##
Updated at UTC 2026-09-16T05:22:38.222378
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-92178 | 7.8 | 0.00% | 2 | 0 | 2026-09-16T04:19:00.327000 | pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution | |
| CVE-2026-92177 | 7.8 | 0.00% | 2 | 0 | 2026-09-16T04:18:59.817000 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Executio | |
| CVE-2026-63695 | 9.8 | 0.00% | 2 | 0 | 2026-09-16T04:18:37.990000 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session F | |
| CVE-2026-12793 | 9.8 | 0.00% | 2 | 0 | 2026-09-16T04:17:56.110000 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnera | |
| CVE-2026-15640 | None | 0.00% | 2 | 0 | 2026-09-16T00:31:41 | Under certain conditions a valid SAML IdP response may be used to impersonate an | |
| CVE-2026-92248 | 7.8 | 0.00% | 2 | 0 | 2026-09-16T00:31:36 | A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail pre | |
| CVE-2026-87289 | 7.5 | 0.00% | 2 | 0 | 2026-09-16T00:31:27 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: hel | |
| CVE-2026-15639 | 0 | 0.00% | 2 | 0 | 2026-09-16T00:17:03.453000 | An attacker can craft a malicious link that, if used by a legitimate user, may c | |
| CVE-2026-85893 | 8.8 | 0.00% | 2 | 0 | 2026-09-15T23:19:12.110000 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke | |
| CVE-2026-69486 | 8.8 | 0.00% | 2 | 0 | 2026-09-15T23:17:41.633000 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthor | |
| CVE-2026-73807 | 9.8 | 0.00% | 4 | 0 | 2026-09-15T22:16:58.683000 | The mySCADA myPRO Manager command API does not properly enforce authentication f | |
| CVE-2026-92000 | 7.5 | 0.00% | 2 | 0 | 2026-09-15T21:33:15 | adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output li | |
| CVE-2026-68070 | 8.8 | 0.00% | 2 | 0 | 2026-09-15T21:33:13 | The affected products are missing authentication for a critical function, which | |
| CVE-2026-66890 | 9.6 | 0.00% | 2 | 0 | 2026-09-15T21:33:13 | The affected products use hard-coded credentials, which could allow remote acces | |
| CVE-2026-89040 | 9.8 | 0.00% | 2 | 0 | 2026-09-15T21:33:13 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated a | |
| CVE-2026-87288 | 8.1 | 0.00% | 2 | 0 | 2026-09-15T21:33:06 | Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil | |
| CVE-2026-87287 | 8.1 | 0.00% | 2 | 0 | 2026-09-15T21:33:06 | Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil | |
| CVE-2026-92176 | 7.8 | 0.00% | 2 | 0 | 2026-09-15T21:31:29 | pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulne | |
| CVE-2026-92179 | 7.8 | 0.00% | 2 | 0 | 2026-09-15T21:31:29 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Executio | |
| CVE-2026-92180 | 7.8 | 0.00% | 2 | 0 | 2026-09-15T21:31:25 | pdfforge PDF Architect activation-service Update Service Uncontrolled Search Pat | |
| CVE-2026-91939 | 9.8 | 0.00% | 2 | 0 | 2026-09-15T21:16:48.957000 | Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() witho | |
| CVE-2026-88975 | 7.5 | 0.00% | 2 | 0 | 2026-09-15T20:19:19.943000 | Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, E | |
| CVE-2026-87286 | 8.1 | 0.00% | 2 | 0 | 2026-09-15T20:19:18.560000 | Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil | |
| CVE-2026-76670 | 9.9 | 0.00% | 2 | 0 | 2026-09-15T20:17:48.833000 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConn | |
| CVE-2026-90606 | 9.9 | 0.49% | 3 | 0 | 2026-09-15T19:17:46.067000 | A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046 | |
| CVE-2026-69213 | 7.5 | 0.00% | 2 | 0 | 2026-09-15T19:17:38.317000 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, E | |
| CVE-2026-89026 | 9.8 | 0.00% | 4 | 0 | 2026-09-15T18:32:43 | The Issabel Framework, the web framework supporting Issabel PBX software, before | |
| CVE-2026-91990 | 7.5 | 0.00% | 2 | 0 | 2026-09-15T18:32:43 | Tornado before 6.5.8 contains a memory amplification vulnerability in parse_mult | |
| CVE-2026-76441 | 9.8 | 0.46% | 2 | 0 | 2026-09-15T18:32:19 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20353 | 9.8 | 0.37% | 2 | 0 | 2026-09-15T18:32:19 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20275 | 8.8 | 0.18% | 2 | 0 | 2026-09-15T18:32:14 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-90703 | 9.1 | 2.80% | 1 | 0 | 2026-09-15T18:19:38.113000 | A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element i | |
| CVE-2026-76440 | 9.8 | 0.43% | 2 | 0 | 2026-09-15T18:19:12.950000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-59160 | 8.8 | 0.00% | 2 | 0 | 2026-09-15T18:17:26.587000 | Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to | |
| CVE-2026-20276 | 8.6 | 0.25% | 2 | 0 | 2026-09-15T18:17:18.607000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20274 | 9.8 | 0.67% | 2 | 0 | 2026-09-15T18:17:18.240000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-91985 | 7.5 | 0.00% | 2 | 0 | 2026-09-15T17:17:44.127000 | Vikunja before 2.6.0 fails to properly restrict access to the link-share hash fi | |
| CVE-2026-91989 | 7.5 | 0.00% | 2 | 0 | 2026-09-15T16:17:58.010000 | atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the | |
| CVE-2026-63696 | 9.1 | 0.00% | 2 | 0 | 2026-09-15T15:32:20 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download | |
| CVE-2026-89025 | 7.5 | 0.00% | 2 | 0 | 2026-09-15T15:32:20 | Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerabilit | |
| CVE-2026-91001 | 9.9 | 0.48% | 4 | 0 | 2026-09-15T15:17:30.983000 | A security flaw has been discovered in D-Link DI-8400 16.07. This affects the fu | |
| CVE-2026-89308 | 0 | 0.00% | 2 | 0 | 2026-09-15T13:16:45.543000 | An unauthenticated OS command injection vulnerability exists in the ping.php end | |
| CVE-2026-76461 | 9.8 | 2.16% | 43 | 3 | 2026-09-15T12:47:32.497000 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure | |
| CVE-2026-91995 | 9.1 | 0.00% | 2 | 0 | 2026-09-15T12:17:54.943000 | pig before 4.1.0 contains an authentication bypass vulnerability in the /registe | |
| CVE-2026-80217 | 8.8 | 0.28% | 2 | 0 | 2026-09-15T09:30:39 | Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allo | |
| CVE-2026-77853 | 8.8 | 1.03% | 2 | 0 | 2026-09-15T09:30:39 | Improper neutralization of special elements used in an OS command ('OS Command I | |
| CVE-2026-75983 | 7.5 | 0.41% | 2 | 0 | 2026-09-15T09:30:38 | The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugi | |
| CVE-2026-91003 | 9.1 | 0.51% | 4 | 0 | 2026-09-15T06:30:40 | A flaw has been found in D-Link DI-8300 16.07. The affected element is the funct | |
| CVE-2026-90847 | 9.1 | 2.18% | 2 | 0 | 2026-09-15T03:30:30 | A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element i | |
| CVE-2026-91771 | 8.8 | 0.73% | 2 | 0 | 2026-09-15T02:16:49.680000 | Weights & Biases wandb before 0.29.0 fails to validate the file name from server | |
| CVE-2026-91200 | 8.8 | 0.42% | 2 | 0 | 2026-09-15T00:31:22 | DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry n | |
| CVE-2026-12944 | 9.6 | 0.25% | 6 | 1 | 2026-09-15T00:31:21 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary P | |
| CVE-2026-65352 | 4.3 | 0.25% | 2 | 0 | 2026-09-15T00:31:13 | An information disclosure issue was addressed with improved state management. Th | |
| CVE-2026-91144 | 7.5 | 0.37% | 2 | 0 | 2026-09-14T22:16:59.053000 | ZFile through 5.0.5 fails to validate requested file paths against a share link' | |
| CVE-2026-82232 | 9.8 | 0.56% | 2 | 0 | 2026-09-14T21:32:45 | Improper neutralization of special elements used in an SQL command ('SQL injecti | |
| CVE-2026-82028 | 8.8 | 0.43% | 2 | 0 | 2026-09-14T21:31:46 | Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale- | |
| CVE-2026-53713 | 9.1 | 0.41% | 2 | 0 | 2026-09-14T21:17:12.520000 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone | |
| CVE-2026-15891 | 7.5 | 0.34% | 1 | 0 | 2026-09-14T21:10:41.650000 | The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mq | |
| CVE-2026-81648 | 10.0 | 0.28% | 1 | 0 | 2026-09-14T21:10:17.423000 | The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an | |
| CVE-2026-74933 | 8.8 | 0.27% | 1 | 0 | 2026-09-14T21:10:17.423000 | The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisatio | |
| CVE-2026-88793 | 8.8 | 0.28% | 1 | 0 | 2026-09-14T21:10:17.423000 | The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any author | |
| CVE-2026-86406 | 7.5 | 0.19% | 1 | 0 | 2026-09-14T21:10:17.423000 | The User Registration & Membership WordPress plugin before 5.2.8 does not check | |
| CVE-2026-89023 | 8.6 | 0.23% | 2 | 0 | 2026-09-14T21:07:11.883000 | ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missin | |
| CVE-2026-78330 | 9.8 | 0.60% | 2 | 0 | 2026-09-14T20:58:48.430000 | Incorrect privilege assignment vulnerability in Apache Syncope. When the config | |
| CVE-2026-90680 | 9.9 | 0.51% | 1 | 0 | 2026-09-14T20:56:48.220000 | A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The im | |
| CVE-2026-90607 | 9.9 | 0.47% | 2 | 0 | 2026-09-14T20:56:48.220000 | A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is | |
| CVE-2026-90510 | 8.3 | 0.29% | 1 | 0 | 2026-09-14T20:56:48.220000 | A security vulnerability has been detected in dromara orion-visor up to 2.5.7. T | |
| CVE-2026-73496 | 7.7 | 0.33% | 2 | 0 | 2026-09-14T20:16:50.833000 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (C | |
| CVE-2026-91080 | 7.5 | 0.59% | 2 | 0 | 2026-09-14T19:18:14.500000 | webhook through 2.8.3 reads the entire request body into memory before evaluatin | |
| CVE-2026-59178 | 9.8 | 0.42% | 2 | 0 | 2026-09-14T19:17:37.617000 | ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management | |
| CVE-2026-91079 | 8.5 | 0.35% | 2 | 0 | 2026-09-14T18:31:35 | Huly Platform through 0.7.426 contains a server-side request forgery vulnerabili | |
| CVE-2026-90946 | 7.5 | 0.57% | 2 | 0 | 2026-09-14T18:31:29 | DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerabili | |
| CVE-2026-85921 | 8.2 | 0.26% | 2 | 0 | 2026-09-14T18:31:29 | Double free in Windows Secure Kernel Mode allows an authorized attacker to eleva | |
| CVE-2026-90945 | 9.8 | 0.53% | 4 | 0 | 2026-09-14T18:31:28 | Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing | |
| CVE-2026-57129 | 7.5 | 0.44% | 2 | 0 | 2026-09-14T16:17:14.220000 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, Mentio | |
| CVE-2026-89746 | 7.8 | 0.16% | 1 | 0 | 2026-09-14T15:33:42 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fi | |
| CVE-2026-89697 | 9.1 | 0.69% | 1 | 0 | 2026-09-14T15:33:39 | In the Linux kernel, the following vulnerability has been resolved: nfsd: add f | |
| CVE-2026-89461 | None | 0.21% | 1 | 0 | 2026-09-14T15:33:29 | In the Linux kernel, the following vulnerability has been resolved: power: supp | |
| CVE-2026-88802 | 7.5 | 0.23% | 1 | 0 | 2026-09-14T15:32:39 | The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events | |
| CVE-2026-85129 | 8.8 | 0.26% | 1 | 0 | 2026-09-14T15:32:39 | The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or vali | |
| CVE-2026-89736 | 7.8 | 0.13% | 1 | 0 | 2026-09-14T15:32:36 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget | |
| CVE-2026-89706 | 7.5 | 0.51% | 1 | 0 | 2026-09-14T15:32:35 | In the Linux kernel, the following vulnerability has been resolved: nfsd: Reset | |
| CVE-2026-89684 | 7.5 | 0.51% | 1 | 0 | 2026-09-14T15:32:34 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix c | |
| CVE-2026-89504 | 8.4 | 0.14% | 1 | 0 | 2026-09-14T15:32:28 | In the Linux kernel, the following vulnerability has been resolved: regulator: | |
| CVE-2026-89508 | 7.8 | 0.12% | 1 | 0 | 2026-09-14T15:32:27 | In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma: | |
| CVE-2026-89481 | 7.5 | 0.41% | 1 | 0 | 2026-09-14T15:32:26 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: f | |
| CVE-2026-89458 | None | 0.18% | 1 | 0 | 2026-09-14T15:32:24 | In the Linux kernel, the following vulnerability has been resolved: s390/dasd: | |
| CVE-2026-80979 | 7.8 | 0.13% | 1 | 0 | 2026-09-14T15:32:22 | In the Linux kernel, the following vulnerability has been resolved: net/smc: un | |
| CVE-2026-43502 | 7.8 | 0.12% | 2 | 1 | 2026-09-14T15:32:07 | In the Linux kernel, the following vulnerability has been resolved: net/rds: ha | |
| CVE-2026-12258 | 0 | 0.40% | 2 | 0 | 2026-09-14T15:17:04.153000 | Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘cus | |
| CVE-2026-85706 | 10.0 | 11.96% | 20 | 12 | 2026-09-14T14:22:15.323000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 | |
| CVE-2026-73324 | 4.3 | 0.21% | 1 | 0 | 2026-09-14T14:17:08.940000 | Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memor | |
| CVE-2026-89750 | 7.8 | 0.16% | 1 | 0 | 2026-09-14T13:19:23.640000 | In the Linux kernel, the following vulnerability has been resolved: tracing/use | |
| CVE-2026-89744 | 8.4 | 0.14% | 1 | 0 | 2026-09-14T13:19:23.193000 | In the Linux kernel, the following vulnerability has been resolved: device prop | |
| CVE-2026-89704 | 7.5 | 0.51% | 1 | 0 | 2026-09-14T13:19:20.367000 | In the Linux kernel, the following vulnerability has been resolved: nfsd: sampl | |
| CVE-2026-89696 | 7.5 | 0.76% | 1 | 0 | 2026-09-14T13:19:19.897000 | In the Linux kernel, the following vulnerability has been resolved: nfsd: block | |
| CVE-2026-89488 | 7.8 | 0.12% | 1 | 0 | 2026-09-14T13:19:05.627000 | In the Linux kernel, the following vulnerability has been resolved: openvswitch | |
| CVE-2026-80973 | 0 | 0.21% | 1 | 0 | 2026-09-14T13:18:52.180000 | In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire | |
| CVE-2026-80970 | 0 | 0.20% | 1 | 0 | 2026-09-14T13:18:51.770000 | In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: | |
| CVE-2026-80931 | 7.8 | 0.13% | 1 | 0 | 2026-09-14T13:18:49.327000 | In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17 | |
| CVE-2026-90919 | 9.8 | 1.01% | 2 | 0 | 2026-09-14T12:31:50 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the Con | |
| CVE-2026-12518 | 0 | 0.11% | 3 | 0 | 2026-09-14T11:17:02.930000 | A local privilege escalation vulnerability in the Logitech Logi Options+ updater | |
| CVE-2026-90608 | 9.9 | 0.80% | 2 | 0 | 2026-09-14T03:30:29 | A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected elemen | |
| CVE-2026-33963 | 7.5 | 0.11% | 1 | 0 | 2026-09-14T03:30:29 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, | |
| CVE-2026-31278 | 7.7 | 0.15% | 2 | 1 | 2026-09-14T03:30:22 | An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 be | |
| CVE-2026-23789 | 7.8 | 0.11% | 1 | 0 | 2026-09-14T02:17:13.397000 | An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processo | |
| CVE-2026-90605 | 9.9 | 0.47% | 1 | 0 | 2026-09-14T00:31:35 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulne | |
| CVE-2026-82078 | 9.1 | 1.69% | 1 | 2 | 2026-09-14T00:16:56.777000 | An unsafe dynamic class loading vulnerability exists in the database connection | |
| CVE-2026-37008 | 8.1 | 0.13% | 1 | 0 | 2026-09-13T21:31:54 | CrewAI before fb2323b offers a Python blocklist approach that operates at the wr | |
| CVE-2026-29811 | 7.7 | 0.25% | 1 | 0 | 2026-09-13T21:31:53 | CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second dom | |
| CVE-2026-90783 | 7.8 | 0.14% | 1 | 0 | 2026-09-13T15:30:28 | MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib l | |
| CVE-2026-90775 | 6.5 | 0.34% | 1 | 0 | 2026-09-13T12:31:19 | PostGIS address_standardizer through 3.7.0 fails to validate the Weight paramete | |
| CVE-2026-90779 | 7.5 | 0.56% | 1 | 0 | 2026-09-13T12:31:19 | SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthH | |
| CVE-2026-90561 | 8.7 | 0.24% | 1 | 0 | 2026-09-13T12:31:11 | Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross- | |
| CVE-2026-89080 | 7.5 | 0.20% | 1 | 0 | 2026-09-13T12:31:10 | The Really Simple Security WordPress plugin before 9.8.1 does not prevent an un | |
| CVE-2026-90562 | 8.1 | 0.42% | 1 | 0 | 2026-09-13T11:17:00.780000 | LangBot before 4.10.11 generates password recovery keys with only 24 bits of ent | |
| CVE-2026-89690 | 7.8 | 0.16% | 1 | 0 | 2026-09-13T09:33:34 | In the Linux kernel, the following vulnerability has been resolved: nfsd: defer | |
| CVE-2026-89688 | 9.8 | 0.61% | 1 | 0 | 2026-09-13T09:33:31 | In the Linux kernel, the following vulnerability has been resolved: nfsd: drop | |
| CVE-2026-89611 | 9.8 | 0.38% | 1 | 0 | 2026-09-13T09:33:31 | In the Linux kernel, the following vulnerability has been resolved: ntfs: valid | |
| CVE-2026-89695 | 7.5 | 0.49% | 1 | 0 | 2026-09-13T09:33:31 | In the Linux kernel, the following vulnerability has been resolved: nfsd: cap d | |
| CVE-2026-89689 | 9.8 | 0.60% | 1 | 0 | 2026-09-13T09:33:30 | In the Linux kernel, the following vulnerability has been resolved: nfsd: don't | |
| CVE-2026-89521 | 7.3 | 0.15% | 1 | 0 | 2026-09-13T09:33:28 | In the Linux kernel, the following vulnerability has been resolved: sched/core: | |
| CVE-2026-80981 | 9.8 | 0.59% | 1 | 0 | 2026-09-13T09:33:25 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fi | |
| CVE-2026-81006 | 7.8 | 0.13% | 2 | 0 | 2026-09-13T09:33:21 | In the Linux kernel, the following vulnerability has been resolved: ipmi: Remov | |
| CVE-2026-80980 | 9.8 | 0.60% | 1 | 0 | 2026-09-13T09:33:21 | In the Linux kernel, the following vulnerability has been resolved: net/smc: st | |
| CVE-2026-89748 | 7.8 | 0.15% | 1 | 0 | 2026-09-13T09:32:30 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fi | |
| CVE-2026-89758 | 7.8 | 0.14% | 1 | 0 | 2026-09-13T09:32:30 | In the Linux kernel, the following vulnerability has been resolved: mm/mempolic | |
| CVE-2026-89686 | 9.8 | 0.67% | 1 | 0 | 2026-09-13T09:32:28 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix B | |
| CVE-2026-89685 | 7.5 | 0.43% | 1 | 0 | 2026-09-13T09:32:28 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix c | |
| CVE-2026-80947 | 7.8 | 0.16% | 1 | 0 | 2026-09-13T09:32:12 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8x | |
| CVE-2026-89747 | 7.8 | 0.16% | 1 | 0 | 2026-09-13T07:17:39.363000 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fi | |
| CVE-2026-89692 | 7.5 | 0.43% | 1 | 0 | 2026-09-13T07:17:35.107000 | In the Linux kernel, the following vulnerability has been resolved: nfsd: clear | |
| CVE-2026-89687 | 7.5 | 0.47% | 1 | 0 | 2026-09-13T07:17:34.493000 | In the Linux kernel, the following vulnerability has been resolved: nfsd: ensur | |
| CVE-2026-89682 | 8.1 | 0.40% | 1 | 0 | 2026-09-13T07:17:34.003000 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix f | |
| CVE-2026-89613 | 9.8 | 0.55% | 1 | 0 | 2026-09-13T07:17:26.840000 | In the Linux kernel, the following vulnerability has been resolved: ntfs: rejec | |
| CVE-2026-89612 | 9.8 | 0.55% | 1 | 0 | 2026-09-13T07:17:26.730000 | In the Linux kernel, the following vulnerability has been resolved: ntfs: rejec | |
