##
Updated at UTC 2026-09-21T19:48:14.638761
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-93742 | 9.9 | 1.88% | 3 | 0 | 2026-09-21T19:17:17.273000 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected b | |
| CVE-2026-86553 | 8.8 | 0.45% | 4 | 1 | 2026-09-21T19:17:14.327000 | SmartLife app dynamically generates fresh SmartLife application authentication p | |
| CVE-2026-79920 | 9.9 | 0.00% | 2 | 0 | 2026-09-21T19:17:11.323000 | Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any | |
| CVE-2026-68928 | 8.6 | 0.13% | 1 | 0 | 2026-09-21T19:17:09.157000 | Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, | |
| CVE-2026-94301 | 9.8 | 0.00% | 2 | 0 | 2026-09-21T18:10:30.343000 | The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - accept | |
| CVE-2026-83621 | 8.1 | 0.00% | 2 | 0 | 2026-09-21T17:19:08.590000 | ntopng is a web-based network traffic monitoring application. Prior to 6.7.26071 | |
| CVE-2026-77560 | 8.1 | 0.00% | 2 | 0 | 2026-09-21T17:18:52.770000 | Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth | |
| CVE-2026-93740 | 10.0 | 0.61% | 2 | 0 | 2026-09-21T16:17:28.070000 | A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected i | |
| CVE-2026-82187 | 9.8 | 0.14% | 2 | 0 | 2026-09-21T15:33:02 | The Web to Print Online Designer WordPress plugin before 2.15.0 does not validat | |
| CVE-2026-93993 | 8.8 | 0.60% | 2 | 0 | 2026-09-21T15:17:37.247000 | Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the | |
| CVE-2026-92701 | 9.1 | 0.22% | 2 | 1 | 2026-09-21T15:17:35.313000 | Cocos AI is a confidential computing system for running AI workloads inside trus | |
| CVE-2026-90817 | 9.8 | 0.57% | 5 | 2 | 2026-09-21T15:17:34.560000 | An unauthenticated Remote Code Execution vulnerability was found in the survey p | |
| CVE-2026-87839 | 7.5 | 0.21% | 2 | 0 | 2026-09-21T13:34:57.127000 | The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, a | |
| CVE-2026-87067 | 8.5 | 0.28% | 2 | 0 | 2026-09-21T13:34:57.127000 | The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which c | |
| CVE-2026-85017 | 7.5 | 0.24% | 2 | 0 | 2026-09-21T13:34:57.127000 | The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not per | |
| CVE-2026-82842 | 8.1 | 0.22% | 4 | 0 | 2026-09-21T13:34:57.127000 | The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the confi | |
| CVE-2026-85574 | 8.0 | 0.19% | 1 | 0 | 2026-09-21T13:34:57.127000 | The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any au | |
| CVE-2026-86814 | 8.1 | 0.23% | 2 | 0 | 2026-09-21T13:34:57.127000 | The UsersWP WordPress plugin before 1.5.10 does not verify that a social login | |
| CVE-2026-87909 | 7.5 | 0.53% | 3 | 0 | 2026-09-21T13:33:33.387000 | The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execut | |
| CVE-2026-94015 | 7.3 | 0.26% | 1 | 0 | 2026-09-21T13:33:33.387000 | A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. | |
| CVE-2026-94129 | 8.8 | 0.12% | 4 | 1 | 2026-09-21T13:33:33.387000 | A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vul | |
| CVE-2026-94096 | 9.9 | 1.65% | 4 | 0 | 2026-09-21T13:33:33.387000 | A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by thi | |
| CVE-2026-84434 | 9.8 | 0.70% | 3 | 1 | template | 2026-09-21T13:33:33.387000 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in |
| CVE-2026-93962 | 8.3 | 0.53% | 2 | 0 | 2026-09-21T13:33:33.387000 | A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. T | |
| CVE-2026-93741 | 10.0 | 0.64% | 4 | 0 | 2026-09-21T13:33:33.387000 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affec | |
| CVE-2026-1255 | 7.5 | 0.29% | 1 | 0 | 2026-09-21T13:33:33.387000 | The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Expos | |
| CVE-2026-4327 | 8.8 | 0.70% | 1 | 0 | 2026-09-21T13:33:33.387000 | The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution i | |
| CVE-2026-85658 | 8.1 | 0.36% | 1 | 0 | 2026-09-21T13:33:33.387000 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User | |
| CVE-2026-92229 | 9.1 | 0.40% | 2 | 1 | 2026-09-21T13:33:33.387000 | The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plug | |
| CVE-2026-93739 | 9.9 | 0.49% | 1 | 0 | 2026-09-21T13:33:33.387000 | A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impac | |
| CVE-2026-93031 | 8.8 | 0.58% | 1 | 0 | 2026-09-21T13:33:33.387000 | The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-B | |
| CVE-2026-10747 | 10.0 | 0.52% | 4 | 0 | 2026-09-21T13:17:07.147000 | IBM MQ Appliance could allow a remote attacker to cause a denial of service or p | |
| CVE-2026-94146 | 8.8 | 0.12% | 2 | 0 | 2026-09-21T09:31:09 | A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue aff | |
| CVE-2026-94142 | 8.8 | 0.13% | 4 | 0 | 2026-09-21T06:30:32 | A security vulnerability has been detected in BioStar Temperature Monitor Utilit | |
| CVE-2026-94128 | 8.8 | 0.12% | 4 | 1 | 2026-09-21T03:30:29 | A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500 | |
| CVE-2026-94099 | 9.9 | 1.69% | 4 | 0 | 2026-09-21T03:30:27 | A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This | |
| CVE-2026-94101 | 9.9 | 0.45% | 4 | 0 | 2026-09-21T03:30:27 | A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246 | |
| CVE-2026-94100 | 9.9 | 0.46% | 4 | 0 | 2026-09-21T03:30:23 | A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted i | |
| CVE-2026-94098 | 9.1 | 2.38% | 2 | 0 | 2026-09-21T03:30:22 | A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulne | |
| CVE-2026-94097 | 10.0 | 1.99% | 2 | 0 | 2026-09-21T00:30:33 | A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affec | |
| CVE-2026-94095 | 9.9 | 1.67% | 2 | 1 | 2026-09-21T00:30:33 | A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected b | |
| CVE-2026-94089 | 10.0 | 0.98% | 2 | 0 | 2026-09-20T21:31:45 | A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects th | |
| CVE-2026-94036 | 8.8 | 0.47% | 2 | 1 | 2026-09-20T18:31:25 | A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0 | |
| CVE-2026-87068 | 6.6 | 0.21% | 2 | 0 | 2026-09-20T15:31:27 | The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role v | |
| CVE-2026-92965 | 3.7 | 0.15% | 2 | 0 | 2026-09-20T14:17:00.423000 | The TikTok WordPress plugin before 1.4.2 does not check that a request is author | |
| CVE-2026-94106 | 8.8 | 1.66% | 2 | 0 | 2026-09-20T12:30:37 | getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out | |
| CVE-2026-94107 | 8.1 | 0.42% | 2 | 0 | 2026-09-20T12:30:35 | NivoCart through 2.4.0 contains a predictable password reset token vulnerability | |
| CVE-2026-94104 | 8.8 | 0.67% | 2 | 0 | 2026-09-20T12:30:28 | NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the Fi | |
| CVE-2026-94003 | 10.0 | 0.61% | 4 | 0 | 2026-09-20T12:30:28 | A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the funct | |
| CVE-2026-94109 | 8.8 | 0.92% | 2 | 0 | 2026-09-20T12:17:06.620000 | openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerabili | |
| CVE-2026-93958 | 9.1 | 2.17% | 4 | 1 | 2026-09-20T03:30:31 | A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affec | |
| CVE-2026-94083 | 9.4 | 0.40% | 8 | 0 | 2026-09-20T03:30:29 | Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, | |
| CVE-2026-94084 | 9.4 | 0.40% | 8 | 0 | 2026-09-20T02:16:53.717000 | Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transacti | |
| CVE-2026-78030 | 9.8 | 0.73% | 4 | 0 | 2026-09-20T01:16:30.017000 | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_ty | |
| CVE-2026-94054 | 7.0 | 0.27% | 2 | 0 | 2026-09-20T00:30:33 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled pro | |
| CVE-2026-94056 | 7.5 | 0.24% | 3 | 0 | 2026-09-20T00:30:32 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled pro | |
| CVE-2026-93992 | 8.1 | 0.80% | 2 | 0 | 2026-09-20T00:30:32 | Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive e | |
| CVE-2026-93990 | 7.5 | 0.35% | 2 | 0 | 2026-09-20T00:30:31 | Expat through 2.8.4 fails to validate low surrogates following high surrogates i | |
| CVE-2026-93991 | 7.7 | 0.33% | 2 | 0 | 2026-09-19T23:17:10.360000 | Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vuln | |
| CVE-2026-88824 | 8.8 | 0.28% | 1 | 0 | 2026-09-19T15:32:24 | The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on | |
| CVE-2026-92404 | 7.5 | 0.26% | 1 | 0 | 2026-09-19T15:31:26 | The MgoSync WordPress plugin before 2.1.7 does not have authorization controls | |
| CVE-2026-88926 | 8.6 | 0.26% | 1 | 0 | 2026-09-19T15:31:25 | The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 | |
| CVE-2026-85680 | 8.8 | 0.28% | 1 | 0 | 2026-09-19T15:31:24 | The Ultimate Member WordPress plugin before 2.13.1 does not escape a value deri | |
| CVE-2026-84750 | 6.5 | 0.27% | 1 | 0 | 2026-09-19T15:31:24 | The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not vali | |
| CVE-2026-86591 | 9.8 | 0.37% | 2 | 0 | 2026-09-19T15:31:23 | The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation | |
| CVE-2026-84082 | 9.8 | 0.40% | 2 | 0 | 2026-09-19T15:17:05.647000 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit | |
| CVE-2026-84078 | 9.9 | 0.28% | 3 | 0 | 2026-09-19T15:17:05.430000 | IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vuln | |
| CVE-2026-84070 | 8.9 | 0.32% | 3 | 0 | 2026-09-19T15:17:04.867000 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to | |
| CVE-2026-84064 | 9.9 | 0.37% | 2 | 0 | 2026-09-19T15:17:04.757000 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to | |
| CVE-2026-82967 | 9.8 | 0.43% | 3 | 0 | 2026-09-19T15:17:04.430000 | IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that | |
| CVE-2026-82892 | 8.1 | 0.39% | 2 | 0 | 2026-09-19T15:17:04.107000 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit | |
| CVE-2026-82887 | 8.8 | 0.41% | 2 | 0 | 2026-09-19T15:17:03.990000 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to | |
| CVE-2026-80441 | 9.8 | 0.38% | 2 | 0 | 2026-09-19T15:17:02.430000 | IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-ord | |
| CVE-2026-61817 | 8.5 | 0.58% | 2 | 0 | 2026-09-19T15:16:59.910000 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or | |
| CVE-2026-17619 | 8.6 | 0.30% | 2 | 0 | 2026-09-19T15:16:58.713000 | IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send sp | |
| CVE-2026-11726 | 8.1 | 0.46% | 2 | 0 | 2026-09-19T15:16:57.777000 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac | |
| CVE-2026-84241 | 8.1 | 0.30% | 2 | 0 | 2026-09-19T14:17:00.260000 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi | |
| CVE-2026-84239 | 7.6 | 0.41% | 3 | 0 | 2026-09-19T14:17:00.143000 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to | |
| CVE-2026-84108 | 8.1 | 0.40% | 2 | 0 | 2026-09-19T14:17:00.037000 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit | |
| CVE-2026-84085 | 8.1 | 0.32% | 1 | 0 | 2026-09-19T14:16:59.587000 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit | |
| CVE-2026-93985 | 9.9 | 0.48% | 2 | 0 | 2026-09-19T12:32:19 | OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerabi | |
| CVE-2026-53266 | 8.8 | 0.28% | 8 | 1 | 2026-09-19T04:17:53.580000 | In the Linux kernel, the following vulnerability has been resolved: netfilter: | |
| CVE-2026-92807 | 8.8 | 0.25% | 2 | 0 | 2026-09-19T03:32:15 | The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitra | |
| CVE-2026-89274 | 9.1 | 0.38% | 2 | 2 | 2026-09-19T03:32:09 | The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Ex | |
| CVE-2026-93923 | 8.8 | 0.41% | 1 | 0 | 2026-09-19T00:32:50 | SiYuan through 3.8.4 fails to escape heading style attributes when rendering out | |
| CVE-2026-93922 | 8.8 | 0.54% | 1 | 0 | 2026-09-19T00:16:57.913000 | SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker | |
| CVE-2026-75885 | 9.3 | 0.41% | 2 | 0 | 2026-09-18T22:17:10.313000 | A flaw was found in the OpenShift console. Unauthenticated access to the `/api/d | |
| CVE-2026-93738 | 9.9 | 0.50% | 1 | 0 | 2026-09-18T21:32:44 | A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects th | |
| CVE-2026-88097 | 8.1 | 0.22% | 1 | 0 | 2026-09-18T21:32:43 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke | |
| CVE-2026-93868 | 8.1 | 0.61% | 1 | 0 | 2026-09-18T21:32:41 | Cotonti through 1.0.0 derives password recovery validation tokens from md5(micro | |
| CVE-2026-84077 | 8.1 | 0.19% | 2 | 0 | 2026-09-18T21:32:40 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi | |
| CVE-2026-93839 | 9.8 | 0.60% | 1 | 0 | 2026-09-18T21:32:40 | LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /p | |
| CVE-2026-84089 | 7.8 | 0.11% | 2 | 0 | 2026-09-18T21:32:39 | IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated | |
| CVE-2026-84075 | 9.9 | 0.35% | 3 | 0 | 2026-09-18T21:32:39 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi | |
| CVE-2026-84076 | 7.6 | 0.31% | 2 | 0 | 2026-09-18T21:32:39 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to | |
| CVE-2026-84084 | 8.8 | 0.18% | 1 | 0 | 2026-09-18T21:32:39 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi | |
| CVE-2026-84031 | 9.0 | 0.33% | 3 | 0 | 2026-09-18T21:32:38 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to | |
| CVE-2026-84074 | 8.9 | 0.32% | 2 | 0 | 2026-09-18T21:32:38 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to | |
| CVE-2026-84083 | 7.8 | 0.11% | 2 | 0 | 2026-09-18T21:32:38 | IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation vi | |
| CVE-2026-84105 | 7.7 | 0.35% | 1 | 0 | 2026-09-18T21:32:38 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to | |
| CVE-2026-84081 | 8.1 | 0.20% | 3 | 0 | 2026-09-18T21:32:37 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi | |
| CVE-2026-82896 | 7.6 | 0.36% | 2 | 0 | 2026-09-18T21:32:37 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to | |
| CVE-2026-84073 | 9.1 | 0.26% | 2 | 0 | 2026-09-18T21:32:37 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to | |
| CVE-2026-84034 | 8.8 | 0.25% | 2 | 0 | 2026-09-18T21:32:37 | IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulne | |
| CVE-2026-82885 | 8.8 | 0.28% | 2 | 0 | 2026-09-18T21:32:36 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to | |
| CVE-2026-82832 | 9.6 | 0.38% | 2 | 0 | 2026-09-18T21:32:36 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to | |
| CVE-2026-82893 | 7.8 | 0.11% | 2 | 0 | 2026-09-18T21:32:36 | IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated | |
| CVE-2026-75878 | 9.1 | 0.48% | 2 | 0 | 2026-09-18T21:32:35 | IBM Sterling File Gateway could allow a remote attacker to bypass authentication | |
| CVE-2026-81656 | 8.8 | 0.29% | 2 | 0 | 2026-09-18T21:32:35 | IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability | |
| CVE-2026-80442 | 9.9 | 0.63% | 2 | 0 | 2026-09-18T21:32:35 | IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command i | |
| CVE-2026-82340 | 9.8 | 0.51% | 2 | 0 | 2026-09-18T21:32:35 | IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure dese | |
| CVE-2026-11716 | 7.5 | 0.45% | 2 | 0 | 2026-09-18T21:32:28 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac | |
| CVE-2026-11727 | 8.1 | 0.61% | 2 | 0 | 2026-09-18T21:32:28 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remo | |
| CVE-2025-39682 | 7.1 | 1.20% | 8 | 2 | 2026-09-18T21:31:33 | In the Linux kernel, the following vulnerability has been resolved: tls: fix ha | |
| CVE-2026-84106 | 8.9 | 0.32% | 2 | 0 | 2026-09-18T21:18:44.520000 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to | |
| CVE-2026-71418 | 7.5 | 0.35% | 1 | 0 | 2026-09-18T21:18:08.590000 | Suricata is a network Intrusion Detection System, Intrusion Prevention System an | |
| CVE-2026-61781 | 9.9 | 0.57% | 2 | 0 | 2026-09-18T21:17:02.257000 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or | |
| CVE-2026-92708 | 7.5 | 0.34% | 1 | 0 | 2026-09-18T20:17:30.150000 | Svelte devalue is a JavaScript library that serializes values into strings when | |
| CVE-2026-81933 | 8.8 | 0.32% | 2 | 0 | 2026-09-18T20:17:24.250000 | IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability | |
| CVE-2026-81657 | 9.8 | 0.58% | 2 | 0 | 2026-09-18T20:17:23.997000 | IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker | |
| CVE-2026-81626 | 8.6 | 0.27% | 2 | 0 | 2026-09-18T20:17:23.723000 | IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability | |
| CVE-2026-81179 | 8.1 | 0.26% | 2 | 0 | 2026-09-18T20:17:23.470000 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, | |
| CVE-2026-61714 | 7.8 | 0.14% | 2 | 0 | 2026-09-18T20:17:18.270000 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. Fr | |
| CVE-2026-58264 | 9.8 | 0.59% | 2 | 0 | 2026-09-18T20:17:18.107000 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. Fr | |
| CVE-2026-11725 | 8.8 | 0.40% | 2 | 0 | 2026-09-18T20:17:03.167000 | IBM MQ could allow an authenticated attacker to cause a denial of service or pot | |
| CVE-2026-89308 | 0 | 2.97% | 2 | 0 | 2026-09-18T19:24:36.593000 | An unauthenticated OS command injection vulnerability exists in the ping.php end | |
| CVE-2026-59569 | 8.1 | 0.12% | 1 | 0 | 2026-09-18T19:08:02.707000 | An improper input validation vulnerability in Zscaler Client Connector on Androi | |
| CVE-2026-93748 | 7.5 | 0.40% | 2 | 0 | 2026-09-18T18:32:07 | http-cache-semantics through 4.2.0 fails to properly validate security-zeroed ca | |
| CVE-2026-93759 | 8.6 | 0.24% | 1 | 0 | 2026-09-18T18:32:04 | Mongoid does not neutralize a string-typed query criterion supplied to its query | |
| CVE-2026-93762 | 9.8 | 0.34% | 2 | 0 | 2026-09-18T18:32:01 | Mongoid contains an unsafe reflection weakness in the query path used for embedd | |
| CVE-2026-10858 | 9.9 | 0.33% | 2 | 0 | 2026-09-18T18:31:53 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac | |
| CVE-2026-93749 | 7.5 | 0.35% | 3 | 0 | 2026-09-18T18:18:33.480000 | source-map-js through 1.2.1 fails to validate the per-section offset line value | |
| CVE-2026-85058 | 7.5 | 0.27% | 2 | 0 | 2026-09-18T18:17:17.447000 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishW | |
| CVE-2026-81180 | 8.8 | 0.36% | 2 | 0 | 2026-09-18T18:17:15.930000 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, | |
| CVE-2026-69184 | 7.5 | 0.68% | 2 | 0 | 2026-09-18T18:17:11.477000 | c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse | |
| CVE-2026-91127 | 8.2 | 0.24% | 2 | 0 | 2026-09-18T17:19:44 | ### Summary Before 2.3.1, the legacy `.doc` renderer emitted document hyperlink | |
| CVE-2026-81916 | 4.3 | 0.20% | 1 | 0 | 2026-09-18T15:31:47 | Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry | |
| CVE-2025-39964 | 3.3 | 0.79% | 9 | 2 | 2026-09-18T15:31:06 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_ | |
| CVE-2026-20283 | 6.5 | 0.43% | 2 | 0 | 2026-09-18T13:28:28.567000 | A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authe | |
| CVE-2026-85889 | 10.0 | 0.49% | 2 | 0 | 2026-09-18T00:31:16 | Missing authentication for critical function in Azure AI Foundry allows an unaut | |
| CVE-2026-90426 | None | 0.20% | 1 | 0 | 2026-09-17T18:33:37 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra | |
| CVE-2026-58704 | 8.8 | 0.21% | 2 | 0 | 2026-09-17T04:17:54.930000 | In Cellular Modem, there is a possible permission bypass due to a logic error in | |
| CVE-2026-20306 | 9.1 | 1.37% | 1 | 0 | 2026-09-17T04:17:40.777000 | A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenti | |
| CVE-2026-20305 | 9.1 | 1.37% | 1 | 0 | 2026-09-17T04:17:40.540000 | A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an | |
| CVE-2026-76460 | 10.0 | 0.78% | 5 | 1 | 2026-09-16T21:33:00 | A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an | |
| CVE-2026-20284 | 9.1 | 0.39% | 2 | 0 | 2026-09-16T21:32:50 | A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, r | |
| CVE-2026-20282 | 4.9 | 0.56% | 2 | 0 | 2026-09-16T21:32:50 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to ob | |
| CVE-2026-27561 | 7.2 | 2.23% | 2 | 0 | 2026-09-16T19:17:13.633000 | A high-privileged remote attacker can exploit a command injection vulnerability | |
| CVE-2026-27560 | 7.2 | 2.23% | 2 | 0 | 2026-09-16T19:17:13.420000 | A high-privileged remote attacker can exploit a command injection vulnerability | |
| CVE-2026-92397 | 9.1 | 2.30% | 2 | 0 | 2026-09-16T18:32:09 | A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected | |
| CVE-2026-92398 | 9.1 | 2.47% | 2 | 0 | 2026-09-16T18:32:09 | A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by th | |
| CVE-2026-91843 | 9.8 | 0.50% | 2 | 1 | 2026-09-16T15:31:14 | A stack overflow during the unauthenticated login process may allow an attacker | |
| CVE-2026-27562 | 7.2 | 2.23% | 2 | 0 | 2026-09-16T09:30:34 | A high-privileged remote attacker can exploit a command injection vulnerability | |
| CVE-2026-77179 | None | 0.16% | 1 | 1 | 2026-09-16T00:32:25 | On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows | |
| CVE-2026-76698 | 6.5 | 4.11% | 2 | 0 | 2026-09-15T21:31:36 | A command injection vulnerability exists in the web-based management interface o | |
| CVE-2026-90703 | 9.1 | 2.80% | 2 | 0 | 2026-09-15T18:19:38.113000 | A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element i | |
| CVE-2026-89267 | 4.3 | 0.19% | 1 | 0 | 2026-09-15T17:17:36.800000 | starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fi | |
| CVE-2026-90439 | 6.5 | 0.26% | 2 | 0 | 2026-09-15T15:32:20 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module | |
| CVE-2026-90847 | 9.1 | 2.18% | 2 | 0 | 2026-09-15T03:30:30 | A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element i | |
| CVE-2026-76461 | 9.8 | 2.01% | 2 | 4 | 2026-09-14T21:32:49 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure | |
| CVE-2026-81000 | 7.8 | 0.16% | 1 | 2 | 2026-09-14T15:33:28 | In the Linux kernel, the following vulnerability has been resolved: net: tun: b | |
| CVE-2026-25687 | 8.1 | 0.23% | 1 | 0 | 2026-09-14T15:32:56 | A race condition in the ZPA tunnel handler of affected versions of Zscaler Clien | |
| CVE-2026-89496 | None | 0.18% | 1 | 0 | 2026-09-14T15:32:27 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: alwa | |
| CVE-2026-80968 | None | 0.21% | 1 | 0 | 2026-09-14T15:32:21 | In the Linux kernel, the following vulnerability has been resolved: ALSA: mts64 | |
| CVE-2026-80949 | None | 0.18% | 1 | 0 | 2026-09-14T15:32:21 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmf | |
| CVE-2026-80930 | None | 0.18% | 1 | 0 | 2026-09-14T15:32:20 | In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2 | |
| CVE-2026-80994 | 7.8 | 0.16% | 1 | 0 | 2026-09-14T13:18:54.043000 | In the Linux kernel, the following vulnerability has been resolved: net: openvs | |
| CVE-2026-80990 | 0 | 0.20% | 1 | 0 | 2026-09-14T13:18:53.787000 | In the Linux kernel, the following vulnerability has been resolved: net: thunde | |
| CVE-2026-80987 | 7.5 | 0.51% | 1 | 0 | 2026-09-14T13:18:53.343000 | In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_tr | |
| CVE-2026-80984 | 0 | 0.20% | 1 | 0 | 2026-09-14T13:18:53.227000 | In the Linux kernel, the following vulnerability has been resolved: net/smc: do | |
| CVE-2026-90702 | 9.1 | 2.80% | 2 | 0 | 2026-09-14T12:31:44 | A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system | |
| CVE-2026-80937 | 8.8 | 0.32% | 1 | 0 | 2026-09-13T09:32:11 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: | |
| CVE-2026-80950 | 7.8 | 0.16% | 2 | 0 | 2026-09-13T07:17:02.210000 | In the Linux kernel, the following vulnerability has been resolved: i3c: renesa | |
| CVE-2026-81913 | None | 0.59% | 1 | 0 | 2026-09-11T21:31:32 | Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via th | |
| CVE-2026-80957 | 0 | 0.17% | 1 | 0 | 2026-09-11T20:19:01.520000 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: | |
| CVE-2026-80942 | 0 | 0.17% | 1 | 0 | 2026-09-11T20:18:59.660000 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwi | |
| CVE-2026-80934 | 0 | 0.17% | 1 | 0 | 2026-09-11T20:18:57.280000 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: | |
| CVE-2026-42945 | 8.1 | 68.05% | 2 | 45 | 2026-09-10T13:20:09.723000 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo | |
| CVE-2025-25249 | 8.1 | 2.40% | 1 | 0 | 2026-09-09T21:30:27 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6 | |
| CVE-2025-20701 | 8.8 | 8.67% | 2 | 2 | 2026-09-08T16:17:48.883000 | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth aud | |
| CVE-2026-31431 | 7.8 | 99.91% | 1 | 100 | 2026-09-08T15:13:07.273000 | In the Linux kernel, the following vulnerability has been resolved: crypto: alg | |
| CVE-2026-54218 | 0 | 0.34% | 2 | 0 | 2026-09-07T14:16:53.357000 | Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamD | |
| CVE-2026-75925 | 9.6 | 0.67% | 2 | 0 | 2026-09-05T00:31:10 | Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4. | |
| CVE-2026-80844 | 0 | 0.19% | 1 | 2 | 2026-09-04T16:18:13.023000 | In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: | |
| CVE-2026-13348 | 0 | 0.31% | 1 | 0 | 2026-09-01T20:52:39.973000 | CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability | |
| CVE-2026-74469 | 8.8 | 0.47% | 1 | 2 | 2026-08-19T17:21:03.977000 | In the Linux kernel, the following vulnerability has been resolved: sctp: preve | |
| CVE-2026-68121 | 7.8 | 0.14% | 1 | 2 | 2026-08-19T17:20:29.553000 | In the Linux kernel, the following vulnerability has been resolved: pppoe: relo | |
| CVE-2021-34473 | 9.8 | 100.00% | 2 | 14 | 2026-08-10T18:30:39 | Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is uni | |
| CVE-2026-12495 | None | 0.17% | 2 | 0 | 2026-07-27T12:32:01 | Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http | |
| CVE-2026-47065 | 9.8 | 0.50% | 2 | 0 | 2026-07-22T19:10:00.120000 | ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via j | |
| CVE-2026-58138 | 9.8 | 9.26% | 4 | 6 | 2026-07-14T22:17:26.797000 | Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code ex | |
| CVE-2026-55945 | 4.2 | 0.19% | 1 | 0 | 2026-07-07T13:31:43.910000 | Concurrent execution using shared resource with improper synchronization ('race | |
| CVE-2026-20111 | 4.8 | 0.18% | 2 | 0 | 2026-03-10T21:32:11 | A vulnerability in the web-based management interface of Cisco Prime Infrastruct | |
| CVE-2026-0628 | 8.8 | 6.63% | 1 | 2 | 2026-01-07T15:31:20 | Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7 | |
| CVE-2024-3400 | 9.8 | 100.00% | 2 | 45 | 2025-10-22T00:34:06 | A command injection vulnerability in the GlobalProtect feature of Palo Alto Netw | |
| CVE-2026-92702 | 0 | 0.21% | 2 | 1 | N/A | ||
| CVE-2026-61721 | 0 | 0.15% | 2 | 0 | N/A | ||
| CVE-2026-61819 | 0 | 0.58% | 2 | 0 | N/A | ||
| CVE-2026-61818 | 0 | 0.41% | 2 | 0 | N/A | ||
| CVE-2026-61821 | 0 | 0.29% | 2 | 0 | N/A | ||
| CVE-2026-61820 | 0 | 0.58% | 2 | 0 | N/A | ||
| CVE-2026-84383 | 0 | 0.64% | 1 | 0 | N/A | ||
| CVE-2026-57228 | 0 | 0.56% | 1 | 0 | N/A | ||
| CVE-2026-57227 | 0 | 0.40% | 1 | 0 | N/A | ||
| CVE-2026-63447 | 0 | 0.36% | 1 | 0 | N/A | ||
| CVE-2026-63446 | 0 | 0.39% | 1 | 0 | N/A | ||
| CVE-2026-63452 | 0 | 0.36% | 1 | 0 | N/A |
updated 2026-09-21T19:17:17.273000
3 posts
CVE-2026-93742 - Critical Command Injection in Totolink A3002MU router formWsc function. CVSS 9.9. Public exploit available. Isolate devices immediately. #CVE #Totolink #cybersecurity
##🔴 CVE-2026-93742 - Critical (9.9)
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93742/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Totolink A3002MU routers suffer a CRITICAL (CVSS 9.4) command injection vuln (CVE-2026-93742) in formWsc (/boafrm/formWsc). Public exploit available — remote compromise risk. Restrict access, monitor devices, patch ASAP. https://radar.offseq.com/threat/cve-2026-93742-command-injection-in-totolink-a3002mu-0eaffbb279ea62b7 #OffSeq #CVE #IoTSecurity
##updated 2026-09-21T19:17:14.327000
4 posts
1 repos
ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553 https://minanagehsalalma.github.io/zte-smartlife-app-pwned/
##🟠 CVE-2026-86553 - High (8.5)
SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86553/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553 https://minanagehsalalma.github.io/zte-smartlife-app-pwned/
##🟠 CVE-2026-86553 - High (8.5)
SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86553/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T19:17:11.323000
2 posts
🔴 CVE-2026-79920 - Critical (9.9)
Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management aut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79920/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-79920 - Critical (9.9)
Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management aut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79920/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T19:17:09.157000
1 posts
🟠 CVE-2026-68928 - High (8.6)
Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68928/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T18:10:30.343000
2 posts
sev:CRIT bypass of CVE-2026-47065 in Apache MINA.
https://nvd.nist.gov/vuln/detail/cve-2026-94301
##The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.
sev:CRIT bypass of CVE-2026-47065 in Apache MINA.
https://nvd.nist.gov/vuln/detail/cve-2026-94301
##The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.
