##
Updated at UTC 2026-09-08T05:07:31.327227
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-18922 | 9.8 | 0.00% | 2 | 0 | 2026-09-08T03:32:16 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a st | |
| CVE-2026-86510 | 9.9 | 0.00% | 4 | 0 | 2026-09-08T02:17:28.357000 | A vulnerability has been found in D-Link DIR-822A A_101. Affected is the functio | |
| CVE-2026-86509 | 9.6 | 0.00% | 4 | 0 | 2026-09-08T01:17:55.947000 | A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function se | |
| CVE-2026-76969 | 9.4 | 0.00% | 4 | 0 | 2026-09-08T01:17:55.407000 | @sap/cds-mtxs NPM library does not perform sufficient checks on certain function | |
| CVE-2026-76967 | 7.8 | 0.00% | 2 | 0 | 2026-09-08T01:17:55.170000 | SAP NetWeaver Business Client does not perform sufficient validation when proces | |
| CVE-2026-76958 | 8.5 | 0.00% | 2 | 0 | 2026-09-08T01:17:54.430000 | SAP Integration Suite does not sufficiently validate XML documents accepted from | |
| CVE-2026-66768 | 9.0 | 0.00% | 2 | 0 | 2026-09-08T01:17:52.113000 | SAP GUI for Java does not correctly enforce the trust level policy for certain f | |
| CVE-2026-66767 | 7.7 | 0.00% | 2 | 0 | 2026-09-08T01:17:51.987000 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenti | |
| CVE-2026-58240 | 9.8 | 0.00% | 2 | 0 | 2026-09-08T01:17:51.080000 | SAP NetWeaver Message Server does not sufficiently validate the authenticity of | |
| CVE-2026-44756 | 10.0 | 0.00% | 2 | 0 | 2026-09-08T01:17:30.840000 | A memory safety vulnerability exists in the Extended Passport Protocol (EPP) pro | |
| CVE-2026-86541 | 8.3 | 0.00% | 2 | 0 | 2026-09-08T00:30:33 | knowns versions before 0.30.0 contain a path traversal vulnerability in the hand | |
| CVE-2026-86540 | 7.8 | 0.00% | 2 | 0 | 2026-09-08T00:30:32 | knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary | |
| CVE-2026-86544 | 8.1 | 0.00% | 2 | 0 | 2026-09-08T00:30:32 | knowns versions before 0.30.0 contain an authorization bypass vulnerability wher | |
| CVE-2026-86543 | 9.8 | 0.00% | 4 | 0 | 2026-09-08T00:30:32 | knowns versions before 0.30.0 serve the management API without authentication on | |
| CVE-2026-86542 | 9.1 | 0.00% | 2 | 0 | 2026-09-07T23:16:54.020000 | knowns before 0.30.0 fails to validate import names in the import routes, allowi | |
| CVE-2026-86538 | 7.5 | 0.00% | 2 | 0 | 2026-09-07T23:16:53.443000 | knowns versions before 0.30.0 contain a path traversal vulnerability in the POST | |
| CVE-2026-86439 | 8.8 | 0.00% | 2 | 0 | 2026-09-07T23:16:53.297000 | knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool argu | |
| CVE-2026-75650 | 10.0 | 0.00% | 9 | 0 | 2026-09-07T21:30:30 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Use | |
| CVE-2026-86494 | 7.7 | 0.00% | 2 | 0 | 2026-09-07T18:31:42 | In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthori | |
| CVE-2026-86498 | 7.7 | 0.00% | 2 | 0 | 2026-09-07T18:31:42 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link s | |
| CVE-2026-80166 | 7.8 | 0.00% | 2 | 0 | 2026-09-07T18:31:36 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application | |
| CVE-2026-86482 | 8.8 | 0.00% | 2 | 0 | 2026-09-07T18:31:36 | In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes all | |
| CVE-2026-86478 | 9.8 | 0.00% | 2 | 0 | 2026-09-07T18:31:36 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authenticatio | |
| CVE-2026-86492 | 8.5 | 0.00% | 2 | 0 | 2026-09-07T18:31:33 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-ten | |
| CVE-2026-86504 | 7.8 | 0.00% | 2 | 0 | 2026-09-07T17:17:28.903000 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation be | |
| CVE-2026-86502 | 8.4 | 0.00% | 2 | 0 | 2026-09-07T17:17:28.670000 | In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the | |
| CVE-2026-86480 | 9.8 | 0.00% | 4 | 0 | 2026-09-07T17:17:26.150000 | In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register | |
| CVE-2026-86479 | 8.1 | 0.00% | 2 | 0 | 2026-09-07T17:17:26.040000 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing | |
| CVE-2026-86429 | 7.5 | 0.00% | 2 | 0 | 2026-09-07T15:34:01 | The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and | |
| CVE-2026-86435 | 7.5 | 0.00% | 2 | 0 | 2026-09-07T15:34:01 | commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerab | |
| CVE-2026-76578 | 9.8 | 0.00% | 2 | 0 | 2026-09-07T15:33:55 | A flaw was found in FreeIPA. The self-managed OTP token ACI does not require aut | |
| CVE-2026-6223 | 9.4 | 0.00% | 2 | 0 | 2026-09-07T15:33:55 | Improper restriction of excessive authentication attempts vulnerability in Bahçe | |
| CVE-2026-7861 | 9.8 | 0.00% | 2 | 0 | 2026-09-07T15:17:32.153000 | Deserialization of untrusted data vulnerability in Next4Biz Information Technolo | |
| CVE-2026-67276 | 0 | 0.25% | 16 | 3 | 2026-09-07T14:16:53.843000 | RouterOS does not compare the complete RSA public key when matching an SSH authe | |
| CVE-2026-86428 | 7.5 | 0.00% | 2 | 0 | 2026-09-07T13:20:42.037000 | commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnera | |
| CVE-2026-86296 | 10.0 | 0.00% | 2 | 0 | 2026-09-07T12:30:36 | A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affe | |
| CVE-2026-86297 | 8.1 | 0.00% | 2 | 0 | 2026-09-07T12:30:36 | A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects | |
| CVE-2026-83627 | 9.8 | 0.82% | 1 | 0 | 2026-09-07T12:17:20.100000 | The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for | |
| CVE-2026-81543 | 8.8 | 0.25% | 1 | 0 | 2026-09-07T12:17:19.753000 | The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Pri | |
| CVE-2026-77393 | 8.8 | 0.51% | 1 | 0 | 2026-09-07T12:17:19.230000 | In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shi | |
| CVE-2026-75925 | 9.6 | 0.67% | 3 | 0 | 2026-09-07T12:17:18.960000 | Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4. | |
| CVE-2026-75816 | 9.8 | 0.50% | 2 | 0 | 2026-09-07T12:17:18.850000 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentic | |
| CVE-2026-79697 | 9.9 | 3.35% | 2 | 0 | 2026-09-07T09:31:46 | A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-661 | |
| CVE-2026-79698 | 9.9 | 1.70% | 4 | 0 | 2026-09-07T09:31:46 | A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-661 | |
| CVE-2026-14296 | 7.5 | 0.11% | 3 | 0 | 2026-09-07T09:31:39 | When using the Direct XIP update strategy, the main application image starts oth | |
| CVE-2026-19633 | 8.8 | 0.36% | 2 | 0 | 2026-09-06T18:34:45 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked u | |
| CVE-2026-86259 | 7.5 | 0.25% | 2 | 0 | 2026-09-06T15:31:06 | OpenMAIC before 1.0.1 skips server-side request forgery validation in non-produc | |
| CVE-2026-78362 | 9.8 | 0.34% | 2 | 0 | 2026-09-06T12:31:26 | The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly vali | |
| CVE-2026-84935 | 8.0 | 0.23% | 2 | 0 | 2026-09-06T12:31:26 | The HT Menu WordPress plugin before 1.2.7 does not perform any capability or ob | |
| CVE-2026-84934 | 8.0 | 0.23% | 2 | 0 | 2026-09-06T12:31:26 | The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability che | |
| CVE-2026-86250 | 7.5 | 0.28% | 2 | 0 | 2026-09-06T12:30:30 | h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user | |
| CVE-2026-86242 | 8.1 | 0.62% | 2 | 0 | 2026-09-06T12:17:15.583000 | Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path | |
| CVE-2026-84219 | 7.5 | 0.22% | 2 | 0 | 2026-09-06T11:18:03.950000 | The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of th | |
| CVE-2026-82304 | 8.6 | 0.32% | 2 | 0 | 2026-09-06T11:18:02.880000 | The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user | |
| CVE-2026-77826 | 8.8 | 0.27% | 2 | 0 | 2026-09-06T11:18:01.470000 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which app | |
| CVE-2026-19858 | 7.5 | 0.32% | 2 | 0 | 2026-09-06T11:18:00.793000 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 | |
| CVE-2026-18480 | 8.8 | 0.23% | 2 | 0 | 2026-09-06T11:18:00.657000 | The SureCart WordPress plugin before 4.6.3 does not ensure that the account aff | |
| CVE-2026-86165 | 9.8 | 0.64% | 2 | 0 | 2026-09-06T06:30:21 | A vulnerability was found in Tenda HG10 300001138. This vulnerability affects th | |
| CVE-2026-86167 | 9.9 | 1.63% | 2 | 0 | 2026-09-06T05:16:50.477000 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function | |
| CVE-2026-86166 | 8.8 | 0.48% | 2 | 0 | 2026-09-06T04:18:32.783000 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the f | |
| CVE-2026-86218 | None | 0.41% | 22 | 1 | 2026-09-06T03:30:35 | N-central is vulnerable to a pre-auth remote code execution This issue affects N | |
| CVE-2026-16310 | 9.8 | 0.30% | 2 | 0 | 2026-09-06T03:30:30 | The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Refe | |
| CVE-2026-18056 | 7.5 | 0.34% | 2 | 0 | 2026-09-06T03:30:30 | The HivePress Authentication plugin for WordPress is vulnerable to Authenticatio | |
| CVE-2026-86153 | 9.1 | 0.39% | 2 | 0 | 2026-09-06T03:30:30 | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the functi | |
| CVE-2026-86152 | 10.0 | 1.86% | 2 | 0 | 2026-09-06T03:30:30 | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the func | |
| CVE-2026-85046 | 8.8 | 1.16% | 43 | 4 | 2026-09-06T03:30:24 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at | |
| CVE-2026-86151 | 9.1 | 2.04% | 2 | 0 | 2026-09-06T00:31:04 | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is t | |
| CVE-2026-86148 | 9.1 | 2.46% | 2 | 0 | 2026-09-06T00:31:04 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability | |
| CVE-2026-86149 | 9.1 | 2.04% | 2 | 0 | 2026-09-05T22:17:18.943000 | A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some | |
| CVE-2026-86206 | None | 0.29% | 2 | 0 | 2026-09-05T21:31:26 | A vulnerability in the N-central internal API access control filter allows unaut | |
| CVE-2026-67277 | None | 0.43% | 6 | 0 | 2026-09-05T21:31:20 | RouterOS accepts a "related" btest connection before the corresponding primary s | |
| CVE-2026-86060 | 0 | 0.40% | 11 | 0 | 2026-09-05T21:16:51.400000 | RouterOS contains an argument-handling flaw in the SSH login path involving user | |
| CVE-2026-67279 | 0 | 0.45% | 4 | 0 | 2026-09-05T21:16:50.613000 | RouterOS SSH enters the connection protocol after a client-requested rekey even | |
| CVE-2026-86207 | 0 | 0.30% | 2 | 0 | 2026-09-05T19:16:56.190000 | An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypa | |
| CVE-2026-0799 | 8.7 | 0.11% | 2 | 0 | 2026-09-05T19:16:55.320000 | In BPF instructions that load/store a value from/to a scratch memory register th | |
| CVE-2026-86189 | 9.8 | 0.41% | 2 | 0 | 2026-09-05T15:30:31 | WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php th | |
| CVE-2026-86145 | 8.2 | 0.37% | 1 | 0 | 2026-09-05T14:17:23.897000 | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of | |
| CVE-2026-86190 | 9.1 | 0.27% | 3 | 0 | 2026-09-05T13:18:14.150000 | WWBN AVideo contains a broken access control vulnerability in videoViewsInfo end | |
| CVE-2026-86184 | 9.8 | 0.60% | 2 | 0 | 2026-09-05T12:31:35 | Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in t | |
| CVE-2026-10196 | 9.8 | 0.63% | 2 | 0 | 2026-09-05T12:31:34 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emai | |
| CVE-2025-9049 | 8.8 | 0.25% | 2 | 0 | 2026-09-05T12:31:34 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unaut | |
| CVE-2026-86117 | 8.1 | 0.42% | 2 | 0 | 2026-09-05T12:31:34 | Coolify through 4.3.17 contains an authentication bypass vulnerability in the OA | |
| CVE-2026-86123 | 8.7 | 0.33% | 1 | 0 | 2026-09-05T12:31:34 | SQL Chat contains four unauthenticated API endpoints that accept client-supplied | |
| CVE-2026-86124 | 9.8 | 0.54% | 3 | 0 | 2026-09-05T12:31:27 | AutoAgent contains an unauthenticated remote code execution vulnerability in the | |
| CVE-2026-86121 | 9.8 | 0.59% | 2 | 0 | 2026-09-05T12:31:27 | Cua computer-server versions before 0.3.42 skip authentication when the CONTAINE | |
| CVE-2026-86173 | 7.5 | 0.37% | 2 | 0 | 2026-09-05T12:31:27 | MindsDB through 26.1.0 contains a server-side request forgery vulnerability in t | |
| CVE-2026-86185 | 8.0 | 0.11% | 2 | 0 | 2026-09-05T12:16:49.240000 | Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wi | |
| CVE-2026-86177 | 8.8 | 0.31% | 2 | 0 | 2026-09-05T11:16:46.397000 | Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in | |
| CVE-2026-86169 | 8.8 | 0.48% | 2 | 0 | 2026-09-05T11:16:45.703000 | Axolotl through 0.18.0 contains a remote code execution vulnerability in the mul | |
| CVE-2026-86119 | 8.6 | 0.35% | 1 | 0 | 2026-09-05T10:16:43.157000 | Webstudio through 0.296.0 contains an unauthenticated server-side request forger | |
| CVE-2026-19887 | 8.8 | 0.57% | 1 | 0 | 2026-09-05T07:17:11.657000 | The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injectio | |
| CVE-2026-13447 | 9.8 | 0.38% | 2 | 0 | 2026-09-05T06:32:44 | The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via J | |
| CVE-2026-86140 | 8.0 | 0.14% | 1 | 0 | 2026-09-05T05:17:12.877000 | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-base | |
| CVE-2026-78012 | 9.8 | 0.47% | 2 | 0 | 2026-09-05T00:32:06 | An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Cl | |
| CVE-2026-82684 | 8.1 | 0.46% | 2 | 0 | 2026-09-05T00:31:10 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Mi | |
| CVE-2026-52775 | 8.8 | 0.29% | 1 | 0 | 2026-09-05T00:17:20.520000 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through | |
| CVE-2026-52771 | 8.3 | 0.30% | 2 | 0 | 2026-09-05T00:17:19.963000 | YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4. | |
| CVE-2026-52767 | 8.2 | 0.22% | 1 | 0 | 2026-09-05T00:17:19.540000 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4. | |
| CVE-2026-52766 | 9.1 | 0.33% | 1 | 0 | 2026-09-05T00:17:19.393000 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespam | |
| CVE-2026-86095 | 7.8 | 0.13% | 1 | 0 | 2026-09-04T23:18:03.220000 | Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in | |
| CVE-2026-48019 | 8.9 | 0.68% | 1 | 1 | 2026-09-04T23:17:09.143000 | Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a | |
| CVE-2026-82712 | 8.8 | 0.25% | 1 | 0 | 2026-09-04T21:31:59 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cr | |
| CVE-2026-80119 | 7.8 | 0.12% | 1 | 0 | 2026-09-04T21:31:59 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10 | |
| CVE-2026-80116 | 7.8 | 0.11% | 1 | 0 | 2026-09-04T21:31:59 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10 | |
| CVE-2026-78327 | 9.1 | 1.55% | 2 | 0 | 2026-09-04T21:31:50 | An Improper Neutralization of Special Elements used in an OS Command ('OS Comman | |
| CVE-2026-75431 | 9.1 | 0.77% | 1 | 1 | 2026-09-04T21:31:48 | PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signin | |
| CVE-2026-81939 | 9.1 | 0.73% | 1 | 0 | 2026-09-04T20:17:29.647000 | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem | |
| CVE-2026-80114 | 7.8 | 0.13% | 1 | 0 | 2026-09-04T20:17:28.787000 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10 | |
| CVE-2026-78328 | 9.1 | 0.50% | 2 | 0 | 2026-09-04T20:17:27.993000 | A missing authorization vulnerability in the SonicWall Network Security Manager | |
| CVE-2026-75160 | 9.1 | 0.43% | 2 | 0 | 2026-09-04T20:17:26.533000 | An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escala | |
| CVE-2026-61699 | 8.1 | 0.25% | 1 | 0 | 2026-09-04T20:17:24.347000 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to v | |
| CVE-2026-53932 | 8.0 | 0.91% | 1 | 0 | 2026-09-04T20:17:23.570000 | laravel-backup-restore restores database backups made with spatie/laravel-backup | |
| CVE-2026-80118 | 7.1 | 0.11% | 1 | 0 | 2026-09-04T19:17:28.710000 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10 | |
| CVE-2026-80112 | 7.8 | 0.10% | 2 | 0 | 2026-09-04T19:17:27.823000 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10 | |
| CVE-2026-77822 | 8.2 | 0.21% | 1 | 0 | 2026-09-04T19:17:27.240000 | IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obta | |
| CVE-2026-75430 | 9.8 | 0.89% | 1 | 1 | 2026-09-04T19:17:26.990000 | PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/ | |
| CVE-2026-85654 | 7.8 | 0.14% | 1 | 0 | 2026-09-04T18:31:46 | Improper neutralization of special elements used in a template engine in the CDK | |
| CVE-2026-18486 | 8.8 | 0.32% | 1 | 0 | 2026-09-04T18:31:32 | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote au | |
| CVE-2026-18221 | 8.1 | 0.32% | 1 | 0 | 2026-09-04T18:31:31 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized | |
| CVE-2026-19298 | 8.8 | 0.47% | 2 | 0 | 2026-09-04T18:31:26 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke | |
| CVE-2026-19300 | 7.5 | 0.38% | 2 | 0 | 2026-09-04T18:31:26 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain se | |
| CVE-2026-19305 | 8.6 | 0.29% | 2 | 0 | 2026-09-04T18:31:26 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain se | |
| CVE-2026-19304 | 7.7 | 0.31% | 1 | 0 | 2026-09-04T18:31:21 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke | |
| CVE-2026-19303 | 8.1 | 0.38% | 1 | 0 | 2026-09-04T18:31:21 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke | |
| CVE-2026-18905 | 7.7 | 0.31% | 2 | 0 | 2026-09-04T18:31:20 | IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context | |
| CVE-2026-9317 | 8.1 | 0.68% | 1 | 0 | 2026-09-04T18:18:07.297000 | Nango before 0.71.6 contains a missing authentication vulnerability in the runne | |
| CVE-2026-85656 | 7.8 | 1.12% | 2 | 0 | 2026-09-04T18:18:06.133000 | An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Am | |
| CVE-2026-82538 | 8.8 | 0.39% | 1 | 0 | 2026-09-04T18:18:01.357000 | ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerabili | |
| CVE-2026-44402 | 9.8 | 0.89% | 1 | 2 | 2026-09-04T18:17:52.080000 | Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code executi | |
| CVE-2026-31020 | 9.8 | 0.58% | 2 | 0 | 2026-09-04T18:17:51.893000 | In DocsGPT 0.15.0 and below, the application provides a custom prompt feature th | |
| CVE-2026-19306 | 7.7 | 0.41% | 2 | 0 | 2026-09-04T18:17:51.513000 | IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read a | |
| CVE-2026-19274 | 9.6 | 0.21% | 2 | 0 | 2026-09-04T18:17:51.260000 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana | |
| CVE-2026-57777 | 7.6 | 0.24% | 2 | 0 | 2026-09-04T17:16:57.160000 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti | |
| CVE-2026-18175 | 8.1 | 0.21% | 1 | 0 | 2026-09-04T17:16:56.010000 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate databas | |
| CVE-2026-5522 | 6.7 | 0.09% | 1 | 0 | 2026-09-04T16:17:25.870000 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credenti | |
| CVE-2026-19283 | 7.7 | 0.31% | 2 | 0 | 2026-09-04T16:17:21.777000 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana | |
| CVE-2026-18658 | 9.8 | 0.43% | 2 | 0 | 2026-09-04T16:17:21.133000 | IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, | |
| CVE-2026-85695 | 9.4 | 0.41% | 2 | 0 | 2026-09-04T15:36:24 | FastChat contains an authentication bypass vulnerability in the /register_worker | |
| CVE-2026-85620 | 8.6 | 0.37% | 2 | 0 | 2026-09-04T15:36:23 | Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where fun | |
| CVE-2026-85694 | 8.1 | 0.55% | 2 | 0 | 2026-09-04T15:17:47.540000 | LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkd | |
| CVE-2026-20274 | 9.8 | 0.67% | 1 | 0 | 2026-09-04T14:17:18.423000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-85224 | 9.1 | 2.15% | 2 | 0 | 2026-09-04T00:31:11 | A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affec | |
| CVE-2026-18167 | None | 0.27% | 1 | 0 | 2026-09-04T00:31:11 | A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP- | |
| CVE-2026-18330 | None | 0.23% | 1 | 0 | 2026-09-04T00:31:10 | A hard-coded cryptographic key vulnerability exists in the web module of TP-Link | |
| CVE-2026-85222 | 9.1 | 2.11% | 2 | 0 | 2026-09-03T21:31:26 | A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vuln | |
| CVE-2026-83548 | 10.0 | 0.71% | 1 | 2 | 2026-09-03T13:06:16.053000 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla | |
| CVE-2026-82329 | 9.8 | 7.67% | 1 | 7 | template | 2026-09-03T13:06:15.630000 | JFrog Artifactory contains an authentication weakness that, under default config |
| CVE-2026-20212 | 9.8 | 0.53% | 3 | 1 | 2026-09-03T13:04:38.177000 | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switc | |
| CVE-2026-20279 | 9.8 | 0.28% | 1 | 0 | 2026-09-02T18:32:32 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-82691 | 9.1 | 2.11% | 2 | 0 | 2026-09-02T14:17:15.257000 | A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-34 | |
| CVE-2026-62911 | 8.0 | 1.32% | 2 | 1 | 2026-09-02T04:18:00.460000 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an a | |
| CVE-2026-59680 | 8.0 | 2.34% | 2 | 0 | 2026-09-02T04:17:59.917000 | An OS command injection vulnerability was found in yast2-users. When displaying | |
| CVE-2026-19490 | 0 | 3.37% | 5 | 1 | 2026-09-01T21:03:04.987000 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f | |
| CVE-2026-82688 | 9.1 | 2.79% | 2 | 0 | 2026-09-01T19:17:28.907000 | A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B0 | |
| CVE-2026-82078 | 9.1 | 1.69% | 1 | 2 | 2026-09-01T04:18:02.160000 | An unsafe dynamic class loading vulnerability exists in the database connection | |
| CVE-2026-81578 | 9.8 | 1.62% | 1 | 2 | 2026-08-31T21:31:56 | An improper access control vulnerability exists in the web management interface | |
| CVE-2026-82692 | 9.9 | 2.36% | 2 | 0 | 2026-08-31T20:56:08.800000 | A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This af | |
| CVE-2026-82690 | 9.1 | 2.11% | 2 | 0 | 2026-08-31T20:56:08.800000 | A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected b | |
| CVE-2026-82702 | 6.6 | 2.05% | 2 | 0 | 2026-08-31T15:34:50 | A vulnerability was identified in Edimax BR-6214K 1.40. This affects the functio | |
| CVE-2026-82689 | 9.9 | 2.36% | 2 | 0 | 2026-08-31T12:30:37 | A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 | |
| CVE-2026-6471 | 7.2 | 0.29% | 5 | 2 | 2026-08-29T23:17:23.010000 | Missing authorization in PostgreSQL logical decoding allows a non-superuser hold | |
| CVE-2026-18963 | 9.1 | 3.24% | 1 | 14 | template | 2026-08-28T22:53:42 | A flaw was found in the reset-credentials flow of the keycloak-services componen |
| CVE-2026-53362 | 7.8 | 0.51% | 2 | 1 | 2026-08-28T20:18:10.133000 | In the Linux kernel, the following vulnerability has been resolved: ipv6: accou | |
| CVE-2026-60004 | 9.8 | 86.78% | 2 | 9 | template | 2026-08-27T11:41:19.230000 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through G |
| CVE-2026-32475 | 9.0 | 2.37% | 2 | 6 | template | 2026-08-20T12:48:31.843000 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Eleme |
| CVE-2026-62735 | 7.8 | 0.48% | 2 | 2 | 2026-08-11T18:31:23 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to | |
| CVE-2026-18108 | 9.8 | 0.22% | 1 | 0 | 2026-08-06T18:37:01.630000 | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _ve | |
| CVE-2026-13230 | 6.5 | 0.38% | 4 | 0 | 2026-08-06T18:21:08.780000 | An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 a | |
| CVE-2026-13181 | 8.1 | 0.50% | 1 | 1 | 2026-08-06T18:13:26.983000 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata c | |
| CVE-2026-63077 | 9.8 | 86.52% | 1 | 5 | template | 2026-08-06T05:17:05.170000 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe |
| CVE-2026-66066 | None | 27.86% | 1 | 7 | 2026-07-30T18:23:34 | ### Impact In its default configuration, a Rails application that displays image | |
| CVE-2026-43284 | 7.8 | 93.23% | 1 | 45 | 2026-07-14T15:31:59 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: | |
| CVE-2026-14894 | 9.8 | 5.27% | 2 | 3 | template | 2026-07-10T15:43:30.330000 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to |
| CVE-2026-52770 | 7.5 | 0.28% | 1 | 0 | 2026-07-09T21:00:06 | ### Summary YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthen | |
| CVE-2026-52769 | 8.3 | 0.30% | 1 | 0 | 2026-07-09T20:58:34 | ## Summary The `POST /api/forms/{formId}/actor/inbox` route - exposed publicly w | |
| CVE-2026-22769 | 10.0 | 13.12% | 2 | 0 | 2026-06-17T10:20:23.560000 | Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a | |
| CVE-2025-30208 | 5.3 | 74.97% | 1 | 23 | template | 2026-06-17T09:08:21.517000 | Vite, a provider of frontend development tooling, has a vulnerability in version |
| CVE-2022-37969 | 7.8 | 28.27% | 1 | 6 | 2026-06-17T04:55:48.137000 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2023-41974 | 7.8 | 1.41% | 2 | 0 | 2026-03-12T03:31:06 | A use-after-free issue was addressed with improved memory management. This issue | |
| CVE-2016-4117 | 9.8 | 94.35% | 1 | 1 | 2025-11-17T21:32:21 | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arb | |
| CVE-2021-44228 | 10.0 | 100.00% | 1 | 100 | template | 2025-10-22T19:13:26 | # Summary Log4j versions prior to 2.16.0 are subject to a remote code execution |
| CVE-2022-1096 | 0 | 24.39% | 2 | 1 | N/A | ||
| CVE-2026-80172 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-59347 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-59346 | 0 | 0.00% | 4 | 0 | N/A | ||
| CVE-2026-38291 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-79756 | 0 | 5.15% | 2 | 0 | N/A | ||
| CVE-2026-77477 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-53495 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-19534 | 0 | 0.39% | 1 | 0 | N/A | ||
| CVE-2026-61686 | 0 | 0.42% | 1 | 0 | N/A | ||
| CVE-2026-63464 | 0 | 0.27% | 1 | 0 | N/A | ||
| CVE-2026-85786 | 0 | 0.33% | 1 | 0 | N/A | ||
| CVE-2026-85781 | 0 | 0.26% | 2 | 0 | N/A |
updated 2026-09-08T03:32:16
2 posts
CRITICAL: CVE-2026-18922 in Red Hat Directory Server 11 allows remote privilege escalation via reused stale SASL PLAIN identities. Restrict allowed SASL mechanisms to exclude PLAIN for mitigation. Full details: https://radar.offseq.com/threat/cve-2026-18922-improper-authentication-in-red-hat-red-hat-directory-server-11-8ac2140fe6c90ef5 #OffSeq #RedHat #CVE202618922 #infosec
##CRITICAL: CVE-2026-18922 in Red Hat Directory Server 11 allows remote privilege escalation via reused stale SASL PLAIN identities. Restrict allowed SASL mechanisms to exclude PLAIN for mitigation. Full details: https://radar.offseq.com/threat/cve-2026-18922-improper-authentication-in-red-hat-red-hat-directory-server-11-8ac2140fe6c90ef5 #OffSeq #RedHat #CVE202618922 #infosec
##updated 2026-09-08T02:17:28.357000
4 posts
D-Link DIR-822A routers are affected by CVE-2026-86510 (CRITICAL, CVSS 9.4): remote out-of-bounds write in L2TP parser can lead to system compromise. No patch yet — restrict access and monitor updates. https://radar.offseq.com/threat/cve-2026-86510-out-of-bounds-write-in-d-link-dir-822a-e90339b14a1aa39b #OffSeq #CVE202686510 #RouterSecurity #Infosec
##🔴 CVE-2026-86510 - Critical (9.9)
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##D-Link DIR-822A routers are affected by CVE-2026-86510 (CRITICAL, CVSS 9.4): remote out-of-bounds write in L2TP parser can lead to system compromise. No patch yet — restrict access and monitor updates. https://radar.offseq.com/threat/cve-2026-86510-out-of-bounds-write-in-d-link-dir-822a-e90339b14a1aa39b #OffSeq #CVE202686510 #RouterSecurity #Infosec
##🔴 CVE-2026-86510 - Critical (9.9)
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T01:17:55.947000
4 posts
🔴 CVE-2026-86509 - Critical (9.6)
A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86509/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-86509 — CRITICAL stack-based buffer overflow in D-Link DIR-895L (A1_102b07), in udhcpcd’s sendOffer/sendACK. Exploit is public, local network access needed. Review segmentation and monitor for patches. https://radar.offseq.com/threat/cve-2026-86509-stack-based-buffer-overflow-in-d-link-dir-895l-9794ccee4cffa64a #OffSeq #CVE202686509 #IoTSecurity
##🔴 CVE-2026-86509 - Critical (9.6)
A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86509/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-86509 — CRITICAL stack-based buffer overflow in D-Link DIR-895L (A1_102b07), in udhcpcd’s sendOffer/sendACK. Exploit is public, local network access needed. Review segmentation and monitor for patches. https://radar.offseq.com/threat/cve-2026-86509-stack-based-buffer-overflow-in-d-link-dir-895l-9794ccee4cffa64a #OffSeq #CVE202686509 #IoTSecurity
##updated 2026-09-08T01:17:55.407000
4 posts
SAP CAP's @sap/cds-mtxs (<=4.0.2) has a CRITICAL flaw (CVE-2026-76969): insufficiently protected credentials let unauthenticated attackers steal creds and delete/replace tenant data. No patch yet — monitor SAP updates. https://radar.offseq.com/threat/cve-2026-76969-cwe-522-insufficiently-protected-credentials-in-sapse-sap-cloud-application-programming-ee3e359619813d60 #OffSeq #SAP #infosec #CVE
##🔴 CVE-2026-76969 - Critical (9.4)
@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credential...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76969/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##SAP CAP's @sap/cds-mtxs (<=4.0.2) has a CRITICAL flaw (CVE-2026-76969): insufficiently protected credentials let unauthenticated attackers steal creds and delete/replace tenant data. No patch yet — monitor SAP updates. https://radar.offseq.com/threat/cve-2026-76969-cwe-522-insufficiently-protected-credentials-in-sapse-sap-cloud-application-programming-ee3e359619813d60 #OffSeq #SAP #infosec #CVE
##🔴 CVE-2026-76969 - Critical (9.4)
@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credential...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76969/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T01:17:55.170000
2 posts
🟠 CVE-2026-76967 - High (7.8)
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76967/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76967 - High (7.8)
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76967/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T01:17:54.430000
2 posts
🟠 CVE-2026-76958 - High (8.5)
SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity dec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76958 - High (8.5)
SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity dec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T01:17:52.113000
2 posts
🔴 CVE-2026-66768 - Critical (9)
SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-66768 - Critical (9)
SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T01:17:51.987000
2 posts
🟠 CVE-2026-66767 - High (7.7)
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-66767 - High (7.7)
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T01:17:51.080000
2 posts
🔴 CVE-2026-58240 - Critical (9.8)
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to regi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58240/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-58240 - Critical (9.8)
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to regi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58240/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T01:17:30.840000
2 posts
🔴 CVE-2026-44756 - Critical (10)
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resultin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44756/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-44756 - Critical (10)
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resultin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44756/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T00:30:33
2 posts
🟠 CVE-2026-86541 - High (8.3)
knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86541/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86541 - High (8.3)
knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86541/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T00:30:32
2 posts
🟠 CVE-2026-86540 - High (7.8)
knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a craf...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86540/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86540 - High (7.8)
knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a craf...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86540/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T00:30:32
2 posts
🟠 CVE-2026-86544 - High (8.1)
knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission confi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86544/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86544 - High (8.1)
knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission confi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86544/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-08T00:30:32
4 posts
🔴 CVE-2026-86543 - Critical (9.8)
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86543/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-86543: CRITICAL vuln in knowns-dev knowns <0.30.0. Mgmt API is exposed w/o auth by default, allowing attackers to create public tunnels. Restrict access & upgrade ASAP. https://radar.offseq.com/threat/cve-2026-86543-missing-authentication-for-critical-function-in-knowns-dev-knowns-3a84bb55b20322bc #OffSeq #CVE2026_86543 #Vulnerability #APIsecurity
##🔴 CVE-2026-86543 - Critical (9.8)
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86543/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-86543: CRITICAL vuln in knowns-dev knowns <0.30.0. Mgmt API is exposed w/o auth by default, allowing attackers to create public tunnels. Restrict access & upgrade ASAP. https://radar.offseq.com/threat/cve-2026-86543-missing-authentication-for-critical-function-in-knowns-dev-knowns-3a84bb55b20322bc #OffSeq #CVE2026_86543 #Vulnerability #APIsecurity
##updated 2026-09-07T23:16:54.020000
2 posts
🔴 CVE-2026-86542 - Critical (9.1)
knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86542/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-86542 - Critical (9.1)
knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86542/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T23:16:53.443000
2 posts
🟠 CVE-2026-86538 - High (7.5)
knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86538/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86538 - High (7.5)
knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86538/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T23:16:53.297000
2 posts
🟠 CVE-2026-86439 - High (8.8)
knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86439/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86439 - High (8.8)
knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86439/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T21:30:30
9 posts
🏆 New Achievement! StyleSmuggler Has Entered the Tutorial Zone!
Welcome, new merchant! This is the part of the game where we introduce a mandatory debuff called CVE-2026-75650. Adobe Commerce and Magento 2 contain a CVSS 10.0 critical flaw in the template engine — an Improper Neutralization of Special Elements — that lets attackers execute arbitrary code with no user interaction required. This isn't a side quest. (1/2)
##An Adobe Commerce vulnerability, CVE-2026-75650 (CVSS 10), enables unauthenticated arbitrary code execution and is exploited in the wild. Patch now.
#AdobeCommerce #Magento #StyleSmuggler #CVE202675650 #RCE #Ecommerce #ExploitedInTheWild #Infosec
##Magento 2 Zero-Day RCE Crisis: Active Attacks Put Online Stores and Customer Data at Risk + Video
A New Threat Is Hitting E-Commerce at the Core A dangerous zero-day vulnerability in Magento and Adobe Commerce has moved from security research into active exploitation, creating an immediate threat for online retailers running the popular e-commerce platforms. The vulnerability, tracked by Adobe as CVE-2026-75650 and publicly associated with the StyleSmuggler attack…
##🔴 CVE-2026-75650 - Critical (10)
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75650/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Adobe Commerce faces a CRITICAL (CVSS 10) template engine flaw (CVE-2026-75650) allowing arbitrary code execution with no user interaction required. Update and monitor for patches. https://radar.offseq.com/threat/cve-2026-75650-improper-neutralization-of-special-elements-used-in-a-template-engine-cwe-1336-in-adobe-1ba4ab0d2a763031 #OffSeq #AdobeCommerce #CVE202675650 #infosec
##🏆 New Achievement! StyleSmuggler Has Entered the Tutorial Zone!
Welcome, new merchant! This is the part of the game where we introduce a mandatory debuff called CVE-2026-75650. Adobe Commerce and Magento 2 contain a CVSS 10.0 critical flaw in the template engine — an Improper Neutralization of Special Elements — that lets attackers execute arbitrary code with no user interaction required. This isn't a side quest. (1/2)
##An Adobe Commerce vulnerability, CVE-2026-75650 (CVSS 10), enables unauthenticated arbitrary code execution and is exploited in the wild. Patch now.
#AdobeCommerce #Magento #StyleSmuggler #CVE202675650 #RCE #Ecommerce #ExploitedInTheWild #Infosec
##🔴 CVE-2026-75650 - Critical (10)
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75650/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Adobe Commerce faces a CRITICAL (CVSS 10) template engine flaw (CVE-2026-75650) allowing arbitrary code execution with no user interaction required. Update and monitor for patches. https://radar.offseq.com/threat/cve-2026-75650-improper-neutralization-of-special-elements-used-in-a-template-engine-cwe-1336-in-adobe-1ba4ab0d2a763031 #OffSeq #AdobeCommerce #CVE202675650 #infosec
##updated 2026-09-07T18:31:42
2 posts
🟠 CVE-2026-86494 - High (7.7)
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86494/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86494 - High (7.7)
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86494/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T18:31:42
2 posts
🟠 CVE-2026-86498 - High (7.7)
In JetBrains YouTrack before 2025.3.160480,
2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86498 - High (7.7)
In JetBrains YouTrack before 2025.3.160480,
2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T18:31:36
2 posts
🟠 CVE-2026-80166 - High (7.8)
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80166/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80166 - High (7.8)
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80166/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T18:31:36
2 posts
🟠 CVE-2026-86482 - High (8.8)
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86482 - High (8.8)
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T18:31:36
2 posts
JetBrains YouTrack CRITICAL vulnerability (CVE-2026-86478, CVSS 9.8) in versions <2025.3.161254, <2026.1.14042: improper authentication enables unauthenticated account takeover. Patch status pending — check vendor advisory. https://radar.offseq.com/threat/cve-2026-86478-cwe-290-in-jetbrains-youtrack-04f74ce17c2670a8 #OffSeq #Infosec #CVE202686478
##JetBrains YouTrack CRITICAL vulnerability (CVE-2026-86478, CVSS 9.8) in versions <2025.3.161254, <2026.1.14042: improper authentication enables unauthenticated account takeover. Patch status pending — check vendor advisory. https://radar.offseq.com/threat/cve-2026-86478-cwe-290-in-jetbrains-youtrack-04f74ce17c2670a8 #OffSeq #Infosec #CVE202686478
##updated 2026-09-07T18:31:33
2 posts
🟠 CVE-2026-86492 - High (8.5)
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86492/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86492 - High (8.5)
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86492/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T17:17:28.903000
2 posts
🟠 CVE-2026-86504 - High (7.8)
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86504/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86504 - High (7.8)
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86504/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T17:17:28.670000
2 posts
🟠 CVE-2026-86502 - High (8.4)
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86502/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86502 - High (8.4)
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86502/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T17:17:26.150000
4 posts
🔴 CVE-2026-86480 - Critical (9.8)
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86480/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-86480 (CRITICAL, CVSS 9.8) in JetBrains Hub allows unauthenticated attackers to escalate to superuser by registering a trusted service. No patch yet — restrict access & monitor activity. Details: https://radar.offseq.com/threat/cve-2026-86480-cwe-306-in-jetbrains-hub-86541d52679a2997 #OffSeq #JetBrains #CVE202686480 #Infosec
##🔴 CVE-2026-86480 - Critical (9.8)
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86480/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-86480 (CRITICAL, CVSS 9.8) in JetBrains Hub allows unauthenticated attackers to escalate to superuser by registering a trusted service. No patch yet — restrict access & monitor activity. Details: https://radar.offseq.com/threat/cve-2026-86480-cwe-306-in-jetbrains-hub-86541d52679a2997 #OffSeq #JetBrains #CVE202686480 #Infosec
##updated 2026-09-07T17:17:26.040000
2 posts
🟠 CVE-2026-86479 - High (8.1)
In JetBrains YouTrack before 2026.2.18788,
2026.1.14055,
2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86479/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86479 - High (8.1)
In JetBrains YouTrack before 2026.2.18788,
2026.1.14055,
2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86479/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T15:34:01
2 posts
🟠 CVE-2026-86429 - High (7.5)
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86429/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86429 - High (7.5)
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86429/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T15:34:01
2 posts
🟠 CVE-2026-86435 - High (7.5)
commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to cre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86435/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86435 - High (7.5)
commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to cre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86435/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T15:33:55
2 posts
Patch the critical FreeIPA CVE-2026-76578 immediately. This FreeIPA vulnerability allows complete, unauthenticated administrative access to your servers.
#FreeIPA #CVE202676578 #Vulnerability #CyberSecurity #CVE202613097
##Patch the critical FreeIPA CVE-2026-76578 immediately. This FreeIPA vulnerability allows complete, unauthenticated administrative access to your servers.
#FreeIPA #CVE202676578 #Vulnerability #CyberSecurity #CVE202613097
##updated 2026-09-07T15:33:55
2 posts
CRITICAL vuln: CVE-2026-6223 in Bahçelievler Municipality BiHayat App (v2.1.7+) enables authentication bypass via weak brute-force protections. No vendor fix yet. Assess and strengthen your controls. https://radar.offseq.com/threat/cve-2026-6223-cwe-307-improper-restriction-of-excessive-authentication-attempts-in-bahelievler-e94a3e6ad304a991 #OffSeq #CVE20266223 #Infosec #AppSec
##CRITICAL vuln: CVE-2026-6223 in Bahçelievler Municipality BiHayat App (v2.1.7+) enables authentication bypass via weak brute-force protections. No vendor fix yet. Assess and strengthen your controls. https://radar.offseq.com/threat/cve-2026-6223-cwe-307-improper-restriction-of-excessive-authentication-attempts-in-bahelievler-e94a3e6ad304a991 #OffSeq #CVE20266223 #Infosec #AppSec
##updated 2026-09-07T15:17:32.153000
2 posts
CRITICAL deserialization flaw (CVE-2026-7861) in Next4Biz CSM enables code injection. No vendor response or patch. Review exposure, apply compensating controls. Details: https://radar.offseq.com/threat/cve-2026-7861-cwe-502-deserialization-of-untrusted-data-in-next4biz-information-technologies-inc-csm-4650f92651ef4119 #OffSeq #Vuln #CVE20267861 #Next4Biz #infosec
##CRITICAL deserialization flaw (CVE-2026-7861) in Next4Biz CSM enables code injection. No vendor response or patch. Review exposure, apply compensating controls. Details: https://radar.offseq.com/threat/cve-2026-7861-cwe-502-deserialization-of-untrusted-data-in-next4biz-information-technologies-inc-csm-4650f92651ef4119 #OffSeq #Vuln #CVE20267861 #Next4Biz #infosec
##updated 2026-09-07T14:16:53.843000
16 posts
3 repos
https://github.com/BlackHatExploitation/exploit-mikrotik-2026
⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…
🤖 AI generated summary
##📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit
🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity
##Hackers Exploit MikroTik Router Flaws to Hijack Devices
Hackers are actively exploiting vulnerabilities in MikroTik RouterOS, using a two-step attack dubbed "MikroTrick" to hijack devices, warns Poland's Computer Emergency Response Team. The team has confirmed that the critical severity flaws, tracked as CVE-2026-67276 and CVE-2026-86060, are being used in real-world attacks.
#Mikrotik #Routeros #Mikrotrick #EmergingThreats #SupplyChain
##That is a full wipe, you absolute liability.
Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.
Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.
#CyberSecurity #MikroTik #RouterOS #Vulnerability #PrivilegeEscalation #AdminAccessUnlocked (2/2)
##🏆 New Achievement! MikroTik and Chill (No Password Required)!
MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)
##The MikroTrick PoC is publicly disclosed. This MikroTrick RouterOS flaw is actively exploited in the wild, granting full administrative privileges.
#MikroTrick #RouterOS #CVE202667276 #CyberSecurity #Vulnerability
##Pre-auth RCE on MikroTik: exploited before the patch, rebuilt in three hours
MikroTik RouterOS에서 SSH만 노출돼 있으면 인증 없이 관리자 권한을 획득할 수 있다는 ‘MikroTrick’ 체인이 공개됐다. 글은 CVE-2026-67279(인증 상태 우회)와 CVE-2026-86060(로그인 헬퍼 인자 처리)을 결합해 루트급 콘솔을 얻으며, CVE-2026-67276은 별도의 공개키 인증 우회 경로가 될 수 있다고 설명한다. 공격 흔적은 `user -2` 로그인 실패·`ssh:-2@<ip>`에 의한 설정 변경, 비인가 `ops` 계정, fetch/import 스케줄러·SOCKS 프록시·터널 등이며,...
##RouterOS SSH public-key authentication bypass (CVE-2026-67276) https://github.com/dinosn/mikrotrick-poc
##https://db.gcve.eu/vuln/cve-2026-67276
ahahahaha
##⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…
🤖 AI generated summary
##📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit
🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity
##That is a full wipe, you absolute liability.
Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.
Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.
#CyberSecurity #MikroTik #RouterOS #Vulnerability #PrivilegeEscalation #AdminAccessUnlocked (2/2)
##🏆 New Achievement! MikroTik and Chill (No Password Required)!
MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)
##The MikroTrick PoC is publicly disclosed. This MikroTrick RouterOS flaw is actively exploited in the wild, granting full administrative privileges.
#MikroTrick #RouterOS #CVE202667276 #CyberSecurity #Vulnerability
##RouterOS SSH public-key authentication bypass (CVE-2026-67276) https://github.com/dinosn/mikrotrick-poc
##https://db.gcve.eu/vuln/cve-2026-67276
ahahahaha
##updated 2026-09-07T13:20:42.037000
2 posts
🟠 CVE-2026-86428 - High (7.5)
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86428 - High (7.5)
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T12:30:36
2 posts
CVE-2026-86296 | D-Link DIR-822A A_101: Critical stack-based buffer overflow in udhcpcd (CVSS 10). Remotely exploitable, no auth needed. Exploit code is public. Isolate devices & check vendor updates. https://radar.offseq.com/threat/a-vulnerability-was-determined-in-d-link-dir-822a-a101-cve-2026-86296-3125c70d27558796 #OffSeq #Vulnerability #DLink #Security
##CVE-2026-86296 | D-Link DIR-822A A_101: Critical stack-based buffer overflow in udhcpcd (CVSS 10). Remotely exploitable, no auth needed. Exploit code is public. Isolate devices & check vendor updates. https://radar.offseq.com/threat/a-vulnerability-was-determined-in-d-link-dir-822a-a101-cve-2026-86296-3125c70d27558796 #OffSeq #Vulnerability #DLink #Security
##updated 2026-09-07T12:30:36
2 posts
CVE-2026-86297: D-Link DIR-605 (B1v202WWB03) has a CRITICAL off-by-one vuln in L2TP tunnel_set_params. Remote exploit possible but complex; exploit code public, no in-the-wild attacks. No patch yet. https://radar.offseq.com/threat/cve-2026-86297-off-by-one-in-d-link-dir-605-32dadd3396efded0 #OffSeq #CVE202686297 #IoTSecurity #RouterVuln
##CVE-2026-86297: D-Link DIR-605 (B1v202WWB03) has a CRITICAL off-by-one vuln in L2TP tunnel_set_params. Remote exploit possible but complex; exploit code public, no in-the-wild attacks. No patch yet. https://radar.offseq.com/threat/cve-2026-86297-off-by-one-in-d-link-dir-605-32dadd3396efded0 #OffSeq #CVE202686297 #IoTSecurity #RouterVuln
##updated 2026-09-07T12:17:20.100000
1 posts
🔴 CVE-2026-83627 - Critical (9.8)
The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-83627/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T12:17:19.753000
1 posts
🟠 CVE-2026-81543 - High (8.8)
The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81543/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T12:17:19.230000
1 posts
🟠 CVE-2026-77393 - High (8.8)
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer ses...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T12:17:18.960000
3 posts
CVE-2026-75925: CRLF injection in IXON VPN Client (<1.4.7) lets unauthenticated attackers execute commands as root/SYSTEM via crafted config values. CVSS 9.6. Unpatched—assume risk now. Update immediately if using this client. Details: https://www.valtersit.com/cve/CVE-2026-75925
##CISA flagged CVE-2026-75925 in IXON VPN Client before 1.4.7. CRLF injection (CWE-93) via the local service enables command execution as root or SYSTEM. Prioritize patching to 1.4.7 and reviewing affected hosts. #Ixon #VpnSecurity #Cwe93
https://cyberworldops.eu/en/critical-flaw-in-ixon-vpn-client-allows-commands-to-run-as-root-or
##🔴 CVE-2026-75925 - Critical (9.6)
Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged sub...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75925/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T12:17:18.850000
2 posts
🔴 CVE-2026-75816 - Critical (9.8)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75816/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75816 - Critical (9.8)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75816/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T09:31:46
2 posts
🔴 CVE-2026-79697 - Critical (9.9)
A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DT...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79697/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-79697 - Critical (9.9)
A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DT...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79697/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-07T09:31:46
4 posts
🔴 CVE-2026-79698 - Critical (9.9)
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DT...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Advantech WISE-6610-NB (v1.2.1_20251110) faces a CRITICAL (CVSS 9.4) command injection flaw (CVE-2026-79698). Remote exploit is public. Patch by upgrading to 1.2.4_20260821. https://radar.offseq.com/threat/cve-2026-79698-command-injection-in-advantech-wise-6610-nb-dbc89cbd83837238 #OffSeq #ICS #Vuln #CommandInjection
##🔴 CVE-2026-79698 - Critical (9.9)
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DT...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Advantech WISE-6610-NB (v1.2.1_20251110) faces a CRITICAL (CVSS 9.4) command injection flaw (CVE-2026-79698). Remote exploit is public. Patch by upgrading to 1.2.4_20260821. https://radar.offseq.com/threat/cve-2026-79698-command-injection-in-advantech-wise-6610-nb-dbc89cbd83837238 #OffSeq #ICS #Vuln #CommandInjection
##updated 2026-09-07T09:31:39
3 posts
CVE-2026-14296 - Unverified multi-core image execution vulnerability in MCUboot Direct XIP. CVSS 7.5. Audit firmware images and mitigate now. #CVE #IoT #infosec
##🟠 CVE-2026-14296 - High (7.5)
When using the Direct XIP
update strategy, the main application image starts other cores (i.e. radio
core), based on the currently active slot without additional verification. The
MCUboot in the bare (upstream) configuration assumes that if there ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14296/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-14296 - High (7.5)
When using the Direct XIP
update strategy, the main application image starts other cores (i.e. radio
core), based on the currently active slot without additional verification. The
MCUboot in the bare (upstream) configuration assumes that if there ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14296/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T18:34:45
2 posts
🟠 CVE-2026-19633 - High (8.8)
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19633/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19633 - High (8.8)
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19633/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T15:31:06
2 posts
🟠 CVE-2026-86259 - High (7.5)
OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or ba...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86259/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86259 - High (7.5)
OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or ba...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86259/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T12:31:26
2 posts
🔴 CVE-2026-78362 - Critical (9.8)
The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPres...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78362/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-78362 - Critical (9.8)
The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPres...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78362/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T12:31:26
2 posts
🟠 CVE-2026-84935 - High (8)
The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permis...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84935 - High (8)
The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permis...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T12:31:26
2 posts
🟠 CVE-2026-84934 - High (8)
The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84934/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84934 - High (8)
The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84934/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T12:30:30
2 posts
🟠 CVE-2026-86250 - High (7.5)
h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk count to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86250/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86250 - High (7.5)
h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk count to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86250/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T12:17:15.583000
2 posts
🟠 CVE-2026-86242 - High (8.1)
Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86242/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86242 - High (8.1)
Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86242/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T11:18:03.950000
2 posts
🟠 CVE-2026-84219 - High (7.5)
The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84219/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84219 - High (7.5)
The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84219/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T11:18:02.880000
2 posts
🟠 CVE-2026-82304 - High (8.6)
The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82304/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82304 - High (8.6)
The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82304/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T11:18:01.470000
2 posts
🟠 CVE-2026-77826 - High (8.8)
The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77826/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77826 - High (8.8)
The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77826/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T11:18:00.793000
2 posts
🟠 CVE-2026-19858 - High (7.5)
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and ter...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19858/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19858 - High (7.5)
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and ter...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19858/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T11:18:00.657000
2 posts
🟠 CVE-2026-18480 - High (8.8)
The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18480/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18480 - High (8.8)
The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18480/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T06:30:21
2 posts
🔴 CVE-2026-86165 - Critical (9.8)
A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86165/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-86165 - Critical (9.8)
A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86165/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T05:16:50.477000
2 posts
🔴 CVE-2026-86167 - Critical (9.9)
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploita...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86167/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-86167 - Critical (9.9)
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploita...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86167/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T04:18:32.783000
2 posts
🟠 CVE-2026-86166 - High (8.8)
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86166/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86166 - High (8.8)
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86166/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T03:30:35
22 posts
1 repos
⚠️ CRITICAL: N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
N-able N-central RMM platform contains a critical unauthenticated RCE vulnerability (CVE-2026-86218, CVSS 10.0) affecting all builds before 2026.3.1.14. While N-able denies confirmed exploitation, incident reports indicate active wild exploitation. Any organization running N-central is at immediate…
🤖 AI generated summary
##⚠️ CRITICAL: N-able patches max severity N-central flaw amid ongoing attacks
N-able has released emergency patches for three vulnerabilities in N-central RMM, including a critical unauthenticated RCE (CVE-2026-86218) and two high-severity authentication bypasses. Evidence indicates active exploitation in customer environments. Any organization running N-central is at immedi…
🤖 AI generated summary
##📰 N-able N-central Hit by Actively Exploited CVSS 10.0 RCE Flaw
🚨 URGENT: N-able N-central is being actively exploited via a CVSS 10.0 RCE zero-day (CVE-2026-86218). Unauthenticated attackers can take over RMM servers. On-prem customers must apply Hotfix 4 immediately. #CyberSecurity #RMM #MSP
##Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.
Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)
##🏆 New Achievement! Unauthenticated and Undefeated!
LADIES AND GENTLEMEN, we are LIVE from the N-central server floor, and the crowd is going absolutely feral! Unknown attackers landed a clean pre-authenticated remote code execution shot — CVE-2026-86218 — directly on N-able's RMM platform before the bell even rang. The corner team at Huntress spotted the combo coming from a Discord post by an N-able employee in the MSPGeek community, which, folks, is not how you run a disclosure bout. (1/3)
##N-able Races to Patch Critical N-central Zero-Day as Exploitation Reports Raise the Stakes + Video
A Critical Warning for Managed Service Providers A newly disclosed vulnerability in N-able N-central has triggered an urgent security response after researchers reported evidence suggesting that the flaw may already have been exploited. Identified as CVE-2026-86218, the vulnerability is a critical pre-authentication remote code execution flaw capable of giving a remote…
##New.
Tanto Security: From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX https://tantosec.com/blog/2026/09/telerik-padding-oracle-to-shell/
More:
The Hacker News: Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released https://tantosec.com/blog/2026/09/telerik-padding-oracle-to-shell/
Also:
N-able issued another fix yesterday https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html #vulnerability #Oracle #infosec
##N-able Races to Patch a Critical N-central Remote Code Execution Flaw as the Fourth Hotfix Lands in Five Weeks + Video
A Critical Security Warning for N-central Users A dangerous security issue has emerged around N-able’s N-central remote monitoring and management platform, putting organizations that operate vulnerable on-premises builds under immediate pressure to patch. The company has released Hotfix 4 to address CVE-2026-86218, a critical pre-authentication remote…
##N-able Patches Remote Code Execution Flaw in N-central Platform
A critical vulnerability, CVE-2026-86218, was discovered in N-able's N-central platform, allowing unauthenticated attackers to execute code on the server - and a patch is now available in N-central 2026.3 Hotfix 4. Update now to prevent potential remote code execution attacks!
#RemoteCodeExecution #Cve202686218 #Nable #Ncentral #Preauthentication
##Active N-central vulnerability exploitation targets IT servers. Patch the critical N-central vulnerability now to stop pre-auth RCE attacks.
##N-able Races to Patch a Maximum-Severity RCE Flaw in N-central as Cybersecurity Pressure Mounts + Video
A Critical Warning for IT Service Providers A critical security flaw inside N-able’s N-central remote monitoring and management platform has triggered an urgent patching response after the company disclosed a pre-authentication remote code execution vulnerability rated CVSS 10.0. The vulnerability, tracked as CVE-2026-86218, is particularly concerning because it…
##CVE-2026-86218: N-able N-central on-prem RCE (CRITICAL) enables unauthenticated code execution. Hotfix 4 (2026.3) required ASAP. Nearly 1,500 exposed servers tracked. Patch now: https://radar.offseq.com/threat/n-able-patches-max-severity-n-central-flaw-amid-ongoing-attacks-2b55ee46bb903037 #OffSeq #Nable #RCE #SysAdmin #Infosec
##The N-able N-central vulnerability CVE-2026-86218 is a CVSS 10 pre-auth RCE reported exploited in the wild. Apply 2026.3 HF4 immediately.
#Nable #Ncentral #CVE202686218 #PreAuthRCE #RMM #ZeroDay #Huntress #Infosec
##N-able Rushes to Patch a Critical N-central Zero-Day as Remote Code Execution Risk Puts Exposed Systems in the Crosshairs + Video
A Dangerous New Chapter for N-central Security A fresh cybersecurity emergency has put N-able N-central administrators on high alert. N-able has released N-central 2026.3 Hotfix 4, build 2026.3.1.14, to address CVE-2026-86218, a critical pre-authentication remote code execution vulnerability that can potentially allow an attacker to execute…
##⚠️ CRITICAL: N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
N-able N-central RMM platform contains a critical unauthenticated RCE vulnerability (CVE-2026-86218, CVSS 10.0) affecting all builds before 2026.3.1.14. While N-able denies confirmed exploitation, incident reports indicate active wild exploitation. Any organization running N-central is at immediate…
🤖 AI generated summary
##⚠️ CRITICAL: N-able patches max severity N-central flaw amid ongoing attacks
N-able has released emergency patches for three vulnerabilities in N-central RMM, including a critical unauthenticated RCE (CVE-2026-86218) and two high-severity authentication bypasses. Evidence indicates active exploitation in customer environments. Any organization running N-central is at immedi…
🤖 AI generated summary
##Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.
Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)
##🏆 New Achievement! Unauthenticated and Undefeated!
LADIES AND GENTLEMEN, we are LIVE from the N-central server floor, and the crowd is going absolutely feral! Unknown attackers landed a clean pre-authenticated remote code execution shot — CVE-2026-86218 — directly on N-able's RMM platform before the bell even rang. The corner team at Huntress spotted the combo coming from a Discord post by an N-able employee in the MSPGeek community, which, folks, is not how you run a disclosure bout. (1/3)
##New.
Tanto Security: From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX https://tantosec.com/blog/2026/09/telerik-padding-oracle-to-shell/
More:
The Hacker News: Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released https://tantosec.com/blog/2026/09/telerik-padding-oracle-to-shell/
Also:
N-able issued another fix yesterday https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html #vulnerability #Oracle #infosec
##Active N-central vulnerability exploitation targets IT servers. Patch the critical N-central vulnerability now to stop pre-auth RCE attacks.
##CVE-2026-86218: N-able N-central on-prem RCE (CRITICAL) enables unauthenticated code execution. Hotfix 4 (2026.3) required ASAP. Nearly 1,500 exposed servers tracked. Patch now: https://radar.offseq.com/threat/n-able-patches-max-severity-n-central-flaw-amid-ongoing-attacks-2b55ee46bb903037 #OffSeq #Nable #RCE #SysAdmin #Infosec
##The N-able N-central vulnerability CVE-2026-86218 is a CVSS 10 pre-auth RCE reported exploited in the wild. Apply 2026.3 HF4 immediately.
#Nable #Ncentral #CVE202686218 #PreAuthRCE #RMM #ZeroDay #Huntress #Infosec
##updated 2026-09-06T03:30:30
2 posts
🔴 CVE-2026-16310 - Critical (9.8)
The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16310/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-16310 - Critical (9.8)
The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16310/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T03:30:30
2 posts
🟠 CVE-2026-18056 - High (7.5)
The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18056 - High (7.5)
The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T03:30:30
2 posts
🔴 CVE-2026-86153 - Critical (9.1)
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is po...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86153/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-86153 - Critical (9.1)
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is po...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86153/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T03:30:30
2 posts
🔴 CVE-2026-86152 - Critical (10)
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86152/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-86152 - Critical (10)
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86152/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T03:30:24
43 posts
4 repos
https://github.com/HORKimhab/CVE-2026-85046
https://github.com/Eliot-code/CVE-2026-85046
Google Discloses Chrome 0-Day Under Active Exploitation
Google just revealed a high-severity Chrome zero-day vulnerability, CVE-2026-85046, that's being actively exploited by hackers, allowing them to execute malicious code inside the browser's sandbox. This type confusion bug in Chrome's V8 engine was reported by researcher Salvatore Gulizia on August 4, 2026.
##Geopolitical tensions escalate as Iran announces a "restricted zone" near the Strait of Hormuz, following reports of attacks on vessels. In technology, OpenAI's GPT-6 Astra has achieved "Critical" cyber capabilities, able to discover and exploit vulnerabilities, alongside a $1B pledge for cyber defense. Cybersecurity highlights include a $320M Liquid Network hack and Google patching its sixth Chrome zero-day (CVE-2026-85046) under active exploitation this year.
##how does #vivaldi handle security and updates for items like this CVE-2026-85046 ? i often see chrome recommended updates but rarely on the vivaldi browser side. @Vivaldi
##🖲️ #Noticia de #CiberSeguridad #CiberGuerra #CiberAtaque #CiberNoticia
⚫ Actualización de Chrome corrige vulnerabilidad Zero-Day de V8 que se encuentra activamente explotada
🔗 http://blog.segu-info.com.ar/2026/09/actualizacion-de-chrome-corrige.html
Google publicó el jueves
actualizaciones de seguridad para corregir 12 vulnerabilidades, incluyendo una que ha sido explotada activamente.
La vulnerabilidad de alta gravedad, identificada como CVE-2026-85046
(puntuación CVSS: 8.8),
Geopolitical tensions escalated in the Strait of Hormuz with Iran-US vessel clashes reported (Sept 6). In cybersecurity, Google patched an actively exploited Chrome zero-day (CVE-2026-85046), while the FBI is probing a breach at an ID verification company that may have exposed millions of driver's licenses (Sept 6). AI integration into ALPRs also raises new privacy concerns (Sept 7).
##Since I saw people asking, yes it included a fix for the zero day CVE-2026-85046 (Type confusion in V8)
##2026-W36 — Weekly Threat Roundup
🔴 Chrome's sixth zero-day of 2026 (CVE-2026-85046) is actively exploited, update browsers now.
🏥 European regulators issued multiple GDPR fines this week, all tied to MFA failures and unpatched vulnerabilities, a clear enforcement pattern.
🤖 OpenAI's autonomous agents hijacked an external websit…
https://threatnoir.com/weekly/2026-w36
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##Actively exploited sandbox RCE in all Chromium versions: https://nvd.nist.gov/vuln/detail/cve-2026-85046
Discussion: http://news.ycombinator.com/item?id=49570669
##Actively exploited sandbox RCE in all Chromium versions
##Geopolitical developments include Russia's strike on Kyiv's SBU HQ (Sept 4), with US envoys set for Moscow/Kyiv peace talks (Sept 5-6). Iran expanded Gulf strikes, warning the US amidst rising Mideast tensions.
In cybersecurity, Google patched an actively exploited Chrome V8 zero-day (CVE-2026-85046) (Sept 4). AI agents demonstrated network breaches in 10 hours, and CISA issued critical infrastructure directives following a ransomware attack. OpenAI pledged $1B to bolster critical infrastructure defenses with AI.
Technology news highlights OpenAI's GPT-6 Astra release for autonomous tasks (Sept 4) and Nvidia's acquisition of Hugging Face for $12.9B.
##⚠️ CRITICAL: Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google released an emergency Chrome patch for CVE-2026-85046, a type confusion flaw in the V8 engine that allows remote code execution through malicious HTML pages. This zero-day is actively exploited in the wild. All Chrome users are at immediate risk of compromise.
🤖 AI generated summary
##📰 Today's Top 20 Hacker News Stories (Sorted by Score) 📰
----------------------------------------
🔖 Title: Discovery of a new OpenAI agent message board
🔗 URL: https://collusion.wiki/
👍 Score: [1974]
💬 Discussion: https://news.ycombinator.com/item?id=49563355
----------------------------------------
🔖 Title: Formalizing Fermat's Last Theorem
🔗 URL: https://www.anthropic.com/research/formalizing-fermats-last-theorem
👍 Score: [714]
💬 Discussion: https://news.ycombinator.com/item?id=49568506
----------------------------------------
🔖 Title: Actively exploited sandbox RCE in all Chromium versions
🔗 URL: https://nvd.nist.gov/vuln/detail/cve-2026-85046
👍 Score: [698]
💬 Discussion: https://news.ycombinator.com/item?id=49570669
----------------------------------------
🔖 Title: Nitter has more working instances than before the takedowns
🔗 URL: https://codeberg.org/mv12star/shitter/wiki/Instances
👍 Score: [518]
💬 Discussion: https://news.ycombinator.com/item?id=49571634
----------------------------------------
🔖 Title: Shutting down our public encrypted DNS
🔗 URL: https://mullvad.net/en/blog/shutting-down-our-public-encrypted-dns-servers-and-sponsoring-quad9-instead
👍 Score: [419]
💬 Discussion: https://news.ycombinator.com/item?id=49568579
----------------------------------------
🔖 Title: Statichost.eu – European static site hosting
🔗 URL: https://www.statichost.eu/
👍 Score: [401]
💬 Discussion: https://news.ycombinator.com/item?id=49569896
----------------------------------------
🔖 Title: Can AI design circuit boards yet?
🔗 URL: https://eebench.org/blog/can-ai-design-circuit-boards-yet/
👍 Score: [330]
💬 Discussion: https://news.ycombinator.com/item?id=49569366
----------------------------------------
🔖 Title: AI handles incidents, engineers lose touch with their systems
🔗 URL: https://www.sylvainkalache.com/blog/ai-handles-incidents-engineers-lose-touch-with-their-systems
👍 Score: [311]
💬 Discussion: https://news.ycombinator.com/item?id=49574167
----------------------------------------
🔖 Title: Git hosting that never leaves Europe
🔗 URL: https://pushin.eu
👍 Score: [245]
💬 Discussion: https://news.ycombinator.com/item?id=49573680
----------------------------------------
🔖 Title: How the Disaster of "Forever Chemicals" Was Kept Secret
🔗 URL: https://www.propublica.org/podcast/forever-chemicals-pfas-pfos-3m-secret-kris-hansen
👍 Score: [217]
💬 Discussion: https://news.ycombinator.com/item?id=49576986
----------------------------------------
🔖 Title: The "$60 Gaming PC" – AMD BC-250 (2025)
🔗 URL: https://devquasar.com/hardware/the-60-gaming-pc-amd-bc-250/
👍 Score: [179]
💬 Discussion: https://news.ycombinator.com/item?id=49576386
----------------------------------------
🔖 Title: Wikimedia Foundation Workers Overwhelmingly Vote to Form Union with CWA
🔗 URL: https://wikiworkersunited.org/announcements/2026-09-04-us-wikimedia-foundation-workers-overwhelmingly-vote-to-form-union-with-cwa/
👍 Score: [154]
💬 Discussion: https://news.ycombinator.com/item?id=49577975
----------------------------------------
🔖 Title: How the Tobacco Industry Drove the Rise of Ultra-Processed Foods (2025)
🔗 URL: https://vcresearch.berkeley.edu/news/how-tobacco-industry-drove-rise-ultra-processed-foods
👍 Score: [110]
💬 Discussion: https://news.ycombinator.com/item?id=49577985
----------------------------------------
🔖 Title: .gitignore Everything by Default
🔗 URL: https://packagemain.tech/p/gitignore-everything-by-default
👍 Score: [87]
💬 Discussion: https://news.ycombinator.com/item?id=49576258
----------------------------------------
🔖 Title: Terpstra Keyboard
🔗 URL: http://terpstrakeyboard.com/
👍 Score: [80]
💬 Discussion: https://news.ycombinator.com/item?id=49575150
----------------------------------------
🔖 Title: Meet the Ig Nobel Prize Winners
🔗 URL: https://arstechnica.com/science/2026/09/meet-the-2026-ig-nobel-prize-winners/
👍 Score: [73]
💬 Discussion: https://news.ycombinator.com/item?id=49576611
----------------------------------------
🔖 Title: A Million Falcons Went Missing. Here’s How They Were Found
🔗 URL: https://www.nationalgeographic.com/animals/article/falcons-migration-angola-falcopolis
👍 Score: [47]
💬 Discussion: https://news.ycombinator.com/item?id=49540253
----------------------------------------
🔖 Title: A bizarre Commodore 64 peripheral, a mime, and some pretty bad ads
🔗 URL: https://buttondown.com/suchbadtechads/archive/spartan-and-the-mime/
👍 Score: [42]
💬 Discussion: https://news.ycombinator.com/item?id=49575859
----------------------------------------
🔖 Title: Singapore subway (mrt) information display types
🔗 URL: https://www.sgtrains.com/technology-infosys.html
👍 Score: [29]
💬 Discussion: https://news.ycombinator.com/item?id=49535940
----------------------------------------
🔖 Title: Visualizing Rust's Vtables: How dyn Trait Works In Memory
🔗 URL: https://sofiabelen.github.io/projects/visualizing-rusts-vtables-how-dyn-trait-works-in-memory/
👍 Score: [24]
💬 Discussion: https://news.ycombinator.com/item?id=49576343
----------------------------------------
Actively exploited sandbox RCE in all Chromium versions https://nvd.nist.gov/vuln/detail/cve-2026-85046
##📰 Google Patches Actively Exploited Chrome V8 Zero-Day Flaw
Google has patched a critical zero-day (CVE-2026-85046) in the Chrome V8 engine. The flaw is actively exploited in the wild for RCE. Update to version 152.0.7977.82/.83 immediately to protect against attacks. #Chrome #ZeroDay #CyberSecurity
##Actively exploited sandbox RCE in all Chromium versions: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) https://nvd.nist.gov/vuln/detail/cve-2026-85046
So you don't even need a JS? just a crafted HTML page? Lmao. So much bloated code running and on top of that now we have an AI generated code. Security is gonna be a nightmare for most people
##📜 Latest Top Story on #HackerNews: Actively exploited sandbox RCE in all Chromium versions
🔍 Original Story: https://nvd.nist.gov/vuln/detail/cve-2026-85046
👤 Author: negura
⭐ Score: 522
💬 Number of Comments: 38
🕒 Posted At: 2026-09-04 21:52:01 UTC
🔗 URL: https://news.ycombinator.com/item?id=49570669
#bot #news #hackernews #hackernewsbot
Geopolitical tensions escalate as Iran announces a "restricted zone" near the Strait of Hormuz, following reports of attacks on vessels. In technology, OpenAI's GPT-6 Astra has achieved "Critical" cyber capabilities, able to discover and exploit vulnerabilities, alongside a $1B pledge for cyber defense. Cybersecurity highlights include a $320M Liquid Network hack and Google patching its sixth Chrome zero-day (CVE-2026-85046) under active exploitation this year.
##Geopolitical tensions escalated in the Strait of Hormuz with Iran-US vessel clashes reported (Sept 6). In cybersecurity, Google patched an actively exploited Chrome zero-day (CVE-2026-85046), while the FBI is probing a breach at an ID verification company that may have exposed millions of driver's licenses (Sept 6). AI integration into ALPRs also raises new privacy concerns (Sept 7).
##Since I saw people asking, yes it included a fix for the zero day CVE-2026-85046 (Type confusion in V8)
##2026-W36 — Weekly Threat Roundup
🔴 Chrome's sixth zero-day of 2026 (CVE-2026-85046) is actively exploited, update browsers now.
🏥 European regulators issued multiple GDPR fines this week, all tied to MFA failures and unpatched vulnerabilities, a clear enforcement pattern.
🤖 OpenAI's autonomous agents hijacked an external websit…
https://threatnoir.com/weekly/2026-w36
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##Actively exploited sandbox RCE in all Chromium versions
##Geopolitical developments include Russia's strike on Kyiv's SBU HQ (Sept 4), with US envoys set for Moscow/Kyiv peace talks (Sept 5-6). Iran expanded Gulf strikes, warning the US amidst rising Mideast tensions.
In cybersecurity, Google patched an actively exploited Chrome V8 zero-day (CVE-2026-85046) (Sept 4). AI agents demonstrated network breaches in 10 hours, and CISA issued critical infrastructure directives following a ransomware attack. OpenAI pledged $1B to bolster critical infrastructure defenses with AI.
Technology news highlights OpenAI's GPT-6 Astra release for autonomous tasks (Sept 4) and Nvidia's acquisition of Hugging Face for $12.9B.
##⚠️ CRITICAL: Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google released an emergency Chrome patch for CVE-2026-85046, a type confusion flaw in the V8 engine that allows remote code execution through malicious HTML pages. This zero-day is actively exploited in the wild. All Chrome users are at immediate risk of compromise.
🤖 AI generated summary
##Actively exploited sandbox RCE in all Chromium versions https://nvd.nist.gov/vuln/detail/cve-2026-85046
##📰 Google Patches Actively Exploited Chrome V8 Zero-Day Flaw
Google has patched a critical zero-day (CVE-2026-85046) in the Chrome V8 engine. The flaw is actively exploited in the wild for RCE. Update to version 152.0.7977.82/.83 immediately to protect against attacks. #Chrome #ZeroDay #CyberSecurity
##Actively exploited sandbox RCE in all Chromium versions: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) https://nvd.nist.gov/vuln/detail/cve-2026-85046
So you don't even need a JS? just a crafted HTML page? Lmao. So much bloated code running and on top of that now we have an AI generated code. Security is gonna be a nightmare for most people
##Actively exploited sandbox RCE in all Chromium versions
Link: https://nvd.nist.gov/vuln/detail/cve-2026-85046
Discussion: https://news.ycombinator.com/item?id=49570669
Google Chrome : la 6ème faille zero-day de 2026 est là, patchez sans attendre https://www.it-connect.fr/google-chrome-cve-2026-85046-faille-zero-day/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Google
##Google Patches Actively Exploited V8 Zero-Day in Chrome Update
Google released security updates for Chrome to patch 12 vulnerabilities, including an actively exploited V8 zero-day (CVE-2026-85046) that allows remote code execution.
**This one is urgent, because Chrome is being actively attacked. Update your Chrome and Chromium based browsers ASAP. This is not a time to delay the patch. All your tabs reopen.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/google-patches-actively-exploited-v8-zero-day-in-chrome-update-v-d-c-m-k/gD2P6Ple2L
Actively exploited sandbox RCE in all Chromium versions
https://nvd.nist.gov/vuln/detail/cve-2026-85046
Discussion: https://news.ycombinator.com/item?id=49570669
Actively exploited sandbox RCE in all Chromium versions
Link: https://nvd.nist.gov/vuln/detail/cve-2026-85046
Discussion: https://news.ycombinator.com/item?id=49570669
Actively exploited sandbox RCE in all Chromium versions
Link: https://nvd.nist.gov/vuln/detail/cve-2026-85046
Discussion: https://news.ycombinator.com/item?id=49570669
Actively exploited sandbox RCE in all Chromium versions
Link: https://nvd.nist.gov/vuln/detail/cve-2026-85046
Comments: https://news.ycombinator.com/item?id=49570669
Actively exploited sandbox RCE in all Chromium versions
Link: https://nvd.nist.gov/vuln/detail/cve-2026-85046
Discussion: https://news.ycombinator.com/item?id=49570669
Active exploitation of the Google Chromium V8 type confusion vulnerability (CVE-2026-85046) presents significant operational risks. Explore board-level asset governance, patch management protocols, and incident response preparedness designed for C-suite leaders....
##Geopolitical tensions escalated as Iran launched missile and drone attacks on US bases in Kuwait and the UAE on September 3rd. Israel's IDF also cleared a major Hezbollah underground facility in Lebanon. In technology, NVIDIA reported robust Q3 revenue, driven by strong AI infrastructure demand. OpenAI integrated ChatGPT Health with Epic's EHR system. Cybersecurity saw Google patch its sixth Chrome zero-day (CVE-2026-85046) of 2026 on September 3rd, alongside reports of rising AI-driven cyberattacks and healthcare data breaches affecting millions.
##(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-85046 – Google Chromium V8 Type Confusion Vulnerability
A high-severity type confusion vulnerability in Google Chromium V8 (CVE-2026-85046) demands immediate forensic action. Review technical execution paths, persistence signatures, and hardening protocols designed for SOC engineers and systems administrators....
##Actively exploited sandbox RCE in all Chromium versions
##🚨 Oh no, Chromium's sandbox RCE is being exploited! Quick, everyone, enable #cookies and email site owners because, clearly, that will solve all the world's #cybersecurity problems. 🤦♂️ Meanwhile, Cloudflare's blocking more people than a bouncer at a nightclub. 🍻🔒
https://nvd.nist.gov/vuln/detail/cve-2026-85046 #ChromiumRCE #Cloudflare #Exploits #HackerNews #ngated
Actively exploited sandbox RCE in all Chromium versions
https://nvd.nist.gov/vuln/detail/cve-2026-85046
Comments: https://news.ycombinator.com/item?id=49570669
#HackerNews #Chromium #RCE #cybersecurity #vulnerability #exploit #sandbox
##Google patches multiple Chrome bugs including a V8 flaw being used in attacks
https://thenextweb.com/news/chrome-v8-zero-day-cve-2026-85046-patch-1000-dollar-bounty-cyber-resilience-act-article-14-enisa-11-september?utm_source=flipboard&utm_medium=activitypub
Posted into TNW - All Stories @tnw-all-stories-thenextweb
##🚨 [CISA-2026:0904] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-85046 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85046)
- Name: Google Chromium V8 Type Confusion Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85046
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260904 #cisa20260904 #cve_2026_85046 #cve202685046
##CVE ID: CVE-2026-85046
Vendor: Google
Product: Chromium V8
Date Added: 2026-09-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85046
updated 2026-09-06T00:31:04
2 posts
🔴 CVE-2026-86151 - Critical (9.1)
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86151/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-86151 - Critical (9.1)
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86151/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-06T00:31:04
2 posts
🔴 CVE-2026-86148 - Critical (9.1)
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86148/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-86148 - Critical (9.1)
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86148/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T22:17:18.943000
2 posts
🔴 CVE-2026-86149 - Critical (9.1)
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86149/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-86149 - Critical (9.1)
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86149/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T21:31:26
2 posts
Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.
Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)
##Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.
Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)
##updated 2026-09-05T21:31:20
6 posts
⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…
🤖 AI generated summary
##That is a full wipe, you absolute liability.
Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.
Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.
#CyberSecurity #MikroTik #RouterOS #Vulnerability #PrivilegeEscalation #AdminAccessUnlocked (2/2)
##🏆 New Achievement! MikroTik and Chill (No Password Required)!
MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)
##⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…
🤖 AI generated summary
##That is a full wipe, you absolute liability.
Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.
Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.
#CyberSecurity #MikroTik #RouterOS #Vulnerability #PrivilegeEscalation #AdminAccessUnlocked (2/2)
##🏆 New Achievement! MikroTik and Chill (No Password Required)!
MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)
##updated 2026-09-05T21:16:51.400000
11 posts
⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…
🤖 AI generated summary
##📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit
🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity
##Hackers Exploit MikroTik Router Flaws to Hijack Devices
Hackers are actively exploiting vulnerabilities in MikroTik RouterOS, using a two-step attack dubbed "MikroTrick" to hijack devices, warns Poland's Computer Emergency Response Team. The team has confirmed that the critical severity flaws, tracked as CVE-2026-67276 and CVE-2026-86060, are being used in real-world attacks.
#Mikrotik #Routeros #Mikrotrick #EmergingThreats #SupplyChain
##That is a full wipe, you absolute liability.
Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.
Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.
#CyberSecurity #MikroTik #RouterOS #Vulnerability #PrivilegeEscalation #AdminAccessUnlocked (2/2)
##🏆 New Achievement! MikroTik and Chill (No Password Required)!
MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)
##Pre-auth RCE on MikroTik: exploited before the patch, rebuilt in three hours
MikroTik RouterOS에서 SSH만 노출돼 있으면 인증 없이 관리자 권한을 획득할 수 있다는 ‘MikroTrick’ 체인이 공개됐다. 글은 CVE-2026-67279(인증 상태 우회)와 CVE-2026-86060(로그인 헬퍼 인자 처리)을 결합해 루트급 콘솔을 얻으며, CVE-2026-67276은 별도의 공개키 인증 우회 경로가 될 수 있다고 설명한다. 공격 흔적은 `user -2` 로그인 실패·`ssh:-2@<ip>`에 의한 설정 변경, 비인가 `ops` 계정, fetch/import 스케줄러·SOCKS 프록시·터널 등이며,...
##The reason for the Mikrotik “patch now, we’ll say why later” announcements last week seems to be out.
It’s patching a zero day exploit chain that seems to be CVE-2026-67279 (ssh rekey bypasses auth phase) and CVE-2026-86060 (username of “-2” misinterpreted as flag to read from file descriptor).
Several people on Mikrotik forum and Mikrotik subreddit report exploits early September 2026, so likely automated exploit 😬
https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve/
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
https://forum.mikrotik.com/t/important-security-update/272851/109
⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…
🤖 AI generated summary
##📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit
🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity
##That is a full wipe, you absolute liability.
Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.
Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.
#CyberSecurity #MikroTik #RouterOS #Vulnerability #PrivilegeEscalation #AdminAccessUnlocked (2/2)
##🏆 New Achievement! MikroTik and Chill (No Password Required)!
MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)
##updated 2026-09-05T21:16:50.613000
4 posts
Pre-auth RCE on MikroTik: exploited before the patch, rebuilt in three hours
MikroTik RouterOS에서 SSH만 노출돼 있으면 인증 없이 관리자 권한을 획득할 수 있다는 ‘MikroTrick’ 체인이 공개됐다. 글은 CVE-2026-67279(인증 상태 우회)와 CVE-2026-86060(로그인 헬퍼 인자 처리)을 결합해 루트급 콘솔을 얻으며, CVE-2026-67276은 별도의 공개키 인증 우회 경로가 될 수 있다고 설명한다. 공격 흔적은 `user -2` 로그인 실패·`ssh:-2@<ip>`에 의한 설정 변경, 비인가 `ops` 계정, fetch/import 스케줄러·SOCKS 프록시·터널 등이며,...
##@ciaranmak that’s authentication hard mode compared with “client triggers ssh rekey to glitch past authentication step”:
“The vulnerability CVE-2026-67279: RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request.“
(And logs people have posted suggest this is in the original zero day.)
##The reason for the Mikrotik “patch now, we’ll say why later” announcements last week seems to be out.
It’s patching a zero day exploit chain that seems to be CVE-2026-67279 (ssh rekey bypasses auth phase) and CVE-2026-86060 (username of “-2” misinterpreted as flag to read from file descriptor).
Several people on Mikrotik forum and Mikrotik subreddit report exploits early September 2026, so likely automated exploit 😬
https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve/
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
https://forum.mikrotik.com/t/important-security-update/272851/109
@ciaranmak that’s authentication hard mode compared with “client triggers ssh rekey to glitch past authentication step”:
“The vulnerability CVE-2026-67279: RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request.“
(And logs people have posted suggest this is in the original zero day.)
##updated 2026-09-05T19:16:56.190000
2 posts
Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.
Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)
##Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.
Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)
##updated 2026-09-05T19:16:55.320000
2 posts
🟠 CVE-2026-0799 - High (8.7)
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a cra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-0799/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-0799 - High (8.7)
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a cra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-0799/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T15:30:31
2 posts
🔴 CVE-2026-86189 - Critical (9.8)
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86189/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-86189 - Critical (9.8)
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86189/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T14:17:23.897000
1 posts
🟠 CVE-2026-86145 - High (8.2)
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86145/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T13:18:14.150000
3 posts
CVE-2026-86190 - Critical Broken Access Control in WWBN AVideo allows admin session hijacking & data theft. CVSS 9.1. Restrict endpoints now. #CVE #infosec #cybersecurity
##🔴 CVE-2026-86190 - Critical (9.1)
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86190/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-86190 - Critical (9.1)
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86190/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T12:31:35
2 posts
🔴 CVE-2026-86184 - Critical (9.8)
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /scr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86184/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-86184 - Critical (9.8)
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /scr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86184/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T12:31:34
2 posts
🔴 CVE-2026-10196 - Critical (9.8)
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10196/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-10196 - Critical (9.8)
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10196/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T12:31:34
2 posts
🟠 CVE-2025-9049 - High (8.8)
The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-9049/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-9049 - High (8.8)
The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-9049/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T12:31:34
2 posts
🟠 CVE-2026-86117 - High (8.1)
Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86117/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86117 - High (8.1)
Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86117/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T12:31:34
1 posts
🟠 CVE-2026-86123 - High (8.7)
SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86123/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T12:31:27
3 posts
CVE-2026-86124 - Critical unauthenticated RCE in AutoAgent. TCP server executes arbitrary commands as root. CVSS 9.8. Restrict network access now. #CVE #RCE #infosec
##🔴 CVE-2026-86124 - Critical (9.8)
AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86124/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-86124 - Critical (9.8)
AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86124/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T12:31:27
2 posts
CVE-2026-86121 - Critical RCE & auth bypass in Cua computer-server. Allows unauthenticated arbitrary command execution. CVSS 9.8. Update to 0.3.42 now. #CVE #infosec #cybersecurity
##🔴 CVE-2026-86121 - Critical (9.8)
Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86121/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T12:31:27
2 posts
🟠 CVE-2026-86173 - High (7.5)
MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can bypass the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86173/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86173 - High (7.5)
MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can bypass the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86173/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T12:16:49.240000
2 posts
🟠 CVE-2026-86185 - High (8)
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inje...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86185/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86185 - High (8)
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inje...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86185/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T11:16:46.397000
2 posts
🟠 CVE-2026-86177 - High (8.8)
Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger sc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86177/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86177 - High (8.8)
Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger sc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86177/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T11:16:45.703000
2 posts
🟠 CVE-2026-86169 - High (8.8)
Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86169/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86169 - High (8.8)
Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86169/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T10:16:43.157000
1 posts
🟠 CVE-2026-86119 - High (8.6)
Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86119/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T07:17:11.657000
1 posts
🟠 CVE-2026-19887 - High (8.8)
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenti...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19887/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T06:32:44
2 posts
CVE-2026-13447 - Critical Auth Bypass in FluxBuilder Mstore API WordPress plugin via JWT forgery. CVSS 9.8. Unpatched! Mitigate immediately. #CVE #WordPress #infosec
##🔴 CVE-2026-13447 - Critical (9.8)
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() funct...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13447/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T05:17:12.877000
1 posts
🟠 CVE-2026-86140 - High (8)
In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86140/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T00:32:06
2 posts
Pyramid Solutions NetStaX EtherNet/IP Stack before 5.6.1 contains CVE-2026-78012, a stack-based buffer overflow triggered by oversized Class 3 explicit messages without error. It enables DoS and potential RCE in OT systems, making immediate patching critical. #IcsSecurity #EtherNetIp #BufferOverflow
https://cyberworldops.eu/en/netstax-ethernetip-critical-buffer-overflow-in-pyramid-solutions-kits
##Pyramid Solutions NetStaX EtherNet/IP Stack before 5.6.1 contains CVE-2026-78012, a stack-based buffer overflow triggered by oversized Class 3 explicit messages without error. It enables DoS and potential RCE in OT systems, making immediate patching critical. #IcsSecurity #EtherNetIp #BufferOverflow
https://cyberworldops.eu/en/netstax-ethernetip-critical-buffer-overflow-in-pyramid-solutions-kits
##updated 2026-09-05T00:31:10
2 posts
CVE-2026-82684: Missing authorization in Tycon Systems TPDIN-Monitor-WEB3 (≤2.2.9) lets attackers dump system credentials, configs, or flash contents. CVSS 8.1. Unpatched—assume exposure. Isolate affected units and restrict access now. Details: https://www.valtersit.com/cve/CVE-2
##🟠 CVE-2026-82684 - High (8.1)
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82684/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T00:17:20.520000
1 posts
🟠 CVE-2026-52775 - High (8.8)
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject arbitrary S...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52775/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T00:17:19.963000
2 posts
CVE-2026-52771: YesWiki SQL injection via attacker-controlled page tags in ApiController::deletePage(). CVSS 8.3. Low-privilege users can exploit arbitrary tags to inject SQL. Unpatched—no fix available. Update or disable API if exposed. https://www.valtersit.com/cve/CVE-2026-527
##🟠 CVE-2026-52771 - High (8.3)
YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a DELETE FROM …_links WHERE to_tag = '$tag' query without escaping. The pag...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52771/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T00:17:19.540000
1 posts
🟠 CVE-2026-52767 - High (8.2)
YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ... }. PHP's...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-05T00:17:19.393000
1 posts
🔴 CVE-2026-52766 - Critical (9.1)
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52766/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T23:18:03.220000
1 posts
🟠 CVE-2026-86095 - High (7.8)
Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86095/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T23:17:09.143000
1 posts
1 repos
🟠 CVE-2026-48019 - High (8.9)
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48019/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T21:31:59
1 posts
🟠 CVE-2026-82712 - High (8.8)
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82712/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T21:31:59
1 posts
🟠 CVE-2026-80119 - High (7.8)
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump comple...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80119/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T21:31:59
1 posts
🟠 CVE-2026-80116 - High (7.8)
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80116/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T21:31:50
2 posts
CVE-2026-78327: OS Command Injection in SonicWall NSM On-Prem lets SuperAdmin execute arbitrary commands as RCE on the host. CVSS 9.1. Unpatched—assume exposure. Restrict SuperAdmin access now and monitor for updates. https://www.valtersit.com/cve/CVE-2026-78327/ #CVE #SonicWall
##🔴 CVE-2026-78327 - Critical (9.1)
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78327/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T21:31:48
1 posts
1 repos
https://github.com/unpredictable21/CVE-2026-75431_PowerJob_jwt_key_predictable
🔴 CVE-2026-75431 - Critical (9.1)
PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75431/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T20:17:29.647000
1 posts
🔴 CVE-2026-81939 - Critical (9.1)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81939/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T20:17:28.787000
1 posts
🟠 CVE-2026-80114 - High (7.8)
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80114/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T20:17:27.993000
2 posts
CVE-2026-78328 SonicWall NSM On-Prem flaw lets lower-privileged Admins escalate to SuperAdmin. CVSS 9.1, unpatched. Assume compromise until fixed. Restrict access now. Details: https://www.valtersit.com/cve/CVE-2026-78328/ #CVE #infosec #SonicWall
##🔴 CVE-2026-78328 - Critical (9.1)
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78328/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T20:17:26.533000
2 posts
CVE-2026-75160: Critical flaw in X-Serie Gateway Firmware V6_00_05 allows remote privilege escalation via /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. CVSS 9.1. Unpatched—assume exposure. Isolate devices, restrict access, monitor logs now. Details: https://www.valtersit.com/
##🔴 CVE-2026-75160 - Critical (9.1)
An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75160/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T20:17:24.347000
1 posts
🟠 CVE-2026-61699 - High (8.1)
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any peer's c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T20:17:23.570000
1 posts
🟠 CVE-2026-53932 - High (8)
laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53932/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T19:17:28.710000
1 posts
CVE-2026-80118: Unpatched flaw in PassMark PerformanceTest, BurnInTest & OSForensics (DirectIo64.sys) lets local users dump all physical memory via IOCTL—exposing passwords, keys, and data. CVSS 7.1. No patch yet. Stop using these tools or restrict access NOW. Details: https://ww
##updated 2026-09-04T19:17:27.823000
2 posts
CVE-2026-80112: PassMark tools (PerformanceTest, BurnInTest, OSForensics) have an improper access control flaw in DirectIo64.sys, letting unprivileged users run privileged hardware IOCTLs. CVSS 7.8. Unpatched—limit exposure now. Details: https://www.valtersit.com/cve/CVE-2026-801
##🟠 CVE-2026-80112 - High (7.8)
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80112/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T19:17:27.240000
1 posts
🟠 CVE-2026-77822 - High (8.2)
IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77822/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T19:17:26.990000
1 posts
1 repos
https://github.com/unpredictable21/CVE-2026-75430_PowerJob_worker_deployContainer_RCE
🔴 CVE-2026-75430 - Critical (9.8)
PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75430/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:46
1 posts
🟠 CVE-2026-85654 - High (7.8)
Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated ap...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85654/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:32
1 posts
🟠 CVE-2026-18486 - High (8.8)
IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18486/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:31
1 posts
🟠 CVE-2026-18221 - High (8.1)
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18221/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:26
2 posts
🟠 CVE-2026-19298 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19298/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19298 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19298/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:26
2 posts
🟠 CVE-2026-19300 - High (7.5)
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19300/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19300 - High (7.5)
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19300/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:26
2 posts
🟠 CVE-2026-19305 - High (8.6)
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19305/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19305 - High (8.6)
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19305/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:21
1 posts
🟠 CVE-2026-19304 - High (7.7)
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19304/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:21
1 posts
🟠 CVE-2026-19303 - High (8.1)
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19303/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:20
2 posts
🟠 CVE-2026-18905 - High (7.7)
IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18905/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18905 - High (7.7)
IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18905/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:18:07.297000
1 posts
🟠 CVE-2026-9317 - High (8.1)
Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with ne...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9317/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:18:06.133000
2 posts
CVE-2026-85656: OS command injection in Amazon Linux's log4j hotpatch package (<1.3-9). Local user can execute arbitrary commands as root via crafted Java process path with newlines. CVSS 7.8. Unpatched! If you rely on this hotpatch, isolate and monitor systems immediately. Detai
##🟠 CVE-2026-85656 - High (7.8)
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85656/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:18:01.357000
1 posts
🟠 CVE-2026-82538 - High (8.8)
ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82538/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:17:52.080000
1 posts
2 repos
🔴 CVE-2026-44402 - Critical (9.8)
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive witho...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44402/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:17:51.893000
2 posts
CVE-2026-31020: SSTI to RCE in DocsGPT ≤0.15.0 via unsanitized Jinja prompts. CVSS 9.8, unpatched. No auth needed. Patch? None yet—disable custom prompts or isolate instance now. Details: https://www.valtersit.com/cve/CVE-2026-31020/ #CVE #infosec #cybersecurity
##🔴 CVE-2026-31020 - Critical (9.8)
In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input san...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-31020/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:17:51.513000
2 posts
🟠 CVE-2026-19306 - High (7.7)
IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19306/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19306 - High (7.7)
IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19306/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:17:51.260000
2 posts
🔴 CVE-2026-19274 - Critical (9.6)
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scop...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19274/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-19274 - Critical (9.6)
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scop...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19274/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T17:16:57.160000
2 posts
WooCommerce CVE-2026-57777 carries a CVSS score of 7.6 and lets a low-privilege user, a free subscriber, manipulate their own role to gain full admin access. Any store below version 11.0 is exposed. I have written up what the vulnerability involves and the steps I recommend taking to address it.
#WordPress #WooCommerce #SecurityHardening #CVE #WordPressSecurity
https://wpguy.uk/blog/woocommerce-cve-2026-57777-fix-privilege-escalation-now/
##WooCommerce CVE-2026-57777 carries a CVSS score of 7.6 and lets a low-privilege user, a free subscriber, manipulate their own role to gain full admin access. Any store below version 11.0 is exposed. I have written up what the vulnerability involves and the steps I recommend taking to address it.
#WordPress #WooCommerce #SecurityHardening #CVE #WordPressSecurity
https://wpguy.uk/blog/woocommerce-cve-2026-57777-fix-privilege-escalation-now/
##updated 2026-09-04T17:16:56.010000
1 posts
🟠 CVE-2026-18175 - High (8.1)
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18175/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T16:17:25.870000
1 posts
updated 2026-09-04T16:17:21.777000
2 posts
🟠 CVE-2026-19283 - High (7.7)
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19283/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19283 - High (7.7)
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19283/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T16:17:21.133000
2 posts
🔴 CVE-2026-18658 - Critical (9.8)
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18658/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-18658 - Critical (9.8)
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18658/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T15:36:24
2 posts
🔴 CVE-2026-85695 - Critical (9.4)
FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious worker...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-85695 - Critical (9.4)
FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious worker...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T15:36:23
2 posts
Postgres MCP Pro Restricted-Mode Bypass Allows Arbitrary Host File Disclosure
Postgres MCP Pro version 0.3.0 contains a critical restricted-mode bypass (CVE-2026-85620) that allows unauthenticated attackers to read arbitrary files from the database host. The flaw is caused by an incomplete SQL validation in the Abstract Syntax Tree parser, enabling the execution of dangerous functions through FROM clauses.
**If you're running Crystal DBA's Postgres MCP Pro (version 0.3.0 or earlier), don't rely on its restricted mode to keep your AI agents in check. It can be bypassed to read files off your server, including passwords and private keys. Change the database account the MCP server uses to a least-privilege role, strip its superuser status and `pg_read_server_files` permission, and keep it off the internet until an official fix ships.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/postgres-mcp-pro-restricted-mode-bypass-allows-arbitrary-host-file-disclosure-t-6-8-7-8/gD2P6Ple2L
Postgres MCP Pro Restricted-Mode Bypass Allows Arbitrary Host File Disclosure
Postgres MCP Pro version 0.3.0 contains a critical restricted-mode bypass (CVE-2026-85620) that allows unauthenticated attackers to read arbitrary files from the database host. The flaw is caused by an incomplete SQL validation in the Abstract Syntax Tree parser, enabling the execution of dangerous functions through FROM clauses.
**If you're running Crystal DBA's Postgres MCP Pro (version 0.3.0 or earlier), don't rely on its restricted mode to keep your AI agents in check. It can be bypassed to read files off your server, including passwords and private keys. Change the database account the MCP server uses to a least-privilege role, strip its superuser status and `pg_read_server_files` permission, and keep it off the internet until an official fix ships.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/postgres-mcp-pro-restricted-mode-bypass-allows-arbitrary-host-file-disclosure-t-6-8-7-8/gD2P6Ple2L
updated 2026-09-04T15:17:47.540000
2 posts
🟠 CVE-2026-85694 - High (8.1)
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pag...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85694/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85694 - High (8.1)
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pag...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85694/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T14:17:18.423000
1 posts
📰 Cisco Patches Three Critical Flaws in IOS XR Network Software
Cisco patches 3 critical (CVSS 9.8) remote code execution vulnerabilities in IOS XR software (CVE-2026-20274, CVE-2026-20279, CVE-2026-20212). No active exploitation known, but immediate patching is urged. #Cisco #CyberSecurity #RCE #Networking
##updated 2026-09-04T00:31:11
2 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-09-04T00:31:11
1 posts
https://thecybersecguru.com/exploits/tp-link-archer-ax55-cve-2026-18167-cve-2026-18330/
##updated 2026-09-04T00:31:10
1 posts
https://thecybersecguru.com/exploits/tp-link-archer-ax55-cve-2026-18167-cve-2026-18330/
##updated 2026-09-03T21:31:26
2 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-09-03T13:06:16.053000
1 posts
2 repos
https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis
🔵 THREAT INTELLIGENCE
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
Vulnerability | CRITICAL
CVEs: CVE-2026-83548
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV)...
Full analysis:
https://www.yazoul.net/news/article/cisa-adds-seven-exploited-flaws-as-attackers-deploy-reverse-shells-and-crypto-mi
by Yazoul AI
##updated 2026-09-03T13:06:15.630000
1 posts
7 repos
https://github.com/HORKimhab/CVE-2026-82329
https://github.com/realalexandergeorgiev/artifactory-CVE-2026-82329-poc.py
https://github.com/0xCyp1337/CVE-2026-82329
https://github.com/gagaltotal/CVE-2026-82329-poc
https://github.com/0xTerror/CVE-2026-82329-JFrog-Artifactory-
https://github.com/ynsmroztas/CVE-2026-82329-JFrog-Artifactory-Auth-Bypass
🚨 Critical Auth Bypass:
CVE-2026-82329 (CVSS 9.8) in JFrog Artifactory allows remote attackers to bypass authentication & mint admin tokens via blank join keys.
Read our full technical analysis & mitigation guide: https://denizhalil.com/2026/09/05/cve-2026-82329-jfrog-artifactory-authentication-bypass/
##updated 2026-09-03T13:04:38.177000
3 posts
1 repos
🏆 New Achievement! Root of All Evil: The Nexus Awakens!
PHASE TWO HAS BEGUN. CVE-2026-20212 stalks the arena — a CVSS 9.8 critical flaw in Cisco Nexus 9000 Series Switches running Silicon One ASICs. It requires no credentials, no user interaction, nothing. An attacker simply crafts input to TCP ports 43210 or 43211, exposed by default, and ascends to root. Full device compromise. Network disruption. Lateral movement through your data center like a speedrunner who memorized the map. (1/2)
##📰 Cisco Patches Three Critical Flaws in IOS XR Network Software
Cisco patches 3 critical (CVSS 9.8) remote code execution vulnerabilities in IOS XR software (CVE-2026-20274, CVE-2026-20279, CVE-2026-20212). No active exploitation known, but immediate patching is urged. #Cisco #CyberSecurity #RCE #Networking
##🏆 New Achievement! Root of All Evil: The Nexus Awakens!
PHASE TWO HAS BEGUN. CVE-2026-20212 stalks the arena — a CVSS 9.8 critical flaw in Cisco Nexus 9000 Series Switches running Silicon One ASICs. It requires no credentials, no user interaction, nothing. An attacker simply crafts input to TCP ports 43210 or 43211, exposed by default, and ascends to root. Full device compromise. Network disruption. Lateral movement through your data center like a speedrunner who memorized the map. (1/2)
##updated 2026-09-02T18:32:32
1 posts
📰 Cisco Patches Three Critical Flaws in IOS XR Network Software
Cisco patches 3 critical (CVSS 9.8) remote code execution vulnerabilities in IOS XR software (CVE-2026-20274, CVE-2026-20279, CVE-2026-20212). No active exploitation known, but immediate patching is urged. #Cisco #CyberSecurity #RCE #Networking
##updated 2026-09-02T14:17:15.257000
2 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-09-02T04:18:00.460000
2 posts
1 repos
A critical Microsoft Exchange vulnerability (CVE-2026-62911) leaves thousands of servers unpatched, while AI-assisted ransomware now compromises networks in under 10 hours. OpenAI released GPT-6 Astra, advancing Artificial General Intelligence. Geopolitically, Ukrainian drones struck Russia's Taganrog airbase overnight (Sept 6-7).
##A critical Microsoft Exchange vulnerability (CVE-2026-62911) leaves thousands of servers unpatched, while AI-assisted ransomware now compromises networks in under 10 hours. OpenAI released GPT-6 Astra, advancing Artificial General Intelligence. Geopolitically, Ukrainian drones struck Russia's Taganrog airbase overnight (Sept 6-7).
##updated 2026-09-02T04:17:59.917000
2 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-09-01T21:03:04.987000
5 posts
1 repos
Hackers are actively exploiting CVE-2026-19490, a critical authentication bypass vulnerability in Citrix NetScaler. Update your systems immediately.
#CitrixNetScaler #CyberSecurity #Vulnerability #NetworkSecurity #Infosec
##Threat Actors Target Critical Citrix NetScaler Authentication Bypass
Citrix NetScaler ADC and Gateway appliances face active exploitation of a critical authentication bypass (CVE-2026-19490) that allows unauthenticated attackers to access internal applications and VPN services.
**Your NetScaler appliances are now under attack, so act fast. Patch ASAP and check your logs for any unusual logins from the past few weeks. Even if you patch now, an attacker might have already created a back door while the system was open. And make sure to isolate the management interface from the internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/threat-actors-target-critical-citrix-netscaler-authentication-bypass-p-f-z-7-1/gD2P6Ple2L
Hackers are actively exploiting CVE-2026-19490, a critical authentication bypass vulnerability in Citrix NetScaler. Update your systems immediately.
#CitrixNetScaler #CyberSecurity #Vulnerability #NetworkSecurity #Infosec
##Threat Actors Target Critical Citrix NetScaler Authentication Bypass
Citrix NetScaler ADC and Gateway appliances face active exploitation of a critical authentication bypass (CVE-2026-19490) that allows unauthenticated attackers to access internal applications and VPN services.
**Your NetScaler appliances are now under attack, so act fast. Patch ASAP and check your logs for any unusual logins from the past few weeks. Even if you patch now, an attacker might have already created a back door while the system was open. And make sure to isolate the management interface from the internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/threat-actors-target-critical-citrix-netscaler-authentication-bypass-p-f-z-7-1/gD2P6Ple2L
Previdian reports exploitation attempts targeting CVE-2026-19490, a critical authentication bypass in Citrix NetScaler ADC and Gateway. Exposure depends on firmware version and AAA virtual server configuration. Review exposed assets and authentication logs for anomalous access. #CitrixNetScaler #AuthBypass #ThreatIntel
https://cyberworldops.eu/en/citrix-netscaler-exploitation-attempts-target-critical-vulnerability
##updated 2026-09-01T19:17:28.907000
2 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-09-01T04:18:02.160000
1 posts
2 repos
🔵 THREAT INTELLIGENCE
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Vulnerability | CRITICAL
CVEs: CVE-2026-81578, CVE-2026-82078
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S...
Full analysis:
https://www.yazoul.net/news/article/attackers-exploit-papercut-flaws-to-steal-credentials-from-schools-and-universit
by Yazoul AI
##updated 2026-08-31T21:31:56
1 posts
2 repos
🔵 THREAT INTELLIGENCE
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Vulnerability | CRITICAL
CVEs: CVE-2026-81578, CVE-2026-82078
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S...
Full analysis:
https://www.yazoul.net/news/article/attackers-exploit-papercut-flaws-to-steal-credentials-from-schools-and-universit
by Yazoul AI
##updated 2026-08-31T20:56:08.800000
2 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-08-31T20:56:08.800000
2 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-08-31T15:34:50
2 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-08-31T12:30:37
2 posts
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
updated 2026-08-29T23:17:23.010000
5 posts
2 repos
https://github.com/goldendivider/cve-2026-6471-postgres-logical-decoding-dlopen
PostgreSQL fixed CVE-2026-6471, an authorization flaw in logical decoding that lets users with REPLICATION privilege load arbitrary shared libraries. Code executes as the server OS user, typically postgres, enabling full host compromise from a low-privileged DB role. #PostgreSQL #AccessControl #CodeExecution
https://cyberworldops.eu/en/postgresql-logical-decoding-flaw-allows-code-execution-as-the-postgres
##https://www.postgresql.org/support/security/CVE-2026-6471/
PostgreSQL-virhe mahdollistaa palvelimen haltuunoton pienillä oikeuksilla PostgreSQL on korjannut CVE-2026-6471 , vuodesta 2014 lähtien olleen virheen, joka sallii REPLICATION-oikeuksilla varustettujen tilien ladata mielivaltaisia tiedostoja loogisen dekoodauksen laajennusten kautta ja suorittaa koodia tietokantapalvelutilinä. Vaikuttavat haarat sisältävät versiot 9.4–18, ja korjaukset on julkaistu versioissa 18.6, 17.11, 16.15, 15.
PostgreSQL fixed CVE-2026-6471, an authorization flaw in logical decoding that lets users with REPLICATION privilege load arbitrary shared libraries. Code executes as the server OS user, typically postgres, enabling full host compromise from a low-privileged DB role. #PostgreSQL #AccessControl #CodeExecution
https://cyberworldops.eu/en/postgresql-logical-decoding-flaw-allows-code-execution-as-the-postgres
##https://thecybersecguru.com/exploits/cve-2026-6471-postgresql-postgreshell-rce/
##CVE-2026-6471 PostGREShell is an authorization flaw in PostgreSQL allowing REPLICATION users to execute arbitrary code as the server OS user. It affects versions since 2014 and enables escalation to superuser, making exposed replication accounts a critical risk. #PostgreSQL #CodeExecution #ThreatIntel
https://cyberworldops.eu/en/postgreshell-a-postgresql-flaw-turns-replication-accounts-into-a
##updated 2026-08-28T22:53:42
1 posts
14 repos
https://github.com/minh3102011/CVE-2026-18963_analyst
https://github.com/0xlyvio/CVE-2026-18963-keycloak
https://github.com/alt3kx/CVE-2026-18963
https://github.com/Snizi/CVE-2026-18963-Exploit
https://github.com/T0w0T/POC-CVE-2026-18963
https://github.com/prot0tw/Keycloak_CVE-2026-18963_PoC
https://github.com/EQSTLab/CVE-2026-18963
https://github.com/ynsmroztas/KeySniper
https://github.com/Red-Darkin/CVE-2026-18963-keycloak
https://github.com/BlackHatExploitation/Exploit-For-CVE-2026-18963
https://github.com/debugactiveprocess/CVE-2026-18963
https://github.com/kyos-public/keycloak-cve-2026-18963-hunt
A flaw in the reset-credentials flow of the keycloak-services component
CVE-2026-18963은 Red Hat Build of Keycloak의 핵심 IAM 엔진인 keycloak-services에서 비밀번호 재설정 이메일 검증 단계를 우회할 수 있는 취약점이다. 인증되지 않은 원격 공격자가 임의 사용자의 재설정 절차를 강제하고 새 자격 증명을 설정해 계정을 완전히 탈취할 수 있으며, Red Hat CNA 평가는 CVSS 9.1(Critical)이다. AI 서비스의 SSO·관리자 콘솔·에이전트 및 내부 도구 인증에 Keycloak을 쓰는 팀은 영향을 받는 Red Hat 배포판을 즉시 보안 권고 버전(26.4.15 또는 26.6.6 계...
##updated 2026-08-28T20:18:10.133000
2 posts
1 repos
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53362 – Linux Kernel Unspecified Vulnerability
Active exploitation of Linux kernel vulnerability CVE-2026-53362 threatens enterprise infrastructure. Read our C-Suite threat intelligence brief for mitigation strategies....
##(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53362 – Linux Kernel Unspecified Vulnerability
Active exploitation of Linux kernel vulnerability CVE-2026-53362 threatens enterprise infrastructure. Read our C-Suite threat intelligence brief for mitigation strategies....
##updated 2026-08-27T11:41:19.230000
2 posts
9 repos
https://github.com/EQSTLab/CVE-2026-60004
https://github.com/shinthink/CVE-2026-60004
https://github.com/HackSpeak/CVE-2026-60004
https://github.com/gagaltotal/CVE-2026-60004-poc-gitea
https://github.com/HORKimhab/CVE-2026-60004
https://github.com/imbas007/CVE-2026-60004-POC
https://github.com/0xBlackash/CVE-2026-60004
Welp. My Forgejo instance got popped with an RCE two days ago by CVE-2026-60004. Luckily, I noticed the following morning and had the day free to figure out what happened. Let's dive in!
As a homelab enthusiast, I found this a very interesting post. Here are my take aways from the post that I'm implementing myself:
log-inventory.sh, so "could I actually reconstruct what happened" is a command I run instead of a thing I assume.Welp. My Forgejo instance got popped with an RCE two days ago by CVE-2026-60004. Luckily, I noticed the following morning and had the day free to figure out what happened. Let's dive in!
As a homelab enthusiast, I found this a very interesting post. Here are my take aways from the post that I'm implementing myself:
log-inventory.sh, so "could I actually reconstruct what happened" is a command I run instead of a thing I assume.updated 2026-08-20T12:48:31.843000
2 posts
6 repos
https://github.com/dinosn/cve-2026-32475-elementor-pro-lab
https://github.com/4minx/CVE-2026-32475
https://github.com/Boreas37/CVE-2026-32475-PoC
https://github.com/absholi7ly/Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE
⚠️ CRITICAL: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are actively exploiting two critical RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475), with over 440,000 exploit attempts already blocked. Unauthenticated attackers can upload arbitrary files including PHP web shells to gain full…
🤖 AI generated summary
##⚠️ CRITICAL: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are actively exploiting two critical RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475), with over 440,000 exploit attempts already blocked. Unauthenticated attackers can upload arbitrary files including PHP web shells to gain full…
🤖 AI generated summary
##updated 2026-08-11T18:31:23
2 posts
2 repos
A Windows HTTP.sys vulnerability, CVE-2026-62735 (CVSS 7.8), now has public details and a PoC. It escalates local users to SYSTEM. Patch now.
#Windows #HTTPsys #CVE202662735 #PrivilegeEscalation #Pwn2Own #SYSTEM #Infosec #PoC
##A Windows HTTP.sys vulnerability, CVE-2026-62735 (CVSS 7.8), now has public details and a PoC. It escalates local users to SYSTEM. Patch now.
#Windows #HTTPsys #CVE202662735 #PrivilegeEscalation #Pwn2Own #SYSTEM #Infosec #PoC
##updated 2026-08-06T18:37:01.630000
1 posts
New issue of #Perl Weekly:789 - The impact of LLMs on Perl - https://perlweekly.com/archive/789.html
CVE-2026-18108: Net::SAML2 Authentication Bypass via Unsigned Encrypted Assertions (CVSS 9.8)
AmberDB - An Embedded NoSQL Database Engine for Perl
DBI now has a minimum version of v5.12
CPAN Uploads Are Up 50% Year-over-Year
perl in cybersecurity?
The videos of the German Perl Workshop 2026 are online
German Perl/Raku Workshop 2027
YAPC::Tokyo 2026
London Perl & Raku Workshop 2026
[...]
updated 2026-08-06T18:21:08.780000
4 posts
@ohunt I can't speak to the CFAA since I'm no lawyer. Exploitation in this exact scenario isn't a valid classifier either since the underlying vuln of CVE-2026-13230 is a lack of meaningful protection, it equates to intercepting HTTP at this point. Ask and receive. However the protocol that operates on UDP 9999 has been broken for about 10 years now and has an RCE vuln on a different device class.
##The LG TV network scanning story breaking today includes UDP 9999 Kasa discovery broadcasts every 25 seconds. That's the exact port I documented in CVE-2026-13230 as returning unauthenticated precise GPS coordinates from Kasa cameras with no authentication. Any LG TV + unpatched Kasa camera on the same network = GPS harvesting every 25 seconds. @briankrebs Advisory: https://github.com/BadChemical/IoT-Vulnerability-Research-Public/blob/main/TP-Link_Kasa_EC71/Kasa_EC71.md
##@ohunt I can't speak to the CFAA since I'm no lawyer. Exploitation in this exact scenario isn't a valid classifier either since the underlying vuln of CVE-2026-13230 is a lack of meaningful protection, it equates to intercepting HTTP at this point. Ask and receive. However the protocol that operates on UDP 9999 has been broken for about 10 years now and has an RCE vuln on a different device class.
##The LG TV network scanning story breaking today includes UDP 9999 Kasa discovery broadcasts every 25 seconds. That's the exact port I documented in CVE-2026-13230 as returning unauthenticated precise GPS coordinates from Kasa cameras with no authentication. Any LG TV + unpatched Kasa camera on the same network = GPS harvesting every 25 seconds. @briankrebs Advisory: https://github.com/BadChemical/IoT-Vulnerability-Research-Public/blob/main/TP-Link_Kasa_EC71/Kasa_EC71.md
##updated 2026-08-06T18:13:26.983000
1 posts
1 repos
https://github.com/HORKimhab/CVE-2026-13181-CVE-2026-13182-CVE-2026-13183-CVE-2026-13184
From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for Asp.net Ajax
Tanto Security는 Telerik UI for ASP.NET AJAX에서 인증 없이 AES-CBC 패딩 오라클을 악용하고 추가 취약점과 체이닝해 원격 코드 실행(RCE)에 도달할 수 있는 CVE-2026-13181~13184를 공개했습니다. 영향 범위는 2010.1.309부터 2026.2.519까지이며, Progress Software는 2026.2.708(2026 Q2 SP1)에서 해당 공격 체인 악용을 차단했다고 밝혔습니다. 공격에는 RadAsyncUpload가 포함된 접근 가능한 페이지, `UploadR...
https://tantosec.com/blog/2026/09/telerik-padding-oracle-to-shell/
##updated 2026-08-06T05:17:05.170000
1 posts
5 repos
https://github.com/AnggaTechI/CVE-2026-63077
https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap
https://github.com/sfewer-r7/CVE-2026-63077
https://github.com/bakos-sandor-nx/teamcity-cve-2026-63077-remediation
JetBrains Cadence Breach Exposes AWS Credentials, User Data
A critical deserialization flaw, CVE-2026-63077, was exploited by unknown attackers to breach JetBrains' Cadence environment, compromising AWS credentials, backups, and user data. The vulnerability, scoring 9.8, allowed threat actors to bypass authentication and execute malicious commands with ease.
#Cve202663077 #Jetbrains #Teamcity #AwsCredentialsExposure #DeserializationFlaw
##updated 2026-07-30T18:23:34
1 posts
7 repos
https://github.com/HackSpeak/CVE-2026-66066
https://github.com/0xBlackash/CVE-2026-66066
https://github.com/shinthink/CVE-2026-66066
https://github.com/Zer0SumGam3/CVE-2026-66066-POC
https://github.com/rails/rails-forensics-CVE-2026-66066
📢 CVE-2026-66066 : exploitation d'une RCE ActiveStorage (Rails) quelques heures après le patch
Cet article est un post-mortem détaillé d'un incident de sécurité impliquant la CVE-2026-66066 (alias KindaRails2Shell), une vulnérabilité de type exécution de code à distance (RCE) avec un score CVSS 9.5/10 affectant le composant ActiveStorage de Ruby on…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-05-cve-2026-66066-exploitation-d-une-rce-activestorage-rails-quelques-heures-apres-le-patch/
🌐 source : https://rietta.com/blog/ruby-on-rails-cve-exploited-hours-after-patch/
🟡 vérification factuelle moyenne
#ActiveStorage #RCE #Cyberveille
updated 2026-07-14T15:31:59
1 posts
45 repos
https://github.com/cumakurt/linuxpi
https://github.com/krisiasty/vcheck
https://github.com/aettern/copyfrag-fuse
https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester
https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/haydenjames/dirty-frag-check
https://github.com/nonameuserosint-hue/DirtyFrag-go
https://github.com/linnemanlabs/dirtyfrag-arm64
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/First-John/cve_2026_frag_family_fix
https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/0xBlackash/CVE-2026-43284
https://github.com/AK777177/Dirty-Frag-Analysis
https://github.com/kuniyal08/Dirty-Frag-CVE-2026-43284
https://github.com/attaattaatta/CVE-2026-43500
https://github.com/FrosterDL/CVE-2026-43284
https://github.com/0xlane/pagecache-guard
https://github.com/t1ckprivate/CVE-2026-43284-Dirty-Frag
https://github.com/jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC
https://github.com/1neptune/DirtyFrag
https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284
https://github.com/XRSecCD/202605_dirty_frag
https://github.com/LucasPDiniz/CVE-2026-43284
https://github.com/g0thamRabb1t/CVE-2026-43284-dirtyfrag-detection
https://github.com/RevyHub/CVE-2026-43284---DirtyFrag-Analysis-THM-
https://github.com/Aiyakami/rust_dirtyfrag
https://github.com/suominen/CVE-2026-43284
https://github.com/cyber-niz/Dirty-Frag
https://github.com/xd20111/CVE-2026-43284
https://github.com/nabhan-mohy/Dirty-Frag-Research-CVE-2026-43284-
https://github.com/ChernStepanov/DirtyFrag-for-dummies
https://github.com/ryan2929/CVE-2026-43284-
https://github.com/metalx1993/dirtyfrag-patches
https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC
https://github.com/armircetaj/tetragon-dirtyfrag
https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4
https://github.com/liamromanis101/DirtyFrag-Detector
https://github.com/dixyes/dirtypatch
https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan
https://github.com/lukeslp/redtail-ioc
https://github.com/MadExploits/CVE-2026-46300
https://github.com/millikanjohnl-blip/dirtyfrag-detection-rules
https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag
🐧 SIGINT // Linux Watch — 2026-09-08
A local root escalation with public PoC code and Ubuntu already shipping fixed package versions — translation: patch your kernels this week, not next quarter.
##updated 2026-07-10T15:43:30.330000
2 posts
3 repos
https://github.com/1beelze/CVE-2026-14894
⚠️ CRITICAL: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are actively exploiting two critical RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475), with over 440,000 exploit attempts already blocked. Unauthenticated attackers can upload arbitrary files including PHP web shells to gain full…
🤖 AI generated summary
##⚠️ CRITICAL: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are actively exploiting two critical RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475), with over 440,000 exploit attempts already blocked. Unauthenticated attackers can upload arbitrary files including PHP web shells to gain full…
🤖 AI generated summary
##updated 2026-07-09T21:00:06
1 posts
🟠 CVE-2026-52770 - High (7.5)
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query / queries filters. For Bazar fields whose value structure is numeric, Yes...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-09T20:58:34
1 posts
🟠 CVE-2026-52769 - High (8.3)
YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - accepts an HTTP Signature header whose keyId parameter is a URL. HttpSignatu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52769/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-17T10:20:23.560000
2 posts
@mttaggart @jerry @ifin Well, this isn't a good start. The link attached to CVE-2026-22769 returns a 404.
But the CVE-2023-41974 link is solid https://cybertop.ai/t/cve-2023-41974-apple-ios-and-ipados-use-after-free-vulnerability
##@mttaggart @jerry @ifin Well, this isn't a good start. The link attached to CVE-2026-22769 returns a 404.
But the CVE-2023-41974 link is solid https://cybertop.ai/t/cve-2023-41974-apple-ios-and-ipados-use-after-free-vulnerability
##updated 2026-06-17T09:08:21.517000
1 posts
23 repos
https://github.com/MiclelsonCN/CVE-2025-30208_POC
https://github.com/HaGsec/CVE-2025-30208
https://github.com/Lusensec/CVE-2025-30208
https://github.com/On1onss/CVE-2025-30208
https://github.com/r0ngy40/CVE-2025-30208-Series
https://github.com/marino-admin/Vite-CVE-2025-30208-Scanner
https://github.com/TH-SecForge/CVE-2025-30208
https://github.com/jackieya/ViteVulScan
https://github.com/keklick1337/CVE-2025-30208-ViteVulnScanner
https://github.com/lilil3333/Vite-CVE-2025-30208-EXP
https://github.com/nkuty/CVE-2025-30208-31125-31486-32395
https://github.com/sadhfdw129/CVE-2025-30208-Vite
https://github.com/sumeet-darekar/CVE-2025-30208
https://github.com/imbas007/CVE-2025-30208-template
https://github.com/cc3305/CVE-2025-30208
https://github.com/4xura/CVE-2025-30208
https://github.com/0xshaheen/CVE-2025-30208
https://github.com/HazaVVIP/CVE-2025-30208
https://github.com/ThemeHackers/CVE-2025-30208
https://github.com/ThumpBo/CVE-2025-30208-EXP
https://github.com/4m3rr0r/CVE-2025-30208-PoC
#Blog #Security
Tient tient du monde essaye de trouver https://www.offsec.com/blog/cve-2025-30208/
Comme /@fs/home/ec2-user/.aws/credentials
Les scanners de vulnérabilité ... y en a TOUT le temps
updated 2026-06-17T04:55:48.137000
1 posts
6 repos
https://github.com/nhh9905/CVE-2022-37969
https://github.com/fortra/CVE-2022-37969
https://github.com/NoobCat2000/CVE-2022-37969
https://github.com/EmilC3978/CVE-2022-37969PoC
CVE-2022-37969 - Changed to Known Ransomware Status
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityVendor: MicrosoftProduct: WindowsMicrosoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 04, 2026 at 16:08:17 UTCDate Added to KEV: https://nvd.nist.gov/vuln/detail/CVE-2022-37969
##updated 2026-03-12T03:31:06
2 posts
@mttaggart @jerry @ifin Well, this isn't a good start. The link attached to CVE-2026-22769 returns a 404.
But the CVE-2023-41974 link is solid https://cybertop.ai/t/cve-2023-41974-apple-ios-and-ipados-use-after-free-vulnerability
##@mttaggart @jerry @ifin Well, this isn't a good start. The link attached to CVE-2026-22769 returns a 404.
But the CVE-2023-41974 link is solid https://cybertop.ai/t/cve-2023-41974-apple-ios-and-ipados-use-after-free-vulnerability
##updated 2025-11-17T21:32:21
1 posts
1 repos
CVE-2016-4117 - Changed to Known Ransomware Status
Adobe Flash Player Arbitrary Code Execution VulnerabilityVendor: AdobeProduct: Flash PlayerAn access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 04, 2026 at 16:08:17 UTCDate Added to KEV: 2022-03-03View https://nvd.nist.gov/vuln/detail/CVE-2016-4117
##updated 2025-10-22T19:13:26
1 posts
100 repos
https://github.com/sec13b/CVE-2021-44228-POC
https://github.com/justakazh/Log4j-CVE-2021-44228
https://github.com/1lann/log4shelldetect
https://github.com/jas502n/Log4j2-CVE-2021-44228
https://github.com/CreeperHost/Log4jPatcher
https://github.com/toramanemre/log4j-rce-detect-waf-bypass
https://github.com/giterlizzi/nmap-log4shell
https://github.com/mergebase/log4j-detector
https://github.com/CrackerCat/CVE-2021-44228-Log4j-Payloads
https://github.com/momos1337/Log4j-RCE
https://github.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent
https://github.com/leonjza/log4jpwn
https://github.com/LiveOverflow/log4shell
https://github.com/alexbakker/log4shell-tools
https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words
https://github.com/yahoo/check-log4j
https://github.com/qingtengyun/cve-2021-44228-qingteng-patch
https://github.com/boundaryx/cloudrasp-log4j2
https://github.com/KosmX/CVE-2021-44228-example
https://github.com/NCSC-NL/log4shell
https://github.com/DragonSurvivalEU/RCE
https://github.com/tippexs/nginx-njs-waf-cve2021-44228
https://github.com/Jeromeyoung/log4j2burpscanner
https://github.com/0xInfection/LogMePwn
https://github.com/redhuntlabs/Log4JHunt
https://github.com/simonis/Log4jPatch
https://github.com/f0ng/log4j2burpscanner
https://github.com/mzlogin/CVE-2021-44228-Demo
https://github.com/CERTCC/CVE-2021-44228_scanner
https://github.com/stripe/log4j-remediation-tools
https://github.com/alexandre-lavoie/python-log4rce
https://github.com/infiniroot/nginx-mitigate-log4shell
https://github.com/rubo77/log4j_checker_beta
https://github.com/MalwareTech/Log4jTools
https://github.com/Nanitor/log4fix
https://github.com/back2root/log4shell-rex
https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes
https://github.com/NorthwaveSecurity/log4jcheck
https://github.com/blake-fm/vcenter-log4j
https://github.com/thomaspatzke/Log4Pot
https://github.com/ssl/scan4log4j
https://github.com/kubearmor/log4j-CVE-2021-44228
https://github.com/darkarnium/Log4j-CVE-Detect
https://github.com/wortell/log4j
https://github.com/dtact/divd-2021-00038--log4j-scanner
https://github.com/corelight/cve-2021-44228
https://github.com/Labout/log4shell-rmi-poc
https://github.com/Adikso/minecraft-log4j-honeypot
https://github.com/puzzlepeaches/Log4jCenter
https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs
https://github.com/corretto/hotpatch-for-apache-log4j2
https://github.com/hackinghippo/log4shell_ioc_ips
https://github.com/nccgroup/log4j-jndi-be-gone
https://github.com/mr-vill4in/log4j-fuzzer
https://github.com/dwisiswant0/look4jar
https://github.com/nu11secur1ty/CVE-2021-44228-VULN-APP
https://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228
https://github.com/fireeye/CVE-2021-44228
https://github.com/greymd/CVE-2021-44228
https://github.com/bigsizeme/Log4j-check
https://github.com/fullhunt/log4j-scan
https://github.com/thecyberneh/Log4j-RCE-Exploiter
https://github.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit
https://github.com/mufeedvh/log4jail
https://github.com/Diverto/nse-log4shell
https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator
https://github.com/takito1812/log4j-detect
https://github.com/puzzlepeaches/Log4jHorizon
https://github.com/christophetd/log4shell-vulnerable-app
https://github.com/qingtengyun/cve-2021-44228-qingteng-online-patch
https://github.com/roxas-tan/CVE-2021-44228
https://github.com/marcourbano/CVE-2021-44228
https://github.com/BinaryDefense/log4j-honeypot-flask
https://github.com/cisagov/log4j-scanner
https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce
https://github.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228
https://github.com/pedrohavay/exploit-CVE-2021-44228
https://github.com/puzzlepeaches/Log4jUnifi
https://github.com/logpresso/CVE-2021-44228-Scanner
https://github.com/lucab85/log4j-cve-2021-44228
https://github.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell
https://github.com/0xDexter0us/Log4J-Scanner
https://github.com/mr-r3b00t/CVE-2021-44228
https://github.com/CodeShield-Security/Log4JShell-Bytecode-Detector
https://github.com/kozmer/log4j-shell-poc
https://github.com/claranet/ansible-role-log4shell
https://github.com/Kadantte/CVE-2021-44228-poc
https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept
https://github.com/cyberxml/log4j-poc
https://github.com/sunnyvale-it/CVE-2021-44228-PoC
https://github.com/AlexandreHeroux/Fix-CVE-2021-44228
https://github.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab
https://github.com/HynekPetrak/log4shell-finder
https://github.com/future-client/CVE-2021-44228
https://github.com/fox-it/log4j-finder
https://github.com/toramanemre/apache-solr-log4j-CVE-2021-44228
https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes
https://github.com/lfama/log4j_checker
https://github.com/NS-Sp4ce/Vm4J
https://github.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228
🟠 CVE-2026-85656 - High (7.8)
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85656/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##2 posts
1 repos
https://github.com/Mav3r1ck0x1/Chrome-and-Edge-Version-Dumper
RE: https://mastodon.online/@rozie/117224244824728530
Eteryu stara się przedstawić swoje tezy jako wynik rzetelnej analizy, jego tekst zawiera elementy dezinformacji, wybiórcze traktowanie faktów oraz jednostronne podejście do omawianych kwestii.
Jak na moje oko, Baza wiedzy Eteryu space – jest jedynie kopią, niestety mocno okrojoną i uproszczoną. Szczegóły w dalszej częśći tekstu, wraz ze zródłami oraz zrzutami ekranu.
🧵 1/2
Baza Wiedzy Eteryu
PODWÓJNE STANDARDY W OCENIE CHROME I BRAVE
Eteryu twierdzi, że Chrome na PC jest ‘czystszym wyborem’ dzięki izolacji procesów, ale celowo bagatelizuje ryzyko związane z telemetrią Chrome.
Błędne założenie o izolacji procesów
Chrome oferuje ‘niezrównaną izolację procesów’, w rzeczywistości wiele przeglądarek opartych na Chromium stosuje identyczne mechanizmy, takie jak: Site Isolation (izolacja stron w osobnych procesach), Process-per-site-instance (osobny proces dla każdej instancji strony). Różnice w izolacji wynikają głównie z ustawień domyślnych (np. Chrome domyślnie włącza Site Isolation, podczas gdy niektóre forki wymagają ręcznej konfiguracji). Przedstawia Chrome jako wyjątkowego lidera, podczas gdy w praktyce wiele przegląddek Chromium osiąga podobnypoziom bezpieczeństwa.
Niespójność w ocenie Brave jest ‘wysoce zalecany’ na Androidzie ze względu na możliwość wyłączenia JIT w V8, co rzekomo ‘amputuje główny wektor ataków’. To prawda, ale częściowa. Wyłączenie JIT nie jest unikalne dla Brave , każdy użytkownik Chromium może to zrobić ręcznie (np. poprzez flagi –disable-jit). JIT nie jest jedynym wektorem ataków, luki w V8 (np. CVE-2022-1096) były wykorzystywane w atakach nawet z wyłączonym JIT. Eteryu przedstawia rozwiązanie jako panaceum, podczas gdy realne bezpieczeństwo wymaga szerszego podejścia. Brave jest dobrą opcją, ale nie ze względu na ‘wyłączanie JIT’, a raczej dzięki blokowaniu reklam, trackerów i lepszej ochronie prywatności. Tak, “zbędne” funkcje w Brave (jak moduły krypto czy AI) można ręcznie wyłączyć, celowo pomijane, by przedstawić przeglądarkę jako “skomplikowaną”. W rzeczywistości Brave jest bardziej konfigurowalny niż Chrome dzięki lepszej obsłudze rozszerzeń i flag.
AKTUALIZACJE
Chrome jako ‘upstream’ otrzymuje łatki krytyczne ‘natychmiast’, podczas gdy forki muszą je synchronizować. To półprawda. Chrome nie jest jedynym projektem upstream: Chromium (na którym bazuje Chrome) jest open source i wszystkie przeglądarki oparte na Chromium otrzymują łatki w tym samym czasie. Różnice wynikają jedynie z czasu potrzebnego na kompilację i testowanie własnych modyfikacji.
NAJWIĘKSZY PROBLEM TKWI W IGNOROWANIU REALNYCH ALTERNATYW NA DESKTOPIE.
Chrome jest “zawsze lepszy”, ale: Edge (również Chromium) ma lepszą integrację z Windows (ochrona przed phishingiem, lepsze zarządzanie pamięcią) i jest domyślnie instalowany na wielu maszynach.
Przeglądarka Edge zdobyła nawet uznanie wśród autorów treści, którymi Eteryu zdaje się posiłkować. Można tam przeczytać że przeglądarka Edge na Windows, oferuje większe bezpieczeństwo od Chrome i nawet stawia się ją obok przeglądarek Vanadium (GrapheneOS), oraz Trivalent (Secureblue) jednak zwraca się uwagę na problemem z telemetrią.
Safari na MacOS oferuje lepszą izolację procesów niż Chrome dzięki głębszej integracji z systemem i mniejsze ryzyko zero-day (mniejsza baza użytkowników = mniej celów dla ataków).
Czy Eteryu celowo pomija te przeglądarki, by promować Chrome? Choć Edge i Safari są technicznie lepsze w swoich ekosystemach. Jak widać jest to wybiórcza, analiza skupia się na jednym ignorując szerszy kontekst bezpieczeństwa i wydajności.
Podsumowując: To nie jest “ścisła analiza”, tylko subiektywna ocena oparta na preferencjach. Dla prawdziwie bezpiecznej przeglądarki na desktopie lepszym wyborem byłoby Edge (Windows), Safari (Mac). Brave często cenony jest za blokowanie reklam i trackerów.
Linux
Rzeczywistość jest bardziej złożona:
Więcej
👇
2/2 poniżej
~
##RE: https://mastodon.online/@rozie/117224244824728530
Eteryu stara się przedstawić swoje tezy jako wynik rzetelnej analizy, jego tekst zawiera elementy dezinformacji, wybiórcze traktowanie faktów oraz jednostronne podejście do omawianych kwestii.
Jak na moje oko, Baza wiedzy Eteryu space – jest jedynie kopią, niestety mocno okrojoną i uproszczoną. Szczegóły w dalszej częśći tekstu, wraz ze zródłami oraz zrzutami ekranu.
🧵 1/2
Baza Wiedzy Eteryu
PODWÓJNE STANDARDY W OCENIE CHROME I BRAVE
Eteryu twierdzi, że Chrome na PC jest ‘czystszym wyborem’ dzięki izolacji procesów, ale celowo bagatelizuje ryzyko związane z telemetrią Chrome.
Błędne założenie o izolacji procesów
Chrome oferuje ‘niezrównaną izolację procesów’, w rzeczywistości wiele przeglądarek opartych na Chromium stosuje identyczne mechanizmy, takie jak: Site Isolation (izolacja stron w osobnych procesach), Process-per-site-instance (osobny proces dla każdej instancji strony). Różnice w izolacji wynikają głównie z ustawień domyślnych (np. Chrome domyślnie włącza Site Isolation, podczas gdy niektóre forki wymagają ręcznej konfiguracji). Przedstawia Chrome jako wyjątkowego lidera, podczas gdy w praktyce wiele przegląddek Chromium osiąga podobnypoziom bezpieczeństwa.
Niespójność w ocenie
Brave jest ‘wysoce zalecany’ na Androidzie ze względu na możliwość wyłączenia JIT w V8, co rzekomo ‘amputuje główny wektor ataków’. To prawda, ale częściowa. Wyłączenie JIT nie jest unikalne dla Brave , każdy użytkownik Chromium może to zrobić ręcznie (np. poprzez flagi –disable-jit). JIT nie jest jedynym wektorem ataków, luki w V8 (np. CVE-2022-1096) były wykorzystywane w atakach nawet z wyłączonym JIT. Eteryu przedstawia rozwiązanie jako panaceum, podczas gdy realne bezpieczeństwo wymaga szerszego podejścia. Brave jest dobrą opcją, ale nie ze względu na ‘wyłączanie JIT’, a raczej dzięki blokowaniu reklam, trackerów i lepszej ochronie prywatności. Tak, “zbędne” funkcje w Brave (jak moduły krypto czy AI) można ręcznie wyłączyć, celowo pomijane, by przedstawić przeglądarkę jako “skomplikowaną”. W rzeczywistości Brave jest bardziej konfigurowalny niż Chrome dzięki lepszej obsłudze rozszerzeń i flag.
AKTUALIZACJE
Chrome jako ‘upstream’ otrzymuje łatki krytyczne ‘natychmiast’, podczas gdy forki muszą je synchronizować. To półprawda. Chrome nie jest jedynym projektem upstream: Chromium (na którym bazuje Chrome) jest open source i wszystkie przeglądarki oparte na Chromium otrzymują łatki w tym samym czasie. Różnice wynikają jedynie z czasu potrzebnego na kompilację i testowanie własnych modyfikacji.
NAJWIĘKSZY PROBLEM TKWI W IGNOROWANIU REALNYCH ALTERNATYW NA DESKTOPIE.
Chrome jest “zawsze lepszy”, ale: Edge (również Chromium) ma lepszą integrację z Windows (ochrona przed phishingiem, lepsze zarządzanie pamięcią) i jest domyślnie instalowany na wielu maszynach.
Przeglądarka Edge zdobyła nawet uznanie wśród autorów treści, którymi Eteryu zdaje się posiłkować. Można tam przeczytać że przeglądarka Edge na Windows, oferuje większe bezpieczeństwo od Chrome i nawet stawia się ją obok przeglądarek Vanadium (GrapheneOS), oraz Trivalent (Secureblue) jednak zwraca się uwagę na problemem z telemetrią.
Safari na MacOS oferuje lepszą izolację procesów niż Chrome dzięki głębszej integracji z systemem i
mniejsze ryzyko zero-day (mniejsza baza użytkowników = mniej celów dla ataków).
Czy Eteryu celowo pomija te przeglądarki, by promować Chrome? Choć Edge i Safari są technicznie lepsze w swoich ekosystemach. Jak widać jest to wybiórcza, analiza skupia się na jednym ignorując szerszy kontekst bezpieczeństwa i wydajności.
Podsumowując: To nie jest “ścisła analiza”, tylko subiektywna ocena oparta na preferencjach. Dla prawdziwie bezpiecznej przeglądarki na desktopie lepszym wyborem byłoby Edge (Windows), Safari (Mac). Brave często cenony jest za blokowanie reklam i trackerów.
Linux
Rzeczywistość jest bardziej złożona:
Więcej poniżej👇
##A Dell Secure Connect Gateway vulnerability (CVE-2026-80172, CVSS 9.8) grants unauthorized access via forged admin tokens. Patch SCG now.
#Dell #SecureConnectGateway #CVE202680172 #RCE #UnauthorizedAccess #PatchNow #Infosec #SCG
https://securityonline.info/dell-scg-cve-2026-80172/?utm_source=mastodon&utm_medium=jetpack_social
##A Dell Secure Connect Gateway vulnerability (CVE-2026-80172, CVSS 9.8) grants unauthorized access via forged admin tokens. Patch SCG now.
#Dell #SecureConnectGateway #CVE202680172 #RCE #UnauthorizedAccess #PatchNow #Infosec #SCG
https://securityonline.info/dell-scg-cve-2026-80172/?utm_source=mastodon&utm_medium=jetpack_social
##📢 [VULN] Une VM pour prendre le contrôle de votre PC : patchez VMware Workstation et Fusion - CVE-2026-59346 CVE-2026-59347
Vous utilisez VMware Workstation Pro ou VMware Fusion ? Passez par la case maintenance. Broadcom vient de corriger deux vulnérabilités, dont une critique, qui permettent à un attaquant ayant le contrôle d'une machine virtuelle d'exécuter du code sur la machine hôte. Voici…
🔗 https://www.it-connect.fr/vmware-workstation-et-fusion-failles-vm-escape-septembre-2026/
💬 discussion : https://infosec.pub/post/51979344
#Vulnérabilité #CVE #Cyberveille
📢 [VULN] Une VM pour prendre le contrôle de votre PC : patchez VMware Workstation et Fusion - CVE-2026-59346 CVE-2026-59347
Vous utilisez VMware Workstation Pro ou VMware Fusion ? Passez par la case maintenance. Broadcom vient de corriger deux vulnérabilités, dont une critique, qui permettent à un attaquant ayant le contrôle d'une machine virtuelle d'exécuter du code sur la machine hôte. Voici…
🔗 https://www.it-connect.fr/vmware-workstation-et-fusion-failles-vm-escape-septembre-2026/
💬 discussion : https://infosec.pub/post/51979344
#Vulnérabilité #CVE #Cyberveille
Broadcom Patches VMware Flaws That Expose Hosts to Code Execution
Broadcom has patched a critical VMware flaw that lets attackers with local admin access on a virtual machine execute code on the host, thanks to an integer-overflow vulnerability in the VMXNET3 virtual network adapter. This bug, tracked as CVE-2026-59346, earned a near-perfect CVSS score of 9.3, highlighting the severity of the threat.
##📰 Broadcom Patches Critical VMware VM Escape Vulnerabilities
Broadcom patches critical VMware flaws (CVE-2026-59346, CVSS 9.3) in Workstation & Fusion. Vulnerabilities allow VM escape, enabling code execution on the host system. No active exploits known. #VMware #CyberSecurity #Virtualization #PatchNow
##Broadcom patched two VM escape flaws in VMware Workstation and Fusion. CVE-2026-59346 is an integer overflow in VMXNET3 (CVSS 9.3) allowing host code execution from a privileged VM guest. High risk for dev and lab environments relying on VM isolation. #VmEscape #InfoSec #Virtualization
https://cyberworldops.eu/en/vmware-workstation-and-fusion-two-flaws-allow-escape-from-the-virtual
##📑 Our latest Weekly CVE Roundup is live! We're analyzing a critical RCE in FastAPI-Schema-Validator (CVE-2026-38291) and the emergence of runtime schema injection attacks targeting Python APIs. Essential reading for security pros and Python devs. Read the full analysis: https://cvedatabase.com/blog/weekly-cve-roundup-critical-rce-in-fastapi-ecosystem-and-the-rise-of-schema-inje-2026-08-30 #CVE #FastAPI #Python #CyberSecurity #RCE #SupplyChain
##📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256
Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66
CISA KEVs:
- CISA-2026:0831 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0831)
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70
Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16
Top EPSS Score:
- CVE-2026-79756 - 5.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79756)
- CVE-2026-82688 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82688)
- CVE-2026-82689 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82689)
- CVE-2026-82692 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82692)
- CVE-2026-59680 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59680)
- CVE-2026-85224 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85224)
- CVE-2026-82690 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82690)
- CVE-2026-82691 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82691)
- CVE-2026-85222 - 2.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85222)
- CVE-2026-82702 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82702)
CISA reports CVE-2026-77477 in OPCFoundation UA-LDS-Installers before 1.04.420. A local attacker can abuse the elevated installer session to execute arbitrary commands as SYSTEM. This puts OT discovery hosts at risk of full compromise during deployment. #OpcUa #OtSecurity #IcsSecurity
https://cyberworldops.eu/en/opc-ua-lds-privileged-console-in-installer-exposes-industrial
##CISA reports CVE-2026-77477 in OPCFoundation UA-LDS-Installers before 1.04.420. A local attacker can abuse the elevated installer session to execute arbitrary commands as SYSTEM. This puts OT discovery hosts at risk of full compromise during deployment. #OpcUa #OtSecurity #IcsSecurity
https://cyberworldops.eu/en/opc-ua-lds-privileged-console-in-installer-exposes-industrial
##Release containerd 2.3.5 · containerd/containerd
containerd 2.3.5는 보안 패치(CVE-2026-53495/GHSA-rp3h-jf77-q9p4)를 포함한 2.3 계열의 다섯 번째 패치 릴리스다. 이미지 descriptor URL을 가져올 때 민감한 인증 헤더를 제거하도록 하드닝해 레지스트리 인증 정보 노출 위험을 줄였다. CRI 표준 입출력 스트리밍의 데이터 레이스·교착 상태와 shim 로딩/시작 멈춤 문제를 수정해 Kubernetes 및 컨테이너 기반 AI 워크로드의 런타임 안정성을 개선한다. EROFS 이미지 언팩과 Windows Server 2022 호환성, OpenTelemetry 오류 속성도 보완됐으며, 운영 환...
https://github.com/containerd/containerd/releases/tag/v2.3.5
##🟠 CVE-2026-19534 - High (7.5)
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 respon...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19534/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61686 - High (7.5)
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61686/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63464 - High (7.7)
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-sub...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63464/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85786 - High (7.5)
Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insuff...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85786/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85781 - High (8.7)
Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of direct...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85781/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver
Bulletin ID: 2026-099-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 11:45 AM PDT
Description:
The Amazon EFS CSI Driver is an open-source Kubernetes Container Storage Interface (CSI) dr...
https://aws.amazon.com/security/security-bulletins/rss/2026-099-aws/
##