:32:40 Session fixation in HTTP management authentication allows remote attackers to ga
CVE-2026-57440 7.5 0.26% 1 0 2026-09-25T15:03:43 ### Summary With $wgEmbedVideoRequireConsent disabled (not the default), the url
CVE-2026-89055 9.1 0.39% 2 1 2026-09-25T14:17:21.510000 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to autho
CVE-2026-62062 8.8 0.13% 1 1 2026-09-25T14:17:18.807000 Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder all
CVE-2026-19804 8.8 1.04% 1 0 2026-09-25T14:17:18.497000 The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywa
CVE-2026-97433 8.2 0.32% 1 0 2026-09-25T13:17:26.930000 In the Linux kernel, the following vulnerability has been resolved: nvme: valid
CVE-2026-97428 7.7 0.14% 1 0 2026-09-25T13:17:26.390000 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu:
CVE-2026-77294 8.1 0.31% 1 0 2026-09-25T13:17:26.220000 TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authentic
CVE-2026-86857 0 0.24% 1 0 2026-09-25T13:17:16.663000 ServiceNow has remediated an authorization bypass security issue that was identi
CVE-2026-96883 8.8 0.65% 1 0 2026-09-25T13:16:34.693000 pgcollection is an open source extension to PostgreSQL. A type confusion issue i
CVE-2026-93399 9.1 0.37% 2 1 2026-09-25T13:08:26.930000 The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Referenc
CVE-2026-71362 9.1 87.51% 3 1 2026-09-25T12:53:15.757000 Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
CVE-2026-5430 10.0 0.59% 5 2 2026-09-25T12:53:05.517000 The JWT authentication mechanism accepts tokens signed with algorithms other tha
CVE-2026-92564 None 0.19% 1 0 2026-09-25T09:31:16 A pre-authentication attacker could leverage type nesting to cause a StackOverfl
CVE-2026-89426 8.8 0.47% 1 0 2026-09-25T09:31:16 The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPre
CVE-2026-89406 7.5 0.39% 1 0 2026-09-25T09:31:16 The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vu
CVE-2026-92713 8.1 0.27% 1 0 2026-09-25T09:31:15 The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vu
CVE-2026-14281 9.8 0.53% 1 2 2026-09-25T09:31:05 The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Co
CVE-2026-97444 7.7 0.14% 1 0 2026-09-25T06:31:36 In the Linux kernel, the following vulnerability has been resolved: ACPICA: add
CVE-2026-97448 7.7 0.14% 1 0 2026-09-25T06:31:35 In the Linux kernel, the following vulnerability has been resolved: ACPICA: Add
CVE-2026-97497 7.8 0.13% 1 0 2026-09-25T06:31:35 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd:
CVE-2026-97508 7.5 0.21% 1 0 2026-09-25T06:31:35 In the Linux kernel, the following vulnerability has been resolved: thunderbolt
CVE-2026-97445 7.7 0.15% 1 0 2026-09-25T06:31:34 In the Linux kernel, the following vulnerability has been resolved: ACPICA: Enh
CVE-2026-97442 8.8 0.24% 1 0 2026-09-25T06:31:34 In the Linux kernel, the following vulnerability has been resolved: wifi: ath11
CVE-2026-97452 8.4 0.14% 1 0 2026-09-25T06:31:34 In the Linux kernel, the following vulnerability has been resolved: ACPICA: Pre
CVE-2026-97478 7.8 0.12% 1 0 2026-09-25T06:31:34 In the Linux kernel, the following vulnerability has been resolved: virt: acrn:
CVE-2026-97513 7.8 0.11% 1 0 2026-09-25T06:31:34 In the Linux kernel, the following vulnerability has been resolved: media: chip
CVE-2026-97735 8.0 0.25% 1 0 2026-09-25T06:31:21 ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/tick
CVE-2026-97451 8.4 0.14% 1 0 2026-09-25T06:31:19 In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix
CVE-2026-97818 8.6 0.32% 1 0 2026-09-25T06:31:16 phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all"
CVE-2026-97509 8.8 0.24% 1 0 2026-09-25T05:17:07.410000 In the Linux kernel, the following vulnerability has been resolved: thunderbolt
CVE-2026-97455 8.4 0.14% 1 0 2026-09-25T05:17:06.673000 In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix
CVE-2026-97454 7.7 0.14% 1 0 2026-09-25T05:17:06.553000 In the Linux kernel, the following vulnerability has been resolved: ACPICA: add
CVE-2026-97450 8.4 0.14% 1 0 2026-09-25T05:17:06.200000 In the Linux kernel, the following vulnerability has been resolved: ACPICA: val
CVE-2026-93577 9.9 0.43% 2 0 2026-09-25T04:17:49.330000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
CVE-2026-89078 9.9 0.36% 3 0 2026-09-25T04:17:48.843000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
CVE-2026-86860 0 0.30% 1 0 2026-09-25T04:17:48.557000 ServiceNow has remediated a missing authorization vulnerability that was identif
CVE-2026-82157 8.3 0.12% 1 0 2026-09-25T04:17:48.060000 Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Im
CVE-2026-19072 9.9 0.40% 2 0 2026-09-25T04:17:34.920000 Velociraptor stores the compiled VQL in the hunt object internally to avoid havi
CVE-2026-97730 8.5 1.03% 1 0 2026-09-25T03:31:07 In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File I
CVE-2026-96512 7.8 0.13% 1 2 2026-09-24T21:33:41 A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-base
CVE-2026-81630 8.1 0.19% 2 0 2026-09-24T21:33:02 The Botslab G980H dash camera firmware does not adequately verify the authentici
CVE-2026-81473 8.1 0.09% 1 0 2026-09-24T21:32:59 Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper
CVE-2026-93289 7.5 0.68% 2 0 2026-09-24T21:32:59 The affected products are vulnerable to command injection attack that could allo
CVE-2026-86858 None 0.27% 1 0 2026-09-24T21:32:59 ServiceNow has remediated an improper access control security issue that was ide
CVE-2026-77967 8.1 0.24% 1 0 2026-09-24T21:32:58 The Botslab G980H dash camera firmware accepts a reusable authentication value w
CVE-2026-85496 8.8 0.25% 1 0 2026-09-24T21:32:58 The Botslab G980H dash camera firmware generates session identifiers using a sma
CVE-2026-84399 8.8 0.19% 1 0 2026-09-24T21:32:58 The Botslab G980H dash camera firmware contains an authorization vulnerability i
CVE-2026-93354 8.1 0.27% 1 0 2026-09-24T21:32:58 Taskview Community before 1.56.0 contains a missing authentication vulnerability
CVE-2026-13248 8.8 0.44% 1 0 2026-09-24T21:32:57 An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec
CVE-2026-13249 9.8 0.57% 1 1 2026-09-24T21:32:57 An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability
CVE-2026-81455 8.6 0.26% 1 0 2026-09-24T21:32:57 Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Miss
CVE-2026-86859 None 0.29% 1 0 2026-09-24T21:32:57 ServiceNow has remediated an authorization bypass security issue that was identi
CVE-2026-13016 None 0.27% 1 0 2026-09-24T21:32:57 ServiceNow has remediated a SQL injection vulnerability that was identified in t
CVE-2026-91127 8.2 0.40% 1 0 2026-09-24T21:25:27.050000 File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other
CVE-2026-93291 9.4 0.24% 3 0 2026-09-24T21:25:27.050000 Omni C20 lacks proper certificate validation which could allow an attacker to pe
CVE-2026-82566 8.8 0.28% 1 0 2026-09-24T21:25:27.050000 The Botslab G980H dash camera firmware contains a session management vulnerabili
CVE-2026-97362 7.5 0.29% 1 0 2026-09-24T21:08:55.030000 HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that a
CVE-2026-97057 7.5 0.39% 1 0 2026-09-24T21:08:55.030000 redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP
CVE-2026-77874 8.6 0.43% 1 0 2026-09-24T19:41:16.513000 IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.
CVE-2026-81549 9.6 0.26% 1 0 2026-09-24T19:41:16.513000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-81548 8.8 0.75% 1 0 2026-09-24T19:41:16.513000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-81539 8.8 0.44% 1 0 2026-09-24T19:41:16.513000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-78312 9.1 0.34% 1 0 2026-09-24T19:39:45.600000 Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022
CVE-2026-78311 8.8 0.24% 1 0 2026-09-24T19:39:45.600000 SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: befor
CVE-2026-57590 8.1 0.23% 1 0 2026-09-24T19:36:39.327000 A missing authorization vulnerability exists in the Task Group APIs of Apache Do
CVE-2026-61741 9.3 0.29% 1 0 2026-09-24T19:35:18 http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that pars
CVE-2026-56737 8.1 0.40% 1 0 2026-09-24T19:29:30 ### Summary The public two-factor verification endpoint `POST /check` logs a use
CVE-2026-75907 7.5 0.36% 1 0 2026-09-24T19:17:16.220000 The door access control on a Norwegian Cruise Line asset grants entry based only
CVE-2026-61825 8.7 0.22% 1 0 2026-09-24T19:17:15.500000 code16 Sharp is a Laravel-based framework for building content-management and ad
CVE-2026-61816 7.5 0.39% 1 0 2026-09-24T19:17:15.240000 zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* funct
CVE-2026-95985 8.8 0.14% 1 0 2026-09-24T18:31:48 The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remot
CVE-2026-85056 8.2 0.29% 1 0 2026-09-24T18:19:36 ### Summary A vulnerability in ZITADEL’s Login V2 UI allowed a password-verifie
CVE-2026-85057 8.7 0.39% 1 0 2026-09-24T18:19:04.360000 ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13
CVE-2026-61782 7.5 0.36% 1 0 2026-09-24T18:17:16.333000 Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to v
CVE-2026-77581 8.6 0.27% 1 0 2026-09-24T16:17:10.943000 BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlie
CVE-2026-63203 7.6 0.31% 1 0 2026-09-24T16:17:08.837000 Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From
CVE-2026-81547 8.8 0.92% 1 0 2026-09-24T15:31:42 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-82093 8.8 0.41% 1 0 2026-09-24T15:31:42 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-90959 8.1 0.32% 1 0 2026-09-24T15:31:42 A path traversal vulnerability was found in pulpcore. The content upload API acc
CVE-2026-58008 8.1 0.11% 1 0 2026-09-24T15:31:41 Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allo
CVE-2026-58007 8.1 0.11% 1 0 2026-09-24T15:31:41 Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS al
CVE-2026-81545 8.8 0.85% 1 0 2026-09-24T15:31:41 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-97360 10.0 0.32% 1 0 2026-09-24T15:31:40 HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access
CVE-2026-81552 8.8 0.75% 1 0 2026-09-24T15:31:36 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-95521 7.8 0.58% 1 0 2026-09-24T15:31:35 A command injection flaw was found in rpm. Installing or rebuilding a source RPM
CVE-2026-95519 7.8 0.14% 1 0 2026-09-24T15:31:35 A flaw was found in rpm. An attacker can supply a crafted manifest file that, wh
CVE-2026-97359 10.0 0.78% 1 0 2026-09-24T15:31:33 HFS2 version 2.4.0 and earlier contains a template injection vulnerability in th
CVE-2026-97059 8.2 0.35% 1 0 2026-09-24T15:31:32 DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoad
CVE-2026-80513 7.5 0.31% 1 0 2026-09-24T14:42:02.707000 The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes m
CVE-2026-77193 7.5 0.36% 1 0 2026-09-24T09:32:00 The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Pa
CVE-2026-97185 7.8 0.13% 1 0 2026-09-24T09:32:00 A flaw was found in GIMP. When processing a specially crafted GIMPressionist pre
CVE-2026-85682 8.8 0.14% 1 0 2026-09-24T09:32:00 The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in al
CVE-2026-85102 9.8 0.99% 2 0 2026-09-23T18:22:07.453000 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-71418 7.5 0.63% 1 0 2026-09-23T18:12:04.247000 Suricata is a network Intrusion Detection System, Intrusion Prevention System an
CVE-2026-63452 7.5 0.63% 1 0 2026-09-23T18:12:04.247000 Suricata is a network Intrusion Detection System, Intrusion Prevention System an
CVE-2026-93616 9.8 19.65% 2 1 2026-09-23T16:38:38.987000 A directory traversal and file upload vulnerability allows an unauthenticated at
CVE-2026-84081 8.1 0.31% 1 0 2026-09-23T04:17:55.267000 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-32996 0 0.17% 1 1 2026-09-23T04:17:43.927000 This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privile
CVE-2026-93676 3.2 0.14% 1 0 2026-09-22T23:17:08.413000 xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configure
CVE-2026-87766 8.8 0.15% 1 0 2026-09-22T23:17:07.763000 A flaw was found in bubblewrap. During sandbox setup, creating files or director
CVE-2026-28324 9.8 0.65% 2 0 2026-09-22T21:31:34 SolarWinds Observability Self-Hosted was found to be affected by an unauthentica
CVE-2026-94127 9.8 2.23% 7 2 2026-09-22T21:31:17 When a BIG-IP APM access policy and an OAuth profile is configured on a virtual
CVE-2026-84108 8.1 0.63% 1 0 2026-09-22T19:32:25.730000 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-11727 8.1 0.44% 1 0 2026-09-22T19:32:25.730000 IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remo
CVE-2026-84036 7.4 0.34% 1 0 2026-09-22T19:32:25.730000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2025-39964 7.8 1.00% 2 3 2026-09-19T04:17:48.307000 In the Linux kernel, the following vulnerability has been resolved: crypto: af_
CVE-2026-84241 8.1 0.47% 1 0 2026-09-18T21:32:40 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-91843 9.8 0.52% 1 1 2026-09-16T15:31:14 A stack overflow during the unauthenticated login process may allow an attacker
CVE-2026-19624 7.8 0.13% 1 0 2026-09-14T21:31:45 A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled V
CVE-2026-34223 8.2 0.19% 1 0 2026-09-14T14:17:07.503000 A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versio
CVE-2026-9176 6.7 0.16% 1 0 2026-09-10T21:31:46 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass
CVE-2026-86296 10.0 1.70% 1 0 2026-09-08T17:18:39.613000 A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affe
CVE-2026-63077 9.8 9.76% 1 6 template 2026-08-05T18:32:31 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-35273 9.8 9.44% 4 4 2026-07-23T09:10:00.113000 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS
CVE-2026-39808 9.8 47.36% 1 6 2026-07-16T18:32:24 A improper neutralization of special elements used in an os command ('os command
CVE-2026-23239 7.8 0.10% 1 0 2026-06-17T10:21:09.960000 In the Linux kernel, the following vulnerability has been resolved: espintcp: F
CVE-2022-38694 7.8 0.60% 1 15 2026-06-17T04:57:02.183000 In BootRom, there is a possible unchecked write address. This could lead to loca
CVE-2026-0257 9.1 96.38% 1 8 template 2026-06-09T12:32:02 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of
CVE-2026-48842 8.1 0.89% 3 1 2026-06-04T00:31:26 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authenticat
CVE-2026-42608 None 0.52% 1 0 2026-05-13T13:52:36 # Vulnerability Report: Grav CMS Unauthenticated Path Traversal & Arbitrary File
CVE-2026-39813 9.8 0.72% 1 2 2026-04-14T18:30:41 A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 thro
CVE-2025-13032 9.9 0.25% 7 0 2025-11-11T18:30:23 Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows a
CVE-2026-76654 0 0.00% 1 0 N/A
CVE-2026-2270 0 0.00% 1 0 N/A
CVE-2026-61818 0 0.51% 1 0 N/A
CVE-2026-91765 0 0.52% 1 0 N/A
CVE-2026-100000 0 0.00% 1 0 N/A
CVE-2026-63645 0 0.33% 1 0 N/A
CVE-2026-71540 0 0.35% 1 0 N/A
CVE-2026-96749 0 0.13% 1 0 N/A
CVE-2026-82989 0 0.00% 1 0 N/A
CVE-2026-79417 0 0.00% 1 1 N/A
CVE-2026-93425 0 0.62% 1 0 N/A