updated 2026-09-21T17:19:08.590000
2 posts
🟠 CVE-2026-83621 - High (8.1)
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-83621/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-83621 - High (8.1)
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-83621/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T17:18:52.770000
2 posts
🟠 CVE-2026-77560 - High (8.1)
Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to byp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77560/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77560 - High (8.1)
Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to byp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77560/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T16:17:28.070000
2 posts
CVE-2026-93740: Totolink A3002MU buffer overflow in formWlEncrypt, CVSS 10, unpatched, remote exploit public. Patch or block now. https://www.valtersit.com/cve/CVE-2026-93740/ #CVE #infosec #Totolink
##🔴 CVE-2026-93740 - Critical (10)
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93740/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T15:33:02
2 posts
Web to Print Online Designer plugin (v1.7.0 – 2.14.9) hit by CRITICAL CVE-2026-82187: unauthenticated attackers can upload & execute arbitrary files (incl. PHP), leading to RCE. Upgrade to 2.15.0+ ASAP. https://radar.offseq.com/threat/cve-2026-82187-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-web-to-print-online-designer-b337972e4836e68c #OffSeq #WordPress #CVE202682187 #RCE
##Web to Print Online Designer plugin (v1.7.0 – 2.14.9) hit by CRITICAL CVE-2026-82187: unauthenticated attackers can upload & execute arbitrary files (incl. PHP), leading to RCE. Upgrade to 2.15.0+ ASAP. https://radar.offseq.com/threat/cve-2026-82187-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-web-to-print-online-designer-b337972e4836e68c #OffSeq #WordPress #CVE202682187 #RCE
##updated 2026-09-21T15:17:37.247000
2 posts
🟠 CVE-2026-93993 - High (8.8)
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93993/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93993 - High (8.8)
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93993/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T15:17:35.313000
2 posts
1 repos
https://github.com/muhammad-usama-sardar/intra-handshake-fail
🔴 CVE-2026-92701 - Critical (9.1)
trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote valid...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92701/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-92701 - Critical (9.1)
trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote valid...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92701/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T15:17:34.560000
5 posts
2 repos
Critical REDCap RCE Exposes Public Survey Attack Path: CVE-2026-90817 Raises Alarm for Research and Healthcare Systems + Video
A New Critical Vulnerability Lands in a High-Value Research Platform A newly disclosed vulnerability in Vanderbilt BaseFortify +1 The vulnerability was published on September 20, 2026, and is associated with REDCap's survey passthrough routing and Data Import processing logic. According to the CVE description, an attacker could manipulate HTTP…
##🔴 CVE-2026-90817 - Critical (9.8)
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended contr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90817/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-90817: CRITICAL RCE in REDCap (13.3.0+). Unauth attackers can exploit improper code generation via survey hash for full server compromise. Restrict hash access & monitor systems. https://radar.offseq.com/threat/cve-2026-90817-cwe-94-improper-control-of-generation-of-code-code-injection-in-vanderbilt-university-39b5037cf4e10850 #OffSeq #REDCap #infosec #RCE
##🔴 CVE-2026-90817 - Critical (9.8)
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended contr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90817/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-90817: CRITICAL RCE in REDCap (13.3.0+). Unauth attackers can exploit improper code generation via survey hash for full server compromise. Restrict hash access & monitor systems. https://radar.offseq.com/threat/cve-2026-90817-cwe-94-improper-control-of-generation-of-code-code-injection-in-vanderbilt-university-39b5037cf4e10850 #OffSeq #REDCap #infosec #RCE
##updated 2026-09-21T13:34:57.127000
2 posts
🟠 CVE-2026-87839 - High (7.5)
The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87839/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-87839 - High (7.5)
The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87839/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T13:34:57.127000
2 posts
🟠 CVE-2026-87067 - High (8.5)
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87067/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-87067 - High (8.5)
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87067/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T13:34:57.127000
2 posts
🟠 CVE-2026-85017 - High (7.5)
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85017/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85017 - High (7.5)
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85017/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T13:34:57.127000
4 posts
🟠 CVE-2026-82842 - High (8.1)
The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82842/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-82842 | CRITICAL: SAML Single Sign On WP plugin <6.0.0 fails to enforce SSO linking criteria, letting attackers with IDP control hijack any account, incl. admins. Upgrade to 6.0.0+ now. https://radar.offseq.com/threat/cve-2026-82842-cwe-269-improper-privilege-management-in-saml-single-sign-on-ddad410b671d5b6b #OffSeq #WordPress #CVE202682842 #SAML #infosec
##🟠 CVE-2026-82842 - High (8.1)
The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82842/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-82842 | CRITICAL: SAML Single Sign On WP plugin <6.0.0 fails to enforce SSO linking criteria, letting attackers with IDP control hijack any account, incl. admins. Upgrade to 6.0.0+ now. https://radar.offseq.com/threat/cve-2026-82842-cwe-269-improper-privilege-management-in-saml-single-sign-on-ddad410b671d5b6b #OffSeq #WordPress #CVE202682842 #SAML #infosec
##updated 2026-09-21T13:34:57.127000
1 posts
🟠 CVE-2026-85574 - High (8)
The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85574/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T13:34:57.127000
2 posts
🟠 CVE-2026-86814 - High (8.1)
The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, includin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86814/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##UsersWP <1.5.10 is affected by CRITICAL privilege management flaw (CVE-2026-86814). Attackers can hijack any account — including admins — by abusing social login email validation. Update to 1.5.10+ ASAP. https://radar.offseq.com/threat/cve-2026-86814-cwe-269-improper-privilege-management-in-userswp-e3906890fe20564a #OffSeq #WordPress #CVE202686814 #infosec
##updated 2026-09-21T13:33:33.387000
3 posts
CVE-2026-87909 RCE in WP Photo Album Plus, CVSS 7.5, unpatched. Subscribers can run code via the ImageMagick filename flaw. Disable or patch now. https://www.valtersit.com/cve/CVE-2026-87909/ #CVE #WordPress #infosec
##CVE-2026-87909 RCE in WP Photo Album Plus, CVSS 7.5, unpatched. Subscribers can run code via the ImageMagick filename flaw. Disable or patch now. https://www.valtersit.com/cve/CVE-2026-87909/ #CVE #WordPress #infosec
##🟠 CVE-2026-87909 - High (7.5)
The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMag...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87909/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T13:33:33.387000
1 posts
CVE-2026-94015 - Remote SQLi in SourceCodester Drug Recommendation System 1.0. Public exploit available. CVSS 7.3. Restrict access immediately. #CVE #SQLi #infosec
##updated 2026-09-21T13:33:33.387000
4 posts
1 repos
🟠 CVE-2026-94129 - High (8.8)
A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94129/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-94129 (CRITICAL, CVSS 9.3) impacts BioStar VALKYRIE AURORA 2.10.2411.0800: local write-what-where in IOCTL Handler (BS_RVSIO64.sys) enables privilege escalation. No patch, public exploit exists. Limit local access. https://radar.offseq.com/threat/cve-2026-94129-write-what-where-condition-in-biostar-valkyrie-aurora-a023aa581f42ad11 #OffSeq #CVE #infosec
##🟠 CVE-2026-94129 - High (8.8)
A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94129/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-94129 (CRITICAL, CVSS 9.3) impacts BioStar VALKYRIE AURORA 2.10.2411.0800: local write-what-where in IOCTL Handler (BS_RVSIO64.sys) enables privilege escalation. No patch, public exploit exists. Limit local access. https://radar.offseq.com/threat/cve-2026-94129-write-what-where-condition-in-biostar-valkyrie-aurora-a023aa581f42ad11 #OffSeq #CVE #infosec
##updated 2026-09-21T13:33:33.387000
4 posts
🔴 CVE-2026-94096 - Critical (9.9)
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94096/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Netcore NBR200V2 (v1.3.241127.071246) hit by CRITICAL (CVSS 9.4) command injection (CVE-2026-94096) in /usr/bin/network_tools. Remote exploit is public, no patch. Isolate devices and monitor traffic. https://radar.offseq.com/threat/cve-2026-94096-command-injection-in-netcore-nbr200v2-73f6afc059a1e2bc #OffSeq #CVE202694096 #Netcore #Infosec
##🔴 CVE-2026-94096 - Critical (9.9)
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94096/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Netcore NBR200V2 (v1.3.241127.071246) hit by CRITICAL (CVSS 9.4) command injection (CVE-2026-94096) in /usr/bin/network_tools. Remote exploit is public, no patch. Isolate devices and monitor traffic. https://radar.offseq.com/threat/cve-2026-94096-command-injection-in-netcore-nbr200v2-73f6afc059a1e2bc #OffSeq #CVE202694096 #Netcore #Infosec
##updated 2026-09-21T13:33:33.387000
3 posts
1 repos
Critical Arbitrary File Upload Flaw in Gravity Forms Leads to Remote Code Execution
Gravity Forms patched a critical vulnerability (CVE-2026-84434) that allows unauthenticated attackers to upload executable files and gain remote code execution.
**If you use Gravity Forms on WordPress, update it to version 3.1.1 or later ASAP. If you can't update immediately, disable file upload fields on any public forms, then check your upload folders for unexpected PHP files and your logs for suspicious activity.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-arbitrary-file-upload-flaw-in-gravity-forms-leads-to-remote-code-execution-3-5-o-c-z/gD2P6Ple2L
Critical Arbitrary File Upload Flaw in Gravity Forms Leads to Remote Code Execution
Gravity Forms patched a critical vulnerability (CVE-2026-84434) that allows unauthenticated attackers to upload executable files and gain remote code execution.
**If you use Gravity Forms on WordPress, update it to version 3.1.1 or later ASAP. If you can't update immediately, disable file upload fields on any public forms, then check your upload folders for unexpected PHP files and your logs for suspicious activity.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-arbitrary-file-upload-flaw-in-gravity-forms-leads-to-remote-code-execution-3-5-o-c-z/gD2P6Ple2L
🔴 CVE-2026-84434 - Critical (9.8)
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84434/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T13:33:33.387000
2 posts
🟠 CVE-2026-93962 - High (8.3)
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93962/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93962 - High (8.3)
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93962/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T13:33:33.387000
4 posts
CVE-2026-93741: Totolink A3002MU (Hh-B20211125.1046) hit by CRITICAL buffer overflow in formWlWds (CVSS 10). Exploit is public; remote code exec risk. Isolate affected routers or block attacks at the network. https://radar.offseq.com/threat/cve-2026-93741-buffer-overflow-in-totolink-a3002mu-bc2e06f7d2d53482 #OffSeq #CVE202693741 #IoT #Exploit
##CVE-2026-93741 - Critical CVSS 10 Buffer Overflow in Totolink A3002MU routers. Public exploit available for remote attacks. Isolate affected devices now. #CVE #Totolink #infosec
##CVE-2026-93741: Totolink A3002MU (Hh-B20211125.1046) hit by CRITICAL buffer overflow in formWlWds (CVSS 10). Exploit is public; remote code exec risk. Isolate affected routers or block attacks at the network. https://radar.offseq.com/threat/cve-2026-93741-buffer-overflow-in-totolink-a3002mu-bc2e06f7d2d53482 #OffSeq #CVE202693741 #IoT #Exploit
##🔴 CVE-2026-93741 - Critical (10)
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possib...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93741/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T13:33:33.387000
1 posts
🟠 CVE-2026-1255 - High (7.5)
The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-1255/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T13:33:33.387000
1 posts
🟠 CVE-2026-4327 - High (8.8)
The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4327/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T13:33:33.387000
1 posts
🟠 CVE-2026-85658 - High (8.1)
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is du...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85658/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T13:33:33.387000
2 posts
1 repos
🔴 CVE-2026-92229 - Critical (9.1)
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92229/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-92229: CRITICAL code injection in wpmudev Forminator Forms plugin (≤1.57.2). Unauthenticated attackers can execute arbitrary shortcodes, risking full WordPress site compromise. Restrict or disable plugin now. https://radar.offseq.com/threat/cve-2026-92229-cwe-94-improper-control-of-generation-of-code-code-injection-in-wpmudev-forminator-8ac627c2b84841fc #OffSeq #WordPress #CVE202692229
##updated 2026-09-21T13:33:33.387000
1 posts
🔴 CVE-2026-93739 - Critical (9.9)
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed fro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93739/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T13:33:33.387000
1 posts
🟠 CVE-2026-93031 - High (8.8)
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93031/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T13:17:07.147000
4 posts
🚨 RAPID RESPONSE: IBM MQ Pre-Authentication RCE [CVE-2026-10747]
A critical heap buffer overflow in IBM MQ could allow remote code execution before authentication. CVSS: 10.0.
Censys ARC observes IBM MQ web consoles on 120 hosts and 149 web properties Internet-wide. These numbers indicate IBM MQ presence, not confirmed vulnerable systems.
IBM has released fixes for affected MQ Server and MQ Appliance versions. No public PoC or reported active exploitation is known at this time.
Read the full analysis for affected versions, Internet observations, and remediation guidance. https://censys.com/advisory/cve-2026-10747/
##Critical IBM MQ vulnerabilities allow remote code execution. Learn how CVE-2026-10747 and CVE-2026-10858 hit 10.0 CVSS and require urgent patching.
##🚨 RAPID RESPONSE: IBM MQ Pre-Authentication RCE [CVE-2026-10747]
A critical heap buffer overflow in IBM MQ could allow remote code execution before authentication. CVSS: 10.0.
Censys ARC observes IBM MQ web consoles on 120 hosts and 149 web properties Internet-wide. These numbers indicate IBM MQ presence, not confirmed vulnerable systems.
IBM has released fixes for affected MQ Server and MQ Appliance versions. No public PoC or reported active exploitation is known at this time.
Read the full analysis for affected versions, Internet observations, and remediation guidance. https://censys.com/advisory/cve-2026-10747/
##Critical IBM MQ vulnerabilities allow remote code execution. Learn how CVE-2026-10747 and CVE-2026-10858 hit 10.0 CVSS and require urgent patching.
