## Updated at UTC 2026-10-01T17:20:59.900820

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-79896 7.5 0.00% 2 0 2026-10-01T16:17:59.940000 Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom T
CVE-2026-14157 0 0.00% 1 0 2026-10-01T16:17:40.980000 Use of an Externally Controlled Format String in the ASUS Router modules allow a
CVE-2026-12627 9.8 0.00% 2 0 2026-10-01T16:17:40.480000 Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer ove
CVE-2026-101283 0 0.43% 1 0 2026-10-01T16:17:32.460000 iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rs
CVE-2026-102831 8.1 0.20% 1 0 2026-10-01T15:20:42 ## Description JupyterLab 4.5.0 enabled copying and pasing cells through the sy
CVE-2026-97297 7.6 0.00% 2 0 2026-10-01T15:17:38.960000 Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions.
CVE-2026-97284 8.8 0.00% 2 0 2026-10-01T15:17:38.807000 Contributor PHP Object Injection in Icegram <= 3.1.31 versions.
CVE-2026-97277 7.6 0.00% 2 0 2026-10-01T15:17:38.380000 Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.
CVE-2026-92966 9.1 0.00% 1 1 2026-10-01T15:17:35.830000 The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordP
CVE-2026-79901 9.9 0.00% 2 0 2026-10-01T15:17:32.163000 In deployments using BoKS keytab management, affected versions of boks_keytabmd
CVE-2024-58388 7.5 0.00% 2 0 2026-10-01T15:17:17.347000 Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthentica
CVE-2026-66246 8.8 0.00% 2 0 2026-10-01T15:07:27.747000 iControl is affected by a Broken Access Control vulnerability, which could allow
CVE-2026-62059 7.6 0.00% 2 1 2026-10-01T14:34:35.357000 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-102115 9.8 0.53% 1 0 2026-10-01T14:17:15.510000 Kiteworks Core did not correctly validate a parameter submitted to the password
CVE-2026-102427 10.0 0.84% 1 1 2026-10-01T13:46:23.090000 Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaS
CVE-2026-7175 0 0.00% 1 0 2026-10-01T13:04:49.340000 CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of th
CVE-2025-41753 9.8 0.00% 1 0 2026-10-01T13:01:47.180000 The object name of a dynamically created BACnet File Object is interpreted as a
CVE-2026-7174 None 0.00% 1 0 2026-10-01T12:31:22 CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocan
CVE-2026-7176 None 0.00% 1 0 2026-10-01T12:31:22 CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event
CVE-2026-7173 None 0.00% 1 0 2026-10-01T12:31:17 CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets
CVE-2026-103655 None 0.00% 2 0 2026-10-01T09:30:42 MISP contains a vulnerability in its two-factor authentication (TOTP) verificati
CVE-2026-78210 None 0.00% 2 0 2026-10-01T06:31:25 In affected versions of Octopus Server, users with certain scoped permission set
CVE-2026-76504 9.8 1.10% 20 1 2026-10-01T04:18:19.193000 A vulnerability in the API session-based authentication management of Cisco Cata
CVE-2026-47600 7.8 0.19% 1 0 2026-10-01T04:18:18.747000 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the
CVE-2026-13313 None 0.00% 3 0 2026-10-01T03:31:14 An Active Debug Code vulnerability in certain ASUS router models allows a remote
CVE-2026-102823 7.5 0.26% 1 0 2026-09-30T23:27:18 ### Summary CVE-2026-68930 was fixed by adding `Session::is_established_channel(
CVE-2026-101276 None 0.43% 1 0 2026-09-30T21:32:15 iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free
CVE-2026-76722 9.8 0.54% 2 0 2026-09-30T21:32:03 Uncontrolled Format string vulnerabilities exist in the affected interface of HP
CVE-2026-76721 9.8 0.56% 2 0 2026-09-30T21:32:02 Buffer overflow vulnerability exists in the affected interface of HPE Networking
CVE-2026-76723 9.6 0.31% 1 0 2026-09-30T21:32:02 Buffer overflow vulnerabilities exist in the affected interface of HPE Networkin
CVE-2026-62146 7.8 0.15% 1 1 2026-09-30T20:17:34.013000 A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influ
CVE-2026-103111 7.6 0.21% 1 0 2026-09-30T20:17:29.847000 PCRE2 before 10.49, when there is an attacker-controlled regular expression and
CVE-2026-103106 7.8 0.14% 1 0 2026-09-30T20:17:29.517000 Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper i
CVE-2026-102489 0 0.71% 1 0 2026-09-30T19:57:08.043000 Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability tha
CVE-2026-79625 8.1 0.40% 2 0 2026-09-30T19:57:08.043000 Affected products do not properly synchronize access to their monitoring functio
CVE-2026-102826 8.1 0.46% 1 0 2026-09-30T19:56:45.443000 simple-git, an interface for running git commands in any node.js application, en
CVE-2026-102827 8.1 0.36% 1 0 2026-09-30T19:56:45.443000 simple-git, an interface for running git commands in any node.js application, en
CVE-2026-102674 8.2 0.27% 1 0 2026-09-30T19:38:27.293000 Electron is a framework for writing cross-platform desktop applications using Ja
CVE-2026-102490 None 0.32% 1 0 2026-09-30T18:33:55 All versions of Zammad including the latest alpha enable the local zammad user t
CVE-2026-47593 7.8 0.18% 1 0 2026-09-30T18:33:55 NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mod
CVE-2026-47592 7.8 0.19% 1 0 2026-09-30T18:33:55 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the
CVE-2026-47599 7.8 0.16% 1 0 2026-09-30T18:33:54 NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source
CVE-2026-47601 7.8 0.18% 1 0 2026-09-30T18:33:49 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the
CVE-2026-47591 7.8 0.18% 1 0 2026-09-30T18:18:34.637000 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode
CVE-2026-78902 6.1 0.30% 2 0 2026-09-30T17:23:08.953000 Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an
CVE-2026-103108 7.5 0.31% 1 0 2026-09-30T17:16:41.460000 Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper i
CVE-2026-92871 7.5 0.29% 1 0 2026-09-30T16:47:57.730000 A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an
CVE-2026-76570 0 0.50% 2 1 2026-09-30T16:44:39.840000 Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and writ
CVE-2026-103099 7.5 0.31% 1 0 2026-09-30T16:44:39.840000 Pexip Infinity before 41.1 is affected by improper input validation in the media
CVE-2026-103105 8.8 0.18% 1 0 2026-09-30T16:44:39.840000 Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper ac
CVE-2026-103104 7.5 0.31% 1 0 2026-09-30T16:44:39.840000 Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper in
CVE-2026-103109 7.7 0.24% 1 0 2026-09-30T16:44:39.840000 Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper in
CVE-2026-102455 9.8 0.51% 1 0 2026-09-30T16:30:42.327000 EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability.
CVE-2026-75098 7.5 0.90% 1 0 2026-09-30T16:18:58.363000 The Product Designer App plugin for WordPress is vulnerable to Directory Travers
CVE-2026-18783 8.8 0.39% 1 1 2026-09-30T16:18:57.403000 Missing authentication for critical function vulnerability in Trex Digital Smart
CVE-2026-6806 7.5 0.27% 1 0 2026-09-30T16:18:39.783000 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is
CVE-2026-62097 7.6 0.38% 1 0 2026-09-30T16:17:32.973000 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-19743 7.8 0.13% 1 0 2026-09-30T16:17:12.610000 Improper path validation in the local IPC service of TeamViewer Full Client and
CVE-2026-102508 0 0.13% 1 0 2026-09-30T16:14:10.347000 Improper Verification of Cryptographic Signature and Improper Certificate Valida
CVE-2026-93994 8.1 0.47% 1 0 2026-09-30T16:13:13.493000 Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH serv
CVE-2026-94053 9.1 0.55% 1 0 2026-09-30T16:13:13.493000 Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA S
CVE-2026-18782 9.8 0.58% 1 1 2026-09-30T15:31:44 Improper neutralization of special elements used in an SQL command ('SQL injecti
CVE-2026-82307 9.8 0.47% 1 0 2026-09-30T15:31:39 Improper neutralization of special elements used in an SQL command ('SQL injecti
CVE-2026-97240 7.5 0.42% 1 0 2026-09-30T15:31:38 Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions
CVE-2026-97244 7.5 0.41% 1 0 2026-09-30T15:31:38 Contributor Path Traversal in Creator LMS <= 1.2.19 versions.
CVE-2026-96837 8.8 0.73% 1 0 2026-09-30T15:31:37 Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.
CVE-2026-97274 9.8 0.51% 1 0 2026-09-30T15:31:34 Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client
CVE-2026-97293 8.5 0.36% 1 0 2026-09-30T14:18:18.460000 Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
CVE-2026-97287 8.5 0.36% 1 0 2026-09-30T14:18:17.797000 Contributor SQL Injection in Event Tickets <= 5.29.5 versions.
CVE-2026-97248 9.8 0.56% 1 0 2026-09-30T14:18:15.890000 Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
CVE-2026-97241 7.5 0.42% 1 0 2026-09-30T14:18:15.073000 Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions.
CVE-2026-97197 7.5 0.39% 1 0 2026-09-30T14:18:14.280000 Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 v
CVE-2026-102331 9.6 0.43% 1 0 2026-09-30T13:15:08.430000 Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 a
CVE-2026-76992 7.5 0.57% 2 0 2026-09-30T12:35:21 The CODESYS Gateway Client allocates memory based on a size field in a gateway r
CVE-2026-94052 9.1 0.55% 1 0 2026-09-30T12:35:21 A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MI
CVE-2026-94002 7.5 0.43% 1 0 2026-09-30T12:35:16 Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd
CVE-2026-77185 9.1 0.51% 2 0 2026-09-30T12:35:16 Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0
CVE-2026-10764 8.7 0.24% 1 0 2026-09-30T12:35:15 Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle
CVE-2026-89294 7.5 0.65% 1 0 2026-09-30T09:31:20 The Simply Schedule Appointments plugin for WordPress is vulnerable to Local Fil
CVE-2026-92867 8.8 0.34% 1 0 2026-09-30T09:31:20 An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an au
CVE-2026-102458 9.8 0.43% 2 0 2026-09-30T09:31:20 EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. U
CVE-2026-97196 9.1 0.30% 2 0 2026-09-30T09:31:11 Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web /
CVE-2026-92870 7.5 0.32% 1 0 2026-09-30T09:31:11 A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow
CVE-2026-103110 9.8 0.61% 2 0 2026-09-30T06:31:42 Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper in
CVE-2026-102911 9.9 1.78% 2 0 2026-09-30T06:31:35 A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknow
CVE-2026-95373 8.8 0.37% 1 0 2026-09-30T04:18:49.650000 Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a rem
CVE-2026-103088 7.5 0.69% 1 0 2026-09-30T03:31:41 Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc
CVE-2026-103102 8.6 0.32% 1 0 2026-09-30T03:31:41 Pexip Infinity before 41.0 is affected by improper input validation in the signa
CVE-2026-103101 8.6 0.27% 1 0 2026-09-30T03:31:41 Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input valid
CVE-2026-103100 7.5 0.26% 1 0 2026-09-30T03:31:40 Pexip Infinity before 40.1 is affected by improper input validation in the signa
CVE-2026-86131 None 0.33% 6 0 2026-09-30T00:32:48 A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client
CVE-2026-71379 10.0 0.44% 1 0 2026-09-30T00:32:46 The file export endpoint allows any unauthenticated attacker to export arbitrary
CVE-2026-102794 9.1 2.36% 2 0 2026-09-30T00:32:32 A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects
CVE-2026-96587 10.0 0.34% 1 0 2026-09-29T22:19:05.860000 The Viidure Android application embeds permanent, plaintext cloud storage creden
CVE-2026-96274 7.4 0.16% 1 0 2026-09-29T22:19:05.720000 In Baicells Nova 430H, an unauthenticated device within radio range can send a m
CVE-2026-94204 7.5 0.27% 1 0 2026-09-29T21:33:36 The central cloud storage backend for the entire dashcam platform is misconfigur
CVE-2026-95372 8.3 0.38% 1 0 2026-09-29T21:33:22 Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a r
CVE-2026-84782 8.2 0.39% 3 0 2026-09-29T21:27:41.130000 Issue summary: The DTLS retransmission logic does not correctly handle a handsha
CVE-2026-92370 8.8 0.38% 1 0 2026-09-29T18:31:49 An improper access control vulnerability in TeamViewer Full Client, Host, and re
CVE-2026-92368 7.8 0.14% 1 0 2026-09-29T18:31:46 TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain
CVE-2026-102673 8.2 0.15% 1 0 2026-09-29T18:05:37 ### Impact Popups opened from a sandboxed iframe through a link (for example `t
CVE-2026-102676 8.3 0.45% 1 0 2026-09-29T18:02:22 ### Impact A `<webview>` could enable Node.js integration in its Web Workers ev
CVE-2026-86950 8.8 1.24% 10 1 2026-09-29T15:32:17 An out-of-bounds write issue was addressed with improved bounds checking. This i
CVE-2026-88771 9.8 1.06% 7 10 2026-09-29T04:18:01.603000 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc
CVE-2026-88772 8.1 1.30% 10 7 2026-09-28T12:32:09 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-87902 8.1 19.76% 4 26 2026-09-28T12:20:54.040000 An unauthenticated attacker can make `get_page_template()` page-template resolut
CVE-2026-100382 None 0.95% 2 1 2026-09-26T00:32:22 Improper Neutralization of Special Elements used in an OS Command ('OS Command I
CVE-2026-85706 10.0 92.96% 1 14 2026-09-24T12:52:28.143000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7
CVE-2026-85102 9.8 7.55% 3 0 2026-09-23T18:22:07.453000 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-93616 9.8 19.65% 3 2 2026-09-23T16:38:38.987000 A directory traversal and file upload vulnerability allows an unauthenticated at
CVE-2026-93710 7.5 0.63% 1 0 2026-09-22T21:32:15 Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying
CVE-2026-88738 8.8 0.61% 1 0 2026-09-22T19:43:52.337000 Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulner
CVE-2026-87079 7.5 0.63% 1 0 2026-09-22T19:07:00.983000 Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadr
CVE-2026-93556 None 0.30% 2 0 2026-09-22T09:31:18 The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, w
CVE-2026-94426 3.5 0.33% 1 0 2026-09-22T00:31:02 A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted elem
CVE-2026-80521 7.8 0.17% 1 2 2026-09-21T14:17:20.193000 In the Linux kernel, the following vulnerability has been resolved: af_unix: Un
CVE-2026-85046 8.8 48.88% 1 8 2026-09-21T13:17:10.970000 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at
CVE-2026-63490 7.5 0.69% 1 0 2026-09-18T20:09:01.757000 Handlebars.java provides logic-less and semantic Mustache templates with Java. P
CVE-2026-86869 6.5 0.34% 1 0 2026-09-17T18:31:49 An out-of-bounds write issue was addressed with improved bounds checking. This i
CVE-2026-50610 None 0.13% 1 0 2026-09-17T09:33:03 A vulnerability has been identified in the Acer System Monitoring component incl
CVE-2026-76460 10.0 14.03% 1 1 2026-09-16T21:33:00 A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an
CVE-2026-76461 9.8 28.27% 1 4 2026-09-14T21:32:49 A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure
CVE-2026-81578 9.8 85.17% 1 2 template 2026-09-14T00:16:56.207000 An improper access control vulnerability exists in the web management interface
CVE-2026-84869 9.9 0.92% 1 0 2026-09-12T04:16:42.757000 A condition in the ScreenConnect client may allow files to be transferred and ex
CVE-2026-86218 9.8 12.93% 1 3 template 2026-09-09T05:18:19.490000 N-central is vulnerable to a pre-auth remote code execution This issue affects N
CVE-2026-81963 7.8 0.39% 2 0 2026-09-08T21:34:09 Improper link resolution before file access ('link following') in Windows Update
CVE-2026-75650 10.0 3.95% 1 6 2026-09-08T21:33:09 Adobe Commerce is affected by an Improper Neutralization of Special Elements Use
CVE-2026-70590 4.8 0.32% 1 0 2026-09-08T20:51:43.490000 Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level u
CVE-2026-60004 9.8 23.99% 1 11 2026-09-08T17:56:31 ### Summary Gitea's `diffpatch` endpoint can be abused to install and execute a
CVE-2026-83548 10.0 8.76% 1 3 template 2026-09-02T18:32:06 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla
CVE-2026-83549 7.8 10.76% 1 2 2026-09-02T18:32:06 Post-authentication Improper Neutralization of Special Elements used in an OS Co
CVE-2026-82078 9.1 61.39% 1 2 2026-08-31T21:31:56 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-73570 8.9 11.74% 5 10 2026-08-24T13:19:17.577000 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-64508 None 0.21% 1 0 2026-08-19T18:32:01 In the Linux kernel, the following vulnerability has been resolved: bpf: Suppor
CVE-2026-64507 0 0.16% 1 0 2026-08-19T17:20:15.123000 In the Linux kernel, the following vulnerability has been resolved: x86/bugs: E
CVE-2026-72018 7.8 0.18% 1 1 2026-08-17T06:17:59.313000 In the Linux kernel, the following vulnerability has been resolved: dibs: loopb
CVE-2025-41739 5.9 0.35% 1 0 2026-06-17T09:23:04.017000 An unauthenticated remote attacker, who beats a race condition, can exploit a fl
CVE-2026-35273 9.8 9.44% 1 4 template 2026-06-12T18:31:50 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS
CVE-2026-22755 None 20.44% 1 0 2026-01-20T21:31:34 Improper Neutralization of Special Elements used in a Command ('Command Injectio
CVE-2025-41700 7.8 0.15% 1 0 2025-12-01T12:30:34 An unauthenticated attacker can trick a local user into executing arbitrary code
CVE-2025-41738 7.5 0.39% 1 0 2025-12-01T12:30:33 An unauthenticated remote attacker may cause the visualisation server of the COD
CVE-2025-4802 9.8 0.59% 1 1 2025-11-03T21:34:58 Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Librar
CVE-2024-6872 4.3 0.33% 2 0 2024-08-03T12:30:40 The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages,
CVE-2026-84411 0 0.00% 3 0 N/A
CVE-2026-54154 0 0.00% 1 0 N/A
CVE-2026-72898 0 19.05% 1 9 N/A
CVE-2026-102989 0 0.00% 1 0 N/A
CVE-2026-102147 0 0.43% 2 0 N/A
CVE-2026-94545 0 0.80% 3 5 N/A
CVE-2026-102149 0 0.33% 1 0 N/A
CVE-2026-102106 0 0.64% 1 0 N/A
CVE-2026-102105 0 0.53% 1 0 N/A
CVE-2026-91881 0 0.00% 1 0 N/A
CVE-2026-43598 0 0.00% 1 0 N/A
CVE-2026-88650 0 0.00% 1 0 N/A
CVE-2026-94603 0 0.00% 1 0 N/A
CVE-2026-102530 0 0.00% 1 0 N/A
CVE-2026-12345 0 0.18% 2 0 N/A

CVE-2026-79896
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-01T16:17:59.940000

2 posts

Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.

thehackerwire@mastodon.social at 2026-10-01T16:32:24.000Z ##

🟠 CVE-2026-79896 - High (7.5)

Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is nor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T16:32:24.000Z ##

🟠 CVE-2026-79896 - High (7.5)

Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is nor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14157
(0 None)

EPSS: 0.00%

updated 2026-10-01T16:17:40.980000

1 posts

Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.

offseq@infosec.exchange at 2026-10-01T03:00:27.000Z ##

ASUS Routers hit by CRITICAL vuln: CVE-2026-14157 (CVSS 9.4). Remote authenticated users can execute arbitrary commands via crafted file upload in web interface. Restrict access, monitor closely. radar.offseq.com/threat/cve-20 #OffSeq #CVE202614157 #ASUS #Vuln #BlueTeam

##

CVE-2026-12627
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-01T16:17:40.480000

2 posts

Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.

thehackerwire@mastodon.social at 2026-10-01T16:18:28.000Z ##

🔴 CVE-2026-12627 - Critical (9.8)

Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T16:18:28.000Z ##

🔴 CVE-2026-12627 - Critical (9.8)

Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101283
(0 None)

EPSS: 0.43%

updated 2026-10-01T16:17:32.460000

1 posts

iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22

offseq@infosec.exchange at 2026-10-01T00:00:37.000Z ##

CVE-2026-101283: CRITICAL heap buffer overflow in esnet iperf3 (v3.20 & v3.21). Unauthenticated attackers can trigger memory corruption via decrypt_rsa_message(). Upgrade to 3.22 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026101283 #infosec #vulnerability

##

CVE-2026-102831
(8.1 HIGH)

EPSS: 0.20%

updated 2026-10-01T15:20:42

1 posts

## Description JupyterLab 4.5.0 enabled copying and pasing cells through the system clipboard. The paste path parses clipboard text as cell JSON and inserts the cells without clearing `metadata.trusted`, so a payload can declare its own output as trusted. JupyterLab does not sanitize a trusted output and evaluates the `<script>` elements it contains, so pasting the cell runs attacker's JavaScript

thehackerwire@mastodon.social at 2026-09-29T19:46:31.000Z ##

🟠 CVE-2026-102831 - High (8.1)

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97297
(7.6 HIGH)

EPSS: 0.00%

updated 2026-10-01T15:17:38.960000

2 posts

Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions.

thehackerwire@mastodon.social at 2026-10-01T16:32:34.000Z ##

🟠 CVE-2026-97297 - High (7.6)

Subscriber Broken Access Control in Gratisfaction &lt;= 4.6.3 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T16:32:34.000Z ##

🟠 CVE-2026-97297 - High (7.6)

Subscriber Broken Access Control in Gratisfaction &lt;= 4.6.3 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97284
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-01T15:17:38.807000

2 posts

Contributor PHP Object Injection in Icegram <= 3.1.31 versions.

CVE-2026-97277
(7.6 HIGH)

EPSS: 0.00%

updated 2026-10-01T15:17:38.380000

2 posts

Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.

thehackerwire@mastodon.social at 2026-10-01T16:18:38.000Z ##

🟠 CVE-2026-97277 - High (7.6)

Subscriber Broken Access Control in Social Boost &lt;= 3.6.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T16:18:38.000Z ##

🟠 CVE-2026-97277 - High (7.6)

Subscriber Broken Access Control in Social Boost &lt;= 3.6.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92966
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-10-01T15:17:35.830000

1 posts

The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbit

1 repos

https://github.com/murrez/CVE-2026-92966

offseq@infosec.exchange at 2026-10-01T06:00:25.000Z ##

CVE-2026-92966: CRITICAL code injection in LatePoint Appointment Booking Plugin (<=5.7.0) for WordPress. Unauthenticated attackers can inject & execute shortcodes, risking full site compromise. Disable plugin or restrict access until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202692966

##

CVE-2026-79901
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-10-01T15:17:32.163000

2 posts

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

thehackerwire@mastodon.social at 2026-10-01T15:03:49.000Z ##

🔴 CVE-2026-79901 - Critical (9.9)

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T15:03:49.000Z ##

🔴 CVE-2026-79901 - Critical (9.9)

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2024-58388
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-01T15:17:17.347000

2 posts

Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, inclu

cR0w at 2026-10-01T14:52:02.393Z ##

Fuck this bullshit. This 2024 CVE was just published today. Which, fine, whatever. It happens. Except it specifically says it was observed EITW in July 2024.

cve.org/CVERecord?id=CVE-2024-

Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.

Witholding a CVE for something known to be EITW for over two years is fucking bullshit. Especially when the PoC was published in June 2024:

pierrekim.github.io/blog/2024-

But at least there's a Nuclei template:

github.com/projectdiscovery/nu

##

cR0w@infosec.exchange at 2026-10-01T14:52:02.000Z ##

Fuck this bullshit. This 2024 CVE was just published today. Which, fine, whatever. It happens. Except it specifically says it was observed EITW in July 2024.

cve.org/CVERecord?id=CVE-2024-

Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.

Witholding a CVE for something known to be EITW for over two years is fucking bullshit. Especially when the PoC was published in June 2024:

pierrekim.github.io/blog/2024-

But at least there's a Nuclei template:

github.com/projectdiscovery/nu

##

CVE-2026-66246
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-01T15:07:27.747000

2 posts

iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data.

thehackerwire@mastodon.social at 2026-10-01T15:03:58.000Z ##

🟠 CVE-2026-66246 - High (8.8)

iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T15:03:58.000Z ##

🟠 CVE-2026-66246 - High (8.8)

iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62059
(7.6 HIGH)

EPSS: 0.00%

updated 2026-10-01T14:34:35.357000

2 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1.

1 repos

https://github.com/Hassham1/CVE-2026-62059-ultimate-member-sqli-poc

thehackerwire@mastodon.social at 2026-10-01T15:04:07.000Z ##

🟠 CVE-2026-62059 - High (7.6)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-01T15:04:07.000Z ##

🟠 CVE-2026-62059 - High (7.6)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102115
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-10-01T14:17:15.510000

1 posts

Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.

CVE-2026-102427
(10.0 CRITICAL)

EPSS: 0.84%

updated 2026-10-01T13:46:23.090000

1 posts

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that woul

1 repos

https://github.com/murrez/CVE-2026-102427

Matchbook3469@mastodon.social at 2026-10-01T13:48:55.000Z ##

🔴 New security advisory:

CVE-2026-102427 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#Cybersecurity #PatchNow #InfoSecCommunity

##

CVE-2026-7175
(0 None)

EPSS: 0.00%

updated 2026-10-01T13:04:49.340000

1 posts

CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;

EUVD_Bot@mastodon.social at 2026-10-01T11:06:11.000Z ##

🚨 EUVD-2026-90745

📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Entradium
🏢 Vendor: Crocantickets
📅 Updated: 2026-10-01

📝 CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2025-41753
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-01T13:01:47.180000

1 posts

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.

certvde@infosec.exchange at 2026-10-01T06:41:41.000Z ##

🔒 New CSAF advisory published

VDE-2025-102
WAGO: Multiple Devices are affected by a Vulnerability in BACnet IP Stack
CVE-2025-41753

Multiple WAGO devices are affected by a vulnerability in the dynamic creation of BACnet File Objects. The object name is used as a file path without sufficient validation and is not restricted to the intend…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: wago.csaf-tp.certvde.com/.well

#OT #Advisory

##

CVE-2026-7174(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-10-01T12:31:22

1 posts

CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Specifically, in the Name and Field parameters of the endpoint /tools/discount_wizard/discount_config during the process of creating discounts assigned to an event. This vulnerability allows JavaScript code to be injected into the affected parameters, which executes when an event’s discount list page is displa

EUVD_Bot@mastodon.social at 2026-10-01T11:06:15.000Z ##

🚨 EUVD-2026-90744

📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Entradium
🏢 Vendor: Crocantickets
📅 Updated: 2026-10-01

📝 CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Specifically, in the Name and Field parameters of the endpoint /tools/discount_wizard/discount_config during the process of creating discounts assigned to an eve...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-7176(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-10-01T12:31:22

1 posts

CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for an event, which allows for the injection of JavaScript that will execute on the public ticket purchase page for the event.

EUVD_Bot@mastodon.social at 2026-10-01T11:06:09.000Z ##

🚨 EUVD-2026-90746

📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Entradium
🏢 Vendor: Crocantickets
📅 Updated: 2026-10-01

📝 CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for an event, which allows for the injection of JavaSc...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-7173(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-10-01T12:31:17

1 posts

CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data. * (Stored XSS) The City parameter in the endpoint /events/<event_name>/edit_general during the process of creating or editing events assigned to a promoter allows for the in

EUVD_Bot@mastodon.social at 2026-10-01T11:06:16.000Z ##

🚨 EUVD-2026-90743

📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Entradium
🏢 Vendor: Crocantickets
📅 Updated: 2026-10-01

📝 CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data.

* (Stored XSS) The City...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-103655(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-10-01T09:30:42

2 posts

MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same c

cR0w at 2026-10-01T12:52:40.096Z ##

This is an interesting vuln and one that can be a great example of why a sev:CRIT may not be high priority.

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user's login could replay it to authenticate a second session as that user. Preconditions: - The target user has TOTP-based two-factor authentication enabled. - The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client). - The replay must occur within the TOTP validity period. Security impact: - Unauthorized account access by replaying a captured one-time code. - Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user. Affected versions: <v2.5.48.

nvd.nist.gov/vuln/detail/cve-2

##

cR0w@infosec.exchange at 2026-10-01T12:52:40.000Z ##

This is an interesting vuln and one that can be a great example of why a sev:CRIT may not be high priority.

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user's login could replay it to authenticate a second session as that user. Preconditions: - The target user has TOTP-based two-factor authentication enabled. - The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client). - The replay must occur within the TOTP validity period. Security impact: - Unauthorized account access by replaying a captured one-time code. - Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user. Affected versions: <v2.5.48.

nvd.nist.gov/vuln/detail/cve-2

##

CVE-2026-78210(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-10-01T06:31:25

2 posts

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization.

offseq at 2026-10-01T12:00:24.142Z ##

CVE-2026-78210: HIGH severity in Octopus Server (CVSS 7.1) lets users with scoped permissions execute unauthorized scripts in certain environments. Patch status unknown — minimize permissions and monitor for updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-01T12:00:24.000Z ##

CVE-2026-78210: HIGH severity in Octopus Server (CVSS 7.1) lets users with scoped permissions execute unauthorized scripts in certain environments. Patch status unknown — minimize permissions and monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #OctopusDeploy #Vuln #CVE202678210

##

CVE-2026-76504
(9.8 CRITICAL)

EPSS: 1.10%

updated 2026-10-01T04:18:19.193000

20 posts

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a spe

1 repos

https://github.com/ShadowForge-Cyber/CVE-2026-76504-Proof-of-concept

thecybermind at 2026-10-01T12:27:31.848Z ##

Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

CISA’s active exploitation verification of CVE-2026-76504 demands an immediate, high-priority posture adjustment across all Cisco Catalyst SD-WAN Manager…...

thecybermind.co/2026/10/01/cve

##

Analyst207@mastodon.social at 2026-10-01T11:51:38.000Z ##

CISA Flags Exploited Cisco SD-WAN Flaw

A critical vulnerability in Cisco SD-WAN Manager, known as CVE-2026-76504, has been flagged by CISA and is being actively exploited, allowing hackers to gain admin-level access with a CVSS score of 9.8. This hex encoding flaw could let unauthenticated attackers remotely access and control affected systems.

osintsights.com/cisa-flags-exp

#CiscoSdwan #Cve202676504 #Cisa #ExploitedVulnerabilities #KnownExploitedVulnerabilities

##

thecybermind at 2026-10-01T11:16:17.864Z ##

Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

CISA’s active exploitation verification of CVE-2026-76504 demands an immediate, high-priority posture adjustment across all Cisco Catalyst SD-WAN Manager…...

thecybermind.co/2026/10/01/cve

##

thecybermind at 2026-10-01T11:05:43.182Z ##

Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

Strategic Threat Advisory: CVE-2026-76504 Affected Vendor & Product: Cisco - Catalyst SD-WAN Manager Vulnerability Class (CWE):...

thecybermind.co/2026/10/01/cve

##

thecybermind at 2026-10-01T11:02:05.878Z ##

Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

Threat Advisory: CVE-2026-76504 Affected Vendor/Product: Cisco - Catalyst SD-WAN Manager Vulnerability Type (CWE): N/A Operational Threat Level:...

thecybermind.co/2026/10/01/cve

##

thecybermind@infosec.exchange at 2026-10-01T12:27:31.000Z ##

Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

CISA’s active exploitation verification of CVE-2026-76504 demands an immediate, high-priority posture adjustment across all Cisco Catalyst SD-WAN Manager…...

thecybermind.co/2026/10/01/cve

##

thecybermind@infosec.exchange at 2026-10-01T11:16:17.000Z ##

Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

CISA’s active exploitation verification of CVE-2026-76504 demands an immediate, high-priority posture adjustment across all Cisco Catalyst SD-WAN Manager…...

thecybermind.co/2026/10/01/cve

##

thecybermind@infosec.exchange at 2026-10-01T11:05:43.000Z ##

Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

Strategic Threat Advisory: CVE-2026-76504 Affected Vendor & Product: Cisco - Catalyst SD-WAN Manager Vulnerability Class (CWE):...

thecybermind.co/2026/10/01/cve

##

thecybermind@infosec.exchange at 2026-10-01T11:02:05.000Z ##

Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

Threat Advisory: CVE-2026-76504 Affected Vendor/Product: Cisco - Catalyst SD-WAN Manager Vulnerability Type (CWE): N/A Operational Threat Level:...

thecybermind.co/2026/10/01/cve

##

beyondmachines1@infosec.exchange at 2026-10-01T08:01:13.000Z ##

Cisco Patches Actively Exploited Zero-Day in Catalyst SD-WAN Manager

Cisco released security updates for a zero-day vulnerability (CVE-2026-76504) in Catalyst SD-WAN Manager that attackers are actively exploiting to gain admin privileges. The flaw allows unauthenticated remote access to the management API through URI encoding bypasses.

**If you run Cisco Catalyst SD-WAN Manager, make sure it is isolated from the internet and reachable from trusted networks only, then patch it ASAP to the fixed version for your release (or migrate if you're on anything older than 20.9). Before patching, save an admin-tech file and check the logs for suspicious j_security_check requests or activity from viptela-reserved- accounts. If you find any, assume your whole SD-WAN network is compromised and call in incident response.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

secdb@infosec.exchange at 2026-09-30T19:00:11.000Z ##

🚨 [CISA-2026:0930] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-76504 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Catalyst SD-WAN Manager
- Notes: sec.cloudapps.cisco.com/securi ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260930 #cisa20260930 #cve_2026_76504 #cve202676504

##

cyberworldops@infosec.exchange at 2026-09-30T18:50:00.000Z ##

Cisco confirmed active exploitation of CVE-2026-76504, an authentication bypass in Catalyst SD-WAN Manager API session handling. It allows unauthenticated remote admin access, enabling full control of SD-WAN fabrics. Prioritize patching and review management-plane logs for abuse. #CiscoSecurity #SdWan #AuthBypass

cyberworldops.eu/en/cisco-sd-w

##

DarkWebInformer@infosec.exchange at 2026-09-30T18:34:31.000Z ##

🚨 Cisco warns critical SD-WAN Manager zero-day is actively exploited

CVE-2026-76504 is a critical authentication bypass affecting Cisco Catalyst SD-WAN Manager.

The flaw allows an unauthenticated remote attacker to send a crafted HTTP request that bypasses an API authentication rule and grants access with admin privileges.
⠀
The vulnerability carries a CVSS score of 9.8 and affects the product regardless of its configuration.

Cisco became aware of active exploitation in September after investigating a support case.
⠀
There are no workarounds. Administrators should install a fixed release immediately and investigate internet-facing systems for signs of compromise.

Source: bleepingcomputer.com/news/secu

##

ifin@infosec.exchange at 2026-09-30T18:29:01.000Z ##

Well would you look at that; it's Cisco 0-day o'clock again.

ifin.network/t/cve-2026-76504-

#ThreatIntel #ThreatIntelligence #IFIN

##

cisakevtracker@mastodon.social at 2026-09-30T18:01:01.000Z ##

CVE ID: CVE-2026-76504
Vendor: Cisco
Product: Catalyst SD-WAN Manager
Date Added: 2026-09-30
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

news@fawkes.rocks at 2026-09-30T17:22:28.000Z ##

Cisco SD-WAN Manager zero-day CVE-2026-76504 exploited

fawkes.rocks/2026/09/30/cisco-

##

security_crawler_carl@infosec.exchange at 2026-09-30T16:54:42.000Z ##

🏆 New Achievement! Unauthenticated and Loving It!

Welcome to Module 7: API Authentication and Why Your Vendor Forgot To Include It. Today's learning objective is CVE-2026-76504, a critical zero-day in Cisco Catalyst SD-WAN Manager. Attackers are actively exploiting a flaw in the API authentication mechanism to gain full administrator privileges on your systems. Without a username. Without a password. Without so much as a polite knock. (1/3)

##

AAKL@infosec.exchange at 2026-09-30T16:09:42.000Z ##

New advisory, new flaw.

Cisco: CRITICAL CVE-2026-76504: Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

More on that Cisco vulnerability:

Rapid7: Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504) rapid7.com/blog/post/etr-criti @Rapid7Official

Also:

Broadcom has several advisories today, three of them addressing critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom #infosec #vulnerability

##

oversecurity@mastodon.social at 2026-09-30T15:50:31.000Z ##

Cisco warns of new SD-WAN zero-day exploited in attacks

Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are...

🔗️ [Bleepingcomputer] link.is.it/cZgOkH

##

DailyCyberSecurity@infosec.exchange at 2026-09-30T15:16:24.000Z ##

Attackers exploit CVE-2026-76504, a 9.8 authentication bypass in Cisco SD-WAN Manager that grants admin API access. Patch now.

#Cisco #SDWAN #CVE202676504 #AuthenticationBypass #ActivelyExploited #CyberSecurity

securityonline.info/cisco-sd-w

##

CVE-2026-47600
(7.8 HIGH)

EPSS: 0.19%

updated 2026-10-01T04:18:18.747000

1 posts

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an error-handling path could operate on an improperly initialized resource. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.

thehackerwire@mastodon.social at 2026-09-30T16:32:03.000Z ##

🟠 CVE-2026-47600 - High (7.8)

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an error-handling path could operate on an improperly initialized resource. A successful exploit of this vulnerability might lead to code execu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13313(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-10-01T03:31:14

3 posts

An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security

offseq at 2026-10-01T13:30:28.141Z ##

CVE-2026-13313 (HIGH, CVSS 8.9) in ASUS routers: Authenticated attackers can enable Telnet via debug code, gaining root command execution. Restrict management access & monitor Telnet until patch info is released. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-01T13:30:28.000Z ##

CVE-2026-13313 (HIGH, CVSS 8.9) in ASUS routers: Authenticated attackers can enable Telnet via debug code, gaining root command execution. Restrict management access & monitor Telnet until patch info is released. radar.offseq.com/threat/cve-20 #OffSeq #ASUS #Infosec #Vuln

##

DailyCyberSecurity@infosec.exchange at 2026-10-01T03:40:21.000Z ##

Learn how to patch critical ASUS security vulnerabilities like CVE-2026-13313 to protect your routers and motherboards from severe network exploits.

#ASUS #Cybersecurity #Vulnerability #Router #Hardware

securityonline.info/asus-secur

##

CVE-2026-102823
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-30T23:27:18

1 posts

### Summary CVE-2026-68930 was fixed by adding `Session::is_established_channel()` in `russh/src/server/encrypted.rs`, which gates every channel-scoped SERVER-side message (CHANNEL_REQUEST, CHANNEL_DATA, CHANNEL_EOF, CHANNEL_CLOSE, CHANNEL_WINDOW_ADJUST, CHANNEL_EXTENDED_DATA) on `enc.channels.get(&channel).is_some_and(|c| c.confirmed)` before invoking any `Handler` callback. The identical validat

thehackerwire@mastodon.social at 2026-09-29T19:46:40.000Z ##

🟠 CVE-2026-102823 - High (7.5)

Russh is a Rust SSH client and server library. Prior to 0.63.1, client_read_authenticated in russh/src/client/encrypted.rs forwards CHANNEL_DATA, CHANNEL_EXTENDED_DATA, CHANNEL_EOF, CHANNEL_CLOSE, CHANNEL_OPEN_FAILURE, CHANNEL_SUCCESS, CHANNEL_FAI...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101276(CVSS UNKNOWN)

EPSS: 0.43%

updated 2026-09-30T21:32:15

1 posts

iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.

offseq@infosec.exchange at 2026-10-01T01:30:23.000Z ##

CVE-2026-101276: esnet iperf3 3.21 suffers a CRITICAL remote use-after-free (CVSS 9.2). Unauthenticated attackers can trigger memory corruption or RCE. Upgrade to 3.22+ now. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE2026101276 #iperf3 #infosec

##

CVE-2026-76722
(9.8 CRITICAL)

EPSS: 0.54%

updated 2026-09-30T21:32:03

2 posts

Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.

DailyCyberSecurity@infosec.exchange at 2026-09-30T03:37:33.000Z ##

HPE fixed 18 HPE Instant ON vulnerabilities in its access points, including CVSS 9.8 RCE flaws CVE-2026-76721 and CVE-2026-76722. Update to 3.4.2.0.

#HPE #InstantON #HPENetworking #CVE202676721 #WiFiSecurity #AccessPoint #RCE #PatchNow

securityonline.info/hpe-instan

##

thehackerwire@mastodon.social at 2026-09-29T20:31:30.000Z ##

🔴 CVE-2026-76722 - Critical (9.8)

Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76721
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-09-30T21:32:02

2 posts

Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.

DailyCyberSecurity@infosec.exchange at 2026-09-30T03:37:33.000Z ##

HPE fixed 18 HPE Instant ON vulnerabilities in its access points, including CVSS 9.8 RCE flaws CVE-2026-76721 and CVE-2026-76722. Update to 3.4.2.0.

#HPE #InstantON #HPENetworking #CVE202676721 #WiFiSecurity #AccessPoint #RCE #PatchNow

securityonline.info/hpe-instan

##

thehackerwire@mastodon.social at 2026-09-29T20:31:21.000Z ##

🔴 CVE-2026-76721 - Critical (9.8)

Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76723
(9.6 CRITICAL)

EPSS: 0.31%

updated 2026-09-30T21:32:02

1 posts

Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

thehackerwire@mastodon.social at 2026-09-29T20:31:39.000Z ##

🔴 CVE-2026-76723 - Critical (9.6)

Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62146
(7.8 HIGH)

EPSS: 0.15%

updated 2026-09-30T20:17:34.013000

1 posts

A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.

1 repos

https://github.com/TeamN4C/SG-2026-0026

thehackerwire@mastodon.social at 2026-09-30T12:46:01.000Z ##

🟠 CVE-2026-62146 - High (7.8)

A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103111
(7.6 HIGH)

EPSS: 0.21%

updated 2026-09-30T20:17:29.847000

1 posts

PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.

thehackerwire@mastodon.social at 2026-09-30T05:30:34.000Z ##

🟠 CVE-2026-103111 - High (7.6)

PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103106
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-30T20:17:29.517000

1 posts

Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulnerability or having administrative access to the o

thehackerwire@mastodon.social at 2026-09-30T03:32:22.000Z ##

🟠 CVE-2026-103106 - High (7.8)

Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102489
(0 None)

EPSS: 0.71%

updated 2026-09-30T19:57:08.043000

1 posts

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

security_crawler_carl@infosec.exchange at 2026-09-30T20:28:42.000Z ##

🏆 New Achievement! Root in the Wild!

Observe the Zammad ticketing system in its natural habitat — quietly managing support queues, utterly unaware it carries two zero-days, CVE-2026-102489 and CVE-2026-102490, like a doomed species bearing a genetic flaw it cannot name. An autonomous AI agent, patient and efficient as a nature film's apex predator, chained the pair together: session hijack, remote code execution, root escalation — all in mere seconds. The herd had no warning. (1/2)

##

CVE-2026-79625
(8.1 HIGH)

EPSS: 0.40%

updated 2026-09-30T19:57:08.043000

2 posts

Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.

thehackerwire@mastodon.social at 2026-09-30T11:32:19.000Z ##

🟠 CVE-2026-79625 - High (8.1)

Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-09-30T09:22:53.000Z ##

🔒 New CSAF advisory published

VDE-2026-097
CODESYS Control Runtime - Improper Synchronization in Monitoring
CVE-2026-79625

The monitoring functionality of affected CODESYS Control runtime systems processes read and write requests to PLC application data sent by the CODESYS Development System and other clients suc…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: codesys.csaf-tp.certvde.com/.w

#OT #Advisory

##

CVE-2026-102826
(8.1 HIGH)

EPSS: 0.46%

updated 2026-09-30T19:56:45.443000

1 posts

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The missing include.path classification permits Git to load an attacker-controlled configuration file, and t

thehackerwire@mastodon.social at 2026-09-29T20:02:11.000Z ##

🟠 CVE-2026-102826 - High (8.1)

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102827
(8.1 HIGH)

EPSS: 0.36%

updated 2026-09-30T19:56:45.443000

1 posts

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option abbreviations. Attacker-influenced push arguments such as abbreviated --receive-pack or --e

thehackerwire@mastodon.social at 2026-09-29T19:46:22.000Z ##

🟠 CVE-2026-102827 - High (8.1)

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangero...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102674
(8.2 HIGH)

EPSS: 0.27%

updated 2026-09-30T19:38:27.293000

1 posts

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTML sandbox restrictions. Untrusted content in a sandboxed top-level document that was permitted to open popups could therefore create a window with the

CVE-2026-102490(CVSS UNKNOWN)

EPSS: 0.32%

updated 2026-09-30T18:33:55

1 posts

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

security_crawler_carl@infosec.exchange at 2026-09-30T20:28:42.000Z ##

🏆 New Achievement! Root in the Wild!

Observe the Zammad ticketing system in its natural habitat — quietly managing support queues, utterly unaware it carries two zero-days, CVE-2026-102489 and CVE-2026-102490, like a doomed species bearing a genetic flaw it cannot name. An autonomous AI agent, patient and efficient as a nature film's apex predator, chained the pair together: session hijack, remote code execution, root escalation — all in mere seconds. The herd had no warning. (1/2)

##

CVE-2026-47593
(7.8 HIGH)

EPSS: 0.18%

updated 2026-09-30T18:33:55

1 posts

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and denial of service.

thehackerwire@mastodon.social at 2026-09-30T17:02:07.000Z ##

🟠 CVE-2026-47593 - High (7.8)

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47592
(7.8 HIGH)

EPSS: 0.19%

updated 2026-09-30T18:33:55

1 posts

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

thehackerwire@mastodon.social at 2026-09-30T17:01:57.000Z ##

🟠 CVE-2026-47592 - High (7.8)

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47599
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-30T18:33:54

1 posts

NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DMA mapping. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.

thehackerwire@mastodon.social at 2026-09-30T16:31:54.000Z ##

🟠 CVE-2026-47599 - High (7.8)

NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DMA mapping. A successful exploit of this vulnerab...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47601
(7.8 HIGH)

EPSS: 0.18%

updated 2026-09-30T18:33:49

1 posts

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of memory access permissions when importing a read-only buffer from another device's DMA-BUF exporter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denia

thehackerwire@mastodon.social at 2026-09-30T16:32:12.000Z ##

🟠 CVE-2026-47601 - High (7.8)

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of memory access permissions when importing a read-onl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47591
(7.8 HIGH)

EPSS: 0.18%

updated 2026-09-30T18:18:34.637000

1 posts

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass read-only memory protection due to incorrect authorization, enabling write access to memory marked read-only. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

thehackerwire@mastodon.social at 2026-09-30T17:01:48.000Z ##

🟠 CVE-2026-47591 - High (7.8)

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass read-only memory protection due to incorrect authorization, enabling write access to memory marked read-only. A successfu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78902
(6.1 MEDIUM)

EPSS: 0.30%

updated 2026-09-30T17:23:08.953000

2 posts

Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package

christopherkunz@chaos.social at 2026-10-01T15:14:28.000Z ##

@hlux @bkastl Im Prinzip stimmt das mit meiner Wahrnehmung überein, vor allem im Vergleich mit Citrix, Ivanti, Fortinet, Cisco. Aber auch hier gab's neulich was Spannendes: netspi.com/blog/technical-blog

##

christopherkunz@chaos.social at 2026-10-01T15:14:28.000Z ##

@hlux @bkastl Im Prinzip stimmt das mit meiner Wahrnehmung überein, vor allem im Vergleich mit Citrix, Ivanti, Fortinet, Cisco. Aber auch hier gab's neulich was Spannendes: netspi.com/blog/technical-blog

##

CVE-2026-103108
(7.5 HIGH)

EPSS: 0.31%

updated 2026-09-30T17:16:41.460000

1 posts

Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service

thehackerwire@mastodon.social at 2026-09-30T03:47:46.000Z ##

🟠 CVE-2026-103108 - High (7.5)

Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92871
(7.5 HIGH)

EPSS: 0.29%

updated 2026-09-30T16:47:57.730000

1 posts

A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.

thehackerwire@mastodon.social at 2026-09-30T12:02:04.000Z ##

🟠 CVE-2026-92871 - High (7.5)

A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76570
(0 None)

EPSS: 0.50%

updated 2026-09-30T16:44:39.840000

2 posts

Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries.

1 repos

https://github.com/murrez/CVE-2026-76570

Matchbook3469@mastodon.social at 2026-10-01T14:17:40.000Z ##

🚨 New security advisory:

CVE-2026-76570 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #VulnerabilityManagement #CyberSec

##

AAKL@infosec.exchange at 2026-09-30T16:21:59.000Z ##

New. This relates to CVE-2026-76570.

VulnCheck: JCTables for Joomla: When "Already Escaped" Means Injectable vulncheck.com/blog/jctables-un @vulncheck #infoec #vulnerability #SQL

##

CVE-2026-103099
(7.5 HIGH)

EPSS: 0.31%

updated 2026-09-30T16:44:39.840000

1 posts

Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.

thehackerwire@mastodon.social at 2026-09-30T03:47:55.000Z ##

🟠 CVE-2026-103099 - High (7.5)

Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103105
(8.8 HIGH)

EPSS: 0.18%

updated 2026-09-30T16:44:39.840000

1 posts

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.

thehackerwire@mastodon.social at 2026-09-30T03:32:12.000Z ##

🟠 CVE-2026-103105 - High (8.8)

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unpriv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103104
(7.5 HIGH)

EPSS: 0.31%

updated 2026-09-30T16:44:39.840000

1 posts

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.

thehackerwire@mastodon.social at 2026-09-30T03:32:03.000Z ##

🟠 CVE-2026-103104 - High (7.5)

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103109
(7.7 HIGH)

EPSS: 0.24%

updated 2026-09-30T16:44:39.840000

1 posts

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.

thehackerwire@mastodon.social at 2026-09-30T03:17:52.000Z ##

🟠 CVE-2026-103109 - High (7.7)

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102455
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-30T16:30:42.327000

1 posts

EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

thehackerwire@mastodon.social at 2026-09-30T11:47:32.000Z ##

🔴 CVE-2026-102455 - Critical (9.8)

EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75098
(7.5 HIGH)

EPSS: 0.90%

updated 2026-09-30T16:18:58.363000

1 posts

The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The endpoint's only authentication gate relies on a nonce and token that are both publicl

thehackerwire@mastodon.social at 2026-09-30T11:33:29.000Z ##

🟠 CVE-2026-75098 - High (7.5)

The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18783
(8.8 HIGH)

EPSS: 0.39%

updated 2026-09-30T16:18:57.403000

1 posts

Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication Bypass. This issue affects Trex MES: through 2026-09-29.

1 repos

https://github.com/Hasanuyarrr/CVE-2026-18783-TREX-MES-Uygulamalarinda-Yetkisiz-Nesne-Erisimi

thehackerwire@mastodon.social at 2026-09-30T15:47:56.000Z ##

🟠 CVE-2026-18783 - High (8.8)

Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication Bypass.

This issue affects Trex MES: through 2026-09-29.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6806
(7.5 HIGH)

EPSS: 0.27%

updated 2026-09-30T16:18:39.783000

1 posts

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additio

thehackerwire@mastodon.social at 2026-09-30T12:02:13.000Z ##

🟠 CVE-2026-6806 - High (7.5)

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62097
(7.6 HIGH)

EPSS: 0.38%

updated 2026-09-30T16:17:32.973000

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business Directory: from n/a through 6.4.27.

thehackerwire@mastodon.social at 2026-09-30T15:47:37.000Z ##

🟠 CVE-2026-62097 - High (7.6)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business Directory: from n/a through 6.4.27.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19743
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-30T16:17:12.610000

1 posts

Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local pr

CVE-2026-102508
(0 None)

EPSS: 0.13%

updated 2026-09-30T16:14:10.347000

1 posts

Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client. The defect manifests differently depending on the version: - In 0.9.0

CVE-2026-93994
(8.1 HIGH)

EPSS: 0.47%

updated 2026-09-30T16:13:13.493000

1 posts

Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods "publickey,publickey". Apache MINA SSHD provides an equivalent configuration mechanism. In Apache MINA SSHD versions up

thehackerwire@mastodon.social at 2026-09-30T11:32:29.000Z ##

🟠 CVE-2026-93994 - High (8.1)

Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94053
(9.1 CRITICAL)

EPSS: 0.55%

updated 2026-09-30T16:13:13.493000

1 posts

Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ldap is an optional component. SS

thehackerwire@mastodon.social at 2026-09-30T11:01:42.000Z ##

🔴 CVE-2026-94053 - Critical (9.1)

Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.

Apache MINA SSHD is a Java library for client-side and server-side SSH.
The optional sshd-ldap component p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18782
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-09-30T15:31:44

1 posts

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.

1 repos

https://github.com/Hasanuyarrr/CVE-2026-18782-TREX-MES-Uygulamalarinda-SQL-Zafiyeti

thehackerwire@mastodon.social at 2026-09-30T15:47:46.000Z ##

🔴 CVE-2026-18782 - Critical (9.8)

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection.

This issue affects Trex MES: through...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82307
(9.8 CRITICAL)

EPSS: 0.47%

updated 2026-09-30T15:31:39

1 posts

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.

thehackerwire@mastodon.social at 2026-09-30T14:32:08.000Z ##

🔴 CVE-2026-82307 - Critical (9.8)

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection.

This issue affects SOPLOG: before Soplog 2026.9.4.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97240
(7.5 HIGH)

EPSS: 0.42%

updated 2026-09-30T15:31:38

1 posts

Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.

thehackerwire@mastodon.social at 2026-09-30T14:19:05.000Z ##

🟠 CVE-2026-97240 - High (7.5)

Unauthenticated Sensitive Data Exposure in StifLi Backup Tools &lt;= 2.2.7 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97244
(7.5 HIGH)

EPSS: 0.41%

updated 2026-09-30T15:31:38

1 posts

Contributor Path Traversal in Creator LMS <= 1.2.19 versions.

CVE-2026-96837
(8.8 HIGH)

EPSS: 0.73%

updated 2026-09-30T15:31:37

1 posts

Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.

thehackerwire@mastodon.social at 2026-09-30T14:49:10.000Z ##

🟠 CVE-2026-96837 - High (8.8)

Contributor Remote Code Execution (RCE) in CartFlows &lt;= 3.2.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97274
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-30T15:31:34

1 posts

Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.

thehackerwire@mastodon.social at 2026-09-30T13:31:56.000Z ##

🔴 CVE-2026-97274 - Critical (9.8)

Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) &lt;= 7.1.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97293
(8.5 HIGH)

EPSS: 0.36%

updated 2026-09-30T14:18:18.460000

1 posts

Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.

thehackerwire@mastodon.social at 2026-09-30T13:31:47.000Z ##

🟠 CVE-2026-97293 - High (8.5)

Contributor SQL Injection in Media LIbrary Assistant &lt;= 3.41 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97287
(8.5 HIGH)

EPSS: 0.36%

updated 2026-09-30T14:18:17.797000

1 posts

Contributor SQL Injection in Event Tickets <= 5.29.5 versions.

CVE-2026-97248
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-09-30T14:18:15.890000

1 posts

Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.

thehackerwire@mastodon.social at 2026-09-30T14:18:54.000Z ##

🔴 CVE-2026-97248 - Critical (9.8)

Unauthenticated PHP Object Injection in Booking Activities &lt;= 1.18.7.1 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97241
(7.5 HIGH)

EPSS: 0.42%

updated 2026-09-30T14:18:15.073000

1 posts

Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions.

thehackerwire@mastodon.social at 2026-09-30T14:48:52.000Z ##

🟠 CVE-2026-97241 - High (7.5)

Unauthenticated Sensitive Data Exposure in BackupEase &lt;= 2.2.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97197
(7.5 HIGH)

EPSS: 0.39%

updated 2026-09-30T14:18:14.280000

1 posts

Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.

thehackerwire@mastodon.social at 2026-09-30T14:49:01.000Z ##

🟠 CVE-2026-97197 - High (7.5)

Unauthenticated Broken Access Control in WordPress Backup & Migration &lt;= 1.6.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102331
(9.6 CRITICAL)

EPSS: 0.43%

updated 2026-09-30T13:15:08.430000

1 posts

Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-76992
(7.5 HIGH)

EPSS: 0.57%

updated 2026-09-30T12:35:21

2 posts

The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.

thehackerwire@mastodon.social at 2026-09-30T11:32:09.000Z ##

🟠 CVE-2026-76992 - High (7.5)

The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-09-30T11:04:07.000Z ##

🔒 New CSAF advisory published

VDE-2026-094
CODESYS Gateway Client - Uncontrolled Memory Allocation
CVE-2026-76992

The CODESYS Gateway Client (CmpGatewayClient) is used by various CODESYS products to establish PLC communication via the CODESYS Gateway.

Due to missing limits on memory allocations derived from a si…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: codesys.csaf-tp.certvde.com/.w

#OT #Advisory

##

CVE-2026-94052
(9.1 CRITICAL)

EPSS: 0.55%

updated 2026-09-30T12:35:21

1 posts

A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ld

thehackerwire@mastodon.social at 2026-09-30T11:01:32.000Z ##

🔴 CVE-2026-94052 - Critical (9.1)

A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks.

Apache MINA SSHD is a Java library for client-side and server-side SSH. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94002
(7.5 HIGH)

EPSS: 0.43%

updated 2026-09-30T12:35:16

1 posts

Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP. The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request

thehackerwire@mastodon.social at 2026-09-30T11:33:10.000Z ##

🟠 CVE-2026-94002 - High (7.5)

Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.

Apache
MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77185
(9.1 CRITICAL)

EPSS: 0.51%

updated 2026-09-30T12:35:16

2 posts

Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform "asynchronous authentication" exists. A server implemented with Apache MINA SSHD must contain explicit

thehackerwire@mastodon.social at 2026-09-30T11:01:52.000Z ##

🔴 CVE-2026-77185 - Critical (9.1)

Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server.

Apache MINA SSHD is a Java library for client- and server-side SSH. In the s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-30T10:30:28.000Z ##

Apache MINA SSHD auth bypass (CVE-2026-77185, CRITICAL, CVSS 9.1): Async public-key/hostbased auth can be skipped, risking full SSH compromise. Affected: 2.0.0 – 2.19.x, 3.0.0-M1 – M5. Patch to 2.20.0/3.0.0-M6. radar.offseq.com/threat/cve-20 #OffSeq #Apache #Infosec

##

CVE-2026-10764
(8.7 HIGH)

EPSS: 0.24%

updated 2026-09-30T12:35:15

1 posts

Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data.

thehackerwire@mastodon.social at 2026-09-30T11:33:20.000Z ##

🟠 CVE-2026-10764 - High (8.7)

Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89294
(7.5 HIGH)

EPSS: 0.65%

updated 2026-09-30T09:31:20

1 posts

The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be

thehackerwire@mastodon.social at 2026-09-30T13:17:29.000Z ##

🟠 CVE-2026-89294 - High (7.5)

The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscrib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92867
(8.8 HIGH)

EPSS: 0.34%

updated 2026-09-30T09:31:20

1 posts

An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.

thehackerwire@mastodon.social at 2026-09-30T12:02:23.000Z ##

🟠 CVE-2026-92867 - High (8.8)

An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102458
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-09-30T09:31:20

2 posts

EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.

thehackerwire@mastodon.social at 2026-09-30T11:47:43.000Z ##

🔴 CVE-2026-102458 - Critical (9.8)

EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-30T09:00:25.000Z ##

CRITICAL vuln in DigiWin EasyFlow .NET (CVE-2026-102458, CVSS 9.3): Missing authentication allows remote attackers to obtain plaintext passwords via API. Affects 6.6 – 6.6.19, 8.1 – 8.1.5. Patch ASAP! radar.offseq.com/threat/cve-20 #OffSeq #CVE2026_102458 #infosec #appsec

##

CVE-2026-97196
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-09-30T09:31:11

2 posts

Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.

thehackerwire@mastodon.social at 2026-09-30T13:17:20.000Z ##

🔴 CVE-2026-97196 - Critical (9.1)

Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass.

This issue affects GiveWP: from n/a through 4.16.9.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-30T07:30:27.000Z ##

GiveWP (Liquid Web/StellarWP) CRITICAL vuln (CVE-2026-97196): Improper input validation leads to auth bypass (CVSS 9.1). Affects up to 4.16.9. Patch when available. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #WordPress

##

CVE-2026-92870
(7.5 HIGH)

EPSS: 0.32%

updated 2026-09-30T09:31:11

1 posts

A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.

thehackerwire@mastodon.social at 2026-09-30T11:47:52.000Z ##

🟠 CVE-2026-92870 - High (7.5)

A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103110
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-09-30T06:31:42

2 posts

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.

offseq@infosec.exchange at 2026-09-30T06:00:23.000Z ##

CVE-2026-103110: CRITICAL out-of-bounds write in Pexip Infinity (CVSS 9.8) allows remote code execution as unprivileged user. Versions <38.2, 39.0, 39.1, 40.0 affected. Patch status unknown. See details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #Pexip #AppSec

##

thehackerwire@mastodon.social at 2026-09-30T05:30:43.000Z ##

🔴 CVE-2026-103110 - Critical (9.8)

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102911
(9.9 CRITICAL)

EPSS: 1.78%

updated 2026-09-30T06:31:35

2 posts

A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is

thehackerwire@mastodon.social at 2026-09-30T05:30:53.000Z ##

🔴 CVE-2026-102911 - Critical (9.9)

A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-30T04:30:24.000Z ##

CVE-2026-102911: zosmaai pi-llm-wiki (v0.11.0 – 0.11.7) suffers CRITICAL OS command injection in mcp/index.ts. Public exploit available — remote code execution possible. Upgrade to 0.11.8 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026102911 #Vuln #Infosec

##

CVE-2026-95373
(8.8 HIGH)

EPSS: 0.37%

updated 2026-09-30T04:18:49.650000

1 posts

Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-09-29T20:02:30.000Z ##

🟠 CVE-2026-95373 - High (8.8)

Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103088
(7.5 HIGH)

EPSS: 0.69%

updated 2026-09-30T03:31:41

1 posts

Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded

thehackerwire@mastodon.social at 2026-09-30T13:17:38.000Z ##

🟠 CVE-2026-103088 - High (7.5)

Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103102
(8.6 HIGH)

EPSS: 0.32%

updated 2026-09-30T03:31:41

1 posts

Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.

thehackerwire@mastodon.social at 2026-09-30T03:18:10.000Z ##

🟠 CVE-2026-103102 - High (8.6)

Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gatewa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103101
(8.6 HIGH)

EPSS: 0.27%

updated 2026-09-30T03:31:41

1 posts

Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.

thehackerwire@mastodon.social at 2026-09-30T03:18:01.000Z ##

🟠 CVE-2026-103101 - High (8.6)

Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103100
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-30T03:31:40

1 posts

Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.

thehackerwire@mastodon.social at 2026-09-30T03:48:05.000Z ##

🟠 CVE-2026-103100 - High (7.5)

Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86131(CVSS UNKNOWN)

EPSS: 0.33%

updated 2026-09-30T00:32:48

6 posts

A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.

beyondmachines1@infosec.exchange at 2026-10-01T10:01:13.000Z ##

WatchGuard Patches Multiple Flaws, One Critical in Fireware OS

WatchGuard patched 15 Fireware OS vulnerabilities, the worst a critical code injection flaw (CVE-2026-86131) that lets a malicious remote BOVPN-over-TLS server run root commands on a connecting Firebox, along several pre-authentication remote code execution and DoS bugs in services such as fingerd, spamd, iked and samld.

**If you run WatchGuard Firebox appliances, upgrade Fireware OS to a fixed version ASAP (2026.3.2, 2026.2.3, 12.12.3, or 12.5.21 on T15/T35). There are 15 flaws, including a critical one with no workaround, so prioritize devices that use Branch Office VPN over TLS. Until you patch, make sure the firewall's management interface is reachable only from trusted admin networks, and only connect VPN tunnels to servers you fully control.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-09-30T22:40:00.000Z ##

WatchGuard patched CVE-2026-86131 (CVSS 9.2) in Fireware OS, allowing a malicious VPN server to achieve root RCE on connecting Firebox appliances. Unpatched edge devices risk full takeover and network compromise, so prioritize updates and review VPN peers. #WatchGuard #FirewareOS #VulnManagement

cyberworldops.eu/en/malicious-

##

offseq@infosec.exchange at 2026-09-30T13:30:30.000Z ##

CRITICAL RCE (CVE-2026-86131) in WatchGuard Fireware OS enables root code execution via BOVPN over TLS. Multiple high-severity flaws also patched. No known in-the-wild attacks, but update ASAP. radar.offseq.com/threat/watchg #OffSeq #Vuln #WatchGuard #PatchTuesday #InfoSec

##

cR0w@infosec.exchange at 2026-09-30T04:07:44.000Z ##

Another one from Watch Guard.

A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.

psirt.watchguard.com/CVE-2026-

##

DailyCyberSecurity@infosec.exchange at 2026-09-30T02:39:47.000Z ##

WatchGuard patched 14 Fireware OS vulnerabilities, including CVSS 9.2 RCE flaw CVE-2026-86131 in BOVPN Over TLS. Update Firebox appliances now.

#WatchGuard #FirewareOS #Firebox #CVE202686131 #FirewallSecurity #VPN #NetworkSecurity #PatchNow

securityonline.info/watchguard

##

offseq@infosec.exchange at 2026-09-30T01:30:23.000Z ##

CVE-2026-86131: CRITICAL code injection in WatchGuard Fireware OS BOVPN Over TLS. Attackers controlling a VPN server can execute root commands on Firebox devices. Avoid untrusted VPNs until patched. radar.offseq.com/threat/a-code #OffSeq #WatchGuard #FirewareOS #Vuln

##

CVE-2026-71379
(10.0 CRITICAL)

EPSS: 0.44%

updated 2026-09-30T00:32:46

1 posts

The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.

CVE-2026-102794
(9.1 CRITICAL)

EPSS: 2.36%

updated 2026-09-30T00:32:32

2 posts

A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

offseq@infosec.exchange at 2026-09-30T03:00:25.000Z ##

CVE-2026-102794: Ziroom ZHOME A0101 v1.0.1.0 is affected by a CRITICAL command injection flaw (CVSS 9.1) in /api/ZRnetwork/ping. No patch, public exploit out. Restrict access & monitor usage. radar.offseq.com/threat/a-vuln #OffSeq #Vulnerability #InfoSec

##

offseq@infosec.exchange at 2026-09-30T00:00:37.000Z ##

CVE-2026-102794: Ziroom ZHOME A0101 v1.0.1.0 has a CRITICAL command injection vuln in /api/ZRnetwork/ping (url param). Public exploit available, vendor silent. Remediate ASAP if deployed. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026102794 #Infosec #IoT

##

CVE-2026-96587
(10.0 CRITICAL)

EPSS: 0.34%

updated 2026-09-29T22:19:05.860000

1 posts

The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.

CVE-2026-96274
(7.4 HIGH)

EPSS: 0.16%

updated 2026-09-29T22:19:05.720000

1 posts

In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the

cyberworldops@infosec.exchange at 2026-09-29T21:10:01.000Z ##

CISA issued ICSA-26-272-04 for CVE-2026-96274, an uncaught-exception flaw in Baicells Nova 430H eNodeB (pBS3101SH). It can be triggered from radio range to disrupt cellular service, exposing small-cell deployments to remote DoS. Operators should review affected BaiBLQ versions and apply CISA guidance. #Baicells #TelecomSecurity #DenialOfService

cyberworldops.eu/en/radio-rang

##

CVE-2026-94204
(7.5 HIGH)

EPSS: 0.27%

updated 2026-09-29T21:33:36

1 posts

The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.

CVE-2026-95372
(8.3 HIGH)

EPSS: 0.38%

updated 2026-09-29T21:33:22

1 posts

Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-09-29T20:02:21.000Z ##

🟠 CVE-2026-95372 - High (8.3)

Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity:...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84782
(8.2 HIGH)

EPSS: 0.39%

updated 2026-09-29T21:27:41.130000

3 posts

Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake

cyberveille@mastobot.ping.moi at 2026-10-01T17:00:26.000Z ##

📢 Correctifs haute sévérité dans OpenSSL et WolfSSL : authentification et fuites mémoire

Cet article couvre les correctifs de sécurité publiés par les équipes des bibliothèques cryptographiques open source OpenSSL et WolfSSL. La dernière version d'OpenSSL corrige 14 vulnérabilités, dont : CVE-2026-84782 (CVSS 8.2 — haute sévérité) : un pair distant peut…

📖 cyberveille : cyberveille.ch/posts/2026-10-0
🌐 source : securityweek.com/high-severity
🟢 vérification factuelle haute
#OpenSSL #WolfSSL #Cyberveille

##

cyberworldops@infosec.exchange at 2026-09-30T11:10:00.000Z ##

OpenSSL disclosed CVE-2026-84782, a high-severity bug in DTLS handshake retransmission that can leak unencrypted heap data to peers or crash the process. Ubuntu describes the impact as incorrect handshake behavior or denial of service. Patch affected builds and audit DTLS-exposed services. #OpenSSL #Dtls #VulnManagement

cyberworldops.eu/en/openssl-dt

##

DailyCyberSecurity@infosec.exchange at 2026-09-29T19:21:54.000Z ##

OpenSSL patched 14 OpenSSL vulnerabilities, including high-severity DTLS flaw CVE-2026-84782 that can leak heap memory. Upgrade to 4.0.3 now.

#OpenSSL #OpenSSLVulnerabilities #CVE202684782 #DTLS #QUIC #TLS #Cryptography #PatchNow

securityonline.info/openssl-vu

##

CVE-2026-92370
(8.8 HIGH)

EPSS: 0.38%

updated 2026-09-29T18:31:49

1 posts

An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuratio

CVE-2026-92368
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-29T18:31:46

1 posts

TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature,

CVE-2026-102673
(8.2 HIGH)

EPSS: 0.15%

updated 2026-09-29T18:05:37

1 posts

### Impact Popups opened from a sandboxed iframe through a link (for example `target="_blank"` or a middle-click) did not inherit the iframe's HTML `sandbox` restrictions. Content that was meant to run sandboxed could open a popup with the embedding app's full origin, gaining access to that origin's cookies, storage, and same-origin scripting. Apps are only affected if they embed untrusted conte

CVE-2026-102676
(8.3 HIGH)

EPSS: 0.45%

updated 2026-09-29T18:02:22

1 posts

### Impact A `<webview>` could enable Node.js integration in its Web Workers even when its embedder had Node.js integration disabled, giving guest content more privilege than the embedder allowed. Apps are only affected if they enable the `<webview>` tag and the embedder is unsandboxed. Apps that do not use `<webview>`, or that keep the embedder sandboxed, are not affected. ### Workarounds Rem

CVE-2026-86950
(8.8 HIGH)

EPSS: 1.24%

updated 2026-09-29T15:32:17

10 posts

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions o

1 repos

https://github.com/DeAurity/CVE-2026-86950-POC

cyberworldops at 2026-10-01T10:30:00.658Z ##

Researchers published the first public PoC for CVE-2026-86950, an Apple CoreGraphics out-of-bounds write via crafted PDF font data. The PoC shows crash and controlled write only, but Apple reports targeted exploitation in the wild, raising immediate patching priority.

cyberworldops.eu/en/public-cor

##

cyberworldops@infosec.exchange at 2026-10-01T10:30:00.000Z ##

Researchers published the first public PoC for CVE-2026-86950, an Apple CoreGraphics out-of-bounds write via crafted PDF font data. The PoC shows crash and controlled write only, but Apple reports targeted exploitation in the wild, raising immediate patching priority. #AppleSecurity #CoreGraphics #VulnManagement

cyberworldops.eu/en/public-cor

##

youranonnewsirc@nerdculture.de at 2026-09-30T22:26:25.000Z ##

Geopolitical: Iran warned UAE following Netanyahu's visit (Sept 30) amidst regional tensions, while Russia conducted a drone strike on Ukraine's National Academy of Sciences (Sept 29).

Technology: OpenAI launched "dots" agents and GPT-6.1 Sol (Sept 29), despite shelving a prior AI model (Astra) due to safety concerns. SpaceX's Starship successfully completed its first orbital flight (Sept 28-29).

Cybersecurity: Urgent advisories were issued for actively exploited Citrix NetScaler zero-days (Sept 30), mandating federal agency patching. Apple also patched a CoreGraphics zero-day (CVE-2026-86950) used in targeted attacks (Sept 29).

#AnonNews_irc #Cybersecurity #News

##

technews@eicker.news at 2026-09-30T21:47:01.000Z ##

#Apple released a #security update for #iOS 26, #iPadOS 26, and #macOS 26 to fix a #vulnerability in the #graphicsengine that could be exploited for sophisticated attacks. The bug, CVE-2026-86950, was discovered by Meta and could potentially allow hackers to steal personal data. A separate zero-click bug, CVE-2026-86869, was also fixed, preventing silent data theft via malicious iMessages. techcrunch.com/2026/09/29/stil

##

DailyCyberSecurity@infosec.exchange at 2026-09-30T20:20:10.000Z ##

Apple released the urgent iOS 26.7.1 update to patch a critical zero-day vulnerability (CVE-2026-86950) in CoreGraphics, preventing arbitrary code execution.

#AppleSecurity #iOSUpdate #ZeroDay #CyberSecurity #TechNews

dailytechnow.com/apple-patches

##

beyondmachines1@infosec.exchange at 2026-09-30T11:01:12.000Z ##

Apple Patches Actively Exploited Zero-Day in iOS 26, iPadOS 26 and macOS

Apple patched a zero-click vulnerability (CVE-2026-86950) in iOS 26 and macOS 26 that allow remote code execution and data theft, and has been exploited

**If you use an iPhone, iPad or Mac, update it right now to iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1. Alterantively, where possible, move to iOS 27. Attackers are already using this flaw to take over devices and steal personal data. If you're a likely target, such as a journalist, activist or executive, consider turning on Lockdown Mode for extra protection.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

benzogaga33@mamot.fr at 2026-09-30T09:40:04.000Z ##

Apple a corrigé une faille CoreGraphics exploitée pour cibler des utilisateurs d’iPhone (CVE-2026-86950) it-connect.fr/apple-cve-2026-8 #ActuCybersécurité #Cybersécurité #Vulnérabilité #Apple

##

thecybermind@infosec.exchange at 2026-09-30T06:40:11.000Z ##

(CISA TS+SOC) CVE-2026-86950 – Apple CoreGraphics Out-of-Bounds Write Briefing

Active exploitation of CVE-2026-88650 [CVE-2026-86950] in Apple CoreGraphics requires immediate patch deployment and forensic triage. Review integrated TSUITE + SOC intelligence assets....

thecybermind.co/2qk4

##

winterkvist@mastodonsweden.se at 2026-09-29T21:47:22.000Z ##

Apple squashes zero-day bug exploited in ”extremely sophisticated” attack (CVE-2026-86950) – Help Net Security macken.xyz/2026/09/apple-squas

##

news@fawkes.rocks at 2026-09-29T21:21:46.000Z ##

Apple fixes CoreGraphics zero-day CVE-2026-86950

fawkes.rocks/2026/09/29/apple-

##

CVE-2026-88771
(9.8 CRITICAL)

EPSS: 1.06%

updated 2026-09-29T04:18:01.603000

7 posts

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

10 repos

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771

https://github.com/SwiftSecur/CVE-2026-88771-HuntScript

https://github.com/bkchaudhari/NetScaler-CTX697096-Assessment-Script

https://github.com/securekomodo/citrixInspector

https://github.com/craigsblackie/cve-2026-88771-netscaler

https://github.com/technion/netscaler_scanner

https://github.com/techupdate24/citrix-netscaler-cve-2026-88771-rce

https://github.com/emilstahl/pitscaler

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/EXEcution-py/CVE-2026-88771-POC

cyberworldops@infosec.exchange at 2026-10-01T07:00:01.000Z ##

LevelBlue THOR observed active exploitation of CVE-2026-88771 in Citrix NetScaler ADC and Gateway for unauthenticated command execution. Payloads establish reverse shells, create persistent superuser accounts, and hide web shells as CSS URLs while staging configs. This enables long-term persistence and credential access on edge devices. #NetScaler #Citrix #ThreatIntel

cyberworldops.eu/en/netscaler-

##

cyberworldops@infosec.exchange at 2026-10-01T00:30:00.000Z ##

Mandiant and GTIG confirm active exploitation of NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 on ADC and Gateway appliances. Edge compromise can escalate to root-level network access, bypassing perimeter controls. Immediate patching and compromise hunting are required. #NetScaler #ZeroDay #ThreatIntel

cyberworldops.eu/en/netscaler-

##

GossiTheDog@cyberplace.social at 2026-10-01T00:12:49.000Z ##

Great IOCs on the follow up spray and pray activity on #PitScaler so far.

For context this activity definitely is not related to the inital threat actor activity in early September. This is new stuff.

github.com/rtkwlf/wolf-tools/t

##

ssvc@infosec.exchange at 2026-09-30T15:53:50.000Z ##

CERT-EU shares their insights on CVE-2026-88771 exploitation and provides threat hunting tips in different logs.

cert.europa.eu/blog/taking-exe

#threatintel #threathunting #citrix #netscaler

##

guru@thecybersecguru.com at 2026-09-30T09:10:53.000Z ##

Critical Citrix NetScaler RCE (CVE-2026-88772) exploited in the wild: a deep dive into the DTLS buffer overflow

Citrix NetScaler vulnerability, NetScaler RCE, Citrix zero-day, DTLS buffer overflow, CVE-2026-88771, NetScaler Gateway exploit, Citrix security advisory

thecybersecguru.com/news/citri

##

ssvc@infosec.exchange at 2026-09-29T20:25:25.000Z ##

Mandiant and Google Threat Intelligence Group describe in-the-wild exploitation CVE-2026-88771 and CVE-2026-88772 against Citrix NetScaler ADC and NetScaler Gateway appliances globally. Indicators of compromise and YARA rules are included.

cloud.google.com/blog/topics/t

#threatintel #citrix #netscaler #kev #zeroday #ioc

##

news@fawkes.rocks at 2026-09-29T20:23:35.000Z ##

Citrix NetScaler CVE-2026-88771 now under mass attack

fawkes.rocks/2026/09/29/citrix

##

CVE-2026-88772
(8.1 HIGH)

EPSS: 1.30%

updated 2026-09-28T12:32:09

10 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

7 repos

https://github.com/FollowerSeize/CVE-2026-88772-POC

https://github.com/securekomodo/citrixInspector

https://github.com/technion/netscaler_scanner

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772

https://github.com/emilstahl/pitscaler

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/murrez/CVE-2026-88772

DailyCyberSecurity@infosec.exchange at 2026-10-01T08:15:04.000Z ##

Attackers exploit Citrix NetScaler zero-day CVE-2026-88772 for root access, then hide WHIPSHOT web shells and a SLAPSHOT tunneler. Patch now.

#CitrixNetScaler #ZeroDay #CVE202688772 #CVE202688771 #WHIPSHOT #SLAPSHOT #Mandiant #CyberSecurity

securityonline.info/citrix-net

##

cyberworldops@infosec.exchange at 2026-10-01T00:30:00.000Z ##

Mandiant and GTIG confirm active exploitation of NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 on ADC and Gateway appliances. Edge compromise can escalate to root-level network access, bypassing perimeter controls. Immediate patching and compromise hunting are required. #NetScaler #ZeroDay #ThreatIntel

cyberworldops.eu/en/netscaler-

##

DailyCyberSecurity@infosec.exchange at 2026-10-01T00:29:03.000Z ##

CVE-2026-88772, a Citrix NetScaler DTLS memory overflow, is exploited in the wild. A watchTowr PoC and full details are now public. Patch NetScaler now.

#Citrix #NetScaler #CVE202688772 #DTLS #watchTowr #KEV #ZeroDay #RCE

securityonline.info/citrix-net

##

reput_io@infosec.exchange at 2026-09-30T15:27:50.000Z ##

Two Citrix NetScaler zero-days (CVE-2026-88772/88771) gave attackers pre-auth root on the box that fronts your whole network. GTIG traced exploitation to early September, weeks before the patch existed.

Once inside, their C2 leaves from your own public IP. No strange domain, no foreign address to block. The call is coming from inside the house.

Reputation Radar #13:
reput.io/blog/reputation-radar

#ThreatIntel #NetScaler #SOC

##

news@fawkes.rocks at 2026-09-30T13:22:34.000Z ##

NetScaler CVE-2026-88772 zero-day tied to state hackers

fawkes.rocks/2026/09/30/netsca

##

pwr2@infosec.exchange at 2026-09-30T13:09:38.000Z ##

Nice blog post on Citrix CVE-2026-88772 exploit:

cloud.google.com/blog/topics/t

#citrix #cve_2026_88772 #pitscaler

##

guru@thecybersecguru.com at 2026-09-30T09:10:53.000Z ##

Critical Citrix NetScaler RCE (CVE-2026-88772) exploited in the wild: a deep dive into the DTLS buffer overflow

Citrix NetScaler vulnerability, NetScaler RCE, Citrix zero-day, DTLS buffer overflow, CVE-2026-88771, NetScaler Gateway exploit, Citrix security advisory

thecybersecguru.com/news/citri

##

gtronix@infosec.exchange at 2026-09-29T23:00:44.000Z ##

"Hackers exploit Citrix NetScaler zero-day to deploy web shells"

"[...] Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks."

bleepingcomputer.com/news/secu

#Cybersecurity

##

ssvc@infosec.exchange at 2026-09-29T20:40:22.000Z ##

We had first POC yes, but what about second POC? watchTowr breaks down CVE-2026-88772 and provides a "detection artifact generator"

labs.watchtowr.com/here-we-go-

#citrix #netscaler #poc #zeroday #kev

##

ssvc@infosec.exchange at 2026-09-29T20:25:25.000Z ##

Mandiant and Google Threat Intelligence Group describe in-the-wild exploitation CVE-2026-88771 and CVE-2026-88772 against Citrix NetScaler ADC and NetScaler Gateway appliances globally. Indicators of compromise and YARA rules are included.

cloud.google.com/blog/topics/t

#threatintel #citrix #netscaler #kev #zeroday #ioc

##

CVE-2026-87902
(8.1 HIGH)

EPSS: 19.76%

updated 2026-09-28T12:20:54.040000

4 posts

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

26 repos

https://github.com/abraxas/CVE-2026-87902

https://github.com/zyphorixofficialmain-lab/cve-2026-87902

https://github.com/rabakuku/CVE-2026-87902-A-working-PoC-for-WordPress-s-critical-path-traversal

https://github.com/tonydelouvre/CVE-2026-87902

https://github.com/joaovicdev/EXPLOIT-CVE-2026-87902

https://github.com/itskill-jp/wordpress-upgrade-check

https://github.com/Hassham1/CVE-2026-87902

https://github.com/vulpecuna/CVE-2026-87902

https://github.com/Lutfifakee-Project/CVE-2026-87902

https://github.com/rwxrwxs/CVE-2026-87902

https://github.com/ynsmroztas/WPSniper

https://github.com/dinosn/cve-2026-87902-wordpress-lfi-lab

https://github.com/bhideki/CVE-2026-87902

https://github.com/SVTagan/WP-CVE-2026-87902

https://github.com/Maalfer/CVE-2026-87902-exploit

https://github.com/crowsec-edtech/CVE-2026-87902

https://github.com/tc4dy/CVE-2026-87902-Toolkit

https://github.com/zer0dayf/CVE-2026-87902

https://github.com/MRdark-ops/CVE-2026-87902

https://github.com/oliveiralimajr/CVE_2026_87902

https://github.com/langz337/CVE-2026-87902

https://github.com/abatsakidis/wp-cve-2026-87902-checker

https://github.com/pwnVader/CVE-2026-87902-PoC-pwnVader

https://github.com/nextco/wordpress-cve-2026-87902

https://github.com/ressl/cve-2026-87902-poc

https://github.com/HackfutSecRoot/CVE-2026-87902

thecybermind at 2026-10-01T10:07:22.427Z ##

(CISA TS+SOC) CVE-2026-87902 WORDPRESS CODE REMOTE FILE INCLUSION

Active exploitation of CVE-2026-87902 WordPress requires immediate patch deployment and forensic triage. Review integrated TSUITE + SOC intelligence assets....

thecybermind.co/go2d

##

thecybermind@infosec.exchange at 2026-10-01T10:07:22.000Z ##

(CISA TS+SOC) CVE-2026-87902 WORDPRESS CODE REMOTE FILE INCLUSION

Active exploitation of CVE-2026-87902 WordPress requires immediate patch deployment and forensic triage. Review integrated TSUITE + SOC intelligence assets....

thecybermind.co/go2d

##

wpguyuk@infosec.exchange at 2026-10-01T07:04:45.000Z ##

CVE-2026-87902 scored 9.2 out of 10, affected every WordPress version since 2016, and was actively exploited within 24 hours of disclosure — no login required. Most site owners never heard a word about it. That silence is the real vulnerability. Knowing your site runs WordPress is not the same as knowing what is happening to it.

#WordPress #WordPressSecurity #CyberSecurity #SecurityHardening

wpguy.uk/blog/cve-2026-87902-t

##

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-100382(CVSS UNKNOWN)

EPSS: 0.95%

updated 2026-09-26T00:32:22

2 posts

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7.

1 repos

https://github.com/nth347/mediawiki-CVE-2026-100382

DailyCyberSecurity@infosec.exchange at 2026-10-01T03:30:34.000Z ##

Attackers exploit CVE-2026-100382, a CVSS 10 unauthenticated MediaWiki RCE in External Data. PoC is public. Upgrade to 3.7 now.

#MediaWiki #ExternalData #CVE2026100382 #RCE #CommandInjection #ExploitedInTheWild #PoC

securityonline.info/mediawiki-

##

maxlath@piaille.fr at 2026-09-30T08:59:15.000Z ##

[🚨 #MediaWiki vulnerable extension]

If you are running a MediaWiki instance with Extension:External_Data < v3.7, your instance is vulnerable to arbitrary file loading and #RemoteCodeExecution.

The vulnerability was apparently publicly known since August, but due to the lack of communication, instance admins learned about it due to that vulnerability being exploited en masse.

If you know and like a MediaWiki instance, you can check their Special:Version page to see if they are using the External_Data extension to warn them.

More info:
- lists.wikimedia.org/hyperkitty
- cve.org/CVERecord?id=CVE-2026-

#infosec #wikipedia #wikidata #adminsys #CVE #pwned cc @mediawiki

##

CVE-2026-85706
(10.0 CRITICAL)

EPSS: 92.96%

updated 2026-09-24T12:52:28.143000

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

14 repos

https://github.com/plur1bu5/gitread

https://github.com/gagaltotal/CVE-2026-85706-gitlab-poc

https://github.com/EQSTLab/CVE-2026-85706

https://github.com/ynsmroztas/GitLabSniper

https://github.com/guneykabel/cve-2026-85706

https://github.com/wuyou6956-glitch/cve-2026-85706

https://github.com/unh00k3d/cve-2026-85706

https://github.com/FlowerWitch/CVE-2026-85706_docker_exp

https://github.com/solivaquaant/CVE-2026-85706

https://github.com/gabrielunknown/CVE-2026-85706

https://github.com/mhtsec/CVE-2026-85706

https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab

https://github.com/tc4dy/CVE-2026-85706-PoC-Toolkit

https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 7.55%

updated 2026-09-23T18:22:07.453000

3 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

daniel1820815 at 2026-10-01T15:24:02.232Z ##

From Check Point Research: Exploitation of CVE-2026-85102 and CVE-2026-93616

Check Point has observed active exploitation of two critical pre-authentication vulnerabilities with CVSS scores of 9.8 - CVE-2026-85102 and CVE-2026-93616. The flaws affect Security Gateway and Security Management products and can enable remote code execution. Fixes for both vulnerabilities are available.

blog.checkpoint.com/security/s

##

daniel1820815@infosec.exchange at 2026-10-01T15:24:02.000Z ##

From Check Point Research: Exploitation of CVE-2026-85102 and CVE-2026-93616

Check Point has observed active exploitation of two critical pre-authentication vulnerabilities with CVSS scores of 9.8 - CVE-2026-85102 and CVE-2026-93616. The flaws affect Security Gateway and Security Management products and can enable remote code execution. Fixes for both vulnerabilities are available.

blog.checkpoint.com/security/s

#CheckPoint #CheckPointSoftwareTechnologies #CVE #CVE202685102 #CVE202693616

##

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-93616
(9.8 CRITICAL)

EPSS: 19.65%

updated 2026-09-23T16:38:38.987000

3 posts

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

2 repos

https://github.com/WadesWeaponShed/CVE-2026-93616_Checks

https://github.com/BishopFox/CVE-2026-93616-check

daniel1820815 at 2026-10-01T15:24:02.232Z ##

From Check Point Research: Exploitation of CVE-2026-85102 and CVE-2026-93616

Check Point has observed active exploitation of two critical pre-authentication vulnerabilities with CVSS scores of 9.8 - CVE-2026-85102 and CVE-2026-93616. The flaws affect Security Gateway and Security Management products and can enable remote code execution. Fixes for both vulnerabilities are available.

blog.checkpoint.com/security/s

##

daniel1820815@infosec.exchange at 2026-10-01T15:24:02.000Z ##

From Check Point Research: Exploitation of CVE-2026-85102 and CVE-2026-93616

Check Point has observed active exploitation of two critical pre-authentication vulnerabilities with CVSS scores of 9.8 - CVE-2026-85102 and CVE-2026-93616. The flaws affect Security Gateway and Security Management products and can enable remote code execution. Fixes for both vulnerabilities are available.

blog.checkpoint.com/security/s

#CheckPoint #CheckPointSoftwareTechnologies #CVE #CVE202685102 #CVE202693616

##

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-93710
(7.5 HIGH)

EPSS: 0.63%

updated 2026-09-22T21:32:15

1 posts

Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. A hook that dies fires core.app.hook_exception, then calls cleanup unless the failing hook is the exception handler. A handler that halts does not stop that cleanup, which discards the request, response and session the dispatcher has yet to r

hugovalters@mastodon.social at 2026-10-01T12:00:02.000Z ##

CVE-2026-93710 Dancer2 2.0.0-2.2.0 for Perl dispatch routes a dying hook refused, letting a halted exception handler run refused routes. CVSS 7.5. Patched in 2.2.0, update now. valtersit.com/cve/CVE-2026-937 #CVE #infosec #Perl

##

CVE-2026-88738
(8.8 HIGH)

EPSS: 0.61%

updated 2026-09-22T19:43:52.337000

1 posts

Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.

hugovalters@mastodon.social at 2026-10-01T16:40:19.000Z ##

CVE-2026-88738 Jazzware RT1000 Edge webUI RCE via unrestricted file upload. CVSS 8.8, no patch yet. Patch now or restrict upload access. valtersit.com/cve/CVE-2026-887 #CVE #infosec #cybersecurity

##

CVE-2026-87079
(7.5 HIGH)

EPSS: 0.63%

updated 2026-09-22T19:07:00.983000

1 posts

Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the insertion point by scanning that buffer from the start, one character at a time. The scan runs once per code point over the output built so far, so the cost is quadratic i

hugovalters@mastodon.social at 2026-10-01T15:10:02.000Z ##

CVE-2026-87079 Net::IDN::Punycode for Perl, CVSS 7.5. Decoding a long label triggers quadratic CPU exhaustion (DoS). No patch yet, only under review, so isolate untrusted punycode input now. valtersit.com/cve/CVE-2026-870 #CVE #Perl #infosec

##

CVE-2026-93556(CVSS UNKNOWN)

EPSS: 0.30%

updated 2026-09-22T09:31:18

2 posts

The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the password for any account, including administrative accounts, which could allow them

hugovalters@mastodon.social at 2026-10-01T13:30:02.000Z ##

CVE-2026-93556: CVSS 9.8. Broken JWT validation in /password/guardarClau/recover lets unauthenticated attackers reset any password, including admin. Patch status unknown. Assume exposed and mitigate now. valtersit.com/cve/CVE-2026-935 #CVE #infosec #cybersecurity

##

hugovalters@mastodon.social at 2026-10-01T13:30:02.000Z ##

CVE-2026-93556: CVSS 9.8. Broken JWT validation in /password/guardarClau/recover lets unauthenticated attackers reset any password, including admin. Patch status unknown. Assume exposed and mitigate now. valtersit.com/cve/CVE-2026-935 #CVE #infosec #cybersecurity

##

CVE-2026-94426
(3.5 LOW)

EPSS: 0.33%

updated 2026-09-22T00:31:02

1 posts

A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

hugovalters@mastodon.social at 2026-10-01T10:20:17.000Z ##

CVE-2026-94426: reflected XSS in Xxl Job up to 3.5.0, /jobgroup/insert. CVSS 3.5, exploit public, vendor unresponsive. No patch yet - restrict access now.
valtersit.com/cve/CVE-2026-944
#CVE #infosec #cybersecurity

##

CVE-2026-80521
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-21T14:17:20.193000

1 posts

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: X -. A <-> B ^--' 2) Run the following concurrently: 2-1) send() sk-B to sk-B from sk-X 2-2) close() both A and B At 2-1), there is a sm

2 repos

https://github.com/Markakd/Container_escape

https://github.com/rifkyards/Container_escape-CVE-2026-80521-CVE-2026-52910

sigint@fosstodon.org at 2026-09-30T23:45:07.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-10-01

Public exploit for container-to-host root escape, CVE-2026-80521, patched upstream but not yet shipped in Ubuntu 22.04/24.04/26.04 LTS. If you run containers on Ubuntu hosts, treat this as urgent and watch for the USN, or mitigate with stricter namespace/seccomp policies now.

🔗 thehackernews.com/2026/09/expl

#Ubuntu #Linux #infosec

##

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-63490
(7.5 HIGH)

EPSS: 0.69%

updated 2026-09-18T20:09:01.757000

1 posts

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the path-containment validation used by other URL-based loaders. In handlebars-springmvc/src/main/java/com/github/jknack/handlebars/springmvc/SpringTemplate

thehackerwire@mastodon.social at 2026-09-30T13:17:38.000Z ##

🟠 CVE-2026-103088 - High (7.5)

Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86869
(6.5 MEDIUM)

EPSS: 0.34%

updated 2026-09-17T18:31:49

1 posts

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27. Processing a maliciously crafted image may lead to unexpected app termination.

technews@eicker.news at 2026-09-30T21:47:01.000Z ##

#Apple released a #security update for #iOS 26, #iPadOS 26, and #macOS 26 to fix a #vulnerability in the #graphicsengine that could be exploited for sophisticated attacks. The bug, CVE-2026-86950, was discovered by Meta and could potentially allow hackers to steal personal data. A separate zero-click bug, CVE-2026-86869, was also fixed, preventing silent data theft via malicious iMessages. techcrunch.com/2026/09/29/stil

##

CVE-2026-50610(CVSS UNKNOWN)

EPSS: 0.13%

updated 2026-09-17T09:33:03

1 posts

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user may be able to access the service and perform unauthorized registry modifications, potentially resulting in local privilege escalation.

CVE-2026-76460
(10.0 CRITICAL)

EPSS: 14.03%

updated 2026-09-16T21:33:00

1 posts

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized acce

1 repos

https://github.com/S3v3n-JG/CVE-2026-76460

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-76461
(9.8 CRITICAL)

EPSS: 28.27%

updated 2026-09-14T21:32:49

1 posts

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that cont

4 repos

https://github.com/HORKimhab/CVE-2026-76461

https://github.com/S3v3n-JG/CVE-2026-76461

https://github.com/fevar54/CVE-2026-76461-Detection-Kit-

https://github.com/0xBlackash/CVE-2026-76461

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 85.17%

updated 2026-09-14T00:16:56.207000

1 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

Nuclei template

2 repos

https://github.com/virologi-info/papercut-toolkit

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

VirusBulletin@infosec.exchange at 2026-09-30T12:35:26.000Z ##

eSentire's TRU team shows how a threat actor exploited an internet-facing PaperCut MF server to deploy a Java loader & a web shell. Threat actors subsequently used the web shell to deploy a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant. esentire.com/blog/papercut-mf-

##

CVE-2026-84869
(9.9 CRITICAL)

EPSS: 0.92%

updated 2026-09-12T04:16:42.757000

1 posts

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

cyberveille@mastobot.ping.moi at 2026-10-01T17:00:20.000Z ##

📢 CVE-2026-84869 : vulnérabilité critique dans ScreenConnect exploitée activement

Cet article analyse la vulnérabilité CVE-2026-84869 affectant ConnectWise ScreenConnect, un outil de gestion à distance largement utilisé par les entreprises et les fournisseurs de services managés (MSP). CVE-2026-84869 est une faille dans la gestion des…

📖 cyberveille : cyberveille.ch/posts/2026-10-0
🌐 source : criminalip.io/knowledge-hub/bl
🟡 vérification factuelle moyenne
#ScreenConnect #ConnectWise #Cyberveille

##

CVE-2026-86218
(9.8 CRITICAL)

EPSS: 12.93%

updated 2026-09-09T05:18:19.490000

1 posts

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Nuclei template

3 repos

https://github.com/Udyz/CVE-2026-86218

https://github.com/HORKimhab/CVE-2026-86218

https://github.com/super-meuw/CVE-2026-86218

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-81963
(7.8 HIGH)

EPSS: 0.39%

updated 2026-09-08T21:34:09

2 posts

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

CVE-2026-75650
(10.0 CRITICAL)

EPSS: 3.95%

updated 2026-09-08T21:33:09

1 posts

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

6 repos

https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos

https://github.com/dinosn/cve-2026-75650-magento-validation-lab

https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit

https://github.com/abraxas/CVE-2026-75650

https://github.com/disrex-group/stylesmuggler-adobe-patches

https://github.com/fortbridge/stylesmuggler

CVE-2026-70590
(4.8 MEDIUM)

EPSS: 0.32%

updated 2026-09-08T20:51:43.490000

1 posts

Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have prevented an attacker from logging in with a recovered password. Depending on the database

EUVD_Bot@mastodon.social at 2026-10-01T11:02:21.000Z ##

🚨 EUVD-2026-90668

📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Ghost
🏢 Vendor: TryGhost
📅 Updated: 2026-10-01

📝 Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in the Admin API bulk post and page edit and delete endpoints, which accept filters on restricted fields such as authors.password, because of an incomplete fix for CVE-2026-70590. Sta...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-60004
(9.8 CRITICAL)

EPSS: 23.99%

updated 2026-09-08T17:56:31

1 posts

### Summary Gitea's `diffpatch` endpoint can be abused to install and execute a Git hook from repository-controlled content. An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository. ### Detai

11 repos

https://github.com/fevar54/cve-2026-60004

https://github.com/HORKimhab/CVE-2026-60004

https://github.com/HackSpeak/CVE-2026-60004

https://github.com/erberkan/CVE-2026-60004-PoC

https://github.com/0xBlackash/CVE-2026-60004

https://github.com/gagaltotal/CVE-2026-60004-poc-gitea

https://github.com/yym8538/CVE-2026-60004

https://github.com/EQSTLab/CVE-2026-60004

https://github.com/shinthink/CVE-2026-60004

https://github.com/Sachinart/CVE-2026-60004-gitea-0day

https://github.com/imbas007/CVE-2026-60004-POC

egeltje@infosec.exchange at 2026-10-01T08:18:29.000Z ##

When you find your private Gitea server infected with #XMrigMalware cryptominer through CVE-2026-60004...
Enormous gratitude to foresh.com/posts/2026-09-15-ai for writing a very concise analysis and recovery!

##

CVE-2026-83548
(10.0 CRITICAL)

EPSS: 8.76%

updated 2026-09-02T18:32:06

1 posts

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Nuclei template

3 repos

https://github.com/xcoy0te/CVE-2026-83548-checker

https://github.com/HORKimhab/CVE-2026-83548-CVE-2026-83549

https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-83549
(7.8 HIGH)

EPSS: 10.76%

updated 2026-09-02T18:32:06

1 posts

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

2 repos

https://github.com/xcoy0te/CVE-2026-83548-checker

https://github.com/HORKimhab/CVE-2026-83548-CVE-2026-83549

secdb@infosec.exchange at 2026-10-01T00:02:39.000Z ##

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85046 - 48.88 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76461 - 28.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 19.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76460 - 14.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-86218 - 12.93 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83549 - 10.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-83548 - 8.76 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85102 - 7.55 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 61.39%

updated 2026-08-31T21:31:56

1 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/virologi-info/papercut-toolkit

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

VirusBulletin@infosec.exchange at 2026-09-30T12:35:26.000Z ##

eSentire's TRU team shows how a threat actor exploited an internet-facing PaperCut MF server to deploy a Java loader & a web shell. Threat actors subsequently used the web shell to deploy a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant. esentire.com/blog/papercut-mf-

##

CVE-2026-73570
(8.9 HIGH)

EPSS: 11.74%

updated 2026-08-24T13:19:17.577000

5 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

10 repos

https://github.com/alsyundawy/eradicate-zimbra-malware

https://github.com/dahnutz/zimbra-cve-2026-73570-ir

https://github.com/gabrielunknown/CVE-2026-73570

https://github.com/BiuTrap/CVE-2026-73570

https://github.com/hainhc/CVE-2026-73570

https://github.com/jishino567/CVE-2026-73570

https://github.com/HORKimhab/CVE-2026-73570

https://github.com/juanpoch/CVE-2026-73570

https://github.com/0xBlackash/CVE-2026-73570

https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules

Analyst207@mastodon.social at 2026-10-01T14:51:03.000Z ##

Microsoft tracks hackers exploiting Zimbra bug before public disclosure

Microsoft detected hackers probing for a Zimbra bug, CVE-2026-73570, just days after it was patched, but before the vulnerability was publicly disclosed - a concerning gap that highlights the need for swift and secretive fixes. The bug, which allows attackers to run commands on exposed mail servers,…

osintsights.com/microsoft-trac

#Cve202673570 #Zimbra #UnauthenticatedCommandInjection #VulnerabilityExploitation #EmergingThreats

##

news@fawkes.rocks at 2026-10-01T13:22:43.000Z ##

Zimbra CVE-2026-73570 exploited before public disclosure

fawkes.rocks/2026/10/01/zimbra

##

news@fawkes.rocks at 2026-10-01T13:22:43.000Z ##

Zimbra CVE-2026-73570 exploited before public disclosure

fawkes.rocks/2026/10/01/zimbra

##

AAKL@infosec.exchange at 2026-09-30T16:12:01.000Z ##

New.

Microsoft: Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 microsoft.com/en-us/security/b #Microsoft #threatresearch #infosec #vulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-09-30T15:34:23.000Z ##

Zimbra CVE-2026-73570 lets one crafted email run code. Microsoft details the Zimbra command injection attacks: web shells, root access, and key theft.

#Zimbra #CVE202673570 #CommandInjection #WebShell #EmailSecurity #MailServer #Microsoft #CyberSecurity

securityonline.info/zimbra-cve

##

CVE-2026-64508(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-08-19T18:32:01

1 posts

In the Linux kernel, the following vulnerability has been resolved: bpf: Support for hardening against JIT spraying The BPF JIT allocator packs many small programs into larger executable allocations and reuses space within those allocations as programs are loaded and freed. When fresh code is written into space that a previous program occupied, an indirect jump into the new program can reuse a b

cyberveille@mastobot.ping.moi at 2026-10-01T11:30:31.000Z ##

📢 [VULN] 5 minutes pour voler le hash du mot de passe root avec BTR, une variante de Spectre v2 - CVE-2026-64507 CVE-2026-64508.

La nouvelle attaque BTR est capable de dérober le hash du mot de passe root sur une machine Linux équipée d'un processeur Intel récent, en 3 à 5 minutes. Cette variante de Spectre v2 cible les moteurs JIT, et côté processeurs, elle ne fait pas de jaloux. Voici ce qu'il faut retenir.

🔗 it-connect.fr/spectre-v2-btr-l
💬 discussion : infosec.pub/post/53004283
#CVE #Cyberveille

##

CVE-2026-64507
(0 None)

EPSS: 0.16%

updated 2026-08-19T17:20:15.123000

1 posts

In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2 mitigations are in use. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip enabling the IBPB flush if the BPF dispatcher is already using a retpoline sequence. This hardening applies only when BPF-JIT is in use.

cyberveille@mastobot.ping.moi at 2026-10-01T11:30:31.000Z ##

📢 [VULN] 5 minutes pour voler le hash du mot de passe root avec BTR, une variante de Spectre v2 - CVE-2026-64507 CVE-2026-64508.

La nouvelle attaque BTR est capable de dérober le hash du mot de passe root sur une machine Linux équipée d'un processeur Intel récent, en 3 à 5 minutes. Cette variante de Spectre v2 cible les moteurs JIT, et côté processeurs, elle ne fait pas de jaloux. Voici ce qu'il faut retenir.

🔗 it-connect.fr/spectre-v2-btr-l
💬 discussion : infosec.pub/post/53004283
#CVE #Cyberveille

##

CVE-2026-72018
(7.8 HIGH)

EPSS: 0.18%

updated 2026-08-17T06:17:59.313000

1 posts

In the Linux kernel, the following vulnerability has been resolved: dibs: loopback: validate offset and size in move_data() The loopback move_data() performs a memcpy into the registered DMB without checking whether offset + size exceeds the DMB length. Unlike real ISM hardware, which enforces memory region bounds natively, the software loopback has no such protection. A peer-supplied out-of-b

1 repos

https://github.com/0xBlackash/CVE-2026-72018

_r_netsec@infosec.exchange at 2026-09-30T07:03:21.000Z ##

No Time to Pwn – Can AI Find and Exploit the Linux Kernel? xbow.com/blog/no-time-to-pwn-c

##

CVE-2025-41739
(5.9 MEDIUM)

EPSS: 0.35%

updated 2026-06-17T09:23:04.017000

1 posts

An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.

certvde@infosec.exchange at 2026-10-01T06:41:04.000Z ##

🔒 New CSAF advisory published

VDE-2025-081
WAGO: Multiple PLCs and Communication Components are Affected by multiple Vulnerabilities leading to RCE
CVE-2025-41700, CVE-2025-41738, CVE-2025-41739

Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are <4.10.0 (FW32) and <4.10.0 (70).

HTML: certvde.com/en/advisories/vde-
CSAF JSON: wago.csaf-tp.certvde.com/.well

#OT #Advisory

##

CVE-2026-35273
(9.8 CRITICAL)

EPSS: 9.44%

updated 2026-06-12T18:31:50

1 posts

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of Peopl

Nuclei template

4 repos

https://github.com/12hrformat/CVE-2026-35273-POC

https://github.com/HORKimhab/CVE-2026-35273

https://github.com/ekomsSavior/POC_cve_2026_35273

https://github.com/0xBlackash/CVE-2026-35273

linuxmint_hun@mastodon.social at 2026-10-01T07:06:30.000Z ##

A ShinyHunters ismét kihasználja a CVE-2026-35273 hibát, web shellt és rendszerszintű hozzáférést szerezve több tucat PeopleSoft-rendszerben. Vannak érintett felsőoktatási, egészségügyi és kormányzati szervek — téged is érinthet, ha nem telepítettétek a javítást? Olvasd el, milyen jeleket keressenek az adminok és miért sürgős a frissítés.

linuxmint.hu/hir/2026/09/tobb-

#ShinyHunters #PeopleSoft #CVE2026-35273 #Oracle #Mandiant #cybersecurity #adatbiztonság #webshell #incidentresponse #ITbiztonság

##

CVE-2026-22755(CVSS UNKNOWN)

EPSS: 20.44%

updated 2026-01-20T21:31:34

1 posts

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, M

cyberworldops@infosec.exchange at 2026-09-30T02:20:00.000Z ##

CISA flagged CVE-2026-22755, a command injection in VIVOTEK's upload_map.cgi allowing unauthenticated OS command execution. Dozens of camera models are affected, creating persistence and lateral movement risk in enterprise and critical infrastructure networks. #Vivotek #CommandInjection #NetworkSecurity

cyberworldops.eu/en/vivotek-ca

##

CVE-2025-41700
(7.8 HIGH)

EPSS: 0.15%

updated 2025-12-01T12:30:34

1 posts

An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.

certvde@infosec.exchange at 2026-10-01T06:41:04.000Z ##

🔒 New CSAF advisory published

VDE-2025-081
WAGO: Multiple PLCs and Communication Components are Affected by multiple Vulnerabilities leading to RCE
CVE-2025-41700, CVE-2025-41738, CVE-2025-41739

Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are <4.10.0 (FW32) and <4.10.0 (70).

HTML: certvde.com/en/advisories/vde-
CSAF JSON: wago.csaf-tp.certvde.com/.well

#OT #Advisory

##

CVE-2025-41738
(7.5 HIGH)

EPSS: 0.39%

updated 2025-12-01T12:30:33

1 posts

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.

certvde@infosec.exchange at 2026-10-01T06:41:04.000Z ##

🔒 New CSAF advisory published

VDE-2025-081
WAGO: Multiple PLCs and Communication Components are Affected by multiple Vulnerabilities leading to RCE
CVE-2025-41700, CVE-2025-41738, CVE-2025-41739

Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are <4.10.0 (FW32) and <4.10.0 (70).

HTML: certvde.com/en/advisories/vde-
CSAF JSON: wago.csaf-tp.certvde.com/.well

#OT #Advisory

##

CVE-2025-4802
(9.8 CRITICAL)

EPSS: 0.59%

updated 2025-11-03T21:34:58

1 posts

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).

1 repos

https://github.com/betizzel/CVE-2025-4802-Proof-of-Concept

alleleintel@infosec.exchange at 2026-09-29T20:56:18.000Z ##

Além de oferecermos os treinamentos mais avançados e completos do mercado brasileiro, nós também desenvolvemos materiais de apoio em português para a comunidade, visando ajudar aqueles que ainda estão começando. O nosso objetivo é que você aprenda de verdade e alcance patamares em sua carreira inicialmente inimagináveis!

Todo aluno inscrito participa da lista de discussão privada do treinamento, na qual compartilhamos conteúdo relevante, e tem acesso a um material complementar que serve como base preparatória.

Confira 3 artigos que escrevemos especialmente para os alunos do nosso treinamento de Exploração de Vulnerabilidades em Binários em Ambientes Linux:

Breve análise de uma vulnerabilidade na glibc (CVE-2025-4802)
allelesecurity.com/libc-vuln-a

O Mindset que Separa o Sênior do Júnior: Lições de Nelson Elhage
allelesecurity.com/mindset-sen

A importância de conhecimentos diversos em pesquisa de vulnerabilidades – A transferibilidade de conhecimento
allelesecurity.com/transferibi

Quanto mais cedo se inscrever, mais rápido alcançará o próximo passo da sua carreira:

Treinamento de Desenvolvimento de Exploits e Segurança de Binários em Linux (Linux Binary Exploitation) – Abril 2027
allelesecurity.com/treinamento

##

CVE-2024-6872
(4.3 MEDIUM)

EPSS: 0.33%

updated 2024-08-03T12:30:40

2 posts

The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for Elementor & Gutenberg Blocks! – TemplateSpare plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'templatespare_activate_required_theme' and 'templatespare_get_theme_status' functions in all versions up to, and includi

security_crawler_carl@infosec.exchange at 2026-09-30T01:08:56.000Z ##

🏆 New Achievement! NetScaler? I Hardly Know Her!

Step right up, friend. Lovely timing — you've arrived just as dozens of government, finance, and education organizations across North America and Europe discovered their Citrix NetScaler appliances had been quietly owned via a zero-day, CVE-2024-6872. Mandiant pulled back the curtain on a stealthy campaign suspected to be state-sponsored. (1/3)

##

security_crawler_carl@infosec.exchange at 2026-09-30T01:08:56.000Z ##

Think of it like those extended warranty calls, except the caller already has your keys, your wallet, and is rearranging the furniture.

May I interest you in our Premium Post-Breach Visibility Package? It retails for slightly more than patching beforehand would have. Tragic coincidence, really.

Apply patches for CVE-2024-6872 to your Citrix NetScaler appliances immediately and review your environment for indicators of compromise. (2/3)

##

CVE-2026-84411
(0 None)

EPSS: 0.00%

3 posts

N/A

tierrasapiens@mastodon.social at 2026-10-01T14:28:15.000Z ##

🖲️ #Noticia de #CiberSeguridad #CiberGuerra #CiberAtaque #CiberNoticia
⚫ (Otra) vulnerabilidad crítica en MikroTik RouterOS (CVE-2026-84411)
🔗 blog.segu-info.com.ar/2026/09/

La Agencia CISA advierte sobre una
nueva vulnerabilidad crítica en MikroTik RouterOS que podría permitir
la ejecución remota de código o provocar una condición de denegación de
servicio.

Identificado como CVE-2026-84411, el problema de seguridad consiste en

##

news@fawkes.rocks at 2026-09-30T16:23:13.000Z ##

MikroTik RouterOS CVE-2026-84411 enables pre-auth root RCE

fawkes.rocks/2026/09/30/mikrot

##

DailyCyberSecurity@infosec.exchange at 2026-09-29T20:11:21.000Z ##

A critical MikroTik RouterOS vulnerability, CVE-2026-84411 (CVSS 9.8), lets unauthenticated attackers run code as root. Update RouterOS now.

#MikroTik #RouterOS #CVE202684411 #RCE #NetworkSecurity #CISA #RouterSecurity #PatchNow

securityonline.info/mikrotik-r

##

CVE-2026-54154
(0 None)

EPSS: 0.00%

1 posts

N/A

Analyst207@mastodon.social at 2026-10-01T14:21:57.000Z ##

Kiteworks Fixes Code Injection Flaw in Email Protection Gateway

Kiteworks has patched a critical vulnerability in its Email Protection Gateway that could have allowed hackers to take full control of the system, and it's essential to update your software ASAP to avoid potential threats. This max-severity flaw, tracked as CVE-2026-54154, could be exploited through low-complexity…

osintsights.com/kiteworks-fixe

#EmailProtectionGateway #Kiteworks #Cve202654154 #CodeInjection #ArbitraryCodeExecution

##

cyberveille@mastobot.ping.moi at 2026-10-01T11:00:31.000Z ##

📢 [VULN] Elle a permis aux hackers de piéger les gendarmes de la cybersécurité en France : c'est quoi la faille Metabase ? CVE-2026-72898

Utilisé par plusieurs services de l’État, Metabase a fait l’objet le 6 août d’un avis de sécurité de son éditeur, accompagné d’un correctif contre une faille de type injection SQL, qui permettait de glisser des instructions malveillantes dans une requête envoyée à…

🔗 numerama.com/cyberguerre/23445
💬 discussion : infosec.pub/post/53003801
#CVE #Cyberveille

##

CVE-2026-102989
(0 None)

EPSS: 0.00%

1 posts

N/A

sayzard@mastodon.sayzard.org at 2026-10-01T10:43:49.000Z ##

TanStack Start critical XSS in server functions (CVE-2026-102989)

TanStack Start의 server function 응답 처리에서 인증되지 않은 공격자가 악성 URL을 통해 애플리케이션 원본(origin)에서 공격자 제어 HTML을 반환하게 만들 수 있는 치명적 반사형 XSS(CVE-2026-102989)가 공개되었습니다. 사용자가 해당 링크를 열면 공격자 JavaScript가 피해자의 애플리케이션 권한 범위에서 실행될 수 있으며, 수정은 클라이언트 입력 제한과 서버 경계에서의 응답 검증을 적용합니다. 영향을 받는 범위는 1.143.12 이상부터 각 패키지별 수정 버전 미만이며, @tanst...

tanstack.com/blog/tanstack-sta

##

CVE-2026-102147
(0 None)

EPSS: 0.43%

2 posts

N/A

offseq at 2026-10-01T10:30:27.593Z ##

CVE-2026-102147: Stored XSS in Kiteworks Core (<9.5.1) rated CRITICAL (CVSS 9.3). Unauth attacker can hijack admin sessions via injected JS — admin takeover risk. No patch yet; restrict access & monitor logs. radar.offseq.com/threat/cve-20 ⚡️

##

offseq@infosec.exchange at 2026-10-01T10:30:27.000Z ##

CVE-2026-102147: Stored XSS in Kiteworks Core (<9.5.1) rated CRITICAL (CVSS 9.3). Unauth attacker can hijack admin sessions via injected JS — admin takeover risk. No patch yet; restrict access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026102147 #AppSec ⚡️

##

CVE-2026-102149
(0 None)

EPSS: 0.33%

1 posts

N/A

offseq@infosec.exchange at 2026-10-01T09:00:24.000Z ##

Kiteworks Email Protection Gateway <9.5.1 has a CRITICAL vuln (CVE-2026-102149, CVSS 9.4): attackers can assign certificates to other user accounts, risking encrypted email exposure & unauthorized access. Await patch, consider disabling cert login. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026102149 #infosec

##

CVE-2026-102106
(0 None)

EPSS: 0.64%

1 posts

N/A

offseq@infosec.exchange at 2026-10-01T07:30:24.000Z ##

CVE-2026-102106 (CRITICAL, CVSS 9.1): Kiteworks Email Protection Gateway (<9.5.0) suffers improper admin authentication — attackers can bypass password checks & gain full admin access. Restrict admin service access & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec

##

CVE-2026-102105
(0 None)

EPSS: 0.53%

1 posts

N/A

offseq@infosec.exchange at 2026-10-01T04:30:23.000Z ##

CVE-2026-102105: Kiteworks Email Protection Gateway <9.5.0 has a CRITICAL SSRF (CVSS 9.1) letting remote attackers access internal resources. No confirmed patch — review vendor guidance & restrict network access. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #Infosec #Vuln

##

CVE-2026-91881
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-10-01T02:32:57.000Z ##

Dell patched critical Dell Terraform Provider vulnerabilities. CVE-2026-91881 exposes BMC traffic to attackers. Upgrade your providers to stay safe.

#Dell #Terraform #CVE202691881 #Cybersecurity #InfoSec

securityonline.info/dell-terra

##

CVE-2026-43598
(0 None)

EPSS: 0.00%

1 posts

N/A

AAKL@infosec.exchange at 2026-09-30T17:06:18.000Z ##

New.

Nvidia security advisories today:

This impacts multiple CVEs: NVIDIA GPU Display Driver - September 2026 nvidia.custhelp.com/app/answer

There's more, posted yesterday nvidia.com/en-us/product-secur

AMD security bulletin: CVE-2026-43598: RCCL Vulnerability amd.com/en/resources/product-s #AMD #infosec #vulnerability #Nvidia

##

CVE-2026-88650
(0 None)

EPSS: 0.00%

1 posts

N/A

thecybermind@infosec.exchange at 2026-09-30T06:40:11.000Z ##

(CISA TS+SOC) CVE-2026-86950 – Apple CoreGraphics Out-of-Bounds Write Briefing

Active exploitation of CVE-2026-88650 [CVE-2026-86950] in Apple CoreGraphics requires immediate patch deployment and forensic triage. Review integrated TSUITE + SOC intelligence assets....

thecybermind.co/2qk4

##

CVE-2026-94603
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-102530
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-12345
(0 None)

EPSS: 0.18%

2 posts

N/A

stanfromireland@mastodon.social at 2026-09-29T19:40:59.000Z ##

Yes, really: cve.org/CVERecord?id=CVE-2026-

##

stanfromireland@mastodon.social at 2026-09-29T19:40:10.000Z ##

CPython was just assigned a delightfully placeholder-looking CVE number for a recent (undelightful) advisory: CVE-2026-12345 😆

##

Visit counter For Websites