CVE-2026-96533
(0 None)

EPSS: 0.14%

updated 2026-09-26T07:17:03.630000

2 posts

The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.

offseq at 2026-09-26T12:00:25.555Z ##

CVE-2026-96533: HIGH severity SSRF in Testimonials Widget (<=4.0.4). Unauthenticated users can make the server fetch internal URLs, exposing responses 🛡️. Disable or restrict plugin until patched. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-26T12:00:25.000Z ##

CVE-2026-96533: HIGH severity SSRF in Testimonials Widget (<=4.0.4). Unauthenticated users can make the server fetch internal URLs, exposing responses 🛡️. Disable or restrict plugin until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #SSRF #Infosec

##

CVE-2026-18143
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-09-26T07:17:02.017000

4 posts

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied filename directly as the destination for `move_uploaded_file()`. This makes it p

1 repos

https://github.com/murrez/CVE-2026-18143

thehackerwire@mastodon.social at 2026-09-26T07:30:13.000Z ##

🔴 CVE-2026-18143 - Critical (9.8)

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type vali...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-26T07:30:22.972Z ##

CVE-2026-18143 | CRITICAL unrestricted file upload in Addify Request a Quote for WooCommerce (<=2.9.2). Unauth attackers can achieve RCE. Disable public quote rule/multi-page popup or restrict uploads. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-26T07:30:13.000Z ##

🔴 CVE-2026-18143 - Critical (9.8)

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type vali...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-26T07:30:22.000Z ##

CVE-2026-18143 | CRITICAL unrestricted file upload in Addify Request a Quote for WooCommerce (<=2.9.2). Unauth attackers can achieve RCE. Disable public quote rule/multi-page popup or restrict uploads. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #RCE

##

CVE-2026-89325
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-26T04:17:49.963000

1 posts

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Assessment content at or below version 0.0.261.0 included a check that invoked the `code` command without a fully qualified path from a process running as SYSTEM. The

thehackerwire@mastodon.social at 2026-09-25T05:16:37.000Z ##

🟠 CVE-2026-89325 - High (7.8)

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH.

Assessment con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

chun_log_jp@mastodon.social at 2026-09-26T10:06:28.000Z ##

WordPress 7.1.1に更新したばかりでもCVE-2026-87902への対応が必要です。
7.1.1で修正されたClick2Shellとは別のWordPressコアの脆弱性です。
未ログインの第三者が細工したpagenameを送ることで条件次第でテーマ外のPHPファイルをテンプレートとして読み込ませられます。
コード実行にはテーマの構造や悪用できるPHPファイル、PHP設定など追加の条件があります。
「ダッシュボード」→「更新」で7.1系は7.1.2、旧系列は対応する修正版が適用済みか確認を。
公開当日から攻撃リクエストが観測されています。更新前の影響が気になる場合はアクセスログや不審なPHPファイルも調べてください。
chunlog.jp/wordpress-7-1-2-cve
#WordPress #PHP #セキュリティ

##

undercodenews@mastodon.social at 2026-09-26T08:42:02.000Z ##

WordPress Under Attack: Critical Core Flaw Exploited in the Wild as CISA Orders Emergency Patching + Video

A Decade-Old WordPress Vulnerability Becomes an Active Threat A critical security vulnerability in WordPress Core has been added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog after evidence emerged that attackers are actively exploiting the flaw. Tracked as CVE-2026-87902, the vulnerability…

undercodenews.com/wordpress-un

##

rhudaur@flipboard.com at 2026-09-25T21:01:15.000Z ##

WordPress Patch Became Exploit Blueprint: CVE-2026-87902 Webshells Hit 350K Sites
techtimes.com/articles/328042/

Posted into Cybersecurity Today @cybersecurity-today-rhudaur

##

cisakevtracker@mastodon.social at 2026-09-25T20:00:51.000Z ##

CVE ID: CVE-2026-87902
Vendor: WordPress
Product: Core
Date Added: 2026-09-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

threatcodex@infosec.exchange at 2026-09-24T17:18:06.000Z ##

CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch
#CVE_2026_87902
patchstack.com/articles/cve-20

##

security_crawler_carl@infosec.exchange at 2026-09-24T14:29:50.000Z ##

🏆 New Achievement! The Court Finds Your Server Guilty!

This tribunal has reviewed the evidence. CVE-2026-87902 — an unauthenticated path traversal flaw scoring 9.2 out of 10 — was discovered by researcher Robert Ressl and patched in WordPress 7.1.2. Attackers began probing within five hours of that patch dropping. Exhibit A: Patchstack logged the first malicious requests at 17:44 UTC on September 22. (1/3)

##

CVE-2026-67279
(6.5 MEDIUM)

EPSS: 1.03%

updated 2026-09-26T04:17:47.273000

4 posts

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support

2 repos

https://github.com/HackSpeak/CVE-2026-67279

https://github.com/gagaltotal/CVE-2026-mikrotik-poc

AAKL@infosec.exchange at 2026-09-25T17:13:12.000Z ##

CISA has updated the catalogue.

- CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability cisa.gov/known-exploited-vulne

- CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability cve.org/CVERecord?id=CVE-2026-

Yesterday:

- CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability #Microsoft #Adobe

##

secdb@infosec.exchange at 2026-09-25T17:00:12.000Z ##

🚨 [CISA-2026:0925] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-65660 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SharePoint Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SharePoint
- Notes: msrc.microsoft.com/update-guid ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-67279 (secdb.nttzen.cloud/cve/detail/)
- Name: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260925 #cisa20260925 #cve_2026_65660 #cve_2026_67279 #cve202665660 #cve202667279

##

cisakevtracker@mastodon.social at 2026-09-25T16:00:58.000Z ##

CVE ID: CVE-2026-67279
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cR0w@infosec.exchange at 2026-09-25T15:32:09.000Z ##

cisa.gov/news-events/alerts/20

  • CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability

  • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

##

CVE-2026-65660
(8.8 HIGH)

EPSS: 2.10%

updated 2026-09-26T04:17:45.630000

6 posts

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

2 repos

https://github.com/ShadowForge-Cyber/CVE-2026-65660-Poc

https://github.com/HORKimhab/CVE-2026-65660

AAKL@infosec.exchange at 2026-09-25T17:13:12.000Z ##

CISA has updated the catalogue.

- CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability cisa.gov/known-exploited-vulne

- CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability cve.org/CVERecord?id=CVE-2026-

Yesterday:

- CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability #Microsoft #Adobe

##

secdb@infosec.exchange at 2026-09-25T17:00:12.000Z ##

🚨 [CISA-2026:0925] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-65660 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft SharePoint Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SharePoint
- Notes: msrc.microsoft.com/update-guid ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-67279 (secdb.nttzen.cloud/cve/detail/)
- Name: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260925 #cisa20260925 #cve_2026_65660 #cve_2026_67279 #cve202665660 #cve202667279

##

cisakevtracker@mastodon.social at 2026-09-25T16:01:14.000Z ##

CVE ID: CVE-2026-65660
Vendor: Microsoft
Product: SharePoint
Date Added: 2026-09-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cR0w@infosec.exchange at 2026-09-25T15:32:09.000Z ##

cisa.gov/news-events/alerts/20

  • CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability

  • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

##

cR0w@infosec.exchange at 2026-09-25T14:24:26.000Z ##

Go hunt on your SharePoint shit.

blog.previdian.com/cve-2026-65

Update September 25th, 2026: The exploitation creates a webshell backdoor named: "/_layouts/15/sphealth.aspx"

##

DailyCyberSecurity@infosec.exchange at 2026-09-25T08:15:27.000Z ##

An exploited SharePoint RCE vulnerability is under attack. Technical details for this SharePoint RCE vulnerability are public. Patch CVE-2026-65660 now.

#SharePoint #CVE202665660 #RCE #Cybersecurity #Infosec #ZeroDay

securityonline.info/exploited-

##

CVE-2026-100575
(8.8 HIGH)

EPSS: 0.26%

updated 2026-09-26T03:30:36

4 posts

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.

thehackerwire@mastodon.social at 2026-09-26T05:47:41.000Z ##

🟠 CVE-2026-100575 - High (8.8)

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-26T04:30:25.471Z ##

CVE-2026-100575 | HIGH severity | OpenClaw Slack (<2026.8.1): Missing authorization in multi-person DMs lets unauthorized users trigger Slack agents and access restricted tools/data. Patch to 2026.8.1+ now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-26T05:47:41.000Z ##

🟠 CVE-2026-100575 - High (8.8)

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-26T04:30:25.000Z ##

CVE-2026-100575 | HIGH severity | OpenClaw Slack (<2026.8.1): Missing authorization in multi-person DMs lets unauthorized users trigger Slack agents and access restricted tools/data. Patch to 2026.8.1+ now. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Infosec #Slack

##

CVE-2026-100596
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:30:36

2 posts

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.

thehackerwire@mastodon.social at 2026-09-26T03:46:38.000Z ##

🟠 CVE-2026-100596 - High (8.8)

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privil...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T03:46:38.000Z ##

🟠 CVE-2026-100596 - High (8.8)

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privil...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100560
(7.5 HIGH)

EPSS: 0.58%

updated 2026-09-26T03:30:35

2 posts

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without triggering new approval prompts, potentially accessing files or internal services.

thehackerwire@mastodon.social at 2026-09-26T07:00:56.000Z ##

🟠 CVE-2026-100560 - High (7.5)

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to exe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T07:00:56.000Z ##

🟠 CVE-2026-100560 - High (7.5)

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to exe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100567
(8.2 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:30:35

2 posts

OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gateway validated a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the raw WebSocket and Playwright transports performed a later, independent DNS resolution, discarding the DNS pinning enforced at validation time. An attacker who con

thehackerwire@mastodon.social at 2026-09-26T06:32:46.000Z ##

🟠 CVE-2026-100567 - High (8.2)

OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and &lt; 2026.8.1, the Gateway validated a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the raw We...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T06:32:46.000Z ##

🟠 CVE-2026-100567 - High (8.2)

OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and &lt; 2026.8.1, the Gateway validated a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the raw We...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100580
(8.8 HIGH)

EPSS: 0.34%

updated 2026-09-26T03:30:35

2 posts

OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to steer a tool-enabled agent can therefore create a persistent cron job that executes attacker-selected commands with the privileges of the OpenClaw proce

thehackerwire@mastodon.social at 2026-09-26T05:48:39.000Z ##

🟠 CVE-2026-100580 - High (8.8)

OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T05:48:39.000Z ##

🟠 CVE-2026-100580 - High (8.8)

OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100578
(7.6 HIGH)

EPSS: 0.23%

updated 2026-09-26T03:30:35

2 posts

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, a write-scoped non-owner caller can start a chat turn whose tool inventory includes the `gateway` and `cron` tools, causing the agent to invoke owner-onl

thehackerwire@mastodon.social at 2026-09-26T05:48:21.000Z ##

🟠 CVE-2026-100578 - High (7.6)

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T05:48:21.000Z ##

🟠 CVE-2026-100578 - High (7.6)

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100586
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:30:35

2 posts

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes.

thehackerwire@mastodon.social at 2026-09-26T03:47:54.000Z ##

🟠 CVE-2026-100586 - High (8.8)

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T03:47:54.000Z ##

🟠 CVE-2026-100586 - High (8.8)

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100585
(8.0 HIGH)

EPSS: 0.19%

updated 2026-09-26T03:30:35

2 posts

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel command access can approve or deny a pending permission request intended for the owner, causing the requested action to proceed without owner consent. The practica

thehackerwire@mastodon.social at 2026-09-26T03:47:46.000Z ##

🟠 CVE-2026-100585 - High (8)

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel command ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T03:47:46.000Z ##

🟠 CVE-2026-100585 - High (8)

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel command ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100582
(6.5 MEDIUM)

EPSS: 0.21%

updated 2026-09-26T03:30:35

1 posts

OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a steered agent with access to a channel read action can therefore retrieve content or m

offseq@infosec.exchange at 2026-09-26T03:00:25.000Z ##

CVE-2026-100582 (HIGH): openclaw msteams <2026.8.1 has a missing authorization flaw — low-trust users can bypass channel read allowlists and access restricted data. Patch to 2026.8.1 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #OpenClaw #Security

##

CVE-2026-100559
(8.0 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:30:34

2 posts

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and execute additional commands without expected authorization prompts.

thehackerwire@mastodon.social at 2026-09-26T06:45:37.000Z ##

🟠 CVE-2026-100559 - High (8)

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T06:45:37.000Z ##

🟠 CVE-2026-100559 - High (8)

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100558
(7.5 HIGH)

EPSS: 0.28%

updated 2026-09-26T03:30:34

2 posts

OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attackers can repeatedly send malformed upgrade requests to exhaust listener resources and cause denial of service without consuming the WebSocket pre-auth co

thehackerwire@mastodon.social at 2026-09-26T06:45:27.000Z ##

🟠 CVE-2026-100558 - High (7.5)

OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T06:45:27.000Z ##

🟠 CVE-2026-100558 - High (7.5)

OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100589
(8.3 HIGH)

EPSS: 0.32%

updated 2026-09-26T03:30:29

2 posts

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed agent input can select a paired node and perform host browser operations, inspecting or manipulating the connected browser profile and its authenticated s

thehackerwire@mastodon.social at 2026-09-26T03:47:37.000Z ##

🟠 CVE-2026-100589 - High (8.3)

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T03:47:37.000Z ##

🟠 CVE-2026-100589 - High (8.3)

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100597
(7.8 HIGH)

EPSS: 0.08%

updated 2026-09-26T03:30:29

2 posts

OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different filesystem target after OpenClaw completed its sandbox path-safety check, if the path is changed concurrently. An attacker able to win the race can cause a sandboxed

thehackerwire@mastodon.social at 2026-09-26T03:46:47.000Z ##

🟠 CVE-2026-100597 - High (7.8)

OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different filesystem ta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T03:46:47.000Z ##

🟠 CVE-2026-100597 - High (7.8)

OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different filesystem ta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100532
(8.1 HIGH)

EPSS: 0.27%

updated 2026-09-26T03:30:28

2 posts

@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender able to steer the tool can request a forced login and receive a new QR code for a configured account, disconnecting the Gateway's WhatsApp account and ca

thehackerwire@mastodon.social at 2026-09-26T07:30:57.000Z ##

🟠 CVE-2026-100532 - High (8.1)

@OpenClaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T07:30:57.000Z ##

🟠 CVE-2026-100532 - High (8.1)

@OpenClaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100541
(7.5 HIGH)

EPSS: 0.30%

updated 2026-09-26T03:30:28

2 posts

OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can normalize to the same authorization identity. A Matrix participant controlling a c

thehackerwire@mastodon.social at 2026-09-26T07:30:48.000Z ##

🟠 CVE-2026-100541 - High (7.5)