| CVE-2026-89501 | 7.8 | 0.16% | 1 | 0 | 2026-09-13T07:17:13.333000 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer | |
| CVE-2026-89499 | 7.8 | 0.12% | 1 | 0 | 2026-09-13T07:17:13.100000 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer | |
| CVE-2026-89450 | 8.8 | 0.13% | 1 | 0 | 2026-09-13T07:17:09.350000 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra | |
| CVE-2026-80995 | 7.8 | 0.12% | 1 | 0 | 2026-09-13T07:17:06.230000 | In the Linux kernel, the following vulnerability has been resolved: net: mctp: | |
| CVE-2026-80936 | 7.8 | 0.13% | 1 | 0 | 2026-09-13T07:17:01.293000 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: | |
| CVE-2026-89517 | None | 0.20% | 1 | 0 | 2026-09-11T21:31:37 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: | |
| CVE-2026-81911 | None | 0.30% | 1 | 0 | 2026-09-11T21:31:32 | Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom | |
| CVE-2026-89447 | None | 0.18% | 1 | 0 | 2026-09-11T21:31:32 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Av | |
| CVE-2026-80927 | None | 0.17% | 1 | 0 | 2026-09-11T21:31:19 | In the Linux kernel, the following vulnerability has been resolved: timekeeping | |
| CVE-2026-84869 | 9.9 | 0.69% | 9 | 0 | 2026-09-11T21:31:17 | A condition in the ScreenConnect client may allow files to be transferred and ex | |
| CVE-2026-42016 | 8.1 | 0.89% | 3 | 0 | 2026-09-11T21:31:06 | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri | |
| CVE-2026-59971 | 10.0 | 0.00% | 2 | 0 | 2026-09-11T20:36:20 | ## Summary In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServer | |
| CVE-2026-81861 | 0 | 0.38% | 2 | 1 | 2026-09-11T20:19:13.263000 | CWE-522: Insufficiently Protected Credentials vulnerability that could result in | |
| CVE-2026-81018 | 0 | 0.13% | 1 | 0 | 2026-09-11T20:19:10.813000 | In the Linux kernel, the following vulnerability has been resolved: platform/x8 | |
| CVE-2026-80974 | 0 | 0.20% | 1 | 0 | 2026-09-11T20:19:03.623000 | In the Linux kernel, the following vulnerability has been resolved: mfd: sm501: | |
| CVE-2026-80960 | 0 | 0.20% | 1 | 0 | 2026-09-11T20:19:01.863000 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: | |
| CVE-2026-89010 | 9.8 | 2.85% | 1 | 0 | 2026-09-11T17:35:21.440000 | WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 cont | |
| CVE-2026-17176 | 0 | 3.59% | 1 | 0 | 2026-09-11T15:21:12.850000 | An OS command injection vulnerability in the TDDP module of Deco BE11000 allows | |
| CVE-2026-87020 | 8.1 | 0.56% | 1 | 0 | 2026-09-11T15:17:06.937000 | An integer overflow in a specified pitch and buffer-size computation leads to a | |
| CVE-2026-86060 | 9.8 | 1.06% | 2 | 1 | 2026-09-11T12:52:16.507000 | RouterOS contains an argument-handling flaw in the SSH login path involving user | |
| CVE-2026-82079 | 8.4 | 0.16% | 2 | 0 | 2026-09-11T03:31:25 | A stack-based buffer overflow vulnerability in the Nintendo Switch local wireles | |
| CVE-2026-65638 | 0 | 3.20% | 1 | 0 | 2026-09-10T19:54:25.810000 | Improper escaping of a request URL in ConfigServer Security & Firewall allows a | |
| CVE-2026-81467 | 9.8 | 3.84% | 1 | 0 | 2026-09-10T18:33:04 | Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutraliza | |
| CVE-2026-81468 | 9.1 | 2.28% | 1 | 0 | 2026-09-10T18:33:03 | Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutraliza | |
| CVE-2026-20079 | 10.0 | 75.75% | 1 | 3 | 2026-09-10T12:48:17.580000 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2025-25249 | 8.1 | 2.40% | 1 | 0 | 2026-09-10T12:47:59.933000 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6 | |
| CVE-2026-85103 | 9.8 | 0.36% | 2 | 0 | 2026-09-10T04:18:18.390000 | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unau | |
| CVE-2026-87491 | 8.8 | 1.00% | 1 | 2 | 2026-09-09T21:31:35 | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remo | |
| CVE-2026-58113 | 6.1 | 0.22% | 2 | 0 | 2026-09-09T16:17:03.483000 | A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.00 | |
| CVE-2026-87827 | 0 | 1.07% | 2 | 0 | 2026-09-09T15:37:49.157000 | Certain KGUARD DVR devices running vulnerable firmware expose a system command e | |
| CVE-2026-85102 | 9.8 | 0.33% | 2 | 0 | 2026-09-09T15:35:15 | Improper certificate trust validation during VPN negotiation in Check Point Quan | |
| CVE-2026-56711 | 8.8 | 0.11% | 1 | 0 | 2026-09-09T15:35:15 | VLC media player computes the size of a picture buffer with 32-bit arithmetic an | |
| CVE-2026-86218 | 9.8 | 0.74% | 1 | 3 | 2026-09-09T05:18:19.490000 | N-central is vulnerable to a pre-auth remote code execution This issue affects N | |
| CVE-2026-85880 | 7.8 | 0.57% | 3 | 0 | 2026-09-09T05:18:19.193000 | Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev | |
| CVE-2026-81963 | 7.8 | 0.63% | 2 | 0 | 2026-09-09T05:18:17.173000 | Improper link resolution before file access ('link following') in Windows Update | |
| CVE-2026-75650 | 10.0 | 2.15% | 3 | 5 | 2026-09-09T05:18:07.237000 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Use | |
| CVE-2026-12745 | 9.8 | 2.09% | 1 | 0 | 2026-09-08T15:32:04 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM bef | |
| CVE-2026-12744 | 9.8 | 2.17% | 1 | 0 | 2026-09-08T15:32:04 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM bef | |
| CVE-2026-79697 | 9.9 | 3.35% | 1 | 0 | 2026-09-08T14:17:29.160000 | A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-661 | |
| CVE-2026-48888 | 7.5 | 0.26% | 2 | 0 | 2026-09-08T13:12:58.310000 | Allocation of Resources Without Limits or Throttling vulnerability in Automattic | |
| CVE-2026-78488 | 6.5 | 3.25% | 1 | 0 | 2026-09-07T15:34:02 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application | |
| CVE-2026-85046 | 8.8 | 1.46% | 1 | 8 | 2026-09-06T03:30:24 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at | |
| CVE-2026-80881 | 0 | 0.17% | 1 | 0 | 2026-09-04T17:17:00.390000 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix | |
| CVE-2026-83548 | 10.0 | 4.67% | 1 | 3 | template | 2026-09-03T13:06:16.053000 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla |
| CVE-2026-83549 | 7.8 | 8.51% | 1 | 2 | 2026-09-02T18:32:06 | Post-authentication Improper Neutralization of Special Elements used in an OS Co | |
| CVE-2026-81573 | 8.6 | 0.46% | 2 | 0 | 2026-09-01T20:56:59.203000 | If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configu | |
| CVE-2026-81575 | 7.5 | 0.44% | 2 | 0 | 2026-09-01T20:56:59.203000 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 acce | |
| CVE-2026-81578 | 9.8 | 1.62% | 1 | 2 | template | 2026-08-31T21:31:56 | An improper access control vulnerability exists in the web management interface |
| CVE-2026-82448 | 9.8 | 0.41% | 2 | 0 | 2026-08-29T15:30:20 | Shinobi before commit 5a76c74f contains a hardcoded connection key in the child | |
| CVE-2026-81576 | 7.7 | 0.33% | 2 | 0 | 2026-08-27T12:30:27 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issu | |
| CVE-2026-81572 | 7.8 | 0.17% | 2 | 0 | 2026-08-27T12:30:27 | cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-S | |
| CVE-2026-81574 | 8.2 | 0.41% | 2 | 0 | 2026-08-27T12:30:27 | In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitiz | |
| CVE-2026-60004 | 9.8 | 86.78% | 6 | 10 | 2026-08-27T11:41:19.230000 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through G | |
| CVE-2026-56368 | 3.7 | 0.26% | 2 | 0 | 2026-08-26T20:48:48 | A memory leak vulnerability exists in multiple coders that write raw pixel data | |
| CVE-2026-59310 | 9.8 | 45.88% | 2 | 2 | 2026-08-18T18:32:52 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-72898 | 10.0 | 94.22% | 1 | 9 | template | 2026-08-12T15:18:30.347000 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via t |
| CVE-2026-62721 | 7.8 | 0.41% | 2 | 0 | 2026-08-11T18:31:23 | Insufficient granularity of access control in User-Mode Power Service (UMPS) all | |
| CVE-2026-61511 | 9.8 | 70.77% | 1 | 5 | 2026-08-07T06:31:24 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul | |
| CVE-2026-62946 | 5.1 | 0.09% | 2 | 0 | 2026-08-03T16:19:22.763000 | ImageMagick is free and open-source software used for editing and manipulating d | |
| CVE-2026-46331 | 7.8 | 0.58% | 1 | 15 | 2026-07-23T12:33:27 | In the Linux kernel, the following vulnerability has been resolved: net/sched: | |
| CVE-2026-4986 | 5.3 | 0.20% | 1 | 2 | 2026-07-23T08:10:00.137000 | The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity o | |
| CVE-2026-49176 | 7.8 | 0.47% | 1 | 2 | 2026-07-22T16:17:28.753000 | Improper privilege management in Windows WalletService allows an authorized atta | |
| CVE-2026-57130 | 8.1 | 0.35% | 2 | 0 | 2026-07-20T21:26:50 | ## Summary The email search tool in `src/praisonai-agents/praisonaiagents/tools | |
| CVE-2026-57126 | 8.5 | 0.38% | 2 | 0 | 2026-07-20T21:25:26 | # praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS | |
| CVE-2026-61865 | 2.9 | 0.10% | 2 | 0 | 2026-07-15T18:20:21.237000 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough li | |
| CVE-2026-61864 | 2.9 | 0.10% | 2 | 0 | 2026-07-15T18:20:21.237000 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transf | |
| CVE-2026-61863 | 2.9 | 0.19% | 2 | 0 | 2026-07-15T12:32:05 | ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in | |
| CVE-2026-61866 | 2.9 | 0.19% | 2 | 0 | 2026-07-15T12:32:05 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG enco | |
| CVE-2026-50458 | 7.8 | 0.26% | 1 | 0 | 2026-07-14T18:32:25 | Use after free in Microsoft Brokering File System allows an authorized attacker | |
| CVE-2026-56373 | 3.7 | 0.23% | 2 | 0 | 2026-07-13T15:15:51.143000 | ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB d | |
| CVE-2026-61857 | 3.7 | 0.27% | 2 | 0 | 2026-07-11T15:30:30 | ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused | |
| CVE-2026-61870 | 2.9 | 0.19% | 2 | 0 | 2026-07-11T15:30:30 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF enc | |
| CVE-2026-61465 | 3.3 | 0.17% | 2 | 0 | 2026-07-11T15:30:29 | ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed mem | |
| CVE-2026-56366 | 3.3 | 0.17% | 2 | 0 | 2026-07-10T15:31:48 | ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META rea | |
| CVE-2026-57239 | 8.2 | 0.17% | 1 | 1 | 2026-07-09T15:33:27 | The user-controllable executable files will be directly executed by high-privile | |
| CVE-2026-56371 | 5.3 | 0.26% | 2 | 0 | 2026-07-02T15:17:07.390000 | ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c | |
| CVE-2026-56379 | None | 0.88% | 2 | 0 | 2026-06-30T03:38:15 | ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerabi | |
| CVE-2026-56370 | 3.3 | 0.12% | 2 | 0 | 2026-06-26T21:50:37.890000 | ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in Co | |
| CVE-2026-47203 | None | 0.45% | 2 | 0 | 2026-06-26T21:32:44 | ### Impact **CVSSv4 Baseline Score:** Moderate 6.3 **CVSSv4 Weighted Score:** | |
| CVE-2026-45051 | None | 0.69% | 2 | 0 | 2026-06-24T17:25:29 | ## Summary **Description** A deserialization of untrusted data vulnerability ( | |
| CVE-2026-56378 | 3.7 | 0.22% | 2 | 0 | 2026-06-21T15:31:31 | ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bo | |
| CVE-2026-4201 | 7.3 | 0.28% | 1 | 0 | 2026-06-17T10:56:10.603000 | A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040f | |
| CVE-2026-28993 | 5.5 | 0.12% | 2 | 0 | 2026-06-17T10:29:27.873000 | This issue was addressed by adding an additional prompt for user consent. This i | |
| CVE-2026-27540 | 9.0 | 1.73% | 3 | 1 | 2026-06-17T10:27:18.693000 | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co P | |
| CVE-2025-30208 | 5.3 | 74.97% | 2 | 23 | 2026-06-17T09:08:21.517000 | Vite, a provider of frontend development tooling, has a vulnerability in version | |
| CVE-2024-45811 | 4.8 | 1.06% | 2 | 0 | 2026-06-17T07:54:51.767000 | Vite a frontend build tooling framework for javascript. In affected versions the | |
| CVE-2024-3094 | 10.0 | 85.97% | 1 | 90 | 2026-06-17T07:43:17.830000 | Malicious code was discovered in the upstream tarballs of xz, starting with vers | |
| CVE-2024-1813 | 9.8 | 1.22% | 1 | 1 | 2026-06-17T07:05:03.993000 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection | |
| CVE-2023-38198 | 9.8 | 1.08% | 2 | 0 | 2026-06-17T06:09:38.793000 | acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as e | |
| CVE-2026-39987 | 9.8 | 98.95% | 4 | 25 | 2026-04-27T16:30:09 | ## Summary Marimo (19.6k stars) has a Pre-Auth RCE vulnerability. The terminal | |
| CVE-2026-39364 | None | 2.00% | 8 | 0 | 2026-04-07T22:16:19 | ### Summary The contents of files that are specified by [`server.fs.deny`](http | |
| CVE-2026-2275 | 9.6 | 0.44% | 1 | 0 | 2026-03-31T18:32:38 | The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach | |
| CVE-2025-31125 | 5.3 | 58.46% | 2 | 7 | 2026-01-22T21:47:41 | ### Summary The contents of arbitrary files can be returned to the browser. ## | |
| CVE-2021-44228 | 10.0 | 100.00% | 1 | 100 | 2025-10-22T19:13:26 | # Summary Log4j versions prior to 2.16.0 are subject to a remote code execution | |
| CVE-2026-87886 | 0 | 0.00% | 5 | 0 | N/A | ||
| CVE-2026-90711 | 0 | 0.19% | 4 | 0 | N/A | ||
| CVE-2026-61642 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-85498 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-88065 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-63443 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-51990 | 0 | 0.00% | 6 | 1 | N/A | ||
| CVE-2026-57586 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-65838 | 0 | 0.27% | 2 | 0 | N/A | ||
| CVE-2026-63030 | 0 | 97.27% | 1 | 85 | template | N/A |
updated 2026-09-16T04:19:00.327000
2 posts
🟠 CVE-2026-92178 - High (7.8)
pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92178/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92178 - High (7.8)
pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92178/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T04:18:59.817000
2 posts
🟠 CVE-2026-92177 - High (7.8)
pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92177/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92177 - High (7.8)
pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92177/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T04:18:37.990000
2 posts
🔴 CVE-2026-63695 - Critical (9.8)
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-63695 - Critical (9.8)
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T04:17:56.110000
2 posts
CVE-2026-12793: CRITICAL privilege escalation in JetFormBuilder Dynamic Blocks Form Builder (<=3.6.2). Unauthenticated attackers can create admin accounts. Restrict access & monitor until patch. https://radar.offseq.com/threat/cve-2026-12793-cwe-269-improper-privilege-management-in-jetmonsters-jetformbuilder-dynamic-blocks-form-fa1c70f5eeec8d4c #OffSeq #WordPress #CVE202612793 #Infosec
##CVE-2026-12793: CRITICAL privilege escalation in JetFormBuilder Dynamic Blocks Form Builder (<=3.6.2). Unauthenticated attackers can create admin accounts. Restrict access & monitor until patch. https://radar.offseq.com/threat/cve-2026-12793-cwe-269-improper-privilege-management-in-jetmonsters-jetformbuilder-dynamic-blocks-form-fa1c70f5eeec8d4c #OffSeq #WordPress #CVE202612793 #Infosec
##updated 2026-09-16T00:31:41
2 posts
Delinea Secret Server (On-Prem, v10.5.0 – 12.1.3) hit by CRITICAL auth bypass (CVE-2026-15640). SAML spoofing may allow attacker impersonation. Patch info not yet available. Details: https://radar.offseq.com/threat/cve-2026-15640-cwe-290-authentication-bypass-by-spoofing-in-delinea-secret-server-on-prem-e1dc96081cdc3445 #OffSeq #Vuln #Delinea #CVE202615640
##Delinea Secret Server (On-Prem, v10.5.0 – 12.1.3) hit by CRITICAL auth bypass (CVE-2026-15640). SAML spoofing may allow attacker impersonation. Patch info not yet available. Details: https://radar.offseq.com/threat/cve-2026-15640-cwe-290-authentication-bypass-by-spoofing-in-delinea-secret-server-on-prem-e1dc96081cdc3445 #OffSeq #Vuln #Delinea #CVE202615640
##updated 2026-09-16T00:31:36
2 posts
🟠 CVE-2026-92248 - High (7.8)
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This lea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92248/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92248 - High (7.8)
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This lea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92248/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T00:31:27
2 posts
🟠 CVE-2026-87289 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network ac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87289/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-87289 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network ac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87289/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-16T00:17:03.453000
2 posts
CVE-2026-15639: CRITICAL XSS in Delinea Secret Server (On-Prem, 10.2.19 – 11.9.48). Exploitation allows remote attackers to run JS in user sessions. Patch status unknown — check vendor advisories. https://radar.offseq.com/threat/cve-2026-15639-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-ac80ea2cb57f59e8 #OffSeq #XSS #Vuln #Delinea #Cybersecurity
##CVE-2026-15639: CRITICAL XSS in Delinea Secret Server (On-Prem, 10.2.19 – 11.9.48). Exploitation allows remote attackers to run JS in user sessions. Patch status unknown — check vendor advisories. https://radar.offseq.com/threat/cve-2026-15639-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-ac80ea2cb57f59e8 #OffSeq #XSS #Vuln #Delinea #Cybersecurity
##updated 2026-09-15T23:19:12.110000
2 posts
🟠 CVE-2026-85893 - High (8.8)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85893/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85893 - High (8.8)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85893/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T23:17:41.633000
2 posts
🟠 CVE-2026-69486 - High (8.8)
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69486/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-69486 - High (8.8)
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69486/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T22:16:58.683000
4 posts
Discover the latest mySCADA myPRO Manager vulnerabilities, including CVE-2026-73807, and learn how to patch your systems to prevent remote attacks.
##CVE-2026-73807 | CRITICAL: mySCADA myPRO (v0 – 2.1) API flaw allows unauthenticated access to privileged functions. No patch yet — restrict API network access & monitor logs. https://radar.offseq.com/threat/cve-2026-73807-cwe-862-in-myscada-technologies-myscada-mypro-e06debb83925d7aa #OffSeq #ICS #SCADA #Vulnerability
##Discover the latest mySCADA myPRO Manager vulnerabilities, including CVE-2026-73807, and learn how to patch your systems to prevent remote attacks.
