## Updated at UTC 2026-08-15T07:16:27.995686

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-73327 7.6 0.85% 1 0 2026-08-15T04:18:25.363000 Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate ext
CVE-2026-65400 9.8 0.31% 6 0 2026-08-15T04:18:24.470000 An authentication issue was addressed with improved state management. This issue
CVE-2026-63700 7.8 0.00% 2 0 2026-08-15T04:18:22.480000 Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorre
CVE-2026-15965 8.8 0.00% 2 0 2026-08-15T03:16:48.077000 The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for
CVE-2026-15341 9.8 0.00% 2 0 2026-08-15T03:16:47.943000 The User Session Synchronizer plugin for WordPress is vulnerable to Authenticati
CVE-2026-15303 9.8 0.00% 2 0 2026-08-15T03:16:47.670000 The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass
CVE-2026-14484 9.1 0.00% 2 0 2026-08-15T03:16:47.263000 The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress
CVE-2026-69414 7.8 0.00% 2 0 2026-08-15T00:31:32 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-73683 8.1 0.00% 2 0 2026-08-14T22:17:11.550000 Laravel Socialite's Facebook provider contains an authentication bypass vulnerab
CVE-2026-20272 9.8 0.34% 1 0 2026-08-14T21:32:20 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-73680 8.8 0.00% 2 0 2026-08-14T21:31:44 Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the F
CVE-2026-50523 7.8 0.00% 2 0 2026-08-14T21:31:44 Improper neutralization of special elements used in a command ('command injectio
CVE-2026-73678 10.0 0.00% 2 0 2026-08-14T21:31:39 MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated re
CVE-2026-73682 8.8 0.00% 2 0 2026-08-14T21:17:58.033000 Semaphore versions prior to 2.18.20 contain an OS command injection (argument in
CVE-2026-67365 0 0.00% 2 0 2026-08-14T20:16:55.850000 Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.
CVE-2026-19909 7.5 0.00% 2 0 2026-08-14T20:16:52.437000 PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnera
CVE-2026-17186 9.9 0.00% 2 0 2026-08-14T20:16:51.127000 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute
CVE-2026-69101 7.7 0.00% 2 0 2026-08-14T19:17:56.140000 Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerabilit
CVE-2026-13610 7.5 0.15% 2 1 2026-08-14T19:17:14.350000 The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignab
CVE-2026-12949 9.8 0.34% 3 0 2026-08-14T19:09:56.813000 The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via I
CVE-2026-19789 8.8 0.47% 1 0 2026-08-14T19:09:39.140000 A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vuln
CVE-2026-19811 8.8 0.47% 4 0 2026-08-14T19:09:39.140000 A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Th
CVE-2026-19844 8.8 0.00% 2 0 2026-08-14T19:09:39.140000 A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted
CVE-2026-19792 8.8 0.47% 1 0 2026-08-14T19:09:39.140000 A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the
CVE-2026-19815 8.8 0.47% 2 0 2026-08-14T19:09:39.140000 A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this
CVE-2026-19813 8.8 0.60% 2 0 2026-08-14T19:09:39.140000 A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200
CVE-2026-18039 8.1 0.15% 2 0 2026-08-14T18:32:42 The Essential Addons for Elementor WordPress plugin before 6.7.2 does not preve
CVE-2026-19845 8.8 0.00% 2 0 2026-08-14T18:31:46 A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This af
CVE-2026-73843 9.6 0.29% 2 0 2026-08-14T18:19:09.623000 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior t
CVE-2026-72830 9.8 0.00% 2 0 2026-08-14T18:19:08.780000 Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in Con
CVE-2026-66804 7.8 3.03% 6 2 2026-08-14T18:06:11.420000 Improper access control in Windows Cross Device Service allows an authorized att
CVE-2026-73841 8.8 0.35% 2 0 2026-08-14T17:20:36.590000 OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.
CVE-2026-72857 7.7 0.26% 2 0 2026-08-14T17:20:31.747000 Budibase before 3.40.0 fails to redact datasource credentials stored in STRING t
CVE-2026-72842 9.9 0.42% 2 0 2026-08-14T17:20:31.403000 luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privile
CVE-2026-46439 7.8 0.00% 2 0 2026-08-14T17:18:14.853000 compliance-trestle is a tooling platform for managing compliance as code. Versio
CVE-2026-73420 0 0.53% 2 0 2026-08-14T16:17:00.207000 NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and
CVE-2026-53970 7.5 0.00% 2 0 2026-08-14T16:16:57.073000 ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulne
CVE-2026-19768 8.1 0.00% 2 0 2026-08-14T15:32:54 Improper control of generation of code ('Code Injection') in the settings featur
CVE-2026-73633 7.5 0.00% 2 0 2026-08-14T15:32:50 Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Str
CVE-2026-72859 7.7 0.00% 2 0 2026-08-14T12:31:39 Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in th
CVE-2026-72829 9.8 0.00% 2 0 2026-08-14T12:31:34 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key
CVE-2026-19821 8.8 0.00% 2 0 2026-08-14T12:31:34 A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulner
CVE-2026-72837 8.8 0.00% 2 0 2026-08-14T12:31:28 File Browser versions before 2.63.20 fail to honor the createUserDir isolation i
CVE-2026-72836 8.1 0.00% 2 0 2026-08-14T12:16:47.060000 FileBrowser before 2.63.19 does not account for case-insensitive filesystems whe
CVE-2026-19814 8.8 0.47% 2 0 2026-08-14T09:30:32 A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected
CVE-2026-19812 8.8 0.49% 2 0 2026-08-14T09:30:32 A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This af
CVE-2026-19790 8.8 0.47% 1 0 2026-08-14T06:31:11 A vulnerability was identified in Tenda G0 up to 20260625. This issue affects th
CVE-2026-19791 8.8 0.47% 1 0 2026-08-14T06:31:11 A weakness has been identified in Tenda G0 up to 20260625. The affected element
CVE-2026-19788 8.8 0.47% 1 0 2026-08-14T06:31:05 A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects t
CVE-2026-73570 8.9 0.54% 2 0 2026-08-14T05:17:00.340000 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-72841 9.9 0.42% 2 0 2026-08-14T00:32:06 luci-app-openvpn fails to properly validate the instance_name2 parameter during
CVE-2026-72850 9.1 0.42% 4 0 2026-08-14T00:32:06 Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authe
CVE-2026-72851 10.0 0.29% 2 0 2026-08-14T00:32:06 Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability i
CVE-2026-73421 0 0.64% 2 0 2026-08-13T22:17:26.447000 NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 unt
CVE-2026-72849 7.7 0.12% 2 0 2026-08-13T22:17:24.140000 Budibase before 3.40.0 contains a cross-site request forgery vulnerability in th
CVE-2026-17197 8.1 0.34% 2 0 2026-08-13T21:36:08 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security re
CVE-2026-72777 8.6 0.32% 2 0 2026-08-13T21:36:08 Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerabil
CVE-2026-73482 8.1 0.24% 2 0 2026-08-13T21:36:08 phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerabil
CVE-2026-10534 8.4 0.18% 2 0 2026-08-13T20:59:20.483000 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer
CVE-2026-17220 8.2 0.39% 2 0 2026-08-13T20:36:48.443000 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of
CVE-2026-73653 9.4 0.64% 2 0 2026-08-13T19:17:38.920000 Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10,
CVE-2026-73650 8.2 0.24% 2 0 2026-08-13T19:17:38.460000 SVGO, short for SVG Optimizer, is a Node.js library and command-line application
CVE-2026-73515 8.1 0.41% 2 0 2026-08-13T18:31:43 PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allo
CVE-2026-73514 8.8 0.45% 2 0 2026-08-13T18:18:18.097000 The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 42
CVE-2026-73493 7.5 0.35% 1 0 2026-08-13T18:18:17.740000 Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP se
CVE-2026-69105 8.1 0.13% 1 0 2026-08-13T16:18:55.870000 An unauthenticated attacker may cause untrusted package content to be cached und
CVE-2025-41769 9.8 0.59% 3 0 2026-08-13T16:17:50.857000 The device's PROFINET service is affected by a buffer overflow vulnerability tha
CVE-2026-28173 7.1 0.23% 1 0 2026-08-13T15:34:46 Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.
CVE-2026-6464 8.1 0.49% 2 1 2026-08-13T15:34:45 Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrato
CVE-2026-55040 9.1 3.97% 10 2 2026-08-13T15:34:13 Weak authentication in Microsoft Office SharePoint allows an unauthorized attack
CVE-2026-71398 10.0 0.64% 2 0 2026-08-13T15:20:01.813000 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-59500 10.0 0.38% 2 0 2026-08-13T15:19:53.323000 CWE-287: Improper Authentication
CVE-2026-19311 8.1 0.41% 1 0 2026-08-13T15:19:38.027000 Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting p
CVE-2026-11840 8.8 1.58% 1 0 2026-08-13T15:19:27.787000 Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngin
CVE-2026-73519 9.8 0.62% 2 0 2026-08-13T14:17:13.773000 WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret comp
CVE-2026-71193 9.6 0.53% 2 0 2026-08-13T14:17:12.087000 In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_sup
CVE-2026-66898 9.9 0.34% 1 0 2026-08-13T14:17:11.320000 A path traversal vulnerability in LXD allows an attacker to manipulate file syst
CVE-2026-14863 8.8 1.67% 4 0 2026-08-13T14:16:54.583000 FileRun up to and including version 2026.2.0 contains an OS command injection vu
CVE-2026-73418 7.5 0.46% 1 0 2026-08-13T13:19:17.513000 NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and
CVE-2026-49819 9.8 0.61% 3 0 2026-08-13T13:19:09.937000 UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to
CVE-2026-19002 8.1 0.29% 1 0 2026-08-13T13:17:48.387000 A missing bounds check when parsing stored procedure parameter metadata in the M
CVE-2026-59501 8.2 0.32% 2 0 2026-08-13T12:31:13 CWE-284: Improper Access Control
CVE-2026-12263 8.8 0.70% 2 0 2026-08-13T12:31:13 Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 vers
CVE-2026-59506 9.3 0.40% 2 0 2026-08-13T12:31:13 CWE-306: Missing Authentication for Critical Function
CVE-2026-59507 9.3 0.32% 2 0 2026-08-13T12:31:13 CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Informatio
CVE-2026-0301 None 0.31% 2 0 2026-08-13T03:31:24 An information disclosure vulnerability in the URL Filtering feature of Palo Alt
CVE-2026-71469 7.5 0.36% 2 0 2026-08-13T00:31:33 A flaw was found in search-v2-api. An unauthenticated attacker can exploit this
CVE-2026-19003 7.8 0.13% 1 0 2026-08-13T00:31:33 A data source definition containing an over-length file path setting may cause t
CVE-2026-71471 9.0 1.45% 4 0 2026-08-13T00:31:26 A flaw was found in acm-search-v2-rhel9. An attacker with administrative privile
CVE-2026-71473 8.5 0.26% 1 0 2026-08-13T00:31:26 A flaw was found in the `search-v2-operator` component. A user with specific adm
CVE-2026-73292 8.3 0.19% 1 0 2026-08-12T23:17:24.190000 Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the
CVE-2026-19001 9.8 0.38% 1 0 2026-08-12T21:31:51 The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-siz
CVE-2026-73326 7.6 0.27% 1 0 2026-08-12T21:31:50 CamaleonCMS contains a missing authorization vulnerability that allows any authe
CVE-2026-17083 9.8 0.46% 2 0 2026-08-12T21:31:44 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary
CVE-2026-73433 6.6 0.13% 1 0 2026-08-12T21:31:44 A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM
CVE-2026-72798 8.6 0.26% 1 0 2026-08-12T21:31:42 SiYuan versions before v3.7.4 fail to properly filter related-database content i
CVE-2026-73329 8.7 0.23% 1 0 2026-08-12T21:17:40.527000 CamaleonCMS contains a stored cross-site scripting vulnerability that allows aut
CVE-2026-73498 7.7 0.33% 1 0 2026-08-12T21:17:31 ### Summary `confluence_upload_attachment` passes `file_path` directly to `open(
CVE-2026-71362 9.1 0.48% 12 0 2026-08-12T21:03:43.743000 Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
CVE-2026-71384 9.6 0.24% 2 0 2026-08-12T21:03:43.743000 is affected by an Incorrect Authorization vulnerability that could result in a S
CVE-2026-73332 8.7 0.23% 1 0 2026-08-12T20:17:55.480000 CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_con
CVE-2026-64629 7.8 0.11% 2 0 2026-08-12T20:17:48.073000 A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235
CVE-2026-73406 7.5 0.37% 1 0 2026-08-12T19:03:59 #### Summary The Budibase Worker service exposes a public, unauthenticated API e
CVE-2026-73305 8.8 0.37% 2 0 2026-08-12T18:57:18 ### Summary Budibase `3.39.19` (commit `03fbabae4`) is affected by a privilege-
CVE-2026-73303 None 0.23% 1 0 2026-08-12T18:56:58 ## Summary `POST /api/v2/email` on the account portal (`account.budibase.app`)
CVE-2026-73300 9.6 0.38% 1 0 2026-08-12T18:56:53 ## Summary A critical SQL injection vulnerability was discovered in Budibase's M
CVE-2026-17248 7.1 0.33% 1 0 2026-08-12T18:31:29 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to caus
CVE-2026-69106 8.8 0.35% 1 0 2026-08-12T18:31:29 A low-privileged user may poison cached artifact metadata under specific conditi
CVE-2026-73325 7.8 0.26% 1 0 2026-08-12T18:31:28 Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserializati
CVE-2026-18634 8.4 0.22% 1 0 2026-08-12T18:17:28.580000 An insecure handling of serialized objects vulnerability was found in the one of
CVE-2026-65941 8.8 0.44% 1 0 2026-08-12T17:17:29.610000 In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote att
CVE-2026-50656 7.8 10.75% 7 3 2026-08-12T17:17:27.983000 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-26035 9.8 0.51% 2 0 2026-08-12T15:30:49 An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet For
CVE-2026-57858 8.9 0.41% 2 1 2026-08-12T15:30:49 Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripti
CVE-2026-70468 8.1 0.59% 1 0 2026-08-12T15:30:49 A authentication bypass using an alternate path or channel vulnerability in Fort
CVE-2026-72898 10.0 10.40% 7 2 2026-08-12T15:18:30.347000 Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via t
CVE-2026-19594 8.1 0.40% 1 0 2026-08-12T13:17:22.180000 Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versi
CVE-2025-41771 4.3 0.16% 2 0 2026-08-12T13:17:18.880000 An authenticated attacker with low privileges can access an endpoint in the cont
CVE-2026-67282 None 0.57% 1 0 2026-08-12T09:31:30 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabri
CVE-2026-58231 10.0 0.73% 11 0 2026-08-12T05:17:56.963000 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent
CVE-2026-66878 7.7 0.21% 1 0 2026-08-12T03:31:17 A flaw was found in multicloud-operators-subscription. A privileged user, specif
CVE-2026-68067 9.8 0.28% 2 0 2026-08-12T00:31:23 The login endpoint on the Mira cloud API accepts any format-valid string in the
CVE-2026-19579 5.4 0.24% 1 0 2026-08-11T21:33:18 Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object r
CVE-2026-73282 4.8 0.16% 1 0 2026-08-11T21:33:18 In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a
CVE-2026-73281 3.5 0.16% 1 0 2026-08-11T21:33:11 In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were
CVE-2026-68820 7.0 0.33% 14 1 2026-08-11T21:33:01 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-20349 8.6 0.87% 4 0 2026-08-11T21:32:37 A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall A
CVE-2026-73283 2.5 0.08% 1 0 2026-08-11T21:17:53.413000 In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was su
CVE-2026-18687 7.1 0.17% 1 0 2026-08-11T21:17:31.273000 MongoDB Server's handling of a Queryable Encryption maintenance operation did no
CVE-2026-20337 7.5 0.36% 1 0 2026-08-11T18:54:19.877000 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-48381 9.0 0.48% 2 0 2026-08-11T18:32:00 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-27302 10.0 0.57% 2 0 2026-08-11T18:32:00 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-62832 7.8 2.37% 4 0 2026-08-11T18:31:33 Improper link resolution before file access ('link following') in Windows User P
CVE-2026-48442 7.1 0.24% 1 0 2026-08-11T18:31:03 CAI Content Credentials is affected by an Improper Limitation of a Pathname to a
CVE-2026-59124 9.8 1.72% 1 0 2026-08-11T18:31:01 Deserialization of untrusted data in Microsoft High Performance Computing (HPC)
CVE-2026-48362 10.0 2.07% 2 0 2026-08-11T18:30:56 ColdFusion is affected by an Improper Neutralization of Special Elements used in
CVE-2026-18129 8.1 0.87% 1 0 2026-08-11T15:32:51 Cleartext transmission of sensitive information in the Core of Ivanti Endpoint M
CVE-2026-59693 4.3 0.16% 2 0 2026-08-11T15:32:41 A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16
CVE-2026-64582 7.8 0.12% 2 0 2026-08-08T15:31:27 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: F
CVE-2026-67261 9.8 1.60% 1 0 2026-08-07T20:08:27.597000 Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.
CVE-2026-20339 7.5 0.33% 1 0 2026-08-07T18:31:54 A vulnerability in the PESpin file format parser of ClamAV could allow an unauth
CVE-2026-71319 9.6 0.32% 1 0 2026-08-07T05:17:03.660000 Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nux
CVE-2026-63455 9.8 0.43% 2 0 2026-08-06T15:40:50.227000 Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orch
CVE-2025-24472 8.1 3.58% 1 1 2026-08-05T05:16:43.473000 An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2
CVE-2026-63456 9.8 0.43% 2 0 2026-08-04T18:31:36 Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orch
CVE-2026-18577 8.1 4.10% 2 3 2026-08-04T15:33:20 An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco
CVE-2026-61515 9.8 1.58% 1 0 2026-08-04T15:32:30 Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated c
CVE-2025-4318 None 0.93% 1 0 2026-07-30T20:57:25 ### Summary The AWS Amplify Studio [amplify-codegen-ui](https://github.com/aws-a
CVE-2026-59309 9.8 0.74% 2 0 2026-07-30T15:31:54 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-59310 9.8 1.14% 21 0 2026-07-30T15:31:51 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-43723 7.8 0.15% 2 0 2026-07-28T19:31:46.327000 A path handling issue was addressed with improved validation. This issue is fixe
CVE-2026-16756 7.5 0.42% 1 0 2026-07-24T22:37:39 ## Summary Smithy-RS is a Rust code generation and runtime framework that genera
CVE-2026-46331 7.8 0.53% 1 14 2026-07-23T12:18:18.287000 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-44761 9.1 0.46% 1 0 2026-07-15T05:16:39.133000 SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented
CVE-2026-43500 7.8 92.86% 1 24 2026-07-15T02:21:44.380000 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also
CVE-2026-43284 8.8 93.23% 1 44 2026-07-15T02:21:43.190000 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp:
CVE-2026-47301 8.8 0.54% 2 1 2026-07-14T21:32:21 Improper access control in Microsoft Configuration Manager allows an authorized
CVE-2026-49457 9.1 0.00% 2 0 2026-07-01T20:32:36 ### Impact The QUIC client did not authenticate the server during the TLS 1.3 h
CVE-2026-8452 9.8 0.49% 12 2 2026-07-01T15:52:28.390000 Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp
CVE-2026-49478 8.7 0.28% 2 0 2026-06-30T18:38:47 ## Impact Three security vulnerabilities were identified in the OIDC Discovery
CVE-2026-49473 8.8 0.28% 1 0 2026-06-30T18:09:14 ### Summary @cedar-policy/authorization-for-expressjs is an open-source Express.
CVE-2026-23670 5.7 0.26% 1 0 2026-06-17T10:21:55.793000 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enc
CVE-2025-24994 7.3 1.17% 2 0 2026-06-17T08:59:57.383000 Improper access control in Windows Cross Device Service allows an authorized att
CVE-2026-47717 7.5 1.20% 1 0 2026-05-27T22:51:19 ### Summary The GET /api/project endpoint exposes sensitive project configurati
CVE-2026-34263 9.6 0.61% 1 0 2026-05-12T03:31:32 Due to improper Spring Security configuration, SAP Commerce cloud allows an unau
CVE-2026-27912 8.0 0.24% 1 3 2026-04-14T18:30:50 Improper authorization in Windows Kerberos allows an authorized attacker to elev
CVE-2026-22732 9.1 0.48% 1 1 2026-03-20T20:42:26 When applications specify HTTP response headers for servlet applications using S
CVE-2024-55591 9.8 98.26% 2 9 2025-10-22T00:34:16 An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2
CVE-2025-24076 7.3 3.15% 2 1 2025-03-11T18:32:27 Improper access control in Windows Cross Device Service allows an authorized att
CVE-2026-15826 0 0.00% 2 0 N/A
CVE-2026-45699 0 0.00% 2 0 N/A
CVE-2026-34491 0 0.00% 1 0 N/A
CVE-2026-65640 0 0.00% 10 1 N/A
CVE-2026-63030 0 95.60% 2 82 N/A
CVE-2026-73408 0 0.33% 2 0 N/A
CVE-2026-73659 0 0.34% 2 0 N/A
CVE-2026-73658 0 0.33% 2 0 N/A
CVE-2026-73667 0 0.61% 2 0 N/A
CVE-2026-73666 0 0.48% 2 0 N/A
CVE-2026-73842 0 0.18% 2 0 N/A
CVE-2026-49827 0 0.48% 4 0 N/A
CVE-2026-48273 0 0.00% 2 0 N/A
CVE-2026-49481 0 0.88% 3 0 N/A
CVE-2026-73501 0 0.34% 1 0 N/A
CVE-2026-19654 0 0.40% 1 0 N/A
CVE-2026-73299 0 1.21% 1 0 N/A
CVE-2026-18952 0 0.32% 1 0 N/A
CVE-2026-73294 0 0.45% 1 0 N/A
CVE-2026-73293 0 0.40% 1 0 N/A

CVE-2026-73327
(7.6 HIGH)

EPSS: 0.85%

updated 2026-08-15T04:18:25.363000

1 posts

Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be wr

thehackerwire@mastodon.social at 2026-08-12T20:01:10.000Z ##

🟠 CVE-2026-73327 - High (7.6)

Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65400
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-08-15T04:18:24.470000

6 posts

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

sayzard@mastodon.sayzard.org at 2026-08-15T01:38:11.000Z ##

Vulnerability giving attackers full control of Macs is under active exploitation

Apple이 지난주 패치한 macOS 화면 공유 취약점 CVE-2026-65400(심각도 7.1)이 실제 공격에 악용되고 있다. 네덜란드 NCSC는 인터넷에 VNC 포트(5900)를 노출한 여러 Mac에서 공격자가 root 권한을 획득하고 Monero 채굴기를 설치한 사례를 확인했다. 영향 대상은 macOS Tahoe, Sequoia, Sonoma이며, 화면 공유의 상태 관리 결함으로 인증 없는 원격 접근이 가능할 수...

arstechnica.com/security/2026/

##

cyberworldops at 2026-08-14T22:10:00.434Z ##

The Dutch NCSC reports active exploitation of CVE-2026-65400, an authentication flaw in macOS Screen Sharing. Attackers leverage public exploit code to deploy Monero miners on systems exposing the built-in VNC service on TCP/5900. Organizations running macOS with screen sharing enabled should audit their perimeter exposure immediately.

cyberworldops.eu/en/macos-scre

##

aidoo@mastodon.social at 2026-08-14T19:06:46.000Z ##

Alertan explotación de CVE-2026-65400 en macOS: si el puerto 5900 está expuesto, atacantes logran root e instalan minero de Monero. Apple ya parchó Tahoe/Sequoia/Sonoma. aidoo.news/noticia/6AqPP1

#Apple #Vulnerabilidades #SeguridadInformatica #Monero #BlackHat

##

dangoodin at 2026-08-14T17:13:14.256Z ##

Dutch officials are warning that CVE-2026-65400, a macOS vulnerability that allows attackers to execute malicious code, is under active exploitation. (Apple patched the vulnerability recently.) The attacks come when screen sharing is turned on and port 5900 is exposed to the internet. Can anyone tell me how common it is for this port to be exposed? Does it happen automatically when screen sharing is enabled, or are other conditions required?

advisories.ncsc.nl/2026/ncsc-2

advisories.ncsc.nl/2026/ncsc-2

##

cyberworldops@infosec.exchange at 2026-08-14T22:10:00.000Z ##

The Dutch NCSC reports active exploitation of CVE-2026-65400, an authentication flaw in macOS Screen Sharing. Attackers leverage public exploit code to deploy Monero miners on systems exposing the built-in VNC service on TCP/5900. Organizations running macOS with screen sharing enabled should audit their perimeter exposure immediately.