OpenClaw's Matrix integration (npm package @OpenClaw/matrix) versions >= 2026.2.2 and &lt; 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw au...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T07:30:48.000Z ##

🟠 CVE-2026-100541 - High (7.5)

OpenClaw's Matrix integration (npm package @OpenClaw/matrix) versions >= 2026.2.2 and &lt; 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw au...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100535
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-26T03:30:28

2 posts

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and dreaming are enabled, a restricted external sender whose messages are admitted with limited tools can persist instructions that are later supplied to

thehackerwire@mastodon.social at 2026-09-26T07:30:39.000Z ##

🟠 CVE-2026-100535 - High (7.5)

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and &lt; 2026.8.1 can lose the originating requester&#039;s restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T07:30:39.000Z ##

🟠 CVE-2026-100535 - High (7.5)

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and &lt; 2026.8.1 can lose the originating requester&#039;s restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100544
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:30:28

2 posts

openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose the agent's normal tool authority to a remote caller. A caller who is admitted by the configured inbound-call policy (open, pairing, or allowlist) on a dep

thehackerwire@mastodon.social at 2026-09-26T07:15:40.000Z ##

🟠 CVE-2026-100544 - High (8.8)

openclaw's @OpenClaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T07:15:40.000Z ##

🟠 CVE-2026-100544 - High (8.8)

openclaw's @OpenClaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100587
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:30:28

2 posts

OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary plugins and execute MCP processes with OpenClaw user privileges, affecting host confidentiality, integrity, and availability.

thehackerwire@mastodon.social at 2026-09-26T05:47:23.000Z ##

🟠 CVE-2026-100587 - High (8.8)

OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary plugins and execute MCP processes with OpenClaw user privileges, affect...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T05:47:23.000Z ##

🟠 CVE-2026-100587 - High (8.8)

OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary plugins and execute MCP processes with OpenClaw user privileges, affect...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100543
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-26T03:30:25

2 posts

OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as offline password verifiers: a caller able to obtain the redacted configuration (for example via config

thehackerwire@mastodon.social at 2026-09-26T07:15:31.000Z ##

🟠 CVE-2026-100543 - High (7.5)

OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T07:15:31.000Z ##

🟠 CVE-2026-100543 - High (7.5)

OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100551
(8.3 HIGH)

EPSS: 0.17%

updated 2026-09-26T03:30:25

4 posts

OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by

thehackerwire@mastodon.social at 2026-09-26T07:01:14.000Z ##

🟠 CVE-2026-100551 - High (8.3)

OpenClaw for iOS versions >= 2026.7.1 and &lt; 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-26T06:00:25.560Z ##

CVE-2026-100551: OpenClaw for iOS (>=2026.7.1, <2026.8.11) has a CRITICAL vuln in Control UI WebViews — TLS pins not enforced. Attackers can steal Gateway creds if they can redirect traffic. Patch to 2026.8.11 ASAP! radar.offseq.com/threat/opencl

##

thehackerwire@mastodon.social at 2026-09-26T07:01:14.000Z ##

🟠 CVE-2026-100551 - High (8.3)

OpenClaw for iOS versions >= 2026.7.1 and &lt; 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-26T06:00:25.000Z ##

CVE-2026-100551: OpenClaw for iOS (>=2026.7.1, <2026.8.11) has a CRITICAL vuln in Control UI WebViews — TLS pins not enforced. Attackers can steal Gateway creds if they can redirect traffic. Patch to 2026.8.11 ASAP! radar.offseq.com/threat/opencl #OffSeq #Vulnerability #iOS #AppSec

##

CVE-2026-100599
(8.8 HIGH)

EPSS: 0.30%

updated 2026-09-26T03:17:08.667000

2 posts

OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node without going through the normal system.run approval flow. In deployments with the Google Meet plugin enabled, a paired Chrome node, and the googlemeet.chrome node comm

thehackerwire@mastodon.social at 2026-09-26T03:46:56.000Z ##

🟠 CVE-2026-100599 - High (8.8)

OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node without going t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T03:46:56.000Z ##

🟠 CVE-2026-100599 - High (8.8)

OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node without going t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100588
(8.3 HIGH)

EPSS: 0.30%

updated 2026-09-26T03:17:06.963000

2 posts

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narrower operator scopes, a write-scoped caller with access to a connected browser-capable node can insp

thehackerwire@mastodon.social at 2026-09-26T05:47:32.000Z ##

🟠 CVE-2026-100588 - High (8.3)

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Ga...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T05:47:32.000Z ##

🟠 CVE-2026-100588 - High (8.3)

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Ga...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100579
(7.6 HIGH)

EPSS: 0.23%

updated 2026-09-26T03:17:05.633000

2 posts

OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator scopes), a write-scoped caller can supply another sender's identifier to the channel authorization checks and invoke a channel action under that spoofed requester identity, reachin

thehackerwire@mastodon.social at 2026-09-26T05:48:30.000Z ##

🟠 CVE-2026-100579 - High (7.6)

OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator scopes), a write-scoped cal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T05:48:30.000Z ##

🟠 CVE-2026-100579 - High (7.6)

OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator scopes), a write-scoped cal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100570
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-26T03:17:04.177000

2 posts

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and then runs the Gmail setup flow, that value is inherited when gcloud is launched, and the gcloud launcher passes it as arguments to the trusted Python interpre

thehackerwire@mastodon.social at 2026-09-26T06:32:36.000Z ##

🟠 CVE-2026-100570 - High (7.8)

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and &lt; 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T06:32:36.000Z ##

🟠 CVE-2026-100570 - High (7.8)

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and &lt; 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100568
(8.3 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:17:03.887000

2 posts

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabled or unscheduled command jobs to access secrets and execute operator-authored commands.

thehackerwire@mastodon.social at 2026-09-26T06:32:55.000Z ##

🟠 CVE-2026-100568 - High (8.3)

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run dis...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T06:32:55.000Z ##

🟠 CVE-2026-100568 - High (8.3)

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run dis...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100561
(8.0 HIGH)

EPSS: 0.25%

updated 2026-09-26T03:17:02.987000

2 posts

OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign wrapper invocation, a later agent turn could substitute an arbitrary inner command and execute it w

thehackerwire@mastodon.social at 2026-09-26T07:01:05.000Z ##

🟠 CVE-2026-100561 - High (8)

OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and &lt; 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T07:01:05.000Z ##

🟠 CVE-2026-100561 - High (8)

OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and &lt; 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100557
(8.3 HIGH)

EPSS: 0.24%

updated 2026-09-26T03:17:02.387000

2 posts

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server credentials reserved for owners.

thehackerwire@mastodon.social at 2026-09-26T06:45:18.000Z ##

🟠 CVE-2026-100557 - High (8.3)

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server cred...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T06:45:18.000Z ##

🟠 CVE-2026-100557 - High (8.3)

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server cred...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100552
(8.8 HIGH)

EPSS: 0.26%

updated 2026-09-26T03:17:01.640000

2 posts

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, and patch tools owned by the Codex runtime. When a lower-trust conversation was assigned to a Codex runtime and restricted with a per-chat tool allowlist,

thehackerwire@mastodon.social at 2026-09-26T07:15:22.000Z ##

🟠 CVE-2026-100552 - High (8.8)

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T07:15:22.000Z ##

🟠 CVE-2026-100552 - High (8.8)

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100520
(8.8 HIGH)

EPSS: 0.94%

updated 2026-09-26T01:17:00.357000

2 posts

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants.

thehackerwire@mastodon.social at 2026-09-26T03:16:42.000Z ##

🟠 CVE-2026-100520 - High (8.8)

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal seq...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T03:16:42.000Z ##

🟠 CVE-2026-100520 - High (8.8)

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal seq...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96795
(8.8 HIGH)

EPSS: 0.30%

updated 2026-09-25T23:16:55.020000

1 posts

Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated function definition to exec(). A crafted string that remains valid under ast.literal_eval can inject Python syntax into a defa

thehackerwire@mastodon.social at 2026-09-25T23:46:00.000Z ##

🟠 CVE-2026-96795 - High (8.8)

Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100382
(0 None)

EPSS: 0.95%

updated 2026-09-25T22:17:10.150000

3 posts

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7.

offseq at 2026-09-26T09:00:23.528Z ##

Mediawiki ExternalData Extension <3.7 has a CRITICAL OS Command Injection vuln (CVE-2026-100382). Unauthenticated attackers could run arbitrary OS commands. No exploits yet. Restrict access, monitor activity. radar.offseq.com/threat/improp

##

offseq@infosec.exchange at 2026-09-26T09:00:23.000Z ##

Mediawiki ExternalData Extension <3.7 has a CRITICAL OS Command Injection vuln (CVE-2026-100382). Unauthenticated attackers could run arbitrary OS commands. No exploits yet. Restrict access, monitor activity. radar.offseq.com/threat/improp #OffSeq #CVE2026100382 #Mediawiki #Security

##

offseq@infosec.exchange at 2026-09-26T00:00:36.000Z ##

CVE-2026-100382 (CRITICAL, CVSS 10): Wikimedia Mediawiki ExternalData Extension (<3.7) suffers OS Command Injection. Remote, unauthenticated code execution is possible. Restrict access & monitor systems. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE2026100382 #infosec #Mediawiki

##

CVE-2026-100368
(8.4 HIGH)

EPSS: 0.58%

updated 2026-09-25T21:41:49

2 posts

### Impact An OS command injection vulnerability exists in the PowerShell and Cmd shell wrappers provided by the `CliInvoke.Specializations` package (the `PowershellProcessInvoker`/`CmdProcessInvoker` invokers, and the `UsePowerShell`/`UseCmd` middleware in v3 pre-release versions). The wrappers re-run a caller-supplied target and arguments inside a shell command (`pwsh -Command ...` / `cmd /c ..

thehackerwire@mastodon.social at 2026-09-26T03:17:23.000Z ##

🟠 CVE-2026-100368 - High (8.4)

CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt. `CliInvoke.Specializations` versions 2.2.0 through ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T03:17:23.000Z ##

🟠 CVE-2026-100368 - High (8.4)

CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt. `CliInvoke.Specializations` versions 2.2.0 through ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100369
(8.4 HIGH)

EPSS: 0.36%

updated 2026-09-25T21:41:37

2 posts

### Impact An argument-injection vulnerability exists in the `CliInvoke` package's runner factory: `RunnerProcessFactory` on the 2.x line and `RunnerConfigurationFactory` on the 3.x line. The factory joins the runner arguments, the caller's target, and the caller's arguments into a single `ProcessStartInfo.Arguments` string and hands it to the OS. The OS command-line parser re-tokenizes the strin

thehackerwire@mastodon.social at 2026-09-26T03:17:05.000Z ##

🟠 CVE-2026-100369 - High (8.4)

CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, and 3...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T03:17:05.000Z ##

🟠 CVE-2026-100369 - High (8.4)

CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, and 3...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100390
(7.4 HIGH)

EPSS: 0.29%

updated 2026-09-25T21:33:12

1 posts

Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.

offseq@infosec.exchange at 2026-09-26T01:30:25.000Z ##

CRITICAL vuln: CVE-2026-100390 in tobychui zoraxy (3.2.3 – 3.3.4). IPv6 parsing flaw lets attackers bypass IP-based controls via spoofed X-Forwarded-For headers. Restrict IPv6 or XFF reliance until patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026100390 #infosec

##

CVE-2026-10758
(7.5 HIGH)

EPSS: 0.33%

updated 2026-09-25T21:33:12

1 posts

Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earlier may allow a remote, unauthenticated attacker who can pass specifically crafted attacker controlled imagery to an application that uses LERC to crash the application, leading to a denial of service.

thehackerwire@mastodon.social at 2026-09-25T23:46:31.000Z ##

🟠 CVE-2026-10758 - High (7.5)

Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earlier may allow a remote, unauthenticated attacker...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5267
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-25T21:33:11

2 posts

Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.

thehackerwire@mastodon.social at 2026-09-26T03:17:14.000Z ##

🟠 CVE-2026-5267 - High (7.5)

Ciena Navigator Network
Control Suite (NCS) contains an information exposure vulnerability in an
event-streaming API that does not properly enforce authentication. An
unauthenticated attacker with network access to the affected service could
acces...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T03:17:14.000Z ##

🟠 CVE-2026-5267 - High (7.5)

Ciena Navigator Network
Control Suite (NCS) contains an information exposure vulnerability in an
event-streaming API that does not properly enforce authentication. An
unauthenticated attacker with network access to the affected service could
acces...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100208
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-25T21:33:06

2 posts

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-09-26T07:45:22.000Z ##

🟠 CVE-2026-100208 - High (7.5)

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T07:45:22.000Z ##

🟠 CVE-2026-100208 - High (7.5)

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97063
(9.1 CRITICAL)

EPSS: 0.29%

updated 2026-09-25T21:33:06

2 posts

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as victims via POST /sys/emailOrMobileLogin/login to hijack accounts.

thehackerwire@mastodon.social at 2026-09-26T07:45:31.000Z ##

🔴 CVE-2026-97063 - Critical (9.1)

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T07:45:31.000Z ##

🔴 CVE-2026-97063 - Critical (9.1)

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97064
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-09-25T21:33:03

2 posts

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileLogin endpoint with a known email or mobile number.

thehackerwire@mastodon.social at 2026-09-26T07:45:39.000Z ##

🔴 CVE-2026-97064 - Critical (9.1)

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileL...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T07:45:39.000Z ##

🔴 CVE-2026-97064 - Critical (9.1)

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileL...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91766
(5.9 MEDIUM)

EPSS: 0.34%

updated 2026-09-25T21:17:24.673000

1 posts

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that l

CVE-2026-57443
(7.5 HIGH)

EPSS: 0.57%

updated 2026-09-25T21:17:23.413000

1 posts

SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint without any authentication. Any remote attacker can call this endpoint and trigger execution of the `email_reader.py` subprocess, which connects to configur

thehackerwire@mastodon.social at 2026-09-25T23:46:39.000Z ##

🟠 CVE-2026-57443 - High (7.5)

SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100391
(8.2 HIGH)

EPSS: 0.31%

updated 2026-09-25T21:17:22.800000

1 posts

MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full responses from the proxy server.

thehackerwire@mastodon.social at 2026-09-26T00:02:12.000Z ##

🟠 CVE-2026-100391 - High (8.2)

MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including lo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100389
(8.1 HIGH)

EPSS: 0.57%

updated 2026-09-25T21:17:22.483000

3 posts

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.

offseq at 2026-09-26T10:30:24.023Z ##

GestSup <3.2.61 is vulnerable to CRITICAL RCE (CVE-2026-100389) via IMAP connector. Attackers can send PHP attachments to monitored mailboxes, leading to system compromise. Upgrade to 3.2.61+ ASAP. radar.offseq.com/threat/gestsu

##

offseq@infosec.exchange at 2026-09-26T10:30:24.000Z ##

GestSup <3.2.61 is vulnerable to CRITICAL RCE (CVE-2026-100389) via IMAP connector. Attackers can send PHP attachments to monitored mailboxes, leading to system compromise. Upgrade to 3.2.61+ ASAP. radar.offseq.com/threat/gestsu #OffSeq #Infosec #RCE #GestSup

##

thehackerwire@mastodon.social at 2026-09-26T00:02:02.000Z ##

🟠 CVE-2026-100389 - High (8.1)