##CVE-2026-73807 | CRITICAL: mySCADA myPRO (v0 – 2.1) API flaw allows unauthenticated access to privileged functions. No patch yet — restrict API network access & monitor logs. https://radar.offseq.com/threat/cve-2026-73807-cwe-862-in-myscada-technologies-myscada-mypro-e06debb83925d7aa #OffSeq #ICS #SCADA #Vulnerability
##updated 2026-09-15T21:33:15
2 posts
🟠 CVE-2026-92000 - High (7.5)
adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92000/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92000 - High (7.5)
adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92000/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:33:13
2 posts
🟠 CVE-2026-68070 - High (8.8)
The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68070/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-68070 - High (8.8)
The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68070/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:33:13
2 posts
🔴 CVE-2026-66890 - Critical (9.6)
The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66890/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-66890 - Critical (9.6)
The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66890/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:33:13
2 posts
🔴 CVE-2026-89040 - Critical (9.8)
Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89040/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-89040 - Critical (9.8)
Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89040/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:33:06
2 posts
🟠 CVE-2026-87288 - High (8.1)
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-87288 - High (8.1)
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:33:06
2 posts
🟠 CVE-2026-87287 - High (8.1)
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87287/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-87287 - High (8.1)
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87287/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:31:29
2 posts
🟠 CVE-2026-92176 - High (7.8)
pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92176/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92176 - High (7.8)
pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92176/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:31:29
2 posts
🟠 CVE-2026-92179 - High (7.8)
pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92179/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92179 - High (7.8)
pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92179/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:31:25
2 posts
🟠 CVE-2026-92180 - High (7.8)
pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92180/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-92180 - High (7.8)
pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92180/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T21:16:48.957000
2 posts
🔴 CVE-2026-91939 - Critical (9.8)
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91939/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-91939 - Critical (9.8)
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91939/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T20:19:19.943000
2 posts
🟠 CVE-2026-88975 - High (7.5)
Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88975/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-88975 - High (7.5)
Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88975/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T20:19:18.560000
2 posts
🟠 CVE-2026-87286 - High (8.1)
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-87286 - High (8.1)
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T20:17:48.833000
2 posts
A critical HPE EdgeConnect authorization bypass (CVE-2026-76670) enables full system compromise. Patch this HPE EdgeConnect authorization bypass now.
#HPE #EdgeConnect #AuthorizationBypass #CVE202676670 #Cybersecurity
##A critical HPE EdgeConnect authorization bypass (CVE-2026-76670) enables full system compromise. Patch this HPE EdgeConnect authorization bypass now.
#HPE #EdgeConnect #AuthorizationBypass #CVE202676670 #Cybersecurity
##updated 2026-09-15T19:17:46.067000
3 posts
CVE-2026-90606: HIGH-severity buffer overflow in Totolink A3002MU Hh-B20211125.1046 (boa/formIpv6Setup). Public exploit disclosed. RCE or DoS possible. Restrict access & monitor IPv6 setup. No patch yet. https://radar.offseq.com/threat/a-security-vulnerability-has-been-detected-in-totolink-a3002mu-hh-b202111251046-cve-2026-90606-6a6dad4a128a1845 #OffSeq #Vuln #IoTSecurity #BufferOverflow
##🔴 CVE-2026-90606 - Critical (9.9)
A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer ov...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90606/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-90606: CRITICAL buffer overflow in Totolink A3002MU (Hh-B20211125.1046). Remote attackers can exploit static_ipv6 in /boafrm/formIpv6Setup. Exploit is public — review device exposure now. https://radar.offseq.com/threat/cve-2026-90606-buffer-overflow-in-totolink-a3002mu-ff1e560ec5dedad6 #OffSeq #CVE202690606 #RouterSecurity #NetSec
##updated 2026-09-15T19:17:38.317000
2 posts
🟠 CVE-2026-69213 - High (7.5)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can continue se...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69213/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-69213 - High (7.5)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can continue se...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69213/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T18:32:43
4 posts
Thank you to @vulncheck for the smooth collaboration throughout the CNA process.
More details:
https://www.cve.org/CVERecord?id=CVE-2026-89026
🔴 CVE-2026-89026 - Critical (9.8)
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89026/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Thank you to @vulncheck for the smooth collaboration throughout the CNA process.
More details:
https://www.cve.org/CVERecord?id=CVE-2026-89026
🔴 CVE-2026-89026 - Critical (9.8)
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89026/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T18:32:43
2 posts
🟠 CVE-2026-91990 - High (7.5)
Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transie...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91990/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91990 - High (7.5)
Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transie...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91990/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T18:32:19
2 posts
Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-09-15T18:32:19
2 posts
Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-09-15T18:32:14
2 posts
Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
##Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
##updated 2026-09-15T18:19:38.113000
1 posts
D-Link DWR-M921 v1.1.52 is vulnerable to CRITICAL OS command injection (CVE-2026-90703, CVSS 9.4). No patch yet, public exploit out. Restrict access & monitor logs. Details: https://radar.offseq.com/threat/cve-2026-90703-os-command-injection-in-d-link-dwr-m921-f9739a3ef4495656 #OffSeq #CVE #RouterSecurity #Infosec
##updated 2026-09-15T18:19:12.950000
2 posts
Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-09-15T18:17:26.587000
2 posts
🟠 CVE-2026-59160 - High (8.8)
Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59160/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-59160 - High (8.8)
Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59160/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T18:17:18.607000
2 posts
Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
##Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
##updated 2026-09-15T18:17:18.240000
2 posts
Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
##Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
##updated 2026-09-15T17:17:44.127000
2 posts
🟠 CVE-2026-91985 - High (7.5)
Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91985/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91985 - High (7.5)
Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91985/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T16:17:58.010000
2 posts
🟠 CVE-2026-91989 - High (7.5)
atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path conta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91989/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91989 - High (7.5)
atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path conta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91989/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T15:32:20
2 posts
🔴 CVE-2026-63696 - Critical (9.1)
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63696/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-63696 - Critical (9.1)
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63696/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T15:32:20
2 posts
🟠 CVE-2026-89025 - High (7.5)
Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specif...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89025/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89025 - High (7.5)
Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specif...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89025/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T15:17:30.983000
4 posts
🔴 CVE-2026-91001 - Critical (9.9)
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91001/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Stack-based buffer overflow (CVE-2026-91001, CVSS 9.4) in D-Link DI-8400 (16.07) exposes devices to RCE. Exploit code is public. Restrict management access until fix. Details: https://radar.offseq.com/threat/cve-2026-91001-stack-based-buffer-overflow-in-d-link-di-8400-abc2e3e858f255b9 #OffSeq #CVE202691001 #IoTSecurity #Vulnerability
##🔴 CVE-2026-91001 - Critical (9.9)
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91001/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Stack-based buffer overflow (CVE-2026-91001, CVSS 9.4) in D-Link DI-8400 (16.07) exposes devices to RCE. Exploit code is public. Restrict management access until fix. Details: https://radar.offseq.com/threat/cve-2026-91001-stack-based-buffer-overflow-in-d-link-di-8400-abc2e3e858f255b9 #OffSeq #CVE202691001 #IoTSecurity #Vulnerability
##updated 2026-09-15T13:16:45.543000
2 posts
CVE-2026-89308 in TREXOM TrxTimeATTENDANCE (v1.0.5 – 1.9.5): CRITICAL OS command injection in ping.php allows unauthenticated RCE. Remediate ASAP. https://radar.offseq.com/threat/cve-2026-89308-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-8f863d468f1bf361 #OffSeq #CVE202689308 #infosec #vuln #remediation
##CVE-2026-89308 in TREXOM TrxTimeATTENDANCE (v1.0.5 – 1.9.5): CRITICAL OS command injection in ping.php allows unauthenticated RCE. Remediate ASAP. https://radar.offseq.com/threat/cve-2026-89308-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-8f863d468f1bf361 #OffSeq #CVE202689308 #infosec #vuln #remediation
##updated 2026-09-15T12:47:32.497000
43 posts
3 repos
https://github.com/fevar54/CVE-2026-76461-Detection-Kit-
⚠️ CRITICAL: Cisco warns customers of actively exploited zero-day in email gateways
Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabili…
🤖 AI generated summary
##⚠️ CRITICAL: Cisco patches Secure Email Gateway zero-day exploited in attacks
Cisco Secure Email Gateway has a critical zero-day (CVE-2026-76461) that allows unauthenticated attackers to execute arbitrary commands as root via malicious SQL in crafted emails. This is actively exploited in the wild. Any organization running SEG is at immediate risk of full compromise.
🤖 AI generated summary
##Cisco email security boxes can be rooted by an email
Cisco Secure Email Gateway의 AsyncOS에서 수신 이메일 처리 취약점(CVE-2026-76461)이 악용되고 있으며, 인증 없이 조작된 이메일 하나로 어플라이언스의 root 권한 명령 실행이 가능하다. CVSS는 9.8이고 물리·가상 어플라이언스 구성과 무관하게 영향을 받으며, 우회책이 없어 패치가 유일한 대응이다. 침해 후 공격자는 로컬 로그를 변조해 흔적을 지울 수 있으므로 게이트웨이 로그뿐 아니라 네트워크·방화벽 로그를 함께 조사해야 한다. Cisco는 AsyncO...
##Cisco Secure Email Gateway Zero-Day Under Active Attack: Critical CVE-2026-76461 Puts Root-Level Access at Risk + Video
A Critical Warning for Cisco Customers A serious cybersecurity warning is unfolding around Cisco Secure Email Gateway after Cisco disclosed active exploitation of CVE-2026-76461, a critical zero-day vulnerability that can allow an unauthenticated remote attacker to execute commands with root privileges. The vulnerability has also been added to the…
##🔵 THREAT INTELLIGENCE
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Vulnerability | CRITICAL
CVEs: CVE-2026-76461
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]
Full analysis:
https://www.yazoul.net/news/article/cisco-secure-email-gateway-flaw-exploited-in-the-wild-enables-root-command-execu
by Yazoul AI
##Cisco Discloses Actively Exploited Zero-Day in Email Gateways
A critical zero-day vulnerability, CVE-2026-76461, is under active exploitation, allowing hackers to remotely execute commands as root on Cisco Secure Email Gateway appliances with just a simple email. This gaping security hole gives attackers total control of the gateway, putting your email security at risk.
#ZeroDay #Cve202676461 #Cisco #EmailGateway #RemoteCodeExecution
##📰 Cisco Patches Actively Exploited Zero-Day in Secure Email Gateways
Cisco patches critical, actively exploited zero-day (CVE-2026-76461) in Secure Email Gateways. Unauthenticated attackers can compromise devices via a crafted email. CISA has added it to the KEV catalog. #CyberSecurity #ZeroDay #Infosec #Cisco
##Geopolitical tensions: A Russian drone struck a Kyiv-Warsaw train near the Polish border (Sept 13), and Houthi forces secured Yemen's Red Sea coast (Sept 11), affecting maritime routes. Tech news: Apple's Siri AI, powered by Apple Intelligence, began its beta rollout (Sept 14). Cybersecurity: Cisco warned of active exploitation of a critical Secure Email Gateway flaw (CVE-2026-76461) (Sept 15), and Anthropic reported Russia-linked spies used its AI Claude for hacking campaigns.
##Actionable C-Suite threat intelligence and mitigation strategies for CVE-2026-76461, addressing active SQL injection exploitation vectors within enterprise Cisco Secure Email Gateway infrastructures. https://thecybermind.co/r5ry
##Cisco Email Gateways Exploited by Malicious Emails
A single malicious email can wreak havoc on your Cisco Secure Email Gateway, thanks to a critical vulnerability (CVE-2026-76461) that allows hackers to gain root access with a 9.8 CVSS score - and patching is the only fix.
#Cisco #Cve202676461 #EmailGateway #SecureEmailGateway #Vulnerability
##Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
##Cisco Secure Email Gateway Zero-Day CVE-2026-76461: Critical 98 Flaw Is Already Being Exploited in the Wild + Video
A Dangerous New Threat Hiding Inside Email Traffic Email security appliances are supposed to stand between organizations and malicious messages. This time, however, attackers are using the email-processing function itself as the entry point. Cisco has disclosed CVE-2026-76461, a critical SQL-injection vulnerability in Cisco Secure Email Gateway appliances…
##🔴 New security advisory:
CVE-2026-76461 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-76461-cisco-secure-email-gateway-rce-exploited-poc
by Yazoul AI
##Cisco Secure Email Gateway Hit by Critical Zero-Day as Attackers Gain Root Access Through Malicious Emails + Video
A Dangerous New Cisco Zero-Day A critical zero-day vulnerability in Cisco Secure Email Gateway has moved from a theoretical security concern into an active incident, with Cisco confirming exploitation in the wild. Tracked as CVE-2026-76461, the flaw carries a CVSS score of 9.8 and can allow an unauthenticated remote attacker to execute arbitrary commands…
##Cisco Secure Email Gateway Zero-Day Exploited in the Wild: Critical CVE-2026-76461 Gives Attackers a Path to Root + Video
A New Cisco Security Crisis Is Unfolding A serious security warning has emerged for organizations relying on Cisco Secure Email Gateway. Cisco has confirmed that CVE-2026-76461, a critical SQL injection vulnerability in Cisco AsyncOS, is being actively exploited in the wild. The flaw can allow a remote, unauthenticated attacker to send a specially…
##📢 [VULN] ⚠️Injection SQL exploitée dans Cisco Secure Email Gateway - CVE-2026-76461
Le 14 septembre 2026 à 16 h 00 UTC, Cisco a publié deux avis de sécurité sur sa passerelle de messagerie.
🔗 https://blog.marcfredericgomez.fr/injection-sql-exploitee-dans-cisco-secure-email-gateway/
💬 discussion : https://infosec.pub/post/52317366
#CVE #Cyberveille
「Ciscoのセキュアメールゲートウェイの脆弱性が実際に悪用され、ルート権限でのコマンド実行が可能になる 」: #TheHackerNews
「スコは、Cisco Secure Email Gateway向けAsyncOSソフトウェアに影響を与える新たな重大な脆弱性が、実際に悪用されていると警告した。
CVE-2026-76461 として追跡されているこの脆弱性は 、CVSSスコアが10.0点満点中9.8点です。これは、メール解析ロジックにおける検証の不備が原因で、認証されていないリモート攻撃者が、基盤となるオペレーティングシステム上でroot権限で任意のコマンドを実行できる可能性があるとされています。
シスコは月曜日の勧告で、「攻撃者は、悪意のあるSQL文を含む細工された電子メールメッセージを影響を受けるデバイスに送信することで、この脆弱性を悪用する可能性がある」 と述べた 。」
https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html
##Cisco Discloses Zero-Day Exploited in Secure Email Gateway Attacks
Cisco has warned of a zero-day flaw in its Secure Email Gateway that allows attackers to run commands as root, prompting federal agencies to patch the vulnerability within just three days. This critical defect, tracked as CVE-2026-76461, lets hackers execute arbitrary commands with root privileges, putting systems at risk.
#ZeroDay #SecureEmailGateway #Cve202676461 #EmergingThreats #Cisco
##Cisco Email Gateway Flaw Exploited, Enables Root Command Execution
A critical Cisco email gateway flaw, CVE-2026-76461, with a near-perfect CVSS score of 9.8, is being actively exploited in the wild, allowing attackers to send a single crafted email and gain root command execution on vulnerable devices. This severe vulnerability stems from insufficient validation in AsyncOS email parsing, making it…
#Cisco #Cve202676461 #EmailGateway #RemoteCodeExecution #SupplyChain
##Cisco Secure Email Gateway Zero-Day Under Active Attack as Root-Level Access Puts Defenders on High Alert + Video
A Critical Warning for Email Security Teams Cisco has confirmed that a critical vulnerability in Cisco Secure Email Gateway is being actively exploited in the wild, turning a security weakness inside email-processing logic into a potential gateway for complete operating-system compromise. Tracked as CVE-2026-76461, the flaw carries a CVSS score of 9.8,…
##CRITICAL (CVSS 9.8): CVE-2026-76461 in Cisco AsyncOS for Secure Email Gateway lets unauthenticated attackers execute commands as root via crafted emails. Patch status unknown — monitor Cisco’s updates. https://radar.offseq.com/threat/a-vulnerability-in-the-email-parsing-of-cisco-asyncos-software-for-cisco-secure-email-gateway-could-a5a1b3247d786df4 #OffSeq #Cisco #Vulnerability #EmailSecurity
##CVE-2026-76461 (CVSS 9.8) is a Cisco Secure Email Gateway vulnerability exploited in the wild. SQL injection grants root command execution. Patch now.
#Cisco #EmailSecurity #CVE202676461 #SQLInjection #RCE #ExploitedInTheWild #AsyncOS #InfoSec #PatchNow #RootAccess
##No one else seems to have noticed the Cisco exploited zero-day:
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability
##🚨 [CISA-2026:0914] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-76461 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76461)
- Name: Cisco Secure Email Gateway SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Email Gateway
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-76461
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260914 #cisa20260914 #cve_2026_76461 #cve202676461
##CRITICAL CISA KEV ALERT: CVE-2026-76461 targets Cisco Secure Email Gateway via SQL injection, granting root-level RCE. Active exploitation verified. Access our TSUITE brief for SIEM queries and hardening steps to secure your email perimeter.
##CVE ID: CVE-2026-76461
Vendor: Cisco
Product: Secure Email Gateway
Date Added: 2026-09-14
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76461
Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##ayy lmao Cisco CVE-2026-76461
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
##In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.
⚠️ CRITICAL: Cisco warns customers of actively exploited zero-day in email gateways
Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabili…
🤖 AI generated summary
##⚠️ CRITICAL: Cisco patches Secure Email Gateway zero-day exploited in attacks
Cisco Secure Email Gateway has a critical zero-day (CVE-2026-76461) that allows unauthenticated attackers to execute arbitrary commands as root via malicious SQL in crafted emails. This is actively exploited in the wild. Any organization running SEG is at immediate risk of full compromise.
🤖 AI generated summary
##Geopolitical tensions: A Russian drone struck a Kyiv-Warsaw train near the Polish border (Sept 13), and Houthi forces secured Yemen's Red Sea coast (Sept 11), affecting maritime routes. Tech news: Apple's Siri AI, powered by Apple Intelligence, began its beta rollout (Sept 14). Cybersecurity: Cisco warned of active exploitation of a critical Secure Email Gateway flaw (CVE-2026-76461) (Sept 15), and Anthropic reported Russia-linked spies used its AI Claude for hacking campaigns.
##Actionable C-Suite threat intelligence and mitigation strategies for CVE-2026-76461, addressing active SQL injection exploitation vectors within enterprise Cisco Secure Email Gateway infrastructures. https://thecybermind.co/r5ry
##Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
##📢 [VULN] ⚠️Injection SQL exploitée dans Cisco Secure Email Gateway - CVE-2026-76461
Le 14 septembre 2026 à 16 h 00 UTC, Cisco a publié deux avis de sécurité sur sa passerelle de messagerie.
🔗 https://blog.marcfredericgomez.fr/injection-sql-exploitee-dans-cisco-secure-email-gateway/
💬 discussion : https://infosec.pub/post/52317366
#CVE #Cyberveille
「Ciscoのセキュアメールゲートウェイの脆弱性が実際に悪用され、ルート権限でのコマンド実行が可能になる 」: #TheHackerNews
「スコは、Cisco Secure Email Gateway向けAsyncOSソフトウェアに影響を与える新たな重大な脆弱性が、実際に悪用されていると警告した。
CVE-2026-76461 として追跡されているこの脆弱性は 、CVSSスコアが10.0点満点中9.8点です。これは、メール解析ロジックにおける検証の不備が原因で、認証されていないリモート攻撃者が、基盤となるオペレーティングシステム上でroot権限で任意のコマンドを実行できる可能性があるとされています。
シスコは月曜日の勧告で、「攻撃者は、悪意のあるSQL文を含む細工された電子メールメッセージを影響を受けるデバイスに送信することで、この脆弱性を悪用する可能性がある」 と述べた 。」
https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html
##CRITICAL (CVSS 9.8): CVE-2026-76461 in Cisco AsyncOS for Secure Email Gateway lets unauthenticated attackers execute commands as root via crafted emails. Patch status unknown — monitor Cisco’s updates. https://radar.offseq.com/threat/a-vulnerability-in-the-email-parsing-of-cisco-asyncos-software-for-cisco-secure-email-gateway-could-a5a1b3247d786df4 #OffSeq #Cisco #Vulnerability #EmailSecurity
##CVE-2026-76461 (CVSS 9.8) is a Cisco Secure Email Gateway vulnerability exploited in the wild. SQL injection grants root command execution. Patch now.