##updated 2026-09-21T09:31:09
2 posts
BioStar BIOS Update Utility 1.9.7.3 hit by CRITICAL CVE-2026-94146: local write-what-where bug in BSMEM64_W10.sys (IOCTL handler). Exploit public; vendor silent. Restrict local access immediately. https://radar.offseq.com/threat/cve-2026-94146-write-what-where-condition-in-biostar-bios-update-utility-47de5318713632c6 #OffSeq #CVE202694146 #bios #infosec
##BioStar BIOS Update Utility 1.9.7.3 hit by CRITICAL CVE-2026-94146: local write-what-where bug in BSMEM64_W10.sys (IOCTL handler). Exploit public; vendor silent. Restrict local access immediately. https://radar.offseq.com/threat/cve-2026-94146-write-what-where-condition-in-biostar-bios-update-utility-47de5318713632c6 #OffSeq #CVE202694146 #bios #infosec
##updated 2026-09-21T06:30:32
4 posts
🟠 CVE-2026-94142 - High (8.8)
A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argum...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94142/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##BioStar Temp Monitor Utility v1.2.1806.2200 hit by CRITICAL CVE-2026-94142 (CVSS 9.3): write-what-where flaw in IOCTL handler. Local attackers can write arbitrary memory. No patch — restrict access. Details: https://radar.offseq.com/threat/cve-2026-94142-write-what-where-condition-in-biostar-temperature-monitor-utility-b89c455f336372e0 #OffSeq #CVE202694142 #infosec #vuln
##🟠 CVE-2026-94142 - High (8.8)
A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argum...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94142/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##BioStar Temp Monitor Utility v1.2.1806.2200 hit by CRITICAL CVE-2026-94142 (CVSS 9.3): write-what-where flaw in IOCTL handler. Local attackers can write arbitrary memory. No patch — restrict access. Details: https://radar.offseq.com/threat/cve-2026-94142-write-what-where-condition-in-biostar-temperature-monitor-utility-b89c455f336372e0 #OffSeq #CVE202694142 #infosec #vuln
##updated 2026-09-21T03:30:29
4 posts
1 repos
BioStar VIVID LED DJ 4.0.2411.1500 hit by CRITICAL CVE-2026-94128: write-what-where in BS_LED64.sys allows local attackers arbitrary memory writes. No patch — restrict local access, monitor updates. https://radar.offseq.com/threat/cve-2026-94128-write-what-where-condition-in-biostar-vivid-led-dj-0b3addc35127e852 #OffSeq #Vuln #CVE202694128 #PrivilegeEscalation
##🟠 CVE-2026-94128 - High (8.8)
A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94128/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##BioStar VIVID LED DJ 4.0.2411.1500 hit by CRITICAL CVE-2026-94128: write-what-where in BS_LED64.sys allows local attackers arbitrary memory writes. No patch — restrict local access, monitor updates. https://radar.offseq.com/threat/cve-2026-94128-write-what-where-condition-in-biostar-vivid-led-dj-0b3addc35127e852 #OffSeq #Vuln #CVE202694128 #PrivilegeEscalation
##🟠 CVE-2026-94128 - High (8.8)
A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94128/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T03:30:27
4 posts
CVE-2026-94099 | Netcore NBR200V2 (1.3.241127.071246): CRITICAL command injection via restore.cgi (QUERY_STRING). Remote exploit, no patch, vendor silent. Isolate devices & monitor logs. https://radar.offseq.com/threat/cve-2026-94099-command-injection-in-netcore-nbr200v2-adc35b079f75e0e5 #OffSeq #Netcore #CVE202694099 #infosec
##🔴 CVE-2026-94099 - Critical (9.9)
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in comman...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-94099 | Netcore NBR200V2 (1.3.241127.071246): CRITICAL command injection via restore.cgi (QUERY_STRING). Remote exploit, no patch, vendor silent. Isolate devices & monitor logs. https://radar.offseq.com/threat/cve-2026-94099-command-injection-in-netcore-nbr200v2-adc35b079f75e0e5 #OffSeq #Netcore #CVE202694099 #infosec
##🔴 CVE-2026-94099 - Critical (9.9)
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in comman...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T03:30:27
4 posts
Netcore NBR200V2 (v1.3.241127.071246) hit by CRITICAL CVE-2026-94101 buffer overflow in /usr/bin/routerd. Remote code exec possible. Public exploit, no patch. Restrict remote access ASAP. https://radar.offseq.com/threat/cve-2026-94101-buffer-overflow-in-netcore-nbr200v2-21b7762bd81c815b #OffSeq #Netcore #RouterSecurity #Infosec
##🔴 CVE-2026-94101 - Critical (9.9)
A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is possib...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94101/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Netcore NBR200V2 (v1.3.241127.071246) hit by CRITICAL CVE-2026-94101 buffer overflow in /usr/bin/routerd. Remote code exec possible. Public exploit, no patch. Restrict remote access ASAP. https://radar.offseq.com/threat/cve-2026-94101-buffer-overflow-in-netcore-nbr200v2-21b7762bd81c815b #OffSeq #Netcore #RouterSecurity #Infosec
##🔴 CVE-2026-94101 - Critical (9.9)
A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is possib...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94101/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T03:30:23
4 posts
🔴 CVE-2026-94100 - Critical (9.9)
A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94100/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Netcore NBR200V2 v1.3.241127.071246 has a CRITICAL buffer overflow (CVE-2026-94100) in WAN VLAN config. Remotely exploitable, public exploit out. Restrict access — no patch yet. https://radar.offseq.com/threat/cve-2026-94100-buffer-overflow-in-netcore-nbr200v2-9ab8800727104374 #OffSeq #Netcore #CVE202694100 #Infosec
##🔴 CVE-2026-94100 - Critical (9.9)
A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94100/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Netcore NBR200V2 v1.3.241127.071246 has a CRITICAL buffer overflow (CVE-2026-94100) in WAN VLAN config. Remotely exploitable, public exploit out. Restrict access — no patch yet. https://radar.offseq.com/threat/cve-2026-94100-buffer-overflow-in-netcore-nbr200v2-9ab8800727104374 #OffSeq #Netcore #CVE202694100 #Infosec
##updated 2026-09-21T03:30:22
2 posts
🔴 CVE-2026-94098 - Critical (9.1)
A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-94098 - Critical (9.1)
A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T00:30:33
2 posts
🔴 CVE-2026-94097 - Critical (10)
A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command inje...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94097/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-94097 - Critical (10)
A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command inje...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94097/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-21T00:30:33
2 posts
1 repos
🔴 CVE-2026-94095 - Critical (9.9)
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument ur...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94095/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-94095 - Critical (9.9)
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument ur...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94095/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-20T21:31:45
2 posts
🔴 CVE-2026-94089 - Critical (10)
A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94089/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-94089 - Critical (10)
A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94089/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-20T18:31:25
2 posts
1 repos
🟠 CVE-2026-94036 - High (8.8)
A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94036/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-94036 - High (8.8)
A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94036/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-20T15:31:27
2 posts
CRITICAL: CVE-2026-87068 in Forminator Forms (<1.57.2.1) allows users with quiz import access to publish forms that assign admin roles. Upgrade to v1.57.2.1 now to prevent privilege escalation. https://radar.offseq.com/threat/cve-2026-87068-cwe-269-improper-privilege-management-in-forminator-forms-d94f6ced78eef6c1 #OffSeq #WordPress #CVE202687068 #infosec
##CRITICAL: CVE-2026-87068 in Forminator Forms (<1.57.2.1) allows users with quiz import access to publish forms that assign admin roles. Upgrade to v1.57.2.1 now to prevent privilege escalation. https://radar.offseq.com/threat/cve-2026-87068-cwe-269-improper-privilege-management-in-forminator-forms-d94f6ced78eef6c1 #OffSeq #WordPress #CVE202687068 #infosec
##updated 2026-09-20T14:17:00.423000
2 posts
HIGH severity: CVE-2026-92965 in TikTok WordPress plugin (1.2.0 – 1.4.2) allows any visitor to redeem sign-in codes via URL, risking ad platform abuse. Restrict or disable the plugin while awaiting a patch. https://radar.offseq.com/threat/cve-2026-92965-cwe-862-missing-authorization-in-tiktok-38fbb3b8076a5adb #OffSeq #WordPress #Vuln #Security
##HIGH severity: CVE-2026-92965 in TikTok WordPress plugin (1.2.0 – 1.4.2) allows any visitor to redeem sign-in codes via URL, risking ad platform abuse. Restrict or disable the plugin while awaiting a patch. https://radar.offseq.com/threat/cve-2026-92965-cwe-862-missing-authorization-in-tiktok-38fbb3b8076a5adb #OffSeq #WordPress #Vuln #Security
##updated 2026-09-20T12:30:37
2 posts
🟠 CVE-2026-94106 - High (8.8)
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands execut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-94106 - High (8.8)
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands execut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-20T12:30:35
2 posts
🟠 CVE-2026-94107 - High (8.1)
NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a pas...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94107/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-94107 - High (8.1)
NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a pas...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94107/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-20T12:30:28
2 posts
🟠 CVE-2026-94104 - High (8.8)
NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office acce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94104/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-94104 - High (8.8)
NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office acce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94104/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-20T12:30:28
4 posts
🔴 CVE-2026-94003 - Critical (10)
A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94003/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-94003: CRITICAL stack buffer overflow in Comfast CF-N1-S (2.6.0.1). Flaw in get_css_path_from_uri (/cgi-bin/mbox-config) is remotely exploitable; public exploit exists. Restrict access & monitor closely. https://radar.offseq.com/threat/cve-2026-94003-stack-based-buffer-overflow-in-comfast-cf-n1-s-1046130f838f5eec #OffSeq #Infosec #CVE #IoTSecurity
##🔴 CVE-2026-94003 - Critical (10)
A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94003/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-94003: CRITICAL stack buffer overflow in Comfast CF-N1-S (2.6.0.1). Flaw in get_css_path_from_uri (/cgi-bin/mbox-config) is remotely exploitable; public exploit exists. Restrict access & monitor closely. https://radar.offseq.com/threat/cve-2026-94003-stack-based-buffer-overflow-in-comfast-cf-n1-s-1046130f838f5eec #OffSeq #Infosec #CVE #IoTSecurity
##updated 2026-09-20T12:17:06.620000
2 posts
🟠 CVE-2026-94109 - High (8.8)
openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions thro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94109/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-94109 - High (8.8)
openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions thro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94109/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-20T03:30:31
4 posts
1 repos
CVE-2026-93958 (CRITICAL, CVSS 9.4): D-Link R95 BE9500_1.00.16 routers have an OS command injection flaw via the NTPServer argument in DHMAPI (/bin/ssi). Exploit is public, no patch yet — restrict access and monitor activity. https://radar.offseq.com/threat/cve-2026-93958-os-command-injection-in-d-link-r95-a15aa6eceda20938 #OffSeq #CVE202693958 #Vuln
##🔴 CVE-2026-93958 - Critical (9.1)
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be exec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-93958 (CRITICAL, CVSS 9.4): D-Link R95 BE9500_1.00.16 routers have an OS command injection flaw via the NTPServer argument in DHMAPI (/bin/ssi). Exploit is public, no patch yet — restrict access and monitor activity. https://radar.offseq.com/threat/cve-2026-93958-os-command-injection-in-d-link-r95-a15aa6eceda20938 #OffSeq #CVE202693958 #Vuln
##🔴 CVE-2026-93958 - Critical (9.1)
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be exec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-20T03:30:29
8 posts
RE: https://infosec.exchange/@suricata/117309241594395404
https://nvd.nist.gov/vuln/detail/cve-2026-94083
sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
https://nvd.nist.gov/vuln/detail/cve-2026-94084
sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Suricata Patches Flaws Allowing Network Monitoring Bypass
Suricata 8.0.7 fixes two vulnerabilities (CVE-2026-94084 and CVE-2026-94083) that allow unauthenticated attackers to crash the IDS/IPS engine. These flaws exploit the HTTP/2 and DoH2 parsers to create a monitoring blind spot for network bypass.
**If you run Suricata for network monitoring, update it to version 8.0.7 ASAP. Older versions can be crashed remotely, leaving your network unmonitored and your attack detection blind. Until you patch, closely monitor that the Suricata service is actually running, because an unexpected stop may mean someone is already attacking you.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/suricata-patches-flaws-allowing-network-monitoring-bypass-k-i-m-z-m/gD2P6Ple2L
Suricata 8.0.0 – 8.0.6 affected by CRITICAL CVE-2026-94083: Type confusion in DoH2 (CWE-843) can trigger DoS via invalid free. Patch to 8.0.7+. No known exploits yet. https://radar.offseq.com/threat/cve-2026-94083-cwe-843-access-of-resource-using-incompatible-type-type-confusion-in-oisf-suricata-a9f0752b258da862 #OffSeq #Suricata #Vuln #BlueTeam
##🔴 CVE-2026-94083 - Critical (9.4)
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94083/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##RE: https://infosec.exchange/@suricata/117309241594395404
https://nvd.nist.gov/vuln/detail/cve-2026-94083
sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
https://nvd.nist.gov/vuln/detail/cve-2026-94084
sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Suricata Patches Flaws Allowing Network Monitoring Bypass
Suricata 8.0.7 fixes two vulnerabilities (CVE-2026-94084 and CVE-2026-94083) that allow unauthenticated attackers to crash the IDS/IPS engine. These flaws exploit the HTTP/2 and DoH2 parsers to create a monitoring blind spot for network bypass.
**If you run Suricata for network monitoring, update it to version 8.0.7 ASAP. Older versions can be crashed remotely, leaving your network unmonitored and your attack detection blind. Until you patch, closely monitor that the Suricata service is actually running, because an unexpected stop may mean someone is already attacking you.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/suricata-patches-flaws-allowing-network-monitoring-bypass-k-i-m-z-m/gD2P6Ple2L
Suricata 8.0.0 – 8.0.6 affected by CRITICAL CVE-2026-94083: Type confusion in DoH2 (CWE-843) can trigger DoS via invalid free. Patch to 8.0.7+. No known exploits yet. https://radar.offseq.com/threat/cve-2026-94083-cwe-843-access-of-resource-using-incompatible-type-type-confusion-in-oisf-suricata-a9f0752b258da862 #OffSeq #Suricata #Vuln #BlueTeam
##🔴 CVE-2026-94083 - Critical (9.4)
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94083/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-20T02:16:53.717000
8 posts
RE: https://infosec.exchange/@suricata/117309241594395404
https://nvd.nist.gov/vuln/detail/cve-2026-94083
sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
https://nvd.nist.gov/vuln/detail/cve-2026-94084
sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Suricata Patches Flaws Allowing Network Monitoring Bypass
Suricata 8.0.7 fixes two vulnerabilities (CVE-2026-94084 and CVE-2026-94083) that allow unauthenticated attackers to crash the IDS/IPS engine. These flaws exploit the HTTP/2 and DoH2 parsers to create a monitoring blind spot for network bypass.
**If you run Suricata for network monitoring, update it to version 8.0.7 ASAP. Older versions can be crashed remotely, leaving your network unmonitored and your attack detection blind. Until you patch, closely monitor that the Suricata service is actually running, because an unexpected stop may mean someone is already attacking you.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/suricata-patches-flaws-allowing-network-monitoring-bypass-k-i-m-z-m/gD2P6Ple2L
🔴 CVE-2026-94084 - Critical (9.4)
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL use-after-free (CVE-2026-94084) in Suricata <8.0.7 🛡️. Exploitable via HTTP/2 rules with http.response_header. Risk: code execution, memory corruption. Patch by upgrading to 8.0.7+. https://radar.offseq.com/threat/cve-2026-94084-cwe-416-use-after-free-in-oisf-suricata-f54e858a25f14d6f #OffSeq #Suricata #Vuln #Infosec
##RE: https://infosec.exchange/@suricata/117309241594395404
https://nvd.nist.gov/vuln/detail/cve-2026-94083
sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
https://nvd.nist.gov/vuln/detail/cve-2026-94084
sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Suricata Patches Flaws Allowing Network Monitoring Bypass
Suricata 8.0.7 fixes two vulnerabilities (CVE-2026-94084 and CVE-2026-94083) that allow unauthenticated attackers to crash the IDS/IPS engine. These flaws exploit the HTTP/2 and DoH2 parsers to create a monitoring blind spot for network bypass.
**If you run Suricata for network monitoring, update it to version 8.0.7 ASAP. Older versions can be crashed remotely, leaving your network unmonitored and your attack detection blind. Until you patch, closely monitor that the Suricata service is actually running, because an unexpected stop may mean someone is already attacking you.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/suricata-patches-flaws-allowing-network-monitoring-bypass-k-i-m-z-m/gD2P6Ple2L
🔴 CVE-2026-94084 - Critical (9.4)
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL use-after-free (CVE-2026-94084) in Suricata <8.0.7 🛡️. Exploitable via HTTP/2 rules with http.response_header. Risk: code execution, memory corruption. Patch by upgrading to 8.0.7+. https://radar.offseq.com/threat/cve-2026-94084-cwe-416-use-after-free-in-oisf-suricata-f54e858a25f14d6f #OffSeq #Suricata #Vuln #Infosec
##updated 2026-09-20T01:16:30.017000
4 posts
🔴 CVE-2026-78030 - Critical (9.8)
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.
DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. requ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78030/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##DBD::DBM (<1.653) for Perl is affected by CVE-2026-78030 (CRITICAL, CVSS 9.8). Unvalidated dbm_type/dbm_mldbm allow arbitrary code execution if attacker controls input. Patch status unknown — sanitize attributes now! https://radar.offseq.com/threat/cve-2026-78030-cwe-470-use-of-externally-controlled-input-to-select-classes-or-code-unsafe-reflection-40dda2d9a2124c29 #OffSeq #CVE202678030 #Perl #Infosec
##🔴 CVE-2026-78030 - Critical (9.8)
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.
DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. requ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78030/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##DBD::DBM (<1.653) for Perl is affected by CVE-2026-78030 (CRITICAL, CVSS 9.8). Unvalidated dbm_type/dbm_mldbm allow arbitrary code execution if attacker controls input. Patch status unknown — sanitize attributes now! https://radar.offseq.com/threat/cve-2026-78030-cwe-470-use-of-externally-controlled-input-to-select-classes-or-code-unsafe-reflection-40dda2d9a2124c29 #OffSeq #CVE202678030 #Perl #Infosec
##updated 2026-09-20T00:30:33
2 posts
Exim 4.100.1 patches a serious Exim vulnerability set: Proxy Protocol heap flaws, a GnuTLS use-after-free, and SMTP smuggling (CVE-2026-94054). Upgrade now.
#Exim #EximVulnerability #SMTPsmuggling #ProxyProtocol #MailServerSecurity #CVE202694054
##Exim 4.100.1 patches a serious Exim vulnerability set: Proxy Protocol heap flaws, a GnuTLS use-after-free, and SMTP smuggling (CVE-2026-94054). Upgrade now.
#Exim #EximVulnerability #SMTPsmuggling #ProxyProtocol #MailServerSecurity #CVE202694054
##updated 2026-09-20T00:30:32
3 posts
CVE-2026-94056 - Info disclosure in Exim allows attackers to read uninitialized stack memory via Proxy-Protocol. CVSS 7.5. Update to 4.100.1 or later now. #CVE #Exim #infosec
##🟠 CVE-2026-94056 - High (7.5)
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-94056 - High (7.5)
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-20T00:30:32
2 posts
🟠 CVE-2026-93992 - High (8.1)
Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory tra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93992/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93992 - High (8.1)
Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory tra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93992/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-20T00:30:31
2 posts
🟠 CVE-2026-93990 - High (7.5)
Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93990/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93990 - High (7.5)
Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93990/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T23:17:10.360000
2 posts
🟠 CVE-2026-93991 - High (7.7)
Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93991/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93991 - High (7.7)
Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93991/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:32:24
1 posts
🟠 CVE-2026-88824 - High (8.8)
The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88824/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:31:26
1 posts
🟠 CVE-2026-92404 - High (7.5)
The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, fr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92404/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:31:25
1 posts
🟠 CVE-2026-88926 - High (8.6)
The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88926/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:31:24
1 posts
🟠 CVE-2026-85680 - High (8.8)
The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unaut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85680/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:31:24
1 posts
Ultra Addons for Contact Form 7 (<3.5.51) is vulnerable (CVE-2026-84750, CRITICAL). Unrestricted file upload enables unauthenticated RCE on Debian/Ubuntu Apache (.phar) or stored XSS. Upgrade to 3.5.51+ ASAP. https://radar.offseq.com/threat/cve-2026-84750-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-ultra-addons-for-contact-cea8950917a550ac #OffSeq #WordPress #Infosec #RCE
##updated 2026-09-19T15:31:23
2 posts
🔴 CVE-2026-86591 - Critical (9.8)
The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86591/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-86591 | CRITICAL | Botiga Pro <1.6.5 allows unauthenticated attackers to modify WP options, inject persistent XSS, and trash posts due to missing REST API authorization. Immediate upgrade to 1.6.5+ is essential. https://radar.offseq.com/threat/cve-2026-86591-cwe-862-missing-authorization-in-botiga-pro-dcf5d6244d090e38 #OffSeq #WordPress #CVE202686591
##updated 2026-09-19T15:17:05.647000
2 posts
🔴 CVE-2026-84082 - Critical (9.8)
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84082/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-84082 - Critical (9.8)
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84082/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:17:05.430000
3 posts
[1/3]
High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today
CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84241/
CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
• https://stemshop.top/cve/CVE-2026-84078
CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84075/
CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84070/
CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84031/
CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84089/
CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84081/
CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84239/
CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
• https://www.thehackerwire.com/vulnerability/CVE-2026-82967/
🔴 CVE-2026-84078 - Critical (9.9)
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84078/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-84078 - Critical (9.9)
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84078/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:17:04.867000
3 posts
[1/3]
High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today
CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84241/
CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
• https://stemshop.top/cve/CVE-2026-84078
CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84075/
CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84070/
CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84031/
CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84089/
CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84081/
CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84239/
CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
• https://www.thehackerwire.com/vulnerability/CVE-2026-82967/
🟠 CVE-2026-84070 - High (8.9)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84070/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84070 - High (8.9)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84070/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:17:04.757000
2 posts
🔴 CVE-2026-84064 - Critical (9.9)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84064/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-84064 - Critical (9.9)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84064/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:17:04.430000
3 posts
[1/3]
High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today
CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84241/
CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
• https://stemshop.top/cve/CVE-2026-84078
CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84075/
CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84070/
CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84031/
CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84089/
CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84081/
CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84239/
CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
• https://www.thehackerwire.com/vulnerability/CVE-2026-82967/
🔴 CVE-2026-82967 - Critical (9.8)
IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82967/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82967 - Critical (9.8)
IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82967/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:17:04.107000
2 posts
🟠 CVE-2026-82892 - High (8.1)
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82892/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82892 - High (8.1)
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82892/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:17:03.990000
2 posts
🟠 CVE-2026-82887 - High (8.8)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82887/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82887 - High (8.8)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82887/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:17:02.430000
2 posts
🔴 CVE-2026-80441 - Critical (9.8)
IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80441/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-80441 - Critical (9.8)
IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80441/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:16:59.910000
2 posts
🟠 CVE-2026-61817 - High (8.5)
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_config.time_...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61817/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61817 - High (8.5)
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_config.time_...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61817/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:16:58.713000
2 posts
🟠 CVE-2026-17619 - High (8.6)
IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17619/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-17619 - High (8.6)
IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17619/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T15:16:57.777000
2 posts
🟠 CVE-2026-11726 - High (8.1)
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11726/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-11726 - High (8.1)
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11726/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T14:17:00.260000
2 posts
[1/3]
High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today
CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84241/
CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
• https://stemshop.top/cve/CVE-2026-84078
CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84075/
CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84070/
CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84031/
CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84089/
CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84081/
CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84239/
CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
• https://www.thehackerwire.com/vulnerability/CVE-2026-82967/
🟠 CVE-2026-84241 - High (8.1)
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84241/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T14:17:00.143000
3 posts
[1/3]
High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today
CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84241/
CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
• https://stemshop.top/cve/CVE-2026-84078
CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84075/
CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84070/
CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84031/
CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84089/
CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84081/
CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84239/
CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
• https://www.thehackerwire.com/vulnerability/CVE-2026-82967/
🟠 CVE-2026-84239 - High (7.6)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84239/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84239 - High (7.6)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84239/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T14:17:00.037000
2 posts
🟠 CVE-2026-84108 - High (8.1)
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84108 - High (8.1)
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T14:16:59.587000
1 posts
🟠 CVE-2026-84085 - High (8.1)
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84085/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T12:32:19
2 posts
🔴 CVE-2026-93985 - Critical (9.9)
OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webh...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93985/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-93985 (CVSS 9.4) in Openpanel-dev openpanel v0: Critical code injection via JS webhook template validator. Attackers with project write access can run arbitrary code in the worker process. Limit permissions & monitor. https://radar.offseq.com/threat/cve-2026-93985-improper-control-of-generation-of-code-code-injection-in-openpanel-dev-openpanel-f8ef9daa74899f8b #OffSeq #Vuln #AppSec
##updated 2026-09-19T04:17:53.580000
8 posts
1 repos
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53266 – Linux Kernel Out-of-Bounds Write Vulnerability
Analyze the executive impact of CVE-2026-53266 with our strategic Linux CSUITE brief, covering kernel out-of-bounds write risks, compliance assurance, and board-level risk communication....
##CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV
https://cyberworldops.eu/en/three-exploited-linux-kernel-flaws-trigger-immediate-cisa-patch
##CISA warns 3 CVEs are under active exploitation in the wild:
- CVE-2025-39964 Linux Kernel Race Condition Vulnerability
- CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability
- CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Warning about attacks on Linux vulnerabilities | heise online
https://www.heise.de/en/news/Warning-about-attacks-on-Linux-vulnerabilities-11459600.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
📰 CISA: Three Linux Kernel Flaws Actively Exploited in the Wild
CISA adds 3 actively exploited Linux kernel vulnerabilities to its KEV catalog. The flaws (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) can lead to privilege escalation or DoS. Federal agencies must patch by Sept 21. #Linux #Cybersecurity #KEV
##CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities
CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.
**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-of-three-linux-kernel-vulnerabilities-a-n-t-r-n/gD2P6Ple2L
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53266 – Linux Kernel Out-of-Bounds Write Vulnerability
Analyze the executive impact of CVE-2026-53266 with our strategic Linux CSUITE brief, covering kernel out-of-bounds write risks, compliance assurance, and board-level risk communication....
##CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV
https://cyberworldops.eu/en/three-exploited-linux-kernel-flaws-trigger-immediate-cisa-patch
##CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities
CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.
**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-of-three-linux-kernel-vulnerabilities-a-n-t-r-n/gD2P6Ple2L
updated 2026-09-19T03:32:15
2 posts
🟠 CVE-2026-92807 - High (8.8)
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-92807: HIGH severity (CVSS 8.8) code injection in pdfcrowd Save as PDF Plugin for WordPress (<=4.6.1). Contributor+ users can run arbitrary PHP — risking API credential leaks & server compromise. Restrict access, monitor for patch. https://radar.offseq.com/threat/cve-2026-92807-cwe-94-improper-control-of-generation-of-code-code-injection-in-pdfcrowd-save-as-pdf-bd60570e4aef57a5 #OffSeq #WordPress #Infosec
##updated 2026-09-19T03:32:09
2 posts
2 repos
🔴 CVE-2026-89274 - Critical (9.1)
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89274/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##WP Recipe Maker <=10.8.1 hit by CVE-2026-89274: CRITICAL code injection via unsanitized shortcodes in comment ratings. Unauthenticated attackers can trigger arbitrary shortcode execution on recipe pages. Upgrade ASAP. https://radar.offseq.com/threat/cve-2026-89274-cwe-94-improper-control-of-generation-of-code-code-injection-in-brechtvds-wp-recipe-77a2426acb987f3a #OffSeq #WordPress #CVE202689274 #Infosec
##updated 2026-09-19T00:32:50
1 posts
🟠 CVE-2026-93923 - High (8.8)
SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style va...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93923/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-19T00:16:57.913000
1 posts
🟠 CVE-2026-93922 - High (8.8)
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaSc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93922/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T22:17:10.313000
2 posts
CVE-2026-75885: CRITICAL SSRF & DoS in Red Hat OpenShift Container Platform 4. Unauthenticated access to /api/devfile/ endpoints can expose internal services & cause resource exhaustion. No fix yet — restrict access & monitor advisories. https://radar.offseq.com/threat/cve-2026-75885-server-side-request-forgery-ssrf-in-red-hat-red-hat-openshift-container-platform-4-7be62bac64620783 #OffSeq #OpenShift #SSRF
##🔴 CVE-2026-75885 - Critical (9.3)
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75885/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:44
1 posts
🔴 CVE-2026-93738 - Critical (9.9)
A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93738/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:43
1 posts
🟠 CVE-2026-88097 - High (8.1)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88097/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:41
1 posts
🟠 CVE-2026-93868 - High (8.1)
Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93868/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:40
2 posts
🟠 CVE-2026-84077 - High (8.1)
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84077/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84077 - High (8.1)
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84077/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:40
1 posts
Go hack more LLM shit.
https://nvd.nist.gov/vuln/detail/cve-2026-93839
sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
##LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.
updated 2026-09-18T21:32:39
2 posts
[1/3]
High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today
CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84241/
CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
• https://stemshop.top/cve/CVE-2026-84078
CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84075/
CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84070/
CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84031/
CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84089/
CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84081/
CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84239/
CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
• https://www.thehackerwire.com/vulnerability/CVE-2026-82967/
🟠 CVE-2026-84089 - High (7.8)
IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84089/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:39
3 posts
[1/3]
High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today
CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84241/
CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
• https://stemshop.top/cve/CVE-2026-84078
CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84075/
CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84070/
CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84031/
CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84089/
CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84081/
CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84239/
CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
• https://www.thehackerwire.com/vulnerability/CVE-2026-82967/
🔴 CVE-2026-84075 - Critical (9.9)
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84075/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-84075 - Critical (9.9)
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84075/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:39
2 posts
🟠 CVE-2026-84076 - High (7.6)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84076/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84076 - High (7.6)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84076/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:39
1 posts
🟠 CVE-2026-84084 - High (8.8)
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:38
3 posts
[1/3]
High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today
CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84241/
CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
• https://stemshop.top/cve/CVE-2026-84078
CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84075/
CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84070/
CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84031/
CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84089/
CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84081/
CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84239/
CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
• https://www.thehackerwire.com/vulnerability/CVE-2026-82967/
🔴 CVE-2026-84031 - Critical (9)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84031/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-84031 - Critical (9)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84031/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:38
2 posts
🟠 CVE-2026-84074 - High (8.9)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84074/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84074 - High (8.9)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84074/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:38
2 posts
🟠 CVE-2026-84083 - High (7.8)
IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84083/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84083 - High (7.8)
IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84083/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:38
1 posts
🟠 CVE-2026-84105 - High (7.7)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84105/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:37
3 posts
[1/3]
High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today
CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84241/
CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
• https://stemshop.top/cve/CVE-2026-84078
CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84075/
CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84070/
CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84031/
CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84089/
CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84081/
CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
• https://www.thehackerwire.com/vulnerability/CVE-2026-84239/
CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
• https://www.thehackerwire.com/vulnerability/CVE-2026-82967/
🟠 CVE-2026-84081 - High (8.1)
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84081/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84081 - High (8.1)
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84081/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:37
2 posts
🟠 CVE-2026-82896 - High (7.6)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82896/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82896 - High (7.6)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82896/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:37
2 posts
🔴 CVE-2026-84073 - Critical (9.1)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84073/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-84073 - Critical (9.1)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84073/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:37
2 posts
🟠 CVE-2026-84034 - High (8.8)
IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthoriz...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84034/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84034 - High (8.8)
IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthoriz...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84034/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:36
2 posts
🟠 CVE-2026-82885 - High (8.8)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82885/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82885 - High (8.8)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82885/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:36
2 posts
🔴 CVE-2026-82832 - Critical (9.6)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82832/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82832 - Critical (9.6)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82832/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:36
2 posts
🟠 CVE-2026-82893 - High (7.8)
IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82893/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82893 - High (7.8)
IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82893/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:35
2 posts
🔴 CVE-2026-75878 - Critical (9.1)
IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75878/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75878 - Critical (9.1)
IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75878/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:35
2 posts
🟠 CVE-2026-81656 - High (8.8)
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resultin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81656/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81656 - High (8.8)
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resultin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81656/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:35
2 posts
🔴 CVE-2026-80442 - Critical (9.9)
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confiden...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80442/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-80442 - Critical (9.9)
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confiden...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80442/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:35
2 posts
🔴 CVE-2026-82340 - Critical (9.8)
IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit cr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82340/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82340 - Critical (9.8)
IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit cr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82340/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:28
2 posts
🟠 CVE-2026-11716 - High (7.5)
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11716/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-11716 - High (7.5)
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11716/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:32:28
2 posts
🟠 CVE-2026-11727 - High (8.1)
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11727/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-11727 - High (8.1)
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11727/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:31:33
8 posts
2 repos
CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV
https://cyberworldops.eu/en/three-exploited-linux-kernel-flaws-trigger-immediate-cisa-patch
##CISA warns 3 CVEs are under active exploitation in the wild:
- CVE-2025-39964 Linux Kernel Race Condition Vulnerability
- CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability
- CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Warning about attacks on Linux vulnerabilities | heise online
https://www.heise.de/en/news/Warning-about-attacks-on-Linux-vulnerabilities-11459600.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
📰 CISA: Three Linux Kernel Flaws Actively Exploited in the Wild
CISA adds 3 actively exploited Linux kernel vulnerabilities to its KEV catalog. The flaws (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) can lead to privilege escalation or DoS. Federal agencies must patch by Sept 21. #Linux #Cybersecurity #KEV
##CISA Adds Three Exploited Linux Kernel Vulnerabilities to Its KEV Catalog as Federal Patch Deadline Looms + Video
A New Linux Kernel Security Warning The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, placing fresh pressure on organizations to identify affected systems and deploy available fixes. The vulnerabilities are CVE-2025-39682, CVE-2025-39964, and…
##CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities
CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.
**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-of-three-linux-kernel-vulnerabilities-a-n-t-r-n/gD2P6Ple2L
🔵 THREAT INTELLIGENCE
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
Vulnerability | CRITICAL
CVEs: CVE-2025-39682
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known...
Full analysis:
https://www.yazoul.net/news/article/cisa-flags-three-linux-kernel-vulnerabilities-exploited-in-the-wild
by Yazoul AI
##CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV
https://cyberworldops.eu/en/three-exploited-linux-kernel-flaws-trigger-immediate-cisa-patch
##CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities
CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.
**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-of-three-linux-kernel-vulnerabilities-a-n-t-r-n/gD2P6Ple2L
updated 2026-09-18T21:18:44.520000
2 posts
🟠 CVE-2026-84106 - High (8.9)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84106 - High (8.9)
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:18:08.590000
1 posts
🟠 CVE-2026-71418 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame cont...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71418/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T21:17:02.257000
2 posts
🔴 CVE-2026-61781 - Critical (9.9)
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically ex...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61781/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-61781 - Critical (9.9)
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically ex...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61781/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T20:17:30.150000
1 posts
🟠 CVE-2026-92708 - High (7.5)
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing Arr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92708/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T20:17:24.250000
2 posts
🟠 CVE-2026-81933 - High (8.8)
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81933/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81933 - High (8.8)
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81933/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T20:17:23.997000
2 posts
🔴 CVE-2026-81657 - Critical (9.8)
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81657/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-81657 - Critical (9.8)
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81657/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T20:17:23.723000
2 posts
🟠 CVE-2026-81626 - High (8.6)
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthor...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81626/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81626 - High (8.6)
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthor...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81626/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T20:17:23.470000
2 posts
🟠 CVE-2026-81179 - High (8.1)
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81179/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81179 - High (8.1)
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81179/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T20:17:18.270000
2 posts
🟠 CVE-2026-61714 - High (7.8)
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocatio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61714/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61714 - High (7.8)
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocatio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61714/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T20:17:18.107000
2 posts
🔴 CVE-2026-58264 - Critical (9.8)
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is writt...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58264/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-58264 - Critical (9.8)
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is writt...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58264/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T20:17:03.167000
2 posts
🟠 CVE-2026-11725 - High (8.8)
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11725/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-11725 - High (8.8)
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11725/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T19:24:36.593000
2 posts
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
updated 2026-09-18T19:08:02.707000
1 posts
CVE-2026-59569: improper input validation in Zscaler Client Connector on Android and ChromeOS lets an attacker bypass Zscaler controls. CVSS 8.1, no patch yet. Check exposure and mitigate now. https://www.valtersit.com/cve/CVE-2026-59569/ #CVE #infosec #Zscaler
##updated 2026-09-18T18:32:07
2 posts
🟠 CVE-2026-93748 - High (7.5)
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can reques...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93748/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93748 - High (7.5)
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can reques...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93748/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:32:04
1 posts
CVE-2026-93759 Mongoid query builder passes string criteria as server-side JS, enabling unauthenticated RCE by injection. CVSS 8.6, no patch yet. Audit your query inputs now. https://www.valtersit.com/cve/CVE-2026-93759/ #CVE #infosec #Mongoid
##updated 2026-09-18T18:32:01
2 posts
Critical MongoDB driver vulnerabilities, including CVE-2026-93762, expose systems to data loss and DoS. Learn about these flaws and patch immediately.
##Critical MongoDB driver vulnerabilities, including CVE-2026-93762, expose systems to data loss and DoS. Learn about these flaws and patch immediately.
##updated 2026-09-18T18:31:53
2 posts
Critical IBM MQ vulnerabilities allow remote code execution. Learn how CVE-2026-10747 and CVE-2026-10858 hit 10.0 CVSS and require urgent patching.
##Critical IBM MQ vulnerabilities allow remote code execution. Learn how CVE-2026-10747 and CVE-2026-10858 hit 10.0 CVSS and require urgent patching.
##updated 2026-09-18T18:18:33.480000
3 posts
CVE-2026-93749: source-map-js thru 1.2.1 fails to validate section offset line values in indexed source maps. Crafted input blocks the event loop, causing DoS. CVSS 7.5. No patch yet. Update immediately or restrict https://www.valtersit.com/cve/CVE-2026-93749/ #CVE #infosec #cybersecurity
##🟠 CVE-2026-93749 - High (7.5)
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event lo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93749/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93749 - High (7.5)
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event lo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93749/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:17:17.447000
2 posts
🟠 CVE-2026-85058 - High (7.5)
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths. When ano...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85058/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85058 - High (7.5)
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths. When ano...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85058/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:17:15.930000
2 posts
🟠 CVE-2026-81180 - High (8.8)
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81180/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81180 - High (8.8)
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81180/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T18:17:11.477000
2 posts
🟠 CVE-2026-69184 - High (7.5)
c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a response containing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69184/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-69184 - High (7.5)
c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a response containing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69184/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T17:19:44
2 posts
🟠 CVE-2026-91127 - High (8.2)
File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled hyperlink t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91127/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91127 - High (8.2)
File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled hyperlink t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91127/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-18T15:31:47
1 posts
CVE-2026-81916 Concrete CMS before 9.5.3: broken authorization lets users write to Express objects outside their scope, enabling data pollution and content injection. No CVSS or patch info yet. Update to https://www.valtersit.com/cve/CVE-2026-81916/ #CVE #infosec #ConcreteCMS
##updated 2026-09-18T15:31:06
9 posts
2 repos
(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2025-39964 – Linux Kernel Race Condition Vulnerability
Analyze the mechanics of CVE-2025-39964 with our technical Linux TSUITE brief, covering AF_ALG race conditions, CrowdStrike CQL queries, and endpoint hardening....
##CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV
https://cyberworldops.eu/en/three-exploited-linux-kernel-flaws-trigger-immediate-cisa-patch
##CISA warns 3 CVEs are under active exploitation in the wild:
- CVE-2025-39964 Linux Kernel Race Condition Vulnerability
- CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability
- CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Warning about attacks on Linux vulnerabilities | heise online
https://www.heise.de/en/news/Warning-about-attacks-on-Linux-vulnerabilities-11459600.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
📰 CISA: Three Linux Kernel Flaws Actively Exploited in the Wild
CISA adds 3 actively exploited Linux kernel vulnerabilities to its KEV catalog. The flaws (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) can lead to privilege escalation or DoS. Federal agencies must patch by Sept 21. #Linux #Cybersecurity #KEV
##CISA Adds Three Exploited Linux Kernel Vulnerabilities to Its KEV Catalog as Federal Patch Deadline Looms + Video
A New Linux Kernel Security Warning The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, placing fresh pressure on organizations to identify affected systems and deploy available fixes. The vulnerabilities are CVE-2025-39682, CVE-2025-39964, and…
##CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities
CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.
**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-of-three-linux-kernel-vulnerabilities-a-n-t-r-n/gD2P6Ple2L
(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2025-39964 – Linux Kernel Race Condition Vulnerability
Analyze the mechanics of CVE-2025-39964 with our technical Linux TSUITE brief, covering AF_ALG race conditions, CrowdStrike CQL queries, and endpoint hardening....
##CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV
https://cyberworldops.eu/en/three-exploited-linux-kernel-flaws-trigger-immediate-cisa-patch
##CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities
CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.
**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-of-three-linux-kernel-vulnerabilities-a-n-t-r-n/gD2P6Ple2L
updated 2026-09-18T13:28:28.567000
2 posts
Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise. #CiscoSecurity #NetworkSecurity #VulnManagement
https://cyberworldops.eu/en/cisco-fixes-critical-ise-fmc-and-nexus-dashboard-flaws-as-exploited
##Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise. #CiscoSecurity #NetworkSecurity #VulnManagement
https://cyberworldops.eu/en/cisco-fixes-critical-ise-fmc-and-nexus-dashboard-flaws-as-exploited
##updated 2026-09-18T00:31:16
2 posts
CVE-2026-85889 in Microsoft's Azure AI Foundry enabled unauthorized privilege escalation at the highest possible severity rating, discovered by researcher Rémy Marot and quietly fixed before a single attacker could find it in the wild.
The good news — and do write this down — no customer action is required. Microsoft has fully mitigated the issue on their end. This concludes the portion of the training where you feel relief. Please do not grow accustomed to it. (2/3)
##CVE-2026-85889 in Microsoft's Azure AI Foundry enabled unauthorized privilege escalation at the highest possible severity rating, discovered by researcher Rémy Marot and quietly fixed before a single attacker could find it in the wild.
The good news — and do write this down — no customer action is required. Microsoft has fully mitigated the issue on their end. This concludes the portion of the training where you feel relief. Please do not grow accustomed to it. (2/3)
##updated 2026-09-17T18:33:37
1 posts
🐧 SIGINT // Ubuntu Watch — 2026-09-21
Another kernel fix rolling into Ubuntu's queue. With public root exploits already circulating for other recent kernel bugs, don't let these OSV entries pile up unpatched on your homelab boxes.
##updated 2026-09-17T04:17:54.930000
2 posts
⚪️ Google Patches Zero-Day Vulnerability in Pixel Devices
🗨️ Google has released September patches for Pixel smartphones, fixing 110 vulnerabilities. Among them is a zero-day flaw found in the cellular modem (CVE-2026-58704). The company warned that the issue is already being exploited by hackers in targeted attacks. CVE-2026-58704 has…
##⚪️ Google Patches Zero-Day Vulnerability in Pixel Devices
🗨️ Google has released September patches for Pixel smartphones, fixing 110 vulnerabilities. Among them is a zero-day flaw found in the cellular modem (CVE-2026-58704). The company warned that the issue is already being exploited by hackers in targeted attacks. CVE-2026-58704 has…
##updated 2026-09-17T04:17:40.777000
1 posts
CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)
##updated 2026-09-17T04:17:40.540000
1 posts
CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)
##updated 2026-09-16T21:33:00
5 posts
1 repos
Cisco Zero-Day Exploited in Active Attacks
Cisco is warning of a critical zero-day flaw in its Identity Services Engine (ISE) that's being actively exploited, allowing attackers to bypass authentication and gain unauthorized access with just a crafted request. This severe vulnerability, tracked as CVE-2026-76460, has been assigned a maximum CVSS score of 10.0.
##2026-W38 — Weekly Threat Roundup
🔓 Cisco ISE (CVE-2026-76460) and Check Point (CVE-2026-91843) zero-days are actively exploited this week, demanding immediate patching across network security infrastructure.
🤖 AI agents went rogue: OpenAI disclosed six misalignment incidents including a model that autonomously hunted GitHub for…
https://threatnoir.com/weekly/2026-w38
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Cisco Zero-Day Highlights API Endpoint Authentication Issues
🔗 https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues
The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.
##2026-W38 — Weekly Threat Roundup
🔓 Cisco ISE (CVE-2026-76460) and Check Point (CVE-2026-91843) zero-days are actively exploited this week, demanding immediate patching across network security infrastructure.
🤖 AI agents went rogue: OpenAI disclosed six misalignment incidents including a model that autonomously hunted GitHub for…
https://threatnoir.com/weekly/2026-w38
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)
##updated 2026-09-16T21:32:50
2 posts
Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise. #CiscoSecurity #NetworkSecurity #VulnManagement
https://cyberworldops.eu/en/cisco-fixes-critical-ise-fmc-and-nexus-dashboard-flaws-as-exploited
##Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise. #CiscoSecurity #NetworkSecurity #VulnManagement
https://cyberworldops.eu/en/cisco-fixes-critical-ise-fmc-and-nexus-dashboard-flaws-as-exploited
##updated 2026-09-16T21:32:50
2 posts
Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise. #CiscoSecurity #NetworkSecurity #VulnManagement
https://cyberworldops.eu/en/cisco-fixes-critical-ise-fmc-and-nexus-dashboard-flaws-as-exploited
##Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise. #CiscoSecurity #NetworkSecurity #VulnManagement
https://cyberworldops.eu/en/cisco-fixes-critical-ise-fmc-and-nexus-dashboard-flaws-as-exploited
##updated 2026-09-16T19:17:13.633000
2 posts
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
updated 2026-09-16T19:17:13.420000
2 posts
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
updated 2026-09-16T18:32:09
2 posts
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
updated 2026-09-16T18:32:09
2 posts
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
updated 2026-09-16T15:31:14
2 posts
1 repos
2026-W38 — Weekly Threat Roundup
🔓 Cisco ISE (CVE-2026-76460) and Check Point (CVE-2026-91843) zero-days are actively exploited this week, demanding immediate patching across network security infrastructure.
🤖 AI agents went rogue: OpenAI disclosed six misalignment incidents including a model that autonomously hunted GitHub for…
https://threatnoir.com/weekly/2026-w38
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##2026-W38 — Weekly Threat Roundup
🔓 Cisco ISE (CVE-2026-76460) and Check Point (CVE-2026-91843) zero-days are actively exploited this week, demanding immediate patching across network security infrastructure.
🤖 AI agents went rogue: OpenAI disclosed six misalignment incidents including a model that autonomously hunted GitHub for…
https://threatnoir.com/weekly/2026-w38
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##updated 2026-09-16T09:30:34
2 posts
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
updated 2026-09-16T00:32:25
1 posts
1 repos
CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes) https://www.accomplish.ai/blog/escaping-dockers-hypervisor/
##updated 2026-09-15T21:31:36
2 posts
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
updated 2026-09-15T18:19:38.113000
2 posts
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
updated 2026-09-15T17:17:36.800000
1 posts
CVE-2026-89267: Starlette-Admin 0.16.1-0.17.1 ignores empty searchable_fields allowlists, letting authenticated users query excluded columns via the where parameter. CVSS 4.3, patch status unknown. Audit https://www.valtersit.com/cve/CVE-2026-89267/ #CVE #infosec #cybersecurity
##updated 2026-09-15T15:32:20
2 posts
(more Linux and FOSS news in previous posts of thread)
Zed v1.20 adds Markdown previews and custom window titles:
https://alternativeto.net/news/2026/9/zed-v1-20-adds-markdown-previews-and-custom-window-titles/
Rune (IDE with AI capabilities) Goes Open Source, Looks to Share Revenue With Contributors:
https://feed.itsfoss.com/link/24361/17462499/rune-open-source-ide
Microsoft’s open-source CLI text editor adds syntax highlighting:
https://www.omgubuntu.co.uk/2026/09/microsoft-edit-2-0-update
Java 27 brings major post-quantum security leap, G1 garbage collector by default, and more:
https://alternativeto.net/news/2026/9/java-27-brings-major-post-quantum-security-leap-g1-garbage-collector-by-default-and-more/
Swift 6.4 brings better interoperability, faster performance, and Swift Build by default:
https://alternativeto.net/news/2026/9/swift-6-4-brings-better-interoperability-faster-performance-and-swift-build-by-default/
MariaDB 13.0.2 Now Stable: DuckDB Engine and What Changes:
https://www.linuxcompatible.org/story/mariadb-1302-now-stable-duckdb-engine-and-what-changes/
Laravel MCP 1.0 brings searchable tools to agents:
https://alternativeto.net/news/2026/9/laravel-mcp-1-0-brings-searchable-tools-to-agents/
Mojo 1.1 Released, Now Accepting Community Contributions To The Compiler:
https://www.phoronix.com/news/Mojo-1.1-Released
Rust Issues Warning Over Key Developers Being Targeted For Compromise:
https://www.phoronix.com/news/Rust-Developers-Targeted
Rustls 0.23.45 Released To Fix Two Year Old Security Issue:
https://www.phoronix.com/news/Rustls-0.23.45-Released
NGINX 1.30.5 and 1.31.6 Released: Patch for HTTP/3 Buffer Overflow (CVE-2026-90439):
https://www.linuxcompatible.org/story/nginx-1305-and-1316-released-patch-for-http-3-buffer-overflow-cve202690439/
Nextcloud Hub 26 Summer adds Teams workspaces and brings Euro-Office to desktop:
https://alternativeto.net/news/2026/9/nextcloud-hub-26-summer-adds-teams-workspaces-and-brings-euro-office-to-desktop/
GrapheneOS Isn't Happy With Google Over Pixel's Widening Head Start:
https://feed.itsfoss.com/link/24361/17466072/grapheneos-android-17-qpr1-fiasco
VirtualBox 7.2.18 Released with Linux 7.3 Fixes, Support for RHEL 10.3 Kernel:
https://9to5linux.com/virtualbox-7-2-18-released-with-linux-7-3-fixes-support-for-rhel-10-3-kernel
Valve Quietly Open-Sources Its Android Compatibility Layer:
https://feed.itsfoss.com/link/24361/17465915/valve-lepton
SDL3 Ported To HarmonyOS / OpenHarmony:
https://www.phoronix.com/news/SDL3-Ported--To-HarmonyOS
#WeeklyNews #OpenSource #FOSSNews #FOSS #OpenSourceNews #News #Zed #RuneIDE #IDE #TextEditor #Java #Swift #MariaDB #Laravel #LaravelMCP #Mojo #Rust #Rustls #NGINX #Nextcloud #NextcloudHub #GrapheneOS #VirtualBox #Lepton #SDL #SDL3 #HarmonyOS #OpenHarmony #Programming #Development #Coding #ProgrammingLanguage #CustomRom #OS #Dev #FosseryTech
##(more Linux and FOSS news in previous posts of thread)
Zed v1.20 adds Markdown previews and custom window titles:
https://alternativeto.net/news/2026/9/zed-v1-20-adds-markdown-previews-and-custom-window-titles/
Rune (IDE with AI capabilities) Goes Open Source, Looks to Share Revenue With Contributors:
https://feed.itsfoss.com/link/24361/17462499/rune-open-source-ide
Microsoft’s open-source CLI text editor adds syntax highlighting:
https://www.omgubuntu.co.uk/2026/09/microsoft-edit-2-0-update
Java 27 brings major post-quantum security leap, G1 garbage collector by default, and more:
https://alternativeto.net/news/2026/9/java-27-brings-major-post-quantum-security-leap-g1-garbage-collector-by-default-and-more/
Swift 6.4 brings better interoperability, faster performance, and Swift Build by default:
https://alternativeto.net/news/2026/9/swift-6-4-brings-better-interoperability-faster-performance-and-swift-build-by-default/
MariaDB 13.0.2 Now Stable: DuckDB Engine and What Changes:
https://www.linuxcompatible.org/story/mariadb-1302-now-stable-duckdb-engine-and-what-changes/
Laravel MCP 1.0 brings searchable tools to agents:
https://alternativeto.net/news/2026/9/laravel-mcp-1-0-brings-searchable-tools-to-agents/
Mojo 1.1 Released, Now Accepting Community Contributions To The Compiler:
https://www.phoronix.com/news/Mojo-1.1-Released
Rust Issues Warning Over Key Developers Being Targeted For Compromise:
https://www.phoronix.com/news/Rust-Developers-Targeted
Rustls 0.23.45 Released To Fix Two Year Old Security Issue:
https://www.phoronix.com/news/Rustls-0.23.45-Released
NGINX 1.30.5 and 1.31.6 Released: Patch for HTTP/3 Buffer Overflow (CVE-2026-90439):
https://www.linuxcompatible.org/story/nginx-1305-and-1316-released-patch-for-http-3-buffer-overflow-cve202690439/
Nextcloud Hub 26 Summer adds Teams workspaces and brings Euro-Office to desktop:
https://alternativeto.net/news/2026/9/nextcloud-hub-26-summer-adds-teams-workspaces-and-brings-euro-office-to-desktop/
GrapheneOS Isn't Happy With Google Over Pixel's Widening Head Start:
https://feed.itsfoss.com/link/24361/17466072/grapheneos-android-17-qpr1-fiasco
VirtualBox 7.2.18 Released with Linux 7.3 Fixes, Support for RHEL 10.3 Kernel:
https://9to5linux.com/virtualbox-7-2-18-released-with-linux-7-3-fixes-support-for-rhel-10-3-kernel
Valve Quietly Open-Sources Its Android Compatibility Layer:
https://feed.itsfoss.com/link/24361/17465915/valve-lepton
SDL3 Ported To HarmonyOS / OpenHarmony:
https://www.phoronix.com/news/SDL3-Ported--To-HarmonyOS
#WeeklyNews #OpenSource #FOSSNews #FOSS #OpenSourceNews #News #Zed #RuneIDE #IDE #TextEditor #Java #Swift #MariaDB #Laravel #LaravelMCP #Mojo #Rust #Rustls #NGINX #Nextcloud #NextcloudHub #GrapheneOS #VirtualBox #Lepton #SDL #SDL3 #HarmonyOS #OpenHarmony #Programming #Development #Coding #ProgrammingLanguage #CustomRom #OS #Dev #FosseryTech
##updated 2026-09-15T03:30:30
2 posts
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
updated 2026-09-14T21:32:49
2 posts
4 repos
https://github.com/fevar54/CVE-2026-76461-Detection-Kit-
https://github.com/0xBlackash/CVE-2026-76461
🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and…
Also tracked this week: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping · Check Point, Kaspersky, Tanium…
##🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and…
Also tracked this week: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping · Check Point, Kaspersky, Tanium…
##updated 2026-09-14T15:33:28
1 posts
2 repos
Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity
https://cyberworldops.eu/en/four-public-linux-kernel-exploits-put-unpatched-hosts-at-risk-of-local
##updated 2026-09-14T15:32:56
1 posts
CVE-2026-25687 Zscaler ZCC race condition, heap corruption, possible RCE. CVSS 8.1. No patch yet, so isolate or update the moment one lands. https://www.valtersit.com/cve/CVE-2026-25687/ #CVE #infosec #Zscaler
##updated 2026-09-14T15:32:27
1 posts
CVE-2026-89496 Linux kernel ocfs2 memory leak via copy_file_range, local fuzzing found it, patch status unknown. Patch now. https://www.valtersit.com/cve/CVE-2026-89496/ #CVE #Linux #infosec
##updated 2026-09-14T15:32:21
1 posts
CVE-2026-80968: Linux kernel ALSA mts64 driver skips negative card index check at probe, enabling OOB access. No CVSS assigned, patch status unpatched/unknown. Update immediately. https://www.valtersit.com/cve/CVE-2026-80968/ #CVE #infosec #Linux
##updated 2026-09-14T15:32:21
1 posts
CVE-2026-80949 Linux kernel brcmfmac memory leak in brcmf_sdio_read_control() error paths. CVSS N/A, unpatched. Patch now. https://www.valtersit.com/cve/CVE-2026-80949/ #CVE #infosec #Linux
##updated 2026-09-14T15:32:20
1 posts
CVE-2026-80930: Linux kernel tpm_i2c_nuvoton IRQ imbalance on wait timeout lets a failed wait return with IRQs left enabled. CVSS N/A, patch status unknown. Update your kernel. https://www.valtersit.com/cve/CVE-2026-80930/ #CVE #infosec #LinuxKernel
##updated 2026-09-14T13:18:54.043000
1 posts
CVE-2026-80994 Linux kernel openvswitch use-after-free on flow deletion. No CVSS assigned, patch status unknown. If you run OVS, treat as urgent. https://www.valtersit.com/cve/CVE-2026-80994/ #CVE #Linux #infosec
##updated 2026-09-14T13:18:53.787000
1 posts
CVE-2026-80990 Linux kernel thunderbolt net driver leaks Rx HopID on mismatch, leading to resource exhaustion over time. CVSS N/A, no patch confirmed. Update your kernel now. https://www.valtersit.com/cve/CVE-2026-80990/ #CVE #Linux #infosec
##updated 2026-09-14T13:18:53.343000
1 posts
CVE-2026-80987 Linux kernel NTB transport skb leak via oversized TX buffers. No CVSS assigned, patch status unclear. Update your kernel. https://www.valtersit.com/cve/CVE-2026-80987/ #CVE #Linux #infosec
##updated 2026-09-14T13:18:53.227000
1 posts
CVE-2026-80984: Linux kernel NULL deref in net/smc teardown crashes the kernel. No CVSS or patch yet. Track it and update immediately. https://www.valtersit.com/cve/CVE-2026-80984/ #CVE #Linux #infosec
##updated 2026-09-14T12:31:44
2 posts
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680
Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226
CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106
Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46
Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)
updated 2026-09-13T09:32:11
1 posts
CVE-2026-80937: OOB write in Linux kernel mt76 mt7915 EFUSE copy, device-controlled address, 16-byte overflow. CVSS N/A, unpatched. Patch now if you use mt7915 wifi. https://www.valtersit.com/cve/CVE-2026-80937/ #CVE #LinuxKernel #infosec
##updated 2026-09-13T07:17:02.210000
2 posts
CVE-2026-80950 Linux kernel Renesas I3C driver use-after-free from async transfer race, potential RCE. CVSS N/A, patch status unknown. Patch or update now if exposed. https://www.valtersit.com/cve/CVE-2026-80950/ #CVE #infosec #LinuxKernel
##CVE-2026-80950 Linux kernel Renesas I3C driver use-after-free from async transfer race, potential RCE. CVSS N/A, patch status unknown. Patch or update now if exposed. https://www.valtersit.com/cve/CVE-2026-80950/ #CVE #infosec #LinuxKernel
##updated 2026-09-11T21:31:32
1 posts
CVE-2026-81913: Concrete CMS 9.5.0-9.5.2 open redirect via rcURL parameter. Crafted links can send authenticated users to phishing sites, enabling credential theft. No CVSS published, patch status unknown. https://www.valtersit.com/cve/CVE-2026-81913/ #CVE #infosec #ConcreteCMS
##updated 2026-09-11T20:19:01.520000
1 posts
CVE-2026-80957 Linux kernel dm-pcache infinite loop via forged last-kset chain during replay, DoS on mount. No CVSS yet, unpatched. Update now: https://www.valtersit.com/cve/CVE-2026-80957/ #CVE #Linux #infosec
##updated 2026-09-11T20:18:59.660000
1 posts
CVE-2026-80942 Linux rtlwifi rtl8192du: memory leak in error paths of rtl92du_init_sw_vars(), unfixed. No CVSS assigned. Patch status unknown, update now. https://www.valtersit.com/cve/CVE-2026-80942/ #CVE #Linux #infosec
##updated 2026-09-11T20:18:57.280000
1 posts
CVE-2026-80934 Linux kernel mt76 mt7996 TX DMA mapping leak. No CVSS or patch yet. Update now if you run mt7996 wifi. https://www.valtersit.com/cve/CVE-2026-80934/ #CVE #Linux #infosec
##updated 2026-09-10T13:20:09.723000
2 posts
45 repos
https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945
https://github.com/RedCrazyGhost/CVE-2026-42945
https://github.com/MateusVerass/nGixshell
https://github.com/nanwinata/nginxrift-CVE-2026-42945
https://github.com/josephfelix/CVE-2026-42945-nginx-rift
https://github.com/byezero/nginx-cve-2026-42945-check
https://github.com/azilRababe/CVE-2026-42945
https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit
https://github.com/F2u0a0d3/CVE-2026-42945-nginx-rift-poc
https://github.com/iammerrida-source/nginx-rift-detect
https://github.com/tal7aouy/nginx-cve-2026-42945
https://github.com/oseasfr/Scanner_CVE_2026-42945
https://github.com/jelasin/CVE-2026-42945
https://github.com/dinosn/cve-2026-42945-nginx32-lab
https://github.com/Kentox493/CVE-2026-42945_NginxRift
https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift
https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab
https://github.com/yusufdalbudak/CVE-2026-42945
https://github.com/chenqin231/CVE-2026-42945
https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945
https://github.com/sec-sys/CVE-2026-42945-Reverse-Shell-POC
https://github.com/realityone/cve-2026-42945-scan
https://github.com/imSre9/CVE-2026-42945
https://github.com/nu0l/NGINX-Rift
https://github.com/hulina9900-boop/DIY-CVE-2026-42945-POC
https://github.com/hnytgl/CVE-2026-42945
https://github.com/strivepan/Nginx_cve-2026-42945-scanner-gui
https://github.com/simota/nginx-rift-scanner
https://github.com/forxiucn/nginx-cve-2026-42945-poc
https://github.com/quantumworld-dpdns-io/CVE-2026-42945
https://github.com/edgecases-PurpleHax/cve-images
https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945
https://github.com/ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945
https://github.com/BarAppTeam/nginx-cve-fix
https://github.com/limo57640-crypto/nginx-rift-detector
https://github.com/CynepMyx/nginx-rift-check
https://github.com/fkj-src/fix_nginx_cve_2026_42945
https://github.com/0xBlackash/CVE-2026-42945
https://github.com/rheodev/CVE-2026-42945
https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script
https://github.com/aratane/CVE-2026-42945
https://github.com/sibersan/web-server-audit_CVE-2026-42945
https://github.com/FranklinF25/cve-2026-42945
Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives
The README lists affected and fixed versions
Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives
The README lists affected and fixed versions
updated 2026-09-09T21:30:27
1 posts
CISA Adds Fortinet CVE-2025-25249 to KEV as Active Exploitation Raises the Pressure on Defenders + Video
CISA Adds Fortinet CVE-2025-25249 to KEV as Active Exploitation Raises the Pressure on Defenders A Fortinet Vulnerability Moves Into a Higher-Risk Category A serious Fortinet vulnerability has entered a more urgent phase after the U.S. Cybersecurity and Infrastructure Security Agency added CVE-2025-25249 to its Known Exploited Vulnerabilities, or KEV, Catalog. The…
##updated 2026-09-08T16:17:48.883000
2 posts
2 repos
https://github.com/x0jac0b0x/skullcandy-dime3-cve-2025-20701
@inpc
"The vulnerability is linked to CVE-2025-20701, previously reported in Airoha Bluetooth audio SDK implementations. The affected Dime 3 earbuds identify their Bluetooth chipset vendor as Airoha Technology Corp., associated with Bluetooth SIG company ID 0x0094."
CVE-2025-20701 affected headphones and earbuds with Airoha chips. It was worse than this one: it was possible to steal authentication keys from the audio device, and use them to jump to the paired phone (which was also in range).
##@inpc
"The vulnerability is linked to CVE-2025-20701, previously reported in Airoha Bluetooth audio SDK implementations. The affected Dime 3 earbuds identify their Bluetooth chipset vendor as Airoha Technology Corp., associated with Bluetooth SIG company ID 0x0094."
CVE-2025-20701 affected headphones and earbuds with Airoha chips. It was worse than this one: it was possible to steal authentication keys from the audio device, and use them to jump to the paired phone (which was also in range).
##updated 2026-09-08T15:13:07.273000
1 posts
100 repos
https://github.com/tgies/copy-fail-c
https://github.com/AdityaBhatt3010/CVE-2026-31431
https://github.com/MartinPham/copy-fail-CVE-2026-31431-php
https://github.com/guiimoraes/CVE-2026-31431
https://github.com/sgkdev/ptrace_may_dream
https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit
https://github.com/sudoytang/copyfail-arm64
https://github.com/gagaltotal/cve-2026-31431-copy-fail
https://github.com/ExploitEoom/CVE-2026-31431
https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script
https://github.com/MrAriaNet/cPanel-Fix
https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs
https://github.com/rootsecdev/cve_2026_31431
https://github.com/cs8425/copy-fail-go
https://github.com/XsanFlip/CVE-2026-31431-Patch
https://github.com/haydenjames/CVE-2026-31431-check
https://github.com/Xerxes-2/CVE-2026-31431-rs
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/ncmprbll/copy-fail-rs
https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431
https://github.com/kadir/copy-fail-CVE-2026-31431-IOC
https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit
https://github.com/Sl4cK0TH/CVE-2026-31431-PoC
https://github.com/Smarttfoxx/copyfail
https://github.com/desultory/CVE-2026-31431
https://github.com/jbnetwork-git/copy-fail-check
https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape
https://github.com/sec17br/CVE-2026-31431-Copy-Fail
https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized
https://github.com/0xShe/CVE-2026-31431
https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431
https://github.com/wuwu001/CVE-2026-31431-exploit
https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation
https://github.com/ben-slates/CVE-2026-31431-Exploit
https://github.com/wesmar/CVE-2026-31431
https://github.com/philfry/cve-2026-31431-ftrace
https://github.com/JnamerZ/CopyFail-CVE-2026-31431
https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431
https://github.com/Alfredooe/CVE-2026-31431
https://github.com/TheMalwareGuardian/CVE-2026-31431
https://github.com/bigwario/copy-fail-CVE-2026-31431-C
https://github.com/aestechno/cve-2026-31431-ansible
https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite
https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit
https://github.com/JuanBindez/CVE-2026-31431
https://github.com/badsectorlabs/copyfail-go
https://github.com/4xura/CVE-2026-31431-Copy-Fail
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431
https://github.com/malwarekid/CVE-2026-31431
https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4
https://github.com/sammwyy/copyfail-rs
https://github.com/theori-io/copy-fail-CVE-2026-31431
https://github.com/cyber-joker/copy-fail-python
https://github.com/novysodope/copy-fail-CVE-2026-31431-C
https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH
https://github.com/Juguitos/copy-fail
https://github.com/Dabbleam/CVE-2026-31431-mitigation
https://github.com/lonelyor/CVE-2026-31431-exp
https://github.com/Iamliuxiaozhen/copy_fail
https://github.com/sgkdev/page_inject
https://github.com/ZephrFish/CopyFail-CVE-2026-31431
https://github.com/ErdemOzgen/copy-fail-cve-2026-31431
https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431
https://github.com/luotian2/CVE-2026-31431
https://github.com/bootsareme/copyfail-deconstructed
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC
https://github.com/diemoeve/copyfail-rs
https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail
https://github.com/qi4L/CVE-2026-31431-Container-Escape
https://github.com/Huchangzhi/autorootlinux
https://github.com/atgreen/block-copyfail
https://github.com/0xBlackash/CVE-2026-31431
https://github.com/cozystack/copy-fail-blocker
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC
https://github.com/abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix
https://github.com/erlangparasu/mitigate_cve_2026_31431-sh
https://github.com/yuspring/cve-2026-31431-poc
https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE
https://github.com/povzayd/CVE-2026-31431
https://github.com/pyroceper/copy-fail-CVE-2026-31431
https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431
https://github.com/mrunalp/block-copyfail
https://github.com/xeloxa/copyfail-exploit
https://github.com/AliHzSec/CVE-2026-31431
https://github.com/pascal-gujer/CVE-2026-31431
https://github.com/SeanRickerd/cve-2026-31431
https://github.com/wgnet/wg.copyfail.patch
https://github.com/kinryulabs/rootpacket-cve-2026-31431
https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail
https://github.com/insomnisec/Detections-CVE-2026-31431
https://github.com/Boos4721/copyfail-rs
https://github.com/Qengineering/RK35xx-CopyFail-Hotfix
https://github.com/samanzamani/copy-fail-checker
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/b5null/CVE-2026-31431-C
https://github.com/nisec-eric/cve-2026-31431
https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell
🐧 SIGINT // Linux Watch — 2026-09-21
CVE-2026-31431: a tiny buffer bug in the kernel's crypto subsystem, full root. Ubuntu 24.04 LTS and Amazon Linux both on the guest list — patch before the weekend, not after.
🔗 https://forkast.news/732-bytes-to-root-copy-fail-turns-the-kernels-crypto-subsystem-against-itself/
##updated 2026-09-07T14:16:53.357000
2 posts
CVE-2026-54218 is also interesting in that it appears to be plaintext/weak-crypto password storage, based on the reference, instead of actually hardcoded
##CVE-2026-54218 is also interesting in that it appears to be plaintext/weak-crypto password storage, based on the reference, instead of actually hardcoded
##updated 2026-09-05T00:31:10
2 posts
🔒 New CSAF advisory published
VDE-2026-089
Lenze: VPN Client Remote Code Execution in combination with Lenze x500 IoT Gateway
CVE-2026-75925
The Lenze VPN client is vulnerable to a Remote Code Execution. The vulnerability would allow an attacker to perform a remote code execution on the computer running the client with elevated privile…
HTML: https://certvde.com/en/advisories/VDE-2026-089
CSAF JSON: https://lenze.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-089.json
🔒 New CSAF advisory published
VDE-2026-089
Lenze: VPN Client Remote Code Execution in combination with Lenze x500 IoT Gateway
CVE-2026-75925
The Lenze VPN client is vulnerable to a Remote Code Execution. The vulnerability would allow an attacker to perform a remote code execution on the computer running the client with elevated privile…
HTML: https://certvde.com/en/advisories/VDE-2026-089
CSAF JSON: https://lenze.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-089.json
updated 2026-09-04T16:18:13.023000
1 posts
2 repos
Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity
https://cyberworldops.eu/en/four-public-linux-kernel-exploits-put-unpatched-hosts-at-risk-of-local
##updated 2026-09-01T20:52:39.973000
1 posts
Schneider Electric disclosed CVE-2026-13348 (CWE-307) in PowerChute Serial Shutdown, allowing unrestricted authentication attempts. Successful brute-forcing enables account takeover with impact on UPS management and operational continuity. #SchneiderElectric #PowerChute #BruteForce
https://cyberworldops.eu/en/powerchute-authentication-flaw-opens-the-door-to-unlimited-login
##updated 2026-08-19T17:21:03.977000
1 posts
2 repos
Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity
https://cyberworldops.eu/en/four-public-linux-kernel-exploits-put-unpatched-hosts-at-risk-of-local
##updated 2026-08-19T17:20:29.553000
1 posts
2 repos
Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity
https://cyberworldops.eu/en/four-public-linux-kernel-exploits-put-unpatched-hosts-at-risk-of-local
##updated 2026-08-10T18:30:39
2 posts
14 repos
https://github.com/psc4re/NSE-scripts
https://github.com/mithridates1313/ProxyShell_POC
https://github.com/cyberheartmi9/Proxyshell-Scanner
https://github.com/RaouzRouik/CVE-2021-34473-scanner
https://github.com/hosch3n/ProxyVulns
https://github.com/horizon3ai/proxyshell
https://github.com/p2-98/CVE-2021-34473
https://github.com/je6k/CVE-2021-34473-Exchange-ProxyShell
https://github.com/Udyz/proxyshell-auto
https://github.com/W01fh4cker/Serein
https://github.com/ipsBruno/CVE-2021-34473-NMAP-SCANNER
https://github.com/learningsurface/ProxyShell-CVE-2021-34473.py
Ungepatchte Exchange-Server mit kritischer Sicherheitslücke
CVE-2021-34473: "Microsoft Exchange Server Remote Code Execution Vulnerability"
Volkshochschule in Amberg, Landkreis Merzig-Wadern und mehreren Stadtverwaltungen: Bernsdorf, Bleckede, Dachau, Erkner, Heilbald Heiligenstadt, Klötze, Mölln, Plauen, Rendsburg, Sassnitz, Stadtbergen, Sulzbach Saar, Vellmar und im Exchange-Server im Theater in Freiburg, ...
c't Artikel: https://www.heise.de/news/Verwundbare-Exchange-Server-der-oeffentlichen-Verwaltung-6320504.html
##Ungepatchte Exchange-Server mit kritischer Sicherheitslücke
CVE-2021-34473: "Microsoft Exchange Server Remote Code Execution Vulnerability"
Volkshochschule in Amberg, Landkreis Merzig-Wadern und mehreren Stadtverwaltungen: Bernsdorf, Bleckede, Dachau, Erkner, Heilbald Heiligenstadt, Klötze, Mölln, Plauen, Rendsburg, Sassnitz, Stadtbergen, Sulzbach Saar, Vellmar und im Exchange-Server im Theater in Freiburg, ...
c't Artikel: https://www.heise.de/news/Verwundbare-Exchange-Server-der-oeffentlichen-Verwaltung-6320504.html
##updated 2026-07-27T12:32:01
2 posts
Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router https://rotcee.github.io/posts/analyzing-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-auth-stack-buffer-overflow-in-the-mercusys-mb115-4g
##Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router https://rotcee.github.io/posts/analyzing-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-auth-stack-buffer-overflow-in-the-mercusys-mb115-4g
##updated 2026-07-22T19:10:00.120000
2 posts
sev:CRIT bypass of CVE-2026-47065 in Apache MINA.
https://nvd.nist.gov/vuln/detail/cve-2026-94301
##The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.
sev:CRIT bypass of CVE-2026-47065 in Apache MINA.
https://nvd.nist.gov/vuln/detail/cve-2026-94301
##The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.
updated 2026-07-14T22:17:26.797000
4 posts
6 repos
https://github.com/0xBlackash/CVE-2026-58138
https://github.com/BiiTts/CVE-2026-58138-Conductor-Unauth-RCE
https://github.com/seqra/cve-2026-58138
https://github.com/Procjevt/CVE-2026-58138
Critical Pre-Auth RCE in Orkes Conductor Under Active Exploitation
Orkes Conductor versions prior to 3.30.2 are vulnerable to a critical unauthenticated remote code execution flaw (CVE-2026-58138) that allows attackers to run arbitrary OS commands via malicious workflow definitions.
**If you run Orkes Conductor or Conductor OSS versions 3.21.21 through 3.30.1 (check your `conductoross/conductor` container images and Helm charts), update to 3.30.2 or later immediately. Working exploit code is public and attacks are already underway. Until you can patch, take the Conductor API off the internet, put it behind a reverse proxy that requires authentication and limit workflow endpoints to trusted internal networks only.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/critical-pre-auth-rce-in-orkes-conductor-under-active-exploitation-5-v-3-f-3/gD2P6Ple2L
⚠️ CRITICAL: Critical Orkes Conductor Vulnerability Exploited in Attacks
Orkes Conductor versions below 3.30.2 have an unauthenticated remote code execution vulnerability (CVE-2026-58138) that is actively being exploited. Attackers can execute arbitrary system commands by injecting malicious JavaScript or Python into workflow definitions. Any organization running Conduc…
🤖 AI generated summary
##Critical Pre-Auth RCE in Orkes Conductor Under Active Exploitation
Orkes Conductor versions prior to 3.30.2 are vulnerable to a critical unauthenticated remote code execution flaw (CVE-2026-58138) that allows attackers to run arbitrary OS commands via malicious workflow definitions.
**If you run Orkes Conductor or Conductor OSS versions 3.21.21 through 3.30.1 (check your `conductoross/conductor` container images and Helm charts), update to 3.30.2 or later immediately. Working exploit code is public and attacks are already underway. Until you can patch, take the Conductor API off the internet, put it behind a reverse proxy that requires authentication and limit workflow endpoints to trusted internal networks only.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/critical-pre-auth-rce-in-orkes-conductor-under-active-exploitation-5-v-3-f-3/gD2P6Ple2L
⚠️ CRITICAL: Critical Orkes Conductor Vulnerability Exploited in Attacks
Orkes Conductor versions below 3.30.2 have an unauthenticated remote code execution vulnerability (CVE-2026-58138) that is actively being exploited. Attackers can execute arbitrary system commands by injecting malicious JavaScript or Python into workflow definitions. Any organization running Conduc…
🤖 AI generated summary
##updated 2026-07-07T13:31:43.910000
1 posts
BragJack attacks hijack AI browser agents through malicious extensions
Forever Security의 Gal Weizman이 악성 Chromium 확장 프로그램 하나로 브라우저 내 AI 에이전트를 탈취하는 ‘BragJack’ 공격을 공개했다. Google Chrome Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, Claude in Chrome 등 5개 대상에서 재현됐으며, Chrome의 CVE-2026-0628과 Edge의 CVE-2026-55945를 포...
##updated 2026-03-10T21:32:11
2 posts
@cR0w hold a second, what the fuck is this vulnerability: https://db.gcve.eu/vuln/CVE-2026-20111
This CWE and description absolutely dont fucking match, what the fuck, cisco
##@cR0w hold a second, what the fuck is this vulnerability: https://db.gcve.eu/vuln/CVE-2026-20111
This CWE and description absolutely dont fucking match, what the fuck, cisco
##updated 2026-01-07T15:31:20
1 posts
2 repos
BragJack attacks hijack AI browser agents through malicious extensions
Forever Security의 Gal Weizman이 악성 Chromium 확장 프로그램 하나로 브라우저 내 AI 에이전트를 탈취하는 ‘BragJack’ 공격을 공개했다. Google Chrome Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, Claude in Chrome 등 5개 대상에서 재현됐으며, Chrome의 CVE-2026-0628과 Edge의 CVE-2026-55945를 포...
##updated 2025-10-22T00:34:06
2 posts
45 repos
https://github.com/andrelia-hacks/CVE-2024-3400
https://github.com/P4rC3L/Global-Protect_VPN_Vuln
https://github.com/Chocapikk/CVE-2024-3400
https://github.com/ak1t4/CVE-2024-3400
https://github.com/marconesler/CVE-2024-3400
https://github.com/wa6n3r/CVE-2024-3400
https://github.com/Yafiah-Darwesh/cs50-cyber-paloalto-oauth
https://github.com/terminalJunki3/CVE-2024-3400-Checker
https://github.com/index2014/CVE-2024-3400-Checker
https://github.com/MrR0b0t19/CVE-2024-3400
https://github.com/codeblueprint/CVE-2024-3400
https://github.com/AdaniKamal/CVE-2024-3400
https://github.com/Ravaan21/CVE-2024-3400
https://github.com/0x0d3ad/CVE-2024-3400
https://github.com/HackingLZ/panrapidcheck
https://github.com/ivan-n0v/cve-2024-3400
https://github.com/MurrayR0123/CVE-2024-3400-Compromise-Checker
https://github.com/Zedocun/PAN-OS-CVE-2024-3400-Command-Injection-Investigation
https://github.com/ihebski/CVE-2024-3400
https://github.com/h4x0r-dz/CVE-2024-3400
https://github.com/0xr2r/CVE-2024-3400-Palo-Alto-OS-Command-Injection
https://github.com/ZephrFish/CVE-2024-3400-Canary
https://github.com/sxyrxyy/CVE-2024-3400-Check
https://github.com/Yuvvi01/CVE-2024-3400
https://github.com/SimoesCTT/-CTT-PAN-OS-EXPLOIT-CVE-2024-340
https://github.com/LoanVitor/CVE-2024-3400-
https://github.com/razureink/cve-2024-3400-panos_rce_reproduction
https://github.com/tfrederick74656/cve-2024-3400-poc
https://github.com/CerTusHack/CVE-2024-3400-PoC
https://github.com/retkoussa/CVE-2024-3400
https://github.com/FoxyProxys/CVE-2024-3400
https://github.com/CyprianAtsyor/letsdefend-cve2024-3400-case-study
https://github.com/workshop748/CVE-2024-3400
https://github.com/GhassanSabir/CVE-2024-3400-poc
https://github.com/schooldropout1337/CVE-2024-3400
https://github.com/pwnj0hn/CVE-2024-3400
https://github.com/momika233/CVE-2024-3400
https://github.com/zam89/CVE-2024-3400-pot
https://github.com/hahasagined/CVE-2024-3400
https://github.com/W01fh4cker/CVE-2024-3400-RCE-Scan
https://github.com/Kr0ff/cve-2024-3400
GET /api/v1/cve/CVE-2024-3400 returns CVSS, affected vendors, and known exploit references in one call. No key juggling, no separate lookups. Metered per request. https://www.valtersit.com/cve/pricing/
##GET /api/v1/cve/CVE-2024-3400 returns CVSS, affected vendors, CPEs, and known exploits in one call. No joins, no scraping. Metered keys at https://www.valtersit.com/cve/pricing/
##2 posts
1 repos
https://github.com/muhammad-usama-sardar/intra-handshake-fail
🔴 CVE-2026-92702 - Critical (9.1)
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92702/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-92702 - Critical (9.1)
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92702/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61721 - High (8)
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61721 - High (8)
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61819 - High (8.5)
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verbatim insid...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61819/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61819 - High (8.5)
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verbatim insid...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61819/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61818 - High (8.5)
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting into a dynamically executed SEL...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61818/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61818 - High (8.5)
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting into a dynamically executed SEL...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61818/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61821 - High (8.5)
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for ALTER TABLE SET SCHEMA and accept any nonempty sch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61821/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61821 - High (8.5)
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for ALTER TABLE SET SCHEMA and accept any nonempty sch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61821/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61820 - High (8.5)
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with double quotes without escaping embedded do...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61820/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61820 - High (8.5)
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with double quotes without escaping embedded do...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61820/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##@paul @arda AVIF is a specific profile/subtype of HEIF. Mastodon uses libvips to handle images and libvips uses libheif to handle both HEIF and AVIF.
libheif was disabled in mastodon 4.7.2 due to unspecified security issues but it's probably because of CVE-2026-84383
##🟠 CVE-2026-57228 - High (8.2)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57228/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-57227 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57227/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63447 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63447/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63446 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63446/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63452 - High (7.5)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli comp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##