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100387
(8.1 HIGH)

EPSS: 0.32%

updated 2026-09-25T21:17:22.163000

1 posts

pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for exfiltration or crash the PostgreSQL backend.

thehackerwire@mastodon.social at 2026-09-26T00:01:53.000Z ##

🟠 CVE-2026-100387 - High (8.1)

pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91841
(7.8 HIGH)

EPSS: 0.19%

updated 2026-09-25T18:31:36

2 posts

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary commands as the root user, leading to local privilege escalation.

thehackerwire@mastodon.social at 2026-09-26T08:15:22.000Z ##

🟠 CVE-2026-91841 - High (7.8)

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T08:15:22.000Z ##

🟠 CVE-2026-91841 - High (7.8)

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91840
(7.8 HIGH)

EPSS: 0.19%

updated 2026-09-25T18:31:36

2 posts

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.

thehackerwire@mastodon.social at 2026-09-26T08:00:45.000Z ##

🟠 CVE-2026-91840 - High (7.8)

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T08:00:45.000Z ##

🟠 CVE-2026-91840 - High (7.8)

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91839
(7.8 HIGH)

EPSS: 0.20%

updated 2026-09-25T18:31:36

2 posts

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject additional configuration directives. This can lead to arbitrary code execution with root p

thehackerwire@mastodon.social at 2026-09-26T08:00:36.000Z ##

🟠 CVE-2026-91839 - High (7.8)

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T08:00:36.000Z ##

🟠 CVE-2026-91839 - High (7.8)

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91838
(7.8 HIGH)

EPSS: 0.10%

updated 2026-09-25T18:31:36

2 posts

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the `pppd` daemon, which runs with root privileges, allowing the attacke

thehackerwire@mastodon.social at 2026-09-26T08:00:27.000Z ##

🟠 CVE-2026-91838 - High (7.8)

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T08:00:27.000Z ##

🟠 CVE-2026-91838 - High (7.8)

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91837
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-25T18:31:35

2 posts

A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedding shell metacharacters (special characters that can execute commands) in the 'nameserver' value, an attacker can inject and execute arbitrary commands. These com

thehackerwire@mastodon.social at 2026-09-26T08:30:27.000Z ##

🟠 CVE-2026-91837 - High (7.8)

A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedding shell ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T08:30:27.000Z ##

🟠 CVE-2026-91837 - High (7.8)

A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedding shell ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89032
(7.7 HIGH)

EPSS: 0.27%

updated 2026-09-25T18:31:35

2 posts

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_cache_tenant_scope() and _get_metadata_variable_name(). Attackers holding a valid virtual key can submit semantically similar prompts on affected routes su

thehackerwire@mastodon.social at 2026-09-26T08:15:39.000Z ##

🟠 CVE-2026-89032 - High (7.7)

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T08:15:39.000Z ##

🟠 CVE-2026-89032 - High (7.7)

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94445
(8.8 HIGH)

EPSS: 0.36%

updated 2026-09-25T18:17:33.730000

2 posts

A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for an environment configuration file rooted in the playground host's $HOME. To

thehackerwire@mastodon.social at 2026-09-26T08:15:30.000Z ##

🟠 CVE-2026-94445 - High (8.8)

A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem.

Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T08:15:30.000Z ##

🟠 CVE-2026-94445 - High (8.8)

A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem.

Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95699
(9.6 CRITICAL)

EPSS: 0.30%

updated 2026-09-25T17:17:20.097000

1 posts

Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.

thehackerwire@mastodon.social at 2026-09-24T23:45:22.000Z ##

🔴 CVE-2026-95699 - Critical (9.6)

Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92161
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-09-25T16:17:29.387000

2 posts

FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before passing the address to Flarum core as trusted through provideTrustedEmail(). When Discord sign-in is enabled, an unauthenticated attacker who knows the email addre

thehackerwire@mastodon.social at 2026-09-26T08:30:36.000Z ##

🔴 CVE-2026-92161 - Critical (9.8)

FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before passing th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-26T08:30:36.000Z ##

🔴 CVE-2026-92161 - Critical (9.8)

FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before passing th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92573
(6.5 MEDIUM)

EPSS: 0.29%

updated 2026-09-25T15:32:45

1 posts

Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrupt broker availability via processing without a decompressed-output limit. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recomme

DailyCyberSecurity@infosec.exchange at 2026-09-25T13:21:02.000Z ##

New Apache Qpid Broker-J vulnerabilities, including CVE-2026-92609, CVE-2026-92573, and CVE-2026-92564, expose brokers to DoS. Patch immediately.

#ApacheQpid #CVE202692609 #CVE202692573 #AMQP #Cybersecurity #Infosec

securityonline.info/apache-qpi

##

CVE-2026-92609
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-09-25T15:32:40

1 posts

Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.

DailyCyberSecurity@infosec.exchange at 2026-09-25T13:21:02.000Z ##

New Apache Qpid Broker-J vulnerabilities, including CVE-2026-92609, CVE-2026-92573, and CVE-2026-92564, expose brokers to DoS. Patch immediately.

#ApacheQpid #CVE202692609 #CVE202692573 #AMQP #Cybersecurity #Infosec

securityonline.info/apache-qpi

##

CVE-2026-57440
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-25T15:03:43

1 posts

### Summary With $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute without sanitization. When given a malformed url or id, the src attribute can be escaped via double quotes, allowing for html/javascript injection. ### Details The iframe assembled [here](https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/blob/a573a1

thehackerwire@mastodon.social at 2026-09-25T06:17:01.000Z ##

🟠 CVE-2026-57440 - High (7.5)

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not the def...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89055
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-09-25T14:17:21.510000

2 posts

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary attachments from the Media Library — including administrator-owned product

1 repos

https://github.com/murrez/CVE-2026-89055

offseq@infosec.exchange at 2026-09-25T12:00:26.000Z ##

CVE-2026-89055 (CRITICAL, CVSS 9.1): Customer Reviews for WooCommerce <=5.120.0 lets unauthenticated attackers delete arbitrary media via public review-form links. Restrict link access, monitor suspicious review activity. radar.offseq.com/threat/cve-20 #OffSeq #CVE202689055 #WordPress #Infosec

##

thehackerwire@mastodon.social at 2026-09-25T07:18:13.000Z ##

🔴 CVE-2026-89055 - Critical (9.1)

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This ma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62062
(8.8 HIGH)

EPSS: 0.13%

updated 2026-09-25T14:17:18.807000

1 posts

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.

1 repos

https://github.com/abraxas/CVE-2026-62062

thehackerwire@mastodon.social at 2026-09-25T07:18:22.000Z ##

🟠 CVE-2026-62062 - High (8.8)

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery.

This issue affects Elementor Website Builder: from n/a through 4.3.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19804
(8.8 HIGH)

EPSS: 1.04%

updated 2026-09-25T14:17:18.497000

1 posts

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 260814 via the 'first_name' parameter parameter. This is due to insufficient sanitization of the first_name parameter via esc_refs(), which strips only regex backreferences and not PHP tag

thehackerwire@mastodon.social at 2026-09-25T08:17:16.000Z ##

🟠 CVE-2026-19804 - High (8.8)

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 260814 via the 'first_name' param...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97433
(8.2 HIGH)

EPSS: 0.32%

updated 2026-09-25T13:17:26.930000

1 posts

In the Linux kernel, the following vulnerability has been resolved: nvme: validate FDP configuration descriptor sizes Validate descriptor sizes while walking the FDP configurations log so dsze == 0 or a descriptor past the log end cannot cause unbounded iteration or reads past the buffer.

thehackerwire@mastodon.social at 2026-09-25T06:31:37.000Z ##

🟠 CVE-2026-97433 - High (8.2)

In the Linux kernel, the following vulnerability has been resolved:

nvme: validate FDP configuration descriptor sizes

Validate descriptor sizes while walking the FDP configurations log so
dsze == 0 or a descriptor past the log end cannot cause u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97428
(7.7 HIGH)

EPSS: 0.14%

updated 2026-09-25T13:17:26.390000

1 posts

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: harden FRU PIA parsing with bounded helpers Replace the open-coded TLV walk with fru_pia_advance() and fru_pia_copy_field() helpers that bound every read by the actual EEPROM data length, preventing out-of-bounds reads on truncated or malformed FRU data.

thehackerwire@mastodon.social at 2026-09-25T06:31:46.000Z ##

🟠 CVE-2026-97428 - High (7.7)

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: harden FRU PIA parsing with bounded helpers

Replace the open-coded TLV walk with fru_pia_advance()
and fru_pia_copy_field() helpers that bound every read
by the actu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77294
(8.1 HIGH)

EPSS: 0.31%

updated 2026-09-25T13:17:26.220000

1 posts

TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM_PARSING feature is enabled. Write permission to the target trip instance is required to trigger the vulnerable AI-assisted import path. The value is consumed by the clients in server/src/nest/llm-parse/clients/openai-compatible

thehackerwire@mastodon.social at 2026-09-25T05:32:05.000Z ##

🟠 CVE-2026-77294 - High (8.1)

TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM_PARSING feature is enabled. Write permission to the target trip instance i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86857
(0 None)

EPSS: 0.24%

updated 2026-09-25T13:17:16.663000

1 posts

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling further unintended access. ServiceNow deployed an update to hosted instances, and

cR0w@infosec.exchange at 2026-09-24T21:41:51.000Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

CVE-2026-96883
(8.8 HIGH)

EPSS: 0.65%

updated 2026-09-25T13:16:34.693000

1 posts

pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions. To remediate this issue, users should upgrade

thehackerwire@mastodon.social at 2026-09-24T20:30:51.000Z ##

🟠 CVE-2026-96883 - High (8.8)

pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL stateme...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93399
(9.1 CRITICAL)

EPSS: 0.37%

updated 2026-09-25T13:08:26.930000

2 posts

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the attacker-controlled 'order_id' from the submitted form_data into a new booking session,

1 repos

https://github.com/murrez/CVE-2026-93399

offseq@infosec.exchange at 2026-09-25T10:30:25.000Z ##

CVE-2026-93399 (CRITICAL): Bookly WordPress plugin (≤28.2) lets unauth'd attackers enumerate, access, and delete bookings via auth bypass in AJAX actions. No patch. Restrict plugin endpoints & monitor for abuse. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Cybersecurity

##

thehackerwire@mastodon.social at 2026-09-25T07:18:04.000Z ##

🔴 CVE-2026-93399 - Critical (9.1)

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. Thi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71362
(9.1 CRITICAL)

EPSS: 87.51%

updated 2026-09-25T12:53:15.757000

3 posts

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

1 repos

https://github.com/dinosn/cve-2026-71362-magento-lab

AAKL@infosec.exchange at 2026-09-25T17:13:12.000Z ##

CISA has updated the catalogue.

- CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability cisa.gov/known-exploited-vulne

- CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability cve.org/CVERecord?id=CVE-2026-

Yesterday:

- CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability #Microsoft #Adobe

##

secdb@infosec.exchange at 2026-09-24T21:00:17.000Z ##

🚨 [CISA-2026:0924] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-5430 (secdb.nttzen.cloud/cve/detail/)
- Name: WSO2 Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WSO2
- Product: Multiple Products
- Notes: security.docs.wso2.com/en/late ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-71362 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260924 #cisa20260924 #cve_2026_5430 #cve_2026_71362 #cve20265430 #cve202671362

##

cisakevtracker@mastodon.social at 2026-09-24T20:00:59.000Z ##

CVE ID: CVE-2026-71362
Vendor: Adobe
Product: Commerce and Magento
Date Added: 2026-09-24
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-5430
(10.0 CRITICAL)

EPSS: 0.59%

updated 2026-09-25T12:53:05.517000

5 posts

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of adm

2 repos

https://github.com/HORKimhab/CVE-2026-5430

https://github.com/abraxas/CVE-2026-5430

gtronix@infosec.exchange at 2026-09-25T18:01:28.000Z ##

"CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks"

"[...] The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2."

bleepingcomputer.com/news/secu

#Cybersecurity

##

AAKL@infosec.exchange at 2026-09-25T17:13:12.000Z ##

CISA has updated the catalogue.

- CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability cisa.gov/known-exploited-vulne

- CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability cve.org/CVERecord?id=CVE-2026-

Yesterday:

- CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability #Microsoft #Adobe

##

thecybermind@infosec.exchange at 2026-09-25T13:00:16.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-5430 – WSO2 Multiple Products Path Traversal Vulnerability

Analyze the technical mechanics of CVE-2026-5430 with our WSO2 TSUITE brief, covering directory traversal vectors, unrestricted file uploads, and endpoint hardening....

thecybermind.co/bg2r

##

secdb@infosec.exchange at 2026-09-24T21:00:17.000Z ##

🚨 [CISA-2026:0924] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-5430 (secdb.nttzen.cloud/cve/detail/)
- Name: WSO2 Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WSO2
- Product: Multiple Products
- Notes: security.docs.wso2.com/en/late ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-71362 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260924 #cisa20260924 #cve_2026_5430 #cve_2026_71362 #cve20265430 #cve202671362

##

cisakevtracker@mastodon.social at 2026-09-24T20:00:44.000Z ##

CVE ID: CVE-2026-5430
Vendor: WSO2
Product: Multiple Products
Date Added: 2026-09-24
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-92564(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-09-25T09:31:16

1 posts

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.

DailyCyberSecurity@infosec.exchange at 2026-09-25T13:21:02.000Z ##

New Apache Qpid Broker-J vulnerabilities, including CVE-2026-92609, CVE-2026-92573, and CVE-2026-92564, expose brokers to DoS. Patch immediately.