#Cisco #EmailSecurity #CVE202676461 #SQLInjection #RCE #ExploitedInTheWild #AsyncOS #InfoSec #PatchNow #RootAccess
##Since no one seems to have noticed the Cisco exploited zero-day:
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability
##🚨 [CISA-2026:0914] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-76461 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76461)
- Name: Cisco Secure Email Gateway SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Email Gateway
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-76461
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260914 #cisa20260914 #cve_2026_76461 #cve202676461
##CRITICAL CISA KEV ALERT: CVE-2026-76461 targets Cisco Secure Email Gateway via SQL injection, granting root-level RCE. Active exploitation verified. Access our TSUITE brief for SIEM queries and hardening steps to secure your email perimeter.
##CVE ID: CVE-2026-76461
Vendor: Cisco
Product: Secure Email Gateway
Date Added: 2026-09-14
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76461
Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##ayy lmao Cisco CVE-2026-76461
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
##In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.
updated 2026-09-15T12:17:54.943000
2 posts
pig-mesh pig <4.1.0 hit by CRITICAL vuln (CVE-2026-91995, CVSS 9.3): remote attackers can reset any account password — admin included — via /register/password auth bypass. Restrict access & monitor logs while awaiting patch. https://radar.offseq.com/threat/cve-2026-91995-unverified-password-change-in-pig-mesh-pig-6a0b879ab4cc0e5c #OffSeq #vulnerability #CVE #infosec
##pig-mesh pig <4.1.0 hit by CRITICAL vuln (CVE-2026-91995, CVSS 9.3): remote attackers can reset any account password — admin included — via /register/password auth bypass. Restrict access & monitor logs while awaiting patch. https://radar.offseq.com/threat/cve-2026-91995-unverified-password-change-in-pig-mesh-pig-6a0b879ab4cc0e5c #OffSeq #vulnerability #CVE #infosec
##updated 2026-09-15T09:30:39
2 posts
🟠 CVE-2026-80217 - High (8.8)
Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80217/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80217 - High (8.8)
Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80217/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T09:30:39
2 posts
🟠 CVE-2026-77853 - High (8.8)
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77853/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77853 - High (8.8)
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77853/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T09:30:38
2 posts
🟠 CVE-2026-75983 - High (7.5)
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` func...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75983 - High (7.5)
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` func...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T06:30:40
4 posts
🔴 CVE-2026-91003 - Critical (9.1)
A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91003/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##D-Link DI-8300 (fw 16.07) hit by CRITICAL stack buffer overflow (CVE-2026-91003) in /rzgl.asp — remote RCE possible, public exploit code out. Restrict access & monitor traffic until patch. https://radar.offseq.com/threat/cve-2026-91003-stack-based-buffer-overflow-in-d-link-di-8300-ce23f2734338a347 #OffSeq #CVE202691003 #DLink #Security
##🔴 CVE-2026-91003 - Critical (9.1)
A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91003/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##D-Link DI-8300 (fw 16.07) hit by CRITICAL stack buffer overflow (CVE-2026-91003) in /rzgl.asp — remote RCE possible, public exploit code out. Restrict access & monitor traffic until patch. https://radar.offseq.com/threat/cve-2026-91003-stack-based-buffer-overflow-in-d-link-di-8300-ce23f2734338a347 #OffSeq #CVE202691003 #DLink #Security
##updated 2026-09-15T03:30:30
2 posts
EFM ipTIME C200E v1.094 suffers CRITICAL OS command injection (CVE-2026-90847, CVSS 9.4) via iux_set.cgi. Remotely exploitable, public exploit available. Restrict device access and monitor. https://radar.offseq.com/threat/cve-2026-90847-os-command-injection-in-efm-iptime-c200e-1c30057b126bbbf4 #OffSeq #Vulnerability #IoTSecurity #CVE
##EFM ipTIME C200E v1.094 suffers CRITICAL OS command injection (CVE-2026-90847, CVSS 9.4) via iux_set.cgi. Remotely exploitable, public exploit available. Restrict device access and monitor. https://radar.offseq.com/threat/cve-2026-90847-os-command-injection-in-efm-iptime-c200e-1c30057b126bbbf4 #OffSeq #Vulnerability #IoTSecurity #CVE
##updated 2026-09-15T02:16:49.680000
2 posts
🟠 CVE-2026-91771 - High (8.8)
Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91771/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91771 - High (8.8)
Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91771/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T00:31:22
2 posts
🟠 CVE-2026-91200 - High (8.8)
DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91200/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91200 - High (8.8)
DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91200/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T00:31:21
6 posts
1 repos
A critical Langflow SSRF flaw (CVE-2026-12944) exposes cloud credentials and internal networks. Patch your Langflow OSS servers immediately.
##CVE-2026-12944 (CRITICAL, CVSS 9.6) affects IBM Langflow OSS 1.0.0 – 1.10.0. Attackers can execute arbitrary Python as root via SSRF, steal AWS creds, and move laterally. Patch is available — validate remediation. https://radar.offseq.com/threat/cve-2026-12944-cwe-918-server-side-request-forgery-ssrf-in-ibm-langflow-oss-98110564771040c9 #OffSeq #SSRF #IBM #CloudSecurity
##🔴 CVE-2026-12944 - Critical (9.6)
IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12944/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##A critical Langflow SSRF flaw (CVE-2026-12944) exposes cloud credentials and internal networks. Patch your Langflow OSS servers immediately.
##CVE-2026-12944 (CRITICAL, CVSS 9.6) affects IBM Langflow OSS 1.0.0 – 1.10.0. Attackers can execute arbitrary Python as root via SSRF, steal AWS creds, and move laterally. Patch is available — validate remediation. https://radar.offseq.com/threat/cve-2026-12944-cwe-918-server-side-request-forgery-ssrf-in-ibm-langflow-oss-98110564771040c9 #OffSeq #SSRF #IBM #CloudSecurity
##🔴 CVE-2026-12944 - Critical (9.6)
IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12944/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-15T00:31:13
2 posts
Apple acknowledges fixing the Private Relay bug leaking the IP in the secure release notes of iOS 26.6.1 and macOS 26.6.2.
CVE-2026-65352 was assigned to it
Apple acknowledges fixing the Private Relay bug leaking the IP in the secure release notes of iOS 26.6.1 and macOS 26.6.2.
CVE-2026-65352 was assigned to it
updated 2026-09-14T22:16:59.053000
2 posts
🟠 CVE-2026-91144 - High (7.5)
ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared ba...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91144/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91144 - High (7.5)
ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared ba...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91144/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:32:45
2 posts
Six Apache Syncope vulnerabilities, including CVE-2026-82232, expose severe identity management flaws. Patch your Apache Syncope servers immediately.
#ApacheSyncope #IdentityManagement #CVE202682232 #Cybersecurity #Vulnerability
##Six Apache Syncope vulnerabilities, including CVE-2026-82232, expose severe identity management flaws. Patch your Apache Syncope servers immediately.
#ApacheSyncope #IdentityManagement #CVE202682232 #Cybersecurity #Vulnerability
##updated 2026-09-14T21:31:46
2 posts
🟠 CVE-2026-82028 - High (8.8)
Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82028 - High (8.8)
Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:17:12.520000
2 posts
🔴 CVE-2026-53713 - Critical (9.1)
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53713/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-53713 - Critical (9.1)
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53713/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:10:41.650000
1 posts
🟠 CVE-2026-15891 - High (7.5)
The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15891/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:10:17.423000
1 posts
🔴 CVE-2026-81648 - Critical (10)
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81648/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:10:17.423000
1 posts
🟠 CVE-2026-74933 - High (8.8)
The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74933/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:10:17.423000
1 posts
🟠 CVE-2026-88793 - High (8.8)
The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88793/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:10:17.423000
1 posts
🟠 CVE-2026-86406 - High (7.5)
The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86406/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T21:07:11.883000
2 posts
🟠 CVE-2026-89023 - High (8.6)
ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stor...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89023/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89023 - High (8.6)
ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stor...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89023/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T20:58:48.430000
2 posts
CVE-2026-78330 | CRITICAL: Apache Syncope vuln allows admin escalation if JWKS is exposed and JWT auth used. Affects 3.0.0-M0 – 3.0.16, 4.0.0-M0 – 4.0.7, 4.1.0-M0 – 4.1.2. Upgrade to 4.0.8/4.1.3 to mitigate. Details: https://radar.offseq.com/threat/incorrect-privilege-assignment-vulnerability-in-apache-syncope-cve-2026-78330-b2c023a1d947f76b #OffSeq #Vulnerability #ApacheSyncope
##CVE-2026-78330 | CRITICAL: Apache Syncope vuln allows admin escalation if JWKS is exposed and JWT auth used. Affects 3.0.0-M0 – 3.0.16, 4.0.0-M0 – 4.0.7, 4.1.0-M0 – 4.1.2. Upgrade to 4.0.8/4.1.3 to mitigate. Details: https://radar.offseq.com/threat/incorrect-privilege-assignment-vulnerability-in-apache-syncope-cve-2026-78330-b2c023a1d947f76b #OffSeq #Vulnerability #ApacheSyncope
##updated 2026-09-14T20:56:48.220000
1 posts
🔴 CVE-2026-90680 - Critical (9.9)
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90680/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T20:56:48.220000
2 posts
🔴 CVE-2026-90607 - Critical (9.9)
A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90607/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Totolink A3002MU routers hit by CRITICAL (CVSS 9.4) buffer overflow (CVE-2026-90607) in formNewSchedule. Public exploit code available. Restrict remote access & monitor systems until a patch is released. https://radar.offseq.com/threat/cve-2026-90607-buffer-overflow-in-totolink-a3002mu-f5be31acbfac3e1f #OffSeq #CVE202690607 #RouterSecurity #Infosec
##updated 2026-09-14T20:56:48.220000
1 posts
🟠 CVE-2026-90510 - High (8.3)
A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/drom...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T20:16:50.833000
2 posts
🟠 CVE-2026-73496 - High (7.7)
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlas...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73496/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73496 - High (7.7)
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlas...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73496/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T19:18:14.500000
2 posts
🟠 CVE-2026-91080 - High (7.5)
webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91080/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91080 - High (7.5)
webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91080/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T19:17:37.617000
2 posts
🔴 CVE-2026-59178 - Critical (9.8)
ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59178/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-59178 - Critical (9.8)
ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59178/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T18:31:35
2 posts
🟠 CVE-2026-91079 - High (8.5)
Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91079/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91079 - High (8.5)
Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91079/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T18:31:29
2 posts
🟠 CVE-2026-90946 - High (7.5)
DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90946/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-90946 - High (7.5)
DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90946/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T18:31:29
2 posts
Looks like Microsoft has a couple of new flaws.
NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerabilityhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921
NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerability New https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921 #infosec #Microsoft #vulnerability #Windows
##Looks like Microsoft has a couple of new flaws.
NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerabilityhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921
NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerability New https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921 #infosec #Microsoft #vulnerability #Windows
##updated 2026-09-14T18:31:28
4 posts
🔴 CVE-2026-90945 - Critical (9.8)
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90945/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Go fuck with some crawlers.
https://nvd.nist.gov/vuln/detail/cve-2026-90945
##Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.
🔴 CVE-2026-90945 - Critical (9.8)
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90945/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Go fuck with some crawlers.
https://nvd.nist.gov/vuln/detail/cve-2026-90945
##Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.
updated 2026-09-14T16:17:14.220000
2 posts
🟠 CVE-2026-57129 - High (7.5)
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, or workspac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57129/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-57129 - High (7.5)
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, or workspac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57129/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:33:42
1 posts
🟠 CVE-2026-89746 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix use-after-free with same-name named triggers
When two hist triggers on different events are registered with the same
name=, the second one reuses the first as named...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89746/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:33:39
1 posts
🔴 CVE-2026-89697 - Critical (9.1)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()
The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare()
can inspect the dentry. This ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89697/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:33:29
1 posts
CVE-2026-89461 Linux kernel max17040 power supply race on suspend. Work callback can keep running and requeue itself after suspend, causing use-after-suspend. No CVSS, still unpatched. Update kernel when fix lands. #CVE #Linux https://www.valtersit.com/cve/CVE-2026-89461/
##updated 2026-09-14T15:32:39
1 posts
🟠 CVE-2026-88802 - High (7.5)
The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88802/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:32:39
1 posts
🟠 CVE-2026-85129 - High (8.8)
The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85129/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:32:36
1 posts
🟠 CVE-2026-89736 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: u_audio: Fix use-after-free on sound card disconnect
g_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound
card teardown and immediately frees the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89736/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:32:35
1 posts
🟠 CVE-2026-89706 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: Reset write verifier when async COPY writeback fails
Async COPY captures nn->writeverf at request time and reports it to
the client via CB_OFFLOAD after the worker kthread...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89706/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:32:34
1 posts
🟠 CVE-2026-89684 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix cpntf publish race in nfs4_init_cp_state
nfs4_alloc_init_cpntf_state() published the new cpntf entry into the
s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89684/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T15:32:28
1 posts
CVE-2026-89504 Linux kernel regulator as3722 use-after-free via premature of_node_put, dangling of_node pointer. CVSS N/A, no patch yet. Audit your kernels and apply fixes as soon as they land. https://www.valtersit.com/cve/CVE-2026-89504/ #CVE #Linux #infosec
##updated 2026-09-14T15:32:27
1 posts
CVE-2026-89508 UAF in Linux kernel RDMA/ucma. No CVSS, no patch. Update immediately. https://www.valtersit.com/cve/CVE-2026-89508/ #CVE #Linux #infosec
##updated 2026-09-14T15:32:26
1 posts
CVE-2026-89481 Linux kernel nvme-tcp host memory disclosure: a malicious controller can send an R2T for a READ and the host returns the read buffer, leaking kernel memory. CVSS N/A, patch status unknown. Patch https://www.valtersit.com/cve/CVE-2026-89481/ #CVE #Linux #infosec
##updated 2026-09-14T15:32:24
1 posts
CVE-2026-89458 Linux kernel s390/dasd flaw: failed ESE reads can be marked successful, returning uninitialized data. No CVSS or patch yet. Audit and update s390 systems now. https://www.valtersit.com/cve/CVE-2026-89458/ #CVE #Linux #infosec
##updated 2026-09-14T15:32:22
1 posts
CVE-2026-80979 Linux kernel net/smc: use-after-free via smc_conn_free() when lgr termination races conn teardown. CVSS N/A, no patch confirmed. Verify your kernel build and update immediately. https://www.valtersit.com/cve/CVE-2026-80979/ #CVE #infosec #Linux
##updated 2026-09-14T15:32:07
2 posts
1 repos
🚨 ZcopyReaper (CVE-2026-43502) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
net/rds: handle zerocopy send cleanup before the message is queued
A zerocopy send can fail after user pages have been pinned but before
the message is attached to the sending socket.
The purge path currently infers zerocopy state from rm->m_rs, so an
unqueued message can be cleaned up as if it owned normal payload pages.
However, zerocopy ownership is really determined by the presence of
op_mmp_znotifier, regardless of whether the message has reached the
socket queue.
Capture op_mmp_znotifier up front in rds_message_purge() and use it as
the cleanup discriminator. If the message is already associated with a
socket, keep the existing completion path. Otherwise, drop the pinned
page accounting directly and release the notifier before putting the
payload pages.
This keeps early send failure cleanup consistent with the zerocopy
lifetime rules without changing the normal queued completion path.
ℹ️ Additional information on ZEN SecDB 👉 https://secdb.nttzen.cloud/cve/detail/CVE-2026-43502
#Infosec #ZcopyReaper #Linux #Kernel #LPE #CVE202643502
#NTTData #ZEN #SecDB
🚨 ZcopyReaper (CVE-2026-43502) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
net/rds: handle zerocopy send cleanup before the message is queued
A zerocopy send can fail after user pages have been pinned but before
the message is attached to the sending socket.
The purge path currently infers zerocopy state from rm->m_rs, so an
unqueued message can be cleaned up as if it owned normal payload pages.
However, zerocopy ownership is really determined by the presence of
op_mmp_znotifier, regardless of whether the message has reached the
socket queue.
Capture op_mmp_znotifier up front in rds_message_purge() and use it as
the cleanup discriminator. If the message is already associated with a
socket, keep the existing completion path. Otherwise, drop the pinned
page accounting directly and release the notifier before putting the
payload pages.
This keeps early send failure cleanup consistent with the zerocopy
lifetime rules without changing the normal queued completion path.
ℹ️ Additional information on ZEN SecDB 👉 https://secdb.nttzen.cloud/cve/detail/CVE-2026-43502
#Infosec #ZcopyReaper #Linux #Kernel #LPE #CVE202643502
#NTTData #ZEN #SecDB
updated 2026-09-14T15:17:04.153000
2 posts
Hiperdino REST API v1.0 (CVE-2026-12258) has a CRITICAL info disclosure flaw (CVSS 9.2): attackers with a static bearer token can enumerate user contact info via the 'customer/check' endpoint. No patch yet. Restrict token access & monitor usage. https://radar.offseq.com/threat/cve-2026-12258-cwe-284-improper-access-control-in-hiperdino-rest-api-827f2edf6294f9bd #OffSeq #infosec #APIsecurity
##Hiperdino REST API v1.0 (CVE-2026-12258) has a CRITICAL info disclosure flaw (CVSS 9.2): attackers with a static bearer token can enumerate user contact info via the 'customer/check' endpoint. No patch yet. Restrict token access & monitor usage. https://radar.offseq.com/threat/cve-2026-12258-cwe-284-improper-access-control-in-hiperdino-rest-api-827f2edf6294f9bd #OffSeq #infosec #APIsecurity
##updated 2026-09-14T14:22:15.323000
20 posts
12 repos
https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab
https://github.com/0xenesbayram/cve-2026-85706
https://github.com/brigadeops32/CVE-2026-85706
https://github.com/guneykabel/cve-2026-85706
https://github.com/FlowerWitch/CVE-2026-85706_docker_exp
https://github.com/ynsmroztas/GitLabSniper
https://github.com/gabrielunknown/CVE-2026-85706
https://github.com/plur1bu5/gitread
https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc
https://github.com/gagaltotal/CVE-2026-85706-gitlab-poc
Learn why CISA added GitLab CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Discover how this CVSS 10 flaw allows remote secret extraction.
##Dropped some research and detection/hunt content on CVE-2026-85706 🤓
RE: https://bsky.app/profile/did:plc:lsvsraxh3ckc7frgv5p5d7gy/post/3mvl6a4xflz23
🚨 GitLab CVE-2026-85706 is a critical CVSS 10.0 vulnerability under active exploitation.
Censys sees 86K+ GitLab hosts on the Internet.
Patch immediately. If your instance was exposed while vulnerable, rotate credentials and investigate for compromise. https://censys.com/advisory/cve-2026-85706/
##Comment la faille de GitLab peut mettre à nu vos serveurs https://goodtech.info/gitlab-faille-critique-cve-2026-85706-cisa-cert-fr/ #Développement #Revuedepresse #Sécurité
##🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Maximum Severity GitLab Flaw Puts Supply Chains at Risk
🔗 https://www.darkreading.com/cyberattacks-data-breaches/maximum-severity-gitlab-flaw-supply-chains-risk
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
##⚪️ Developers Urge Immediate Fix for Critical GitLab Vulnerability
🗨️ GitLab engineers have released patches for the critical CVE-2026-85706 vulnerability, which received the maximum CVSS score of 10 and allows an unauthenticated attacker to read arbitrary files on a server. Security researchers warn that attackers began attempting to exploit the…
##CRITICAL CISA KEV ALERT: CVE-2026-85706 targets GitLab CE/EE via path traversal in the repository commits API. Active exploitation verified. Access our TSUITE brief for SIEM detection queries and compensating controls to protect your CI/CD pipeline and isolate your secrets.