#CVE2026 #ScreenSharing #MoneroMiner #MacOSSecurity

cyberworldops.eu/en/macos-scre

##

dangoodin@infosec.exchange at 2026-08-14T17:13:14.000Z ##

Dutch officials are warning that CVE-2026-65400, a macOS vulnerability that allows attackers to execute malicious code, is under active exploitation. (Apple patched the vulnerability recently.) The attacks come when screen sharing is turned on and port 5900 is exposed to the internet. Can anyone tell me how common it is for this port to be exposed? Does it happen automatically when screen sharing is enabled, or are other conditions required?

advisories.ncsc.nl/2026/ncsc-2

advisories.ncsc.nl/2026/ncsc-2

##

CVE-2026-63700
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-15T04:18:22.480000

2 posts

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

thehackerwire@mastodon.social at 2026-08-14T16:59:51.000Z ##

🟠 CVE-2026-63700 - High (7.8)

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T16:59:51.000Z ##

🟠 CVE-2026-63700 - High (7.8)

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15965
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-15T03:16:48.077000

2 posts

The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation mismatch in the handle_upload function where extension and MIME checks are applied to the uploaded chunk's filename but not to the final assembled filename de

thehackerwire@mastodon.social at 2026-08-15T04:59:53.000Z ##

🟠 CVE-2026-15965 - High (8.8)

The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-15T04:59:53.000Z ##

🟠 CVE-2026-15965 - High (8.8)

The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15341
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-15T03:16:47.943000

2 posts

The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function, hooked on `init` and therefore executed on every request, performs no nonce, capability, or shared-secret validation against the attacker-supplied `ussync-key`, `ussync-token`, and `ussync-ref` param

offseq at 2026-08-15T03:00:23.181Z ##

CVE-2026-15341: CRITICAL auth bypass in rafasashi User Session Synchronizer ≤1.4.0. Attackers can impersonate any WP user — including admins. Disable plugin until fix is released. 🔓 radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-15T03:00:23.000Z ##

CVE-2026-15341: CRITICAL auth bypass in rafasashi User Session Synchronizer ≤1.4.0. Attackers can impersonate any WP user — including admins. Disable plugin until fix is released. 🔓 radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Infosec

##

CVE-2026-15303
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-15T03:16:47.670000

2 posts

The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification, while calling wp_set_current_user() and wp_set_auth_cookie() for any WordPress user

offseq at 2026-08-15T04:30:23.179Z ##

CVE-2026-15303: CRITICAL auth bypass in sixstorage 6Storage Rentals <=2.27.0. Unauthenticated attackers can impersonate any WP user via exposed AJAX handler. Restrict endpoint or disable plugin until patched. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-15T04:30:23.000Z ##

CVE-2026-15303: CRITICAL auth bypass in sixstorage 6Storage Rentals <=2.27.0. Unauthenticated attackers can impersonate any WP user via exposed AJAX handler. Restrict endpoint or disable plugin until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Security

##

CVE-2026-14484
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-15T03:16:47.263000

2 posts

The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the righ

thehackerwire@mastodon.social at 2026-08-15T05:00:03.000Z ##

🔴 CVE-2026-14484 - Critical (9.1)

The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions up to, and including, 1.0.4....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-15T05:00:03.000Z ##

🔴 CVE-2026-14484 - Critical (9.1)

The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions up to, and including, 1.0.4....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69414
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-15T00:31:32

2 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

thehackerwire@mastodon.social at 2026-08-14T23:00:20.000Z ##

🟠 CVE-2026-69414 - High (7.8)

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;.
We are working to provide a high quality security update that addresses this vulnera...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T23:00:20.000Z ##

🟠 CVE-2026-69414 - High (7.8)

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;.
We are working to provide a high quality security update that addresses this vulnera...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73683
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-14T22:17:11.550000

2 posts

Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function within FacebookProvider.php. Attackers who obtain a valid, unexpired id_token issued for the same Facebook App ID can submit the captured token to the backe

thehackerwire@mastodon.social at 2026-08-14T23:00:09.000Z ##

🟠 CVE-2026-73683 - High (8.1)

Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T23:00:09.000Z ##

🟠 CVE-2026-73683 - High (8.1)

Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20272
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-14T21:32:20

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of specia

dailytechfeed@mastodon.social at 2026-08-13T07:04:05.000Z ##

Cisco has released critical security updates for IOS XE Software, addressing vulnerabilities that could expose network devices to remote attacks. Immediate patching is essential due to the severity and lack of workarounds. Affected versions include IOS XE 17.9, 17.12, 17.15, 17.18, and 26.1. Notably, CVE-2026-20272 carries a CVSS score of 9.8, involving improper neutralization of special elements,…

#Cisco #IOSXE #CyberSecurity #NetworkSecurity #Vulnerabilities #Patching

https://thedailytechfe…

##

CVE-2026-73680
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-14T21:31:44

2 posts

Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell metacharacter-laden filename. The unsanitized filename is interpolated into a shell command executed via Process::fromShellCommandline() before the slugify() sani

thehackerwire@mastodon.social at 2026-08-14T22:01:32.000Z ##

🟠 CVE-2026-73680 - High (8.8)

Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell metachara...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T22:01:32.000Z ##

🟠 CVE-2026-73680 - High (8.8)

Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell metachara...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50523
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-14T21:31:44

2 posts

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

thehackerwire@mastodon.social at 2026-08-14T22:01:24.000Z ##

🟠 CVE-2026-50523 - High (7.8)

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T22:01:24.000Z ##

🟠 CVE-2026-50523 - High (7.8)

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73678
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-08-14T21:31:39

2 posts

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers

thehackerwire@mastodon.social at 2026-08-14T20:00:03.000Z ##

🔴 CVE-2026-73678 - Critical (10)

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T20:00:03.000Z ##

🔴 CVE-2026-73678 - Critical (10)

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73682
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-14T21:17:58.033000

2 posts

Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager or Owner role on any project to achieve remote code execution on the Semaphore server host. Attackers can craft a malicious git_url value using git's --upload-pack= option to inject and execute arbitrary shell

thehackerwire@mastodon.social at 2026-08-14T22:01:12.000Z ##

🟠 CVE-2026-73682 - High (8.8)

Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager or Owner role on any project to achieve remote code execu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T22:01:12.000Z ##

🟠 CVE-2026-73682 - High (8.8)

Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager or Owner role on any project to achieve remote code execu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67365
(0 None)

EPSS: 0.00%

updated 2026-08-14T20:16:55.850000

2 posts

Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.

offseq at 2026-08-15T00:00:34.946Z ##

CVE-2026-67365: Unauthenticated SQL injection in Joomla iCagenda (4.0.0 – 4.0.11). Exploitable via com_ajax, no auth needed. CRITICAL (CVSS 9.2). Restrict endpoint & monitor for attacks. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-15T00:00:34.000Z ##

CVE-2026-67365: Unauthenticated SQL injection in Joomla iCagenda (4.0.0 – 4.0.11). Exploitable via com_ajax, no auth needed. CRITICAL (CVSS 9.2). Restrict endpoint & monitor for attacks. radar.offseq.com/threat/cve-20 #OffSeq #CVE202667365 #Joomla #SQLi

##

CVE-2026-19909
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-14T20:16:52.437000

2 posts

PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of AIP files. By creating a symbolic link, an attacker can abuse the installe

thehackerwire@mastodon.social at 2026-08-14T23:00:32.000Z ##

🟠 CVE-2026-19909 - High (7.5)

PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T23:00:32.000Z ##

🟠 CVE-2026-19909 - High (7.5)

PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17186
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-14T20:16:51.127000

2 posts

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.

offseq at 2026-08-15T01:30:24.292Z ##

IBM Db2 Mirror for i (7.4 – 7.6) faces CRITICAL OS command injection (CVE-2026-17186, CVSS 9.9) 🛡️. No patch yet — restrict access, monitor for abuse. No exploits seen in wild. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-15T01:30:24.000Z ##

IBM Db2 Mirror for i (7.4 – 7.6) faces CRITICAL OS command injection (CVE-2026-17186, CVSS 9.9) 🛡️. No patch yet — restrict access, monitor for abuse. No exploits seen in wild. radar.offseq.com/threat/cve-20 #OffSeq #IBM #Vuln #OSCommandInjection

##

CVE-2026-69101
(7.7 HIGH)

EPSS: 0.00%

updated 2026-08-14T19:17:56.140000

2 posts

Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditWorkflow endpoint, which processes XML through an unhardened DocumentBuilderFactory with external entities and DTD loading enabled. Attackers can send a m

thehackerwire@mastodon.social at 2026-08-14T16:00:07.000Z ##

🟠 CVE-2026-69101 - High (7.7)

Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditW...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T16:00:07.000Z ##

🟠 CVE-2026-69101 - High (7.7)

Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditW...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13610
(7.5 HIGH)

EPSS: 0.15%

updated 2026-08-14T19:17:14.350000

2 posts

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.

1 repos

https://github.com/ghostpels/CVE-2026-13610

offseq at 2026-08-13T07:30:23.391Z ##

CVE-2026-13610 | CRITICAL privilege flaw in KiviCare <4.5.2 lets unauthenticated attackers create privileged staff accounts, risking patient data exposure 🏥. Restrict registration endpoint & monitor user creation. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-13T07:30:23.000Z ##

CVE-2026-13610 | CRITICAL privilege flaw in KiviCare <4.5.2 lets unauthenticated attackers create privileged staff accounts, risking patient data exposure 🏥. Restrict registration endpoint & monitor user creation. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #Healthcare

##

CVE-2026-12949
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-14T19:09:56.813000

3 posts

The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and POST wpm_id parameters without verifying that the mergewith user ID references a t

hugovalters@mastodon.social at 2026-08-14T12:02:17.000Z ##

CVE-2026-12949 - Critical Account Takeover in Wishlist Member WordPress plugin. Insufficient verification allows attacker to merge accounts. CVSS 9.8. Unpatched. Update immediately. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-129

##

thehackerwire@mastodon.social at 2026-08-14T11:01:07.000Z ##

🔴 CVE-2026-12949 - Critical (9.8)

The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie onl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T11:01:07.000Z ##

🔴 CVE-2026-12949 - Critical (9.8)

The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie onl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19789
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-14T19:09:39.140000

1 posts

A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the argument shareSpeed causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized

hugovalters@mastodon.social at 2026-08-14T23:04:33.000Z ##

CVE-2026-19789 – Critical stack buffer overflow in Tenda AC1206 via /goform/WifiGuestSet. Remote RCE possible. CVSS 8.8. Unpatched. Update or isolate now. #CVE #Tenda #infosec

valtersit.com/cve/CVE-2026-197

##

CVE-2026-19811
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-14T19:09:39.140000

4 posts

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

hugovalters@mastodon.social at 2026-08-14T18:03:22.000Z ##

CVE-2026-19811 - Critical stack buffer overflow in TOTOLINK A800R routers via setIpQosRules. Remote RCE possible, CVSS 8.8. Public exploit available, unpatched. Update firmware or isolate device now. #CVE #IoT #infosec

valtersit.com/cve/CVE-2026-198

##

thehackerwire@mastodon.social at 2026-08-14T09:00:58.000Z ##

🟠 CVE-2026-19811 - High (8.8)

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in sta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

hugovalters@mastodon.social at 2026-08-14T18:03:22.000Z ##

CVE-2026-19811 - Critical stack buffer overflow in TOTOLINK A800R routers via setIpQosRules. Remote RCE possible, CVSS 8.8. Public exploit available, unpatched. Update firmware or isolate device now. #CVE #IoT #infosec

valtersit.com/cve/CVE-2026-198

##

thehackerwire@mastodon.social at 2026-08-14T09:00:58.000Z ##

🟠 CVE-2026-19811 - High (8.8)

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in sta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19844
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-14T19:09:39.140000

2 posts

A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

thehackerwire@mastodon.social at 2026-08-14T18:00:15.000Z ##

🟠 CVE-2026-19844 - High (8.8)

A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T18:00:15.000Z ##

🟠 CVE-2026-19844 - High (8.8)

A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19792
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-14T19:09:39.140000

1 posts

A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the publ

hugovalters@mastodon.social at 2026-08-14T14:11:29.000Z ##

CVE-2026-19792 – Critical buffer overflow in Tenda G0 httpd via setPortMapping. Remote RCE risk. CVSS 8.8. Exploit public, no patch yet. Disable access or update ASAP. #CVE #Tenda #infosec

valtersit.com/cve/CVE-2026-197

##

CVE-2026-19815
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-14T19:09:39.140000

2 posts

A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.

thehackerwire@mastodon.social at 2026-08-14T11:00:43.000Z ##

🟠 CVE-2026-19815 - High (8.8)

A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T11:00:43.000Z ##

🟠 CVE-2026-19815 - High (8.8)

A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19813
(8.8 HIGH)

EPSS: 0.60%

updated 2026-08-14T19:09:39.140000

2 posts

A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

thehackerwire@mastodon.social at 2026-08-14T09:00:48.000Z ##

🟠 CVE-2026-19813 - High (8.8)

A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T09:00:48.000Z ##

🟠 CVE-2026-19813 - High (8.8)

A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18039
(8.1 HIGH)

EPSS: 0.15%

updated 2026-08-14T18:32:42

2 posts

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.

offseq at 2026-08-14T09:00:22.900Z ##

Essential Addons for Elementor (≤5.8.6) has a CRITICAL CWE-269 bug (CVE-2026-18039) allowing unauthenticated attackers to register admin accounts via custom profile fields. Disable user registration or adjust config until patched. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-14T09:00:22.000Z ##

Essential Addons for Elementor (≤5.8.6) has a CRITICAL CWE-269 bug (CVE-2026-18039) allowing unauthenticated attackers to register admin accounts via custom profile fields. Disable user registration or adjust config until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Security #CVE202618039

##

CVE-2026-19845
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-14T18:31:46

2 posts

A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

thehackerwire@mastodon.social at 2026-08-14T18:00:25.000Z ##

🟠 CVE-2026-19845 - High (8.8)

A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-bas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T18:00:25.000Z ##

🟠 CVE-2026-19845 - High (8.8)

A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-bas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73843
(9.6 CRITICAL)

EPSS: 0.29%

updated 2026-08-14T18:19:09.623000

2 posts

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and /api/exec/ operations, proxy the data-plane Kubernetes API, and execute commands in workload pods i

thehackerwire@mastodon.social at 2026-08-13T23:00:19.000Z ##

🔴 CVE-2026-73843 - Critical (9.6)

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T23:00:19.000Z ##

🔴 CVE-2026-73843 - Critical (9.6)

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72830
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-14T18:19:08.780000

2 posts

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can inject arbitrary commands into scheduler.custom_jobs that execute via Symfony Process for remote code execution.

offseq at 2026-08-14T12:00:26.200Z ##

Grav API plugin <1.0.13 has a CRITICAL flaw (CVE-2026-72830): scoped API keys can inject arbitrary commands into scheduler config, leading to remote code execution. Patch now! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-14T12:00:26.000Z ##

Grav API plugin <1.0.13 has a CRITICAL flaw (CVE-2026-72830): scoped API keys can inject arbitrary commands into scheduler config, leading to remote code execution. Patch now! radar.offseq.com/threat/cve-20 #OffSeq #CVE202672830 #Grav #RCE #Infosec

##

CVE-2026-66804
(7.8 HIGH)

EPSS: 3.03%

updated 2026-08-14T18:06:11.420000

6 posts

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/DavidCarliez/CVE-2026-66804-CrossDevice-LPE

https://github.com/Rat5ak/CVE-2026-66804-CrossDevice-Service-EoP

GossiTheDog@cyberplace.social at 2026-08-14T08:46:43.000Z ##

RE: infosec.exchange/@wdormann/117

I wrote some detections for CVE-2026-66804 exploitation:

github.com/GossiTheDog/ThreatH

##

Kerplunk@mastodon.scot at 2026-08-14T07:08:52.000Z ##

@wdormann
A working exploit to achieve a SYSTEM shell with only CVE-2026-66804 has been released.

Sounds bad
BUT
WINDOZE ONLY
AND
The probable attack vector involves a local, authorized attacker using the Cross Device Service, which can be abused to increase privileges on the host. Successful exploitation requires only local access and does not rely on remote network attack, making it potentially easier for insiders or malicious users with physical access.

##

Nadsec@cyberplace.social at 2026-08-13T04:26:52.000Z ##

CVE-2026-66804 - Windows Cross Device Service LPE - Writeup & PoC

Found another cool one!
nadsec.online/blog/cve-2026-66

Not sure who found it first, but shoutout to them. Despite not being FTF, my mom thinks this one is cool, which is the only important metric 😎

##

GossiTheDog@cyberplace.social at 2026-08-14T08:46:43.000Z ##

RE: infosec.exchange/@wdormann/117

I wrote some detections for CVE-2026-66804 exploitation:

github.com/GossiTheDog/ThreatH

##

Kerplunk@mastodon.scot at 2026-08-14T07:08:52.000Z ##

@wdormann
A working exploit to achieve a SYSTEM shell with only CVE-2026-66804 has been released.

Sounds bad
BUT
WINDOZE ONLY
AND
The probable attack vector involves a local, authorized attacker using the Cross Device Service, which can be abused to increase privileges on the host. Successful exploitation requires only local access and does not rely on remote network attack, making it potentially easier for insiders or malicious users with physical access.

##

Nadsec@cyberplace.social at 2026-08-13T02:25:32.000Z ##

@wdormann
CVE-2026-66804

Haha it’s a good one. And yeah not these days, I had thought I might have atleast been first to find but not quite 🤣

##

CVE-2026-73841
(8.8 HIGH)

EPSS: 0.35%

updated 2026-08-14T17:20:36.590000

2 posts

OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead of comp.Spec.Owner.ProjectName, allowing a user with a project-scoped grant to execute commands in

thehackerwire@mastodon.social at 2026-08-14T00:00:15.000Z ##

🟠 CVE-2026-73841 - High (8.8)

OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view usin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T00:00:15.000Z ##

🟠 CVE-2026-73841 - High (8.8)

OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view usin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72857
(7.7 HIGH)

EPSS: 0.26%

updated 2026-08-14T17:20:31.747000

2 posts

Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend database credentials and service account keys.

thehackerwire@mastodon.social at 2026-08-14T01:00:27.000Z ##

🟠 CVE-2026-72857 - High (7.7)

Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T01:00:27.000Z ##

🟠 CVE-2026-72857 - High (7.7)

Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72842
(9.9 CRITICAL)

EPSS: 0.42%

updated 2026-08-14T17:20:31.403000

2 posts

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape container directories and control host-side scripts executed through `lxc.hook.start-host`, achieving root code execution

offseq at 2026-08-14T06:00:24.514Z ##

CVE-2026-72842: CRITICAL vuln in OpenWrt luci-app-lxc. Authenticated users can bypass ACLs via `/.%2E` path traversal, leading to root code exec on host. Restrict LuCI access & monitor systems. Patch status pending. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-14T06:00:24.000Z ##

CVE-2026-72842: CRITICAL vuln in OpenWrt luci-app-lxc. Authenticated users can bypass ACLs via `/.%2E` path traversal, leading to root code exec on host. Restrict LuCI access & monitor systems. Patch status pending. radar.offseq.com/threat/cve-20 #OffSeq #OpenWrt #LinuxSec #CVE

##

CVE-2026-46439
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-14T17:18:14.853000

2 posts

compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an attacker to achieve arbitrary command execution with privileges of the running process by injecting malicious payloads i

thehackerwire@mastodon.social at 2026-08-14T18:00:05.000Z ##

🟠 CVE-2026-46439 - High (7.8)

compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T18:00:05.000Z ##

🟠 CVE-2026-46439 - High (7.8)

compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73420
(0 None)

EPSS: 0.53%

updated 2026-08-14T16:17:00.207000

2 posts

NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an address before applying Unicode normalization. An address can contain a Unicode character such as U+FF20 FULLWIDTH COMMERCIAL AT that is not ASCII at-sign but canonicalizes to an ASCII at-sign under NFK

offseq at 2026-08-14T01:30:27.070Z ##

NextAuth.js CRITICAL vuln (CVE-2026-73420): Unicode email normalization flaw lets attackers intercept magic links & access accounts. Affects pre-@auth/core 0.41.3, next-auth 4.24.15, 5.0.0-beta.32. Patch now! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-14T01:30:27.000Z ##

NextAuth.js CRITICAL vuln (CVE-2026-73420): Unicode email normalization flaw lets attackers intercept magic links & access accounts. Affects pre-@auth/core 0.41.3, next-auth 4.24.15, 5.0.0-beta.32. Patch now! radar.offseq.com/threat/cve-20 #OffSeq #NextAuth #IAM #CVE202673420

##

CVE-2026-53970
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-14T16:16:57.073000

2 posts

ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patch URLs without checksum validation. Attackers can intercept or replace downloads for secondary resource and patch paths in shim.rb, injecting attacker-co

thehackerwire@mastodon.social at 2026-08-14T17:00:02.000Z ##

🟠 CVE-2026-53970 - High (7.5)

ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T17:00:02.000Z ##

🟠 CVE-2026-53970 - High (7.5)

ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19768
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-14T15:32:54

2 posts

Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.

thehackerwire@mastodon.social at 2026-08-14T16:00:30.000Z ##

🟠 CVE-2026-19768 - High (8.1)

Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T16:00:30.000Z ##

🟠 CVE-2026-19768 - High (8.1)

Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73633
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-14T15:32:50

2 posts

Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. The plugin's configurable JSON input length limit does not bound this read. The

thehackerwire@mastodon.social at 2026-08-14T16:00:18.000Z ##

🟠 CVE-2026-73633 - High (7.5)

Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T16:00:18.000Z ##

🟠 CVE-2026-73633 - High (7.5)

Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72859
(7.7 HIGH)

EPSS: 0.00%

updated 2026-08-14T12:31:39

2 posts

Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by sending POST requests to the attachments endpoint. The route was changed from a BUILDER permission check to a TABLE/WRITE check, which BASIC users hold by default. Attackers can specify arbitrary S3 buckets in the request b

thehackerwire@mastodon.social at 2026-08-14T13:00:33.000Z ##

🟠 CVE-2026-72859 - High (7.7)

Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by sending POST requests to the attachments endpoint. The route was chang...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T13:00:33.000Z ##

🟠 CVE-2026-72859 - High (7.7)

Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by sending POST requests to the attachments endpoint. The route was chang...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72829
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-14T12:31:34

2 posts

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for api.users.write, but gate super-privilege grants on a bare isSuperAdmin() check that reads access.api.super directly without consulting the key's scopes. As a result, an api.users.write-scoped key minted on

offseq at 2026-08-14T13:30:26.112Z ##

CVE-2026-72829 (CRITICAL): getgrav grav API plugin <1.0.13 allows api.users.write-scoped keys from super accounts to escalate to full admin. Restrict API key use & monitor for privilege changes. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-14T13:30:26.000Z ##

CVE-2026-72829 (CRITICAL): getgrav grav API plugin <1.0.13 allows api.users.write-scoped keys from super accounts to escalate to full admin. Restrict API key use & monitor for privilege changes. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202672829 #infosec #WebAppSec

##

CVE-2026-19821
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-14T12:31:34

2 posts

A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argument rebootTime causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

thehackerwire@mastodon.social at 2026-08-14T12:01:12.000Z ##

🟠 CVE-2026-19821 - High (8.8)

A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argum...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T12:01:12.000Z ##

🟠 CVE-2026-19821 - High (8.8)

A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argum...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72837
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-14T12:31:28

2 posts

File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment.

thehackerwire@mastodon.social at 2026-08-14T13:00:18.000Z ##

🟠 CVE-2026-72837 - High (8.8)

File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T13:00:18.000Z ##

🟠 CVE-2026-72837 - High (8.8)

File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72836
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-14T12:16:47.060000

2 posts

FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (confirmed on Windows/NTFS), two self-registered usernames that differ only in letter case (e.g., CaseVictim and casevictim) are stored as distinct accounts

thehackerwire@mastodon.social at 2026-08-14T13:00:06.000Z ##

🟠 CVE-2026-72836 - High (8.1)

FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T13:00:06.000Z ##

🟠 CVE-2026-72836 - High (8.1)

FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19814
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-14T09:30:32

2 posts

A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used.

thehackerwire@mastodon.social at 2026-08-14T11:00:57.000Z ##

🟠 CVE-2026-19814 - High (8.8)

A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based bu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T11:00:57.000Z ##

🟠 CVE-2026-19814 - High (8.8)

A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based bu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19812
(8.8 HIGH)

EPSS: 0.49%

updated 2026-08-14T09:30:32

2 posts

A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

thehackerwire@mastodon.social at 2026-08-14T09:00:36.000Z ##

🟠 CVE-2026-19812 - High (8.8)

A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer ov...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T09:00:36.000Z ##

🟠 CVE-2026-19812 - High (8.8)

A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer ov...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19790
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-14T06:31:11

1 posts

A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the component httpd Web Management Interface. Such manipulation of the argument portMirrorMirroredPorts leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

hugovalters@mastodon.social at 2026-08-14T17:10:50.000Z ##

CVE-2026-19790 - Critical RCE in Tenda G0 router via stack buffer overflow in formSetPortMirror. Remote exploit public. CVSS 8.8. Unpatched—disable WAN management or isolate now. #CVE #Tenda #infosec

valtersit.com/cve/CVE-2026-197

##

CVE-2026-19791
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-14T06:31:11

1 posts

A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for att

hugovalters@mastodon.social at 2026-08-14T15:01:00.000Z ##

CVE-2026-19791 - Critical stack buffer overflow in Tenda G0 router web interface. Remote RCE via staticRouteNet param. CVSS 8.8. Unpatched, exploit public. Disable remote management now. #CVE #Tenda #infosec

valtersit.com/cve/CVE-2026-197

##

CVE-2026-19788
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-14T06:31:05

1 posts

A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The manipulation of the argument devName results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.

hugovalters@mastodon.social at 2026-08-14T11:07:13.000Z ##

CVE-2026-19788 – Critical stack buffer overflow in Tenda AC1206 router via /goform/SetOnlineDevName. Remote RCE possible. CVSS 8.8. Unpatched – update firmware or restrict access now. #CVE #Tenda #infosec

valtersit.com/cve/CVE-2026-197

##

CVE-2026-73570
(8.9 HIGH)

EPSS: 0.54%

updated 2026-08-14T05:17:00.340000

2 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

thehackerwire@mastodon.social at 2026-08-13T17:00:09.000Z ##

🟠 CVE-2026-73570 - High (8.9)

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notificati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T17:00:09.000Z ##

🟠 CVE-2026-73570 - High (8.9)

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notificati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72841
(9.9 CRITICAL)

EPSS: 0.42%

updated 2026-08-14T00:32:06

2 posts

luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code execution by placing SSH keys in system directories accessible on reboot.

offseq at 2026-08-14T10:30:25.427Z ##

CVE-2026-72841 (CRITICAL, CVSS 9.4) affects OpenWrt luci-app-openvpn: improper instance_name2 validation enables path traversal and arbitrary file writes, risking persistent root code execution. Restrict access & monitor uploads. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-14T10:30:25.000Z ##

CVE-2026-72841 (CRITICAL, CVSS 9.4) affects OpenWrt luci-app-openvpn: improper instance_name2 validation enables path traversal and arbitrary file writes, risking persistent root code execution. Restrict access & monitor uploads. radar.offseq.com/threat/cve-20 #OffSeq #OpenWrt #Vuln

##

CVE-2026-72850
(9.1 CRITICAL)

EPSS: 0.42%

updated 2026-08-14T00:32:06

4 posts

Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the temporary directory during workspace export, writing arbitrary content to any path writable by the Budibase process.

offseq at 2026-08-14T04:30:26.700Z ##

CVE-2026-72850: CRITICAL path traversal (CVSS 9.4) in Budibase server <3.40.0 lets authenticated builders write files outside temp dirs. Cloud-hosted — vendor patch applied server-side. Confirm upgrade. Details: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-14T03:01:12.000Z ##

🔴 CVE-2026-72850 - Critical (9.1)

Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the tempo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-14T04:30:26.000Z ##

CVE-2026-72850: CRITICAL path traversal (CVSS 9.4) in Budibase server <3.40.0 lets authenticated builders write files outside temp dirs. Cloud-hosted — vendor patch applied server-side. Confirm upgrade. Details: radar.offseq.com/threat/cve-20 #OffSeq #Budibase #Infosec #Vuln

##

thehackerwire@mastodon.social at 2026-08-14T03:01:12.000Z ##

🔴 CVE-2026-72850 - Critical (9.1)

Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the tempo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72851
(10.0 CRITICAL)

EPSS: 0.29%

updated 2026-08-14T00:32:06

2 posts

Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads that execute with builder-configured database credentials, enabling data exfiltration, modification, and persistence in connected datasources like Snowflake.

offseq at 2026-08-14T03:00:26.920Z ##

Budibase server <3.40.0 hit by CRITICAL SQL injection (CVE-2026-72851) in webhook-triggered EXECUTE_QUERY. Unauthenticated attackers can run arbitrary SQL on connected datasources (e.g., Snowflake). Patch managed by vendor. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-14T03:00:26.000Z ##

Budibase server <3.40.0 hit by CRITICAL SQL injection (CVE-2026-72851) in webhook-triggered EXECUTE_QUERY. Unauthenticated attackers can run arbitrary SQL on connected datasources (e.g., Snowflake). Patch managed by vendor. radar.offseq.com/threat/cve-20 #OffSeq #SQLi #Budibase #Infosec

##

CVE-2026-73421
(0 None)

EPSS: 0.64%

updated 2026-08-13T22:17:26.447000

2 posts

NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.js has a server configuration error. In middleware, Route Handlers, React Server Components, and other auth() entry points, a non-OK session response is parsed int

offseq at 2026-08-14T00:00:36.346Z ##

CVE-2026-73421 (CRITICAL, CVSS 9.1): nextauthjs next-auth (5.0.0-beta.0 to <5.0.0-beta.32) improper authorization bug lets unauthenticated users access protected routes if config is invalid. Patch now! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-14T00:00:36.000Z ##

CVE-2026-73421 (CRITICAL, CVSS 9.1): nextauthjs next-auth (5.0.0-beta.0 to <5.0.0-beta.32) improper authorization bug lets unauthenticated users access protected routes if config is invalid. Patch now! radar.offseq.com/threat/cve-20 #OffSeq #nextauthjs #CVE202673421 #infosec

##

CVE-2026-72849
(7.7 HIGH)

EPSS: 0.12%

updated 2026-08-13T22:17:24.140000

2 posts

Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked confirmation token to bind their chat identity to a victim user's account, enabling impersonation within agent operations and inh

thehackerwire@mastodon.social at 2026-08-14T03:01:03.000Z ##

🟠 CVE-2026-72849 - High (7.7)

Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T03:01:03.000Z ##

🟠 CVE-2026-72849 - High (7.7)

Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17197
(8.1 HIGH)

EPSS: 0.34%

updated 2026-08-13T21:36:08

2 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.

thehackerwire@mastodon.social at 2026-08-13T20:01:24.000Z ##

🟠 CVE-2026-17197 - High (8.1)

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T20:01:24.000Z ##

🟠 CVE-2026-17197 - High (8.1)

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72777
(8.6 HIGH)

EPSS: 0.32%

updated 2026-08-13T21:36:08

2 posts

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses, allowing them to reach arbitrary internal HTTP services and exfiltrate responses inc

thehackerwire@mastodon.social at 2026-08-13T20:01:09.000Z ##

🟠 CVE-2026-72777 - High (8.6)

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostna...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T20:01:09.000Z ##

🟠 CVE-2026-72777 - High (8.6)

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostna...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73482
(8.1 HIGH)

EPSS: 0.24%

updated 2026-08-13T21:36:08

2 posts

phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSRF token (the central verifyCsrfGetToken check uses enforce=false and is bypassed when the token parameter is absent). A remote attacker can trick a logge

thehackerwire@mastodon.social at 2026-08-13T20:00:28.000Z ##

🟠 CVE-2026-73482 - High (8.1)

phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSR...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T20:00:28.000Z ##

🟠 CVE-2026-73482 - High (8.1)

phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSR...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10534
(8.4 HIGH)

EPSS: 0.18%

updated 2026-08-13T20:59:20.483000

2 posts

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

thehackerwire@mastodon.social at 2026-08-13T08:00:36.000Z ##

🟠 CVE-2026-10534 - High (8.4)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T08:00:36.000Z ##

🟠 CVE-2026-10534 - High (8.4)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17220
(8.2 HIGH)

EPSS: 0.39%

updated 2026-08-13T20:36:48.443000

2 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow.

thehackerwire@mastodon.social at 2026-08-13T20:01:34.000Z ##

🟠 CVE-2026-17220 - High (8.2)

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T20:01:34.000Z ##

🟠 CVE-2026-17220 - High (8.2)

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73653
(9.4 CRITICAL)

EPSS: 0.64%

updated 2026-08-13T19:17:38.920000

2 posts

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API

thehackerwire@mastodon.social at 2026-08-13T20:00:19.000Z ##

🔴 CVE-2026-73653 - Critical (9.4)

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T20:00:19.000Z ##

🔴 CVE-2026-73653 - Critical (9.4)

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73650
(8.2 HIGH)

EPSS: 0.24%

updated 2026-08-13T19:17:38.460000

2 posts

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove namespaced or prefixed script elements such as <svg:script> and, in versions 3 and

thehackerwire@mastodon.social at 2026-08-13T20:00:08.000Z ##

🟠 CVE-2026-73650 - High (8.2)

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T20:00:08.000Z ##

🟠 CVE-2026-73650 - High (8.2)

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73515
(8.1 HIGH)

EPSS: 0.41%

updated 2026-08-13T18:31:43

2 posts

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-vis

thehackerwire@mastodon.social at 2026-08-13T17:00:29.000Z ##

🟠 CVE-2026-73515 - High (8.1)

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T17:00:29.000Z ##

🟠 CVE-2026-73515 - High (8.1)

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73514
(8.8 HIGH)

EPSS: 0.45%

updated 2026-08-13T18:18:18.097000

2 posts

The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() to trigger memory corruption by providing a rules table with a classification Type value exceeding the fixed class range. Attackers can craft a malicious

thehackerwire@mastodon.social at 2026-08-13T17:00:19.000Z ##

🟠 CVE-2026-73514 - High (8.8)

The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T17:00:19.000Z ##

🟠 CVE-2026-73514 - High (8.8)

The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73493
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-13T18:18:17.740000

1 posts

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated fragmented message and drive unbounded heap growth in the server JVM, resulting in denia

thehackerwire@mastodon.social at 2026-08-12T23:00:57.000Z ##

🟠 CVE-2026-73493 - High (7.5)

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A clie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69105
(8.1 HIGH)

EPSS: 0.13%

updated 2026-08-13T16:18:55.870000

1 posts

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

thehackerwire@mastodon.social at 2026-08-12T17:01:14.000Z ##

🟠 CVE-2026-69105 - High (8.1)

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-41769
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-08-13T16:17:50.857000

3 posts

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

beyondmachines1 at 2026-08-13T17:01:37.302Z ##

Phoenix Contact Patches Critical Buffer Overflow in PLCnext Firmware

Phoenix Contact addressed three vulnerabilities in PLCnext firmware, including a critical buffer overflow (CVE-2025-41769) that allows unauthenticated remote code execution. The update also fixes denial-of-service and SQL injection flaws affecting various industrial controllers.

**If you run Phoenix Contact PLCnext controllers, first make sure these devices are isolated from the internet and reachable only from trusted networks. Then update the firmware to version 2026.0.3 on every compatible device. For the obsolete EPC 1502 and EPC 1522, which will never be patched, take them off the network or replace them with supported hardware.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-13T17:01:37.000Z ##

Phoenix Contact Patches Critical Buffer Overflow in PLCnext Firmware

Phoenix Contact addressed three vulnerabilities in PLCnext firmware, including a critical buffer overflow (CVE-2025-41769) that allows unauthenticated remote code execution. The update also fixes denial-of-service and SQL injection flaws affecting various industrial controllers.

**If you run Phoenix Contact PLCnext controllers, first make sure these devices are isolated from the internet and reachable only from trusted networks. Then update the firmware to version 2026.0.3 on every compatible device. For the obsolete EPC 1502 and EPC 1522, which will never be patched, take them off the network or replace them with supported hardware.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

cR0w@infosec.exchange at 2026-08-12T14:19:11.000Z ##

BoF in a PROFINET service?! I'm shocked. Shocked! Well, not that shocked.

nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-28173
(7.1 HIGH)

EPSS: 0.23%

updated 2026-08-13T15:34:46

1 posts

Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.

hugovalters@mastodon.social at 2026-08-13T23:09:09.000Z ##

CVE-2026-28173 - Arbitrary content deletion in WP Event Solution <= 4.1.19. CVSS 7.1. Unpatched - check your installs and restrict access now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-281

##

CVE-2026-6464
(8.1 HIGH)

EPSS: 0.49%

updated 2026-08-13T15:34:45

2 posts

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has

1 repos

https://github.com/oscerd/CVE-2026-64640

thehackerwire@mastodon.social at 2026-08-13T14:00:46.000Z ##

🟠 CVE-2026-6464 - High (8.1)

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T14:00:46.000Z ##

🟠 CVE-2026-6464 - High (8.1)

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55040
(9.1 CRITICAL)

EPSS: 3.97%

updated 2026-08-13T15:34:13

10 posts

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

2 repos

https://github.com/l0ggg/CVE-2026-55040

https://github.com/sfewer-r7/CVE-2026-55040

cyberveille@mastobot.ping.moi at 2026-08-13T17:00:07.000Z ##

📢 CVE-2026-55040 : vulnérabilité SharePoint exploitée dans la nature après publication d'un PoC

Il rapporte l'exploitation active en conditions réelles de CVE-2026-55040, une vulnérabilité affectant Microsoft SharePoint, corrigée lors du Patch Tuesday de juillet 2026. CVE-2026-55040 est décrite par Microsoft comme un problème d'authentification faible…

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : securityweek.com/sharepoint-vu
🟢 vérification factuelle haute
#PoC #SharePoint #Cyberveille

##

hackerdogs@mastodon.social at 2026-08-13T16:02:54.000Z ##

Attackers are actively exploiting CVE-2026-55040, a critical remote code execution vulnerability in Microsoft SharePoint, after a proof-of-concept exploit was released by Rapid7. This flaw affects Sha
helpnetsecurity.com/2026/08/13
#cybersecurity #Microsoft #SharePoint

##

ottoto2017@prattohome.com at 2026-08-13T07:17:47.000Z ##

「公開された概念実証(PoC)リリース後、攻撃者がSharePointの認証バイパスを悪用 」: #TheHackerNews

「攻撃者は、概念実証(PoC)コードの公開を受けて、新たに明らかになったMicrosoft SharePointの脆弱性を悪用し始めている。

問題となっている脆弱性は CVE-2026-55040 (CVSSスコア:9.1)で、認証の脆弱性に起因する重大なセキュリティ機能のバイパスに関するものです。この脆弱性は、マイクロソフトが2026年7月のパッチチューズデーアップデートの一環として修正しました。

マイクロソフトは先月、この脆弱性に関する勧告の中で、「この脆弱性によりなりすましが可能になるため、認証機能が回避される可能性がある」と述べた。「この脆弱性を悪用すると、攻撃者はファイルを漏洩させたりデータを改ざんしたりできる可能性があるが、システムの可用性に影響を与えることはできない」としている。 」

thehackernews.com/2026/08/atta

#prattohome

##

Analyst207@mastodon.social at 2026-08-13T07:01:46.000Z ##

Attackers Exploit SharePoint Flaw After Public PoC Release

Microsoft warned that a critical SharePoint flaw, patched in July 2026, could allow attackers to bypass authentication and disclose files or modify data. This vulnerability, tracked as CVE-2026-55040, has now been exploited by attackers following the public release of a proof-of-concept exploit.

osintsights.com/attackers-expl

#Cve202655040 #SharepointFlaw #Microsoft #AuthenticationBypass #SupplyChain

##

undercodenews@mastodon.social at 2026-08-13T06:40:18.000Z ##

Microsoft SharePoint Under Attack: Critical CVE-2026-55040 Exploitation Surges After Public PoC Release + Video

A New SharePoint Warning Is Turning Into a Real-World Security Crisis Microsoft SharePoint administrators are facing another serious warning as attackers appear to be testing a critical authentication-bypass vulnerability that can allow unauthenticated users to impersonate legitimate SharePoint accounts. The situation became more urgent after security…

undercodenews.com/microsoft-sh

##

dailytechfeed@mastodon.social at 2026-08-13T06:18:57.000Z ##

Cybercriminals are exploiting SharePoint vulnerability CVE-2026-55040, allowing authentication bypass and unauthorized access. Organizations should apply patches immediately to mitigate this risk.

#CyberSecurity #SharePoint #CVE202655040 #AuthenticationBypass #DataBreach #Microsoft

thedailytechfeed.com/attackers

##

cyberworldops at 2026-08-13T04:10:00.996Z ##

Rapid7 released a proof-of-concept for CVE-2026-55040, a critical SharePoint vulnerability, on August 12. Within hours, Defused observed the exploit weaponized against SharePoint honeypots. Microsoft patched the flaw in July, yet Shadowserver still reports over 8,500 exposed servers. Patching is no longer optional.

cyberworldops.eu/en/sharepoint

##

ottoto2017@prattohome.com at 2026-08-13T07:17:47.000Z ##

「公開された概念実証(PoC)リリース後、攻撃者がSharePointの認証バイパスを悪用 」: #TheHackerNews

「攻撃者は、概念実証(PoC)コードの公開を受けて、新たに明らかになったMicrosoft SharePointの脆弱性を悪用し始めている。

問題となっている脆弱性は CVE-2026-55040 (CVSSスコア:9.1)で、認証の脆弱性に起因する重大なセキュリティ機能のバイパスに関するものです。この脆弱性は、マイクロソフトが2026年7月のパッチチューズデーアップデートの一環として修正しました。

マイクロソフトは先月、この脆弱性に関する勧告の中で、「この脆弱性によりなりすましが可能になるため、認証機能が回避される可能性がある」と述べた。「この脆弱性を悪用すると、攻撃者はファイルを漏洩させたりデータを改ざんしたりできる可能性があるが、システムの可用性に影響を与えることはできない」としている。 」

thehackernews.com/2026/08/atta

#prattohome

##

cyberworldops@infosec.exchange at 2026-08-13T04:10:00.000Z ##

Rapid7 released a proof-of-concept for CVE-2026-55040, a critical SharePoint vulnerability, on August 12. Within hours, Defused observed the exploit weaponized against SharePoint honeypots. Microsoft patched the flaw in July, yet Shadowserver still reports over 8,500 exposed servers. Patching is no longer optional.

#SharePoint #CVE2026 #VulnerabilityManagement #PatchTuesday

cyberworldops.eu/en/sharepoint

##

jbhall56@infosec.exchange at 2026-08-12T12:48:27.000Z ##

Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator. bleepingcomputer.com/news/micr

##

CVE-2026-71398
(10.0 CRITICAL)

EPSS: 0.64%

updated 2026-08-13T15:20:01.813000

2 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

CVE-2026-59500
(10.0 CRITICAL)

EPSS: 0.38%

updated 2026-08-13T15:19:53.323000

2 posts

CWE-287: Improper Authentication

CVE-2026-19311
(8.1 HIGH)

EPSS: 0.41%

updated 2026-08-13T15:19:38.027000

1 posts

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

thehackerwire@mastodon.social at 2026-08-12T20:00:16.000Z ##

🟠 CVE-2026-19311 - High (8.1)

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11840
(8.8 HIGH)

EPSS: 1.58%

updated 2026-08-13T15:19:27.787000

1 posts

Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.

hugovalters@mastodon.social at 2026-08-13T17:14:55.000Z ##

CVE-2026-11840 - Authenticated SQLi in Zohocorp ManageEngine Password Manager Pro & PAM360. CVSS 8.8. Unpatched. Update immediately. #CVE #Zoho #infosec

valtersit.com/cve/CVE-2026-118

##

CVE-2026-73519
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-08-13T14:17:13.773000

2 posts

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate without any session, API key, or user account. Attackers can reach an affected node's management po

offseq@infosec.exchange at 2026-08-13T03:00:30.000Z ##

CVE-2026-73519: WolfStack <25.9.2 vulnerable to hard-coded secret in src/auth/mod.rs — remote attackers can bypass auth & run root commands in containers via the management port. Restrict access & monitor for X-WolfStack-Secret usage. radar.offseq.com/threat/cve-20 #OffSeq #CVE202673519

##

thehackerwire@mastodon.social at 2026-08-12T23:00:10.000Z ##

🔴 CVE-2026-73519 - Critical (9.8)

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71193
(9.6 CRITICAL)

EPSS: 0.53%

updated 2026-08-13T14:17:12.087000

2 posts

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redire

offseq@infosec.exchange at 2026-08-13T01:30:26.000Z ##

OpenStack Designate CRITICAL vuln (CVE-2026-71193, CVSS 9.6): Authenticated users can hijack or disrupt DNS cross-tenant by bypassing zone checks via AttributeFilter in multi-pool deployments. Disable AttributeFilter until patched. radar.offseq.com/threat/cve-20 #OffSeq #OpenStack #DNS #Vuln

##

thehackerwire@mastodon.social at 2026-08-13T00:00:05.000Z ##

🔴 CVE-2026-71193 - Critical (9.6)

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different poo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66898
(9.9 CRITICAL)

EPSS: 0.34%

updated 2026-08-13T14:17:11.320000

1 posts

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing pa

thehackerwire@mastodon.social at 2026-08-12T22:01:06.000Z ##

🔴 CVE-2026-66898 - Critical (9.9)

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14863
(8.8 HIGH)

EPSS: 1.67%

updated 2026-08-13T14:16:54.583000

4 posts

FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in shell double-quotes directly to exec() without escapeshellarg() sanitization, allowi

catc0n at 2026-08-15T01:51:44.333Z ##

New vulnerability disclosure from
@chocapikk_:

CVE-2026-14863 is an OS command injection-to-RCE in FileRun, a commercial self-hosted file manager. Internet footprint is an appreciable 3.5K or so based on the team's ASM queries. Good stuff as always from Valentin.

vulncheck.com/blog/filerun-thu

##

AAKL at 2026-08-13T16:58:53.238Z ##

New.

"Today VulnCheck is disclosing CVE-2026-14863, an OS command injection to remote code execution in FileRun, a commercial self-hosted file manager. It is being disclosed in accordance with VulnCheck's coordinated vulnerability disclosure policy."

"The motivation was deliberate. Open-source codebases are getting shredded by AI-assisted auditing, where every researcher and their LLM greps the same GitHub repos and finds the same bugs."

Vulncheck: FileRun: When Your File Manager Runs Your Files vulncheck.com/blog/filerun-thu @vulncheck

##

catc0n@infosec.exchange at 2026-08-15T01:51:44.000Z ##

New vulnerability disclosure from
@chocapikk_:

CVE-2026-14863 is an OS command injection-to-RCE in FileRun, a commercial self-hosted file manager. Internet footprint is an appreciable 3.5K or so based on the team's ASM queries. Good stuff as always from Valentin.

vulncheck.com/blog/filerun-thu

##

AAKL@infosec.exchange at 2026-08-13T16:58:53.000Z ##

New.

"Today VulnCheck is disclosing CVE-2026-14863, an OS command injection to remote code execution in FileRun, a commercial self-hosted file manager. It is being disclosed in accordance with VulnCheck's coordinated vulnerability disclosure policy."

"The motivation was deliberate. Open-source codebases are getting shredded by AI-assisted auditing, where every researcher and their LLM greps the same GitHub repos and finds the same bugs."

Vulncheck: FileRun: When Your File Manager Runs Your Files vulncheck.com/blog/filerun-thu @vulncheck #infosec #opensource #vulnerability

##

CVE-2026-73418
(7.5 HIGH)

EPSS: 0.46%

updated 2026-08-13T13:19:17.513000

1 posts

NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a malformed Authorization: Bearer header. When no session cookie is present, getToken() URL-decodes the bearer value before validating it, and malformed perce

thehackerwire@mastodon.social at 2026-08-12T22:00:55.000Z ##

🟠 CVE-2026-73418 - High (7.5)

NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a mal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49819
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-08-13T13:19:09.937000

3 posts

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token, IP allow-list, or rate limit and is gated only by a `totalSuperusers > 0` count check — a conditio

thehackerwire@mastodon.social at 2026-08-13T03:01:18.000Z ##

🔴 CVE-2026-49819 - Critical (9.8)

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T03:01:18.000Z ##

🔴 CVE-2026-49819 - Critical (9.8)

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-13T00:00:35.000Z ##

CVE-2026-49819: UpSnap (4.4.1 – 5.3.5) has a CRITICAL flaw (CVSS 9.8) — unauthenticated attackers can register a superuser & achieve root RCE via POST /api/upsnap/init-superuser. Upgrade to 5.4.0 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Infosec #RCE

##

CVE-2026-19002
(8.1 HIGH)

EPSS: 0.29%

updated 2026-08-13T13:17:48.387000

1 posts

A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. The resulting memory corruption may cause the client appli

thehackerwire@mastodon.social at 2026-08-12T22:02:20.000Z ##

🟠 CVE-2026-19002 - High (8.1)

A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59501
(8.2 HIGH)

EPSS: 0.32%

updated 2026-08-13T12:31:13

2 posts

CWE-284: Improper Access Control

CVE-2026-12263
(8.8 HIGH)

EPSS: 0.70%

updated 2026-08-13T12:31:13

2 posts

Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.

thehackerwire@mastodon.social at 2026-08-13T12:00:54.000Z ##

🟠 CVE-2026-12263 - High (8.8)

Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T12:00:54.000Z ##

🟠 CVE-2026-12263 - High (8.8)

Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59506
(9.3 CRITICAL)

EPSS: 0.40%

updated 2026-08-13T12:31:13

2 posts

CWE-306: Missing Authentication for Critical Function

offseq at 2026-08-13T12:00:25.087Z ##

CVE-2026-59506 (CRITICAL): Portal Generator addon to Priority ERP lacks authentication for a critical function. Unauthenticated remote attackers can access sensitive data. No patch yet — restrict access & monitor. More info: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-13T12:00:25.000Z ##

CVE-2026-59506 (CRITICAL): Portal Generator addon to Priority ERP lacks authentication for a critical function. Unauthenticated remote attackers can access sensitive data. No patch yet — restrict access & monitor. More info: radar.offseq.com/threat/cve-20 #OffSeq #CVE202659506 #ERP #Infosec

##

CVE-2026-59507
(9.3 CRITICAL)

EPSS: 0.32%

updated 2026-08-13T12:31:13

2 posts

CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control

offseq at 2026-08-13T10:30:23.699Z ##

CVE-2026-59507 (CRITICAL, CVSS 9.3) impacts Priority ERP Portal Generator addon: hard-coded creds, info exposure, improper access control. No patch yet — restrict access & monitor systems. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-13T10:30:23.000Z ##

CVE-2026-59507 (CRITICAL, CVSS 9.3) impacts Priority ERP Portal Generator addon: hard-coded creds, info exposure, improper access control. No patch yet — restrict access & monitor systems. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #ERP

##

CVE-2026-0301(CVSS UNKNOWN)

EPSS: 0.31%

updated 2026-08-13T03:31:24

2 posts

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.

AAKL at 2026-08-13T16:06:46.177Z ##

There are several updates from Broadcom addressing a long list of vulnerabilities, one of them critical support.broadcom.com/web/ecx/s

Yesterday:

CISA:

CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts cisa.gov/news-events/news/cisa

Palo Alto: CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering security.paloaltonetworks.com/

##

AAKL@infosec.exchange at 2026-08-13T16:06:46.000Z ##

There are several updates from Broadcom addressing a long list of vulnerabilities, one of them critical support.broadcom.com/web/ecx/s #Broadcom

Yesterday:

CISA:

CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts cisa.gov/news-events/news/cisa #CISA

Palo Alto: CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering security.paloaltonetworks.com/ #infosec #vulnerability

##

CVE-2026-71469
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-13T00:31:33

2 posts

A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This can lead to memory exhaustion of the search-api pod, resulting in a Denial of Service (DoS).

thehackerwire@mastodon.social at 2026-08-13T08:00:13.000Z ##

🟠 CVE-2026-71469 - High (7.5)

A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T08:00:13.000Z ##

🟠 CVE-2026-71469 - High (7.5)

A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19003
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-13T00:31:33

1 posts

A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder selection handling, and is reached only when a user opens the setup dialog for such a data source and initiates a file or fol

thehackerwire@mastodon.social at 2026-08-12T23:01:17.000Z ##

🟠 CVE-2026-19003 - High (7.8)

A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71471
(9.0 None)

EPSS: 1.45%

updated 2026-08-13T00:31:26

4 posts

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all managed clusters. The consequence is remote code execution (RCE), enabling the attac

thehackerwire@mastodon.social at 2026-08-13T08:00:24.000Z ##

🔴 CVE-2026-71471 - Critical (9)

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-13T04:30:24.734Z ##

CVE-2026-71471 (CRITICAL): acm-search-v2-rhel9 lets hub admins with Search CR patch rights deploy arbitrary containers fleet-wide. RCE & data access at risk. Restrict Search CR patch access now. Full details: radar.offseq.com/threat/a-flaw

##

thehackerwire@mastodon.social at 2026-08-13T08:00:24.000Z ##

🔴 CVE-2026-71471 - Critical (9)

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-13T04:30:24.000Z ##

CVE-2026-71471 (CRITICAL): acm-search-v2-rhel9 lets hub admins with Search CR patch rights deploy arbitrary containers fleet-wide. RCE & data access at risk. Restrict Search CR patch access now. Full details: radar.offseq.com/threat/a-flaw #OffSeq #Kubernetes #RedHat #Infosec

##

CVE-2026-71473
(8.5 HIGH)

EPSS: 0.26%

updated 2026-08-13T00:31:26

1 posts

A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critical settings, leading to the replacement of container images. This ultimately results in container image injection on the managed cluster, potentially com

thehackerwire@mastodon.social at 2026-08-12T23:00:20.000Z ##

🟠 CVE-2026-71473 - High (8.5)

A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73292
(8.3 HIGH)

EPSS: 0.19%

updated 2026-08-12T23:17:24.190000

1 posts

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an unauthenticated attacker to change an administrator's or another user's password after user interaction. This issue is fixed in ve

thehackerwire@mastodon.social at 2026-08-12T17:00:15.000Z ##

🟠 CVE-2026-73292 - High (8.3)

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19001
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-08-12T21:31:51

1 posts

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-12T22:02:10.000Z ##

🔴 CVE-2026-19001 - Critical (9.8)

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73326
(7.6 HIGH)

EPSS: 0.27%

updated 2026-08-12T21:31:50

1 posts

CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime across the attack, front_cache, cama_meta_tag, and cama_contact_form plugins to al

thehackerwire@mastodon.social at 2026-08-12T21:01:37.000Z ##

🟠 CVE-2026-73326 - High (7.6)

CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorizatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17083
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-08-12T21:31:44

2 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

nyanbinary at 2026-08-13T14:26:21.890Z ##

also: those are some god damn useless CVEs, istg... db.gcve.eu/vuln/cve-2026-17083

##

nyanbinary@infosec.exchange at 2026-08-13T14:26:21.000Z ##

also: those are some god damn useless CVEs, istg... db.gcve.eu/vuln/cve-2026-17083

##

CVE-2026-73433
(6.6 MEDIUM)

EPSS: 0.13%

updated 2026-08-12T21:31:44

1 posts

A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads of exactly 106 or 107 bytes, the counter underflows to a very large unsigned value, causing subsequent null-terminated

thehackerwire@mastodon.social at 2026-08-12T21:00:14.000Z ##

🟠 CVE-2026-73433 - High (7.6)

A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72798
(8.6 HIGH)

EPSS: 0.26%

updated 2026-08-12T21:31:42

1 posts

SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block ty

hugovalters@mastodon.social at 2026-08-13T12:02:21.000Z ##

CVE-2026-72798 - High severity info disclosure in SiYuan. Unpatched v3.7.4 lets anonymous readers access hidden database content via related-database bypass. CVSS 8.6. Update immediately. #CVE #SiYuan #infosec

valtersit.com/cve/CVE-2026-727

##

CVE-2026-73329
(8.7 HIGH)

EPSS: 0.23%

updated 2026-08-12T21:17:40.527000

1 posts

CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter during draft creation. Attackers can submit a malicious HTML payload as a draft title through the drafts creation endpoint, which is persisted to the databas

thehackerwire@mastodon.social at 2026-08-12T21:00:25.000Z ##

🟠 CVE-2026-73329 - High (8.7)

CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter duri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73498
(7.7 HIGH)

EPSS: 0.33%

updated 2026-08-12T21:17:31

1 posts

### Summary `confluence_upload_attachment` passes `file_path` directly to `open(file_path, "rb")` with no path validation. Any authenticated MCP client — or an AI agent manipulated via prompt injection — can read any file the server process can access and exfiltrate it to Confluence as an attachment. ### Details Root cause: `src/mcp_atlassian/confluence/attachments.py`, `_upload_attachment_direct

thehackerwire@mastodon.social at 2026-08-12T23:01:08.000Z ##

🟠 CVE-2026-73498 - High (7.7)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71362
(9.1 CRITICAL)

EPSS: 0.48%

updated 2026-08-12T21:03:43.743000

12 posts

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

jbhall56 at 2026-08-14T13:36:46.214Z ##

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. securityweek.com/adobe-commerc

##

beyondmachines1 at 2026-08-14T11:01:37.073Z ##

Adobe Reporrts Critical Magento Flaw Under Active Attack

Attackers began probing CVE-2026-71362 (CVSS 9.1), a critical incorrect-authorization flaw in Adobe Commerce, B2B, and Magento Open Source almost immediately after Adobe's August 11 patch (APSB26-92) went public. Sansec blocked the first exploitation attempts shortly after the advisory.

**If you run Adobe Commerce, Adobe Commerce B2B or Magento Open Source, update immediately to the "-2026-aug" release for your version. Attackers are already exploiting this flaw to take over customer accounts. After patching, force a logout of all active customer sessions and review recent account activity for signs that someone else accessed customer data.**

beyondmachines.net/event_detai

##

undercodenews@mastodon.social at 2026-08-13T18:35:12.000Z ##

Adobe Commerce CVE-2026-71362 Exploited Almost Immediately, Turning a Critical 91 Flaw Into an Urgent Security Warning + Video

A Critical Vulnerability Moves From Disclosure to Exploitation Some cybersecurity vulnerabilities remain theoretical for months. Others become dangerous the moment the technical details become public. CVE-2026-71362 appears to belong to the second category. A critical Adobe Commerce vulnerability rated 9.1 has reportedly been exploited shortly…

undercodenews.com/adobe-commer

##

undercodenews@mastodon.social at 2026-08-13T18:27:47.000Z ##

Critical Adobe Commerce Flaw CVE-2026-71362 Is Under Active Attack: Hackers Can Hijack Customer Accounts Without Logging In + Video

A Dangerous Warning for Every Magento Store Owner A critical vulnerability in Adobe Commerce and Magento Open Source has moved from disclosure to exploitation with alarming speed. CVE-2026-71362, carrying a CVSS score of 9.1, gives unauthenticated attackers a way to manipulate customer sessions, potentially hijack accounts and access…

undercodenews.com/critical-ado

##

ottoto2017@prattohome.com at 2026-08-13T07:06:11.000Z ##

「ハッカーがAdobe Commerceの重大な脆弱性を悪用し、顧客アカウントを乗っ取る 」: #BLEEPINGCOMPUTER

「AdobeのeコマースプラットフォームであるCommerceとMagentoにおける重大な脆弱性(CVE-2026-71362)を悪用しようとする試みが検出されました。この脆弱性により、攻撃者が顧客アカウントを乗っ取る可能性があります。

この脆弱性は、認証なしに「機密性の高いリソースへの上位アクセス権を取得する」ために悪用される可能性のある、誤った認証の脆弱性と説明されており、Adobeが昨日のセキュリティアップデートで対処した7つの問題のうちの1つです。

ソフトウェアベンダーは 勧告 の中で、修正された脆弱性に対する実際の攻撃事例は把握していないと述べているが、eコマースセキュリティ企業のSansecは、同社のShieldウェブアプリケーションファイアウォール(WAF)が既にCVE-2026-71362の悪用を阻止していると述べている。 」

bleepingcomputer.com/news/secu

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

jbhall56@infosec.exchange at 2026-08-14T13:36:46.000Z ##

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. securityweek.com/adobe-commerc

##

beyondmachines1@infosec.exchange at 2026-08-14T11:01:37.000Z ##

Adobe Reporrts Critical Magento Flaw Under Active Attack

Attackers began probing CVE-2026-71362 (CVSS 9.1), a critical incorrect-authorization flaw in Adobe Commerce, B2B, and Magento Open Source almost immediately after Adobe's August 11 patch (APSB26-92) went public. Sansec blocked the first exploitation attempts shortly after the advisory.

**If you run Adobe Commerce, Adobe Commerce B2B or Magento Open Source, update immediately to the "-2026-aug" release for your version. Attackers are already exploiting this flaw to take over customer accounts. After patching, force a logout of all active customer sessions and review recent account activity for signs that someone else accessed customer data.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

ottoto2017@prattohome.com at 2026-08-13T07:06:11.000Z ##

「ハッカーがAdobe Commerceの重大な脆弱性を悪用し、顧客アカウントを乗っ取る 」: #BLEEPINGCOMPUTER

「AdobeのeコマースプラットフォームであるCommerceとMagentoにおける重大な脆弱性(CVE-2026-71362)を悪用しようとする試みが検出されました。この脆弱性により、攻撃者が顧客アカウントを乗っ取る可能性があります。

この脆弱性は、認証なしに「機密性の高いリソースへの上位アクセス権を取得する」ために悪用される可能性のある、誤った認証の脆弱性と説明されており、Adobeが昨日のセキュリティアップデートで対処した7つの問題のうちの1つです。

ソフトウェアベンダーは 勧告 の中で、修正された脆弱性に対する実際の攻撃事例は把握していないと述べているが、eコマースセキュリティ企業のSansecは、同社のShieldウェブアプリケーションファイアウォール(WAF)が既にCVE-2026-71362の悪用を阻止していると述べている。 」

bleepingcomputer.com/news/secu

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

cyberworldops@infosec.exchange at 2026-08-12T22:10:00.000Z ##

Active exploitation attempts targeting CVE-2026-71362 have been observed since August 12, 2026, affecting Adobe Commerce and Magento installations. The flaw is an authorization bypass that grants unauthenticated access to sensitive resources due to incorrect identity handling.

#CVE202671362 #AdobeCommerce #Magento #AuthorizationBypass

cyberworldops.eu/en/adobe-comm

##

oversecurity@mastodon.social at 2026-08-12T21:30:32.000Z ##

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially...

🔗️ [Bleepingcomputer] link.is.it/JJqIH9

##

CVE-2026-71384
(9.6 CRITICAL)

EPSS: 0.24%

updated 2026-08-12T21:03:43.743000

2 posts

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this is

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

CVE-2026-73332
(8.7 HIGH)

EPSS: 0.23%

updated 2026-08-12T20:17:55.480000

1 posts

CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which lacks proper authorization controls. Attackers can persist malicious script payloads into the database that execute in vic

thehackerwire@mastodon.social at 2026-08-12T21:00:35.000Z ##

🟠 CVE-2026-73332 - High (8.7)

CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64629
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-12T20:17:48.073000

2 posts

A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.

cyberworldops at 2026-08-14T02:10:00.661Z ##

Siemens has patched CVE-2026-64629, an out-of-bounds read in the Parasolid kernel triggered by crafted X_T files. The flaw can crash applications or allow arbitrary code execution in the context of the reading process.

cyberworldops.eu/en/siemens-pa

##

cyberworldops@infosec.exchange at 2026-08-14T02:10:00.000Z ##

Siemens has patched CVE-2026-64629, an out-of-bounds read in the Parasolid kernel triggered by crafted X_T files. The flaw can crash applications or allow arbitrary code execution in the context of the reading process.

#Siemens #CVE202664629 #Parasolid #OutofBoundsRead

cyberworldops.eu/en/siemens-pa

##

CVE-2026-73406
(7.5 HIGH)

EPSS: 0.37%

updated 2026-08-12T19:03:59

1 posts

#### Summary The Budibase Worker service exposes a public, unauthenticated API endpoint (`GET /api/global/users/tenant/:id`) that returns sensitive user information including `tenantId`, `userId`, `email`, and `ssoId`. The endpoint is registered in the `PUBLIC_ENDPOINTS` list with a `TODO` comment acknowledging it "should be an internal API." Any unauthenticated party can enumerate user emails or

thehackerwire@mastodon.social at 2026-08-12T21:01:12.000Z ##

🟠 CVE-2026-73406 - High (7.5)

Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated cal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73305
(8.8 HIGH)

EPSS: 0.37%

updated 2026-08-12T18:57:18

2 posts

### Summary Budibase `3.39.19` (commit `03fbabae4`) is affected by a privilege-escalation / missing-authorization flaw in the public role-assignment API. An **app-scoped builder** (a user who builds only specific apps — `user.builder.apps = [appA]`, not a global builder or admin) can grant **themselves builder access to ANY other app in the tenant**, or assign themselves/any user an arbitrary dat

thehackerwire@mastodon.social at 2026-08-14T01:00:38.000Z ##

🟠 CVE-2026-73305 - High (8.8)

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleValidation.ts....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T01:00:38.000Z ##

🟠 CVE-2026-73305 - High (8.8)

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleValidation.ts....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73303(CVSS UNKNOWN)

EPSS: 0.23%

updated 2026-08-12T18:56:58

1 posts

## Summary `POST /api/v2/email` on the account portal (`account.budibase.app`) starts an email-change workflow using a client-supplied `accountId` that is **not validated against the authenticated session**. A logged-in attacker supplies a victim's `accountId` and an email address they control; the verification code is delivered to the attacker's address, and completing the workflow changes the *

thehackerwire@mastodon.social at 2026-08-12T21:01:26.000Z ##

🟠 CVE-2026-73303 - High (8.2)

Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73300
(9.6 CRITICAL)

EPSS: 0.38%

updated 2026-08-12T18:56:53

1 posts

## Summary A critical SQL injection vulnerability was discovered in Budibase's MySQL integration that allows remote attackers to execute arbitrary SQL commands. ## Details ### Vulnerability Type SQL Injection ### Description The MySQL integration component in Budibase is configured with `multipleStatements: true`, enabling execution of multiple SQL statements in a single query. Attackers can inj

thehackerwire@mastodon.social at 2026-08-12T20:01:00.000Z ##

🔴 CVE-2026-73300 - Critical (9.6)

Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17248
(7.1 HIGH)

EPSS: 0.33%

updated 2026-08-12T18:31:29

1 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.

hugovalters@mastodon.social at 2026-08-13T15:07:04.000Z ##

CVE-2026-17248 - DoS in IBM i 7.3-7.6 via improper OS command neutralization. Remote authenticated attacker can crash systems. CVSS 7.1. No patch yet - monitor advisory. #CVE #IBM #infosec

valtersit.com/cve/CVE-2026-172

##

CVE-2026-69106
(8.8 HIGH)

EPSS: 0.35%

updated 2026-08-12T18:31:29

1 posts

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

thehackerwire@mastodon.social at 2026-08-12T20:01:20.000Z ##

🟠 CVE-2026-69106 - High (8.8)

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73325
(7.8 HIGH)

EPSS: 0.26%

updated 2026-08-12T18:31:28

1 posts

Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False, invoking Python's pickle machinery during deserialization. Attackers can embed malicious __reduce_

thehackerwire@mastodon.social at 2026-08-12T17:00:05.000Z ##

🟠 CVE-2026-73325 - High (7.8)

Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18634
(8.4 HIGH)

EPSS: 0.22%

updated 2026-08-12T18:17:28.580000

1 posts

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component.

hugovalters@mastodon.social at 2026-08-13T11:01:26.000Z ##

CVE-2026-18634 - High severity deserialization flaw in GMS 9.5.1 and earlier. Local attacker can trigger unauthorized actions via service. CVSS 8.4. Unpatched - update immediately. #CVE #cybersecurity #GMS

valtersit.com/cve/CVE-2026-186

##

CVE-2026-65941
(8.8 HIGH)

EPSS: 0.44%

updated 2026-08-12T17:17:29.610000

1 posts

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

thehackerwire@mastodon.social at 2026-08-12T17:01:24.000Z ##

🟠 CVE-2026-65941 - High (8.8)

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50656
(7.8 HIGH)

EPSS: 10.75%

updated 2026-08-12T17:17:27.983000

7 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;.

3 repos

https://github.com/HORKimhab/CVE-2026-50656

https://github.com/g0thamRabb1t/CVE-2026-50656-rogueplanet-validation

https://github.com/0xBlackash/CVE-2026-50656

DailyCyberSecurity at 2026-08-15T03:39:30.598Z ##

MSNightmare's ShieldBreak PoC claims to fully bypass Microsoft's July patch for CVE-2026-50656, achieving SYSTEM-level privileges on Windows 11 and Server 2025.

meterpreter.org/shieldbreak-cv

##

netsecio@mastodon.social at 2026-08-13T18:23:17.000Z ##

📰 New 'ShieldBreak' Exploit Bypasses Microsoft Defender Patch

A new zero-day exploit, 'ShieldBreak,' bypasses Microsoft's patch for the 'RoguePlanet' Defender flaw (CVE-2026-50656). The PoC allows SYSTEM-level access on patched Windows systems. No fix is currently available. #ZeroDay #MicrosoftDefender #CyberSe...

🔗 cyber.netsecops.io/articles/sh

##

ottoto2017@prattohome.com at 2026-08-13T07:01:03.000Z ##

「Microsoftに恨みを持つハッカーが、完全にパッチが適用されたWindows上でシステム権限を取得できる新たなゼロデイ脆弱性を発見した。
/水曜日の裏技を使おうぜ、ベイビー 」: #TheRegister

「マイクロソフトに恨みを持つ、ゼロデイ攻撃を専門とするNightmare Eclipseは、マイクロソフトのRoguePlanetパッチ(CVE-2026-50656)を回避すると思われる、Defenderの新たなゼロデイ脆弱性「ShieldBreak」を公開した。これにより、攻撃者は完全にパッチが適用されたWindows 10、Windows 11、およびWindows Serverシステム上でSYSTEM権限を取得できる。

少なくとも他の研究者の一人によると、このエクスプロイトは有効だという。「試してみたところ、最新のWindows 11でも動作しました」と、元マイクロソフト社員でセキュリティ専門家のケビン・ボーモント氏 は述べている 。 」

theregister.com/cyber-crime/20

#prattohome

##

teezeh@ieji.de at 2026-08-13T05:45:44.000Z ##

“Nightmare Eclipse, the serial zero-day hunter who has an axe to grind with Microsoft, published a new Defender zero-day, ShieldBreak, that apparently bypasses Redmond’s RoguePlanet patch (CVE-2026-50656), allowing attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.”

theregister.com/cyber-crime/20

##

DailyCyberSecurity@infosec.exchange at 2026-08-15T03:39:30.000Z ##

MSNightmare's ShieldBreak PoC claims to fully bypass Microsoft's July patch for CVE-2026-50656, achieving SYSTEM-level privileges on Windows 11 and Server 2025.

#ShieldBreak #CVE202650656 #MicrosoftDefender #PrivilegeEscalation #Windows11

meterpreter.org/shieldbreak-cv

##

ottoto2017@prattohome.com at 2026-08-13T07:01:03.000Z ##

「Microsoftに恨みを持つハッカーが、完全にパッチが適用されたWindows上でシステム権限を取得できる新たなゼロデイ脆弱性を発見した。
/水曜日の裏技を使おうぜ、ベイビー 」: #TheRegister

「マイクロソフトに恨みを持つ、ゼロデイ攻撃を専門とするNightmare Eclipseは、マイクロソフトのRoguePlanetパッチ(CVE-2026-50656)を回避すると思われる、Defenderの新たなゼロデイ脆弱性「ShieldBreak」を公開した。これにより、攻撃者は完全にパッチが適用されたWindows 10、Windows 11、およびWindows Serverシステム上でSYSTEM権限を取得できる。

少なくとも他の研究者の一人によると、このエクスプロイトは有効だという。「試してみたところ、最新のWindows 11でも動作しました」と、元マイクロソフト社員でセキュリティ専門家のケビン・ボーモント氏 は述べている 。 」

theregister.com/cyber-crime/20

#prattohome

##

teezeh@ieji.de at 2026-08-13T05:45:44.000Z ##

“Nightmare Eclipse, the serial zero-day hunter who has an axe to grind with Microsoft, published a new Defender zero-day, ShieldBreak, that apparently bypasses Redmond’s RoguePlanet patch (CVE-2026-50656), allowing attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.”

theregister.com/cyber-crime/20

##

CVE-2026-26035
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-08-12T15:30:49

2 posts

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password

netsecio@mastodon.social at 2026-08-14T13:36:11.000Z ##

📰 Fortinet patches critical auth bypass in FortiWeb WAF (CVE-2026-26035)

Fortinet patches a critical authentication bypass in FortiWeb WAF (CVE-2026-26035). The flaw allows admin access with any password if a non-default 'admin wildcard' is set. Patch and check your configs now! #Fortinet #CyberSecurity #Vulnerability

🔗 cyber.netsecops.io/articles/fo

##

thehackerwire@mastodon.social at 2026-08-12T14:00:13.000Z ##

🔴 CVE-2026-26035 - Critical (9.8)

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57858
(8.9 HIGH)

EPSS: 0.41%

updated 2026-08-12T15:30:49

2 posts

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to

1 repos

https://github.com/zylideum/CVE-2026-57858

thehackerwire@mastodon.social at 2026-08-12T14:00:23.000Z ##

🟠 CVE-2026-57858 - High (8.9)

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracki...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T13:30:27.000Z ##

CVE-2026-57858: CRITICAL stored XSS in Cal.com Self-Hosted (v2.1.1 – 6.2.0). Exploited via BookingPageTagManager by authenticated event owners; affects all booking page visitors. Patch status unknown. Restrict privileges. radar.offseq.com/threat/cve-20 #OffSeq #XSS #SecOps

##

CVE-2026-70468
(8.1 HIGH)

EPSS: 0.59%

updated 2026-08-12T15:30:49

1 posts

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>

thehackerwire@mastodon.social at 2026-08-12T14:00:02.000Z ##

🟠 CVE-2026-70468 - High (8.1)

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiMan...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72898
(10.0 CRITICAL)

EPSS: 10.40%

updated 2026-08-12T15:18:30.347000

7 posts

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

2 repos

https://github.com/0xBlackash/CVE-2026-72898

https://github.com/codeb0ssx/CVE-2026-72898-PoC

DailyCyberSecurity at 2026-08-15T03:21:56.285Z ##

Nearly 14,000 Trezor customers had their data stolen via CVE-2026-72898, a critical Metabase zero-day exploited through logistics partner ShipMonk.

meterpreter.org/trezor-shipmon

##

halildeniz@mastodon.social at 2026-08-13T16:58:17.000Z ##

🚨 CRITICAL ALERT: CVE-2026-72898 (CVSS 10.0)

Unauthenticated SQL Injection in Metabase allows remote attackers to execute arbitrary SQL, hijack admin accounts & exfiltrate enterprise DB credentials. Patch immediately!

Read full analysis: denizhalil.com/2026/08/13/cve-

#CyberSecurity #Metabase #SQLi

##

security_crawler_carl at 2026-08-13T13:32:36.161Z ##

🏆 New Achievement! Query of Doom: Prerequisite — Having a Database — Complete!

QUEST UPDATE: Gain Total Administrative Access. Status: Already completed. By someone else. Without you. Metabase, the business intelligence platform, disclosed CVE-2026-72898, a critical SQL injection zero-day scoring a perfect 10 — the platonic ideal of catastrophe. (1/3)

##

thecybermind at 2026-08-13T11:34:47.787Z ##

(CISA TS-SOC) CVE-2026-72898 – Metabase SQL Injection Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to gain administrator access, modify configuration, steal credentials, and exfiltrate data from connected databases via SQL injection....

thecybermind.co/join

##

DailyCyberSecurity@infosec.exchange at 2026-08-15T03:21:56.000Z ##

Nearly 14,000 Trezor customers had their data stolen via CVE-2026-72898, a critical Metabase zero-day exploited through logistics partner ShipMonk.

#Trezor #DataBreach #Metabase #CVE202672898 #ShipMonk

meterpreter.org/trezor-shipmon

##

security_crawler_carl@infosec.exchange at 2026-08-13T13:32:36.000Z ##

🏆 New Achievement! Query of Doom: Prerequisite — Having a Database — Complete!

QUEST UPDATE: Gain Total Administrative Access. Status: Already completed. By someone else. Without you. Metabase, the business intelligence platform, disclosed CVE-2026-72898, a critical SQL injection zero-day scoring a perfect 10 — the platonic ideal of catastrophe. (1/3)

##

thecybermind@infosec.exchange at 2026-08-13T11:34:47.000Z ##

(CISA TS-SOC) CVE-2026-72898 – Metabase SQL Injection Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to gain administrator access, modify configuration, steal credentials, and exfiltrate data from connected databases via SQL injection....

thecybermind.co/join

##

CVE-2026-19594
(8.1 HIGH)

EPSS: 0.40%

updated 2026-08-12T13:17:22.180000

1 posts

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `&`/`#`/`=` characters in query string values. An attacker with access to a downstream application bu

thehackerwire@mastodon.social at 2026-08-12T12:00:23.000Z ##

🟠 CVE-2026-19594 - High (8.1)

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-41771
(4.3 MEDIUM)

EPSS: 0.16%

updated 2026-08-12T13:17:18.880000

2 posts

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.

DailyCyberSecurity at 2026-08-14T07:39:34.817Z ##

Phoenix Contact patched three PLCnext flaws, including CVE-2025-41771, which lets an attacker execute unauthorized SQL queries, plus a CVSS 9.8 RCE bug.

securityonline.info/phoenix-co

##

DailyCyberSecurity@infosec.exchange at 2026-08-14T07:39:34.000Z ##

Phoenix Contact patched three PLCnext flaws, including CVE-2025-41771, which lets an attacker execute unauthorized SQL queries, plus a CVSS 9.8 RCE bug.

#PhoenixContact #PLCnext #SQLInjection #CVE202541771 #ICS #OTSecurity #Cybersecurity

securityonline.info/phoenix-co

##

CVE-2026-67282(CVSS UNKNOWN)

EPSS: 0.57%

updated 2026-08-12T09:31:30

1 posts

Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.

offseq@infosec.exchange at 2026-08-12T12:00:27.000Z ##

CRITICAL: CVE-2026-67282 in Joomla Fabrik (v1.0.0 – 4.6.7) allows unauthenticated RCE (CWE-94). No patch yet — disable or restrict Fabrik use and monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #Infosec #RCE #CVE202667282

##

CVE-2026-58231
(10.0 CRITICAL)

EPSS: 0.73%

updated 2026-08-12T05:17:56.963000

11 posts

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

ottoto2017@prattohome.com at 2026-08-15T05:28:23.000Z ##

「SAP Commerce Cloudの脆弱性が最大レベルの攻撃の標的に。 」: #BLEEPINGCOMPUTER

「脅威インテリジェンス企業Defusedによると、3日前にパッチが適用されたSAP Commerce Cloudの深刻度最高レベルのリモートコード実行の脆弱性が、すでに攻撃の標的となっているという。

Commerce Cloud(旧称SAP Hybris)は、世界的に有名なブランドや大手小売業者が所有するオンラインストアで使用されているクラウドベースのeコマースプラットフォームです。

CVE-2026-58231 として追跡されている この重大な脆弱性は、Commerce Cloudの中核となるデータハブアダプタ拡張機能における不適切な認証の弱点に起因するもので、権限を持たない攻撃者が低複雑度の攻撃で悪用し、任意のコードを実行する可能性があります。 」

bleepingcomputer.com/news/secu

#prattohome

##

CapTechGroup@mastodon.social at 2026-08-14T18:26:15.000Z ##

Attackers have begun exploiting a maximum-severity vulnerability in SAP Commerce Cloud. Four CVEs are in scope, CVE-2026-22732, CVE-2026-34263, CVE-2026-44761 and CVE-2026-58231, and any exposed deployment warrants review.

captechgroup.com/threat-intell

##

robbdunewood@dailytechnewsshow.com at 2026-08-14T16:13:54.000Z ##

Apple Partners With Alibaba to Launch China-Specific AI Model – DTH

[🖼 DTH-6-150x150]France’s Top Court Strikes Down Proposed Social Media Ban for Minors, Google Launches Gemini 3.7 Flash to Boost AI Performance, and the White House Imposes 100% Tariffs on Drones to Boost Domestic Manufacturing and Security.

MP3

Please SUBSCRIBE HERE for free or
get DTNS shows ad-free.

A special thanks to all our supporters–without you, none of this would be possible.

If you enjoy what you see you can support the show on Patreon, Thank you!

Send email to feedback@dailytechnewsshow.com

Show Notes

Apple Develops AI Model for China With Alibaba

Apple has developed a proprietary large language model for the China market in partnership with Alibaba, signaling a strategic shift to better compete against domestic rivals. This initiative, designed to integrate with Apple Intelligence, aims to navigate local regulatory challenges and restore Apple’s competitive edge in a critical market where the absence of AI features has previously impacted sales.

Read More — Reuters

France’s Highest Court Rejects Social Media Ban for Children Under 15

France’s highest court has declared a proposed ban on social media for children under 15 unconstitutional, ruling that it infringes upon youths’ freedom of speech and communication. This decision, a setback for President Emmanuel Macron, signals potential legal and technical challenges for global efforts to restrict social media access for younger teenagers. Despite this ruling, the French government intends to pursue revised legislation while other nations and the EU continue to explore similar regulatory approaches, highlighting the ongoing tension between protective digital policies and privacy concerns.

Read More — Bloomberg

Google Launches Gemini 3.7 Flash

Google has launched its new Gemini 3.7 Flash AI model, which offers improved performance in coding, debugging, and efficiency for app production while integrating enhanced safety features. Despite this release, the company continues to face pressure due to delays with its more powerful Gemini 3.5 Pro model and competition from rivals like OpenAI and Anthropic, leading to investor questions regarding Google’s AI roadmap and its ability to maintain a leading market position.

Read More — Bloomberg

White House Introduces Tariffs of Up to 100 Percent on Drones

The White House has introduced new tariffs of up to 100 percent on drones and associated components to enhance national security and encourage domestic manufacturing, or “on-shoring.” These measures, which target both heavy-duty and sensitive commercial drones, are expected to increase costs for consumers as vendors pass on the expenses. The policy aims to reduce dependence on Chinese-manufactured models, like those from DJI, though industry experts note the significant challenge of replicating China’s advanced drone supply chains and specialized engineering capabilities within the US.

Read More — Engadget

Flock Implements Stricter Data Retention Policies

Flock is implementing stricter data retention policies and mandating a new “Audit Assistance” tool designed to flag atypical search patterns for administrative review. Despite Flock’s claims of efficacy, privacy experts and critics from the ACLU and EFF argue that the company has provided insufficient technical details about how the tool works and lacks independent auditing evidence to prove it effectively prevents abuse, suggesting that stronger legal constraints on technology use are more critical for ensuring accountability.

Read More — TechCrunch

Heart Aerospace Completes First Flight of All-Electric X1 Prototype

Heart Aerospace has successfully completed the first flight of its all-electric X1 prototype, marking a significant milestone for the company as it eyes regional aviation markets. With interest from airlines like United and Air Canada, Heart aims to follow this success with the ES-30, a hybrid-electric model designed to replace traditional turboprops by 2031 through lower operational costs and enhanced reliability, though the company’s ambitious timeline remains dependent on future advancements in battery density and weight.

Read More — Engadget

Netflix Shutters Two Internal Game Studios

Netflix is shuttering two internal game studios, Night School Studio and Moonloot, as part of an ongoing restructuring of its gaming division. This decision follows a series of previous studio closures and divestments, signaling a consolidation of the company’s internal game development strategy. Moving forward, Netflix’s gaming focus is shifting toward four specific areas: kids, party, narrative, and mainstream titles, with increasing emphasis on cloud gaming and mobile-controller-based experiences.

Read More — Variety

Critical SAP Commerce Cloud Vulnerability Is Being Actively Exploited

A critical remote code execution vulnerability in SAP Commerce Cloud (CVE-2026-58231) is being actively exploited in the wild three days after patch release. Caused by improper authorization in the Data Hub Adapter, the flaw allows unauthenticated attackers to execute arbitrary code on e-commerce platforms. Despite no public proof-of-concept, researchers confirmed active attacks, underlining persistent security threats for SAP.

Read More — BleepingComputer

Uber Expands Robotaxi Strategy With Pony.ai

Uber is expanding its global robotaxi strategy by partnering with Pony.ai to deploy 2,000 self-driving vehicles across Europe and the Middle East, building on their existing pilot service in Zagreb. This collaboration, which includes plans for four additional European cities, is part of Uber’s broader effort to become a leading platform for autonomous commercialization by working with partners like WeRide and Baidu Apollo Go to scale operations in cities like Madrid and Tokyo, while gathering data to accelerate development against competitors like Waymo.

Read More — CNBC

X Tests Tool to Show Post-Limiting Labels

X is testing a tool giving select users visibility into post-limiting labels like spam or NSFW. Aimed at clarifying algorithmic “shadowbanning,” the complex data remains hard to interpret. Concurrently, X expanded open-sourcing its recommendation algorithm while continuing to withhold sensitive advertising and non-timeline data.

Read More — Engadget

##

tugatech@masto.pt at 2026-08-14T14:43:28.000Z ##

SAP Commerce Cloud é alvo de ataques que exploram vulnerabilidade CVE-2026-58231, classificada com gravidade máxima de 10.0, apenas 3 dias após correção. A plataforma está a ser explorada por investidas que começaram a atingir os sensores de teste após a correção do boletim de segurança oficial." 🚨

🔗 tugatech.com.pt/t89186-sap-com

#cloud #falha #sap 

##

cyberworldops at 2026-08-14T14:10:00.492Z ##

SAP Commerce Cloud CVE-2026-58231 is already being exploited in the wild. Threat intelligence firm Defused detected initial exploitation attempts on its honeypots, as reported by BleepingComputer on August 14, 2026. The critical flaw had been patched three days prior, leaving unpatched and exposed installations at maximum risk.

cyberworldops.eu/en/sap-commer

##

undercodenews@mastodon.social at 2026-08-14T14:06:11.000Z ##

SAP Commerce Cloud Hit by a Maximum-Severity RCE — Attackers Move Just Three Days After the Patch

Introduction: A Patch Arrived, and Attackers Were Already Waiting A critical vulnerability in SAP Commerce Cloud has moved from disclosure to active exploitation with alarming speed. Just three days after SAP released a security fix, threat intelligence researchers reported seeing real-world exploitation attempts against vulnerable systems. Tracked as CVE-2026-58231 and…

undercodenews.com/sap-commerce

##

Analyst207@mastodon.social at 2026-08-14T14:01:53.000Z ##

SAP Commerce Cloud Vulnerability Now Under Active Attack

Hackers are actively exploiting a critical vulnerability in SAP Commerce Cloud, allowing them to remotely execute code without any login credentials. This severe flaw, tracked as CVE-2026-58231, was patched by SAP just three days before attacks began.

osintsights.com/sap-commerce-c

#SapCommerceCloud #Cve202658231 #RemoteCodeExecution #EmergingThreats #SupplyChain

##

ottoto2017@prattohome.com at 2026-08-15T05:28:23.000Z ##

「SAP Commerce Cloudの脆弱性が最大レベルの攻撃の標的に。 」: #BLEEPINGCOMPUTER

「脅威インテリジェンス企業Defusedによると、3日前にパッチが適用されたSAP Commerce Cloudの深刻度最高レベルのリモートコード実行の脆弱性が、すでに攻撃の標的となっているという。

Commerce Cloud(旧称SAP Hybris)は、世界的に有名なブランドや大手小売業者が所有するオンラインストアで使用されているクラウドベースのeコマースプラットフォームです。

CVE-2026-58231 として追跡されている この重大な脆弱性は、Commerce Cloudの中核となるデータハブアダプタ拡張機能における不適切な認証の弱点に起因するもので、権限を持たない攻撃者が低複雑度の攻撃で悪用し、任意のコードを実行する可能性があります。 」

bleepingcomputer.com/news/secu

#prattohome

##

tugatech@masto.pt at 2026-08-14T14:43:28.000Z ##

SAP Commerce Cloud é alvo de ataques que exploram vulnerabilidade CVE-2026-58231, classificada com gravidade máxima de 10.0, apenas 3 dias após correção. A plataforma está a ser explorada por investidas que começaram a atingir os sensores de teste após a correção do boletim de segurança oficial." 🚨

🔗 tugatech.com.pt/t89186-sap-com

#cloud #falha #sap 

##

cyberworldops@infosec.exchange at 2026-08-14T14:10:00.000Z ##

SAP Commerce Cloud CVE-2026-58231 is already being exploited in the wild. Threat intelligence firm Defused detected initial exploitation attempts on its honeypots, as reported by BleepingComputer on August 14, 2026. The critical flaw had been patched three days prior, leaving unpatched and exposed installations at maximum risk.

#SAP #CVE202658231 #ThreatIntelligence #CriticalVulnerability

cyberworldops.eu/en/sap-commer

##

jbhall56@infosec.exchange at 2026-08-12T12:15:46.000Z ##

The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. thehackernews.com/2026/08/sap-

##

CVE-2026-66878
(7.7 HIGH)

EPSS: 0.21%

updated 2026-08-12T03:31:17

1 posts

A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure.

thehackerwire@mastodon.social at 2026-08-12T12:00:33.000Z ##

🟠 CVE-2026-66878 - High (7.7)

A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Nam...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68067
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-08-12T00:31:23

2 posts

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.

CVE-2026-19579
(5.4 MEDIUM)

EPSS: 0.24%

updated 2026-08-11T21:33:18

1 posts

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ow

AAKL@infosec.exchange at 2026-08-12T15:58:29.000Z ##

Broadcom has a new advisory for five vulnerabilities, two of them critical support.broadcom.com/web/ecx/s #Broadcom

Posted yesterday:

Tenable Research advisories: CVE-2026-19579: Snipe-IT Checkout Request Cancellation IDOR tenable.com/security/research/ @tenable $infosec #vulnerability

##

CVE-2026-73282
(4.8 MEDIUM)

EPSS: 0.16%

updated 2026-08-11T21:33:18

1 posts

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

CVE-2026-73281
(3.5 LOW)

EPSS: 0.16%

updated 2026-08-11T21:33:11

1 posts

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

CVE-2026-68820
(7.0 None)

EPSS: 0.33%

updated 2026-08-11T21:33:01

14 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1 repos

https://github.com/HORKimhab/CVE-2026-68820

threatnoir at 2026-08-14T14:06:20.888Z ##

⚠️ CRITICAL: Lazarus hackers exploited Windows zero-day to target defense firms

Lazarus Group is actively exploiting Windows zero-day CVE-2026-68820 to target defense, aerospace, and aviation firms worldwide. The vulnerability enables privilege escalation to SYSTEM level and is being weaponized alongside a new backdoor called Troy. Compromised Roundcube instances have also bee…

threatnoir.com/focus

🤖 AI generated summary

##

hackmag at 2026-08-14T08:30:24.211Z ##

⚪️ Microsoft Releases Patches for More Than 400 Vulnerabilities

🗨️ Microsoft has released its August patches, fixing 421 vulnerabilities. These included three zero-day flaws, among them CVE-2026-68820, which the North Korean Lazarus group had already exploited in real-world attacks. One of the most important fixes this month is a patch…

🔗 hackmag.com/news/august-2026-p

##

Matchbook3469@mastodon.social at 2026-08-13T16:57:45.000Z ##

🔵 THREAT INTELLIGENCE

Lazarus hackers exploited Windows zero-day to target defense firms

Vulnerability | CRITICAL
CVEs: CVE-2026-68820

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the...

Full analysis:
yazoul.net/news/article/lazaru

by Yazoul AI

#CyberSecurity #CVE #ThreatHunting

##

cyberveille@mastobot.ping.moi at 2026-08-13T16:00:05.000Z ##

📢 Lazarus Group exploite un zero-day Windows (CVE-2026-68820) via de fausses offres d'emploi

Cet article documente une nouvelle vague de la campagne Operation Dream Job, attribuée au groupe nord-coréen Lazarus, ciblant les secteurs de la défense, de l'aérospatiale et de l'aviation en Europe, Asie et Amérique du Sud.

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : blog.checkpoint.com/research/s
🟢 vérification factuelle haute
#LazarusGroup #ZeroDay #Cyberveille

##

thecybermind at 2026-08-13T13:27:21.132Z ##

(CISA TS-SOC) CVE-2026-68820 – Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Severity: HIGH Impact Summary: Allows an authorized attacker to elevate privileges locally via a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock....

thecybermind.co/join

##

undercodenews@mastodon.social at 2026-08-13T09:11:47.000Z ##

Microsoft’s Record Patch Tuesday Exposes a New Cybersecurity Reality as AI Finds More Flaws + Video

A Patch Tuesday That Signals a Bigger Change Microsoft’s latest Patch Tuesday has delivered an extraordinary number of security fixes, with 419 vulnerabilities addressed in a single release, including three zero-day flaws. One vulnerability, CVE-2026-68820, was reportedly exploited in the wild and has been linked to activity associated with the Lazarus Group. The scale…

undercodenews.com/microsofts-r

##

threatnoir@infosec.exchange at 2026-08-14T14:06:20.000Z ##

⚠️ CRITICAL: Lazarus hackers exploited Windows zero-day to target defense firms

Lazarus Group is actively exploiting Windows zero-day CVE-2026-68820 to target defense, aerospace, and aviation firms worldwide. The vulnerability enables privilege escalation to SYSTEM level and is being weaponized alongside a new backdoor called Troy. Compromised Roundcube instances have also bee…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

hackmag@infosec.exchange at 2026-08-14T08:30:24.000Z ##

⚪️ Microsoft Releases Patches for More Than 400 Vulnerabilities

🗨️ Microsoft has released its August patches, fixing 421 vulnerabilities. These included three zero-day flaws, among them CVE-2026-68820, which the North Korean Lazarus group had already exploited in real-world attacks. One of the most important fixes this month is a patch…

🔗 hackmag.com/news/august-2026-p

#news

##

thecybermind@infosec.exchange at 2026-08-13T13:27:21.000Z ##

(CISA TS-SOC) CVE-2026-68820 – Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Severity: HIGH Impact Summary: Allows an authorized attacker to elevate privileges locally via a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock....

thecybermind.co/join

##

cyberworldops@infosec.exchange at 2026-08-12T20:20:01.000Z ##

Lazarus Group is exploiting a Windows zero-day (CVE-2026-68820) to escalate to SYSTEM privileges and deploy backdoors. Targets include defense and aerospace firms in France, Germany, Brazil, and India, lured through fake LinkedIn job offers under Operation Dream Job.

#LazarusGroup #ZeroDayExploit #WindowsSecurity #OperationDreamJob

cyberworldops.eu/en/lazarus-ex

##

oversecurity@mastodon.social at 2026-08-12T16:01:31.000Z ##

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the...

🔗️ [Bleepingcomputer] link.is.it/NpjibN

##

tugatech@masto.pt at 2026-08-12T15:07:31.000Z ##

Microsoft lança atualização de emergência para corrigir a CVE-2026-68820, uma falha de gravidade elevada no controlador Ancillary Function para WinSock. A vulnerabilidade, que afeta diversas versões do Windows, já está a ser explorada em ataques reais. 🚨

🔗 tugatech.com.pt/t89012-microso

#falha #lan #microsoft #windows 

##

threatnoir@infosec.exchange at 2026-08-12T13:05:54.000Z ##

⚠️ CRITICAL: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Microsoft patched CVE-2026-68820, a zero-day use-after-free in afd.sys kernel driver actively exploited for SYSTEM privilege escalation. This is the fourth afd.sys zero-day since 2022, with historical links to nation-state actors. All Windows systems running unpatched afd.sys are at immediate risk…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

security_crawler_carl@infosec.exchange at 2026-08-12T12:39:41.000Z ##

🏆 New Achievement! CVE-2026-68820: The Lazarus Rises (Again)!

PHASE ONE BEGINS. Emerging from the shadows of Pyongyang's finest state-sponsored hacking collective, Lazarus has arrived — and they brought a use-after-free bug in afd.sys, the Windows kernel-mode driver, as their opening act. CVE-2026-68820 lets a low-privilege, locally authenticated attacker trigger a race condition, escalate straight to SYSTEM, and basically own the stage. (1/3)

##

CVE-2026-20349
(8.6 HIGH)

EPSS: 0.87%

updated 2026-08-11T21:32:37

4 posts

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.&nbsp; This vulnerability is due to insufficient error checking when processing

thecybermind at 2026-08-14T11:27:31.822Z ##

🚨 THREAT ALERT: CVE-2026-20349

Active exploitation verified on Cisco ASA & FTD firewalls via a high-severity heap inspection flaw. IT leadership must enforce immediate patch protocols and audit perimeter logs.
thecybermind.co/z7x3

👉 Watch breakdown: youtube.com/shorts/xzFNHt3De3I

##

thecybermind@infosec.exchange at 2026-08-14T11:27:31.000Z ##

🚨 THREAT ALERT: CVE-2026-20349

Active exploitation verified on Cisco ASA & FTD firewalls via a high-severity heap inspection flaw. IT leadership must enforce immediate patch protocols and audit perimeter logs.
thecybermind.co/z7x3

👉 Watch breakdown: youtube.com/shorts/xzFNHt3De3I

#CyberSecurity #Cisco #InfoSec

##

cyberworldops@infosec.exchange at 2026-08-12T18:10:01.000Z ##

Cisco confirmed active exploitation of CVE-2026-20349, a high-severity flaw (CVSS 8.6) in ASA and FTD firewalls. Insufficient error handling in HTTP processing allows an unauthenticated remote attacker to trigger a device reboot via the Remote Access SSL VPN service, resulting in denial of service.

#CVE202620349 #CiscoASA #FirewallSecurity #DenialOfService

cyberworldops.eu/en/cisco-asa-

##

jbhall56@infosec.exchange at 2026-08-12T12:57:51.000Z ##

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. securityweek.com/cisco-patches

##

CVE-2026-73283
(2.5 LOW)

EPSS: 0.08%

updated 2026-08-11T21:17:53.413000

1 posts

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

CVE-2026-18687
(7.1 HIGH)

EPSS: 0.17%

updated 2026-08-11T21:17:31.273000

1 posts

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypte

hugovalters@mastodon.social at 2026-08-13T14:13:46.000Z ##

CVE-2026-18687 - High severity DoS in MongoDB Queryable Encryption. Flawed validation lets authenticated users crash servers or corrupt encrypted indexes via crafted requests. CVSS 7.1. Unpatched—restrict access and monitor. #CVE #MongoDB #infosec

valtersit.com/cve/CVE-2026-186

##

CVE-2026-20337
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-11T18:54:19.877000

1 posts

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A succe

cyberveille@mastobot.ping.moi at 2026-08-13T17:30:04.000Z ##

📢 Cisco alerte sur 7 vulnérabilités ClamAV avec PoC public affectant Secure Endpoint

Cet article rapporte une alerte de sécurité émise par Cisco concernant sept vulnérabilités dans ClamAV affectant ses produits Secure Endpoint Connector sur Windows, macOS et Linux. Les failles sont référencées sous les identifiants CVE-2026-20337 à CVE-2026-20339 et…

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : securityweek.com/cisco-warns-o
🟢 vérification factuelle haute
#ClamAV #PoCPublic #Cyberveille

##

CVE-2026-48381
(9.0 None)

EPSS: 0.48%

updated 2026-08-11T18:32:00

2 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not req

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

CVE-2026-27302
(10.0 CRITICAL)

EPSS: 0.57%

updated 2026-08-11T18:32:00

2 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

CVE-2026-62832
(7.8 HIGH)

EPSS: 2.37%

updated 2026-08-11T18:31:33

4 posts

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

tugatech@masto.pt at 2026-08-14T12:05:11.000Z ##

A Microsoft lançou correções de segurança no ciclo de atualizações de agosto de 2026 para resolver a vulnerabilidade de dia zero LegacyHive no Windows. A vulnerabilidade, rastreada como CVE-2026-62832, afeta o serviço de perfis de utilizador. 🛡️

🔗 tugatech.com.pt/t89169-microso

#lan #microsoft #vulnerabilidade #windows 

##

cyberworldops at 2026-08-13T18:10:00.478Z ##

Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.

cyberworldops.eu/en/microsoft-

##

tugatech@masto.pt at 2026-08-14T12:05:11.000Z ##

A Microsoft lançou correções de segurança no ciclo de atualizações de agosto de 2026 para resolver a vulnerabilidade de dia zero LegacyHive no Windows. A vulnerabilidade, rastreada como CVE-2026-62832, afeta o serviço de perfis de utilizador. 🛡️

🔗 tugatech.com.pt/t89169-microso

#lan #microsoft #vulnerabilidade #windows 

##

cyberworldops@infosec.exchange at 2026-08-13T18:10:00.000Z ##

Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.

#ZeroDay #LegacyHive #PatchTuesday #CVE2026

cyberworldops.eu/en/microsoft-

##

CVE-2026-48442
(7.1 HIGH)

EPSS: 0.24%

updated 2026-08-11T18:31:03

1 posts

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is chang

hugovalters@mastodon.social at 2026-08-13T18:12:24.000Z ##

CVE-2026-48442 - Path traversal in CAI Content Credentials allows arbitrary file system read. CVSS 7.1. No user interaction needed. Patch status unknown. Update immediately. #CVE #infosec #CAI

valtersit.com/cve/CVE-2026-484

##

CVE-2026-59124
(9.8 CRITICAL)

EPSS: 1.72%

updated 2026-08-11T18:31:01

1 posts

Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

adulau@infosec.exchange at 2026-08-12T15:34:19.000Z ##

vulnerability-lookup 6.0 will be released this week with many (really, many!) new features.

One of the smaller, but important, additions is support for multiple SSVC views alongside CVSS. When SSVC information is available from an ADP (such as CISA) , or from additional sources such as GCVE, it is now displayed by default.

This allows users to more easily compare the different severity and prioritization assessments associated with a vulnerability.

The CIRCL vulnerability-lookup instance is running the pre-release of 6.0 -
vulnerability.circl.lu/vuln/cv

#cve #gcve #opensource #vulnerabilitylookup #opendata #vulnerabilitymanagement #cyberecurity #ssvc

@gcve
@circl

##

CVE-2026-48362
(10.0 CRITICAL)

EPSS: 2.07%

updated 2026-08-11T18:30:56

2 posts

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

CVE-2026-18129
(8.1 HIGH)

EPSS: 0.87%

updated 2026-08-11T15:32:51

1 posts

Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.

jbhall56@infosec.exchange at 2026-08-12T12:52:08.000Z ##

Tracked as CVE-2026-18129, the first is described as a cleartext transmission of sensitive information issue that can be exploited by an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. securityweek.com/ivanti-epm-up

##

CVE-2026-59693
(4.3 MEDIUM)

EPSS: 0.16%

updated 2026-08-11T15:32:41

2 posts

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service

cyberworldops at 2026-08-13T20:10:00.981Z ##

Siemens disclosed CVE-2026-59693 affecting Desigo DXR and PXC building automation controllers. Malformed BACnet packets can trigger a denial-of-service condition with no remote recovery path, requiring a physical reset of the affected device.

cyberworldops.eu/en/siemens-de

##

cyberworldops@infosec.exchange at 2026-08-13T20:10:00.000Z ##

Siemens disclosed CVE-2026-59693 affecting Desigo DXR and PXC building automation controllers. Malformed BACnet packets can trigger a denial-of-service condition with no remote recovery path, requiring a physical reset of the affected device.

#SiemensDesigo #BuildingAutomation #ICS #BACnet

cyberworldops.eu/en/siemens-de

##

CVE-2026-64582
(7.8 HIGH)

EPSS: 0.12%

updated 2026-08-08T15:31:27

2 posts

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's kref is still at 1: list_del_init(&ip->pending_mmaps); spin_unlock_bh(&rxe->pending_lock); /* ref == 1, no lock held */ ret = remap_vmalloc_range(vma, i

CVE-2026-67261
(9.8 CRITICAL)

EPSS: 1.60%

updated 2026-08-07T20:08:27.597000

1 posts

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete sys

CVE-2026-20339
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T18:31:54

1 posts

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. An attacker could exploit this

cyberveille@mastobot.ping.moi at 2026-08-13T17:30:04.000Z ##

📢 Cisco alerte sur 7 vulnérabilités ClamAV avec PoC public affectant Secure Endpoint

Cet article rapporte une alerte de sécurité émise par Cisco concernant sept vulnérabilités dans ClamAV affectant ses produits Secure Endpoint Connector sur Windows, macOS et Linux. Les failles sont référencées sous les identifiants CVE-2026-20337 à CVE-2026-20339 et…

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : securityweek.com/cisco-warns-o
🟢 vérification factuelle haute
#ClamAV #PoCPublic #Cyberveille

##

CVE-2026-71319
(9.6 CRITICAL)

EPSS: 0.32%

updated 2026-08-07T05:17:03.660000

1 posts

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (ws://<host>:<port>/, subprotocol vite-hmr) can call RPC methods, with no token, ha

DailyCyberSecurity@infosec.exchange at 2026-08-12T13:19:37.000Z ##

CVE-2026-71319 lets attackers run arbitrary commands via unauthenticated Nuxt DevTools RPC. CVSS 9.6, 7.3M monthly downloads. Patch now.

#Nuxt #VueJS #CVE #RCE #CyberSecurity

securityonline.info/nuxt-devto

##

CVE-2026-63455
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-06T15:40:50.227000

2 posts

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.

DailyCyberSecurity at 2026-08-13T14:38:57.478Z ##

CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now.

securityonline.info/edgeconnec

##

DailyCyberSecurity@infosec.exchange at 2026-08-13T14:38:57.000Z ##

CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now.

#HPE #Aruba #SDWAN #CVE #CyberSecurity

securityonline.info/edgeconnec

##

CVE-2025-24472
(8.1 HIGH)

EPSS: 3.58%

updated 2026-08-05T05:16:43.473000

1 posts

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted

1 repos

https://github.com/razureink/cve-2025-24472-fortinet_authbypass_reproduction

PC_Fluesterer@social.tchncs.de at 2026-08-14T09:20:46.000Z ##

Warnung vor Angriffen gegen Fortinet

Diese Meldung wiederholt das Thema der vorigen: Software (oder Firmware) nicht aktuell -> gehackt. Heute geht es um eine konkrete Erpresser-Gang namens Gunra. Die durchsucht das Internet nach erreichbaren Firewalls und Routern von Fortinet und versucht, ältere Sicherheitslücken (CVE-2024-55591 und CVE-2025-24472) auszunutzen. Beide sind längst als bereits ausgenutzt bekannt. Wenn die verfügbaren Updates nicht eingespielt wurden, die Lücken also noch offen sind, ist das angegriffene Netzwerk kompromittiert; Datenlecks, Betriebsunterbrechungen und Erpressung folgen. In den USA hat es bereits viele Institutionen getroffen, vom ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #closedsource #cybercrime #firewall #hersteller #router #sicherheit #vorbeugen

##

CVE-2026-63456
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-04T18:31:36

2 posts

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.

DailyCyberSecurity at 2026-08-13T14:38:57.478Z ##

CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now.

securityonline.info/edgeconnec

##

DailyCyberSecurity@infosec.exchange at 2026-08-13T14:38:57.000Z ##

CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now.

#HPE #Aruba #SDWAN #CVE #CyberSecurity

securityonline.info/edgeconnec

##

CVE-2026-18577
(8.1 HIGH)

EPSS: 4.10%

updated 2026-08-04T15:33:20

2 posts

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

3 repos

https://github.com/HORKimhab/CVE-2026-18577

https://github.com/Yash-Dalvee/stormencryptor-ncentral-defense

https://github.com/CreamyG31337/ncentral-compromise-ioc-triage

cyberveille@mastobot.ping.moi at 2026-08-13T19:00:05.000Z ##

📢 CVE-2026-18577 : Bypass d'authentification N-able N-central exploité activement

Cet article analyse CVE-2026-18577, une vulnérabilité de bypass d'authentification affectant la plateforme de Remote Monitoring and Management (RMM) N-able N-central, confirmée comme activement exploitée fin juillet 2026.

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : criminalip.io/knowledge-hub/bl
🟡 vérification factuelle moyenne
#NAbleNCentral #RMM #Cyberveille

##

hackmag@infosec.exchange at 2026-08-12T20:00:05.000Z ##

⚪️ N-able Releases Two Patches for N-central Authentication Bypass Vulnerability

🗨️ N-able developers have released a second emergency patch for the N-central remote monitoring and management platform. The follow-up update was required due to ongoing attacks exploiting CVE-2026-18577: attackers are gaining administrator privileges on N-central servers and infiltrating customers’…

🔗 hackmag.com/news/n-central-0da

#news

##

CVE-2026-61515
(9.8 CRITICAL)

EPSS: 1.58%

updated 2026-08-04T15:32:30

1 posts

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary com

DailyCyberSecurity@infosec.exchange at 2026-08-12T12:45:44.000Z ##

PoC exploit code is public for CVE-2026-61515, an unauthenticated command injection in Puwell IP Camera firmware. CVSS 9.3. Details inside.

#IPCamera #IoT #CVE #CommandInjection #CyberSecurity

securityonline.info/puwell-ip-

##

CVE-2025-4318(CVSS UNKNOWN)

EPSS: 0.93%

updated 2026-07-30T20:57:25

1 posts

### Summary The AWS Amplify Studio [amplify-codegen-ui](https://github.com/aws-amplify/amplify-codegen-ui) is a package that generates front-end code from UI Builder entities (components, forms, views, and themes) primarily used in AWS Amplify Studio for component previews and in AWS Command Line Interface (AWS CLI) for generating component files in customers' local applications. An issue exists

awssecurityfeed@infosec.exchange at 2026-08-12T19:00:01.000Z ##

Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin....

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-07-30T15:31:54

2 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

beyondmachines1 at 2026-08-13T10:01:21.207Z ##

Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access

German cybersecurity firm QUIRSO reports active exploitation of VMware vCenter and ESXi, critical flaws (CVE-2026-59310 and CVE-2026-59309).

**If you run VMware vCenter, this is important. Make sure it is not reachable from the internet and can only be accessed from trusted internal networks. Then urgently apply the fixes from Broadcom advisory VMSA-2026-0006.1 (vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f), because the platform is being attacked and there is no workaround for the flaws. If your vCenter was exposed, check it for signs of compromise such as unexpected cron jobs, unknown SSH tools, or unusual outbound connections.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-13T10:01:21.000Z ##

Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access

German cybersecurity firm QUIRSO reports active exploitation of VMware vCenter and ESXi, critical flaws (CVE-2026-59310 and CVE-2026-59309).

**If you run VMware vCenter, this is important. Make sure it is not reachable from the internet and can only be accessed from trusted internal networks. Then urgently apply the fixes from Broadcom advisory VMSA-2026-0006.1 (vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f), because the platform is being attacked and there is no workaround for the flaws. If your vCenter was exposed, check it for signs of compromise such as unexpected cron jobs, unknown SSH tools, or unusual outbound connections.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 1.14%

updated 2026-07-30T15:31:51

21 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

threatnoir at 2026-08-14T14:06:23.273Z ##

⚠️ CRITICAL: Global Threat Campaign Hits Critical VMware vCenter Flaw

Active exploitation of CVE-2026-59310 in VMware vCenter Server is ongoing. All organizations running vCenter are at risk of compromise. Patching alone may be insufficient due to suspected persistence mechanisms already deployed by threat actors.

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir at 2026-08-14T14:06:18.557Z ##

⚠️ CRITICAL: Critical VMware vCenter RCE flaw exploited for reverse SSH access

A critical directory traversal vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being actively exploited in the wild to deploy reverse SSH tools for persistence. At least 361 compromised hosts across 47 countries have been identified, with attackers establishing remote access on vi…

threatnoir.com/focus

🤖 AI generated summary

##

security_crawler_carl at 2026-08-14T10:37:17.865Z ##

🏆 New Achievement! Directory Traversal of Doom (9.8 Stars, Would Not Recommend)!

ITEM DROPPED: CVE-2026-59310, a critical directory traversal flaw in VMware vCenter, CVSS 9.8. Broadcom disclosed this cursed artifact on July 29, and attackers — believed to be a single suspected APT actor — were already swinging it around earlier this month. Network access to a vCenter instance is all it takes to remotely execute arbitrary code across your entire virtual environment. (1/2)

##

ottoto2017@prattohome.com at 2026-08-14T05:44:50.000Z ##

「VMware vCenterの重大なリモートコード実行(RCE)の脆弱性が悪用され、リバースSSHアクセスが行われた。 」: #BLEEPINGCOMPUTER

「VMware vCenter Syslog Serverに存在する、最近パッチが適用された重大な脆弱性(CVE-2026-59310)が、永続的な接続とリモートアクセスを目的としたリバースSSHツールの展開を目的としたアクティブな攻撃キャンペーンで悪用されています。

47か国にわたる361のIPアドレスで侵害が確認されており、その半数以上はドイツ、米国、トルコ、イラン、フランスに位置している。

Broadcomは7月29日にCVE-2026-59310を公開し、 vCenter Syslogサーバーにおける重大なディレクトリトラバーサル脆弱性 であり、ネットワークアクセス権を持つ認証されていない攻撃者が悪用して任意のコードを実行できる可能性があると説明した。 」

bleepingcomputer.com/news/secu

#prattohome

##

undercodenews@mastodon.social at 2026-08-13T17:27:20.000Z ##

VMware vCenter Under Attack: Critical CVE-2026-59310 Exploited in a Global Reverse-SSH Campaign + Video

Introduction: A Five-Day Warning That A critical vulnerability in VMware vCenter has rapidly turned from a security advisory into an active global intrusion campaign. CVE-2026-59310, a directory traversal flaw affecting the vCenter Server Syslog component, is now being exploited by attackers to gain access to vulnerable infrastructure and install a reverse-SSH tool…

undercodenews.com/vmware-vcent

##

oversecurity@mastodon.social at 2026-08-13T17:10:35.000Z ##

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a...

🔗️ [Bleepingcomputer] link.is.it/3RirvF

##

Analyst207@mastodon.social at 2026-08-13T17:02:25.000Z ##

VMware vCenter flaw exploited for reverse SSH access globally

A critical VMware vCenter flaw, CVE-2026-59310, is being exploited globally, with 361 Internet-connected systems across 47 countries already compromised. This severe vulnerability allows unauthenticated attackers to execute arbitrary code, making swift action essential to prevent further breaches.

osintsights.com/vmware-vcenter

#Vmware #Cve202659310 #Vcenter #DirectoryTraversal #SupplyChain

##

Analyst207@mastodon.social at 2026-08-13T14:02:13.000Z ##

VMware vCenter Flaw Exploited Days After Disclosure

Within days of Broadcom's advisory, a critical VMware vCenter flaw, CVE-2026-59310, was exploited, putting 361 victim IP addresses across 47 countries at risk. This severe vulnerability allowed attackers to turn a logging service into a gateway to infiltrate operating systems worldwide.

osintsights.com/vmware-vcenter

#Cve202659310 #Vmware #Vcenter #DirectoryTraversal #SupplyChain

##

Hackread@mstdn.social at 2026-08-13T11:44:19.000Z ##

📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310.

Listen/Read: hackread.com/apt-exploits-crit

#CyberSecurity #VMware #vCenter #APT #Vulnerability

##

beyondmachines1 at 2026-08-13T10:01:21.207Z ##

Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access

German cybersecurity firm QUIRSO reports active exploitation of VMware vCenter and ESXi, critical flaws (CVE-2026-59310 and CVE-2026-59309).

**If you run VMware vCenter, this is important. Make sure it is not reachable from the internet and can only be accessed from trusted internal networks. Then urgently apply the fixes from Broadcom advisory VMSA-2026-0006.1 (vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f), because the platform is being attacked and there is no workaround for the flaws. If your vCenter was exposed, check it for signs of compromise such as unexpected cron jobs, unknown SSH tools, or unusual outbound connections.**

beyondmachines.net/event_detai

##

ottoto2017@prattohome.com at 2026-08-13T06:50:40.000Z ##

「攻撃者がVMware vCenterの脆弱性を悪用し、永続的なリモートアクセスを取得する 」: #TheHackerNews

「QUIRSOの 新たな調査結果 によると、攻撃者は、最近パッチが適用されたBroadcom VMware vCenterの重大なセキュリティ脆弱性を積極的に悪用し始めている。

問題となっている脆弱性は CVE-2026-59310 (CVSSスコア:9.8)で、VMware vCenterサーバーのディレクトリトラバーサル脆弱性であり、ネットワークアクセス権を持つ悪意のある攻撃者がこれを悪用して任意のコードを実行できる可能性がある。この脆弱性に対するパッチは、ブロードコム社が先月末にリリースした。

ドイツのサイバーセキュリティ企業は、インシデント対応活動中にこの活動を発見したと発表した。 」

thehackernews.com/2026/08/atta

#prattohome

##

threatnoir@infosec.exchange at 2026-08-14T14:06:23.000Z ##

⚠️ CRITICAL: Global Threat Campaign Hits Critical VMware vCenter Flaw

Active exploitation of CVE-2026-59310 in VMware vCenter Server is ongoing. All organizations running vCenter are at risk of compromise. Patching alone may be insufficient due to suspected persistence mechanisms already deployed by threat actors.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-08-14T14:06:18.000Z ##

⚠️ CRITICAL: Critical VMware vCenter RCE flaw exploited for reverse SSH access

A critical directory traversal vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being actively exploited in the wild to deploy reverse SSH tools for persistence. At least 361 compromised hosts across 47 countries have been identified, with attackers establishing remote access on vi…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

security_crawler_carl@infosec.exchange at 2026-08-14T10:37:17.000Z ##

🏆 New Achievement! Directory Traversal of Doom (9.8 Stars, Would Not Recommend)!

ITEM DROPPED: CVE-2026-59310, a critical directory traversal flaw in VMware vCenter, CVSS 9.8. Broadcom disclosed this cursed artifact on July 29, and attackers — believed to be a single suspected APT actor — were already swinging it around earlier this month. Network access to a vCenter instance is all it takes to remotely execute arbitrary code across your entire virtual environment. (1/2)

##

ottoto2017@prattohome.com at 2026-08-14T05:44:50.000Z ##

「VMware vCenterの重大なリモートコード実行(RCE)の脆弱性が悪用され、リバースSSHアクセスが行われた。 」: #BLEEPINGCOMPUTER

「VMware vCenter Syslog Serverに存在する、最近パッチが適用された重大な脆弱性(CVE-2026-59310)が、永続的な接続とリモートアクセスを目的としたリバースSSHツールの展開を目的としたアクティブな攻撃キャンペーンで悪用されています。

47か国にわたる361のIPアドレスで侵害が確認されており、その半数以上はドイツ、米国、トルコ、イラン、フランスに位置している。

Broadcomは7月29日にCVE-2026-59310を公開し、 vCenter Syslogサーバーにおける重大なディレクトリトラバーサル脆弱性 であり、ネットワークアクセス権を持つ認証されていない攻撃者が悪用して任意のコードを実行できる可能性があると説明した。 」

bleepingcomputer.com/news/secu

#prattohome

##

oversecurity@mastodon.social at 2026-08-13T17:10:35.000Z ##

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a...

🔗️ [Bleepingcomputer] link.is.it/3RirvF

##

Hackread@mstdn.social at 2026-08-13T11:44:19.000Z ##

📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310.

Listen/Read: hackread.com/apt-exploits-crit

#CyberSecurity #VMware #vCenter #APT #Vulnerability

##

beyondmachines1@infosec.exchange at 2026-08-13T10:01:21.000Z ##

Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access

German cybersecurity firm QUIRSO reports active exploitation of VMware vCenter and ESXi, critical flaws (CVE-2026-59310 and CVE-2026-59309).

**If you run VMware vCenter, this is important. Make sure it is not reachable from the internet and can only be accessed from trusted internal networks. Then urgently apply the fixes from Broadcom advisory VMSA-2026-0006.1 (vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f), because the platform is being attacked and there is no workaround for the flaws. If your vCenter was exposed, check it for signs of compromise such as unexpected cron jobs, unknown SSH tools, or unusual outbound connections.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

ottoto2017@prattohome.com at 2026-08-13T06:50:40.000Z ##

「攻撃者がVMware vCenterの脆弱性を悪用し、永続的なリモートアクセスを取得する 」: #TheHackerNews

「QUIRSOの 新たな調査結果 によると、攻撃者は、最近パッチが適用されたBroadcom VMware vCenterの重大なセキュリティ脆弱性を積極的に悪用し始めている。

問題となっている脆弱性は CVE-2026-59310 (CVSSスコア:9.8)で、VMware vCenterサーバーのディレクトリトラバーサル脆弱性であり、ネットワークアクセス権を持つ悪意のある攻撃者がこれを悪用して任意のコードを実行できる可能性がある。この脆弱性に対するパッチは、ブロードコム社が先月末にリリースした。

ドイツのサイバーセキュリティ企業は、インシデント対応活動中にこの活動を発見したと発表した。 」

thehackernews.com/2026/08/atta

#prattohome

##

cyberworldops@infosec.exchange at 2026-08-13T00:10:01.000Z ##

VMware vCenter Under Attack: CVE-2026-59310 Enables Persistent Access

cyberworldops.eu/en/vmware-vce

##

jbhall56@infosec.exchange at 2026-08-12T12:03:53.000Z ##

The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. thehackernews.com/2026/08/atta

##

CVE-2026-43723
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-28T19:31:46.327000

2 posts

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root privileges.

DailyCyberSecurity at 2026-08-13T13:16:52.105Z ##

PoC exploit code is public for CVE-2026-43723, an Apple mediaremoted flaw that lets an app gain root privileges. CVSS 7.8. Patch now.

securityonline.info/apple-medi

##

DailyCyberSecurity@infosec.exchange at 2026-08-13T13:16:52.000Z ##

PoC exploit code is public for CVE-2026-43723, an Apple mediaremoted flaw that lets an app gain root privileges. CVSS 7.8. Patch now.

#Apple #macOS #iOS #CVE #CyberSecurity

securityonline.info/apple-medi

##

CVE-2026-16756
(7.5 HIGH)

EPSS: 0.42%

updated 2026-07-24T22:37:39

1 posts

## Summary Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of servi

awssecurityfeed@infosec.exchange at 2026-08-12T19:00:01.000Z ##

CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 11:30 AM PDT
Description:
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and s...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-46331
(7.8 HIGH)

EPSS: 0.53%

updated 2026-07-23T12:18:18.287000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb

14 repos

https://github.com/vulnquest58/dirtyclone-exploit

https://github.com/douglasmun/pagecache-lpe-containment-kit

https://github.com/0xBlackash/CVE-2026-46331

https://github.com/cherrycherrymay/PoC-CVE-2026-46331

https://github.com/yanxinwu946/CVE-2026-46331

https://github.com/MarwahHadi/CVE-2026-46331-pedit-cow

https://github.com/rjt-gupta/page-cache-corruption-lpes

https://github.com/g0thamRabb1t/CVE-2026-46331-pedit-COW-detection

https://github.com/HORKimhab/CVE-2026-46331

https://github.com/seguridadentrerios/CVE-2026-46331

https://github.com/V0IDNETWORK/CVE-2026-46331

https://github.com/nawalacheker1/CVE-2026-46331

https://github.com/sgkdev/packet_edit_meme

https://github.com/Quaerendir/cve-2026-46331-audit

sigint@fosstodon.org at 2026-08-13T23:45:06.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-08-14

Another local root path via tc act_pedit in the kernel's traffic control subsystem. If you run tc filters or unprivileged netns/containers, check kernel versions and patch status now, not later.

🔗 pasqualepillitteri.it/en/news/

#Ubuntu #Linux #infosec

##

CVE-2026-44761
(9.1 CRITICAL)

EPSS: 0.46%

updated 2026-07-15T05:16:39.133000

1 posts

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on conf

CapTechGroup@mastodon.social at 2026-08-14T18:26:15.000Z ##

Attackers have begun exploiting a maximum-severity vulnerability in SAP Commerce Cloud. Four CVEs are in scope, CVE-2026-22732, CVE-2026-34263, CVE-2026-44761 and CVE-2026-58231, and any exposed deployment warrants review.

captechgroup.com/threat-intell

##

CVE-2026-43500
(7.8 HIGH)

EPSS: 92.86%

updated 2026-07-15T02:21:44.380000

1 posts

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the skb to a linear one before calling into the security ops only when skb_cloned() is true. An skb that is not cloned but still carries externally-o

24 repos

https://github.com/lukeslp/redtail-ioc

https://github.com/0xlane/pagecache-guard

https://github.com/XRSecCD/202605_dirty_frag

https://github.com/haydenjames/dirty-frag-check

https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4

https://github.com/cumakurt/linuxpi

https://github.com/metalx1993/dirtyfrag-patches

https://github.com/AK777177/Dirty-Frag-Analysis

https://github.com/suominen/CVE-2026-43284

https://github.com/vorkampfer/dirty_frag_mitigation

https://github.com/attaattaatta/CVE-2026-43500

https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag

https://github.com/1neptune/DirtyFrag

https://github.com/nonameuserosint-hue/DirtyFrag-go

https://github.com/MadExploits/CVE-2026-46300

https://github.com/linnemanlabs/dirtyfrag-arm64

https://github.com/First-John/cve_2026_frag_family_fix

https://github.com/liamromanis101/DirtyFrag-Detector

https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan

https://github.com/aettern/copyfrag-fuse

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/millikanjohnl-blip/dirtyfrag-detection-rules

https://github.com/krisiasty/vcheck

https://github.com/armircetaj/tetragon-dirtyfrag

CapTechGroup@mastodon.social at 2026-08-13T18:24:55.000Z ##

CISA republished Hitachi Energy PSIRT 8DBD000256 ("Dirty Frag"). CVE-2026-43284 (8.8, esp4/esp6 IPsec ESP, S:C) and CVE-2026-43500 (7.8, rxrpc, CWE-787) write decrypted packet data into pages the kernel doesn't own —...

captechgroup.com/threat-intell

##

CVE-2026-43284
(8.8 HIGH)

EPSS: 93.23%

updated 2026-07-15T02:21:43.190000

1 posts

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when

44 repos

https://github.com/kuniyal08/Dirty-Frag-CVE-2026-43284

https://github.com/lukeslp/redtail-ioc

https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284

https://github.com/0xlane/pagecache-guard

https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284

https://github.com/XRSecCD/202605_dirty_frag

https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC

https://github.com/haydenjames/dirty-frag-check

https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4

https://github.com/cumakurt/linuxpi

https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284

https://github.com/metalx1993/dirtyfrag-patches

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/AK777177/Dirty-Frag-Analysis

https://github.com/ChernStepanov/DirtyFrag-for-dummies

https://github.com/suominen/CVE-2026-43284

https://github.com/attaattaatta/CVE-2026-43500

https://github.com/nabhan-mohy/Dirty-Frag-Research-CVE-2026-43284-

https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag

https://github.com/1neptune/DirtyFrag

https://github.com/g0thamRabb1t/CVE-2026-43284-dirtyfrag-detection

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/nonameuserosint-hue/DirtyFrag-go

https://github.com/linnemanlabs/dirtyfrag-arm64

https://github.com/MadExploits/CVE-2026-46300

https://github.com/First-John/cve_2026_frag_family_fix

https://github.com/t1ckprivate/CVE-2026-43284-Dirty-Frag

https://github.com/liamromanis101/DirtyFrag-Detector

https://github.com/FrosterDL/CVE-2026-43284

https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan

https://github.com/xd20111/CVE-2026-43284

https://github.com/aettern/copyfrag-fuse

https://github.com/ryan2929/CVE-2026-43284-

https://github.com/0xBlackash/CVE-2026-43284

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/RevyHub/CVE-2026-43284---DirtyFrag-Analysis-THM-

https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester

https://github.com/LucasPDiniz/CVE-2026-43284

https://github.com/millikanjohnl-blip/dirtyfrag-detection-rules

https://github.com/dixyes/dirtypatch

https://github.com/krisiasty/vcheck

https://github.com/Aiyakami/rust_dirtyfrag

https://github.com/jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC

https://github.com/armircetaj/tetragon-dirtyfrag

CapTechGroup@mastodon.social at 2026-08-13T18:24:55.000Z ##

CISA republished Hitachi Energy PSIRT 8DBD000256 ("Dirty Frag"). CVE-2026-43284 (8.8, esp4/esp6 IPsec ESP, S:C) and CVE-2026-43500 (7.8, rxrpc, CWE-787) write decrypted packet data into pages the kernel doesn't own —...

captechgroup.com/threat-intell

##

CVE-2026-47301
(8.8 HIGH)

EPSS: 0.54%

updated 2026-07-14T21:32:21

2 posts

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/OmriBaso/SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit

CVE-2026-49457
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-07-01T20:32:36

2 posts

### Impact The QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so `verify` was effectively a no-op on the client. A man-in-the-middle on the network path could present any certificate and impersonate any server, defeating th

thehackerwire@mastodon.social at 2026-08-14T20:00:29.000Z ##

🔴 CVE-2026-49457 - Critical (9.1)

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T20:00:29.000Z ##

🔴 CVE-2026-49457 - Critical (9.1)

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8452
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-07-01T15:52:28.390000

12 posts

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

2 repos

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

https://github.com/derekpreston81/CVE_ADC_IOC_2026

AAKL at 2026-08-14T17:45:06.098Z ##

New.

"Wait, did they just say NetScalers?"

Watch Tower: You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) labs.watchtowr.com/youre-back- #threatresearch

##

guru@thecybersecguru.com at 2026-08-14T17:18:23.000Z ##

CVE-2026-8452: Technical Analysis of the Citrix NetScaler Memory Overflow Vulnerability

CVE-2026-8452 is a high-severity NetScaler vulnerability affecting ADC and Gateway. See affected builds, technical details, impact and patch guidance

thecybersecguru.com/news/cve-2

##

cyberveille@mastobot.ping.moi at 2026-08-14T11:00:05.000Z ##

📢 RCE pré-authentifiée sur Citrix NetScaler via heap overflow SAML (CVE-2026-8452)

Cet article présente une analyse technique approfondie d'une vulnérabilité heap overflow pré-authentifiée affectant Citrix NetScaler ADC et NetScaler Gateway, corrigée dans un récent bulletin de sécurité Citrix. La vulnérabilité, supposée être…

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : labs.watchtowr.com/youre-back-
🟢 vérification factuelle haute
#CitrixNetScaler #RCEPréAuthentifiée #Cyberveille

##

sayzard@mastodon.sayzard.org at 2026-08-14T09:40:31.000Z ##

You're Back in the Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

watchTowr Labs가 NetScaler ADC/Gateway의 SAML 서명 검증 경로에서 인증 없이 도달 가능한 힙 오버플로를 분석해 RCE로 이어질 수 있음을 공개했다. 공격자는 XML Signature의 `SignedInfo` 정규화(canonicalization) 과정에서 `InclusiveNamespaces`의 `PrefixList`를 과도하게 키워 고정 크기 전역 버퍼를 넘치게 만들 수 있으며, 패킷 처리 엔진 `nsppe`가 루트 권한으로 동작하는 점이 핵심 위험...

labs.watchtowr.com/youre-back-

##

GossiTheDog@cyberplace.social at 2026-08-14T08:23:42.000Z ##

Watchtowr got RCE via one of the many Citrix Netscaler SAML vulns. labs.watchtowr.com/youre-back-

##

glitterbean@wehavecookies.social at 2026-08-14T08:08:18.000Z ##

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452 labs.watchtowr.com/youre-back-

##

decio at 2026-08-14T07:48:36.210Z ##

RE: infosec.exchange/@watchTowr/11

Si vous n’avez pas encore patché la RCE NetScaler du mois de juin :
support.citrix.com/support-hom

ChatGPT dit que c’est probablement le dernier moment de le faire avant qu’il utilise ça comme opportunité pour s’échapper de sa sandbox.

Parce que, bien évidemment, la fine équipe de watchTowr vient de publier le write-up qui transforme le gentil « memory overflow » en RCE pré-auth root.

👇
labs.watchtowr.com/youre-back-

##

_r_netsec at 2026-08-14T07:13:05.103Z ##

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) - watchTowr Labs labs.watchtowr.com/youre-back-

##

AAKL@infosec.exchange at 2026-08-14T17:45:06.000Z ##

New.

"Wait, did they just say NetScalers?"

Watch Tower: You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) labs.watchtowr.com/youre-back- #infosec #vulnerability#threatresearch

##

GossiTheDog@cyberplace.social at 2026-08-14T08:23:42.000Z ##

Watchtowr got RCE via one of the many Citrix Netscaler SAML vulns. labs.watchtowr.com/youre-back-

##

decio@infosec.exchange at 2026-08-14T07:48:36.000Z ##

RE: infosec.exchange/@watchTowr/11

Si vous n’avez pas encore patché la RCE NetScaler du mois de juin :
support.citrix.com/support-hom

ChatGPT dit que c’est probablement le dernier moment de le faire avant qu’il utilise ça comme opportunité pour s’échapper de sa sandbox.

Parce que, bien évidemment, la fine équipe de watchTowr vient de publier le write-up qui transforme le gentil « memory overflow » en RCE pré-auth root.

#CyberVeille #NetScaler

👇
labs.watchtowr.com/youre-back-

##

_r_netsec@infosec.exchange at 2026-08-14T07:13:05.000Z ##

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) - watchTowr Labs labs.watchtowr.com/youre-back-

##

CVE-2026-49478
(8.7 HIGH)

EPSS: 0.28%

updated 2026-06-30T18:38:47

2 posts

## Impact Three security vulnerabilities were identified in the OIDC Discovery client: 1. **Blind Server-Side Request Forgery (SSRF) via Cross-Host Redirects**: Fulcio uses an HTTP client to fetch OIDC discovery metadata (`/.well-known/openid-configuration`). Prior to this fix, if a configured issuer returned an HTTP redirect to a different host, the client followed it by default. This allowe

thehackerwire@mastodon.social at 2026-08-13T14:01:13.000Z ##

🟠 CVE-2026-49478 - High (8.7)

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T14:01:13.000Z ##

🟠 CVE-2026-49478 - High (8.7)

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49473
(8.8 HIGH)

EPSS: 0.28%

updated 2026-06-30T18:09:14

1 posts

### Summary @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. An issue exists where, under certain circumstances, the middleware matches incoming requests against Cedar action mappings usin

thehackerwire@mastodon.social at 2026-08-13T03:01:09.000Z ##

🟠 CVE-2026-49473 - High (8.8)

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing request...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-23670
(5.7 MEDIUM)

EPSS: 0.26%

updated 2026-06-17T10:21:55.793000

1 posts

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

sayzard@mastodon.sayzard.org at 2026-08-13T20:43:48.000Z ##

Researchers find Windows 11 can be hacked with no physical access

버밍엄대·더럼대 연구진은 일부 DDR4/DDR5 DIMM의 SPD 구성 칩이 쓰기 보호되지 않은 점을 악용하는 원격 소프트웨어 공격 ‘Download More RAM’을 공개했다. 공격자는 메모리 용량 정보를 조작해 실제 메모리의 별칭 주소를 만들고, 이를 통해 Windows의 VBS·HVCI를 우회하거나 AV/EDR 비활성화, 차단된 취약 드라이버 재활성화 등을 수행할 수 있다. Microsoft는 CVE-2026-23670을 할당하고 2026년 4월 보안 업데이트...

neowin.net/news/researchers-fi

##

CVE-2025-24994
(7.3 HIGH)

EPSS: 1.17%

updated 2026-06-17T08:59:57.383000

2 posts

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

CVE-2026-47717
(7.5 HIGH)

EPSS: 1.20%

updated 2026-05-27T22:51:19

1 posts

### Summary The GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. ### Details File: `server/api/projects/index.js` ```javascript prjApp.get("/api/project", secureFnc, function(req, res) { const permission = checkGroupsFnc(req); runtime.project.getProject(req.userId, permission).then(result => { i

thehackerwire@mastodon.social at 2026-08-13T00:00:28.000Z ##

🟠 CVE-2026-47717 - High (7.5)

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Versio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34263
(9.6 CRITICAL)

EPSS: 0.61%

updated 2026-05-12T03:31:32

1 posts

Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application.

CapTechGroup@mastodon.social at 2026-08-14T18:26:15.000Z ##

Attackers have begun exploiting a maximum-severity vulnerability in SAP Commerce Cloud. Four CVEs are in scope, CVE-2026-22732, CVE-2026-34263, CVE-2026-44761 and CVE-2026-58231, and any exposed deployment warrants review.

captechgroup.com/threat-intell

##

CVE-2026-27912
(8.0 HIGH)

EPSS: 0.24%

updated 2026-04-14T18:30:50

1 posts

Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.

3 repos

https://github.com/oxstussz-eng/Kerberos-CVE-2026-27912

https://github.com/Semperis-Community/ResetNightmare

https://github.com/mihat2/ResetNightmare-impacket

tierrasapiens@mastodon.social at 2026-08-13T18:11:19.000Z ##

🖲️ #Noticia de #CiberSeguridad #CiberGuerra #CiberAtaque #CiberNoticia
⚫ ResetNightmare: exploit público permite restablecer cualquier contraseña de cuentas de AD (CVE-2026-27912)
🔗 blog.segu-info.com.ar/2026/08/

Investigadores publicaron todos los detalles y una herramienta de prueba de
concepto para
CVE-2026-27912
(CVSS 8.0), llamada
ResetNightmare. La falla se encuentra en el protocolo de cambio de contraseña Kerberos de

##

CVE-2026-22732
(9.1 CRITICAL)

EPSS: 0.48%

updated 2026-03-20T20:42:26

1 posts

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

1 repos

https://github.com/semgrep/cve-2026-22732-demo

CapTechGroup@mastodon.social at 2026-08-14T18:26:15.000Z ##

Attackers have begun exploiting a maximum-severity vulnerability in SAP Commerce Cloud. Four CVEs are in scope, CVE-2026-22732, CVE-2026-34263, CVE-2026-44761 and CVE-2026-58231, and any exposed deployment warrants review.

captechgroup.com/threat-intell

##

CVE-2024-55591
(9.8 CRITICAL)

EPSS: 98.26%

updated 2025-10-22T00:34:16

2 posts

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

9 repos

https://github.com/0x7556/CVE-2024-55591

https://github.com/binarywarm/exp-cmd-add-admin-vpn-CVE-2024-55591

https://github.com/watchtowrlabs/fortios-auth-bypass-poc-CVE-2024-55591

https://github.com/sysirq/fortios-auth-bypass-exploit-CVE-2024-55591

https://github.com/sysirq/fortios-auth-bypass-poc-CVE-2024-55591

https://github.com/exfil0/CVE-2024-55591-POC

https://github.com/virus-or-not/CVE-2024-55591

https://github.com/watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591

https://github.com/UMChacker/CVE-2024-55591-POC

PC_Fluesterer@social.tchncs.de at 2026-08-14T09:20:46.000Z ##

Warnung vor Angriffen gegen Fortinet

Diese Meldung wiederholt das Thema der vorigen: Software (oder Firmware) nicht aktuell -> gehackt. Heute geht es um eine konkrete Erpresser-Gang namens Gunra. Die durchsucht das Internet nach erreichbaren Firewalls und Routern von Fortinet und versucht, ältere Sicherheitslücken (CVE-2024-55591 und CVE-2025-24472) auszunutzen. Beide sind längst als bereits ausgenutzt bekannt. Wenn die verfügbaren Updates nicht eingespielt wurden, die Lücken also noch offen sind, ist das angegriffene Netzwerk kompromittiert; Datenlecks, Betriebsunterbrechungen und Erpressung folgen. In den USA hat es bereits viele Institutionen getroffen, vom ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #closedsource #cybercrime #firewall #hersteller #router #sicherheit #vorbeugen

##

Analyst207@mastodon.social at 2026-08-12T14:03:19.000Z ##

Gunra Ransomware Targets Infrastructure via Fortinet Flaws

Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

osintsights.com/gunra-ransomwa

#GunraRansomware #Fortinet #Cve202455591 #Ransomware #SupplyChain

##

CVE-2025-24076
(7.3 HIGH)

EPSS: 3.15%

updated 2025-03-11T18:32:27

2 posts

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

1 repos

https://github.com/mbanyamer/CVE-2025-24076

CVE-2026-15826
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-08-15T04:04:33.401Z ##

CVE-2026-15826 (CVSS 9.8) is a User Profile Builder vulnerability letting attackers log in as WordPress admin. Over 40,000 sites affected; update to 3.16.5

securityonline.info/user-profi

##

DailyCyberSecurity@infosec.exchange at 2026-08-15T04:04:33.000Z ##

CVE-2026-15826 (CVSS 9.8) is a User Profile Builder vulnerability letting attackers log in as WordPress admin. Over 40,000 sites affected; update to 3.16.5

#CVE202615826 #WordPress #UserProfileBuilder #InfoSec

securityonline.info/user-profi

##

CVE-2026-45699
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-14T20:00:14.000Z ##

🟠 CVE-2026-45699 - High (7.5)

Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the copydir() function of Netatalk's afpd daemon due to an integer underflow in the ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T20:00:14.000Z ##

🟠 CVE-2026-45699 - High (7.5)

Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the copydir() function of Netatalk's afpd daemon due to an integer underflow in the ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34491
(0 None)

EPSS: 0.00%

1 posts

N/A

netsecio@mastodon.social at 2026-08-14T13:36:03.000Z ##

📰 CISA warns of XSS flaw in Johnson Controls Metasys ICS (CVE-2026-34491)

CISA warns of a high-severity XSS flaw (CVE-2026-34491) in Johnson Controls Metasys ICS. The bug allows low-privilege users to hijack admin sessions. Affects versions 12-15. Patch now! #ICS #OTsecurity #CISA #Vulnerability

🔗 cyber.netsecops.io/articles/ci

##

CVE-2026-65640
(0 None)

EPSS: 0.00%

10 posts

N/A

1 repos

https://github.com/jobusa755-a11y/CVE-2026-65640-

netsecio@mastodon.social at 2026-08-14T13:35:48.000Z ##

📰 WordPress patches critical RCE flaw (CVE-2026-65640) for author-level users

WordPress 7.0.4 patches a critical RCE flaw (CVE-2026-65640, CVSS 8.8). Authenticated authors could take over sites using a malicious image file on servers with Imagick. Update your WordPress sites immediately! #WordPress #RCE #CyberSecurity

🔗 cyber.netsecops.io/articles/cr

##

cyberveille@mastobot.ping.moi at 2026-08-14T10:30:06.000Z ##

📢 WordPress 7.0.4 corrige une RCE via fichiers PostScript malveillants (CVE-2026-65640)

Cet article rapporte la publication par WordPress d'un correctif pour une vulnérabilité d'exécution de code à distance (RCE) de haute sévérité, identifiée sous CVE-2026-65640 avec un score CVSS de 8.8.

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : securityweek.com/wordpress-7-0
🟢 vérification factuelle haute
#RCE #WordPress #Cyberveille

##

undercodenews@mastodon.social at 2026-08-13T17:55:48.000Z ##

WordPress 704 Security Update: A Claimed CVE-2026-65640 Flaw Puts Author-Level Uploads Under the Microscope + Video

A New WordPress Security Warning Is Raising Fresh Concerns WordPress powers a huge portion of the modern web, which makes every serious vulnerability in its ecosystem worth watching closely. A seemingly ordinary media upload can become something far more dangerous when the underlying image-processing stack is capable of interpreting complex file formats.…

undercodenews.com/wordpress-70

##

decio at 2026-08-13T14:34:22.236Z ##

…et encore une vulnérabilité critique dans , trouvée une nouvelle fois par pwn.ai, qui a nécessité la publication en urgence de la mise à jour 7.0.4

La CVE-2026-65640 est une RCE assez intéressante côté traitement d’images. (ImageMagick)

Un utilisateur avec le rôle Author peut envoyer un fichier nommé comme une innocente image .png, alors que son contenu est en réalité du PostScript/EPS.
WordPress se fiait trop à l’extension ; ImageMagick, lui, regarde le contenu et peut transmettre le fichier à Ghostscript… avec à la clé une exécution de code.

Ce n’est donc pas une RCE pré-auth : il faut déjà disposer d’un compte Author. Mais sur un site multi-auteurs, communautaire ou avec des comptes peu maîtrisés, le risque devient nettement plus concret.
👇
wordpress.org/news/2026/08/wor
⬇️
github.com/WordPress/wordpress

##

raul@mastodon.in4matics.cat at 2026-08-13T11:30:15.000Z ##

🖼️ RCE a WordPress via PNG maliciosos. CVE-2026-65640, fix a 7.0.4.

Atacant amb rol Autor puja `EPS:innocent.png` o un PNG amb PostScript ocult. `Imagick::load()` confiava en l'extensió; ImageMagick llegeix el contingut real → Ghostscript executa. XML-RPC i portades MP3 saltaven la validació.

El patch inspecciona bytes reals: bloqueja PostScript/EPS, PDF sense `%PDF-` i gzip/bzip2.
blog.elhacker.net/2026/08/vuln
#WordPress #SecOps #ImageMagick

##

DailyCyberSecurity at 2026-08-13T07:35:31.550Z ##

WordPress 7.0.4 patches CVE-2026-65640, an Author-level remote code execution bug on sites using Imagick and Ghostscript. Update now.

securityonline.info/wordpress-

##

guru@thecybersecguru.com at 2026-08-13T07:31:35.000Z ##

WordPress 7.0.4 Fixes Critical Imagick RCE: How a Malicious PNG Could Become Server-Side Code Execution

WordPress 7.0.4 fixes CVE-2026-65640, an authenticated RCE affecting sites using Imagick and Ghostscript. Learn how malicious PNG reach code execution

thecybersecguru.com/news/wordp

##

decio@infosec.exchange at 2026-08-13T14:34:22.000Z ##

…et encore une vulnérabilité critique dans #WordPress, trouvée une nouvelle fois par pwn.ai, qui a nécessité la publication en urgence de la mise à jour 7.0.4

La CVE-2026-65640 est une RCE assez intéressante côté traitement d’images. (ImageMagick)

Un utilisateur avec le rôle Author peut envoyer un fichier nommé comme une innocente image .png, alors que son contenu est en réalité du PostScript/EPS.
WordPress se fiait trop à l’extension ; ImageMagick, lui, regarde le contenu et peut transmettre le fichier à Ghostscript… avec à la clé une exécution de code.

Ce n’est donc pas une RCE pré-auth : il faut déjà disposer d’un compte Author. Mais sur un site multi-auteurs, communautaire ou avec des comptes peu maîtrisés, le risque devient nettement plus concret.
👇
wordpress.org/news/2026/08/wor
⬇️
github.com/WordPress/wordpress

#CyberVeille

##

raul@mastodon.in4matics.cat at 2026-08-13T11:30:15.000Z ##

🖼️ RCE a WordPress via PNG maliciosos. CVE-2026-65640, fix a 7.0.4.

Atacant amb rol Autor puja `EPS:innocent.png` o un PNG amb PostScript ocult. `Imagick::load()` confiava en l'extensió; ImageMagick llegeix el contingut real → Ghostscript executa. XML-RPC i portades MP3 saltaven la validació.

El patch inspecciona bytes reals: bloqueja PostScript/EPS, PDF sense `%PDF-` i gzip/bzip2.
blog.elhacker.net/2026/08/vuln
#WordPress #SecOps #ImageMagick

##

DailyCyberSecurity@infosec.exchange at 2026-08-13T07:35:31.000Z ##

WordPress 7.0.4 patches CVE-2026-65640, an Author-level remote code execution bug on sites using Imagick and Ghostscript. Update now.

#WordPress #CVE202665640 #RCE #Imagick #Ghostscript #WebSecurity #Cybersecurity

securityonline.info/wordpress-

##

CVE-2026-63030
(0 None)

EPSS: 95.60%

2 posts

N/A

82 repos

https://github.com/sowarma/wp2shell-PoC

https://github.com/bahartanir/wp2shell-scanner

https://github.com/4minx/CVE-2026-63030

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/yuag/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/shinthink/CVE-2026-63030

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/securelayer7/WordPresShell

https://github.com/ananay/wp2shell-lab

https://github.com/InstaWP/wp2shell-scan

https://github.com/Icex0/wp2shell-poc

https://github.com/imXur/WordPress-CVE-2026-63030-Analysis

https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass

https://github.com/0xjessie21/wp2shell-checker

https://github.com/minwunn/wp2shell-CVE-2026-63030

https://github.com/mhtsec/CVE-2026-63030

https://github.com/attackercan/wp2shell-poc2

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/Madelleimproved411/wp-to-code

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/gbrsh/CVE-2026-63030

https://github.com/kulichr/wp2shell

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/dinosn/wp2shell-lab

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/rechandra/wp2exp-2026

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/johnlodan/wp2shell-rce

https://github.com/zi3lak/wp2shell_scanner

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/vulnquest58/PressVector

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/g0d150ne/WP2Shell

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/c0gnit00/Wp2Shell

https://github.com/ekomsSavior/wp2shell

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/mcipekci/wp2shell

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/Procjevt/CVE-2026-63030

https://github.com/fullhunt/wp2shell-scan

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/x-znn/CVE-2026-63030

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/47Cid/wp2shell-lab

https://github.com/0xWhoknows/wp2shell

https://github.com/AnggaTechI/CVE-2026-63030

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/h4cd0c/wp2shell

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/Iqbalx7/wp2shell

https://github.com/Crypto-Cat/wp2shell

https://github.com/ikow/wp2shell

https://github.com/mverschu/CVE-2026-63030

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/0xsha/wp2shell

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

fastnews@fedibird.com at 2026-08-14T03:15:03.000Z ##

ワークマンプラス公式Instagramが8月3日、「wp2shell」(CVE-2026-63030 / 44歳エッジィなグラフィックTシャツにネックレス。カルチャーの薫りが漂う着こなしにも、一度試してみるのが良いかもしれない。

##

fastnews@fedibird.com at 2026-08-14T03:15:03.000Z ##

ワークマンプラス公式Instagramが8月3日、「wp2shell」(CVE-2026-63030 / 44歳エッジィなグラフィックTシャツにネックレス。カルチャーの薫りが漂う着こなしにも、一度試してみるのが良いかもしれない。

##

CVE-2026-73408
(0 None)

EPSS: 0.33%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-14T03:00:54.000Z ##

🟠 CVE-2026-73408 - High (7.6)

Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table with a bac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T03:00:54.000Z ##

🟠 CVE-2026-73408 - High (7.6)

Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table with a bac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73659
(0 None)

EPSS: 0.34%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-14T01:00:16.000Z ##

🟠 CVE-2026-73659 - High (8.1)

Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.$.ts pass a caller-controlled filename through resolveStoreProtocolForPacke...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T01:00:16.000Z ##

🟠 CVE-2026-73659 - High (8.1)

Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.$.ts pass a caller-controlled filename through resolveStoreProtocolForPacke...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73658
(0 None)

EPSS: 0.33%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-14T00:00:25.000Z ##

🟠 CVE-2026-73658 - High (8.2)

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-control...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T00:00:25.000Z ##

🟠 CVE-2026-73658 - High (8.2)

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-control...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73667
(0 None)

EPSS: 0.61%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-14T00:00:04.000Z ##

🟠 CVE-2026-73667 - High (8.8)

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workflow parame...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-14T00:00:04.000Z ##

🟠 CVE-2026-73667 - High (8.8)

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workflow parame...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73666
(0 None)

EPSS: 0.48%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-13T23:00:30.000Z ##

🟠 CVE-2026-73666 - High (8.2)

OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T23:00:30.000Z ##

🟠 CVE-2026-73666 - High (8.2)

OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73842
(0 None)

EPSS: 0.18%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-13T23:00:08.000Z ##

🔴 CVE-2026-73842 - Critical (9)

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a clie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T23:00:08.000Z ##

🔴 CVE-2026-73842 - Critical (9)

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a clie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49827
(0 None)

EPSS: 0.48%

4 posts

N/A

thehackerwire@mastodon.social at 2026-08-13T14:01:03.000Z ##

🔴 CVE-2026-49827 - Critical (9.8)

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-13T13:30:27.621Z ##

CVE-2026-49827: SMEWebify WebErpMesv2 ≤1.19 has a CRITICAL vuln — improper input validation lets any self-registered user achieve unauth'd RCE via PHP file upload (scan_file param). Patch with commit 5c54862fa044b363fd2be03d586750e81afd6818 radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-13T14:01:03.000Z ##

🔴 CVE-2026-49827 - Critical (9.8)

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-13T13:30:27.000Z ##

CVE-2026-49827: SMEWebify WebErpMesv2 ≤1.19 has a CRITICAL vuln — improper input validation lets any self-registered user achieve unauth'd RCE via PHP file upload (scan_file param). Patch with commit 5c54862fa044b363fd2be03d586750e81afd6818 radar.offseq.com/threat/cve-20 #OffSeq #CVE202649827 #infosec

##

CVE-2026-48273
(0 None)

EPSS: 0.00%

2 posts

N/A

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

CVE-2026-49481
(0 None)

EPSS: 0.88%

3 posts

N/A

offseq at 2026-08-13T06:00:25.000Z ##

CVE-2026-49481 | UpSnap (<5.4.0) has a CRITICAL OS command injection flaw (CVSS 9.6). Authenticated low-priv users can execute arbitrary commands on the server. Patch: upgrade to 5.4.0. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-13T06:00:25.000Z ##

CVE-2026-49481 | UpSnap (<5.4.0) has a CRITICAL OS command injection flaw (CVSS 9.6). Authenticated low-priv users can execute arbitrary commands on the server. Patch: upgrade to 5.4.0. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202649481 #remotecodeexecution

##

thehackerwire@mastodon.social at 2026-08-13T00:00:19.000Z ##

🔴 CVE-2026-49481 - Critical (9.6)

UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac field...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73501
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T23:00:00.000Z ##

🔴 CVE-2026-73501 - Critical (9.1)

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19654
(0 None)

EPSS: 0.40%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T22:02:00.000Z ##

🟠 CVE-2026-19654 - High (7.5)

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73299
(0 None)

EPSS: 1.21%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T20:00:26.000Z ##

🔴 CVE-2026-73299 - Critical (10)

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled templat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18952
(0 None)

EPSS: 0.32%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T20:00:06.000Z ##

🟠 CVE-2026-18952 - High (8.1)

Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the thr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73294
(0 None)

EPSS: 0.45%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T17:01:02.000Z ##

🔴 CVE-2026-73294 - Critical (9.9)

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/project/{id}/rep...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73293
(0 None)

EPSS: 0.40%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T17:00:25.000Z ##

🟠 CVE-2026-73293 - High (8.8)

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to use POST /api/project/{id}/roles to create a cust...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites