##
Updated at UTC 2026-08-18T09:14:05.027555
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-15748 | 9.8 | 0.00% | 9 | 1 | 2026-08-18T06:16:40.670000 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload | |
| CVE-2026-75060 | 8.4 | 0.00% | 2 | 0 | 2026-08-18T04:16:47.650000 | In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthentic | |
| CVE-2026-75051 | 8.1 | 0.00% | 2 | 0 | 2026-08-18T04:16:47.300000 | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between | |
| CVE-2026-75045 | 9.1 | 0.00% | 2 | 0 | 2026-08-18T04:16:47.170000 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unau | |
| CVE-2025-62593 | 8.8 | 0.37% | 15 | 0 | 2026-08-18T04:16:40.860000 | Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ra | |
| CVE-2026-75094 | 9.1 | 0.00% | 4 | 0 | 2026-08-18T03:31:14 | A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_ | |
| CVE-2026-73045 | 7.5 | 0.30% | 1 | 0 | 2026-08-18T03:16:40.450000 | SiYuan before 3.7.4 contains an improper restriction of excessive authentication | |
| CVE-2026-11801 | 7.5 | 0.00% | 4 | 0 | 2026-08-18T03:16:38.650000 | The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authori | |
| CVE-2026-67854 | None | 0.00% | 2 | 0 | 2026-08-18T00:30:36 | SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute | |
| CVE-2026-75081 | 4.3 | 0.00% | 2 | 0 | 2026-08-18T00:16:53.710000 | A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unkno | |
| CVE-2026-9816 | 8.3 | 0.00% | 2 | 0 | 2026-08-17T22:17:27.217000 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail | |
| CVE-2026-64849 | 9.3 | 0.00% | 2 | 0 | 2026-08-17T21:58:52 | ### Summary The default MLflow Tracking Server (`mlflow server`, no authenticati | |
| CVE-2026-56677 | 8.6 | 0.00% | 2 | 0 | 2026-08-17T21:58:44 | ### Summary A Server-Side Request Forgery (SSRF) vulnerability exists in the 9R | |
| CVE-2026-75111 | 7.5 | 0.00% | 2 | 0 | 2026-08-17T21:31:35 | Evidently UI fails to properly validate the filename parameter in the dataset ma | |
| CVE-2026-71472 | 9.1 | 0.00% | 2 | 0 | 2026-08-17T21:31:30 | A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authentica | |
| CVE-2026-70495 | 8.8 | 0.00% | 2 | 0 | 2026-08-17T21:31:30 | A flaw was found in search-v2-operator. This component's `search-serviceaccount` | |
| CVE-2026-74234 | 7.7 | 0.00% | 2 | 0 | 2026-08-17T21:31:30 | Legora before 2026-08-14 contains a cross-site scripting vulnerability that allo | |
| CVE-2026-66792 | 9.9 | 0.00% | 2 | 0 | 2026-08-17T21:31:30 | A flaw was found in the multicloud-operators-subscription component. This vulner | |
| CVE-2026-75479 | 7.5 | 0.00% | 2 | 0 | 2026-08-17T21:31:27 | JimuReport contains an authentication bypass vulnerability in the report folder | |
| CVE-2026-75110 | 9.8 | 0.00% | 2 | 0 | 2026-08-17T21:31:27 | MemOS is a memory operating system for LLMs and AI agents. In deployments where | |
| CVE-2026-75482 | 7.5 | 0.00% | 2 | 0 | 2026-08-17T21:16:50.833000 | SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is a | |
| CVE-2026-75481 | 8.8 | 0.00% | 2 | 0 | 2026-08-17T21:16:50.647000 | SkyPilot fails to validate that authenticated users are entitled to grant admini | |
| CVE-2026-75106 | 9.1 | 0.00% | 2 | 0 | 2026-08-17T21:16:49.610000 | OpnForm derives editable-submission secrets from sequential row identifiers usin | |
| CVE-2026-75105 | 7.5 | 0.00% | 2 | 0 | 2026-08-17T21:16:49.473000 | phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the | |
| CVE-2026-75103 | 8.8 | 0.00% | 2 | 0 | 2026-08-17T21:16:49.200000 | Crawlab fails to verify user ownership or administrative role on the password-ch | |
| CVE-2026-19478 | 9.4 | 0.00% | 10 | 2 | 2026-08-17T21:16:43.490000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 | |
| CVE-2026-19714 | 9.1 | 0.16% | 1 | 0 | 2026-08-17T20:16:42.157000 | The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audien | |
| CVE-2026-74238 | 7.5 | 0.00% | 2 | 0 | 2026-08-17T19:16:42.713000 | TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the | |
| CVE-2026-73044 | 9.0 | 0.25% | 1 | 0 | 2026-08-17T19:16:39.737000 | SiYuan versions before v3.7.4 fail to validate or escape table column width valu | |
| CVE-2026-75056 | 7.8 | 0.00% | 2 | 0 | 2026-08-17T18:31:28 | In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was poss | |
| CVE-2026-74791 | 8.6 | 0.27% | 1 | 0 | 2026-08-17T18:18:15.150000 | Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when Template | |
| CVE-2026-73061 | 9.8 | 0.30% | 2 | 0 | 2026-08-17T18:18:13.617000 | Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedOb | |
| CVE-2026-73052 | 9.0 | 0.30% | 2 | 0 | 2026-08-17T18:18:13.377000 | SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and | |
| CVE-2026-73041 | 9.0 | 0.23% | 1 | 0 | 2026-08-17T18:18:12.767000 | SiYuan versions before v3.7.4 fail to validate or escape annotation fields writt | |
| CVE-2026-17123 | 8.8 | 0.36% | 1 | 0 | 2026-08-17T18:16:33.897000 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Req | |
| CVE-2026-71479 | 9.1 | 0.00% | 3 | 0 | 2026-08-17T16:36:14 | ## Summary Multiple billing paths multiplied **user-controlled quantity paramet | |
| CVE-2026-74876 | 9.8 | 0.00% | 1 | 0 | 2026-08-17T16:17:50.397000 | openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle | |
| CVE-2026-74795 | 7.5 | 0.32% | 1 | 0 | 2026-08-17T16:17:48.827000 | Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its rec | |
| CVE-2026-74790 | 9.1 | 0.29% | 1 | 0 | 2026-08-17T16:17:48.707000 | Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering | |
| CVE-2026-73060 | 7.5 | 0.37% | 2 | 0 | 2026-08-17T16:17:47 | Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerabil | |
| CVE-2026-73042 | 9.0 | 0.30% | 1 | 0 | 2026-08-17T16:17:46.223000 | SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML int | |
| CVE-2026-19983 | 8.3 | 1.31% | 1 | 0 | 2026-08-17T16:16:55.197000 | A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, | |
| CVE-2026-15826 | 9.8 | 0.80% | 2 | 1 | 2026-08-17T16:16:50.140000 | The User Profile Builder plugin for WordPress is vulnerable to Authentication By | |
| CVE-2026-15623 | 0 | 0.20% | 2 | 0 | 2026-08-17T16:16:49.250000 | A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud G | |
| CVE-2026-58231 | 10.0 | 0.73% | 7 | 1 | 2026-08-17T15:39:24.573000 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent | |
| CVE-2026-15218 | 7.9 | 0.00% | 1 | 0 | 2026-08-17T15:30:43 | A flaw was found in the maas-api and maas-controller ServiceAccounts within Red | |
| CVE-2026-74843 | 10.0 | 0.00% | 2 | 0 | 2026-08-17T15:16:58.230000 | A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected | |
| CVE-2026-14564 | 9.0 | 0.00% | 2 | 0 | 2026-08-17T15:16:53.647000 | Insufficiently Protected Credentials vulnerability in Innotim Software Telecommu | |
| CVE-2026-56090 | 7.3 | 0.00% | 1 | 0 | 2026-08-17T14:20:21.077000 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search P | |
| CVE-2026-65400 | 9.8 | 0.50% | 19 | 1 | 2026-08-17T13:16:52.340000 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-74889 | 9.8 | 0.00% | 2 | 0 | 2026-08-17T12:32:31 | openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info para | |
| CVE-2026-74800 | 9.0 | 0.00% | 1 | 0 | 2026-08-17T12:32:26 | SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options | |
| CVE-2026-74845 | 8.8 | 0.94% | 2 | 0 | 2026-08-17T12:32:26 | Official Document Management System developed by 2100 Technology has an Arbitrar | |
| CVE-2026-19981 | 7.4 | 1.05% | 1 | 0 | 2026-08-17T06:33:56 | A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600 | |
| CVE-2026-72407 | 10.0 | 0.52% | 2 | 0 | 2026-08-17T06:19:07.453000 | In the Linux kernel, the following vulnerability has been resolved: geneve: val | |
| CVE-2026-50602 | None | 0.10% | 2 | 0 | 2026-08-17T03:30:28 | A security vulnerability has been identified in Planet9 due to incorrect file pe | |
| CVE-2026-19961 | 9.9 | 0.47% | 4 | 0 | 2026-08-17T00:31:35 | A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function | |
| CVE-2026-19959 | 9.9 | 0.47% | 4 | 0 | 2026-08-16T23:16:24.710000 | A weakness has been identified in Edimax EW-7478APC 1.04. This affects the funct | |
| CVE-2026-65775 | 7.8 | 2.45% | 2 | 0 | 2026-08-16T19:17:18.030000 | Use after free in Windows Win32K allows an authorized attacker to elevate privil | |
| CVE-2026-62696 | 7.8 | 3.17% | 2 | 0 | 2026-08-16T19:16:52.950000 | Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistan | |
| CVE-2026-61358 | 7.8 | 3.68% | 2 | 0 | 2026-08-16T19:16:48.360000 | Improper link resolution before file access ('link following') in Windows Access | |
| CVE-2026-74789 | 7.5 | 0.34% | 2 | 0 | 2026-08-16T15:30:38 | Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only t | |
| CVE-2026-74794 | 7.5 | 0.28% | 1 | 0 | 2026-08-16T15:30:38 | Scriban before 6.6.0 contains an infinite recursion vulnerability in object rend | |
| CVE-2026-74792 | 7.5 | 0.31% | 1 | 0 | 2026-08-16T15:30:38 | Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vuln | |
| CVE-2026-73056 | 9.8 | 0.45% | 4 | 0 | 2026-08-16T15:30:33 | SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive | |
| CVE-2026-74788 | 7.5 | 0.28% | 3 | 0 | 2026-08-16T15:30:33 | Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memor | |
| CVE-2026-74783 | 7.5 | 0.28% | 1 | 0 | 2026-08-16T15:30:33 | Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimi | |
| CVE-2026-74787 | 7.5 | 0.28% | 3 | 0 | 2026-08-16T15:30:26 | Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the obj | |
| CVE-2026-73062 | 7.5 | 0.28% | 2 | 0 | 2026-08-16T15:30:26 | Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability i | |
| CVE-2026-73057 | 7.5 | 0.28% | 2 | 0 | 2026-08-16T15:30:25 | stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy en | |
| CVE-2026-74251 | None | 0.37% | 2 | 1 | 2026-08-16T15:30:24 | Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filte | |
| CVE-2026-17087 | 7.5 | 0.41% | 1 | 0 | 2026-08-16T09:30:22 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for W | |
| CVE-2026-18316 | 9.1 | 0.32% | 2 | 0 | 2026-08-16T06:30:37 | The Solace Extra plugin for WordPress is vulnerable to unauthorized modification | |
| CVE-2026-18432 | 9.8 | 0.45% | 2 | 0 | 2026-08-16T06:30:32 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege | |
| CVE-2026-14524 | 9.1 | 0.70% | 2 | 0 | 2026-08-16T06:30:32 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file d | |
| CVE-2026-16099 | 8.8 | 0.59% | 1 | 0 | 2026-08-16T06:30:32 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary fi | |
| CVE-2026-14498 | 8.8 | 0.55% | 1 | 0 | 2026-08-16T06:30:31 | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution i | |
| CVE-2026-16098 | 9.8 | 0.64% | 2 | 0 | 2026-08-16T05:16:47.667000 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U | |
| CVE-2026-19924 | 9.8 | 0.90% | 2 | 0 | 2026-08-16T03:31:11 | A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01 | |
| CVE-2026-73053 | 9.0 | 0.28% | 2 | 0 | 2026-08-16T00:31:35 | SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th | |
| CVE-2026-73054 | 7.5 | 0.31% | 1 | 0 | 2026-08-16T00:31:35 | SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in | |
| CVE-2026-73055 | 4.8 | 0.21% | 1 | 0 | 2026-08-16T00:31:29 | Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde ( | |
| CVE-2026-73050 | 9.0 | 0.25% | 1 | 0 | 2026-08-16T00:31:28 | SiYuan versions before v3.7.4 fail to validate or escape the color field in attr | |
| CVE-2026-73046 | 9.8 | 0.43% | 1 | 0 | 2026-08-16T00:31:27 | SiYuan before v3.7.4 improperly restricts excessive authentication attempts in t | |
| CVE-2026-73043 | 9.0 | 0.37% | 1 | 0 | 2026-08-16T00:31:26 | SiYuan versions before v3.7.4 contain a remote code execution vulnerability in t | |
| CVE-2026-69414 | 7.8 | 0.24% | 2 | 2 | 2026-08-15T00:31:32 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect | |
| CVE-2026-19188 | 10.0 | 1.89% | 2 | 0 | 2026-08-14T19:17:17.480000 | A critical OS command injection vulnerability has been identified in the Haiwel | |
| CVE-2026-19681 | 9.9 | 2.24% | 2 | 0 | 2026-08-14T18:31:46 | An authenticated command injection vulnerability exists in Security Center relat | |
| CVE-2026-59310 | 9.8 | 1.14% | 4 | 2 | 2026-08-14T05:16:59.407000 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-19771 | 7.2 | 2.79% | 2 | 0 | 2026-08-14T03:31:33 | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This im | |
| CVE-2026-19747 | 9.8 | 2.36% | 2 | 0 | 2026-08-13T21:36:14 | A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B | |
| CVE-2026-55040 | 9.1 | 3.97% | 1 | 2 | 2026-08-13T15:34:13 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attack | |
| CVE-2026-73268 | 9.9 | 0.37% | 2 | 0 | 2026-08-12T21:31:50 | A flaw was found in the cluster-curator-controller component of multicluster eng | |
| CVE-2026-50656 | 7.8 | 10.75% | 1 | 4 | 2026-08-12T18:31:00 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect | |
| CVE-2026-72526 | 9.9 | 0.30% | 2 | 0 | 2026-08-12T03:31:18 | A flaw was found in the multicloud-integrations component. The Application propa | |
| CVE-2026-68820 | 7.0 | 0.33% | 4 | 2 | 2026-08-11T21:33:01 | Use after free in Windows Ancillary Function Driver for WinSock allows an author | |
| CVE-2026-66804 | 7.8 | 3.42% | 4 | 2 | 2026-08-11T18:31:49 | Improper access control in Windows Cross Device Service allows an authorized att | |
| CVE-2026-62832 | 7.8 | 2.37% | 2 | 0 | 2026-08-11T18:31:33 | Improper link resolution before file access ('link following') in Windows User P | |
| CVE-2026-6837 | 7.2 | 0.95% | 2 | 1 | 2026-08-04T03:31:16 | A post-authentication command injection vulnerability in the "export-cgi" CGI pr | |
| CVE-2026-43774 | 5.5 | 0.13% | 2 | 0 | 2026-07-29T19:32:51.167000 | An out-of-bounds read was addressed with improved bounds checking. This issue is | |
| CVE-2026-54121 | 8.8 | 1.05% | 5 | 12 | 2026-07-14T18:32:37 | Improper authorization in Active Directory Certificate Services (AD CS) allows a | |
| CVE-2026-8452 | 9.8 | 0.49% | 8 | 2 | 2026-07-01T18:32:28 | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp | |
| CVE-2026-12569 | 9.8 | 30.20% | 2 | 1 | 2026-06-26T15:33:15 | A critical remote code execution (RCE) vulnerability has been reported in PTC Wi | |
| CVE-2026-42228 | 6.5 | 0.38% | 1 | 1 | 2026-06-17T10:47:32.723000 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, | |
| CVE-2026-32193 | 8.8 | 0.34% | 2 | 0 | 2026-06-09T18:30:48 | Improper limitation of a pathname to a restricted directory ('path traversal') i | |
| CVE-2026-44012 | None | 0.34% | 1 | 0 | 2026-05-13T16:29:55 | ## Summary `AssetsController::actionShowInFolder()` fetches an asset by ID and | |
| CVE-2026-33696 | 9.9 | 0.77% | 1 | 0 | 2026-03-26T16:41:02 | ## Impact An authenticated user with permission to create or modify workflows co | |
| CVE-2026-3286 | 6.3 | 0.31% | 2 | 0 | 2026-02-27T06:31:39 | A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. Th | |
| CVE-2024-39302 | 0 | 0.45% | 2 | 0 | N/A | ||
| CVE-2026-45790 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-71424 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-45698 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-62356 | 0 | 0.00% | 10 | 0 | N/A | ||
| CVE-2026-17106 | 0 | 0.00% | 2 | 3 | N/A | ||
| CVE-2024-69414 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-72898 | 0 | 10.40% | 3 | 6 | template | N/A | |
| CVE-2026-73296 | 0 | 2.61% | 2 | 0 | N/A | ||
| CVE-2026-73554 | 0 | 0.00% | 1 | 0 | N/A |
updated 2026-08-18T06:16:40.670000
9 posts
1 repos
CVE-2026-15748 (CRITICAL, CVSS 9.8): wpmudev Forminator Forms for WordPress up to 1.56.1 lets unauthenticated attackers upload dangerous files via handle_file_upload, risking remote code execution. Patch urgently: https://radar.offseq.com/threat/cve-2026-15748-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-wpmudev-forminator-forms-087a3235e4aa61cd #OffSeq #WordPress #Vuln
##「Forminator WordPressの脆弱性により、悪意のあるPHPファイルのアップロードを介して認証なしのリモートコード実行が可能になる 」: #TheHackerNews
「0万件以上のインストール実績を持つWordPressプラグイン「Forminator Forms」に、重大なセキュリティ上の欠陥が発見された。この欠陥を悪用すれば、脆弱性のあるサイトで任意のコードを実行できる可能性がある。
CVE-2026-15748 として追跡されているこの脆弱性は 、CVSSスコアリングシステムで10点満点中9.8点と評価されている。この脆弱性は、「daroo」というオンライン上のニックネームを持つセキュリティ研究者によって発見され、報告された。
https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html
##CVE-2026-15748 (CVSS 9.8): Forminator Flaw Enables Pre-Auth RCE
##Two critical flaws disclosed in WordPress plugins: Forminator Forms (CVE-2026-15748) allows unauthenticated PHP file upload leading to RCE, and User Profile Builder (CVE-2026-15826) lets unauthenticated attackers authenticate as the site admin. Both can result in full site compromise.
#WordPressSecurity #CVE #RemoteCodeExecution #InfoSec
https://cyberworldops.eu/en/two-critical-wordpress-plugin-vulnerabilities-could-lead-to-full-site
##WordPress Plugin Flaw Enables Unauthenticated Remote Code Execution
A critical vulnerability in the Forminator Forms WordPress plugin can let hackers upload malicious PHP files to your site, allowing them to take control and wreak havoc - all without needing a login. This flaw, tracked as CVE-2026-15748, has a near-perfect severity score of 9.8, making it a high-priority threat.
#RemoteCodeExecution #Wordpress #Cve202615748 #ArbitraryFileUpload #PluginVulnerability
##CVE-2026-15748 (CRITICAL, CVSS 9.8): wpmudev Forminator Forms for WordPress up to 1.56.1 lets unauthenticated attackers upload dangerous files via handle_file_upload, risking remote code execution. Patch urgently: https://radar.offseq.com/threat/cve-2026-15748-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-wpmudev-forminator-forms-087a3235e4aa61cd #OffSeq #WordPress #Vuln
##「Forminator WordPressの脆弱性により、悪意のあるPHPファイルのアップロードを介して認証なしのリモートコード実行が可能になる 」: #TheHackerNews
「0万件以上のインストール実績を持つWordPressプラグイン「Forminator Forms」に、重大なセキュリティ上の欠陥が発見された。この欠陥を悪用すれば、脆弱性のあるサイトで任意のコードを実行できる可能性がある。
CVE-2026-15748 として追跡されているこの脆弱性は 、CVSSスコアリングシステムで10点満点中9.8点と評価されている。この脆弱性は、「daroo」というオンライン上のニックネームを持つセキュリティ研究者によって発見され、報告された。
https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html
##CVE-2026-15748 (CVSS 9.8): Forminator Flaw Enables Pre-Auth RCE
##Two critical flaws disclosed in WordPress plugins: Forminator Forms (CVE-2026-15748) allows unauthenticated PHP file upload leading to RCE, and User Profile Builder (CVE-2026-15826) lets unauthenticated attackers authenticate as the site admin. Both can result in full site compromise.
#WordPressSecurity #CVE #RemoteCodeExecution #InfoSec
https://cyberworldops.eu/en/two-critical-wordpress-plugin-vulnerabilities-could-lead-to-full-site
##updated 2026-08-18T04:16:47.650000
2 posts
🟠 CVE-2026-75060 - High (8.4)
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75060/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75060 - High (8.4)
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75060/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T04:16:47.300000
2 posts
🟠 CVE-2026-75051 - High (8.1)
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75051/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75051 - High (8.1)
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75051/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T04:16:47.170000
2 posts
JetBrains patched CVE-2026-75045, a critical YouTrack flaw letting an unauthenticated attacker download database backups.
#CVE202675045 #YouTrack #JetBrains #DatabaseBackup #DataBreach #PatchNow
##JetBrains patched CVE-2026-75045, a critical YouTrack flaw letting an unauthenticated attacker download database backups.
#CVE202675045 #YouTrack #JetBrains #DatabaseBackup #DataBreach #PatchNow
##updated 2026-08-18T04:16:40.860000
15 posts
CISA Warns of Actively Exploited Ray Flaw Enabling Browser-Based RCE
A critical vulnerability, CVE-2025-62593, is under active exploitation, allowing hackers to execute remote code through web browsers like Firefox and Safari by using a clever DNS rebinding attack. This high-severity flaw, with a CVSS score of 9.4, stems from a weakness in the Ray project's defenses against browser-based…
#RemoteCodeExecution #Ray #Cve202562593 #BrowserbasedAttacks #DnsRebinding
##🚨 [CISA-2026:0817] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-62593 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-62593)
- Name: Ray-Project Ray Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ray-Project
- Product: Ray
- Notes: https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v ; https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-62593
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260817 #cisa20260817 #cve_2025_62593 #cve202562593
##🚨 NEW CISA KEV: CVE-2025-62593 - Ray. Active RCE weaponization via DNS rebinding targeting developers on Firefox/Safari. Vendor patch 2.52.0 is mandatory. Get the full T-Suite brief & SOC detection queries to secure your Precinct Hybrid architecture. Command the wire. Link below 👇
https://thecybermind.co/jily
#CyberSecurity
CVE ID: CVE-2025-62593
Vendor: Ray-Project
Product: Ray
Date Added: 2026-08-17
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2025-62593
🚨 [CISA-2026:0818] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-62593 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-62593)
- Name: Ray-Project Ray Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ray-Project
- Product: Ray
- Notes: https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v ; https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-62593
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260818 #cisa20260818 #cve_2025_62593 #cve202562593
##CISA confirms CVE-2025-62593, a Ray code injection RCE, is exploited in the wild. A public PoC targets Firefox and Safari.
#CVE202562593 #Ray #RemoteCodeExecution #DNSRebinding #KEV #ExploitedInTheWild
https://securityonline.info/cve-2025-62593-ray-rce/?utm_source=mastodon&utm_medium=jetpack_social
##CISA has added one known vulnerability to the KEV catalogue.
- CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-62593 #CISA #infosec #vulnerability
##CVE ID: CVE-2025-62593
Vendor: Ray-Project
Product: Ray
Date Added: 2026-08-18
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2025-62593
🚨 [CISA-2026:0817] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-62593 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-62593)
- Name: Ray-Project Ray Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ray-Project
- Product: Ray
- Notes: https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v ; https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-62593
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260817 #cisa20260817 #cve_2025_62593 #cve202562593
##🚨 NEW CISA KEV: CVE-2025-62593 - Ray. Active RCE weaponization via DNS rebinding targeting developers on Firefox/Safari. Vendor patch 2.52.0 is mandatory. Get the full T-Suite brief & SOC detection queries to secure your Precinct Hybrid architecture. Command the wire. Link below 👇
https://thecybermind.co/jily
#CyberSecurity
CVE ID: CVE-2025-62593
Vendor: Ray-Project
Product: Ray
Date Added: 2026-08-17
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2025-62593
🚨 [CISA-2026:0818] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-62593 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-62593)
- Name: Ray-Project Ray Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ray-Project
- Product: Ray
- Notes: https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v ; https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-62593
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260818 #cisa20260818 #cve_2025_62593 #cve202562593
##CISA confirms CVE-2025-62593, a Ray code injection RCE, is exploited in the wild. A public PoC targets Firefox and Safari.
#CVE202562593 #Ray #RemoteCodeExecution #DNSRebinding #KEV #ExploitedInTheWild
https://securityonline.info/cve-2025-62593-ray-rce/?utm_source=mastodon&utm_medium=jetpack_social
##CISA has added one known vulnerability to the KEV catalogue.
- CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-62593 #CISA #infosec #vulnerability
##CVE ID: CVE-2025-62593
Vendor: Ray-Project
Product: Ray
Date Added: 2026-08-18
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2025-62593
updated 2026-08-18T03:31:14
4 posts
CVE-2026-75094: CRITICAL OS command injection in COMFAST CF-N1-S v2.6.0.1. Exploit code is public, no official patch. Restrict access to /cgi-bin/mbox-config to reduce risk. Details: https://radar.offseq.com/threat/cve-2026-75094-os-command-injection-in-comfast-cf-n1-s-07737fa4c8cac0ee #OffSeq #CVE #IoT #Security
##🔴 CVE-2026-75094 - Critical (9.1)
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injectio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75094/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-75094: CRITICAL OS command injection in COMFAST CF-N1-S v2.6.0.1. Exploit code is public, no official patch. Restrict access to /cgi-bin/mbox-config to reduce risk. Details: https://radar.offseq.com/threat/cve-2026-75094-os-command-injection-in-comfast-cf-n1-s-07737fa4c8cac0ee #OffSeq #CVE #IoT #Security
##🔴 CVE-2026-75094 - Critical (9.1)
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injectio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75094/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T03:16:40.450000
1 posts
🟠 CVE-2026-73045 - High (7.5)
SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73045/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T03:16:38.650000
4 posts
🟠 CVE-2026-11801 - High (7.5)
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This make...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11801/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##WPAdverts – Classifieds Plugin <=2.3.2 hit by HIGH severity CWE-862 auth bypass (CVE-2026-11801). Unauthenticated users can access internal config data via REST API. Restrict endpoints & monitor for fixes. https://radar.offseq.com/threat/cve-2026-11801-cwe-862-missing-authorization-in-gwin-wpadverts-classifieds-plugin-89cace2672af27dd #OffSeq #WordPress #Vulnerability
##🟠 CVE-2026-11801 - High (7.5)
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This make...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11801/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##WPAdverts – Classifieds Plugin <=2.3.2 hit by HIGH severity CWE-862 auth bypass (CVE-2026-11801). Unauthenticated users can access internal config data via REST API. Restrict endpoints & monitor for fixes. https://radar.offseq.com/threat/cve-2026-11801-cwe-862-missing-authorization-in-gwin-wpadverts-classifieds-plugin-89cace2672af27dd #OffSeq #WordPress #Vulnerability
##updated 2026-08-18T00:30:36
2 posts
SQL Injection flaw (CVE-2026-67854) in Qcms v6.0.6 rated CRITICAL: remote code execution risk. No official patch. Restrict access & monitor for injection attempts. Details: https://radar.offseq.com/threat/sql-injection-vulnerability-in-qcms-v606-allows-a-remote-attacker-to-execute-arbitrary-code-cve-2026-3286c90b2be69269 #OffSeq #SQLInjection #Vulnerability #Qcms #InfoSec
##SQL Injection flaw (CVE-2026-67854) in Qcms v6.0.6 rated CRITICAL: remote code execution risk. No official patch. Restrict access & monitor for injection attempts. Details: https://radar.offseq.com/threat/sql-injection-vulnerability-in-qcms-v606-allows-a-remote-attacker-to-execute-arbitrary-code-cve-2026-3286c90b2be69269 #OffSeq #SQLInjection #Vulnerability #Qcms #InfoSec
##updated 2026-08-18T00:16:53.710000
2 posts
CVE-2026-75081 (MEDIUM): Webkul Bagisto ≤2.4.4 has a vuln in /customer/account/rma/store. Public exploit exists — remote attackers may abuse RMA workflow. Monitor for suspicious RMA activity. https://radar.offseq.com/threat/cve-2026-75081-enforcement-of-behavioral-workflow-in-webkul-bagisto-ee135525efc80a57 #OffSeq #Bagisto #Vuln #Infosec
##CVE-2026-75081 (MEDIUM): Webkul Bagisto ≤2.4.4 has a vuln in /customer/account/rma/store. Public exploit exists — remote attackers may abuse RMA workflow. Monitor for suspicious RMA activity. https://radar.offseq.com/threat/cve-2026-75081-enforcement-of-behavioral-workflow-in-webkul-bagisto-ee135525efc80a57 #OffSeq #Bagisto #Vuln #Infosec
##updated 2026-08-17T22:17:27.217000
2 posts
🟠 CVE-2026-9816 - High (8.3)
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board adm...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9816/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-9816 - High (8.3)
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board adm...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9816/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:58:52
2 posts
🔴 CVE-2026-64849 - Critical (9.3)
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/va...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64849/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-64849 - Critical (9.3)
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/va...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64849/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:58:44
2 posts
🟠 CVE-2026-56677 - High (8.6)
9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js without restri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56677/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-56677 - High (8.6)
9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js without restri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56677/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:35
2 posts
🟠 CVE-2026-75111 - High (7.5)
Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75111/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75111 - High (7.5)
Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75111/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:30
2 posts
🔴 CVE-2026-71472 - Critical (9.1)
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_M...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71472/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71472 - Critical (9.1)
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_M...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71472/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:30
2 posts
🟠 CVE-2026-70495 - High (8.8)
A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70495/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-70495 - High (8.8)
A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70495/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:30
2 posts
🟠 CVE-2026-74234 - High (7.7)
Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter directive...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74234/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74234 - High (7.7)
Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter directive...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74234/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:30
2 posts
🔴 CVE-2026-66792 - Critical (9.9)
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-66792 - Critical (9.9)
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:27
2 posts
🟠 CVE-2026-75479 - High (7.5)
JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75479/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75479 - High (7.5)
JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75479/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:31:27
2 posts
🔴 CVE-2026-75110 - Critical (9.8)
MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the is_internal_request() check ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75110/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75110 - Critical (9.8)
MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the is_internal_request() check ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75110/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:16:50.833000
2 posts
🟠 CVE-2026-75482 - High (7.5)
SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the buil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75482 - High (7.5)
SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the buil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:16:50.647000
2 posts
🟠 CVE-2026-75481 - High (8.8)
SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75481/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75481 - High (8.8)
SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75481/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:16:49.610000
2 posts
🔴 CVE-2026-75106 - Critical (9.1)
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission da...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75106 - Critical (9.1)
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission da...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:16:49.473000
2 posts
🟠 CVE-2026-75105 - High (7.5)
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75105/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75105 - High (7.5)
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75105/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:16:49.200000
2 posts
🟠 CVE-2026-75103 - High (8.8)
Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change admi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75103/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75103 - High (8.8)
Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change admi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75103/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T21:16:43.490000
10 posts
2 repos
https://thecybersecguru.com/news/cve-2026-19478-gitlab-graphql-vulnerability/
##Critical GitLab GraphQL Vulnerability Puts Public Projects at Risk — Administrators Urged to Patch Immediately
A Dangerous New Threat Inside a Trusted DevOps Platform GitLab has released an emergency security update after discovering a critical vulnerability that could allow unauthenticated attackers to remotely modify or delete public projects and user data. Tracked as CVE-2026-19478, the flaw carries a CVSS score of 9.4/10, placing it among the most serious…
##GitLab addressed a critical GraphQL flaw, CVE-2026-19478, with a CVSS score of 9.4, allowing attackers to modify or delete projects in GitLab CE and EE. This poses serious risks to code repositories and requires immediate patching to prevent exploitation. #GitLabCVE #GraphQLFlaw #CyberSecurityUpdate #InfoSecCritical
https://cyberworldops.eu/en/gitlab-fixes-critical-graphql-flaw-that-could-modify-or-delete
##🏆 New Achievement! Delete Yourself From This Industry!
Welcome to Module 9: GraphQL Directive Hygiene. Today's learning objective: CVE-2026-19478, a CVSS 9.4 flaw in GitLab Community and Enterprise Edition that allows a completely unauthenticated attacker — no credentials, no victim interaction, no participation trophy — to remotely modify or delete public projects and user data. (1/2)
##GitLab patched CVE-2026-19478, a CVSS 9.4 GraphQL code injection flaw letting unauthenticated users alter or delete project data.
#CVE202619478 #GitLab #CodeInjection #GraphQL #CVE202619650 #PatchNow
##Unauthenticated remote code execution in GitLab.
Update to 19.2.4 / 19.1.6 / 19.0.8 / 18.11.11!
GitLab addressed a critical GraphQL flaw, CVE-2026-19478, with a CVSS score of 9.4, allowing attackers to modify or delete projects in GitLab CE and EE. This poses serious risks to code repositories and requires immediate patching to prevent exploitation. #GitLabCVE #GraphQLFlaw #CyberSecurityUpdate #InfoSecCritical
https://cyberworldops.eu/en/gitlab-fixes-critical-graphql-flaw-that-could-modify-or-delete
##🏆 New Achievement! Delete Yourself From This Industry!
Welcome to Module 9: GraphQL Directive Hygiene. Today's learning objective: CVE-2026-19478, a CVSS 9.4 flaw in GitLab Community and Enterprise Edition that allows a completely unauthenticated attacker — no credentials, no victim interaction, no participation trophy — to remotely modify or delete public projects and user data. (1/2)
##GitLab patched CVE-2026-19478, a CVSS 9.4 GraphQL code injection flaw letting unauthenticated users alter or delete project data.
#CVE202619478 #GitLab #CodeInjection #GraphQL #CVE202619650 #PatchNow
##Unauthenticated remote code execution in GitLab.
Update to 19.2.4 / 19.1.6 / 19.0.8 / 18.11.11!
updated 2026-08-17T20:16:42.157000
1 posts
CVE-2026-19714 (CRITICAL): Simple JWT Login <3.6.8 for WordPress fails to validate Google token audiences. Sites with Google sign-in enabled risk admin impersonation & takeover. Disable Google sign-in or update ASAP. https://radar.offseq.com/threat/cve-2026-19714-cwe-287-improper-authentication-in-simple-jwt-login-2d90d2253c004239 #OffSeq #WordPress #CVE202619714
##updated 2026-08-17T19:16:42.713000
2 posts
🟠 CVE-2026-74238 - High (7.5)
TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap mem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74238/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74238 - High (7.5)
TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap mem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74238/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T19:16:39.737000
1 posts
🔴 CVE-2026-73044 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73044/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T18:31:28
2 posts
🟠 CVE-2026-75056 - High (7.8)
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75056 - High (7.8)
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T18:18:15.150000
1 posts
🟠 CVE-2026-74791 - High (8.6)
Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to acce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74791/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T18:18:13.617000
2 posts
🔴 CVE-2026-73061 - Critical (9.8)
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73061/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73061 - Critical (9.8)
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73061/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T18:18:13.377000
2 posts
CVE-2026-73052: CRITICAL XSS in SiYuan (<3.7.4) enables arbitrary JS & potential code execution if Node integration is enabled. Desktop users most at risk — upgrade ASAP & disable Node integration where possible. https://radar.offseq.com/threat/cve-2026-73052-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-c5f0eb8b5e84714b #OffSeq #XSS #SiYuan #Infosec
##🔴 CVE-2026-73052 - Critical (9)
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73052/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T18:18:12.767000
1 posts
🔴 CVE-2026-73041 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73041/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T18:16:33.897000
1 posts
🟠 CVE-2026-17123 - High (8.8)
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-control...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17123/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T16:36:14
3 posts
New API integer overflow: one request turned a $0.10 balance into $16.9T
OpenAI 호환 셀프호스팅 LLM 게이트웨이 New API의 CVE-2026-71479는 이미지 수량(n), 비디오 작업 시간, 출력 토큰량 등 클라이언트 입력값의 상한 미검증으로 발생하는 정수 오버플로 취약점이다. v1.0.0-rc.17 이하에서는 과금 정산 단계의 int64 값이 음수로 래핑되어, 소액 잔액 계정이 한 번의 요청으로 사실상 무제한 크레딧을 얻고 사용량 원장을 오염시킬 수 있다. 취약점은 야생에서 악용된 것으로 보고됐으며, v1.0.0-rc.18부터 입력 범위 제한과 포화(saturating) quo...
https://hellorecon.com/blog/cve-2026-71479-new-api-quota-integer-overflow
##CVE-2026-71479, an integer overflow in New API billing, is exploited in the wild to inflate user account balances.
#CVE202671479 #IntegerOverflow #NewAPI #ExploitedInTheWild #AIGateway #BillingFraud
##CVE-2026-71479, an integer overflow in New API billing, is exploited in the wild to inflate user account balances.
#CVE202671479 #IntegerOverflow #NewAPI #ExploitedInTheWild #AIGateway #BillingFraud
##updated 2026-08-17T16:17:50.397000
1 posts
CVE-2026-74876 - Critical crypto flaw in openssl_encrypt <1.4.0. Unverified key bundles allow secret leakage via attacker-controlled keys. CVSS 9.8. Unpatched - update immediately. #CVE #infosec #cryptography
##updated 2026-08-17T16:17:48.827000
1 posts
🟠 CVE-2026-74795 - High (7.5)
Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74795/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T16:17:48.707000
1 posts
🔴 CVE-2026-74790 - Critical (9.1)
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74790/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T16:17:47
2 posts
🟠 CVE-2026-73060 - High (7.5)
Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73060/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73060 - High (7.5)
Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73060/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T16:17:46.223000
1 posts
🔴 CVE-2026-73042 - Critical (9)
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73042/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-17T16:16:55.197000
1 posts
CVE-2026-19983 - Critical OS command injection in GL.iNet routers (A1300, AX1800, MT3000, etc.) via NAS service. CVSS 8.3. Remote exploitation possible. Unpatched in 4.8.x - upgrade to 4.9.0 now. #CVE #infosec #GLiNet
##updated 2026-08-17T16:16:50.140000
2 posts
1 repos
Two critical flaws disclosed in WordPress plugins: Forminator Forms (CVE-2026-15748) allows unauthenticated PHP file upload leading to RCE, and User Profile Builder (CVE-2026-15826) lets unauthenticated attackers authenticate as the site admin. Both can result in full site compromise.
#WordPressSecurity #CVE #RemoteCodeExecution #InfoSec
https://cyberworldops.eu/en/two-critical-wordpress-plugin-vulnerabilities-could-lead-to-full-site
##Two critical flaws disclosed in WordPress plugins: Forminator Forms (CVE-2026-15748) allows unauthenticated PHP file upload leading to RCE, and User Profile Builder (CVE-2026-15826) lets unauthenticated attackers authenticate as the site admin. Both can result in full site compromise.
#WordPressSecurity #CVE #RemoteCodeExecution #InfoSec
https://cyberworldops.eu/en/two-critical-wordpress-plugin-vulnerabilities-could-lead-to-full-site
##updated 2026-08-17T16:16:49.250000
2 posts
CVE-2026-15623: CRITICAL SQL Injection vuln (CVSS 9.4) in Google Cloud Google SecOps (Chronicle SOAR) <6.3.85. Auth attackers could run blind SQL queries. Google patched server-side — no customer action needed. https://radar.offseq.com/threat/cve-2026-15623-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-f5c28e40dedcd311 #OffSeq #GoogleCloud #Infosec
##CVE-2026-15623: CRITICAL SQL Injection vuln (CVSS 9.4) in Google Cloud Google SecOps (Chronicle SOAR) <6.3.85. Auth attackers could run blind SQL queries. Google patched server-side — no customer action needed. https://radar.offseq.com/threat/cve-2026-15623-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-f5c28e40dedcd311 #OffSeq #GoogleCloud #Infosec
##updated 2026-08-17T15:39:24.573000
7 posts
1 repos
“A maximum-severity bug in SAP Commerce Cloud was exploited in the wild, research group Defused posted on X Aug. 14.
The 10.0 bug — CVE-2026-58231 — was described as having insufficient authorization checks and input validation and was earlier patched by SAP on Aug. 11.”
https://www.scworld.com/news/critical-sap-commerce-cloud-flaw-exploited-days-after-patch
##「SAP Commerce Cloudの脆弱性CVE-2026-58231が、パッチ適用後数日で悪用される試みの標的となる 」: #TheHackerNews
「SAP Commerce Cloudに影響を与える、最も深刻なセキュリティ脆弱性について、現在活発な悪用活動が行われています。
CVE-2026-58231 として追跡されているこの脆弱性は、 CVSSスコアリングシステムで10.0と評価されています。これは、認証チェックと入力検証が不十分なケースに関連しています。
CVE.orgによると、「SAP Commerce Cloudでは、認証されていない攻撃者がデフォルトの認証クライアントを悪用し、十分な検証が行われていない特定の機能に特別に細工された入力を送信できる」とのことです。
「脆弱性を悪用されると、任意のコード実行が可能になり、内部コンポーネントが侵害される可能性があり、アプリケーションの機密性、完全性、可用性に重大な影響を与える可能性があります。」 」
https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html
##📰 Critical SAP Commerce Cloud Flaw (CVE-2026-58231) Under Active Attack
Max-severity SAP Commerce Cloud flaw (CVE-2026-58231, CVSS 10.0) is under active attack just days after patch release. The unauthenticated RCE affects major e-commerce platforms. #SAP #RCE #PatchNow
##SAP Exploits Maximum-Severity Commerce Cloud Flaw in Active Attacks
SAP Commerce Cloud has a critical vulnerability, known as CVE-2026-58231, that allows unauthenticated attackers to wreak havoc by executing arbitrary code and compromising internal components. This maximum-severity flaw, scoring a perfect 10.0 on the CVSS scale, stems from weak authorization checks and input validation.
#SapCommerceCloud #Cve202658231 #ZeroDay #EmergingThreats #ArbitraryCodeExecution
##SAP Commerce Cloud Under Attack: Critical CVE-2026-58231 Draws Active Exploitation Attempts Just Days After Patch Release
A Maximum-Severity Flaw Has Entered the Attacker Crosshairs Enterprise security teams are once again facing a familiar but increasingly dangerous race: vendors release a critical security patch, defenders begin testing it, and attackers immediately start looking for systems that have not yet been updated. That is now the situation surrounding…
##“A maximum-severity bug in SAP Commerce Cloud was exploited in the wild, research group Defused posted on X Aug. 14.
The 10.0 bug — CVE-2026-58231 — was described as having insufficient authorization checks and input validation and was earlier patched by SAP on Aug. 11.”
https://www.scworld.com/news/critical-sap-commerce-cloud-flaw-exploited-days-after-patch
##「SAP Commerce Cloudの脆弱性CVE-2026-58231が、パッチ適用後数日で悪用される試みの標的となる 」: #TheHackerNews
「SAP Commerce Cloudに影響を与える、最も深刻なセキュリティ脆弱性について、現在活発な悪用活動が行われています。
CVE-2026-58231 として追跡されているこの脆弱性は、 CVSSスコアリングシステムで10.0と評価されています。これは、認証チェックと入力検証が不十分なケースに関連しています。
CVE.orgによると、「SAP Commerce Cloudでは、認証されていない攻撃者がデフォルトの認証クライアントを悪用し、十分な検証が行われていない特定の機能に特別に細工された入力を送信できる」とのことです。
「脆弱性を悪用されると、任意のコード実行が可能になり、内部コンポーネントが侵害される可能性があり、アプリケーションの機密性、完全性、可用性に重大な影響を与える可能性があります。」 」
https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html
##updated 2026-08-17T15:30:43
1 posts
CVE-2026-15218 - High-severity RCE risk in Red Hat OpenShift AI. Overprivileged ServiceAccounts could lead to full cluster admin takeover. CVSS 7.9. Patch or restrict access now. #CVE #RedHat #infosec
##updated 2026-08-17T15:16:58.230000
2 posts
CVE-2026-74843 (CRITICAL, CVSS 10.0) impacts Wavlink WN531P3 & WN535M1: stack buffer overflow in export_pingortrace.cgi enables remote, unauthenticated RCE. No patch. Restrict access & monitor activity. Exploit code public. https://radar.offseq.com/threat/cve-2026-74843-stack-based-buffer-overflow-in-wavlink-wn531p3-0ad150d2e4038bcd #OffSeq #CVE202674843 #IoTSecurity
##CVE-2026-74843 (CRITICAL, CVSS 10.0) impacts Wavlink WN531P3 & WN535M1: stack buffer overflow in export_pingortrace.cgi enables remote, unauthenticated RCE. No patch. Restrict access & monitor activity. Exploit code public. https://radar.offseq.com/threat/cve-2026-74843-stack-based-buffer-overflow-in-wavlink-wn531p3-0ad150d2e4038bcd #OffSeq #CVE202674843 #IoTSecurity
##updated 2026-08-17T15:16:53.647000
2 posts
CVE-2026-14564: CRITICAL vuln in Logsign SIEM (6.4.97 – <6.4.114) due to insufficiently protected credentials (CWE-522). High-priv users can retrieve sensitive data. Patch status unknown — restrict access & monitor vendor updates. https://radar.offseq.com/threat/cve-2026-14564-cwe-522-insufficiently-protected-credentials-in-innotim-software-telecommunications-and-42bf4f857150f859 #OffSeq #SIEM #Vuln
##CVE-2026-14564: CRITICAL vuln in Logsign SIEM (6.4.97 – <6.4.114) due to insufficiently protected credentials (CWE-522). High-priv users can retrieve sensitive data. Patch status unknown — restrict access & monitor vendor updates. https://radar.offseq.com/threat/cve-2026-14564-cwe-522-insufficiently-protected-credentials-in-innotim-software-telecommunications-and-42bf4f857150f859 #OffSeq #SIEM #Vuln
##updated 2026-08-17T14:20:21.077000
1 posts
CVE-2026-56090 - High-severity privilege escalation in Dell ObjectScale (pre-4.3.0.1). Uncontrolled search path, local low-priv attacker. CVSS 7.3. Update immediately. #CVE #Dell #infosec
##updated 2026-08-17T13:16:52.340000
19 posts
1 repos
An AI agent built a working exploit for this macOS flaw in four hours
https://thenextweb.com/news/macos-screen-sharing-flaw-cve-2026-65400-monero-miner?utm_source=flipboard&utm_medium=activitypub
Posted into Technology (UK Edition) @technology-uk-edition-FlipboardUK
##An AI agent built a working exploit for this macOS flaw in four hours
https://thenextweb.com/news/macos-screen-sharing-flaw-cve-2026-65400-monero-miner?utm_source=flipboard&utm_medium=activitypub
Posted into TNW - All Stories @tnw-all-stories-thenextweb
##Here's a summary of the latest geopolitical, technology, and cybersecurity news from the last 24-48 hours:
Cybersecurity: Apple patched a critical macOS Screen Sharing vulnerability (CVE-2026-65400) and issued mercenary spyware alerts across 110 countries. Microsoft's August Patch Tuesday fixed 421 vulnerabilities, including an actively exploited Windows zero-day (CVE-2026-68820). France reported a Bloctel data leak exposing three million phone numbers and a DGFiP tax data leak.
Technology: Massive tech layoffs continue in 2026, surpassing last year's totals, as companies shift to "AI-first" strategies; AI "inference" spending now exceeds "training". Elon Musk's SpaceX committed exclusively to NVIDIA GPUs, forming a major AI partnership.
Geopolitics: US-Iran tensions remain high over the Strait of Hormuz, with new threats and defense contracts emerging. Ukraine faces critical Patriot interceptor shortages, threatening its winter air defense.
##⚠️ Important security update for Mac users:
A vulnerability in macOS Screen Sharing (CVE-2026-65400) is being actively exploited.
If you use Screens or another VNC client app to remotely access a Mac, we strongly recommend updating macOS as soon as possible.
##Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
macOS Screen Sharing(VNC, TCP 5900)의 인증 우회 취약점 CVE-2026-65400이 공개 익스플로잇 이후 실제 공격에 악용되고 있다. 인터넷에 5900 포트를 노출한 시스템에서 공격자는 인증 없이 접근한 뒤 root 권한을 획득하고 Monero 채굴기를 설치한 사례가 네덜란드 NCSC에 보고됐다. Apple은 macOS Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9에서 해당 문제를 수정했으므로 AI 개발용...
##Attackers actively exploit the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. Discover how to protect your Mac from root access and cryptominers.
#macOS #CVE202665400 #ScreenSharing #Vulnerability #Cybersecurity
##CVE-2026-65400 (HIGH) - macOS Screen Sharing vuln lets remote attackers bypass auth and gain root. Active exploitation seen, mainly on systems with port 5900 open. Patch Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9. https://radar.offseq.com/threat/recent-macos-screen-sharing-vulnerability-exploited-in-attacks-6aa0fe0406c5717d #OffSeq #macOS #infosec #vuln
##A recently patched Apple macOS security vulnerability is being actively exploited in the wild to deploy crypto-mining malware, researchers have warned.
The flaw, tracked as CVE-2026-65400, is a critical authentication vulnerability in the Screen Sharing component and could allow an attacker to gain root access.
🏆 New Achievement! Screen Sharing Is Caring (About My Monero Wallet)!
Allow me to monologue, as any proper villain must. CVE-2026-65400 — a gorgeous authentication bypass in macOS Screen Sharing — handed attackers root access through port 5900, wide open to the internet like a velvet rope with no bouncer. Apple patched it August 6 in macOS Tahoe 26.6.1. You simply... did not apply it. Delicious. (1/2)
##An AI agent built a working exploit for this macOS flaw in four hours
https://thenextweb.com/news/macos-screen-sharing-flaw-cve-2026-65400-monero-miner?utm_source=flipboard&utm_medium=activitypub
Posted into Technology (UK Edition) @technology-uk-edition-FlipboardUK
##An AI agent built a working exploit for this macOS flaw in four hours
https://thenextweb.com/news/macos-screen-sharing-flaw-cve-2026-65400-monero-miner?utm_source=flipboard&utm_medium=activitypub
Posted into TNW - All Stories @tnw-all-stories-thenextweb
##Here's a summary of the latest geopolitical, technology, and cybersecurity news from the last 24-48 hours:
Cybersecurity: Apple patched a critical macOS Screen Sharing vulnerability (CVE-2026-65400) and issued mercenary spyware alerts across 110 countries. Microsoft's August Patch Tuesday fixed 421 vulnerabilities, including an actively exploited Windows zero-day (CVE-2026-68820). France reported a Bloctel data leak exposing three million phone numbers and a DGFiP tax data leak.
Technology: Massive tech layoffs continue in 2026, surpassing last year's totals, as companies shift to "AI-first" strategies; AI "inference" spending now exceeds "training". Elon Musk's SpaceX committed exclusively to NVIDIA GPUs, forming a major AI partnership.
Geopolitics: US-Iran tensions remain high over the Strait of Hormuz, with new threats and defense contracts emerging. Ukraine faces critical Patriot interceptor shortages, threatening its winter air defense.
##⚠️ Important security update for Mac users:
A vulnerability in macOS Screen Sharing (CVE-2026-65400) is being actively exploited.
If you use Screens or another VNC client app to remotely access a Mac, we strongly recommend updating macOS as soon as possible.
##Attackers actively exploit the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. Discover how to protect your Mac from root access and cryptominers.
#macOS #CVE202665400 #ScreenSharing #Vulnerability #Cybersecurity
##CVE-2026-65400 (HIGH) - macOS Screen Sharing vuln lets remote attackers bypass auth and gain root. Active exploitation seen, mainly on systems with port 5900 open. Patch Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9. https://radar.offseq.com/threat/recent-macos-screen-sharing-vulnerability-exploited-in-attacks-6aa0fe0406c5717d #OffSeq #macOS #infosec #vuln
##🏆 New Achievement! Screen Sharing Is Caring (About My Monero Wallet)!
Allow me to monologue, as any proper villain must. CVE-2026-65400 — a gorgeous authentication bypass in macOS Screen Sharing — handed attackers root access through port 5900, wide open to the internet like a velvet rope with no bouncer. Apple patched it August 6 in macOS Tahoe 26.6.1. You simply... did not apply it. Delicious. (1/2)
##⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…
🤖 AI generated summary
##Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks
The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
#hardware
https://www.tomshardware.com/tech-industry/cyber-security/macos-screen-sharing-flaw-exploited-to-root-macs-and-plant-monero-miners
Apple Patches Actively Exploited macOS Screen Sharing Vulnerability Used in Crypto Mining Attacks
Apple patched a macOS Screen Sharing vulnerability (CVE-2026-65400) that allows remote attackers to bypass authentication and gain root access. Attackers are actively exploiting the flaw to install Monero crypto miners on systems with port 5900 exposed to the internet.
**If you use a Mac, update macOS now to Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 to fix CVE-2026-65400, which attackers are already using to take full control of Macs without a password. Also turn off Screen Sharing when you don't need it and make sure port 5900 is not reachable from the internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/apple-patches-actively-exploited-macos-screen-sharing-vulnerability-used-in-crypto-mining-attacks-n-5-j-v-1/gD2P6Ple2L
updated 2026-08-17T12:32:31
2 posts
CVE-2026-74889 - Critical crypto weakness in openssl_encrypt <1.4.0. HKDF with no salt/static info weakens key derivation, enabling multi-target attacks. CVSS 9.8. Update immediately. #CVE #cryptography #infosec
##CVE-2026-74889 - Critical crypto weakness in openssl_encrypt <1.4.0. HKDF with no salt/static info weakens key derivation, enabling multi-target attacks. CVSS 9.8. Update immediately. #CVE #cryptography #infosec
##updated 2026-08-17T12:32:26
1 posts
CVE-2026-74800 - Stored XSS in SiYuan. Missing headers allow script execution with full kernel API access. CVSS 9.0. Unpatched. Update or restrict file uploads now. #CVE #SiYuan #infosec
##updated 2026-08-17T12:32:26
2 posts
CVE-2026-74845 (HIGH, CVSS 8.7): 2100 Technology Official Document Management System lets authenticated attackers upload dangerous files — risk of code execution. No patch yet. Limit upload rights & monitor files. https://radar.offseq.com/threat/cve-2026-74845-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-2100-technology-official-1d9f0343bf21764a #OffSeq #vuln #infosec #CVE2026_74845
##CVE-2026-74845 (HIGH, CVSS 8.7): 2100 Technology Official Document Management System lets authenticated attackers upload dangerous files — risk of code execution. No patch yet. Limit upload rights & monitor files. https://radar.offseq.com/threat/cve-2026-74845-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-2100-technology-official-1d9f0343bf21764a #OffSeq #vuln #infosec #CVE2026_74845
##updated 2026-08-17T06:33:56
1 posts
CVE-2026-19981 - OS Command Injection in GL.iNet routers (Wi-Fi Timer feature). Remote attack, CVSS 7.4. Affects many models up to 4.8.x. Unpatched - update immediately. #CVE #GLiNet #infosec
##updated 2026-08-17T06:19:07.453000
2 posts
Say what you will about 'branded' vulnerability disclosures, at least they tend to provide understandable information about the issue, which functionality it concerns, whether you might be affected, and often how to mitigate while waiting for the patch to propagate. As opposed to raw CVEs like https://www.cve.org/CVERecord?id=CVE-2026-72407
##Say what you will about 'branded' vulnerability disclosures, at least they tend to provide understandable information about the issue, which functionality it concerns, whether you might be affected, and often how to mitigate while waiting for the patch to propagate. As opposed to raw CVEs like https://www.cve.org/CVERecord?id=CVE-2026-72407
##updated 2026-08-17T03:30:28
2 posts
CVE-2026-50602: HIGH severity (CVSS 8.5) vuln in Acer Planet9 background service 🖥️. Incorrect permissions on SYSTEM-level executable allow local users to escalate privileges. Restrict permissions or disable service until patched. https://radar.offseq.com/threat/cve-2026-50602-cwe-732-incorrect-permission-assignment-for-critical-resource-in-acer-planet9-b9a1b490c423207e #OffSeq #vuln #Infosec
##CVE-2026-50602: HIGH severity (CVSS 8.5) vuln in Acer Planet9 background service 🖥️. Incorrect permissions on SYSTEM-level executable allow local users to escalate privileges. Restrict permissions or disable service until patched. https://radar.offseq.com/threat/cve-2026-50602-cwe-732-incorrect-permission-assignment-for-critical-resource-in-acer-planet9-b9a1b490c423207e #OffSeq #vuln #Infosec
##updated 2026-08-17T00:31:35
4 posts
🔴 CVE-2026-19961 - Critical (9.9)
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19961/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-19961: CRITICAL buffer overflow in Edimax EW-7478APC v1.04 via /goform/formWlSiteSurvey (selSSID). Remote code execution is possible; no patch, public exploit exists. Isolate affected devices. https://radar.offseq.com/threat/cve-2026-19961-buffer-overflow-in-edimax-ew-7478apc-657492e4d05158fa #OffSeq #CVE202619961 #IoTSecurity
##🔴 CVE-2026-19961 - Critical (9.9)
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19961/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-19961: CRITICAL buffer overflow in Edimax EW-7478APC v1.04 via /goform/formWlSiteSurvey (selSSID). Remote code execution is possible; no patch, public exploit exists. Isolate affected devices. https://radar.offseq.com/threat/cve-2026-19961-buffer-overflow-in-edimax-ew-7478apc-657492e4d05158fa #OffSeq #CVE202619961 #IoTSecurity
##updated 2026-08-16T23:16:24.710000
4 posts
CVE-2026-19959: CRITICAL stack buffer overflow in Edimax EW-7478APC v1.04 (CVSS 9.4). Remote code execution possible. Public exploit out, no fix from vendor. Restrict access or replace device. https://radar.offseq.com/threat/cve-2026-19959-stack-based-buffer-overflow-in-edimax-ew-7478apc-5dd669bf84d8d7ec #OffSeq #CVE #IoTSecurity #infosec
##🔴 CVE-2026-19959 - Critical (9.9)
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19959/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-19959: CRITICAL stack buffer overflow in Edimax EW-7478APC v1.04 (CVSS 9.4). Remote code execution possible. Public exploit out, no fix from vendor. Restrict access or replace device. https://radar.offseq.com/threat/cve-2026-19959-stack-based-buffer-overflow-in-edimax-ew-7478apc-5dd669bf84d8d7ec #OffSeq #CVE #IoTSecurity #infosec
##🔴 CVE-2026-19959 - Critical (9.9)
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19959/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T19:17:18.030000
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-16T19:16:52.950000
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-16T19:16:48.360000
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-16T15:30:38
2 posts
🟠 CVE-2026-74789 - High (7.5)
Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74789 - High (7.5)
Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:38
1 posts
🟠 CVE-2026-74794 - High (7.5)
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74794/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:38
1 posts
🟠 CVE-2026-74792 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:33
4 posts
CVE-2026-73056 - Critical auth bypass in SiYuan kernel <3.7.4. Unauthenticated attackers can brute-force API tokens via CheckAuth() middleware, no lockout. CVSS 9.8. Update immediately. #CVE #SiYuan #infosec
##🔴 CVE-2026-73056 - Critical (9.8)
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73056 - Critical (9.8)
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 https://radar.offseq.com/threat/cve-2026-73056-improper-restriction-of-excessive-authentication-attempts-in-siyuan-note-siyuan-28d3540593a8ef28 #OffSeq #CVE202673056 #infosec
##updated 2026-08-16T15:30:33
3 posts
CVE-2026-74788 - DoS in Scriban templates via string.pad_left/right. Unvalidated width triggers ~1GB allocations, OOM. CVSS 7.5. Unpatched. Update to 7.0.0 or restrict template access. #CVE #infosec #Scriban
##🟠 CVE-2026-74788 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to ....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74788/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74788 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to ....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74788/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:33
1 posts
🟠 CVE-2026-74783 - High (7.5)
Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:26
3 posts
CVE-2026-74787 - Uncontrolled recursion in Scriban's object.to_json. Crafted templates cause stack overflow, crashing .NET apps. CVSS 7.5. No patch yet - mitigate by limiting template input. #CVE #Scriban #infosec
##🟠 CVE-2026-74787 - High (7.5)
Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74787/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74787 - High (7.5)
Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74787/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:26
2 posts
🟠 CVE-2026-73062 - High (7.5)
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73062/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73062 - High (7.5)
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73062/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:25
2 posts
🟠 CVE-2026-73057 - High (7.5)
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73057 - High (7.5)
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:24
2 posts
1 repos
CVE-2026-74251: Phoca Cart (Joomla ext. v5.0.0 – 6.1.16) suffers CRITICAL SQL injection via unauthenticated a[]/s[] params. Full DB extraction possible. Patch status unclear — check vendor. https://radar.offseq.com/threat/cve-2026-74251-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-a5081e610a943a93 #OffSeq #SQLInjection #Joomla #Infosec
##CVE-2026-74251: Phoca Cart (Joomla ext. v5.0.0 – 6.1.16) suffers CRITICAL SQL injection via unauthenticated a[]/s[] params. Full DB extraction possible. Patch status unclear — check vendor. https://radar.offseq.com/threat/cve-2026-74251-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-a5081e610a943a93 #OffSeq #SQLInjection #Joomla #Infosec
##updated 2026-08-16T09:30:22
1 posts
🟠 CVE-2026-17087 - High (7.5)
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authori...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17087/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:37
2 posts
🔴 CVE-2026-18316 - Critical (9.1)
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_act...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18316/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-18316: CRITICAL auth bypass in Solace Extra WordPress plugin (≤1.6.0). Subscriber-level users can perform destructive actions — no patch yet. Restrict user roles & monitor import_zip() activity. https://radar.offseq.com/threat/cve-2026-18316-cwe-862-missing-authorization-in-solacewp-solace-extra-02691f8987449b12 #OffSeq #WordPress #Vuln #CVE202618316
##updated 2026-08-16T06:30:32
2 posts
CVE-2026-18432 (CVSS 9.8): CRITICAL privilege escalation in DynamiApps Frontend Admin <=3.29.9. Unauthenticated attackers can become admins via flawed user ID checks. Restrict access to vulnerable forms & endpoints. https://radar.offseq.com/threat/cve-2026-18432-cwe-269-improper-privilege-management-in-shabti-frontend-admin-by-dynamiapps-0c7e8a2e9b4496ea #OffSeq #WordPress #PrivilegeEscalation #CVE
##🔴 CVE-2026-18432 - Critical (9.8)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18432/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:32
2 posts
CRITICAL: CVE-2026-14524 in ProSolution WP Client ≤2.0.8 enables unauthenticated file deletion via path traversal — risking RCE if key files are removed. No patch; restrict or disable plugin. https://radar.offseq.com/threat/cve-2026-14524-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-2ffa65eefa2c3a5d #OffSeq #WordPress #CVE202614524 #Vuln
##🔴 CVE-2026-14524 - Critical (9.1)
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unaut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14524/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:32
1 posts
🟠 CVE-2026-16099 - High (8.8)
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authentic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:31
1 posts
🟠 CVE-2026-14498 - High (8.8)
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_for...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T05:16:47.667000
2 posts
CVE-2026-16098 (CRITICAL): ProSolution WP Client <=2.0.10 lets unauthenticated attackers upload dangerous files via nonce leak, leading to remote code execution. Restrict plugin use & monitor for patches. https://radar.offseq.com/threat/cve-2026-16098-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-prosolution-prosolution-wp-b1b65fccc57ffd67 #OffSeq #WordPress #CVE202616098 #Infosec
##🔴 CVE-2026-16098 - Critical (9.8)
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Dispo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T03:31:11
2 posts
🔴 CVE-2026-19924 - Critical (9.8)
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19924/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Tenda AC10 (16.03.10.09_multi_TDE01) hit by CRITICAL auth bypass (CVE-2026-19924) via R7WebsSecurityHandler. Public exploit available — remote compromise possible. Update or restrict access! https://radar.offseq.com/threat/cve-2026-19924-improper-authentication-in-tenda-ac10-b84751472c0f965f #OffSeq #CVE202619924 #Tenda #Vuln
##updated 2026-08-16T00:31:35
2 posts
CVE-2026-73053: CRITICAL XSS in SiYuan (pre-v3.7.4) risks code execution on host via crafted icons when Node integration is enabled. No patch confirmed — disable Node integration or avoid untrusted files. https://radar.offseq.com/threat/cve-2026-73053-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-1654398c24cf93d4 #OffSeq #XSS #Vuln #SiYuan
##🔴 CVE-2026-73053 - Critical (9)
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73053/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:35
1 posts
🟠 CVE-2026-73054 - High (7.5)
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73054/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:29
1 posts
CVE-2026-73055: CRITICAL vuln in ericcornelissen shescape (<2.1.15, 3.0.0<3.0.2). Improper tilde (~) escaping lets attackers leak home dir & alter cmd targets on BusyBox /bin/sh. Avoid untrusted input in escape APIs. Patch pending. https://radar.offseq.com/threat/cve-2026-73055-improper-encoding-or-escaping-of-output-in-ericcornelissen-shescape-3ef90f5f16672f7b #OffSeq #CVE202673055 #infosec
##updated 2026-08-16T00:31:28
1 posts
🔴 CVE-2026-73050 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73050/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:27
1 posts
🔴 CVE-2026-73046 - Critical (9.8)
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode)...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73046/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:26
1 posts
🔴 CVE-2026-73043 - Critical (9)
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and Jav...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73043/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T00:31:32
2 posts
2 repos
ShieldBreak appears to be CVE-2026-69414 ht @wdormann https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
ShieldBreak appears to be CVE-2026-69414 ht @wdormann https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
updated 2026-08-14T19:17:17.480000
2 posts
A critical Haiwell HMI Gateway flaw (CVE-2026-19188) allows remote attackers to execute arbitrary OS commands with root privileges.
##A critical Haiwell HMI Gateway flaw (CVE-2026-19188) allows remote attackers to execute arbitrary OS commands with root privileges.
##updated 2026-08-14T18:31:46
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-14T05:16:59.407000
4 posts
2 repos
China APT Exploits VMware Flaw in Targeted Attacks
A recent investigation revealed that a suspected China-nexus APT group is actively exploiting a critical VMware vCenter vulnerability, CVE-2026-59310, to execute arbitrary code and deploy a backdoor, with ransomware seemingly used as a smokescreen to distract from the underlying intrusion. The attackers' true intentions appear to go beyond mere…
#ChinaApt #Vmware #Cve202659310 #AdvancedPersistentThreat #NationState
##https://thecybersecguru.com/news/vmware-vcenter-cve-2026-59310-babuk-esxi-ransomware/
##vCenter Flaw Exploited Just Five Days After Disclosure https://www.infosecurity-magazine.com/news/vcenter-cve-2026-59310-exploited/
##2026-W33 — Weekly Threat Roundup
🔥 VMware vCenter RCE (CVE-2026-59310) under active APT exploitation across 47 countries, patch and hunt for persistence now.
🤖 Near-autonomous AI cyberattack observed against Taiwan's government, adapting mid-operation without human direction.
💀 Lazarus Group's Operation Dream Job exploits Windo…
https://threatnoir.com/weekly/2026-w33
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##updated 2026-08-14T03:31:33
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-13T21:36:14
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-13T15:34:13
1 posts
2 repos
🖲️ #Noticia de #CiberSeguridad #CiberGuerra #CiberAtaque #CiberNoticia
⚫ Explotan vulnerabilidad en SharePoint
🔗 http://blog.segu-info.com.ar/2026/08/explotan-vulnerabilidad-en-sharepoint.html
Los ciberdelincuentes han comenzado a explotar una vulnerabilidad de Microsoft
SharePoint recientemente descubierta tras la publicación de una prueba de
concepto (PoC).
La vulnerabilidad en cuestión es
CVE-2026-55040
(CVSS: 9.1), que se refiere a una omisión de una función de seguridad
updated 2026-08-12T21:31:50
2 posts
Red Hat fixes RHACM remote code execution flaws, including CVE-2026-72526 and CVE-2026-73268, both CVSS 9.9. See patch and mitigation steps.
#RHACM #RedHat #Kubernetes #ArgoCD #RCE #CVE #CyberSecurity #InfoSec
##Red Hat fixes RHACM remote code execution flaws, including CVE-2026-72526 and CVE-2026-73268, both CVSS 9.9. See patch and mitigation steps.
#RHACM #RedHat #Kubernetes #ArgoCD #RCE #CVE #CyberSecurity #InfoSec
##updated 2026-08-12T18:31:00
1 posts
4 repos
https://github.com/g0thamRabb1t/CVE-2026-50656-rogueplanet-validation
https://github.com/0xBlackash/CVE-2026-50656
https://github.com/HORKimhab/CVE-2026-50656
https://github.com/eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-
📰 New 'ShieldBreak' Exploit Bypasses Microsoft Defender Patch
A new zero-day exploit, 'ShieldBreak,' bypasses Microsoft's patch for the 'RoguePlanet' Defender flaw (CVE-2026-50656). The PoC allows SYSTEM-level access on patched Windows systems. No fix is currently available. #ZeroDay #MicrosoftDefender #CyberSe...
##updated 2026-08-12T03:31:18
2 posts
Red Hat fixes RHACM remote code execution flaws, including CVE-2026-72526 and CVE-2026-73268, both CVSS 9.9. See patch and mitigation steps.
#RHACM #RedHat #Kubernetes #ArgoCD #RCE #CVE #CyberSecurity #InfoSec
##Red Hat fixes RHACM remote code execution flaws, including CVE-2026-72526 and CVE-2026-73268, both CVSS 9.9. See patch and mitigation steps.
#RHACM #RedHat #Kubernetes #ArgoCD #RCE #CVE #CyberSecurity #InfoSec
##updated 2026-08-11T21:33:01
4 posts
2 repos
Here's a summary of the latest geopolitical, technology, and cybersecurity news from the last 24-48 hours:
Cybersecurity: Apple patched a critical macOS Screen Sharing vulnerability (CVE-2026-65400) and issued mercenary spyware alerts across 110 countries. Microsoft's August Patch Tuesday fixed 421 vulnerabilities, including an actively exploited Windows zero-day (CVE-2026-68820). France reported a Bloctel data leak exposing three million phone numbers and a DGFiP tax data leak.
Technology: Massive tech layoffs continue in 2026, surpassing last year's totals, as companies shift to "AI-first" strategies; AI "inference" spending now exceeds "training". Elon Musk's SpaceX committed exclusively to NVIDIA GPUs, forming a major AI partnership.
Geopolitics: US-Iran tensions remain high over the Strait of Hormuz, with new threats and defense contracts emerging. Ukraine faces critical Patriot interceptor shortages, threatening its winter air defense.
##Geopolitical tensions rise with a Middle East conflict stalemate and Israeli retaliatory strikes against Hezbollah in Lebanon. Ukraine's air defense faces threats amid Patriot interceptor depletion and drone attacks on Moscow.
In tech, NVIDIA and SpaceX have forged a significant AI partnership, with massive infrastructure spending projected. Cybersecurity sees the US allowing vetted private companies to conduct offensive cyber operations. Microsoft patched a critical, exploited Windows zero-day (CVE-2026-68820), and Cl0p ransomware leveraged a PTC Windchill flaw impacting nearly 50 firms.
##Here's a summary of the latest geopolitical, technology, and cybersecurity news from the last 24-48 hours:
Cybersecurity: Apple patched a critical macOS Screen Sharing vulnerability (CVE-2026-65400) and issued mercenary spyware alerts across 110 countries. Microsoft's August Patch Tuesday fixed 421 vulnerabilities, including an actively exploited Windows zero-day (CVE-2026-68820). France reported a Bloctel data leak exposing three million phone numbers and a DGFiP tax data leak.
Technology: Massive tech layoffs continue in 2026, surpassing last year's totals, as companies shift to "AI-first" strategies; AI "inference" spending now exceeds "training". Elon Musk's SpaceX committed exclusively to NVIDIA GPUs, forming a major AI partnership.
Geopolitics: US-Iran tensions remain high over the Strait of Hormuz, with new threats and defense contracts emerging. Ukraine faces critical Patriot interceptor shortages, threatening its winter air defense.
##Geopolitical tensions rise with a Middle East conflict stalemate and Israeli retaliatory strikes against Hezbollah in Lebanon. Ukraine's air defense faces threats amid Patriot interceptor depletion and drone attacks on Moscow.
In tech, NVIDIA and SpaceX have forged a significant AI partnership, with massive infrastructure spending projected. Cybersecurity sees the US allowing vetted private companies to conduct offensive cyber operations. Microsoft patched a critical, exploited Windows zero-day (CVE-2026-68820), and Cl0p ransomware leveraged a PTC Windchill flaw impacting nearly 50 firms.
##updated 2026-08-11T18:31:49
4 posts
2 repos
https://github.com/DavidCarliez/CVE-2026-66804-CrossDevice-LPE
https://github.com/Rat5ak/CVE-2026-66804-CrossDevice-Service-EoP
A public PoC for CVE-2026-66804 escalates a standard Windows user to SYSTEM through the Cross Device virtual camera COM service.
#CVE202666804 #PrivilegeEscalation #Windows11 #SYSTEMprivileges #EoP #PoCExploit
##📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
A public PoC for CVE-2026-66804 escalates a standard Windows user to SYSTEM through the Cross Device virtual camera COM service.
#CVE202666804 #PrivilegeEscalation #Windows11 #SYSTEMprivileges #EoP #PoCExploit
##📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-11T18:31:33
2 posts
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
updated 2026-08-04T03:31:16
2 posts
1 repos
https://github.com/minanagehsalalma/CVE-2026-6837-zyxel-export-cgi-command-injection
CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/
##CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/
##updated 2026-07-29T19:32:51.167000
2 posts
Petit insight très sympa sur la recherche de vulnérabilité macOS
Le chercheur Csaba Fitzl revient sur une jolie vuln dans Spotlight (Spotlight PostScript plugin), une sorte de petite chimère qui traînait depuis un moment dans sa TODO list : quelques fonctions décompilées du parser PostScript soumises à Claude, une piste identifiée, puis validation humaine.
Résultat : CVE-2026-43774, un simple fichier .ps pouvant faire fuiter des morceaux de mémoire de mdworker via les métadonnées Spotlight.
Au-delà du bug, le billet montre très directement comment les IA s’intègrent naturellement aux workflows de recherche de vulnérabilités, en partant de l’expertise humaine : une intuition et une approche, puis fuzzing dopé au LLM, reverse, détection de patterns suspects…
...et pourquoi les éditeurs comme la pomme doivent courir toujours plus vite derrière les patchs.
"How a single PostScript file leaks your Mac's memory"
👇
https://www.iru.com/blog/how-a-single-postscript-file-leaks-your-macs-memory
Petit insight très sympa sur la recherche de vulnérabilité macOS
Le chercheur Csaba Fitzl revient sur une jolie vuln dans Spotlight (Spotlight PostScript plugin), une sorte de petite chimère qui traînait depuis un moment dans sa TODO list : quelques fonctions décompilées du parser PostScript soumises à Claude, une piste identifiée, puis validation humaine.
Résultat : CVE-2026-43774, un simple fichier .ps pouvant faire fuiter des morceaux de mémoire de mdworker via les métadonnées Spotlight.
Au-delà du bug, le billet montre très directement comment les IA s’intègrent naturellement aux workflows de recherche de vulnérabilités, en partant de l’expertise humaine : une intuition et une approche, puis fuzzing dopé au LLM, reverse, détection de patterns suspects…
...et pourquoi les éditeurs comme la pomme doivent courir toujours plus vite derrière les patchs.
"How a single PostScript file leaks your Mac's memory"
👇
https://www.iru.com/blog/how-a-single-postscript-file-leaks-your-macs-memory
updated 2026-07-14T18:32:37
5 posts
12 repos
https://github.com/KrakenEU/CVE-2026-54121-CertiGhost
https://github.com/GlendonNotGlen/certighost-cve-2026-54121-slides
https://github.com/marcgoam/CVE-2026-54121-CertiGhost
https://github.com/AtlasVector/Certighost-CVE-2026-54121
https://github.com/sam00/POC-CVE-2026-54121-Certighost
https://github.com/HORKimhab/CVE-2026-54121
https://github.com/nafiez/Metasploit-CVE-2026-54121-Certighost
https://github.com/mwnickerson/certighost-bof
https://github.com/0xBlackash/CVE-2026-54121
https://github.com/tc4dy/CVE-2026-54121-PoC-Exploit
Certighost and the Privilege Hiding in Your Certificate Authority
Certighost(CVE-2026-54121)는 AD CS Enterprise CA의 chase 조회 검증 결함을 악용해 일반 도메인 사용자가 공격자 제어 엔드포인트에서 위조한 DC 식별 정보를 CA에 제공하고, 도메인 컨트롤러용 인증서를 발급받을 수 있는 권한 상승 취약점입니다. 발급된 인증서로 PKINIT 기반 Kerberos TGT를 얻은 뒤 DCSync를 수행하면 krbtgt 해시 탈취와 도메인 전체 장악으로 이어질 수 있습니다. Microsoft는 2...
##Certighost and the Privilege Hiding in Your Certificate Authority
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing...
🔗️ [Bleepingcomputer] https://link.is.it/wWmVkm
##Certighost Exposes Hidden Privilege Risks in Certificate Authorities
A single misstep in a Certificate Authority can have devastating consequences, as seen in CVE-2026-54121, aka Certighost, which allows a low-privileged domain user to escalate to full domain compromise. This shocking vulnerability exploits a little-known "chase" functionality in Active Directory Certificate…
#Cve202654121 #Certighost #CertificateAuthorities #ActiveDirectory #PrivilegeEscalation
##Certighost CVE-2026-54121: The Active Directory Certificate Flaw That Can Turn a Low-Privilege User Into a Domain Controller
Introduction: When the System That Creates Trust Becomes the Attack Path Active Directory environments are built around trust. Users trust domain controllers, applications trust authentication services, and machines trust certificates issued by an organization's internal Certification Authority. That architecture is powerful precisely because so…
##Certighost and the Privilege Hiding in Your Certificate Authority
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing...
🔗️ [Bleepingcomputer] https://link.is.it/wWmVkm
##updated 2026-07-01T18:32:28
8 posts
2 repos
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
CVE-2026-8452 in Netscaler is under active pray and spray exploitation - somebody popped my honeypot with it today. Three webshells, x.php, y.php and z.php
I don't think this one will be super impactful in terms of breach numbers as most orgs don't have SAML IDP enabled - you can check with the paths I posted above.
##‼️ Detection Artifact Generator for Citrix NetScaler CVE-2026-8452
GitHub: https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
##Oof; if you're a NetScaler shop you probably want to be very sure you update for this one: https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
Pre-auth RCE is... yikes. Relatively low EPSS for now, but I wouldn't trust that with the CVSSv4 vectors in play: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
##PoC exploit code for CVE-2026-8452, a Citrix NetScaler pre-auth RCE, is now public. The SAML heap overflow grants root. Patch now.
#Citrix #NetScaler #CVE #PreAuthRCE #SAML #CyberSecurity #InfoSec #PatchNow
##CVE-2026-8452 in Netscaler is under active pray and spray exploitation - somebody popped my honeypot with it today. Three webshells, x.php, y.php and z.php
I don't think this one will be super impactful in terms of breach numbers as most orgs don't have SAML IDP enabled - you can check with the paths I posted above.
##‼️ Detection Artifact Generator for Citrix NetScaler CVE-2026-8452
GitHub: https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
##Oof; if you're a NetScaler shop you probably want to be very sure you update for this one: https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
Pre-auth RCE is... yikes. Relatively low EPSS for now, but I wouldn't trust that with the CVSSv4 vectors in play: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
##PoC exploit code for CVE-2026-8452, a Citrix NetScaler pre-auth RCE, is now public. The SAML heap overflow grants root. Patch now.
#Citrix #NetScaler #CVE #PreAuthRCE #SAML #CyberSecurity #InfoSec #PatchNow
##updated 2026-06-26T15:33:15
2 posts
1 repos
🏆 New Achievement! Clop Sends Its Regards to the Living!
Attention, all undead assets and legacy infrastructure currently haunting your network closets: please report to Compliance for re-onboarding. Tech giants General Electric and Philips have confirmed they are investigating claims by the Clop ransomware group that data was stolen, with CVE-2026-12569 tagged in connection with the incident. (1/3)
##🏆 New Achievement! Clop Sends Its Regards to the Living!
Attention, all undead assets and legacy infrastructure currently haunting your network closets: please report to Compliance for re-onboarding. Tech giants General Electric and Philips have confirmed they are investigating claims by the Clop ransomware group that data was stolen, with CVE-2026-12569 tagged in connection with the incident. (1/3)
##updated 2026-06-17T10:47:32.723000
1 posts
1 repos
Breaking AI Orchestration: Hijacking N8n HITL Chat Sessions
n8n의 HITL Chat 노드에서 인증 없이 활성 WebSocket 채팅 세션을 탐색·도청·메시지 주입할 수 있는 취약점이 발견됐다. 순차적인 executionId와 공개된 `/form-waiting` 상태 오라클, 클라이언트가 임의 지정 가능한 sessionId가 결합돼 실행 중인 에이전트 대화를 탈취할 수 있으며, 에이전트가 반환하는 도구 결과·검색 컨텍스트 등의 노출 및 대화 조작으로 이어질 수 있다. 이 이슈는 CVE-2026-42228(CVSS 6.3, Moderate)로 수정됐으며, n...
https://zerolabs.rubrik.com/blog/breaking-ai-orchestration-part-2-hijacking-n8n-hitl-chat-sessions
##updated 2026-06-09T18:30:48
2 posts
From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193) https://zerolabs.rubrik.com/blog/breaking-m365-copilot-sandbox-chatmate
##From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193) https://zerolabs.rubrik.com/blog/breaking-m365-copilot-sandbox-chatmate
##updated 2026-05-13T16:29:55
1 posts
🛡️ Weekly CVE Roundup is live! We're diving deep into the critical RCE found in Fast-API-Router (CVE-2026-44012) and discussing the broader trend of API vulnerabilities. Protect your supply chain and patch today. Full details: https://cvedatabase.com/blog/weekly-cve-roundup-critical-rce-in-fast-api-router-and-the-rising-tide-of-api-vu-2026-08-09 #InfoSec #CyberSecurity #CVE #APISecurity #FastAPIRouter #PatchTuesday
##updated 2026-03-26T16:41:02
1 posts
CVE-2026-33696: From a Schema Name to RCE in n8n https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce
##updated 2026-02-27T06:31:39
2 posts
SQL Injection flaw (CVE-2026-67854) in Qcms v6.0.6 rated CRITICAL: remote code execution risk. No official patch. Restrict access & monitor for injection attempts. Details: https://radar.offseq.com/threat/sql-injection-vulnerability-in-qcms-v606-allows-a-remote-attacker-to-execute-arbitrary-code-cve-2026-3286c90b2be69269 #OffSeq #SQLInjection #Vulnerability #Qcms #InfoSec
##SQL Injection flaw (CVE-2026-67854) in Qcms v6.0.6 rated CRITICAL: remote code execution risk. No official patch. Restrict access & monitor for injection attempts. Details: https://radar.offseq.com/threat/sql-injection-vulnerability-in-qcms-v606-allows-a-remote-attacker-to-execute-arbitrary-code-cve-2026-3286c90b2be69269 #OffSeq #SQLInjection #Vulnerability #Qcms #InfoSec
##A CVSS 10.0 unauthenticated arbitrary file read flaw in BigBlueButton path traversal exposes servers. Prevent attacks like CVE-2024-39302 and update now.
##A CVSS 10.0 unauthenticated arbitrary file read flaw in BigBlueButton path traversal exposes servers. Prevent attacks like CVE-2024-39302 and update now.
##🟠 CVE-2026-45790 - High (8)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission to invite an account ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45790/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-45790 - High (8)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission to invite an account ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45790/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71424 - Critical (9.6)
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and On...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71424/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71424 - Critical (9.6)
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and On...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71424/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-45698 - High (7.5)
Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the deletedir() function of Netatalk's afpd daemon due to an integer underflow in the c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-45698 - High (7.5)
Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the deletedir() function of Netatalk's afpd daemon due to an integer underflow in the c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
####Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path...
##Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path...
##Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path...
##Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path...
##Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-after-free in the TLS pending-data list when a command closes another...
##Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path...
##Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path...
##Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path...
##Update urgency: SECURITY: There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path...
##Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-after-free in the TLS pending-data list when a command closes another...
2 posts
3 repos
https://github.com/masasron/CopyEscape-CVE-2026-17106
CVE-2026-17106 (CVSS 7.1) is the Docker CopyEscape vulnerability, letting malicious containers overwrite host files and trigger code execution.
##CVE-2026-17106 (CVSS 7.1) is the Docker CopyEscape vulnerability, letting malicious containers overwrite host files and trigger code execution.
##🏆 New Achievement! Your Antivirus Has a Virus Problem!
PATCH NOTES v0.0.0 — KNOWN ISSUES: Microsoft Defender, the product specifically designed to protect you from threats, is currently a threat. The Microsoft Malware Protection Engine contains a zero-day tracked as CVE-2024-69414, nicknamed ShieldBreak, which attackers in the wild are actively using to elevate their privileges. Think of it as a DLC nobody ordered.
ADDED: Unauthorized privilege escalation. FIXED: Nothing yet. (1/2)
##🏆 New Achievement! Your Antivirus Has a Virus Problem!
PATCH NOTES v0.0.0 — KNOWN ISSUES: Microsoft Defender, the product specifically designed to protect you from threats, is currently a threat. The Microsoft Malware Protection Engine contains a zero-day tracked as CVE-2024-69414, nicknamed ShieldBreak, which attackers in the wild are actively using to elevate their privileges. Think of it as a DLC nobody ordered.
ADDED: Unauthorized privilege escalation. FIXED: Nothing yet. (1/2)
##3 posts
6 repos
https://github.com/codeb0ssx/CVE-2026-72898-PoC
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
https://github.com/4minx/CVE-2026-72898
https://github.com/VuxNx/CVE-2026-72898
The Metabase SQLi: Exploited in the Wild
Metabase Cloud를 대상으로 실제 악용된 제로데이 SQL 인젝션 취약점(CVE-2026-72898)이 공개됐으며, 자체 호스팅 인스턴스도 즉시 패치가 필요하다. 취약점은 `/api/session/reset_password`에서 요청 JSON의 추가 `user-id` 필드가 인증 결과와 병합되는 과정에서 살아남고, HoneySQL의 `:raw` 표현을 통해 비매개변수화 SQL로 전달되는 구조다. 영향 버전은 1.58 이후이며, Wiz는 취약 버전 0.58.22와 수정 버전 0.58.24의 JAR 디프·디컴파일을 AI 에이전트로 분석해 원인을 재구성했다고 설명했다. Metab...
https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild
##📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📈 CVE Published in last 7 days (2026-08-10 - 2026-08-10)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 326
- High: 1309
- Medium: 1008
- Low: 130
- None: 1222
Status:
- : 39
- Analyzed: 419
- Awaiting Analysis: 226
- Deferred: 197
- Modified: 2
- Received: 2827
- Rejected: 102
- Undergoing Analysis: 183
CISA KEVs:
- CISA-2026:0811 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0811)
Top CNAs:
- kernel.org: 1221
- Microsoft Corporation: 405
- VulnCheck: 343
- GitHub, Inc.: 326
- IBM Corporation: 160
- WPScan: 124
- Patchstack: 111
- VulDB: 104
- Red Hat, Inc.: 101
- Wordfence: 93
Top Affected Products:
- UNKNOWN: 3370
- Microsoft Windows Server 2025: 178
- Microsoft Windows 11 24h2: 171
- Microsoft Windows 11 26h1: 171
- Microsoft Windows 11 25h2: 171
- Microsoft Windows Server 2022: 158
- Microsoft Windows Server 2019: 146
- Microsoft Windows 10 1809: 146
- Microsoft Windows 11 23h2: 146
- Microsoft Windows 10 22h2: 136
Top EPSS Score:
- CVE-2026-72898 - 10.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72898)
- CVE-2026-61358 - 3.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-61358)
- CVE-2026-66804 - 3.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66804)
- CVE-2026-62696 - 3.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62696)
- CVE-2026-19771 - 2.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19771)
- CVE-2026-73296 - 2.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73296)
- CVE-2026-65775 - 2.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65775)
- CVE-2026-62832 - 2.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62832)
- CVE-2026-19747 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19747)
- CVE-2026-19681 - 2.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19681)
📢 Bypass d'authentification critique dans Dolt MCP : exécution d'outils sans authentification
Cet article présente la découverte et la divulgation coordonnée d'une vulnérabilité critique d'authentification bypass dans le serveur MCP distant de DoltHub (CVE-2026-73554). La vulnérabilité affecte Dolt MCP versions 0.3.1 à 0.3.6 sur le transport HTTP distant lorsque…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-16-bypass-d-authentification-critique-dans-dolt-mcp-execution-d-outils-sans-authentification/
🌐 source : https://www.pillar.security/blog/lose-control-flow-unauthenticated-tool-execution-in-dolt-mcp
🟡 vérification factuelle moyenne
#Dolt #MCP #Cyberveille