##GitLab CVE-2026-85706: A Critical Zero-Authentication Flaw Is Now Being Exploited in the Wild + Video
GitLab CVE-2026-85706: A Critical Zero-Authentication Flaw Is Now Being Exploited in the Wild Introduction: A GitLab Warning That Security Teams Cannot Ignore A critical GitLab vulnerability has rapidly moved from a newly patched security issue to an active exploitation concern. Tracked as CVE-2026-85706, the flaw carries the maximum CVSS score of 10.0 and affects…
##New.
Rapid7: CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild/ @Rapid7Official #infosec #GitLab #vulnerability
##⚠️GitLab : CVE-2026-85706 est activement exploitée.
Une faille critique de traversée de répertoires permet à un attaquant non authentifié de lire des fichiers arbitraires sur le serveur.
Encore une vulnérabilité qui prend des chemins de traverse…
../../../../etc/ :dumpster_fire_gif: 👀
-->GitLab auto-hébergé exposé sur Internet : mise à jour rapide recommandée.
Correctifs : 19.1.8, 19.2.6 et 19.3.2.
La faille a déjà rejoint le catalogue KEV de la CISA, et ça commence clairement à renifler autour : watchTowr et plusieurs honeypots ont déjà vu passer des tentatives de probing.
Onyphe recense une bonne centaine d’instances vulnérables en CH aujourd'hui...
🩹
👇
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
#CVE_2026_85706
https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild/
Learn why CISA added GitLab CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Discover how this CVSS 10 flaw allows remote secret extraction.
##🚨 GitLab CVE-2026-85706 is a critical CVSS 10.0 vulnerability under active exploitation.
Censys sees 86K+ GitLab hosts on the Internet.
Patch immediately. If your instance was exposed while vulnerable, rotate credentials and investigate for compromise. https://censys.com/advisory/cve-2026-85706/
##Comment la faille de GitLab peut mettre à nu vos serveurs https://goodtech.info/gitlab-faille-critique-cve-2026-85706-cisa-cert-fr/ #Développement #Revuedepresse #Sécurité
##⚪️ Developers Urge Immediate Fix for Critical GitLab Vulnerability
🗨️ GitLab engineers have released patches for the critical CVE-2026-85706 vulnerability, which received the maximum CVSS score of 10 and allows an unauthenticated attacker to read arbitrary files on a server. Security researchers warn that attackers began attempting to exploit the…
##CRITICAL CISA KEV ALERT: CVE-2026-85706 targets GitLab CE/EE via path traversal in the repository commits API. Active exploitation verified. Access our TSUITE brief for SIEM detection queries and compensating controls to protect your CI/CD pipeline and isolate your secrets.
##New.
Rapid7: CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild/ @Rapid7Official #infosec #GitLab #vulnerability
##⚠️GitLab : CVE-2026-85706 est activement exploitée.
Une faille critique de traversée de répertoires permet à un attaquant non authentifié de lire des fichiers arbitraires sur le serveur.
Encore une vulnérabilité qui prend des chemins de traverse…
../../../../etc/ :dumpster_fire_gif: 👀
-->GitLab auto-hébergé exposé sur Internet : mise à jour rapide recommandée.
Correctifs : 19.1.8, 19.2.6 et 19.3.2.
La faille a déjà rejoint le catalogue KEV de la CISA, et ça commence clairement à renifler autour : watchTowr et plusieurs honeypots ont déjà vu passer des tentatives de probing.
Onyphe recense une bonne centaine d’instances vulnérables en CH aujourd'hui...
🩹
👇
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
#CVE_2026_85706
https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild/
Recent reports confirm a critical GitLab zero-day (CVE-2026-85706) exploited within 24 hours, alongside new EU Cyber Resilience Act mandates for 24-hour vulnerability reporting. Operational technology (OT) sectors face emerging ransomware threats. Meanwhile, leading AI developers advocate for a slowdown in development due to safety concerns, prompting market shifts. Geopolitically, the BRICS summit addressed rising global tensions and the "weaponization of technology."
##updated 2026-09-14T14:17:08.940000
1 posts
VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure
VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams.
**If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN releases it. Until you've updated, don't open media files, playlists, or RTSP streaming links that come from people or websites you don't know and trust.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/vlc-media-player-flaws-allow-heap-corruption-and-sensitive-data-disclosure-6-k-q-2-9/gD2P6Ple2L
updated 2026-09-14T13:19:23.640000
1 posts
🟠 CVE-2026-89750 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
tracing/user_events: Clear copied tracing state before fork duplication
dup_task_struct() copies user_event_mm from the parent into the child,
without grabbing a reference to it...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89750/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T13:19:23.193000
1 posts
🟠 CVE-2026-89744 - High (8.4)
In the Linux kernel, the following vulnerability has been resolved:
device property: fix infinite loop in fwnode_for_each_child_node()
When iterate over children of a fwnode that has a secondary fwnode,
fwnode_get_next_child_node() can enter an ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89744/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T13:19:20.367000
1 posts
🟠 CVE-2026-89704 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: sample writeback error cursor before async COPY loop
_nfsd_copy_file_range() samples dst->f_wb_err into "since"
after the copy loop, then uses it to detect writeback error...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89704/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T13:19:19.897000
1 posts
🟠 CVE-2026-89696 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return
success with fh_dentry and fh_export bo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89696/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T13:19:05.627000
1 posts
CVE-2026-89488: use-after-free in Linux openvswitch CT limit teardown. Unprivileged user can trigger slab-UAF in ovs_ct_execute(). CVSS N/A, no patch yet. Update immediately. https://www.valtersit.com/cve/CVE-2026-89488/ #CVE #Linux #infosec
##updated 2026-09-14T13:18:52.180000
1 posts
CVE-2026-80973 Linux ALSA 6fire: unvalidated MIDI length byte allows out-of-bounds read. CVSS N/A, patch status unknown. Patch now if you use this driver. https://www.valtersit.com/cve/CVE-2026-80973/ #CVE #Linux #infosec
##updated 2026-09-14T13:18:51.770000
1 posts
CVE-2026-80970 Linux kernel ALSA FCP ioctl leaks uninitialised kmalloc memory to userspace via copy_to_user. Info disclosure, no CVSS or patch yet. Patch or restrict ioctl access. https://www.valtersit.com/cve/CVE-2026-80970/ #CVE #infosec #Linux
##updated 2026-09-14T13:18:49.327000
1 posts
CVE-2026-80931 Linux kernel w1 ds28e17: OOB access via oversize I2C block read length. No CVSS, patch status unknown. Update now. https://www.valtersit.com/cve/CVE-2026-80931/ #CVE #Linux #infosec
##updated 2026-09-14T12:31:50
2 posts
CVE-2026-90919: ModelTC LightLLM <=1.2.0 faces CRITICAL RCE risk. Unauthenticated /visual_register WebSocket lets attackers send malicious pickle data, leading to code execution. Patch or restrict access fast. https://radar.offseq.com/threat/cve-2026-90919-deserialization-of-untrusted-data-in-modeltc-lightllm-99a91583cd9500c2 #OffSeq #CVE202690919 #RCE #LightLLM
##CVE-2026-90919: ModelTC LightLLM <=1.2.0 faces CRITICAL RCE risk. Unauthenticated /visual_register WebSocket lets attackers send malicious pickle data, leading to code execution. Patch or restrict access fast. https://radar.offseq.com/threat/cve-2026-90919-deserialization-of-untrusted-data-in-modeltc-lightllm-99a91583cd9500c2 #OffSeq #CVE202690919 #RCE #LightLLM
##updated 2026-09-14T11:17:02.930000
3 posts
Logitech Options+ : une faille donne les privilèges SYSTEM à n’importe quel utilisateur Windows https://www.it-connect.fr/logitech-options-plus-faille-system-cve-2026-12518/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##📢 [VULN] Logitech Options+ : une faille donne les privilèges SYSTEM à n’importe quel utilisateur Windows - CVE-2026-12518
C'est un simple logiciel destiné à configurer une souris ou un clavier, et pourtant Logitech Options+ contient une faille de sécurité permettant d'obtenir les privilèges SYSTEM sur Windows. Voici ce que l'on sait sur ce problème de sécurité.
🔗 https://www.it-connect.fr/logitech-options-plus-faille-system-cve-2026-12518/
💬 discussion : https://infosec.pub/post/52323085
#Vulnérabilité #CVE #Cyberveille
Logitech Options+ : une faille donne les privilèges SYSTEM à n’importe quel utilisateur Windows https://www.it-connect.fr/logitech-options-plus-faille-system-cve-2026-12518/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##updated 2026-09-14T03:30:29
2 posts
🔴 CVE-2026-90608 - Critical (9.9)
A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90608/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-90608: Totolink A3002MU routers have a CRITICAL buffer overflow (CVSS 9.4) in /boafrm/formPortFw. Exploit code is public; RCE possible. No patch — restrict external access & monitor vendor updates. https://radar.offseq.com/threat/cve-2026-90608-buffer-overflow-in-totolink-a3002mu-43328ea907451224 #OffSeq #CVE202690608 #RouterSecurity
##updated 2026-09-14T03:30:29
1 posts
🟠 CVE-2026-33963 - High (7.5)
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-33963/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T03:30:22
2 posts
1 repos
🟠 New security advisory:
CVE-2026-31278 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-31278-biostar-2-leaks-ad-service-credentials-poc
by Yazoul AI
##🟠 CVE-2026-31278 - High (7.7)
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-31278/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T02:17:13.397000
1 posts
🟠 CVE-2026-23789 - High (7.8)
An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-23789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T00:31:35
1 posts
🔴 CVE-2026-90605 - Critical (9.9)
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overf...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90605/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-14T00:16:56.777000
1 posts
2 repos
PaperCut Attacker (Russian Linked) Uses AI Agents to Compromise 440 Instances
러시아어권으로 추정되는 공격자가 PaperCut NG/MF의 인증 우회·RCE 체인(CVE-2026-81578, CVE-2026-82078)을 악용해 48개국 395개 조직의 최소 440개 인스턴스를 침해한 것으로 보고됐다. 공격자는 OpenAI Codex, DeepSeek 모델, Hindsight의 지속 메모리, AionUi 멀티 에이전트 작업 공간을 결합해 취약점 분석부터 익스플로잇 수정, 표적 분류, 재시도, AD 정찰까지 자동화했으며, 실제 공격 개시 후 2...
https://www.swapupdate.in/papercut-attacker-uses-hundreds-of-ai-agents-to-compromise-440-instances/
##updated 2026-09-13T21:31:54
1 posts
🟠 CVE-2026-37008 - High (8.1)
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete obj...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-37008/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T21:31:53
1 posts
🟠 CVE-2026-29811 - High (7.7)
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-29811/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T15:30:28
1 posts
🟠 CVE-2026-90783 - High (7.8)
MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an unde...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T12:31:19
1 posts
CVE-2026-90775: HIGH severity vuln in PostGIS address_standardizer (≤3.7.0) allows out-of-bounds read via unvalidated Weight parameter, crashing PostgreSQL backend (DoS). Patch status pending — monitor vendor updates. https://radar.offseq.com/threat/cve-2026-90775-out-of-bounds-read-in-postgis-addressstandardizer-b09887107f7082c5 #OffSeq #PostGIS #Vuln
##updated 2026-09-13T12:31:19
1 posts
🟠 CVE-2026-90779 - High (7.5)
SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90779/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T12:31:11
1 posts
Strapi 4.x – 4.26.2 & 5.x<5.48.1: CRITICAL stored XSS (CVE-2026-90561, CVSS 8.7) in WYSIWYG preview lets Author roles execute malicious scripts in higher-privileged sessions. Restrict roles & monitor vendor updates. https://radar.offseq.com/threat/strapi-versions-4x-through-4262-and-5x-before-5481-contain-a-stored-cross-site-scripting-vulnerability-e05bee9fce842336 #OffSeq #Strapi #XSS #Infosec
##updated 2026-09-13T12:31:10
1 posts
🟠 CVE-2026-89080 - High (7.5)
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the sec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89080/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T11:17:00.780000
1 posts
🟠 CVE-2026-90562 - High (8.1)
LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90562/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:34
1 posts
🟠 CVE-2026-89690 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: defer vfree of compound ops to fix rpc_status UAF
The rpc_status netlink dumpit walks every in-flight svc_rqst under
rcu_read_lock and, for NFSv4 requests, reads opnums ou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89690/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:31
1 posts
🔴 CVE-2026-89688 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
In nfs4_preprocess_seqid_op() the stateid is obtained from
nfsd4_lookup_stateid(), which holds a reference o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89688/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:31
1 posts
🔴 CVE-2026-89611 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
ntfs: validate non-resident attribute offsets
ntfs_attr_update_meta() shifts the attribute name when converting between
non-sparse and sparse attributes. Converting to sparse al...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89611/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:31
1 posts
🟠 CVE-2026-89695 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: cap decoded POSIX ACL count to bound sort cost
nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes
it straight to posix_acl_alloc() and sort_pacl_range...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:30
1 posts
🔴 CVE-2026-89689 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: don't free session slots that are still in use
nfsd4_sequence() can free the very slot it is currently processing.
When the session shrinker has reduced se_target_maxslots...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89689/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:33:28
1 posts
CVE-2026-89521 Linux kernel core scheduling race: pick_task() can release the rq lock, invalidating selection state and committing uncookied picks. No CVSS, no patch yet. Track it and update as soon as fixes land. https://www.valtersit.com/cve/CVE-2026-89521/ #CVE #Linux #infosec
##updated 2026-09-13T09:33:25
1 posts
CVE-2026-80981 Linux kernel use-after-free in net/smc smc_llc_srv_add_link. CVSS N/A, patch status unknown. Update your kernel now. https://www.valtersit.com/cve/CVE-2026-80981/ #CVE #infosec #Linux
##updated 2026-09-13T09:33:21
2 posts
CVE-2026-81006 Linux kernel ipmi: failed registration leaves sysfs files on freed memory, risking use-after-free. CVSS N/A, patch status unknown. Update your kernel now. https://www.valtersit.com/cve/CVE-2026-81006/ #CVE #Linux #infosec
##CVE-2026-81006 Linux kernel ipmi: failed registration leaves sysfs files on freed memory, risking use-after-free. CVSS N/A, patch status unknown. Update your kernel now. https://www.valtersit.com/cve/CVE-2026-81006/ #CVE #Linux #infosec
##updated 2026-09-13T09:33:21
1 posts
CVE-2026-80980 Linux kernel net/smc bitfield race - killed, freed, out_of_sync share one byte without a common lock, a data race that can corrupt connection state. CVSS N/A, patch status unknown/unpatched. Audit https://www.valtersit.com/cve/CVE-2026-80980/ #CVE #Linux #infosec
##updated 2026-09-13T09:32:30
1 posts
🟠 CVE-2026-89748 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix retry exhaustion in simple ring buffer reader swap
simple_ring_buffer_swap_reader_page() starts with retry set to 8 and
post-decrements it only after a failed link ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89748/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:32:30
1 posts
🟠 CVE-2026-89758 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
mm/mempolicy: skip non-present PMDs when queueing folios
Patch series "mm: handle device-private PMDs in walk callbacks", v3.
Since commit 368076f52ebe ("mm/huge_memory: add de...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89758/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:32:28
1 posts
🔴 CVE-2026-89686 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke
nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding
fi_lock when the parent stateid is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89686/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:32:28
1 posts
🟠 CVE-2026-89685 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix clock domain mismatch in clients_still_reclaiming()
clients_still_reclaiming() computes a deadline from nn->boot_time
(CLOCK_REALTIME, ~1.7 billion) but compares it ag...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89685/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T09:32:12
1 posts
CVE-2026-80947 Linux kernel rtl8xxxu wifi driver use-after-free on stop, triggered via RX path. CVSS N/A, no patch yet. Update your kernel now. https://www.valtersit.com/cve/CVE-2026-80947/ #CVE #Linux #infosec
##updated 2026-09-13T07:17:39.363000
1 posts
🟠 CVE-2026-89747 - High (7.8)
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
Writing to buffer_subbuf_size_kb calls ring_buffer_subbuf_order_set(),
which frees every sub-buffer of ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89747/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T07:17:35.107000
1 posts
🟠 CVE-2026-89692 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: clear CALLBACK_RUNNING on failed delegation recall queue
nfsd_break_one_deleg() sets NFSD4_CALLBACK_RUNNING via test_and_set_bit
at entry to serialize recall work, then ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89692/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T07:17:34.493000
1 posts
🟠 CVE-2026-89687 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file
->atomic_open is permitted to return success without actually opening
the file. It indicates this by calling ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89687/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T07:17:34.003000
1 posts
🟠 CVE-2026-89682 - High (8.1)
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net
nfsd_file_dispose_list_delayed() defers fput() to nfsd service threads
via a per-net freeme queue, preventi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89682/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T07:17:26.840000
1 posts
🔴 CVE-2026-89613 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
ntfs: reject invalid empty mapping pairs
Reject an attribute with empty mapping pairs if it has inconsistent
highest VCN and size.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89613/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T07:17:26.730000
1 posts
🔴 CVE-2026-89612 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
ntfs: reject invalid MFT LCNs from boot sector
The NTFS boot sector stores the MFT and MFTMirr locations as unsigned
64-bit LCNs, but parse_ntfs_boot_sector() decoded them into ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89612/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-13T07:17:13.333000
1 posts
CVE-2026-89501 Linux kernel ring-buffer race on subbuf resize, unpatched, CVSS N/A. Update immediately. https://www.valtersit.com/cve/CVE-2026-89501/ #CVE #Linux #infosec
##updated 2026-09-13T07:17:13.100000
1 posts
CVE-2026-89499 Linux kernel ring-buffer flaw: failed remote page swap corrupts reader state, risking kernel crash or memory corruption during event storms. No CVSS or patch yet. Track it and apply updates as https://www.valtersit.com/cve/CVE-2026-89499/ #CVE #Linux #infosec
##updated 2026-09-13T07:17:09.350000
1 posts
CVE-2026-89450 Linux kernel iommu/tegra241-cmdqv: vSID wider than SID_MATCH field bypasses bound check, dropping bits above 20. CVSS N/A, unpatched. Update immediately. https://www.valtersit.com/cve/CVE-2026-89450/ #CVE #Linux #infosec
##updated 2026-09-13T07:17:06.230000
1 posts
CVE-2026-80995 Linux kernel use-after-free in mctp_route_lookup can crash systems, possibly worse. No CVSS, no patch yet. Track it and update the moment a fix lands. https://www.valtersit.com/cve/CVE-2026-80995/ #CVE #Linux #infosec
##updated 2026-09-13T07:17:01.293000
1 posts
CVE-2026-80936 Linux mt76 mt7925: uncancelled mlo_pm_work fires after teardown, causing a use-after-free-style workqueue warning and kernel crash risk. CVSS N/A, unpatched - update your kernel now. https://www.valtersit.com/cve/CVE-2026-80936/ #CVE #Linux #infosec
##updated 2026-09-11T21:31:37
1 posts
CVE-2026-89517 Linux kernel: sched_ext rq->core_pick corruption under core scheduling. CVSS N/A, patch status unknown. Kernel memory corruption risk. Patch now if a fix lands. https://www.valtersit.com/cve/CVE-2026-89517/ #CVE #Linux #infosec
##updated 2026-09-11T21:31:32
1 posts
CVE-2026-81911 Concrete CMS 9.0.0-9.5.2 Stored XSS via the custom_slot save_template endpoint. No CVSS assigned and no patch available, so treat as unpatched. Restrict board edit permissions and sanitize https://www.valtersit.com/cve/CVE-2026-81911/ #CVE #infosec #ConcreteCMS
##updated 2026-09-11T21:31:32
1 posts
CVE-2026-89447 Linux kernel iommufd flaw: internal accesses skip the matching put during unmap, risking a refcount/lock imbalance. No CVSS yet, patch status unknown. Patch or update now. https://www.valtersit.com/cve/CVE-2026-89447/ #CVE #Linux #infosec
##updated 2026-09-11T21:31:19
1 posts
CVE-2026-80927: Linux kernel timekeeping race leaks uninitialized stack data to userspace. CVSS N/A, patch status unknown. Update your kernel now. https://www.valtersit.com/cve/CVE-2026-80927/ #CVE #infosec #LinuxKernel
##updated 2026-09-11T21:31:17
9 posts
ConnectWise Patches Critical ScreenConnect Flaw Exploited in Worm Attacks
ConnectWise fixed a critical vulnerability (CVE-2026-84869) in ScreenConnect that allows unauthorized file execution and worm-like propagation across remote sessions.
**If you use ConnectWise ScreenConnect, update to version 26.6.5 right away and then reinstall every host client. The update only takes effect once the clients are reinstalled, and this flaw is already being exploited to spread from machine to machine. If you can't patch, turn off the TransferFiles permission for all user roles as a mitigating measures. Don't forget to check integrated tools like ConnectWise Automate for their own patched versions.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/connectwise-patches-critical-screenconnect-flaw-exploited-in-worm-attacks-n-t-h-f-x/gD2P6Ple2L
🏆 New Achievement! The Help Desk Has Turned Against You!
PHASE ONE: ConnectWise ScreenConnect, your trusted remote support companion, enters the arena. PHASE TWO: CVE-2026-84869 awakens — CVSS 9.9, the kind of score that makes sysadmins physically leave their bodies. PHASE THREE: the worm-like propagation begins, chaining active remote sessions into unauthorized file transfers and full remote code execution. Huntress confirmed real-world exploitation. (1/2)
##ConnectWise ScreenConnect Flaw Turns Remote Support Into a Worm-Like Attack Engine + Video
A Critical Vulnerability With a Dangerous Twist ConnectWise has rushed out an emergency security update for its ScreenConnect remote access and support platform after a critical vulnerability was exploited in real-world attacks. Tracked as CVE-2026-84869 and rated 9.9 out of 10, the flaw is particularly dangerous because attackers can potentially abuse an active remote session to…
##CRITICAL CISA KEV ALERT: CVE-2026-84869 targets ConnectWise ScreenConnect with unauthorized file transfer and RCE. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to protect your environment. https://thecybermind.co/g5ob
##ConnectWise Patches Critical ScreenConnect Flaw Exploited in Worm Attacks
ConnectWise fixed a critical vulnerability (CVE-2026-84869) in ScreenConnect that allows unauthorized file execution and worm-like propagation across remote sessions.
**If you use ConnectWise ScreenConnect, update to version 26.6.5 right away and then reinstall every host client. The update only takes effect once the clients are reinstalled, and this flaw is already being exploited to spread from machine to machine. If you can't patch, turn off the TransferFiles permission for all user roles as a mitigating measures. Don't forget to check integrated tools like ConnectWise Automate for their own patched versions.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/connectwise-patches-critical-screenconnect-flaw-exploited-in-worm-attacks-n-t-h-f-x/gD2P6Ple2L
🏆 New Achievement! The Help Desk Has Turned Against You!
PHASE ONE: ConnectWise ScreenConnect, your trusted remote support companion, enters the arena. PHASE TWO: CVE-2026-84869 awakens — CVSS 9.9, the kind of score that makes sysadmins physically leave their bodies. PHASE THREE: the worm-like propagation begins, chaining active remote sessions into unauthorized file transfers and full remote code execution. Huntress confirmed real-world exploitation. (1/2)
##CRITICAL CISA KEV ALERT: CVE-2026-84869 targets ConnectWise ScreenConnect with unauthorized file transfer and RCE. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to protect your environment. https://thecybermind.co/g5ob
##ConnectWise patched CVE-2026-84869, a critical ScreenConnect authorization flaw allowing file transfer and execution via active sessions. Huntress reports worm-like exploitation since August 20. It enables lateral spread without host confirmation, requiring immediate patching and session review. #ScreenConnect #CyberSecurity #InfoSec
https://cyberworldops.eu/en/critical-screenconnect-flaw-fuels-worm-like-attacks-through-active
##ConnectWise ScreenConnect CRITICAL vuln (CVE-2026-84869) exploited in worm-like attacks — unauthorized file transfer & execution via remote sessions in versions <26.6.5. Patch to 26.6.5 now or disable TransferFiles. https://radar.offseq.com/threat/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks-c3e27ae69aeeacb1 #OffSeq #Cybersecurity #Vuln #CISA
##updated 2026-09-11T21:31:06
3 posts
CRITICAL CISA KEV ALERT: CVE-2026-42016 targets JFrog Artifactory via incorrect authorization and token scope flaws. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to secure your software pipelines.
##📢 Exploitation active de trois vulnérabilités critiques dans JFrog Artifactory
🔍 Contexte : Le 10 septembre 2026, Wiz Research publie une analyse technique détaillant l'exploitation active en conditions réelles de trois vulnérabilités critiques et de haute sévérité affectant JFrog Artifactory.
📖 cyberveille : https://cyberveille.ch/posts/2026-09-14-exploitation-active-de-trois-vulnerabilites-critiques-dans-jfrog-artifactory/
🌐 source : https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201
🟢 vérification factuelle haute
#JFrogArtifactory #ExploitationActive #Cyberveille
CRITICAL CISA KEV ALERT: CVE-2026-42016 targets JFrog Artifactory via incorrect authorization and token scope flaws. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to secure your software pipelines.
##updated 2026-09-11T20:36:20
2 posts
🔴 CVE-2026-59971 - Critical (10)
MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59971/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-59971 - Critical (10)
MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59971/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T20:19:13.263000
2 posts
1 repos
https://github.com/abhinavagarwal07/scadapack-secure-lock-poc
Schneider Electric disclosed CVE-2026-81861 (CWE-522) affecting SCADAPack x70 RTUs. Legacy Secure Lock insufficiently protects credentials, exposing RTU authentication data. Exposed credentials matter for OT as they can enable unauthorized access to monitoring and control functions. #IcsSecurity #ScadaSecurity #OtSecurity
https://cyberworldops.eu/en/schneider-electric-scadapack-credential-flaw-exposes-rtu
##Schneider Electric disclosed CVE-2026-81861 (CWE-522) affecting SCADAPack x70 RTUs. Legacy Secure Lock insufficiently protects credentials, exposing RTU authentication data. Exposed credentials matter for OT as they can enable unauthorized access to monitoring and control functions. #IcsSecurity #ScadaSecurity #OtSecurity
https://cyberworldops.eu/en/schneider-electric-scadapack-credential-flaw-exposes-rtu
##updated 2026-09-11T20:19:10.813000
1 posts
CVE-2026-81018 Linux kernel think-lmi driver leaks system certificate signatures on removal. Memory leak only, CVSS not assigned, no patch. Track status and apply fixes when available: https://www.valtersit.com/cve/CVE-2026-81018/ #CVE #Linux #infosec
##updated 2026-09-11T20:19:03.623000
1 posts
CVE-2026-80974 Linux kernel sm501 mfd driver leaks memory on device removal. No CVSS assigned, patch status unknown. Update your kernel when a fix lands. Details: https://www.valtersit.com/cve/CVE-2026-80974/ #CVE #Linux #infosec
##updated 2026-09-11T20:19:01.863000
1 posts
CVE-2026-80960 Linux kernel dm-pcache out-of-bounds access via unchecked seg_num from on-media superblock. Can lead to memory corruption. CVSS N/A, patch status unknown. Patch now if you use dm-pcache. https://www.valtersit.com/cve/CVE-2026-80960/ #CVE #Linux #infosec
##updated 2026-09-11T17:35:21.440000
1 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-11T15:21:12.850000
1 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-11T15:17:06.937000
1 posts
Orthanc DICOM Server is affected by CVE-2026-87020, an integer overflow in image pitch calculation enabling authenticated heap out-of-bounds write via malicious PNG. It matters for clinical environments where exploitation risks service disruption and imaging integrity. #OrthancServer #DicomSecurity #HeapCorruption
https://cyberworldops.eu/en/orthanc-dicom-server-flaw-allows-authenticated-attackers-to-corrupt
##updated 2026-09-11T12:52:16.507000
2 posts
1 repos
CRITICAL CISA KEV ALERT: CVE-2026-86060 targets MikroTik RouterOS via improper argument delimiter neutralization and command injection. Active exploitation verified. Access our TSUITE brief for hardening steps and network segmentation protocols to secure your perimeter.
##CRITICAL CISA KEV ALERT: CVE-2026-86060 targets MikroTik RouterOS via improper argument delimiter neutralization and command injection. Active exploitation verified. Access our TSUITE brief for hardening steps and network segmentation protocols to secure your perimeter.
##updated 2026-09-11T03:31:25
2 posts
Discover the dangerous Nintendo Switch QR code vulnerability (CVE-2026-82079) allowing hackers to execute code. Learn how system update 23.0.0 fixes it.
#NintendoSwitch #CyberSecurity #CVE202682079 #QRCode #Vulnerability
##Discover the dangerous Nintendo Switch QR code vulnerability (CVE-2026-82079) allowing hackers to execute code. Learn how system update 23.0.0 fixes it.
#NintendoSwitch #CyberSecurity #CVE202682079 #QRCode #Vulnerability
##updated 2026-09-10T19:54:25.810000
1 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-10T18:33:04
1 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-10T18:33:03
1 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-10T12:48:17.580000
1 posts
3 repos
https://github.com/DiegoArias008/CVE-2026-20079-checker
🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The vulnerability…
Also tracked this week: Hackers exploit Sangoma Switchvox flaw to deploy reverse… · Microsoft Plugs Nearly 1,000…
##updated 2026-09-10T12:47:59.933000
1 posts
Discover how the PivotC2 FortiGate RAT uses CVE-2025-25249 exploitation to harvest credentials and tunnel traffic across corporate network environments.
#PivotC2 #FortiGate #Malware #Cybercrime #CVE202525249
http://securityonline.info/pivotc2-fortigate-rat/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-09-10T04:18:18.390000
2 posts
⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…
🤖 AI generated summary
##https://thecybersecguru.com/news/check-point-vpn-cve-2026-85102-cve-2026-85103/
##updated 2026-09-09T21:31:35
1 posts
2 repos
https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter
BlueMoon chain: CVE-2026-85046 for arbitrary read/write in the Chrome V8 sandbox, CVE-2026-87491 to escape the browser sandbox, CVE-2026-85880 (Windows ALPC) to inject into the Chrome process. Delivery: reflected XSS on a...
##updated 2026-09-09T16:17:03.483000
2 posts
Siemens patched CVE-2026-58113, a reflected XSS (CWE-79) in Teamcenter /auth/ redirect flow. An unauthenticated attacker can craft a URL executing JavaScript in an authenticated user's session. Update all four affected branches. #SiemensTeamcenter #CrossSiteScripting #PatchManagement
https://cyberworldops.eu/en/siemens-patches-teamcenter-authentication-redirect-xss-across-four
##Siemens patched CVE-2026-58113, a reflected XSS (CWE-79) in Teamcenter /auth/ redirect flow. An unauthenticated attacker can craft a URL executing JavaScript in an authenticated user's session. Update all four affected branches. #SiemensTeamcenter #CrossSiteScripting #PatchManagement
https://cyberworldops.eu/en/siemens-patches-teamcenter-authentication-redirect-xss-across-four
##updated 2026-09-09T15:37:49.157000
2 posts
CVE-2026-87827 (CVSS 10) is a KGUARD DVR vulnerability exploited by the Mirai botnet for unauthenticated RCE and complete device compromise.
#KGUARD #DVR #CVE202687827 #Mirai #Botnet #IoTSecurity #RCE #DDoS #ExploitedInTheWild #InfoSec
##CVE-2026-87827 (CVSS 10) is a KGUARD DVR vulnerability exploited by the Mirai botnet for unauthenticated RCE and complete device compromise.
#KGUARD #DVR #CVE202687827 #Mirai #Botnet #IoTSecurity #RCE #DDoS #ExploitedInTheWild #InfoSec
##updated 2026-09-09T15:35:15
2 posts
⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…
🤖 AI generated summary
##https://thecybersecguru.com/news/check-point-vpn-cve-2026-85102-cve-2026-85103/
##updated 2026-09-09T15:35:15
1 posts
VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure
VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams.
**If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN releases it. Until you've updated, don't open media files, playlists, or RTSP streaming links that come from people or websites you don't know and trust.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/vlc-media-player-flaws-allow-heap-corruption-and-sensitive-data-disclosure-6-k-q-2-9/gD2P6Ple2L
updated 2026-09-09T05:18:19.490000
1 posts
3 repos
https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit
CVE-2026-86218, a CVSS 10 N-central vulnerability, is exploited in the wild for remote code execution. A public Metasploit PoC is out. Patch now.
##updated 2026-09-09T05:18:19.193000
3 posts
BlueMoon chain: CVE-2026-85046 for arbitrary read/write in the Chrome V8 sandbox, CVE-2026-87491 to escape the browser sandbox, CVE-2026-85880 (Windows ALPC) to inject into the Chrome process. Delivery: reflected XSS on a...
##Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.
##Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.
##updated 2026-09-09T05:18:17.173000
2 posts
Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.
##Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.
##updated 2026-09-09T05:18:07.237000
3 posts
5 repos
https://github.com/dinosn/cve-2026-75650-magento-validation-lab
https://github.com/disrex-group/stylesmuggler-adobe-patches
https://github.com/fortbridge/stylesmuggler
https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos
https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit
CVE-2026-75650: StyleSmuggler — Critical RCE in Adobe Commerce and Magento
#CVE_2026_75650 #AdobeCommerce
https://www.akamai.com/blog/security-research/2026/sep/cve-2026-75650-stylesmuggler-adobe-commerce-magento
CVE-2026-75650: StyleSmuggler — Critical RCE in Adobe Commerce and Magento
#CVE_2026_75650 #AdobeCommerce
https://www.akamai.com/blog/security-research/2026/sep/cve-2026-75650-stylesmuggler-adobe-commerce-magento
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-08T15:32:04
1 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-08T15:32:04
1 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-08T14:17:29.160000
1 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-08T13:12:58.310000
2 posts
WooCommerce CVE-2026-48888 is a high-severity flaw an attacker can exploit with no account and no elevated permissions. If my clients have not updated to 11.1.0, their customer data and payment layer are exposed right now. I recommend updating immediately.
#WordPress #WooCommerce #CVE #SecurityHardening #WordPressSecurity
https://wpguy.uk/blog/woocommerce-cve-2026-48888-update-to-1110-now/
##WooCommerce CVE-2026-48888 is a high-severity flaw an attacker can exploit with no account and no elevated permissions. If my clients have not updated to 11.1.0, their customer data and payment layer are exposed right now. I recommend updating immediately.
#WordPress #WooCommerce #CVE #SecurityHardening #WordPressSecurity
https://wpguy.uk/blog/woocommerce-cve-2026-48888-update-to-1110-now/
##updated 2026-09-07T15:34:02
1 posts
📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301
Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405
CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105
Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566
Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)
updated 2026-09-06T03:30:24
1 posts
8 repos
https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter
https://github.com/adriyansyah-mf/cve-2026-85046-poc
https://github.com/Eliot-code/CVE-2026-85046
https://github.com/atiilla/CVE-2026-85046
https://github.com/SneakyNachos/CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm
BlueMoon chain: CVE-2026-85046 for arbitrary read/write in the Chrome V8 sandbox, CVE-2026-87491 to escape the browser sandbox, CVE-2026-85880 (Windows ALPC) to inject into the Chrome process. Delivery: reflected XSS on a...
##updated 2026-09-04T17:17:00.390000
1 posts
🐧 SIGINT // Ubuntu Watch — 2026-09-16
Another kernel CVE patched upstream and in Ubuntu. If you run your own kernel builds or LTS HWE stacks, check this against your running version before your next reboot window.
##updated 2026-09-03T13:06:16.053000
1 posts
3 repos
https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis
📢 SonicWall SMA1000 : module Metasploit pour chaîne RCE non authentifiée (CVE-2026-83548 + CVE-2026-83549)
Ce pull request Metasploit (PR #21883) documente l'intégration d'un module d'exploitation complet pour une chaîne de vulnérabilités zero-day affectant les appliances SonicWall Secure Mobile Access 1000 (SMA1000), divulguée début septembre 2026 comme…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-14-sonicwall-sma1000-module-metasploit-pour-chaine-rce-non-authentifiee-cve-2026-83548-cve-2026-83549/
🌐 source : https://github.com/rapid7/metasploit-framework/pull/21883
🟡 vérification factuelle moyenne
#Metasploit #RCE #Cyberveille
updated 2026-09-02T18:32:06
1 posts
2 repos
📢 SonicWall SMA1000 : module Metasploit pour chaîne RCE non authentifiée (CVE-2026-83548 + CVE-2026-83549)
Ce pull request Metasploit (PR #21883) documente l'intégration d'un module d'exploitation complet pour une chaîne de vulnérabilités zero-day affectant les appliances SonicWall Secure Mobile Access 1000 (SMA1000), divulguée début septembre 2026 comme…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-14-sonicwall-sma1000-module-metasploit-pour-chaine-rce-non-authentifiee-cve-2026-83548-cve-2026-83549/
🌐 source : https://github.com/rapid7/metasploit-framework/pull/21883
🟡 vérification factuelle moyenne
#Metasploit #RCE #Cyberveille
updated 2026-09-01T20:56:59.203000
2 posts
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
updated 2026-09-01T20:56:59.203000
2 posts
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
updated 2026-08-31T21:31:56
1 posts
2 repos
PaperCut Attacker (Russian Linked) Uses AI Agents to Compromise 440 Instances
러시아어권으로 추정되는 공격자가 PaperCut NG/MF의 인증 우회·RCE 체인(CVE-2026-81578, CVE-2026-82078)을 악용해 48개국 395개 조직의 최소 440개 인스턴스를 침해한 것으로 보고됐다. 공격자는 OpenAI Codex, DeepSeek 모델, Hindsight의 지속 메모리, AionUi 멀티 에이전트 작업 공간을 결합해 취약점 분석부터 익스플로잇 수정, 표적 분류, 재시도, AD 정찰까지 자동화했으며, 실제 공격 개시 후 2...
https://www.swapupdate.in/papercut-attacker-uses-hundreds-of-ai-agents-to-compromise-440-instances/
##updated 2026-08-29T15:30:20
2 posts
A critical Shinobi vulnerability (CVE-2026-82448) uses a hardcoded child node key to reach the camera database unauthenticated. Patch and lock port 8288.
#Shinobi #CVE202682448 #CCTV #Vulnerability #HardcodedKey #CyberSecurity #InfoSec
##A critical Shinobi vulnerability (CVE-2026-82448) uses a hardcoded child node key to reach the camera database unauthenticated. Patch and lock port 8288.
#Shinobi #CVE202682448 #CCTV #Vulnerability #HardcodedKey #CyberSecurity #InfoSec
##updated 2026-08-27T12:30:27
2 posts
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
updated 2026-08-27T12:30:27
2 posts
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
updated 2026-08-27T12:30:27
2 posts
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
🔒 New CSAF advisory published
VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576
The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…
HTML: https://certvde.com/en/advisories/VDE-2026-091
CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json
updated 2026-08-27T11:41:19.230000
6 posts
10 repos
https://github.com/imbas007/CVE-2026-60004-POC
https://github.com/HORKimhab/CVE-2026-60004
https://github.com/shinthink/CVE-2026-60004
https://github.com/fevar54/cve-2026-60004
https://github.com/Sachinart/CVE-2026-60004-gitea-0day
https://github.com/gagaltotal/CVE-2026-60004-poc-gitea
https://github.com/erberkan/CVE-2026-60004-PoC
https://github.com/HackSpeak/CVE-2026-60004
Acronis TRU uncovered a multinational campaign in which Red Heron, a Chinese-speaking threat actor, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/
##Red Heron exploited CVE-2026-60004, a critical Gitea RCE, to compromise 13 organizations after scanning 1,386 exposed instances. Exposed dev platforms offer direct access to code and lateral movement. Patch, restrict exposure and review logs. #GiteaSecurity #ThreatIntel #SupplyChain
https://cyberworldops.eu/en/red-heron-exploits-critical-gitea-rce-to-breach-13-organizations
##⚪️ Over 8,300 Gitea Servers Vulnerable to Remote Code Execution
🗨️ Researchers at The Shadowserver Foundation warn that more than 8,300 internet-exposed Gitea instances remain unprotected against the critical CVE-2026-60004 vulnerability. The flaw is already being exploited in real-world attacks and allows arbitrary commands to be executed on vulnerable servers.…
##Acronis TRU uncovered a multinational campaign in which Red Heron, a Chinese-speaking threat actor, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/
##Red Heron exploited CVE-2026-60004, a critical Gitea RCE, to compromise 13 organizations after scanning 1,386 exposed instances. Exposed dev platforms offer direct access to code and lateral movement. Patch, restrict exposure and review logs. #GiteaSecurity #ThreatIntel #SupplyChain
https://cyberworldops.eu/en/red-heron-exploits-critical-gitea-rce-to-breach-13-organizations
##⚪️ Over 8,300 Gitea Servers Vulnerable to Remote Code Execution
🗨️ Researchers at The Shadowserver Foundation warn that more than 8,300 internet-exposed Gitea instances remain unprotected against the critical CVE-2026-60004 vulnerability. The flaw is already being exploited in real-world attacks and allows arbitrary commands to be executed on vulnerable servers.…
##updated 2026-08-26T20:48:48
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-08-18T18:32:52
2 posts
2 repos
CISA Warns VMware vCenter Flaw Is Now in the Hands of Ransomware Gangs + Video
CISA Warns VMware vCenter Flaw Is Now in the Hands of Ransomware Gangs A Critical VMware Vulnerability Has Entered a More Dangerous Phase A critical vulnerability in VMware vCenter Server has moved from a serious patching concern to an active ransomware threat. CISA has warned that ransomware operators are now exploiting CVE-2026-59310, a critical directory-traversal vulnerability that can…
##Ransomware gangs exploit VMware flaw
Ransomware gangs are actively exploiting a critical VMware flaw, CVE-2026-59310, that was patched just two weeks ago, putting organizations at risk of devastating attacks. The US Cybersecurity and Infrastructure Security Agency has warned of the vulnerability, which allows unauthenticated attackers to execute arbitrary code.
https://osintsights.com/ransomware-gangs-exploit-vmware-flaw?utm_source=mastodon&utm_medium=social
#VmwareFlaw #Ransomware #Cve202659310 #EmergingThreats #SupplyChain
##updated 2026-08-12T15:18:30.347000
1 posts
9 repos
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
https://github.com/codeb0ssx/CVE-2026-72898-PoC
https://github.com/EQSTLab/CVE-2026-72898
https://github.com/0xBlackash/CVE-2026-72898
https://github.com/4minx/CVE-2026-72898
https://github.com/34zY/CVE-2026-72898
https://github.com/Franc-Zar/CVE-2026-72898-safe-detection
https://github.com/d-maggipinto/CVE-2026-72898-metabase-sqli
📰 Mathspace Breach Affects 1M Users via Metabase Flaw
Education platform Mathspace discloses a data breach affecting over 1 million users. Attackers exploited a known SQL injection flaw (CVE-2026-72898) in a self-hosted Metabase instance to access user PII. #DataBreach #CyberSecurity #EdTech #Metabase
##updated 2026-08-11T18:31:23
2 posts
Microsoft today released an out of band update that includes a security update to a vulnerability they first patched in August. I guess the first patch didn't work broadly enough or introduced more flaws (or both). According to MS, though, there aren't any signs this vulnerability is actively being exploited. MS just says "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix."
https://msrc.microsoft.com/update-guide/advisory/CVE-2026-62721
##Microsoft today released an out of band update that includes a security update to a vulnerability they first patched in August. I guess the first patch didn't work broadly enough or introduced more flaws (or both). According to MS, though, there aren't any signs this vulnerability is actively being exploited. MS just says "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix."
https://msrc.microsoft.com/update-guide/advisory/CVE-2026-62721
##updated 2026-08-07T06:31:24
1 posts
5 repos
https://github.com/shootcannon/CVE-2026-61511
https://github.com/puj790201-lab/cve-2026-61511
https://github.com/tc4dy/CVE-2026-61511-PoC-Exploit
[CVE-2026-61511] vBulletin <= 6.2.1 (runMaths) Pre-Auth RCE Vulnerability https://karmainsecurity.com/KIS-2026-13
##updated 2026-08-03T16:19:22.763000
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-23T12:33:27
1 posts
15 repos
https://github.com/vulnquest58/dirtyclone-exploit
https://github.com/seguridadentrerios/CVE-2026-46331
https://github.com/MarwahHadi/CVE-2026-46331-pedit-cow
https://github.com/theendofabbys/pedit-cow
https://github.com/rjt-gupta/page-cache-corruption-lpes
https://github.com/g0thamRabb1t/CVE-2026-46331-pedit-COW-detection
https://github.com/Quaerendir/cve-2026-46331-audit
https://github.com/sgkdev/packet_edit_meme
https://github.com/douglasmun/pagecache-lpe-containment-kit
https://github.com/0xBlackash/CVE-2026-46331
https://github.com/yanxinwu946/CVE-2026-46331
https://github.com/nawalacheker1/CVE-2026-46331
https://github.com/cherrycherrymay/PoC-CVE-2026-46331
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/
##updated 2026-07-23T08:10:00.137000
1 posts
2 repos
I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986) https://blog.himanshuanand.com/2026/07/reporter-11-10-people-found-the-wpforms-paypal-bug-before-me-cve-2026-4986/
##updated 2026-07-22T16:17:28.753000
1 posts
2 repos
Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE) https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/
##updated 2026-07-20T21:26:50
2 posts
🟠 CVE-2026-57130 - High (8.1)
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedde...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57130/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-57130 - High (8.1)
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedde...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57130/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-20T21:25:26
2 posts
🟠 CVE-2026-57126 - High (8.5)
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extract_text, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57126/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-57126 - High (8.5)
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extract_text, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57126/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-15T18:20:21.237000
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-15T18:20:21.237000
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-15T12:32:05
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-15T12:32:05
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-14T18:32:25
1 posts
CVE-2026-50458: Finding a UAF in the Windows Brokering File System https://rotcee.github.io/posts/CVE-2026-50458-finding-a-UAF-in-windows-brokering-file-system/
##updated 2026-07-13T15:15:51.143000
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-11T15:30:30
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-11T15:30:30
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-11T15:30:29
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-10T15:31:48
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-07-09T15:33:27
1 posts
1 repos
Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239) https://blog.paradoxis.nl/escalating-all-the-privileges-with-foxit-pdf-reader-cve-2026-57239-582a78b60492
##updated 2026-07-02T15:17:07.390000
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-06-30T03:38:15
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-06-26T21:50:37.890000
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-06-26T21:32:44
2 posts
Say that new authelia exploit looks like one fail2ban already recognises or relies on timing/brute-force then you’re covered even before a patch is available.
Here’s a real authelia vuln:
https://app.opencve.io/cve/CVE-2026-47203
allowing an attacker to circumvent login throttling or account lockouts by simply altering the case of their credentials.
I think fail2ban would help protect authelia here?
##Say that new authelia exploit looks like one fail2ban already recognises or relies on timing/brute-force then you’re covered even before a patch is available.
Here’s a real authelia vuln:
https://app.opencve.io/cve/CVE-2026-47203
allowing an attacker to circumvent login throttling or account lockouts by simply altering the case of their credentials.
I think fail2ban would help protect authelia here?
##updated 2026-06-24T17:25:29
2 posts
OpenAM <16.1.1 suffers from CRITICAL deserialization vuln (CVE-2026-45051, CVSS 9.2). WebAuthnAuthentication lets attackers run arbitrary code via crafted serialized data. Patch to 16.1.1 ASAP! https://radar.offseq.com/threat/cve-2026-45051-cwe-502-deserialization-of-untrusted-data-in-openidentityplatform-openam-946ad921c23871b6 #OffSeq #CVE202645051 #OpenAM #infosec
##OpenAM <16.1.1 suffers from CRITICAL deserialization vuln (CVE-2026-45051, CVSS 9.2). WebAuthnAuthentication lets attackers run arbitrary code via crafted serialized data. Patch to 16.1.1 ASAP! https://radar.offseq.com/threat/cve-2026-45051-cwe-502-deserialization-of-untrusted-data-in-openidentityplatform-openam-946ad921c23871b6 #OffSeq #CVE202645051 #OpenAM #infosec
##updated 2026-06-21T15:31:31
2 posts
imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64
セキュリティ対応なのでお早めに。
##updated 2026-06-17T10:56:10.603000
1 posts
📢 Exploitation active de trois vulnérabilités critiques dans JFrog Artifactory
🔍 Contexte : Le 10 septembre 2026, Wiz Research publie une analyse technique détaillant l'exploitation active en conditions réelles de trois vulnérabilités critiques et de haute sévérité affectant JFrog Artifactory.
📖 cyberveille : https://cyberveille.ch/posts/2026-09-14-exploitation-active-de-trois-vulnerabilites-critiques-dans-jfrog-artifactory/
🌐 source : https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201
🟢 vérification factuelle haute
#JFrogArtifactory #ExploitationActive #Cyberveille
updated 2026-06-17T10:29:27.873000
2 posts
Sequoia 15.7.7 broke a critical shortcut I use. Terra says "Apple’s Shortcuts security fix for CVE-2026-28993,"
It doesn't always fail, just most of the time.
It feels like I run into something of this nature every day now.
##Sequoia 15.7.7 broke a critical shortcut I use. Terra says "Apple’s Shortcuts security fix for CVE-2026-28993,"
It doesn't always fail, just most of the time.
It feels like I run into something of this nature every day now.
##updated 2026-06-17T10:27:18.693000
3 posts
1 repos
🏆 New Achievement! Exceeded All KPIs Except Staying Uncompromised!
Your Q3 infrastructure review is in. Uptime: stellar. Deployment pipeline: smooth. WooCommerce Wholesale Lead Capture plugin: actively backdoored via CVE-2026-27540. That last one is what we in management call an "opportunity area."
Attackers are currently exploiting this critical flaw in the wild, planting PHP backdoors and achieving full takeover of WordPress stores. Everything was going so well, team. Really. (1/3)
##Critical WooCommerce Vulnerability Is Under Active Attack, Putting WordPress Stores at Risk of PHP Backdoors and Full Takeover + Video
Introduction: A WordPress Plugin Became an Open Door A critical vulnerability in the WooCommerce Wholesale Lead Capture plugin is now being actively exploited by attackers, turning a seemingly ordinary WordPress extension into a potential gateway for complete website compromise. The vulnerability, tracked as CVE-2026-27540, allows…
##🏆 New Achievement! Exceeded All KPIs Except Staying Uncompromised!
Your Q3 infrastructure review is in. Uptime: stellar. Deployment pipeline: smooth. WooCommerce Wholesale Lead Capture plugin: actively backdoored via CVE-2026-27540. That last one is what we in management call an "opportunity area."
Attackers are currently exploiting this critical flaw in the wild, planting PHP backdoors and achieving full takeover of WordPress stores. Everything was going so well, team. Really. (1/3)
##updated 2026-06-17T09:08:21.517000
2 posts
23 repos
https://github.com/TH-SecForge/CVE-2025-30208
https://github.com/iSee857/CVE-2025-30208-PoC
https://github.com/4m3rr0r/CVE-2025-30208-PoC
https://github.com/nkuty/CVE-2025-30208-31125-31486-32395
https://github.com/cc3305/CVE-2025-30208
https://github.com/ThemeHackers/CVE-2025-30208
https://github.com/sumeet-darekar/CVE-2025-30208
https://github.com/keklick1337/CVE-2025-30208-ViteVulnScanner
https://github.com/xuemian168/CVE-2025-30208
https://github.com/lilil3333/Vite-CVE-2025-30208-EXP
https://github.com/HazaVVIP/CVE-2025-30208
https://github.com/r0ngy40/CVE-2025-30208-Series
https://github.com/0xshaheen/CVE-2025-30208
https://github.com/On1onss/CVE-2025-30208
https://github.com/MiclelsonCN/CVE-2025-30208_POC
https://github.com/jackieya/ViteVulScan
https://github.com/sadhfdw129/CVE-2025-30208-Vite
https://github.com/4xura/CVE-2025-30208
https://github.com/imbas007/CVE-2025-30208-template
https://github.com/ThumpBo/CVE-2025-30208-EXP
https://github.com/marino-admin/Vite-CVE-2025-30208-Scanner
F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##updated 2026-06-17T07:54:51.767000
2 posts
F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##updated 2026-06-17T07:43:17.830000
1 posts
90 repos
https://github.com/Dermot-lab/TryHack
https://github.com/mesutgungor/xz-backdoor-vulnerability
https://github.com/nnatsopoulos/xz-backdoor-research
https://github.com/weltregie/liblzma-scan
https://github.com/badsectorlabs/ludus_xz_backdoor
https://github.com/BOSE122/CVE-2024-3094
https://github.com/amlweems/xzbot
https://github.com/robertdfrench/ifuncd-up
https://github.com/byinarie/CVE-2024-3094-info
https://github.com/Juul/xz-backdoor-scan
https://github.com/encikayelwhitehat-glitch/CVE-2024-3094
https://github.com/FabioBaroni/CVE-2024-3094-checker
https://github.com/AndreaCicca/Sicurezza-Informatica-Presentazione
https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094
https://github.com/brinhosa/CVE-2024-3094-One-Liner
https://github.com/mrk336/CVE-2024-3094
https://github.com/galacticquest/cve-2024-3094-detect
https://github.com/devjanger/CVE-2024-3094-XZ-Backdoor-Detector
https://github.com/Simplifi-ED/CVE-2024-3094-patcher
https://github.com/harekrishnarai/xz-utils-vuln-checker
https://github.com/jfrog/cve-2024-3094-tools
https://github.com/Michel-DV/xz-utils-backdoor-case-study
https://github.com/MagpieRYL/CVE-2024-3094-backdoor-env-container
https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094
https://github.com/robertdebock/ansible-playbook-cve-2024-3094
https://github.com/ykhurshudyan-blip/CVE-2024-3094
https://github.com/been22426/CVE-2024-3094
https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project
https://github.com/ackemed/detectar_cve-2024-3094
https://github.com/Ava-Vispilio/CVE-2024-3094
https://github.com/Fractal-Tess/CVE-2024-3094
https://github.com/0xlane/xz-cve-2024-3094
https://github.com/shefirot/CVE-2024-3094
https://github.com/Security-Phoenix-demo/CVE-2024-3094-fix-exploits
https://github.com/hackura/xz-cve-2024-3094
https://github.com/Yuma-Tsushima07/CVE-2024-3094
https://github.com/hackingetico21/revisaxzutils
https://github.com/robertdebock/ansible-role-cve_2024_3094
https://github.com/hariskhalil555000-sketch/What-utility-does-CVE-2024-3094-refer-to-
https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094
https://github.com/h3raklez/CVE-2024-3094
https://github.com/hazemkya/CVE-2024-3094-checker
https://github.com/bsekercioglu/cve2024-3094-Checker
https://github.com/ElinaNotElina/cve-2024-3094-analysis
https://github.com/0xBlackash/CVE-2024-3094
https://github.com/valeriot30/cve-2024-3094
https://github.com/spidygal/CVE-2024-3094-Nmap-NSE-script
https://github.com/fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-
https://github.com/gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer
https://github.com/wgetnz/CVE-2024-3094-check
https://github.com/jbnetwork-git/CVE-2024-3094-XZ-Utils-Check
https://github.com/mightysai1997/CVE-2024-3094
https://github.com/neuralinhibitor/xzwhy
https://github.com/zpxlz/CVE-2024-3094
https://github.com/mhicairo-hue/cs50-cybersecurity-final-project
https://github.com/ThomRgn/xzutils_backdoor_obfuscation
https://github.com/KaminaDuck/ansible-CVE-2024-3094
https://github.com/M1lo25/CS50FinalProject
https://github.com/stevehenderson/lab_xz_backdoor
https://github.com/24Owais/threat-intel-cve-2024-3094
https://github.com/r0binak/xzk8s
https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker
https://github.com/isuruwa/CVE-2024-3094
https://github.com/Mustafa1986/CVE-2024-3094
https://github.com/ashwani95/CVE-2024-3094
https://github.com/vnchk1/sec_review_cve-2024-3094
https://github.com/TheTorjanCaptain/CVE-2024-3094-Checker
https://github.com/przemoc/xz-backdoor-links
https://github.com/Ikram124/CVE-2024-3094-analysis
https://github.com/vesjolyjd/Kaspersky_CVE-2024-3094
https://github.com/buluma/ansible-role-cve_2024_3094
https://github.com/lockness-Ko/xz-vulnerable-honeypot
https://github.com/pentestfunctions/CVE-2024-3094
https://github.com/iheb2b/CVE-2024-3094-Checker
https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094
https://github.com/ScrimForever/CVE-2024-3094
https://github.com/extracoding-dozen/CVE-2024-3094
https://github.com/dah4k/CVE-2024-3094
https://github.com/felipecosta09/cve-2024-3094
https://github.com/bioless/xz_cve-2024-3094_detection
https://github.com/Bella-Bc/xz-backdoor-CVE-2024-3094-Check
https://github.com/gustavorobertux/CVE-2024-3094
https://github.com/teyhouse/CVE-2024-3094
https://github.com/mightysai1997/CVE-2024-3094-info
https://github.com/emirkmo/xz-backdoor-github
https://github.com/Horizon-Software-Development/CVE-2024-3094
https://github.com/HackerHermanos/CVE-2024-3094_xz_check
https://github.com/x-cmd-build/xz
https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public
Scraping NVD means rate limits, pagination, and schema drift you own forever. The ValtersIT CVE API returns normalized CVE, vendor, and exploit data in one call: curl https://valtersit.com/api/cve/CVE-2024-3094 Pricing: https://www.valtersit.com/cve/pricing/
##updated 2026-06-17T07:05:03.993000
1 posts
1 repos
Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) https://mobeta.fr/simple-job-board-unauth-rce-cve-2024-1813/
##updated 2026-06-17T06:09:38.793000
2 posts
Using acme.sh to renew a certificate as root sounds like a RCE-as-root waiting to happen. A Web client written in pure shell, what could possibly go wrong? I just wrote a script to drop its own privilege when it calls acme.sh, so it's safe to use in a root cronjob.
After writing this, I found RCE-as-root is not just "waiting" to happen, it has already happened as CVE-2023-38198. Someone even argued the case as a possible mechanism responsible for the jabber.ru wiretapping incident. https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/
Using acme.sh to renew a certificate as root sounds like a RCE-as-root waiting to happen. A Web client written in pure shell, what could possibly go wrong? I just wrote a script to drop its own privilege when it calls acme.sh, so it's safe to use in a root cronjob.
After writing this, I found RCE-as-root is not just "waiting" to happen, it has already happened as CVE-2023-38198. Someone even argued the case as a possible mechanism responsible for the jabber.ru wiretapping incident. https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/
updated 2026-04-27T16:30:09
4 posts
25 repos
https://github.com/Nxploited/CVE-2026-39987
https://github.com/rootdirective-sec/CVE-2026-39987-Lab
https://github.com/0xBlackash/CVE-2026-39987
https://github.com/vanhari/CVE-2026-39987
https://github.com/Ghxstsec/CVE-2026-39987
https://github.com/MADA0L/CVE-2026-39987-Poc
https://github.com/matesz44/cve-2026-39987
https://github.com/mki9/CVE-2026-39987_exploit
https://github.com/alreadyClosed/CVE-2026-39987
https://github.com/HORKimhab/CVE-2026-39987
https://github.com/K3ysTr0K3R/CVE-2026-39987
https://github.com/M3PH1569/CVE-2026-39987-POC
https://github.com/keraattin/CVE-2026-39987
https://github.com/iapetus12/cohort-htb
https://github.com/fevar54/marimo_CVE-2026-39987_RCE_PoC
https://github.com/gbuyssens/CVE-2026-39987
https://github.com/dodeepsink/CVE-2026-39987.py
https://github.com/julichaan/CVE-2026-39987_POC
https://github.com/h3raklez/CVE-2026-39987
https://github.com/Wind010/CVE-2026-39987_PoC
https://github.com/Clara-M-Grossl/Exploit-Marimo
https://github.com/0xdeadroot/CVE-2026-39987-marimo-rce
https://github.com/Dhiaelhak-Rached/CVE-2026-39987-lab-or-marimo-cve-lab
Sysdig reports a human operator exploited CVE-2026-39987, a pre-auth RCE in Marimo, and pivoted from the notebook to an SSH bastion in eight seconds with a custom Python toolkit. It shows manual tradecraft can match automation speed, shrinking detection windows for exposed dev infrastructure. #MarimoRce #SshBastion #IncidentResponse
https://cyberworldops.eu/en/human-operator-exploits-marimo-rce-and-reaches-ssh-bastion-in-eight
##Skilled Human Attackers Exploit Marimo Flaw to Reach SSH Bastion in 8 Seconds
In a stunning display of speed, a skilled human attacker exploited a flaw in Marimo to breach a secure SSH bastion in just 8 seconds - a pace typically associated with AI-assisted attacks. This remarkable feat was made possible by a pre-authenticated remote code execution bug, CVE-2026-39987, with a near-perfect CVSS score of 9.3.
#Marimo #RceExploit #Cve202639987 #SshBastion #CredentialPivot
##Human Exploits Marimo Flaw to Breach SSH Bastion Host in 8 Seconds
In just 8 seconds, a human attacker exploited a vulnerability in Marimo notebooks to breach an SSH bastion host, showcasing the alarming speed and ease of lateral movement within compromised systems. This lightning-fast breach was achieved without the aid of AI tools, highlighting the severity of the CVE-2026-39987 flaw.
#Marimo #Cve202639987 #SshBastionHost #RemoteCodeExecution #Preauthentication
##Sysdig reports a human operator exploited CVE-2026-39987, a pre-auth RCE in Marimo, and pivoted from the notebook to an SSH bastion in eight seconds with a custom Python toolkit. It shows manual tradecraft can match automation speed, shrinking detection windows for exposed dev infrastructure. #MarimoRce #SshBastion #IncidentResponse
https://cyberworldops.eu/en/human-operator-exploits-marimo-rce-and-reaches-ssh-bastion-in-eight
##updated 2026-04-07T22:16:19
8 posts
Mass-Scanning Campaign Exploits Vite Flaw to Harvest Cloud Credentials
A high-severity flaw in Vite, tracked as CVE-2026-39364, has been exploited in a mass-scanning campaign, allowing attackers to bypass security restrictions and harvest cloud credentials. By manipulating query parameters, unauthenticated attackers can leak sensitive files that were meant to be blocked.
#ViteFlaw #Cve202639364 #CloudCredentials #SupplyChain #EmergingThreats
##「ハッカーがViteの開発サーバーを標的にAWSとAzureの機密情報を盗み出す 」: #BLEEPINGCOMPUTER
「インターネットに公開されているVite開発サーバーを標的とした大規模なスキャンキャンペーンが、AWSおよびAzure環境からクラウド認証情報と設定を盗み出そうとしている。
この攻撃は、Vite バージョン 7.1.0 から 7.3.2、および 8.x ブランチの 8.0.5 より前のバージョンにおいて、ファイルの読み取り/アクセス制御を回避できる深刻な脆弱性である CVE-2026-39364 を悪用するものです。
この脆弱性は4月7日に公表され、認証されていない攻撃者がHTTP GETリクエストのクエリパラメータを操作することで、セキュリティ制限を回避し、通常はアクセスできないはずの場所から平文のファイルを取得できるというものである。」
##The Vite development server vulnerability CVE-2026-39364 is exploited in mass scanning for credential harvesting. F5 Labs logged 32,000 events. Patch now.
#Vite #CVE202639364 #CloudSecurity #CredentialHarvesting #F5Labs #DevSecOps #FileDisclosure #InfoSec #AWS #MassScanning
##F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##Hackers Are Mass-Scanning Exposed Vite Servers to Steal AWS, Azure and Terraform Secrets + Video
A New Warning for Developers Modern web development depends heavily on fast local development environments, but convenience can become dangerous when those environments are accidentally exposed to the public internet. A new mass-scanning campaign is reportedly targeting exposed Vite development servers, abusing CVE-2026-39364 to access sensitive files and potentially…
##「ハッカーがViteの開発サーバーを標的にAWSとAzureの機密情報を盗み出す 」: #BLEEPINGCOMPUTER
「インターネットに公開されているVite開発サーバーを標的とした大規模なスキャンキャンペーンが、AWSおよびAzure環境からクラウド認証情報と設定を盗み出そうとしている。
この攻撃は、Vite バージョン 7.1.0 から 7.3.2、および 8.x ブランチの 8.0.5 より前のバージョンにおいて、ファイルの読み取り/アクセス制御を回避できる深刻な脆弱性である CVE-2026-39364 を悪用するものです。
この脆弱性は4月7日に公表され、認証されていない攻撃者がHTTP GETリクエストのクエリパラメータを操作することで、セキュリティ制限を回避し、通常はアクセスできないはずの場所から平文のファイルを取得できるというものである。」
##The Vite development server vulnerability CVE-2026-39364 is exploited in mass scanning for credential harvesting. F5 Labs logged 32,000 events. Patch now.
#Vite #CVE202639364 #CloudSecurity #CredentialHarvesting #F5Labs #DevSecOps #FileDisclosure #InfoSec #AWS #MassScanning
##F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##updated 2026-03-31T18:32:38
1 posts
🟠 CVE-2026-37008 - High (8.1)
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete obj...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-37008/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-01-22T21:47:41
2 posts
7 repos
https://github.com/xuemian168/CVE-2025-30208
https://github.com/MuhammadWaseem29/Vitejs-exploit
https://github.com/0xgh057r3c0n/CVE-2025-31125
https://github.com/nkuty/CVE-2025-30208-31125-31486-32395
https://github.com/harshgupptaa/Path-Transversal-CVE-2025-31125-
F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence
https://cyberworldops.eu/en/hackers-scan-exposed-vite-servers-for-aws-azure-and-deployment-secrets
##updated 2025-10-22T19:13:26
1 posts
100 repos
https://github.com/mergebase/log4j-detector
https://github.com/AlexandreHeroux/Fix-CVE-2021-44228
https://github.com/christophetd/log4shell-vulnerable-app
https://github.com/lfama/log4j_checker
https://github.com/toramanemre/log4j-rce-detect-waf-bypass
https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes
https://github.com/CERTCC/CVE-2021-44228_scanner
https://github.com/alexandre-lavoie/python-log4rce
https://github.com/stripe/log4j-remediation-tools
https://github.com/puzzlepeaches/Log4jUnifi
https://github.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit
https://github.com/pedrohavay/exploit-CVE-2021-44228
https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs
https://github.com/darkarnium/Log4j-CVE-Detect
https://github.com/corretto/hotpatch-for-apache-log4j2
https://github.com/bigsizeme/Log4j-check
https://github.com/LiveOverflow/log4shell
https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce
https://github.com/logpresso/CVE-2021-44228-Scanner
https://github.com/tippexs/nginx-njs-waf-cve2021-44228
https://github.com/redhuntlabs/Log4JHunt
https://github.com/Kadantte/CVE-2021-44228-poc
https://github.com/rubo77/log4j_checker_beta
https://github.com/dwisiswant0/look4jar
https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept
https://github.com/MalwareTech/Log4jTools
https://github.com/future-client/CVE-2021-44228
https://github.com/marcourbano/CVE-2021-44228
https://github.com/qingtengyun/cve-2021-44228-qingteng-online-patch
https://github.com/mr-r3b00t/CVE-2021-44228
https://github.com/Diverto/nse-log4shell
https://github.com/NorthwaveSecurity/log4jcheck
https://github.com/CreeperHost/Log4jPatcher
https://github.com/cisagov/log4j-scanner
https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator
https://github.com/thomaspatzke/Log4Pot
https://github.com/CodeShield-Security/Log4JShell-Bytecode-Detector
https://github.com/greymd/CVE-2021-44228
https://github.com/momos1337/Log4j-RCE
https://github.com/Jeromeyoung/log4j2burpscanner
https://github.com/puzzlepeaches/Log4jHorizon
https://github.com/simonis/Log4jPatch
https://github.com/mzlogin/CVE-2021-44228-Demo
https://github.com/fireeye/CVE-2021-44228
https://github.com/claranet/ansible-role-log4shell
https://github.com/toramanemre/apache-solr-log4j-CVE-2021-44228
https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes
https://github.com/kozmer/log4j-shell-poc
https://github.com/justakazh/Log4j-CVE-2021-44228
https://github.com/1lann/log4shelldetect
https://github.com/puzzlepeaches/Log4jCenter
https://github.com/0xDexter0us/Log4J-Scanner
https://github.com/fullhunt/log4j-scan
https://github.com/leonjza/log4jpwn
https://github.com/BinaryDefense/log4j-honeypot-flask
https://github.com/HynekPetrak/log4shell-finder
https://github.com/kubearmor/log4j-CVE-2021-44228
https://github.com/takito1812/log4j-detect
https://github.com/KosmX/CVE-2021-44228-example
https://github.com/Adikso/minecraft-log4j-honeypot
https://github.com/ssl/scan4log4j
https://github.com/thecyberneh/Log4j-RCE-Exploiter
https://github.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228
https://github.com/yahoo/check-log4j
https://github.com/mufeedvh/log4jail
https://github.com/lucab85/log4j-cve-2021-44228
https://github.com/wortell/log4j
https://github.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell
https://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228
https://github.com/boundaryx/cloudrasp-log4j2
https://github.com/NCSC-NL/log4shell
https://github.com/blake-fm/vcenter-log4j
https://github.com/fox-it/log4j-finder
https://github.com/nu11secur1ty/CVE-2021-44228-VULN-APP
https://github.com/corelight/cve-2021-44228
https://github.com/giterlizzi/nmap-log4shell
https://github.com/hackinghippo/log4shell_ioc_ips
https://github.com/cyberxml/log4j-poc
https://github.com/jas502n/Log4j2-CVE-2021-44228
https://github.com/0xInfection/LogMePwn
https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words
https://github.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228
https://github.com/alexbakker/log4shell-tools
https://github.com/DragonSurvivalEU/RCE
https://github.com/CrackerCat/CVE-2021-44228-Log4j-Payloads
https://github.com/dtact/divd-2021-00038--log4j-scanner
https://github.com/qingtengyun/cve-2021-44228-qingteng-patch
https://github.com/Labout/log4shell-rmi-poc
https://github.com/infiniroot/nginx-mitigate-log4shell
https://github.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent
https://github.com/f0ng/log4j2burpscanner
https://github.com/roxas-tan/CVE-2021-44228
https://github.com/sunnyvale-it/CVE-2021-44228-PoC
https://github.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab
https://github.com/sec13b/CVE-2021-44228-POC
https://github.com/Nanitor/log4fix
https://github.com/nccgroup/log4j-jndi-be-gone
https://github.com/mr-vill4in/log4j-fuzzer
GET /api/cve/CVE-2021-44228 returns CVSS, CPEs, affected vendors, and known exploits in one call. No scraping, no joins. Docs: https://www.valtersit.com/cve/pricing/
##Acronis Backup Plugin Under Attack: Critical Linux Privilege Escalation Flaw Puts Hosting Servers at Risk + Video
A New Warning for Web Hosting Administrators Acronis has disclosed CVE-2026-87886, a high-severity Linux local privilege escalation vulnerability affecting its backup integrations for cPanel & WHM and Plesk. The vulnerability carries a CVSS score of 7.8 and, more importantly, Acronis says exploitation has already been detected in limited, targeted attacks…
##Acronis confirmed active exploitation of CVE-2026-87886, a CVSS 7.8 local privilege escalation in its backup plugin for cPanel and WHM and Plesk. Any local user on shared hosting could escalate to root and compromise all tenants, making immediate patching and audit critical. #LinuxSecurity #PrivilegeEscalation #CpanelSecurity
https://cyberworldops.eu/en/acronis-warns-of-exploited-privilege-escalation-flaw-in-cpanel-backup
##Acronis Discloses Exploited Flaw in cPanel Backup Plugin
A high-severity flaw, CVE-2026-87886, has been discovered in the Acronis Backup plugin for cPanel & WHM deployments, and it's been exploited in limited, targeted attacks. This Linux local privilege-escalation vulnerability has a CVSS severity score of 7.8, making it a critical issue that needs attention.
#Cve202687886 #Acronis #Cpanel #Linux #LocalPrivilegeEscalation
##Acronis Backup Vulnerability Puts Linux Hosting Servers at Risk as Limited Attacks Begin + Video
Introduction: A Quiet Flaw With Serious Consequences A vulnerability hiding inside a widely used server-backup integration has turned into an urgent warning for Linux hosting administrators. Acronis has disclosed CVE-2026-87886, a high-severity local privilege escalation flaw affecting its backup integrations for cPanel & WHM and Plesk, two platforms commonly used to manage…
##Acronis confirmed active exploitation of CVE-2026-87886, a CVSS 7.8 local privilege escalation in its backup plugin for cPanel and WHM and Plesk. Any local user on shared hosting could escalate to root and compromise all tenants, making immediate patching and audit critical. #LinuxSecurity #PrivilegeEscalation #CpanelSecurity
https://cyberworldops.eu/en/acronis-warns-of-exploited-privilege-escalation-flaw-in-cpanel-backup
##A critical proxy-addr IP spoofing flaw (CVE-2026-90711) exposes Node.js apps to access control bypasses. Patch this proxy-addr IP spoofing bug today.
##🔴 CVE-2026-90711 - Critical (9.1)
proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-si...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90711/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##A critical proxy-addr IP spoofing flaw (CVE-2026-90711) exposes Node.js apps to access control bypasses. Patch this proxy-addr IP spoofing bug today.
##🔴 CVE-2026-90711 - Critical (9.1)
proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-si...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90711/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Multiple critical Squid proxy vulnerabilities, including CVE-2026-61642, allow request smuggling and buffer overflows. Patch your servers immediately.
#SquidProxy #CVE202661642 #Cybersecurity #Vulnerability #InfoSec
##Multiple critical Squid proxy vulnerabilities, including CVE-2026-61642, allow request smuggling and buffer overflows. Patch your servers immediately.
#SquidProxy #CVE202661642 #Cybersecurity #Vulnerability #InfoSec
##krb5 (1.20.1-6ubuntu2.10)
セキュリティ対応ではない。
krb5-locales
libgssapi-krb5-2
libk5crypto3
libkrb5-3
libkrb5support0
netplan.io (1.1.2-8ubuntu1~24.04.3)
セキュリティ対応ではない。
libnetplan1
netplan-generator
python3-netplan
policykit-1 (124-2ubuntu1.24.04.4)
CVE-2026-85498へのセキュリティ対応。
libpolkit-agent-1-0
libpolkit-gobject-1-0
libsrt1.5-gnutls
polkitd
セキュリティ対応もあるので、お早めに。
##krb5 (1.20.1-6ubuntu2.10)
セキュリティ対応ではない。
krb5-locales
libgssapi-krb5-2
libk5crypto3
libkrb5-3
libkrb5support0
netplan.io (1.1.2-8ubuntu1~24.04.3)
セキュリティ対応ではない。
libnetplan1
netplan-generator
python3-netplan
policykit-1 (124-2ubuntu1.24.04.4)
CVE-2026-85498へのセキュリティ対応。
libpolkit-agent-1-0
libpolkit-gobject-1-0
libsrt1.5-gnutls
polkitd
セキュリティ対応もあるので、お早めに。
##🟠 CVE-2026-88065 - High (7.5)
`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88065/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-88065 - High (7.5)
`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88065/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63443 - High (8.3)
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request U...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63443/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63443 - High (8.3)
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request U...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63443/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##📰 Chinese Hackers Exploit Critical Flaw in Tencent's Sogou IME Software
A critical flaw (CVE-2026-51990) in Tencent's popular Sogou Input Method is being exploited by Chinese hackers for 1-click RCE. The attack chains a custom protocol handler flaw with an old browser engine. #CyberSecurity #Vulnerability #Tencent
##UNC3569 is exploiting CVE-2026-51990 in Tencent Sogou Input Method for Windows. A crafted sgbiz:// URL enables one-click SYSTEM-level code execution and GrayRabbit backdoor deployment. Widespread IME deployment makes this a high-priority patch and detection target. #SogouFlaw #GrayRabbit #ThreatIntel
https://cyberworldops.eu/en/tencent-sogou-input-flaw-exploited-for-one-click-system-level-code
##UNC3569 is exploiting CVE-2026-51990 in Tencent Sogou Input Method for Windows. A crafted sgbiz:// URL enables one-click SYSTEM-level code execution and GrayRabbit backdoor deployment. Widespread IME deployment makes this a high-priority patch and detection target. #SogouFlaw #GrayRabbit #ThreatIntel
https://cyberworldops.eu/en/tencent-sogou-input-flaw-exploited-for-one-click-system-level-code
##Defend against the CVE-2026-51990 Sogou exploit. Discover how hackers use this one-click flaw to drop backdoors and how to secure your systems today.
#CVE202651990 #SogouInputMethod #CyberSecurity #UNC3569 #InfoSec #EndpointSecurity #ThreatIntel
##🏆 New Achievement! One Click to the Food Chain Bottom!
Here, in the wild habitat of Windows enterprise environments, we observe the Sogou Input Method — a text entry tool installed by millions — standing perfectly still as UNC3569, a China-aligned espionage group, approaches from the brush. CVE-2026-51990 is a critical one-click remote code execution flaw exploiting an unsandboxed Chromium chain. The creature does not run. It simply... accepts the GrayRabbit backdoor. (1/2)
##Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method...
🔗️ [Bleepingcomputer] https://link.is.it/DXBwPD
##🟠 CVE-2026-57586 - High (8.6)
CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py tre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57586/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-57586 - High (8.6)
CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py tre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57586/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65838 - High (8.2)
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65838/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65838 - High (8.2)
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65838/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##1 posts
85 repos
https://github.com/fullhunt/wp2shell-scan
https://github.com/Madelleimproved411/wp-to-code
https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/ikow/wp2shell
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell
https://github.com/TomorrowX6/CVE-2026-63030-poc
https://github.com/0xsha/wp2shell
https://github.com/shinthink/CVE-2026-63030
https://github.com/Iqbalx7/wp2shell
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/InstaWP/wp2shell-scan
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/AnggaTechI/CVE-2026-63030
https://github.com/attackercan/wp2shell-poc2
https://github.com/0xWhoknows/wp2shell
https://github.com/Lutfifakee-Project/wp2shell
https://github.com/raphy76/wp2shell-poc-fulljs
https://github.com/dinosn/wp2shell-lab
https://github.com/ivanesk315/CVE-2026-60137-and-CVE-2026-63030
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-
https://github.com/ekomsSavior/wp2shell
https://github.com/ebrasha/abdal-cve-2026-63030
https://github.com/Icex0/wp2shell-poc
https://github.com/administrator-01001/CVE-2026-63030
https://github.com/mrx-arafat/CVE-2026-63030-POC
https://github.com/h4cd0c/wp2shell
https://github.com/kulichr/wp2shell
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/x-znn/CVE-2026-63030
https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030
https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t
https://github.com/bahartanir/wp2shell-scanner
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/Sec-Dan/WP2Shell-Scanner
https://github.com/g0d150ne/WP2Shell
https://github.com/ZenithGenius/wordpress-batch-rce-lab
https://github.com/Crypto-Cat/wp2shell
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/zeroc00I/CVE-2026-63030
https://github.com/vulnquest58/PressVector
https://github.com/zi3lak/wp2shell_scanner
https://github.com/Ch4120N/CVE-2026-63030
https://github.com/4minx/CVE-2026-63030
https://github.com/mcipekci/wp2shell
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/mhtsec/CVE-2026-63030
https://github.com/0xjessie21/wp2shell-checker
https://github.com/0xBlackash/CVE-2026-63030
https://github.com/Procjevt/CVE-2026-63030
https://github.com/0xh7ml/CVE-2026-63030
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/mverschu/CVE-2026-63030
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/CybersecSpirit/CVE-2026-63030
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/securelayer7/WordPresShell
https://github.com/47Cid/wp2shell-lab
https://github.com/ChiefYoru/CVE-2026-63030_PoC
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/michael-kanda/Wp2shell-ioc-scanner
https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass
https://github.com/DeadExpl0it/wp2shell-poc
https://github.com/yuag/wp2shell
https://github.com/c0gnit00/Wp2Shell
https://github.com/NULL200OK/WP2Shell
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/ananay/wp2shell-lab
https://github.com/mhassani97/cve-2026-63030-lab
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/gbrsh/CVE-2026-63030
https://github.com/4B3R4M4-607D/CVE-2026-63030-POC
https://github.com/imXur/WordPress-CVE-2026-63030-Analysis
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause
https://github.com/sowarma/wp2shell-PoC
https://github.com/johnlodan/wp2shell-rce
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner https://fullhunt.io/blog/2026/07/17/wp2shell-wordpress-core-pre-auth-rce-cve-2026-63030.html
##