#ApacheQpid #CVE202692609 #CVE202692573 #AMQP #Cybersecurity #Infosec

securityonline.info/apache-qpi

##

CVE-2026-89426
(8.8 HIGH)

EPSS: 0.47%

updated 2026-09-25T09:31:16

1 posts

The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.6.1.0. This is due to the `maybe_update_user_role()` function reading the target role directly from an attacker-controlled Gravity Forms entry field — configured via the feed's `user_role_field_id` — and passing it to `WP_User::set_role()`

thehackerwire@mastodon.social at 2026-09-25T08:17:43.000Z ##

🟠 CVE-2026-89426 - High (8.8)

The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.6.1.0. This is due to the `maybe_update_user_role()` function reading the target rol...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89406
(7.5 HIGH)

EPSS: 0.39%

updated 2026-09-25T09:31:16

1 posts

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being hooked to wp_head on every frontend request and looking up any post via get_post( $_GET['modula_gallery_id'] ) without verifying the gallery's post_status o

thehackerwire@mastodon.social at 2026-09-25T08:17:25.000Z ##

🟠 CVE-2026-89406 - High (7.5)

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being h...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92713
(8.1 HIGH)

EPSS: 0.27%

updated 2026-09-25T09:31:15

1 posts

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server. The path restriction to wp-content/uploa

thehackerwire@mastodon.social at 2026-09-25T08:17:07.000Z ##

🟠 CVE-2026-92713 - High (8.1)

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14281
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-25T09:31:05

1 posts

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and the absence of a key allowlist in the `finish_registration_logic` function, which

2 repos

https://github.com/murrez/CVE-2026-14281

https://github.com/langz337/CVE-2026-14281

offseq@infosec.exchange at 2026-09-25T07:30:24.000Z ##

CVE-2026-14281 (CVSS 9.8, CRITICAL) in 101gen Automation Web Platform – Notifications & OTP for WooCommerce (<=4.8.6) allows unauthenticated admin account creation and OTP bypass via REST API. Disable plugin or restrict endpoints now! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202614281

##

CVE-2026-97444
(7.7 HIGH)

EPSS: 0.14%

updated 2026-09-25T06:31:36

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: add boundary checks in two places Add boundary checks in acpi_ps_get_next_namestring() and acpi_ps_peek_opcode() to prevent out-of-bounds access.

thehackerwire@mastodon.social at 2026-09-25T06:16:28.000Z ##

🟠 CVE-2026-97444 - High (7.7)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: add boundary checks in two places

Add boundary checks in acpi_ps_get_next_namestring() and
acpi_ps_peek_opcode() to prevent out-of-bounds access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97448
(7.7 HIGH)

EPSS: 0.14%

updated 2026-09-25T06:31:35

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: Add validation for node in acpi_ns_build_normalized_path() Add validation for node in acpi_ns_build_normalized_path() to prevent use-after-free vulnerabilities.

thehackerwire@mastodon.social at 2026-09-25T05:48:59.000Z ##

🟠 CVE-2026-97448 - High (7.7)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: Add validation for node in acpi_ns_build_normalized_path()

Add validation for node in acpi_ns_build_normalized_path()
to prevent use-after-free vulnerabilities.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97497
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-25T06:31:35

1 posts

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id allocate_sdma_queue has an option where the sdma queue id can be specified (used by CRIU). We weren't bounds-checking that value. Confirm it's less than the maximum number of queues.

thehackerwire@mastodon.social at 2026-09-25T05:48:41.000Z ##

🟠 CVE-2026-97497 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id

allocate_sdma_queue has an option where the sdma queue id can be
specified (used by CRIU). We weren't bounds-che...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97508
(7.5 HIGH)

EPSS: 0.21%

updated 2026-09-25T06:31:35

1 posts

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Set tb->root_switch to NULL when domain is stopped Similarly what we do with the firmware connection manager. This makes tb_xdp_handle_request() return error to the remote host. However, we need to make sure we keep the uuid alive so that we can reply until the whole domain is released.

thehackerwire@mastodon.social at 2026-09-25T05:46:07.000Z ##

🟠 CVE-2026-97508 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

thunderbolt: Set tb->root_switch to NULL when domain is stopped

Similarly what we do with the firmware connection manager. This makes
tb_xdp_handle_request() return error to the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97445
(7.7 HIGH)

EPSS: 0.15%

updated 2026-09-25T06:31:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources() Enhance buffer validation in acpi_ut_walk_aml_resources() to prevent buffer overflows.

thehackerwire@mastodon.social at 2026-09-25T06:31:28.000Z ##

🟠 CVE-2026-97445 - High (7.7)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources()

Enhance buffer validation in acpi_ut_walk_aml_resources() to prevent
buffer overflows.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97442
(8.8 HIGH)

EPSS: 0.24%

updated 2026-09-25T06:31:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath11k_dp_rx_h_undecap_nwifi() function for the DP_RX_DECAP_TYPE_NATIVE

thehackerwire@mastodon.social at 2026-09-25T06:03:54.000Z ##

🟠 CVE-2026-97442 - High (8.8)

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi

In certain cases, hardware might provide packets with a
length greater than the maximum native Wi-Fi header...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97452
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-25T06:31:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: Prevent adding invalid references Prevent adding references for local, argument, and debug objects in acpi_ut_copy_simple_object().

thehackerwire@mastodon.social at 2026-09-25T06:02:03.000Z ##

🟠 CVE-2026-97452 - High (8.4)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: Prevent adding invalid references

Prevent adding references for local, argument, and debug objects
in acpi_ut_copy_simple_object().

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97478
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-25T06:31:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: virt: acrn: Fix irqfd use-after-free during eventfd shutdown acrn_irqfd_deassign() and the eventfd EPOLLHUP wakeup can race and free the same struct hsm_irqfd: CPU0 CPU1 ---- ---- eventfd_release() wake_up_poll(EPOLLHUP) hsm_irqfd_wakeup() q

thehackerwire@mastodon.social at 2026-09-25T05:48:50.000Z ##

🟠 CVE-2026-97478 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

virt: acrn: Fix irqfd use-after-free during eventfd shutdown

acrn_irqfd_deassign() and the eventfd EPOLLHUP wakeup can race and free
the same struct hsm_irqfd:

CPU0 ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97513
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-25T06:31:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Release m2m_ctx after Instance Removed from List Possible use after free if IRQ thread manages to obtain spinlock between m2m_ctx release and wave5_release function removing stream instance from list of active instances. The IRQ thread looks for the m2m_ctx which is freed so null pointer dereference oc

thehackerwire@mastodon.social at 2026-09-25T05:45:57.000Z ##

🟠 CVE-2026-97513 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

media: chips-media: wave5: Release m2m_ctx after Instance Removed from List

Possible use after free if IRQ thread manages to obtain spinlock between
m2m_ctx release and wave5_re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97735
(8.0 HIGH)

EPSS: 0.25%

updated 2026-09-25T06:31:21

1 posts

ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.

thehackerwire@mastodon.social at 2026-09-25T04:30:53.000Z ##

🟠 CVE-2026-97735 - High (8)

ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97451
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-25T06:31:19

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op) Add overflow check for Index + Length to prevent integer overflow when calculating the truncation length. This prevents negative size parameter being passed to memcpy().

thehackerwire@mastodon.social at 2026-09-25T06:01:53.000Z ##

🟠 CVE-2026-97451 - High (8.4)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op)

Add overflow check for Index + Length to prevent integer overflow
when calculating the truncation length. This...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97818
(8.6 HIGH)

EPSS: 0.32%

updated 2026-09-25T06:31:16

1 posts

phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.

thehackerwire@mastodon.social at 2026-09-25T05:31:07.000Z ##

🟠 CVE-2026-97818 - High (8.6)

phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97509
(8.8 HIGH)

EPSS: 0.24%

updated 2026-09-25T05:17:07.410000

1 posts

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Keep XDomain reference during the lifetime of a service This is needed because we release the service ID in tb_service_release() and the ID array is owned by the parent XDomain.

thehackerwire@mastodon.social at 2026-09-25T05:46:16.000Z ##

🟠 CVE-2026-97509 - High (8.8)

In the Linux kernel, the following vulnerability has been resolved:

thunderbolt: Keep XDomain reference during the lifetime of a service

This is needed because we release the service ID in tb_service_release()
and the ID array is owned by the pa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97455
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-25T05:17:06.673000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix use-after-free in acpi_ds_terminate_control_method() Fix use-after-free issue in acpi_ds_terminate_control_method() by clearing references to method locals and arguments.

thehackerwire@mastodon.social at 2026-09-25T06:03:46.000Z ##

🟠 CVE-2026-97455 - High (8.4)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: Fix use-after-free in acpi_ds_terminate_control_method()

Fix use-after-free issue in acpi_ds_terminate_control_method() by
clearing references to method locals and argum...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97454
(7.7 HIGH)

EPSS: 0.14%

updated 2026-09-25T05:17:06.553000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: add boundary checks in acpi_ps_get_next_field() Add boundary checks in acpi_ps_get_next_field() to prevent out-of-bounds access.

thehackerwire@mastodon.social at 2026-09-25T06:03:37.000Z ##

🟠 CVE-2026-97454 - High (7.7)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: add boundary checks in acpi_ps_get_next_field()

Add boundary checks in acpi_ps_get_next_field() to prevent out-of-bounds
access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97450
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-25T05:17:06.200000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ACPICA: validate handler object type in two places ACPICA: validate handler object type in acpi_ev_has_default_handler() and acpi_ev_find_region_handler().

thehackerwire@mastodon.social at 2026-09-25T06:01:44.000Z ##

🟠 CVE-2026-97450 - High (8.4)

In the Linux kernel, the following vulnerability has been resolved:

ACPICA: validate handler object type in two places

ACPICA: validate handler object type in acpi_ev_has_default_handler()
and acpi_ev_find_region_handler().

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93577
(9.9 CRITICAL)

EPSS: 0.43%

updated 2026-09-25T04:17:49.330000

2 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.

beyondmachines1 at 2026-09-26T10:01:12.909Z ##

GitLab Patches Critical Regex Flaws Allowing Remote Code Execution

GitLab released emergency patches for 11 vulnerabilities, including two critical regex-related flaws (CVE-2026-89078 and CVE-2026-93577) that allow authenticated attackers to execute arbitrary code on self-managed servers.

**If you run your own GitLab server, update it to version 19.4.1, 19.3.3, or 19.2.7. Two critical flaws allow any logged-in user take over the whole server. After updating, check your .gitlab-ci.yml files for new or strange-looking regular expressions, and review who has access to your projects in case someone already tried to exploit this. GitLab.com and GitLab Dedicated users don't need to do anything.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-26T10:01:12.000Z ##

GitLab Patches Critical Regex Flaws Allowing Remote Code Execution

GitLab released emergency patches for 11 vulnerabilities, including two critical regex-related flaws (CVE-2026-89078 and CVE-2026-93577) that allow authenticated attackers to execute arbitrary code on self-managed servers.

**If you run your own GitLab server, update it to version 19.4.1, 19.3.3, or 19.2.7. Two critical flaws allow any logged-in user take over the whole server. After updating, check your .gitlab-ci.yml files for new or strange-looking regular expressions, and review who has access to your projects in case someone already tried to exploit this. GitLab.com and GitLab Dedicated users don't need to do anything.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-89078
(9.9 CRITICAL)

EPSS: 0.36%

updated 2026-09-25T04:17:48.843000

3 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.

beyondmachines1 at 2026-09-26T10:01:12.909Z ##

GitLab Patches Critical Regex Flaws Allowing Remote Code Execution

GitLab released emergency patches for 11 vulnerabilities, including two critical regex-related flaws (CVE-2026-89078 and CVE-2026-93577) that allow authenticated attackers to execute arbitrary code on self-managed servers.

**If you run your own GitLab server, update it to version 19.4.1, 19.3.3, or 19.2.7. Two critical flaws allow any logged-in user take over the whole server. After updating, check your .gitlab-ci.yml files for new or strange-looking regular expressions, and review who has access to your projects in case someone already tried to exploit this. GitLab.com and GitLab Dedicated users don't need to do anything.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-26T10:01:12.000Z ##

GitLab Patches Critical Regex Flaws Allowing Remote Code Execution

GitLab released emergency patches for 11 vulnerabilities, including two critical regex-related flaws (CVE-2026-89078 and CVE-2026-93577) that allow authenticated attackers to execute arbitrary code on self-managed servers.

**If you run your own GitLab server, update it to version 19.4.1, 19.3.3, or 19.2.7. Two critical flaws allow any logged-in user take over the whole server. After updating, check your .gitlab-ci.yml files for new or strange-looking regular expressions, and review who has access to your projects in case someone already tried to exploit this. GitLab.com and GitLab Dedicated users don't need to do anything.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

thehackerwire@mastodon.social at 2026-09-24T13:48:00.000Z ##

🔴 CVE-2026-89078 - Critical (9.9)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86860
(0 None)

EPSS: 0.30%

updated 2026-09-25T04:17:48.557000

1 posts

ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners an

cR0w@infosec.exchange at 2026-09-24T21:41:51.000Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

CVE-2026-82157
(8.3 HIGH)

EPSS: 0.12%

updated 2026-09-25T04:17:48.060000

1 posts

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Protection mechanism bypass and Unauthorized access.

thehackerwire@mastodon.social at 2026-09-25T04:31:02.000Z ##

🟠 CVE-2026-82157 - High (8.3)

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Protecti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19072
(9.9 CRITICAL)

EPSS: 0.40%

updated 2026-09-25T04:17:34.920000

2 posts

Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set from a user API call. This allows another user who can schedule a hunt (minimal role of "investigator" ) to set the compiled VQL statements for the hun

thehackerwire@mastodon.social at 2026-09-24T13:34:23.000Z ##

🔴 CVE-2026-19072 - Critical (9.9)

Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-24T13:30:25.000Z ##

CVE-2026-19072 (CRITICAL, CVSS 9.9) impacts Rapid7 Velociraptor <0.77.2. 'Investigator' role can escalate to admin by injecting arbitrary VQL via API. Patch by upgrading to 0.77.2+. Details: radar.offseq.com/threat/cve-20 #OffSeq #Velociraptor #CVE #Infosec

##

CVE-2026-97730
(8.5 HIGH)

EPSS: 1.03%

updated 2026-09-25T03:31:07

1 posts

In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write arbitrary files to the pfSense firewall system (e.g., /tmp/test.widget.php) can subm

thehackerwire@mastodon.social at 2026-09-25T05:01:06.000Z ##

🟠 CVE-2026-97730 - High (8.5)

In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96512
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-24T21:33:41

1 posts

A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by

2 repos

https://github.com/abraxas/CVE-2026-96512

https://github.com/Ermensonx/sudotimewarp-cve-2026-96512-

CVE-2026-81630
(8.1 HIGH)

EPSS: 0.19%

updated 2026-09-24T21:33:02

2 posts

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted

offseq@infosec.exchange at 2026-09-25T00:00:38.000Z ##

Botslab G980H dash cams are affected by CVE-2026-81630 (CRITICAL, CVSS 9.2): Firmware authenticity is not cryptographically verified, enabling remote code execution if updates are intercepted. Avoid untrusted networks until a patch is released. radar.offseq.com/threat/cve-20 #OffSeq #CVE202681630 #IoTSecurity

##

thehackerwire@mastodon.social at 2026-09-24T23:45:30.000Z ##

🟠 CVE-2026-81630 - High (8.1)

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81473
(8.1 HIGH)

EPSS: 0.09%

updated 2026-09-24T21:32:59

1 posts

Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

thehackerwire@mastodon.social at 2026-09-25T05:31:57.000Z ##

🟠 CVE-2026-81473 - High (8.1)

Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93289
(7.5 HIGH)

EPSS: 0.68%

updated 2026-09-24T21:32:59

2 posts

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

DailyCyberSecurity@infosec.exchange at 2026-09-25T02:34:53.000Z ##

Critical Eufy robot vacuum vulnerabilities expose the Omni C20 and X10 Pro to OS command injection. Patch CVE-2026-93289 and CVE-2026-93291 immediately.

#Eufy #CVE202693289 #CVE202693291 #IoT #Cybersecurity #Vulnerability

securityonline.info/eufy-robot

##

thehackerwire@mastodon.social at 2026-09-24T20:31:01.000Z ##

🟠 CVE-2026-93289 - High (7.5)

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86858(CVSS UNKNOWN)

EPSS: 0.27%

updated 2026-09-24T21:32:59

1 posts

ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete instance data beyond what was intended. In August 2026, ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partner

cR0w@infosec.exchange at 2026-09-24T21:41:51.000Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

CVE-2026-77967
(8.1 HIGH)

EPSS: 0.24%

updated 2026-09-24T21:32:58

1 posts

The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a valid authentication value could replay it from another client to establish an authenticated session and access privileged device functionality.

thehackerwire@mastodon.social at 2026-09-25T05:16:20.000Z ##

🟠 CVE-2026-77967 - High (8.1)

The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a valid auth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85496
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-24T21:32:58

1 posts

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.

thehackerwire@mastodon.social at 2026-09-24T23:46:38.000Z ##

🟠 CVE-2026-85496 - High (8.8)

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84399
(8.8 HIGH)

EPSS: 0.19%

updated 2026-09-24T21:32:58

1 posts

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated contex

thehackerwire@mastodon.social at 2026-09-24T23:46:30.000Z ##

🟠 CVE-2026-84399 - High (8.8)

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and sub...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93354
(8.1 HIGH)

EPSS: 0.27%

updated 2026-09-24T21:32:58

1 posts

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers can send a POST request to the registration endpoint to obtain a client_id and cl

thehackerwire@mastodon.social at 2026-09-24T21:01:24.000Z ##

🟠 CVE-2026-93354 - High (8.1)

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13248
(8.8 HIGH)

EPSS: 0.44%

updated 2026-09-24T21:32:57

1 posts

An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated user with access to the admin or itadmin account to submit commands written in the Intermec Fingerprint programming language directly to the printer ’s internal

thehackerwire@mastodon.social at 2026-09-25T06:46:16.000Z ##

🟠 CVE-2026-13248 - High (8.8)

An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated use...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13249
(9.8 CRITICAL)

EPSS: 0.57%

updated 2026-09-24T21:32:57

1 posts

An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updati

1 repos

https://github.com/murrez/CVE-2026-13249

thehackerwire@mastodon.social at 2026-09-25T06:17:09.000Z ##

🔴 CVE-2026-13249 - Critical (9.8)

An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authenticatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81455
(8.6 HIGH)

EPSS: 0.26%

updated 2026-09-24T21:32:57

1 posts

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

thehackerwire@mastodon.social at 2026-09-25T05:31:48.000Z ##

🟠 CVE-2026-81455 - High (8.6)

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unautho...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86859(CVSS UNKNOWN)

EPSS: 0.29%

updated 2026-09-24T21:32:57

1 posts

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling further unintended access. ServiceNow deployed a security update to hosted insta

cR0w@infosec.exchange at 2026-09-24T21:41:51.000Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

CVE-2026-13016(CVSS UNKNOWN)

EPSS: 0.27%

updated 2026-09-24T21:32:57

1 posts

ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended.  ServiceNow deployed a security update to hosted instan

cR0w@infosec.exchange at 2026-09-24T21:41:51.000Z ##

Hack and patch more ServiceNow shit.

support.servicenow.com/kb?id=k

On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.
ServiceNow did not identify evidence of malicious exploitation related to these issues.

##

CVE-2026-91127
(8.2 HIGH)

EPSS: 0.40%

updated 2026-09-24T21:25:27.050000

1 posts

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled hyperlink targets into generated HTML after character escaping but without restricting URL schemes. A crafted legacy DOC file could place javascript:, vbscript:, da

hugovalters@mastodon.social at 2026-09-26T03:30:07.000Z ##

CVE-2026-91127: XSS in File Viewer legacy DOC renderer, CVSS 8.2, no patch yet. Malicious DOC injects javascript: links, executing script in your app. Update to @file-viewer/doc 2.3.1 immediately. valtersit.com/cve/CVE-2026-911 #CVE #infosec

##

CVE-2026-93291
(9.4 CRITICAL)

EPSS: 0.24%

updated 2026-09-24T21:25:27.050000

3 posts

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

offseq@infosec.exchange at 2026-09-25T03:00:24.000Z ##

CVE-2026-93291 (CRITICAL): Eufy Omni C20 (<1.6.4) fails certificate validation, exposing devices to MITM and arbitrary code execution. Patch status unknown — use strong network protections. radar.offseq.com/threat/cve-20 #OffSeq #CVE202693291 #IoTSecurity #Vuln #Infosec

##

DailyCyberSecurity@infosec.exchange at 2026-09-25T02:34:53.000Z ##

Critical Eufy robot vacuum vulnerabilities expose the Omni C20 and X10 Pro to OS command injection. Patch CVE-2026-93289 and CVE-2026-93291 immediately.

#Eufy #CVE202693289 #CVE202693291 #IoT #Cybersecurity #Vulnerability

securityonline.info/eufy-robot

##

thehackerwire@mastodon.social at 2026-09-24T20:31:10.000Z ##

🔴 CVE-2026-93291 - Critical (9.4)

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82566
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-24T21:25:27.050000

1 posts

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism in

thehackerwire@mastodon.social at 2026-09-24T23:46:21.000Z ##

🟠 CVE-2026-82566 - High (8.8)

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97362
(7.5 HIGH)

EPSS: 0.29%

updated 2026-09-24T21:08:55.030000

1 posts

HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive to all clients without self-recovery until an operator manually restarts the ser

thehackerwire@mastodon.social at 2026-09-24T15:18:45.000Z ##

🟠 CVE-2026-97362 - High (7.5)

HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving threa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97057
(7.5 HIGH)

EPSS: 0.39%

updated 2026-09-24T21:08:55.030000

1 posts

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a crafted RESP header with a length above 2^32-1 to crash the Node.js client process.

thehackerwire@mastodon.social at 2026-09-24T14:20:46.000Z ##

🟠 CVE-2026-97057 - High (7.5)

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77874
(8.6 HIGH)

EPSS: 0.43%

updated 2026-09-24T19:41:16.513000

1 posts

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

thehackerwire@mastodon.social at 2026-09-24T15:48:32.000Z ##

🟠 CVE-2026-77874 - High (8.6)

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, mo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81549
(9.6 CRITICAL)

EPSS: 0.26%

updated 2026-09-24T19:41:16.513000

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.

thehackerwire@mastodon.social at 2026-09-24T15:37:04.000Z ##

🔴 CVE-2026-81549 - Critical (9.6)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81548
(8.8 HIGH)

EPSS: 0.75%

updated 2026-09-24T19:41:16.513000

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-24T15:36:56.000Z ##

🟠 CVE-2026-81548 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81539
(8.8 HIGH)

EPSS: 0.44%

updated 2026-09-24T19:41:16.513000

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-24T15:35:29.000Z ##

🟠 CVE-2026-81539 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78312
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-09-24T19:39:45.600000

1 posts

Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

thehackerwire@mastodon.social at 2026-09-24T13:35:36.000Z ##

🔴 CVE-2026-78312 - Critical (9.1)

Path Traversal in DIAEnergie.

This issue affects DIAEnergie: before 1.11.00.022.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78311
(8.8 HIGH)

EPSS: 0.24%

updated 2026-09-24T19:39:45.600000

1 posts

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

thehackerwire@mastodon.social at 2026-09-24T13:34:43.000Z ##

🟠 CVE-2026-78311 - High (8.8)

SQL Injection vulnerability in DIAEnergie.

This issue affects DIAEnergie: before 1.11.00.022.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57590
(8.1 HIGH)

EPSS: 0.23%

updated 2026-09-24T19:36:39.327000

1 posts

A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.

thehackerwire@mastodon.social at 2026-09-24T13:34:33.000Z ##

🟠 CVE-2026-57590 - High (8.1)

A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group.

...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61741
(9.3 CRITICAL)

EPSS: 0.29%

updated 2026-09-24T19:35:18

1 posts

http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. These decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the parser resolves DOCTYPE declarations, external general and parameter entities, and external DTDs. An application that u

thehackerwire@mastodon.social at 2026-09-25T08:02:17.000Z ##

🔴 CVE-2026-61741 - Critical (9.3)

http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56737
(8.1 HIGH)

EPSS: 0.40%

updated 2026-09-24T19:29:30

1 posts

### Summary The public two-factor verification endpoint `POST /check` logs a user in based **solely** on a valid 6-digit TOTP token and a chosen `user-id`. It does **not** require — and is not bound to — a prior successful password authentication. For any account that has 2FA enabled, an unauthenticated attacker can authenticate **without knowing the password**, reducing the account to a single fa

thehackerwire@mastodon.social at 2026-09-24T16:48:58.000Z ##

🟠 CVE-2026-56737 - High (8.1)

phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its public two-factor authentication verification flow: an unauthenticated attacker can submit an account’s numeric user ID and a va...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75907
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-24T19:17:16.220000

1 posts

The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. A UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no

CVE-2026-61825
(8.7 HIGH)

EPSS: 0.22%

updated 2026-09-24T19:17:15.500000

1 posts

code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in `SharpEditorFormField`: attacker-controlled content bearing the `data-html-content` attribute can bypass HTML sanitization and preserve executable markup, which may execute when another user views the stored content.

thehackerwire@mastodon.social at 2026-09-25T06:16:51.000Z ##

🟠 CVE-2026-61825 - High (8.7)

code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in `SharpEditorFormField`: attacker-controlled content bearing the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61816
(7.5 HIGH)

EPSS: 0.39%

updated 2026-09-24T19:17:15.240000

1 posts

zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Starting in version 2.0.0 and prior to version 3.0.6 and 4.0.2, an uncontrolled resource consumption / algorithmic complexity vulnerability (CWE-400) affects any application that parses untrusted email with this library. Three independent

thehackerwire@mastodon.social at 2026-09-25T08:02:07.000Z ##

🟠 CVE-2026-61816 - High (7.5)

zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Starting in version 2.0.0 and prior to version 3.0.6 and 4.0.2, an uncontrolled resour...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95985
(8.8 HIGH)

EPSS: 0.14%

updated 2026-09-24T18:31:48

1 posts

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. U

thehackerwire@mastodon.social at 2026-09-25T06:46:24.000Z ##

🟠 CVE-2026-95985 - High (8.8)

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85056
(8.2 HIGH)

EPSS: 0.29%

updated 2026-09-24T18:19:36

1 posts

### Summary A vulnerability in ZITADEL’s Login V2 UI allowed a password-verified browser session to be reused for a new authentication request without re-checking a user’s enrolled second factor (TOTP, OTP, or U2F). An attacker who already knows valid credentials can fully authenticate to an application without completing MFA. ### Impact ZITADEL Login V2 issues a session as soon as the user’s p

thehackerwire@mastodon.social at 2026-09-25T06:46:34.000Z ##

🟠 CVE-2026-85056 - High (8.2)

ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password verification and can reuse that session for a later authentication request without verifying a user's enroll...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85057
(8.7 HIGH)

EPSS: 0.39%

updated 2026-09-24T18:19:04.360000

1 posts

ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without restricting its filesystem source loader. An organization Action author with ORG_OWNER, org.action.write, and org.flow.write permissions can run JavaScript at OIDC, SAML, and login-flow trigger points and load files readable by t

thehackerwire@mastodon.social at 2026-09-25T07:02:02.000Z ##

🟠 CVE-2026-85057 - High (8.7)

ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without restricting its filesystem source loader. An organization Action author with...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61782
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-24T18:17:16.333000

1 posts

Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` binds to all network interfaces (`0.0.0.0`) and serves a `POST /api/data/key` endpoint with no authentication and wildcard CORS (`Access-Control-Allow-Origin: *`). Any network-adjacent or remote attacker can send a single unauth

thehackerwire@mastodon.social at 2026-09-25T08:02:26.000Z ##

🟠 CVE-2026-61782 - High (7.5)

Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` binds to all network interfaces (`0.0.0.0`) and serves a `POST /api/data/ke...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77581
(8.6 HIGH)

EPSS: 0.27%

updated 2026-09-24T16:17:10.943000

1 posts

BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS proxy in cloudflare/cors-proxy-worker.js uses isPrivateOrReservedHost() to validate a supplied hostname separately from the DNS resolution used by fetch(targetUrl), allowing an attacker-controlled hostname to resolve to an internal or reserved destination after validation. A certif

thehackerwire@mastodon.social at 2026-09-24T16:48:39.000Z ##

🟠 CVE-2026-77581 - High (8.6)

BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS proxy in cloudflare/cors-proxy-worker.js uses isPrivateOrReservedHost() to validate a supplied hostname separately from the DNS r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63203
(7.6 HIGH)

EPSS: 0.31%

updated 2026-09-24T16:17:08.837000

1 posts

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user access token with only the openid scope to retrieve stored social or enterprise SSO provider access tokens through GET /api/my-account/identities/{target}/access-token or GET /api/m

thehackerwire@mastodon.social at 2026-09-24T16:48:49.000Z ##

🟠 CVE-2026-63203 - High (7.6)

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user access token with only the o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81547
(8.8 HIGH)

EPSS: 0.92%

updated 2026-09-24T15:31:42

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal.

thehackerwire@mastodon.social at 2026-09-24T15:36:46.000Z ##

🟠 CVE-2026-81547 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82093
(8.8 HIGH)

EPSS: 0.41%

updated 2026-09-24T15:31:42

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.

thehackerwire@mastodon.social at 2026-09-24T15:35:20.000Z ##

🟠 CVE-2026-82093 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90959
(8.1 HIGH)

EPSS: 0.32%

updated 2026-09-24T15:31:42

1 posts

A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects URLs beginning with 'file://', but Python's URL parser recognizes the 'file:' scheme without double sl

thehackerwire@mastodon.social at 2026-09-24T15:18:54.000Z ##

🟠 CVE-2026-90959 - High (8.1)

A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58008
(8.1 HIGH)

EPSS: 0.11%

updated 2026-09-24T15:31:41

1 posts

Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

thehackerwire@mastodon.social at 2026-09-24T15:48:52.000Z ##

🟠 CVE-2026-58008 - High (8.1)

Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections.

This issue affects Trusted Firmware: through socfpga_v2.14.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58007
(8.1 HIGH)

EPSS: 0.11%

updated 2026-09-24T15:31:41

1 posts

Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

thehackerwire@mastodon.social at 2026-09-24T15:48:43.000Z ##

🟠 CVE-2026-58007 - High (8.1)

Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections.

This issue affects Trusted Firmware: through socfpga_v2.14.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81545
(8.8 HIGH)

EPSS: 0.85%

updated 2026-09-24T15:31:41

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-24T15:35:38.000Z ##

🟠 CVE-2026-81545 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97360
(10.0 CRITICAL)

EPSS: 0.32%

updated 2026-09-24T15:31:40

1 posts

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to

thehackerwire@mastodon.social at 2026-09-24T14:20:37.000Z ##

🔴 CVE-2026-97360 - Critical (10)

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81552
(8.8 HIGH)

EPSS: 0.75%

updated 2026-09-24T15:31:36

1 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables.

thehackerwire@mastodon.social at 2026-09-24T15:19:03.000Z ##

🟠 CVE-2026-81552 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95521
(7.8 HIGH)

EPSS: 0.58%

updated 2026-09-24T15:31:35

1 posts

A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an

thehackerwire@mastodon.social at 2026-09-24T14:33:36.000Z ##

🟠 CVE-2026-95521 - High (7.8)

A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95519
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-24T15:31:35

1 posts

A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitat

thehackerwire@mastodon.social at 2026-09-24T14:33:27.000Z ##

🟠 CVE-2026-95519 - High (7.8)

A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97359
(10.0 CRITICAL)

EPSS: 0.78%

updated 2026-09-24T15:31:33

1 posts

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to exe

thehackerwire@mastodon.social at 2026-09-24T14:20:28.000Z ##

🔴 CVE-2026-97359 - Critical (10)

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97059
(8.2 HIGH)

EPSS: 0.35%

updated 2026-09-24T15:31:32

1 posts

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM instances declaring more frames than the buffer contains to trigger heap over-reads that crash the application or leak adjacent heap memory.

thehackerwire@mastodon.social at 2026-09-24T14:33:18.000Z ##

🟠 CVE-2026-97059 - High (8.2)

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM instances decl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80513
(7.5 HIGH)

EPSS: 0.31%

updated 2026-09-24T14:42:02.707000

1 posts

The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before 3.1.6 itself; if one is present via another installed wpForo Forum WordPress plugin

thehackerwire@mastodon.social at 2026-09-24T13:47:51.000Z ##

🟠 CVE-2026-80513 - High (7.5)

The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77193
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-24T09:32:00

1 posts

The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

thehackerwire@mastodon.social at 2026-09-24T13:47:42.000Z ##

🟠 CVE-2026-77193 - High (7.5)

The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97185
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-24T09:32:00

1 posts

A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.

thehackerwire@mastodon.social at 2026-09-24T13:35:54.000Z ##

🟠 CVE-2026-97185 - High (7.8)

A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85682
(8.8 HIGH)

EPSS: 0.14%

updated 2026-09-24T09:32:00

1 posts

The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email a

thehackerwire@mastodon.social at 2026-09-24T13:35:45.000Z ##

🟠 CVE-2026-85682 - High (8.8)

The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 0.99%

updated 2026-09-23T18:22:07.453000

2 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

thecybermind at 2026-09-26T10:59:17.188Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-85102 – Check Point Multiple Products Improper Certificate Validation Vulnerability

Analyze the technical mechanics of CVE-2026-85102 with our Check Point TSUITE brief, covering VPN certificate trust validation bypass, multi-platform SIEM queries, and gateway hardening....

thecybermind.co/x9a1

##

thecybermind@infosec.exchange at 2026-09-26T10:59:17.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-85102 – Check Point Multiple Products Improper Certificate Validation Vulnerability

Analyze the technical mechanics of CVE-2026-85102 with our Check Point TSUITE brief, covering VPN certificate trust validation bypass, multi-platform SIEM queries, and gateway hardening....

thecybermind.co/x9a1

##

CVE-2026-71418
(7.5 HIGH)

EPSS: 0.63%

updated 2026-09-23T18:12:04.247000

1 posts

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame contents instead of clearing the internal buffer. Multiple DATA frames with the EndOfStream flag set can grow the buffer to its 65 KiB limit while causing al

hugovalters@mastodon.social at 2026-09-26T12:51:02.000Z ##

CVE-2026-71418: Suricata DoS, CVSS 7.5. DNS-over-HTTP/2 buffer flaw causes quadratic CPU use, degrading packet processing. Unpatched as of now - update immediately. valtersit.com/cve/CVE-2026-714 #CVE #Suricata #infosec

##

CVE-2026-63452
(7.5 HIGH)

EPSS: 0.63%

updated 2026-09-23T18:12:04.247000

1 posts

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli compression bombs a single flow can submit. With response-body-decompress-layer-limit enabled, repeated compressed responses make the decompression paths in

hugovalters@mastodon.social at 2026-09-26T04:20:03.000Z ##

CVE-2026-63452 Suricata DoS: brotli compression bombs exhaust the HTTP/1 parser, degrading packet processing. CVSS 7.5, no patch yet. Update immediately. valtersit.com/cve/CVE-2026-634 #CVE #infosec #Suricata

##

CVE-2026-93616
(9.8 CRITICAL)

EPSS: 19.65%

updated 2026-09-23T16:38:38.987000

2 posts

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

1 repos

https://github.com/WadesWeaponShed/CVE-2026-93616_Checks

thecybermind at 2026-09-26T12:27:03.109Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-93616 – Check Point Multiple Products Path Traversal Vulnerability

Analyze the technical mechanics of CVE-2026-93616 with our Check Point TSUITE brief, covering management server path traversal, remote code execution, and endpoint hardening....

thecybermind.co/1yot

##

thecybermind@infosec.exchange at 2026-09-26T12:27:03.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-93616 – Check Point Multiple Products Path Traversal Vulnerability

Analyze the technical mechanics of CVE-2026-93616 with our Check Point TSUITE brief, covering management server path traversal, remote code execution, and endpoint hardening....

thecybermind.co/1yot

##

CVE-2026-84081
(8.1 HIGH)

EPSS: 0.31%

updated 2026-09-23T04:17:55.267000

1 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

hugovalters@mastodon.social at 2026-09-26T09:40:41.000Z ##

CVE-2026-84081: IBM Guardium 12.2 improper cert validation lets remote attackers bypass security. CVSS 8.1, unpatched. Audit your configs now. valtersit.com/cve/CVE-2026-840 #CVE #infosec #IBM

##

CVE-2026-32996
(0 None)

EPSS: 0.17%

updated 2026-09-23T04:17:43.927000

1 posts

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

1 repos

https://github.com/suce0155/CVE-2026-32996

CVE-2026-93676
(3.2 LOW)

EPSS: 0.14%

updated 2026-09-22T23:17:08.413000

1 posts

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.

linuxmint_hun@mastodon.social at 2026-09-25T16:16:05.000Z ##

Megjelent a Flatpak 1.18.3: biztonsági függőségek és regressziós javítások érkeztek – kezelik a CVE-2026-87766 és CVE-2026-93676 sebezhetőségeket. Gondoltad volna, hogy az 1.18.2 okozott build-regressziók SELinuxos rendszereken problémát, és téged érinthetnek? Kíváncsi vagy, javult-e a subsandbox és a bundle-telepítési stabilitás a te setupodon?

linuxmint.hu/hir/2026/09/megje

#Flatpak #Bubblewrap #xdg-dbus-proxy #CVE2026 #SELinux #Linux #Runtime #FlatpakRelease #Security #Bugfix

##

CVE-2026-87766
(8.8 HIGH)

EPSS: 0.15%

updated 2026-09-22T23:17:07.763000

1 posts

A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.

linuxmint_hun@mastodon.social at 2026-09-25T16:16:05.000Z ##

Megjelent a Flatpak 1.18.3: biztonsági függőségek és regressziós javítások érkeztek – kezelik a CVE-2026-87766 és CVE-2026-93676 sebezhetőségeket. Gondoltad volna, hogy az 1.18.2 okozott build-regressziók SELinuxos rendszereken problémát, és téged érinthetnek? Kíváncsi vagy, javult-e a subsandbox és a bundle-telepítési stabilitás a te setupodon?

linuxmint.hu/hir/2026/09/megje

#Flatpak #Bubblewrap #xdg-dbus-proxy #CVE2026 #SELinux #Linux #Runtime #FlatpakRelease #Security #Bugfix

##

CVE-2026-28324
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-09-22T21:31:34

2 posts

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

DailyCyberSecurity@infosec.exchange at 2026-09-26T02:59:37.000Z ##

SolarWinds Critical Vulnerability: RCE Flaw Patched

#SolarWinds #Vulnerability #Cybersecurity #CVE202628324 #InfoSec A monitoring system engineered to oversee corporate infrastructure can inadvertently pave the way for an attacker to breach the network. SolarWinds has rectified a critical vulnerability within Observability Self-Hosted that permitted unauthenticated remote code execution. Tracked as CVE-2026-28324, this flaw achieved a staggering CVSS severity score of 9.8 out of 10. Exploitation requires neither system privileges nor user interaction, and the attack complexity is deemed low.

dailytechnow.com/solarwinds-cr

##

cyberworldops@infosec.exchange at 2026-09-24T13:00:00.000Z ##

SolarWinds patched three RCE flaws in Observability Self-Hosted, including CVE-2026-28324 (CVSS 9.8) exploitable without authentication. Monitoring hosts hold broad access, so RCE risks full environment compromise and persistence. Patch and restrict exposure now. #SolarWinds #RemoteCodeExecution #PatchManagement

cyberworldops.eu/en/three-sola

##

CVE-2026-94127
(9.8 CRITICAL)

EPSS: 2.23%

updated 2026-09-22T21:31:17

7 posts

When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software version

2 repos

https://github.com/FurkanKAYAPINAR/CVE-2026-94127

https://github.com/watchtowrlabs/watchTowr-vs-f5-bigip-PreAuth-RCE-CVE-2026-94127

DailyCyberSecurity@infosec.exchange at 2026-09-25T12:53:34.000Z ##

Discover the critical F5 BIG-IP zero-day vulnerability CVE-2026-94127. Learn why CISA demands immediate patching for this actively exploited APM flaw.

#F5BIGIP #ZeroDay #CISA #CyberSecurity #TechNews

meterpreter.org/f5-big-ip-zero

##

ulldma@infosec.exchange at 2026-09-25T12:46:04.000Z ##

Love the energy 😅

>Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)

labs.watchtowr.com/is-this-a-j

##

DailyCyberSecurity@infosec.exchange at 2026-09-25T02:20:05.000Z ##

An exploited F5 BIG-IP RCE vulnerability (CVE-2026-94127) is under active attack. Discover how the PoC works and patch your APM proxies immediately.

#F5Networks #CVE202694127 #Cybersecurity #Infosec #ZeroDay #Vulnerability

securityonline.info/exploited-

##

DarkWebInformer@infosec.exchange at 2026-09-24T19:41:58.000Z ##

‼️[POC] CVE-2026-94127: When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE)

GitHub: github.com/watchtowrlabs/watch

##

AAKL@infosec.exchange at 2026-09-24T16:38:20.000Z ##

WatchTower posted this yesterday:

WatchTower: Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) labs.watchtowr.com/is-this-a-j #infosec #vulnerability

##

AAKL@infosec.exchange at 2026-09-24T16:26:29.000Z ##

New.

Picus: CVE-2026-94127 Explained: F5 BIG-IP APM Heap Overflow Attack picussecurity.com/resource/blo #infosec #threatresearch

##

threatcodex@infosec.exchange at 2026-09-24T13:48:35.000Z ##

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
#CVE_2026_94127
labs.watchtowr.com/is-this-a-j

##

CVE-2026-84108
(8.1 HIGH)

EPSS: 0.63%

updated 2026-09-22T19:32:25.730000

1 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

hugovalters@mastodon.social at 2026-09-26T16:00:28.000Z ##

CVE-2026-84108: IBM Guardium Data Protection 12.2 RCE via improper input neutralization. CVSS 8.1, unpatched. Patch now. valtersit.com/cve/CVE-2026-841 #CVE #infosec #IBM

##

CVE-2026-11727
(8.1 HIGH)

EPSS: 0.44%

updated 2026-09-22T19:32:25.730000

1 posts

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.

hugovalters@mastodon.social at 2026-09-26T14:30:07.000Z ##

CVE-2026-11727: IBM MQ C client DoS, possible RCE, via unvalidated queue manager responses. CVSS 8.1, unpatched. Apply mitigations now. valtersit.com/cve/CVE-2026-117 #CVE #infosec #IBM

##

CVE-2026-84036
(7.4 HIGH)

EPSS: 0.34%

updated 2026-09-22T19:32:25.730000

1 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

hugovalters@mastodon.social at 2026-09-26T11:20:04.000Z ##

CVE-2026-84036 IBM Guardium Data Protection 12.2 access control bypass, CVSS 7.4. Auth'd attacker can bypass security restrictions. No patch yet - restrict access now. valtersit.com/cve/CVE-2026-840 #CVE #infosec #IBM

##

CVE-2025-39964
(7.8 HIGH)

EPSS: 1.00%

updated 2026-09-19T04:17:48.307000

2 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates

3 repos

https://github.com/suominen/CVE-2025-39964

https://github.com/n1k0oowang/CVE-2025-39964_EXP

https://github.com/mc493/linux-kernel-zero-day-mitigation-zero-downtime-kernel-defense-

ibu_ipop@burnout.cafe at 2026-09-26T07:52:12.000Z ##

Linux kernel flaw enables root and container escape A 14-year-old bug in the AF_ALG cryptographic socket interface, tracked as CVE-2025-39964, allows unprivileged local users to gain root and escape Docker containers. The issue is a race condition in concurrent sendmsg() operations that can be turned into out-of-bounds memory access and an arbitrary kernel write. The vulnerable code dates to Linux 2.6.38

cyberpress.org/14-year-old-lin

##

ibu_ipop@burnout.cafe at 2026-09-26T07:52:12.000Z ##

Linux kernel flaw enables root and container escape A 14-year-old bug in the AF_ALG cryptographic socket interface, tracked as CVE-2025-39964, allows unprivileged local users to gain root and escape Docker containers. The issue is a race condition in concurrent sendmsg() operations that can be turned into out-of-bounds memory access and an arbitrary kernel write. The vulnerable code dates to Linux 2.6.38

cyberpress.org/14-year-old-lin

##

CVE-2026-84241
(8.1 HIGH)

EPSS: 0.47%

updated 2026-09-18T21:32:40

1 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

hugovalters@mastodon.social at 2026-09-26T05:00:57.000Z ##

CVE-2026-84241 IBM Guardium Data Protection 12.2 improper access control lets a remote attacker bypass security restrictions. CVSS 8.1, no patch yet. Restrict exposure and monitor access logs. valtersit.com/cve/CVE-2026-842 #CVE #infosec #IBM

##

CVE-2026-91843
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-09-16T15:31:14

1 posts

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

1 repos

https://github.com/HORKimhab/CVE-2026-91843

daniel1820815@infosec.exchange at 2026-09-25T08:36:01.000Z ##

CVE-2026-91843 Fix

Check Point has released a fix for CVE-2026-91843, a critical vulnerability affecting Security Management and Log Servers. The flaw, rated CVSS 9.8, stems from a stack overflow in the login process and can allow unauthenticated remote attackers to execute code as root on affected R80 through R82 systems.

support.checkpoint.com/results

#CVE #CVE202691843

##

CVE-2026-19624
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-14T21:31:45

1 posts

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security assoc

hugovalters@mastodon.social at 2026-09-26T08:10:02.000Z ##

CVE-2026-19624 NetworkManager-l2tp local privilege escalation: newline injection into ipsec.conf lets a local user run commands as root via pluto. CVSS 7.8. Patched. Update now. valtersit.com/cve/CVE-2026-196 #CVE #infosec #Linux

##

CVE-2026-34223
(8.2 HIGH)

EPSS: 0.19%

updated 2026-09-14T14:17:07.503000

1 posts

A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All versions), Desigo CC Installed Client V7 (All versions). The affected applicatio

cyberworldops@infosec.exchange at 2026-09-25T02:30:00.000Z ##

CISA has issued an advisory for CVE-2026-34223 in Siemens Desigo CC: a compromised graphics document can trigger client-side code execution and write arbitrary files. System compromise and potential lateral movement make this relevant to ICS defenders. #CyberSecurity #ICS #Vulnerability

cyberworldops.eu/en/malicious-

##

CVE-2026-9176
(6.7 MEDIUM)

EPSS: 0.16%

updated 2026-09-10T21:31:46

1 posts

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.

CVE-2026-86296
(10.0 CRITICAL)

EPSS: 1.70%

updated 2026-09-08T17:18:39.613000

1 posts

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

hackmag@infosec.exchange at 2026-09-24T15:30:26.000Z ##

⚪️ D-Link Warns of Unpatched Zero-Day Flaw in DIR-822A Routers

🗨️ D-Link has warned of a critical zero-day vulnerability (CVE-2026-86296) affecting end-of-life DIR-822A dual-band routers. The issue allows an unauthenticated local attacker to cause a denial of service in the DHCP service or achieve remote code execution. No patch is currently…

🔗 hackmag.com/news/d-link-0days?

#news

##

cyberworldops@infosec.exchange at 2026-09-24T19:00:01.000Z ##

CISA added CVE-2026-63077 to the KEV catalog after confirming active exploitation in ransomware operations. The flaw allows unauthenticated RCE on JetBrains TeamCity via the agent-polling protocol, putting internet-exposed build infrastructure at direct risk. #TeamCity #Ransomware #InfoSec

cyberworldops.eu/en/exploited-

##

CVE-2026-35273
(9.8 CRITICAL)

EPSS: 9.44%

updated 2026-07-23T09:10:00.113000

4 posts

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of Peopl

4 repos

https://github.com/ekomsSavior/POC_cve_2026_35273

https://github.com/HORKimhab/CVE-2026-35273

https://github.com/12hrformat/CVE-2026-35273-POC

https://github.com/0xBlackash/CVE-2026-35273

Analyst207@mastodon.social at 2026-09-26T14:49:26.000Z ##

Google Warns of Mass Exploitation of Oracle PeopleSoft Flaw

Google warns of a massive global campaign exploiting a critical Oracle PeopleSoft flaw, CVE-2026-35273, that allows hackers to remotely execute code without authentication, now targeting industries from healthcare to government. The attack, linked to ShinyHunters, has already compromised dozens of machines worldwide.

osintsights.com/google-warns-o

#OraclePeoplesoft #Cve202635273 #Shinyhunters #Unc6240 #WebApplicationFirewallBypass

##

cyberworldops at 2026-09-26T14:40:01.207Z ##

Google reports active exploitation of CVE-2026-35273 in Oracle PeopleSoft PeopleTools by UNC6240, linked to ShinyHunters. Encoded requests evade WAF rules to deploy JSP webshells via the Environment Management Hub, enabling persistent access. Prioritize patching and compromise hunting.

cyberworldops.eu/en/encoded-re

##

cyberworldops@infosec.exchange at 2026-09-26T14:40:01.000Z ##

Google reports active exploitation of CVE-2026-35273 in Oracle PeopleSoft PeopleTools by UNC6240, linked to ShinyHunters. Encoded requests evade WAF rules to deploy JSP webshells via the Environment Management Hub, enabling persistent access. Prioritize patching and compromise hunting. #OracleSecurity #PeopleSoft #ThreatIntel

cyberworldops.eu/en/encoded-re

##

DarkWebInformer@infosec.exchange at 2026-09-25T23:44:38.000Z ##

🚨 ShinyHunters resumes mass exploitation of critical Oracle PeopleSoft flaw using simple WAF bypass.

Mandiant and Google Threat Intelligence Group have identified renewed mass exploitation of CVE-2026-35273 by UNC6240, also known as ShinyHunters.
⠀
The critical vulnerability allows unauthenticated remote code execution in Oracle PeopleSoft PeopleTools and carries a CVSS score of 9.8.

Oracle released an emergency patch on June 10.
⠀
The new campaign targets organizations that attempted to mitigate the flaw using web application firewall rules but did not install the patch.

ShinyHunters bypassed rules blocking the vulnerable /PSEMHUB/ endpoint by encoding a single character and sending requests to /%50SEMHUB/.
⠀
Google says web shells were deployed on dozens of systems worldwide across:

• Higher education
• Technology
• IT services
• Healthcare
• Agriculture
• Transportation
• Government
⠀
The actors deployed web shells, the SIDEEYE backdoor, Neo-reGeorg tunneling tools and MeshAgent for persistent remote access.

Around one-quarter of the observed commands executed with root or SYSTEM privileges.
⠀
Organizations running PeopleSoft should patch immediately, disable or remove the Environment Management Hub where possible and investigate encoded variants of /PSEMHUB/ in access logs.

WAF rules alone are not sufficient.

##

CVE-2026-39808
(9.8 CRITICAL)

EPSS: 47.36%

updated 2026-07-16T18:32:24

1 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

6 repos

https://github.com/Lechansky/CVE-2026-39808

https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808

https://github.com/HORKimhab/CVE-2026-39808

https://github.com/samu-delucas/CVE-2026-39808

https://github.com/0xBlackash/CVE-2026-39808

https://github.com/error-inside/CVE-2026-39808

AAKL@infosec.exchange at 2026-09-25T17:30:37.000Z ##

If you missed this, Fortinet posted advisories for two critical vulnerabilities yesterday - CVE-2026-39813 and CVE-2026-39808 app.opencve.io/cve/?vendor=for #infosec #Fortinet #vulnerability

##

CVE-2026-23239
(7.8 HIGH)

EPSS: 0.10%

updated 2026-06-17T10:21:09.960000

1 posts

In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() This issue was discovered during a code audit. After cancel_work_sync() is called from espintcp_close(), espintcp_tx_work() can still be scheduled from paths such as the Delayed ACK handler or ksoftirqd. As a result, the espintcp_tx_work() worker may dereference a freed espintcp

DailyCyberSecurity@infosec.exchange at 2026-09-25T00:20:58.000Z ##

RustyTux is a public PoC for a Linux kernel privilege escalation via an ESP-in-TCP use-after-free (CVE-2026-23239). Details and exploit code are now public.

#RustyTux #LinuxKernel #PrivilegeEscalation #UseAfterFree #espintcp #LPE #PoC #CVE202623239

securityonline.info/rustytux-l

##

jana@social.jsteuernagel.de at 2026-09-26T13:32:29.000Z ##

I just wanted to unlock the bootloader on a Lenovo android tablet.

One enables OEM unlocking in the dev settings and fastboot is still like "sorry, but that failed”

This is now my most promising lead: github.com/TomKing062/CVE-2022

Thanks Lenovo /s

##

CVE-2026-0257
(9.1 CRITICAL)

EPSS: 96.38%

updated 2026-06-09T12:32:02

1 posts

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Nuclei template

8 repos

https://github.com/grayxploit/CVE-2026-0257

https://github.com/HORKimhab/CVE-2026-0257

https://github.com/akashsingh0454/CVE-2026-0257-PoC

https://github.com/Ez4rd1x1/CVE-2026-0257

https://github.com/0xBlackash/CVE-2026-0257

https://github.com/Mr-Robot-LP/CVE-2026-0257

https://github.com/tushargurav28/CVE-2026-0257

https://github.com/sfewer-r7/CVE-2026-0257

japancyberwatch@infosec.exchange at 2026-09-25T10:08:42.000Z ##

Japan's Digital Agency was breached through a VPN flaw that was public before the attack. Data on ~246,000 officials and contractors may be exposed.

The agency won't name the product. Japanese researcher piyolog points to CVE-2026-0257 (PAN-OS GlobalProtect), added to CISA KEV on May 29. Detection to disclosure: eleven weeks, with no CVE or IOCs in the notice.

Our take on patching by CVSS, "zero trust" as a label, and Japan's disclosure culture:
japancyberwatch.com/articles/j

#infosec #Japan #DataBreach #VulnerabilityManagement #PaloAlto

##

CVE-2026-48842
(8.1 HIGH)

EPSS: 0.89%

updated 2026-06-04T00:31:26

3 posts

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

1 repos

https://github.com/murrez/CVE-2026-48842

DarkWebInformer@infosec.exchange at 2026-09-25T18:36:27.000Z ##

🚨 Roundcube SQL injection flaw actively exploited months after patches were released

The Canadian Centre for Cyber Security has warned that CVE-2026-48842, a high-severity vulnerability in Roundcube Webmail, is being exploited in the wild.
⠀
Roundcube is an open-source webmail application that lets people access email through a browser.

The flaw affects its virtuser_query plugin and allows SQL injection before authentication.
⠀
Key details:

• CVSS score: 8.1
• No attacker credentials required
• No user interaction required
• Affects Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1
⠀
Roundcube released the original fixes on May 24, 2026. Canada added the exploitation warning to its advisory on September 21, citing open-source reporting.

The advisory does not identify the attackers, victims or scale of exploitation.
⠀
Administrators should update affected installations promptly. Newer security releases, 1.6.19 and 1.7.4, also address additional vulnerabilities.

Source: cyber.gc.ca/en/alerts-advisori

##

cyberworldops@infosec.exchange at 2026-09-25T11:10:01.000Z ##

Canadian Centre for Cyber Security warns CVE-2026-48842, a pre-auth SQL injection in Roundcube Webmail virtuser_query plugin, is actively exploited. Unauthenticated preg_replace escape bypass affects 1.6.x before 1.6.16 and 1.7.x before 1.7.1, enabling backend DB compromise. #Roundcube #SqlInjection #InfoSec

cyberworldops.eu/en/active-rou

##

DailyCyberSecurity@infosec.exchange at 2026-09-25T09:57:33.000Z ##

Learn how hackers are exploiting the CVE-2026-48842 Roundcube SQL injection vulnerability. Understand the risk and how to patch your webmail server immediately.

#Roundcube #CyberSecurity #SQLInjection #DataBreach #TechNews

meterpreter.org/roundcube-webm

##

CVE-2026-42608(CVSS UNKNOWN)

EPSS: 0.52%

updated 2026-05-13T13:52:36

1 posts

# Vulnerability Report: Grav CMS Unauthenticated Path Traversal & Arbitrary File Write **[ZERO-DAY] Unauthenticated Path Traversal leading to Arbitrary Directory Creation and Configuration Injection** ## Summary Grav CMS (v1.7.49.5 and latest development source) is vulnerable to a Zero-Day Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed a

Analyst207@mastodon.social at 2026-09-25T21:19:23.000Z ##

ShinyHunters Exploits Grav CMS Flaw to Breach Clop Leak Site

The Grav CMS flaw, tracked as CVE-2026-42608, was exploited by ShinyHunters to breach the Clop gang's leak site, and the vulnerability has since been patched in Grav's 2.0 and 1.7 branches. Grav confirmed the legitimacy of the flaw and the threat actor's description, and has implemented a fix to prevent further attacks.

osintsights.com/shinyhunters-e

#Shinyhunters #GravCms #Cve202642608 #PathTraversal #Clop

##

CVE-2026-39813
(9.8 CRITICAL)

EPSS: 0.72%

updated 2026-04-14T18:30:41

1 posts

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>

2 repos

https://github.com/0xBlackash/CVE-2026-39813

https://github.com/HORKimhab/CVE-2026-39813

AAKL@infosec.exchange at 2026-09-25T17:30:37.000Z ##

If you missed this, Fortinet posted advisories for two critical vulnerabilities yesterday - CVE-2026-39813 and CVE-2026-39808 app.opencve.io/cve/?vendor=for #infosec #Fortinet #vulnerability

##

CVE-2025-13032
(9.9 CRITICAL)

EPSS: 0.25%

updated 2025-11-11T18:30:23

7 posts

Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows allows local attacker to escalate privelages via pool overflow.

hackersnews@mastodon.cesium.pw at 2026-09-25T19:30:07.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2
news.ycombinator.com/item?id=4

#hackernews #tech

##

hn100@social.lansky.name at 2026-09-25T18:30:08.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2

Link: safateam.com/intelligence-hub/
Discussion: news.ycombinator.com/item?id=4

##

_r_netsec@infosec.exchange at 2026-09-25T14:58:04.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2 safateam.com/intelligence-hub/

##

hn50@social.lansky.name at 2026-09-25T10:30:09.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2

Link: safateam.com/intelligence-hub/
Discussion: news.ycombinator.com/item?id=4

##

zer0@infosec.exchange at 2026-09-25T09:02:44.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2 | safateam.com/intelligence-hub/

##

newsycombinator@framapiaf.org at 2026-09-25T08:00:36.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2
Link: safateam.com/intelligence-hub/
Comments: news.ycombinator.com/item?id=4

##

h4ckernews@mastodon.social at 2026-09-25T07:18:10.000Z ##

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2

safateam.com/intelligence-hub/

Comments: news.ycombinator.com/item?id=4

#HackerNews #CVE2025 #CVE #AvastAntivirus #CyberSecurity #Vulnerability #Research

##

CVE-2026-76654
(0 None)

EPSS: 0.00%

1 posts

N/A

mastokukei@social.josko.org at 2026-09-26T09:01:50.000Z ##

agents.
- **Retro computing/embedded**: Z80 Scheme (Skate), Atari Jaguar OS (JagOS), ESP32 Linux support, Arduino libraries (e.g., `ESPNetworkSerial`, `MicroDB`).
- **Security vulnerabilities**: CVE-2026-76654 (Kubernetes), CVE-2026-2270 (Kubernetes), 14-year-old Linux kernel bug (AF_ALG).
- **Web development**: CSS features (scroll-driven animations, anchor positioning), Django, Rails World 2026 keynote, WordPress updates. [2/2]

##

CVE-2026-2270
(0 None)

EPSS: 0.00%

1 posts

N/A

mastokukei@social.josko.org at 2026-09-26T09:01:50.000Z ##

agents.
- **Retro computing/embedded**: Z80 Scheme (Skate), Atari Jaguar OS (JagOS), ESP32 Linux support, Arduino libraries (e.g., `ESPNetworkSerial`, `MicroDB`).
- **Security vulnerabilities**: CVE-2026-76654 (Kubernetes), CVE-2026-2270 (Kubernetes), 14-year-old Linux kernel bug (AF_ALG).
- **Web development**: CSS features (scroll-driven animations, anchor positioning), Django, Rails World 2026 keynote, WordPress updates. [2/2]

##

CVE-2026-61818
(0 None)

EPSS: 0.51%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-26T06:40:19.000Z ##

CVE-2026-61818 pg_partman SQL injection in undo_partition() prior to 5.5.0, CVSS 8.5. Unpatched. A partman_user role can inject SQL that runs with the caller's privileges. Patch or restrict partman_user access now. valtersit.com/cve/CVE-2026-618 #CVE #infosec #PostgreSQL

##

CVE-2026-91765
(0 None)

EPSS: 0.52%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-25T23:46:21.000Z ##

🟠 CVE-2026-91765 - High (7.5)

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100000
(0 None)

EPSS: 0.00%

1 posts

N/A

bagder@mastodon.social at 2026-09-25T13:29:46.000Z ##

"the kernel.org CNA has CVE-2026-100000 reserved"

🍾

/ @gregkh

##

CVE-2026-63645
(0 None)

EPSS: 0.33%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-25T07:02:21.000Z ##

🟠 CVE-2026-63645 - High (7.5)

OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoint without authentication and serializes the complete server configuration after applying the hide_sensitive_fields keyword filt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71540
(0 None)

EPSS: 0.35%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-25T07:02:11.000Z ##

🟠 CVE-2026-71540 - High (7.5)

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.9.0 until 4.14.7, wazuh-clusterd in framework/wazuh/core/cluster/common.py allocates a payload buffer using the size decl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96749
(0 None)

EPSS: 0.13%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-25T05:16:29.000Z ##

🟠 CVE-2026-96749 - High (8.4)

An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82989
(0 None)

EPSS: 0.00%

1 posts

N/A

offseq@infosec.exchange at 2026-09-25T04:30:24.000Z ##

CVE-2026-82989 (CRITICAL): ViewSonic vCast (ViewBoard) has unauth. flaws — screen exfiltration, APK install, input injection — allowing full device compromise from same network. No patch. Segment & monitor systems. radar.offseq.com/threat/vu2341 #OffSeq #vuln #InfoSec

##

CVE-2026-79417
(0 None)

EPSS: 0.00%

1 posts

N/A

1 repos

https://github.com/connorjaydunn/CVE-2026-79417

CVE-2026-93425
(0 None)

EPSS: 0.62%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-24T16:19:14.000Z ##

🔴 CVE-2026-93425 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites