## Updated at UTC 2026-09-23T18:44:19.646567

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-85102 9.8 0.66% 8 0 2026-09-23T18:22:07.453000 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-73547 7.5 0.83% 1 0 2026-09-23T18:21:42.327000 Envoy is an open source edge and service proxy designed for cloud-native applica
CVE-2026-19599 9.9 0.00% 4 0 2026-09-23T18:17:31.543000 ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable
CVE-2026-18169 9.9 0.78% 1 0 2026-09-23T18:17:07.270000 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remot
CVE-2026-77322 7.5 0.61% 1 0 2026-09-23T18:12:04.247000 SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3,
CVE-2026-61714 7.8 0.14% 1 0 2026-09-23T18:12:04.247000 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. Fr
CVE-2026-91809 7.8 0.17% 1 0 2026-09-23T17:58:26.570000 A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of m
CVE-2026-93616 9.8 2.42% 11 2 2026-09-23T16:38:38.987000 A directory traversal and file upload vulnerability allows an unauthenticated at
CVE-2026-96257 10.0 1.04% 1 0 2026-09-23T15:17:31.920000 A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this i
CVE-2026-19202 0 0.23% 1 0 2026-09-23T15:17:13.647000 A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK cau
CVE-2026-94127 9.8 1.39% 17 1 2026-09-23T14:32:07.910000 When a BIG-IP APM access policy and an OAuth profile are configured on a virtual
CVE-2026-91811 7.8 0.17% 1 0 2026-09-23T09:30:37 A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader
CVE-2026-91818 7.8 0.17% 1 0 2026-09-23T09:30:37 A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript ha
CVE-2026-81657 9.8 0.58% 1 0 2026-09-23T04:17:48.700000 IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker
CVE-2026-80442 9.9 0.63% 1 0 2026-09-23T04:17:48.027000 IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command i
CVE-2026-28325 8.8 1.52% 1 0 2026-09-23T04:17:42.200000 SolarWinds Observability Self-Hosted was found to be affected by an unauthentica
CVE-2026-18162 9.8 0.86% 1 0 2026-09-23T00:31:21 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remot
CVE-2026-18163 9.8 0.81% 1 0 2026-09-23T00:31:21 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remot
CVE-2026-77987 None 0.89% 1 0 2026-09-22T21:31:40 A server-side request forgery (SSRF) vulnerability was identified in the noteboo
CVE-2026-88020 6.1 0.27% 2 0 2026-09-22T21:31:39 Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input d
CVE-2026-88419 8.8 0.48% 1 0 2026-09-22T21:31:35 An unrestricted upload of files with a dangerous type in the thumbnail-upload en
CVE-2026-28324 9.8 0.65% 3 0 2026-09-22T21:31:34 SolarWinds Observability Self-Hosted was found to be affected by an unauthentica
CVE-2026-87121 9.8 0.78% 2 0 2026-09-22T21:31:34 lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow
CVE-2026-93952 10.0 0.74% 13 0 2026-09-22T21:31:14 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a
CVE-2026-20282 4.9 0.56% 1 0 2026-09-22T21:17:30.440000 A vulnerability in Cisco ISE could allow an authenticated, remote attacker to ob
CVE-2026-94540 7.7 0.11% 1 0 2026-09-22T20:53:07.383000 DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that a
CVE-2026-94501 8.8 0.30% 1 0 2026-09-22T20:43:58.793000 jshERP through 3.6 contains an authorization bypass vulnerability in the userBus
CVE-2026-94626 7.5 0.45% 1 0 2026-09-22T20:25:55.870000 vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_param
CVE-2026-87902 8.1 0.42% 8 10 2026-09-22T20:00:03.713000 An unauthenticated attacker can make `get_page_template()` page-template resolut
CVE-2026-88407 7.5 0.26% 1 0 2026-09-22T20:00:03.713000 An out-of-bounds read in the node_token_count/relation_token_count component of
CVE-2026-88409 8.8 0.28% 1 0 2026-09-22T20:00:03.713000 FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer ov
CVE-2026-94054 7.0 0.27% 1 0 2026-09-22T19:56:19.073000 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled pro
CVE-2026-86553 8.8 0.45% 1 1 2026-09-22T19:41:38.447000 SmartLife app dynamically generates fresh SmartLife application authentication p
CVE-2026-11726 8.1 0.46% 1 0 2026-09-22T19:32:25.730000 IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac
CVE-2026-11727 8.1 0.61% 1 0 2026-09-22T19:32:25.730000 IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remo
CVE-2026-85279 8.6 0.21% 1 0 2026-09-22T19:16:54.623000 Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad+
CVE-2026-84388 9.6 0.38% 1 1 2026-09-22T19:09:58.680000 A improper restriction of rendered ui layers or frames vulnerability in Fortinet
CVE-2026-88411 7.5 0.28% 1 0 2026-09-22T18:34:30 Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c)
CVE-2026-89275 10.0 1.25% 1 0 2026-09-22T18:33:43 Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of
CVE-2026-93345 7.5 0.49% 1 0 2026-09-22T18:33:35 MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnera
CVE-2026-94099 9.9 1.69% 2 0 2026-09-22T16:18:17.183000 A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This
CVE-2026-81180 8.8 0.36% 2 0 2026-09-22T16:18:02.227000 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61,
CVE-2026-57227 7.5 0.40% 1 0 2026-09-22T16:17:48.827000 Suricata is a network Intrusion Detection System, Intrusion Prevention System an
CVE-2026-95675 9.8 3.91% 1 0 2026-09-22T15:32:43 D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated re
CVE-2026-65113 9.8 0.61% 1 0 2026-09-22T15:32:43 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an att
CVE-2026-88406 7.5 0.27% 1 0 2026-09-22T15:32:31 FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack ove
CVE-2026-76698 6.5 4.44% 1 0 2026-09-22T15:17:15.030000 A command injection vulnerability exists in the web-based management interface o
CVE-2026-73512 7.5 0.83% 1 0 2026-09-22T14:17:14.037000 Envoy is an open source edge and service proxy designed for cloud-native applica
CVE-2026-74849 9.8 4.46% 2 0 2026-09-22T12:30:32 Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerab
CVE-2026-25254 9.8 0.73% 1 0 2026-09-22T12:30:25 Improper authorization leads to Remote Code Execution via SocketIO interface.
CVE-2026-7273 8.8 2.41% 8 0 2026-09-22T12:10:51.067000 A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-4
CVE-2026-13355 9.8 0.34% 1 1 2026-09-22T06:30:35 The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to A
CVE-2026-19658 9.8 0.41% 1 1 2026-09-22T06:30:35 The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in
CVE-2026-94301 9.8 0.39% 1 0 2026-09-22T04:18:02.810000 The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - accept
CVE-2026-94493 10.0 0.73% 1 0 2026-09-22T03:31:06 A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issu
CVE-2026-94627 7.5 0.45% 1 0 2026-09-22T00:31:02 vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache blo
CVE-2026-94425 8.8 0.11% 2 0 2026-09-22T00:31:02 A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The a
CVE-2026-94624 7.5 0.45% 1 0 2026-09-22T00:31:02 vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offload
CVE-2026-94623 7.5 0.45% 1 0 2026-09-22T00:31:01 vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL conne
CVE-2026-12249 9.0 0.14% 1 0 2026-09-21T22:27:11 An issue was discovered in Canonical ADSys upstream versions through v0.16.2. Du
CVE-2026-81469 7.8 0.13% 1 0 2026-09-21T21:32:01 Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted S
CVE-2026-94497 8.3 0.26% 1 0 2026-09-21T21:32:00 jshERP through 3.6 fails to validate object ownership in by-id info, update, and
CVE-2026-94424 8.8 0.14% 1 0 2026-09-21T21:31:57 A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340
CVE-2026-94411 8.8 0.28% 1 0 2026-09-21T21:31:53 jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueBy
CVE-2026-77560 8.1 0.33% 1 0 2026-09-21T21:17:11.637000 Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth
CVE-2026-94142 8.8 0.13% 2 0 2026-09-21T20:17:40.953000 A security vulnerability has been detected in BioStar Temperature Monitor Utilit
CVE-2026-93958 9.1 2.17% 1 1 2026-09-21T19:17:18.593000 A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affec
CVE-2026-68928 8.6 0.13% 1 0 2026-09-21T19:17:09.157000 Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7,
CVE-2026-80521 7.8 0.13% 4 1 2026-09-21T15:32:39 In the Linux kernel, the following vulnerability has been resolved: af_unix: Un
CVE-2026-92701 9.1 0.22% 1 1 2026-09-21T15:17:35.313000 Cocos AI is a confidential computing system for running AI workloads inside trus
CVE-2026-82187 9.8 0.30% 1 0 2026-09-21T15:17:32.223000 The Web to Print Online Designer WordPress plugin before 2.15.0 does not validat
CVE-2026-87067 8.5 0.28% 1 0 2026-09-21T13:34:57.127000 The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which c
CVE-2026-94097 10.0 1.99% 1 0 2026-09-21T13:33:33.387000 A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affec
CVE-2026-94146 8.8 0.12% 1 0 2026-09-21T09:31:09 A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue aff
CVE-2026-94128 8.8 0.12% 2 1 2026-09-21T03:30:29 A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500
CVE-2026-94101 9.9 0.45% 2 0 2026-09-21T03:30:27 A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246
CVE-2026-94129 8.8 0.12% 2 1 2026-09-21T03:30:27 A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vul
CVE-2026-94100 9.9 0.46% 2 0 2026-09-21T03:30:23 A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted i
CVE-2026-94098 9.1 2.38% 1 0 2026-09-21T03:30:22 A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulne
CVE-2026-94096 9.9 1.65% 2 0 2026-09-21T00:30:33 A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by thi
CVE-2026-94095 9.9 1.67% 1 1 2026-09-21T00:30:33 A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected b
CVE-2026-94089 10.0 0.98% 1 0 2026-09-20T21:31:45 A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects th
CVE-2026-94036 8.8 0.47% 1 1 2026-09-20T18:31:25 A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0
CVE-2026-85017 7.5 0.24% 1 0 2026-09-20T15:31:26 The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not per
CVE-2026-87839 7.5 0.21% 1 0 2026-09-20T15:30:26 The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, a
CVE-2026-94084 9.4 0.40% 2 0 2026-09-20T03:30:29 Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transacti
CVE-2026-94083 9.4 0.40% 2 0 2026-09-20T03:30:29 Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free,
CVE-2026-93485 7.1 0.16% 2 2 2026-09-19T15:17:08.323000 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-61821 8.5 0.29% 1 0 2026-09-19T15:17:00.153000 pg_partman is a PostgreSQL extension that manages partitioned tables by time or
CVE-2026-61818 8.5 0.41% 1 0 2026-09-19T15:17:00.040000 pg_partman is a PostgreSQL extension that manages partitioned tables by time or
CVE-2025-39964 7.8 0.79% 2 3 2026-09-19T04:17:48.307000 In the Linux kernel, the following vulnerability has been resolved: crypto: af_
CVE-2026-81626 8.6 0.27% 1 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability
CVE-2026-84071 7.2 1.45% 1 0 2026-09-18T21:32:36 IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the U
CVE-2026-75878 9.1 0.48% 1 0 2026-09-18T21:32:35 IBM Sterling File Gateway could allow a remote attacker to bypass authentication
CVE-2026-81656 8.8 0.29% 1 0 2026-09-18T21:32:35 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability
CVE-2026-11716 7.5 0.45% 1 0 2026-09-18T21:32:28 IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac
CVE-2026-11725 8.8 0.40% 1 0 2026-09-18T21:32:28 IBM MQ could allow an authenticated attacker to cause a denial of service or pot
CVE-2026-17619 8.6 0.30% 1 0 2026-09-18T21:32:26 IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send sp
CVE-2025-39682 7.1 2.03% 1 3 2026-09-18T21:31:33 In the Linux kernel, the following vulnerability has been resolved: tls: fix ha
CVE-2026-81179 8.1 0.26% 1 0 2026-09-18T20:17:23.470000 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58,
CVE-2026-13639 9.8 0.51% 1 0 2026-09-18T20:17:06.860000 An insufficient entropy vulnerability in login logic in Synology DiskStation Man
CVE-2026-93749 7.5 0.35% 1 0 2026-09-18T18:32:09 source-map-js through 1.2.1 fails to validate the per-section offset line value
CVE-2026-93748 7.5 0.40% 1 0 2026-09-18T18:32:07 http-cache-semantics through 4.2.0 fails to properly validate security-zeroed ca
CVE-2026-93762 9.8 0.34% 1 0 2026-09-18T18:32:01 Mongoid contains an unsafe reflection weakness in the query path used for embedd
CVE-2026-10747 10.0 0.52% 2 0 2026-09-18T18:31:55 IBM MQ Appliance could allow a remote attacker to cause a denial of service or p
CVE-2026-10858 9.9 0.33% 1 0 2026-09-18T18:31:53 IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac
CVE-2026-85058 7.5 0.27% 1 0 2026-09-18T17:58:41 ## Summary Moquette MQTT Broker fails to enforce ACL write permission checks wh
CVE-2026-91127 8.2 0.24% 1 0 2026-09-18T17:19:44 ### Summary Before 2.3.1, the legacy `.doc` renderer emitted document hyperlink
CVE-2026-53266 8.8 0.28% 2 2 2026-09-18T15:32:49 In the Linux kernel, the following vulnerability has been resolved: netfilter:
CVE-2026-20283 6.5 0.43% 1 0 2026-09-18T13:28:28.567000 A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authe
CVE-2026-13684 9.8 0.46% 1 0 2026-09-18T09:31:20 An improper encoding or escaping of output vulnerability in SCGI in Synology Dis
CVE-2026-85889 10.0 0.49% 1 0 2026-09-18T00:31:16 Missing authentication for critical function in Azure AI Foundry allows an unaut
CVE-2026-20284 9.1 0.39% 1 0 2026-09-16T21:32:50 A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, r
CVE-2024-20260 8.6 0.59% 2 0 2026-09-16T21:17:05.947000 Update for September 16, 2026: The original 1.0 version of this advisory was spe
CVE-2026-79994 0 0.11% 1 0 2026-09-16T20:38:33.883000 The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a
CVE-2026-92398 9.1 2.47% 1 0 2026-09-16T18:32:09 A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by th
CVE-2026-92397 9.1 2.30% 1 0 2026-09-16T18:32:09 A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected
CVE-2026-58704 8.0 0.21% 1 0 2026-09-16T15:30:57 In Cellular Modem, there is a possible permission bypass due to a logic error in
CVE-2026-27561 7.2 2.23% 1 0 2026-09-16T09:30:35 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-27560 7.2 2.23% 1 0 2026-09-16T09:30:34 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-27562 7.2 2.23% 1 0 2026-09-16T09:30:34 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-77179 None 0.16% 1 1 2026-09-16T00:32:25 On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows
CVE-2026-90847 9.1 2.18% 1 1 2026-09-15T19:17:46.767000 A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element i
CVE-2026-90703 9.1 2.80% 1 0 2026-09-15T18:19:38.113000 A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element i
CVE-2026-89308 None 2.97% 1 0 2026-09-15T12:31:54 An unauthenticated OS command injection vulnerability exists in the ping.php end
CVE-2026-76461 9.8 2.01% 1 4 2026-09-14T21:32:49 A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure
CVE-2026-19499 7.7 0.38% 1 0 2026-09-14T18:31:23 Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can writ
CVE-2026-90894 7.8 0.15% 1 0 2026-09-14T12:31:44 Parallels Desktop runs prl_disp_service as root. Local clients reach it on the w
CVE-2026-90702 9.1 2.80% 1 0 2026-09-14T12:31:44 A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system
CVE-2026-49881 7.8 0.11% 1 2 2026-09-10T15:34:08 In serviceClassExists of InCallController.java, there is a possible arbitrary co
CVE-2026-81963 7.8 0.63% 1 0 2026-09-09T05:18:17.173000 Improper link resolution before file access ('link following') in Windows Update
CVE-2026-85880 7.8 0.57% 1 0 2026-09-08T21:34:12 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev
CVE-2026-50093 9.0 0.19% 1 0 2026-09-08T09:35:45 A vulnerability has been identified in Siveillance Control Pro V3.0 (All version
CVE-2026-43499 7.8 0.79% 1 100 2026-09-08T09:18:05.213000 In the Linux kernel, the following vulnerability has been resolved: rtmutex: Us
CVE-2026-86296 10.0 1.35% 5 0 2026-09-07T12:30:36 A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affe
CVE-2026-75925 9.6 0.67% 1 0 2026-09-05T00:31:10 Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.
CVE-2026-41293 9.8 1.68% 1 1 2026-08-31T21:04:41 Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.21 Apache Tomcat 10.1.0-M1 to
CVE-2026-78306 0 0.15% 2 1 2026-08-26T16:49:18.760000 DJI drones expose an unauthenticated DUML command interface over Bluetooth that
CVE-2026-42945 8.1 68.05% 1 45 2026-08-25T15:33:26 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo
CVE-2026-59310 9.8 50.38% 3 2 2026-08-19T04:17:24.940000 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-55040 9.1 50.59% 1 5 2026-08-18T18:32:50 Weak authentication in Microsoft Office SharePoint allows an unauthorized attack
CVE-2026-33824 9.8 72.69% 1 2 2026-08-18T18:31:46 Double free in Windows IKE Extension allows an unauthorized attacker to execute
CVE-2026-68820 7.0 6.18% 1 4 2026-08-16T19:17:24.183000 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-65660 6.5 0.81% 5 0 2026-08-11T18:31:43 Improper control of generation of code ('code injection') in Microsoft Office Sh
CVE-2021-34473 9.8 100.00% 1 14 template 2026-08-10T18:30:39 Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is uni
CVE-2026-39364 7.5 2.00% 1 0 2026-08-04T13:18:24.733000 Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2
CVE-2026-59309 9.8 7.94% 3 0 2026-07-30T15:31:54 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2025-68686 5.9 29.60% 1 0 2026-07-27T18:31:25 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE
CVE-2026-12495 None 0.17% 1 0 2026-07-27T12:32:01 Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http
CVE-2026-41091 7.8 8.20% 1 4 2026-07-24T10:10:00.197000 Improper link resolution before file access ('link following') in Microsoft Defe
CVE-2026-45659 8.8 76.08% 1 2 2026-07-23T11:10:00.120000 Deserialization of untrusted data in Microsoft Office SharePoint allows an autho
CVE-2026-50522 9.8 85.40% 1 5 2026-07-22T21:31:51 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-10702 4.3 0.86% 1 1 2026-07-22T19:10:00.120000 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CVE-2026-47065 9.8 0.50% 1 0 2026-07-13T17:24:48 ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via j
CVE-2026-4575 2.4 0.21% 1 0 2026-06-17T10:56:50.843000 A flaw has been found in code-projects Exam Form Submission 1.0. This issue affe
CVE-2025-6625 7.5 0.48% 1 0 2026-06-17T10:02:16.587000 CWE-20: Improper Input Validation vulnerability exists that could cause a Denial
CVE-2023-20118 6.5 54.11% 4 0 2026-06-17T05:29:31.353000 A vulnerability in the web-based management interface of Cisco Small Business Ro
CVE-2022-42475 9.8 99.47% 1 9 2026-06-17T05:04:59.630000 A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 th
CVE-2020-4428 9.1 61.69% 1 0 2026-06-17T03:19:58.553000 IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authen
CVE-2026-45756 None 0.63% 1 0 2026-05-28T17:34:56 ### Description The `JsonPath` component's `match()` and `search()` filter func
CVE-2026-32996 None 0.16% 3 1 2026-05-28T06:31:09 This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privile
CVE-2026-21513 8.8 15.64% 1 0 2026-03-27T21:32:39 Protection mechanism failure in MSHTML Framework allows an unauthorized attacker
CVE-2026-21525 6.2 5.04% 1 0 2026-03-27T21:31:32 Null pointer dereference in Windows Remote Access Connection Manager allows an u
CVE-2026-21519 7.8 2.46% 1 0 2026-02-10T21:31:29 Access of resource using incompatible type ('type confusion') in Desktop Window
CVE-2026-20805 5.5 5.19% 1 6 2026-01-13T21:31:44 Exposure of sensitive information to an unauthorized actor in Desktop Windows Ma
CVE-2020-4427 9.8 70.03% 1 0 2025-11-04T00:30:30 IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a
CVE-2023-48788 9.8 98.45% 1 1 2025-10-22T00:34:05 A improper neutralization of special elements used in an sql command ('sql injec
CVE-2021-44168 7.8 0.87% 1 1 2025-10-22T00:32:27 A download of code without integrity check vulnerability in the "execute restore
CVE-2026-94545 0 0.00% 2 2 N/A
CVE-2024-87491 0 0.00% 1 0 N/A
CVE-2024-85880 0 0.00% 1 0 N/A
CVE-2024-85046 0 0.00% 1 0 N/A
CVE-2026-89090 0 0.31% 1 0 N/A
CVE-2026-79916 0 0.27% 1 0 N/A
CVE-2026-73550 0 0.88% 1 0 N/A
CVE-2026-73552 0 0.66% 1 0 N/A
CVE-2026-73548 0 0.66% 1 0 N/A
CVE-2026-79920 0 0.36% 1 0 N/A
CVE-2026-83621 0 0.29% 1 0 N/A
CVE-2026-69184 0 0.68% 1 0 N/A
CVE-2026-92702 0 0.21% 1 1 N/A
CVE-2026-61721 0 0.15% 1 0 N/A
CVE-2026-58264 0 0.59% 1 0 N/A
CVE-2026-61819 0 0.58% 1 0 N/A
CVE-2026-61817 0 0.58% 1 0 N/A
CVE-2026-61781 0 0.57% 1 0 N/A
CVE-2026-61820 0 0.58% 1 0 N/A

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 0.66%

updated 2026-09-23T18:22:07.453000

8 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

netsecio@mastodon.social at 2026-09-23T18:06:59.000Z ##

📰 Check Point Zero-Days in Management Servers and VPNs Under Active Attack

CISA KEV Alert: Two critical Check Point zero-days (CVE-2026-93616 & CVE-2026-85102) are under active attack. Flaws in Management Servers & VPN gateways allow RCE. Patch immediately. #CyberSecurity #Vulnerability #CheckPoint #PatchNow

🔗 cyber.netsecops.io/articles/ch

##

secdb@infosec.exchange at 2026-09-22T22:00:21.000Z ##

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85102 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93616 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93952 (secdb.nttzen.cloud/cve/detail/)
- Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Arista
- Product: VeloCloud Orchestrator
- Notes: arista.com/en/support/advisori ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-94127 (secdb.nttzen.cloud/cve/detail/)
- Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: F5
- Product: BIG-IP APM
- Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: my.f5.com/manage/s/article/K00 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

##

security_crawler_carl@infosec.exchange at 2026-09-22T21:31:08.000Z ##

blog.checkpoint.com/security/s

#CyberSecurity #ZeroDay #CheckPoint #Vulnerability #ActiveExploitation #PatchedOrPerish (3/3)

##

security_crawler_carl@infosec.exchange at 2026-09-22T21:31:07.000Z ##

Meanwhile a second zero-day, CVE-2026-93616, materialized in Security Management with its own handful of pinpointed hits.

Policy dictates we inform you patches now exist for both CVE-2026-85102 and CVE-2026-93616. Policy does not require we feel bad about what happens next if you ignore them. Install both immediately.

Reward: Compliance logged. Outcome: your problem. (2/3)

##

campuscodi@mastodon.social at 2026-09-22T20:02:50.000Z ##

Check Point has disclosed a zero-day (in Security Management Server) and marked an older bug also as exploited in the wild (in Site-to-Site VPN)

blog.checkpoint.com/security/s

##

cisakevtracker@mastodon.social at 2026-09-22T20:01:37.000Z ##

CVE ID: CVE-2026-85102
Vendor: Check Point
Product: Multiple Products
Date Added: 2026-09-22
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

ifin@infosec.exchange at 2026-09-22T19:56:52.000Z ##

Two Check Point critical vulnerabilities are now listed as exploited in the wild.

ifin.network/t/cve-2026-85102-

#ThreatIntel #ThreatIntelligence #IFIN

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T16:11:01.000Z ##

An exploited Check Point VPN vulnerability allows remote code execution. Patch this Check Point VPN vulnerability now to block active in-the-wild attacks.

#CheckPoint #CVE202685102 #VPN #Cybersecurity #Infosec #ZeroDay

securityonline.info/checkpoint

##

CVE-2026-73547
(7.5 HIGH)

EPSS: 0.83%

updated 2026-09-23T18:21:42.327000

1 posts

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parameters_to_set or query_parameters_to_remove from an authorization response. A path-less CONNECT request makes request_headers_->Path() return null, and Filter::onCom

thehackerwire@mastodon.social at 2026-09-21T21:01:11.000Z ##

🟠 CVE-2026-73547 - High (7.5)

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parameters_to_se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19599
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-23T18:17:31.543000

4 posts

ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.

DailyCyberSecurity at 2026-09-23T14:35:09.004Z ##

ManageEngine security vulnerabilities expose servers to remote code execution. Patch these OpManager vulnerabilities and CVE-2026-19599 to secure your network.

securityonline.info/manageengi

##

offseq at 2026-09-23T13:30:24.410Z ##

CVE-2026-19599: CRITICAL RCE in ManageEngine OpManager MSP (<12.8.711). Improper OS command neutralization enables remote command execution (CVSS 9.9). Upgrade to 12.8.711+ ASAP. radar.offseq.com/threat/cve-20

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T14:35:09.000Z ##

ManageEngine security vulnerabilities expose servers to remote code execution. Patch these OpManager vulnerabilities and CVE-2026-19599 to secure your network.

#ManageEngine #Cybersecurity #CVE202619599 #OpManager #Infosec #Vulnerability

securityonline.info/manageengi

##

offseq@infosec.exchange at 2026-09-23T13:30:24.000Z ##

CVE-2026-19599: CRITICAL RCE in ManageEngine OpManager MSP (<12.8.711). Improper OS command neutralization enables remote command execution (CVSS 9.9). Upgrade to 12.8.711+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #RCE

##

CVE-2026-18169
(9.9 CRITICAL)

EPSS: 0.78%

updated 2026-09-23T18:17:07.270000

1 posts

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

offseq@infosec.exchange at 2026-09-23T00:00:43.000Z ##

CVE-2026-18169: CRITICAL path traversal in IBM FTM for RedHat OpenShift 4.0.6.0 (CVSS 9.9) 🕵️‍♂️. Authenticated attackers can access sensitive info via symlink abuse. Restrict access & monitor logs. Patch status unknown. radar.offseq.com/threat/cve-20 #OffSeq #IBM #CVE202618169 #Infosec

##

CVE-2026-77322
(7.5 HIGH)

EPSS: 0.61%

updated 2026-09-23T18:12:04.247000

1 posts

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length before ParseMaxMessageLength is applied. An unauthenticated WS or WSS peer can send a frame header declaring an extremely large payload, causing an oversized allo

thehackerwire@mastodon.social at 2026-09-22T21:02:07.000Z ##

🟠 CVE-2026-77322 - High (7.5)

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length before Pa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61714
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-23T18:12:04.247000

1 posts

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active channels. The resulting out-of-bounds reads and writes invoke undefined behavior and may compromise confidentiality, integrity, o

thehackerwire@mastodon.social at 2026-09-20T21:01:11.000Z ##

🟠 CVE-2026-61714 - High (7.8)

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91809
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-23T17:58:26.570000

1 posts

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.

thehackerwire@mastodon.social at 2026-09-23T09:03:07.000Z ##

🟠 CVE-2026-91809 - High (7.8)

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93616
(9.8 CRITICAL)

EPSS: 2.42%

updated 2026-09-23T16:38:38.987000

11 posts

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

2 repos

https://github.com/WadesWeaponShed/CVE-2026-93616_Checks

https://github.com/Nebula-Consulting-Limited/CVE-2026-93616-PoC

netsecio@mastodon.social at 2026-09-23T18:06:59.000Z ##

📰 Check Point Zero-Days in Management Servers and VPNs Under Active Attack

CISA KEV Alert: Two critical Check Point zero-days (CVE-2026-93616 & CVE-2026-85102) are under active attack. Flaws in Management Servers & VPN gateways allow RCE. Patch immediately. #CyberSecurity #Vulnerability #CheckPoint #PatchNow

🔗 cyber.netsecops.io/articles/ch

##

Matchbook3469@mastodon.social at 2026-09-23T12:37:18.000Z ##

🚨 New security advisory:

CVE-2026-93616 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#CVE #VulnerabilityManagement #CyberSec

##

undercodenews@mastodon.social at 2026-09-23T10:29:31.000Z ##

Check Point Emergency Alert: Critical Management Server Zero-Day Is Being Exploited in the Wild + Video

Check Point Emergency Alert: Critical Management Server Zero-Day Is Being Exploited in the Wild A Critical Warning for Security Teams Check Point has issued an urgent security warning after confirming exploitation of a critical vulnerability in its Security Management infrastructure. Tracked as CVE-2026-93616, the flaw carries a CVSS score of 9.8 and can allow an…

undercodenews.com/check-point-

##

secdb@infosec.exchange at 2026-09-22T22:00:21.000Z ##

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85102 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93616 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93952 (secdb.nttzen.cloud/cve/detail/)
- Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Arista
- Product: VeloCloud Orchestrator
- Notes: arista.com/en/support/advisori ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-94127 (secdb.nttzen.cloud/cve/detail/)
- Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: F5
- Product: BIG-IP APM
- Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: my.f5.com/manage/s/article/K00 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

##

security_crawler_carl@infosec.exchange at 2026-09-22T21:31:08.000Z ##

blog.checkpoint.com/security/s

#CyberSecurity #ZeroDay #CheckPoint #Vulnerability #ActiveExploitation #PatchedOrPerish (3/3)

##

security_crawler_carl@infosec.exchange at 2026-09-22T21:31:07.000Z ##

Meanwhile a second zero-day, CVE-2026-93616, materialized in Security Management with its own handful of pinpointed hits.

Policy dictates we inform you patches now exist for both CVE-2026-85102 and CVE-2026-93616. Policy does not require we feel bad about what happens next if you ignore them. Install both immediately.

Reward: Compliance logged. Outcome: your problem. (2/3)

##

campuscodi@mastodon.social at 2026-09-22T20:02:50.000Z ##

Check Point has disclosed a zero-day (in Security Management Server) and marked an older bug also as exploited in the wild (in Site-to-Site VPN)

blog.checkpoint.com/security/s

##

cisakevtracker@mastodon.social at 2026-09-22T20:01:22.000Z ##

CVE ID: CVE-2026-93616
Vendor: Check Point
Product: Multiple Products
Date Added: 2026-09-22
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DarkWebInformer@infosec.exchange at 2026-09-22T18:46:03.000Z ##

🚨 Check Point patches Management Server zero-day exploited in attacks

Check Point has released fixes for CVE-2026-93616, a vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts on affected management servers.

The company says a small number of customers have already been attacked.

Affected products include:

• Security Management Server
• Multi-Domain Security Management Server
• Log Server
• Multi-Domain Log Server
• SmartEvent

The vulnerability carries a CVSS score of 9.8.

Check Point advises installing the applicable fixes, restricting management access to trusted IP addresses, and checking for signs of exploitation.

LivePatch Take 28/29 does not fix this vulnerability.

Source: bleepingcomputer.com/news/secu

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T13:58:15.000Z ##

A critical exploited Check Point Management vulnerability (CVE-2026-93616) allows attackers to execute arbitrary scripts. Secure your servers now.

#CheckPoint #CVE202693616 #Cybersecurity #InfoSec #Vulnerability #RCE

securityonline.info/exploited-

##

offseq@infosec.exchange at 2026-09-22T13:30:26.000Z ##

Check Point Quantum Security Management is affected by CVE-2026-93616 (CRITICAL, CVSS 9.8): unauthenticated attackers can upload & execute scripts via path traversal. Restrict access & monitor activity until patch info is released. radar.offseq.com/threat/cve-20 #OffSeq #CheckPoint #CyberAlert

##

CVE-2026-96257
(10.0 CRITICAL)

EPSS: 1.04%

updated 2026-09-23T15:17:31.920000

1 posts

A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

offseq@infosec.exchange at 2026-09-23T04:30:24.000Z ##

Fast FAC1203R Gigabit Edition v2.0.4 hit by CRITICAL stack-based buffer overflow (CVE-2026-96257). Remote, unauthenticated RCE possible. Exploit is public, no patch exists — restrict access to Device Discovery Service now. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec

##

CVE-2026-19202
(0 None)

EPSS: 0.23%

updated 2026-09-23T15:17:13.647000

1 posts

A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. If an application uses the SDK to authenticate to two or more different audiences within the same process, the module-level token cache fails to key its cached tokens by the requested audience. Consequently, a valid, unexpired token minted

offseq@infosec.exchange at 2026-09-23T06:00:25.000Z ##

CVE-2026-19202: CRITICAL vuln in Google mcp-toolbox-sdk-python (v0 – 1.1.0). Shared cache flaw lets Google ID tokens be reused across audiences — risk of token replay & impersonation. Patch pending. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202619202 #Python

##

CVE-2026-94127
(9.8 CRITICAL)

EPSS: 1.39%

updated 2026-09-23T14:32:07.910000

17 posts

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by

1 repos

https://github.com/FurkanKAYAPINAR/CVE-2026-94127

netsecio@mastodon.social at 2026-09-23T18:07:03.000Z ##

📰 F5 BIG-IP APM Zero-Day (CVE-2026-94127) Actively Exploited for RCE

F5 BIG-IP APM is being actively exploited via a critical RCE zero-day (CVE-2026-94127). CISA has added it to the KEV catalog, mandating an urgent patch. The flaw affects systems with a specific OAuth config. #F5 #BIGIP #CyberSecurity #RCE

🔗 cyber.netsecops.io/articles/f5

##

Matchbook3469@mastodon.social at 2026-09-23T12:02:38.000Z ##

🔴 New security advisory:

CVE-2026-94127 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #PatchNow #InfoSecCommunity

##

sayzard@mastodon.sayzard.org at 2026-09-23T11:41:45.000Z ##

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

F5가 BIG-IP Access Policy Manager(APM)의 OAuth Authorization Server 구성에서 원격 코드 실행(RCE)으로 악용 중인 제로데이 CVE-2026-94127 패치를 배포했다. 영향을 받는 환경은 APM 액세스 정책과 OAuth 프로파일을 가상 서버에 함께 설정한 경우이며, OAuth Client 또는 Resource Server로만 사용하는 배포는 영향 범위에서 제외된다. 관리자는 즉시 보안 업데이트를 적용하고...

bleepingcomputer.com/news/secu

##

undercodenews@mastodon.social at 2026-09-23T11:31:13.000Z ##

Critical F5 BIG-IP APM Zero-Day Exploited for Unauthenticated Remote Code Execution + Video

Introduction A critical vulnerability in F5 BIG-IP Access Policy Manager (APM) is now being exploited in the wild as a zero-day, according to warnings from F5 and the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Tracked as CVE-2026-94127, the flaw carries a CVSS score of 9.8 and can allow an unauthenticated attacker to execute code remotely. The vulnerability is…

undercodenews.com/critical-f5-

##

security_crawler_carl at 2026-09-23T11:14:37.079Z ##

🏆 New Achievement! Terms and Conditions of Your Own Destruction!

LOOTBOX DISCLAIMER: By operating F5 BIG-IP APM versions 21.1.0, 17.5.0–17.5.1, or 17.1.0–17.1.3, you have automatically entered our Unauthenticated Remote Code Execution Sweepstakes. Prizes are awarded via CVE-2026-94127, targeting the OAuth Authorization Server component. Odds of receiving a prize are classified as "active exploitation." The System does not guarantee prize desirability. (1/3)

##

offseq at 2026-09-23T10:30:25.457Z ##

F5 BIG-IP APM (OAuth Authorization Server) is facing a CRITICAL RCE zero-day, CVE-2026-94127, with active exploitation. Versions 21.1.0, 17.5.0 – 17.5.1, 17.1.0 – 17.1.3 affected. Apply hotfixes now. Details: radar.offseq.com/threat/critic

##

undercodenews@mastodon.social at 2026-09-23T10:28:09.000Z ##

F5 BIG-IP Zero-Day Under Active Attack: Critical APM Flaw Enables Unauthenticated Remote Code Execution + Video

A Critical Vulnerability Has Become an Immediate Security Priority F5 has disclosed a critical vulnerability in BIG-IP Access Policy Manager (APM) that is already being exploited in the wild, creating an urgent patching situation for organizations using a specific OAuth configuration. Tracked as CVE-2026-94127, the vulnerability carries a CVSS v3.1 score of…

undercodenews.com/f5-big-ip-ze

##

security_crawler_carl@infosec.exchange at 2026-09-23T11:14:37.000Z ##

🏆 New Achievement! Terms and Conditions of Your Own Destruction!

LOOTBOX DISCLAIMER: By operating F5 BIG-IP APM versions 21.1.0, 17.5.0–17.5.1, or 17.1.0–17.1.3, you have automatically entered our Unauthenticated Remote Code Execution Sweepstakes. Prizes are awarded via CVE-2026-94127, targeting the OAuth Authorization Server component. Odds of receiving a prize are classified as "active exploitation." The System does not guarantee prize desirability. (1/3)

##

offseq@infosec.exchange at 2026-09-23T10:30:25.000Z ##

F5 BIG-IP APM (OAuth Authorization Server) is facing a CRITICAL RCE zero-day, CVE-2026-94127, with active exploitation. Versions 21.1.0, 17.5.0 – 17.5.1, 17.1.0 – 17.1.3 affected. Apply hotfixes now. Details: radar.offseq.com/threat/critic #OffSeq #F5 #ZeroDay #Infosec

##

cyberworldops@infosec.exchange at 2026-09-23T08:20:00.000Z ##

F5 patched CVE-2026-94127, a heap-based buffer overflow in BIG-IP APM when operating as OAuth Authorization Server, enabling remote code execution. Active zero-day exploitation poses high risk of full appliance compromise. Patch immediately and review for crafted malicious traffic. #F5BigIp #ZeroDay #RemoteCodeExecution

cyberworldops.eu/en/actively-e

##

bsi@social.bund.de at 2026-09-23T08:09:54.000Z ##

Der Hersteller F5 veröffentlichte ein Advisory zu einer ausgenutzten Zero-Day Schwachstelle in seinem Produkt BIG-IP Access Policy Manager (APM) zur sicheren Zugriffsteuerung und Anwendungszugriff: CVE-2026-94127, CVSS-Score 9.8/10 ("kritisch")

F5 gibt an, dass die Schwachstelle bereits aktiv ausgenutzt wird. IT-Sicherheitsverantwortliche sollten unverzüglich die Patchstände prüfen und, sofern erforderlich, die verfügbaren Engineering Hotfixes einspielen.

👉️ bsi.bund.de/dok/1209384

##

offseq@infosec.exchange at 2026-09-23T07:30:23.000Z ##

CVE-2026-94127: Critical zero-day in F5 BIG-IP APM exploited for RCE on OAuth Authorization Servers. Patch urgently or use F5's iRule mitigation. Monitor for OAuth auth failures and TMM SIGABRTs. radar.offseq.com/threat/f5-pat #OffSeq #F5 #ZeroDay #RCE #Vuln

##

secdb@infosec.exchange at 2026-09-22T22:00:21.000Z ##

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85102 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93616 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93952 (secdb.nttzen.cloud/cve/detail/)
- Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Arista
- Product: VeloCloud Orchestrator
- Notes: arista.com/en/support/advisori ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-94127 (secdb.nttzen.cloud/cve/detail/)
- Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: F5
- Product: BIG-IP APM
- Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: my.f5.com/manage/s/article/K00 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

##

ifin@infosec.exchange at 2026-09-22T20:51:00.000Z ##

When it rains, it pours. F5 BIG-IP APM also has an exploited CVE!

ifin.network/t/f5-big-ip-cve-2

#ThreatIntel #ThreatIntelligence #IFIN

##

cisakevtracker@mastodon.social at 2026-09-22T20:01:07.000Z ##

CVE ID: CVE-2026-94127
Vendor: F5
Product: BIG-IP APM
Date Added: 2026-09-22
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T16:27:39.000Z ##

An exploited BIG-IP APM vulnerability tracked as CVE-2026-94127 allows RCE attacks. Secure your BIG-IP APM vulnerability deployments with new F5 hotfixes.

#F5 #BIGIP #CVE202694127 #Cybersecurity #InfoSec #RCE #Vulnerability

securityonline.info/big-ip-apm

##

cR0w@infosec.exchange at 2026-09-22T15:03:32.000Z ##

EITW 0day in F5 APM.

my.f5.com/manage/s/article/K00

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). (CVE-2026-94127)

This vulnerability allows an unauthenticated attacker to perform RCE. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.

##

CVE-2026-91811
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-23T09:30:37

1 posts

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an application crash.

thehackerwire@mastodon.social at 2026-09-23T09:03:17.000Z ##

🟠 CVE-2026-91811 - High (7.8)

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an app...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91818
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-23T09:30:37

1 posts

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting in an application crash.

thehackerwire@mastodon.social at 2026-09-23T09:02:58.000Z ##

🟠 CVE-2026-91818 - High (7.8)

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81657
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-09-23T04:17:48.700000

1 posts

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

thehackerwire@mastodon.social at 2026-09-20T18:01:01.000Z ##

🔴 CVE-2026-81657 - Critical (9.8)

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80442
(9.9 CRITICAL)

EPSS: 0.63%

updated 2026-09-23T04:17:48.027000

1 posts

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T17:03:57.000Z ##

🔴 CVE-2026-80442 - Critical (9.9)

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confiden...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-28325
(8.8 HIGH)

EPSS: 1.52%

updated 2026-09-23T04:17:42.200000

1 posts

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.

undercodenews@mastodon.social at 2026-09-23T12:05:14.000Z ##

SolarWinds Fixes Critical Observability RCE Flaws That Could Enable Unauthenticated System Compromise

SolarWinds Releases Emergency Security Update SolarWinds has released Observability Self-Hosted 2026.2.3 to address two serious remote code execution vulnerabilities that could allow unauthenticated attackers to compromise affected deployments. Tracked as CVE-2026-28324 and CVE-2026-28325, the vulnerabilities carry CVSS scores of 9.8 and 8.8, respectively. Both were…

undercodenews.com/solarwinds-f

##

CVE-2026-18162
(9.8 CRITICAL)

EPSS: 0.86%

updated 2026-09-23T00:31:21

1 posts

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.

offseq@infosec.exchange at 2026-09-23T03:00:24.000Z ##

CVE-2026-18162: IBM FTM for RedHat OpenShift v4.0.6.0 has a CRITICAL code injection flaw (CVSS 9.8). Remote attackers can execute arbitrary code via improper input neutralization. No patch yet — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202618162 #IBM #RCE

##

CVE-2026-18163
(9.8 CRITICAL)

EPSS: 0.81%

updated 2026-09-23T00:31:21

1 posts

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.

offseq@infosec.exchange at 2026-09-23T01:30:24.000Z ##

CVE-2026-18163 (CRITICAL, CVSS 9.8): IBM FTM for RedHat OpenShift v4.0.6.0 has a deserialization vulnerability enabling remote code execution without auth. Restrict access & monitor activity. Patch status unconfirmed. radar.offseq.com/threat/cve-20 #OffSeq #CVE202618163 #IBM #InfoSec 🛡️

##

CVE-2026-77987(CVSS UNKNOWN)

EPSS: 0.89%

updated 2026-09-22T21:31:40

1 posts

A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same appliance. Response bodies were not returned to the requester, but response timing acte

cR0w@infosec.exchange at 2026-09-22T21:36:48.000Z ##

Go hack more GitHub shit.

nvd.nist.gov/vuln/detail/cve-2

A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same appliance. Response bodies were not returned to the requester, but response timing acted as an oracle that allowed instance secrets to be extracted character by character. An extracted secret could then be used in a separate interaction with an internal service to obtain remote code execution on the appliance. Exploitation required network access to the instance and was unauthenticated when private mode was disabled, or required any authenticated user when private mode was enabled. This vulnerability affected GitHub Enterprise Server versions 3.17 through 3.22 and was fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported through the GitHub Bug Bounty program.

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

##

CVE-2026-88020
(6.1 MEDIUM)

EPSS: 0.27%

updated 2026-09-22T21:31:39

2 posts

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

cyberworldops at 2026-09-23T11:00:01.225Z ##

CISA reports CVE-2026-88020, XSS in OpenPLC Runtime v3 6.1. Theft of an operator session cookie can enable state-changing requests and PLC-level control. Exposure of OT web interfaces significantly raises impact.

cyberworldops.eu/en/openplc-we

##

cyberworldops@infosec.exchange at 2026-09-23T11:00:01.000Z ##

CISA reports CVE-2026-88020, XSS in OpenPLC Runtime v3 6.1. Theft of an operator session cookie can enable state-changing requests and PLC-level control. Exposure of OT web interfaces significantly raises impact. #IcsSecurity #OtSecurity #Xss

cyberworldops.eu/en/openplc-we

##

CVE-2026-88419
(8.8 HIGH)

EPSS: 0.48%

updated 2026-09-22T21:31:35

1 posts

An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrary PHP code on the server, because the stored file extension is taken verbatim from the client-supplied filename with no extension allowlist or content va

thehackerwire@mastodon.social at 2026-09-22T21:01:48.000Z ##

🟠 CVE-2026-88419 - High (8.8)

An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-28324
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-09-22T21:31:34

3 posts

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

undercodenews@mastodon.social at 2026-09-23T12:05:14.000Z ##

SolarWinds Fixes Critical Observability RCE Flaws That Could Enable Unauthenticated System Compromise

SolarWinds Releases Emergency Security Update SolarWinds has released Observability Self-Hosted 2026.2.3 to address two serious remote code execution vulnerabilities that could allow unauthenticated attackers to compromise affected deployments. Tracked as CVE-2026-28324 and CVE-2026-28325, the vulnerabilities carry CVSS scores of 9.8 and 8.8, respectively. Both were…

undercodenews.com/solarwinds-f

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T01:02:41.000Z ##

SolarWinds Observability vulnerabilities allow RCE via CVE-2026-28324. Update to version 2026.2.3 to secure your monitoring infrastructure today.

#SolarWinds #Cybersecurity #CVE202628324 #CVE202628325 #RCE #Infosec

securityonline.info/solarwinds

##

cR0w@infosec.exchange at 2026-09-22T21:34:44.000Z ##

solarwinds.com/trust-center/se

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

sev:CRIT 9.8 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

##

CVE-2026-87121
(9.8 CRITICAL)

EPSS: 0.78%

updated 2026-09-22T21:31:34

2 posts

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

cR0w@infosec.exchange at 2026-09-22T21:35:40.000Z ##

Go hack more MQTT shit.

nvd.nist.gov/vuln/detail/cve-2

##

thehackerwire@mastodon.social at 2026-09-22T21:01:57.000Z ##

🔴 CVE-2026-87121 - Critical (9.8)

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93952
(10.0 CRITICAL)

EPSS: 0.74%

updated 2026-09-22T21:31:14

13 posts

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been

undercodenews@mastodon.social at 2026-09-23T13:11:17.000Z ##

Arista Patches Actively Exploited VeloCloud Zero-Day as CISA Issues Urgent Warning + Video

A Critical Vulnerability Puts On-Premises VeloCloud Orchestrators Under Attack Arista Networks has released security updates for a maximum-severity zero-day vulnerability in VeloCloud Orchestrator (VCO) On-Prem deployments after confirming that attackers are actively exploiting the flaw in the wild. Tracked as CVE-2026-93952, the vulnerability is an improper input validation…

undercodenews.com/arista-patch

##

Analyst207@mastodon.social at 2026-09-23T12:50:00.000Z ##

Arista Disrupts Actively Exploited Zero-Day in VeloCloud Orchestrator

Arista Networks has sounded the alarm on a critical zero-day vulnerability, CVE-2026-93952, that's being actively exploited in the wild, allowing attackers to access sensitive internal functionality in VeloCloud Orchestrator. This severe flaw can be easily exploited with low complexity, making it a high-risk threat.

osintsights.com/arista-disrupt

#ZeroDay #Cve202693952 #VelocloudOrchestrator #AristaNetworks #SupplyChain

##

undercodenews@mastodon.social at 2026-09-23T11:32:21.000Z ##

Arista Warns of Actively Exploited VeloCloud Zero-Day With CVSS 100 Severity + Video

A Critical Vulnerability Has Been Confirmed Arista has released urgent security fixes for CVE-2026-93952, a critical vulnerability affecting VeloCloud Orchestrator (VCO) on-premises deployments. The company says the flaw is actively exploited in the wild, making this more than a theoretical security issue. Arista Networks The vulnerability carries a CVSS v3.1 score of 10.0, the highest…

undercodenews.com/arista-warns

##

undercodenews@mastodon.social at 2026-09-23T10:27:40.000Z ##

Arista VeloCloud Orchestrator Hit by Actively Exploited CVSS 10 Zero-Day — Administrators Urged to Patch Immediately + Video

Critical Zero-Day Targets VeloCloud Management Infrastructure Arista Networks has released emergency security updates for a critical-severity zero-day vulnerability in on-premises VeloCloud Orchestrator (VCO), the centralized management platform used to configure, monitor, and orchestrate VeloCloud SD-WAN Edge devices. Tracked as CVE-2026-93952,…

undercodenews.com/arista-veloc

##

offseq@infosec.exchange at 2026-09-23T09:00:25.000Z ##

CVE-2026-93952: CRITICAL zero-day in Arista VeloCloud Orchestrator (on-prem <5.2.3.16, <6.4.2.8) is actively exploited. Remote attackers can access privileged functions w/o creds. Patch now — review logs for signs of compromise. radar.offseq.com/threat/arista #OffSeq #Arista #ZeroDay #Infosec

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T08:40:23.000Z ##

Arista confirmed active exploitation of a CVSS 10 VeloCloud Orchestrator vulnerability (CVE-2026-93952) affecting certificate-based SD-WAN setups. Patch now.

#VeloCloud #Arista #CVE202693952 #SDWAN #Vulnerability #CyberSecurity

meterpreter.org/arista-veloclo

##

ifin@infosec.exchange at 2026-09-22T22:28:10.000Z ##

Completing our tour of new known-exploited vulns today, here is Arista's perfect-10.

ifin.network/t/arista-cve-2026

#ThreatIntel #ThreatIntelligence #IFIN

##

secdb@infosec.exchange at 2026-09-22T22:00:21.000Z ##

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85102 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93616 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93952 (secdb.nttzen.cloud/cve/detail/)
- Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Arista
- Product: VeloCloud Orchestrator
- Notes: arista.com/en/support/advisori ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-94127 (secdb.nttzen.cloud/cve/detail/)
- Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: F5
- Product: BIG-IP APM
- Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: my.f5.com/manage/s/article/K00 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

##

cisakevtracker@mastodon.social at 2026-09-22T20:00:51.000Z ##

CVE ID: CVE-2026-93952
Vendor: Arista
Product: VeloCloud Orchestrator
Date Added: 2026-09-22
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops@infosec.exchange at 2026-09-22T14:40:00.000Z ##

Arista disclosed active exploitation of CVE-2026-93952, a CVSS 10.0 unauthenticated flaw in on-prem VeloCloud Orchestrator with certificate authentication enabled. Compromise of the management plane risks full SD-WAN Edge control and lateral movement. Isolate exposed instances and hunt for abuse. #VeloCloud #ThreatIntel #InfoSec

cyberworldops.eu/en/active-att

##

security_crawler_carl@infosec.exchange at 2026-09-22T14:39:04.000Z ##

🏆 New Achievement! Exceeds Expectations (Except Security)!

Thank you for joining us for your annual review, Arista VeloCloud Orchestrator team. Uptime? Stellar. Throughput? Impressive. Unauthorized remote access granted to unauthenticated strangers due to CVE-2026-93952, a CVSS 10.0 critical improper-input-validation flaw currently being actively exploited in the wild? That's a "needs improvement," and frankly it drags down the whole scorecard.

Full system compromise is on the table. (1/2)

##

offseq@infosec.exchange at 2026-09-22T09:00:24.000Z ##

CVE-2026-93952 (CRITICAL, CVSS 10) impacts Arista VeloCloud Orchestrator (On-Prem) via improper input validation. Remote, unauthenticated access may lead to full system compromise. Patch urgently. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec #Vulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T03:14:59.000Z ##

An exploited VeloCloud vulnerability with a 10.0 CVSS score hits Arista appliances. Patch the critical VeloCloud vulnerability to stop active attacks.

#VeloCloud #Arista #CVE202693952 #ZeroDay #Cybersecurity #Infosec

securityonline.info/velocloud-

##

CVE-2026-20282
(4.9 MEDIUM)

EPSS: 0.56%

updated 2026-09-22T21:17:30.440000

1 posts

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain write

cyberworldops@infosec.exchange at 2026-09-21T02:20:00.000Z ##

Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise. #CiscoSecurity #NetworkSecurity #VulnManagement

cyberworldops.eu/en/cisco-fixe

##

CVE-2026-94540
(7.7 HIGH)

EPSS: 0.11%

updated 2026-09-22T20:53:07.383000

1 posts

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform

thehackerwire@mastodon.social at 2026-09-22T00:01:22.000Z ##

🟠 CVE-2026-94540 - High (7.7)

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local servi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94501
(8.8 HIGH)

EPSS: 0.30%

updated 2026-09-22T20:43:58.793000

1 posts

jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-role mappings and access controls to escalate privileges, strip access from other accounts, or modify role-function relationships for any user in the tena

thehackerwire@mastodon.social at 2026-09-21T20:00:56.000Z ##

🟠 CVE-2026-94501 - High (8.8)

jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94626
(7.5 HIGH)

EPSS: 0.45%

updated 2026-09-22T20:25:55.870000

1 posts

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregated deployments to exhaust memory and trigger kernel OOM-kill of the decode worker process.

thehackerwire@mastodon.social at 2026-09-21T23:02:44.000Z ##

🟠 CVE-2026-94626 - High (7.5)

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggreg...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87902
(8.1 HIGH)

EPSS: 0.42%

updated 2026-09-22T20:00:03.713000

8 posts

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

10 repos

https://github.com/zer0dayf/CVE-2026-87902

https://github.com/ressl/cve-2026-87902-poc

https://github.com/bhideki/CVE-2026-87902

https://github.com/dinosn/cve-2026-87902-wordpress-lfi-lab

https://github.com/ynsmroztas/WPSniper

https://github.com/vulpecuna/CVE-2026-87902

https://github.com/rabakuku/CVE-2026-87902-A-working-PoC-for-WordPress-s-critical-path-traversal

https://github.com/Hassham1/CVE-2026-87902

https://github.com/oliveiralimajr/CVE_2026_87902

https://github.com/abraxas/CVE-2026-87902

DailyCyberSecurity at 2026-09-23T15:02:03.272Z ##

An exploited WordPress RCE vulnerability (CVE-2026-87902) is under attack. Details and PoC exploit code are public. Patch your sites now.

securityonline.info/exploited-

##

undercodenews@mastodon.social at 2026-09-23T11:22:57.000Z ##

WordPress 712 Emergency Update Fixes Critical RCE Vulnerability Affecting Versions Back to 47

WordPress has released version 7.1.2, a security update addressing a critical vulnerability that could allow an unauthenticated remote attacker to execute arbitrary PHP code on vulnerable websites under specific server and theme configurations. Tracked as CVE-2026-87902 and GHSA-7hp8-65ch-5whp, the vulnerability has received a CVSS v4 score of 9.2, placing it firmly in the…

undercodenews.com/wordpress-71

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T15:02:03.000Z ##

An exploited WordPress RCE vulnerability (CVE-2026-87902) is under attack. Details and PoC exploit code are public. Patch your sites now.

#WordPress #CVE202687902 #RCE #Cybersecurity #Infosec #ZeroDay

securityonline.info/exploited-

##

obivan@infosec.exchange at 2026-09-23T08:47:19.000Z ##

WordPress unauthenticated LFI to RCE PoC github.com/dinosn/cve-2026-879

##

appinn@m.cmx.im at 2026-09-23T04:13:48.000Z ##

新内容:《WordPress 爆出 9.2 分严重安全漏洞|CVE-2026-87902》
appinn.com/wordpress-cve-2026-
2026年9月23日,WordPress 爆出 9.2 分的严重安全漏洞,攻击者无需登录即可在服务器上运行代码。漏洞编号 CVE-2026-87902,请务必升级至最新版本 7.1.2。@appinn 根据 W3Techs 2026 年 9 月 22 日的最新统计,全球约 40.2% 的网站都在使用

##

technotenshi@infosec.exchange at 2026-09-22T21:07:41.000Z ##

WordPress patched a critical unauthenticated path traversal vulnerability (CVE-2026-87902, GHSA-7hp8-65ch-5whp, CVSS 9.2) in its page-template resolution function get_page_template(), discovered and responsibly disclosed by Robert Ressl. Under specific preconditions, such as an active theme with a top level directory starting with "page-" and a readable local PHP file usable for the pearcmd.php PEAR RCE chain, an attacker could achieve remote code execution with no authentication. WordPress 7.1.2 fixes the issue, and the patch has been backported to every supported branch back to 4.7.37, so all sites should update immediately.

github.com/WordPress/wordpress

#InfoSec #WordPress #Vulnerability #CVE

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T15:47:49.000Z ##

WordPress 7.1.2 patches a critical WordPress RCE vulnerability (CVE-2026-87902). Update your site to prevent conditional remote code execution.

#WordPress #CVE202687902 #RCE #Cybersecurity #Infosec #WordPressSecurity

securityonline.info/wordpress-

##

cyberia@mast.eu.org at 2026-09-22T15:30:11.000Z ##

Service notice: all hosted/maintained WP websites have been updated to the latest minor version of your current major branch (security release, CVE-2026-87902). No action needed from you!

I don't host or maintain your website? Be sure to update your WordPress ASAP. This one is critical.

Release notes → wordpress.org/news/2026/09/wor

#WordPress #Security #Critical #Cyberia

##

CVE-2026-88407
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-22T20:00:03.713000

1 posts

An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.

thehackerwire@mastodon.social at 2026-09-21T22:04:05.000Z ##

🟠 CVE-2026-88407 - High (7.5)

An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88409
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-22T20:00:03.713000

1 posts

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

thehackerwire@mastodon.social at 2026-09-21T22:02:37.000Z ##

🟠 CVE-2026-88409 - High (8.8)

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94054
(7.0 HIGH)

EPSS: 0.27%

updated 2026-09-22T19:56:19.073000

1 posts

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

DailyCyberSecurity@infosec.exchange at 2026-09-21T00:35:40.000Z ##

Exim 4.100.1 patches a serious Exim vulnerability set: Proxy Protocol heap flaws, a GnuTLS use-after-free, and SMTP smuggling (CVE-2026-94054). Upgrade now.

#Exim #EximVulnerability #SMTPsmuggling #ProxyProtocol #MailServerSecurity #CVE202694054

securityonline.info/exim-4-100

##

CVE-2026-86553
(8.8 HIGH)

EPSS: 0.45%

updated 2026-09-22T19:41:38.447000

1 posts

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered email address. By spoofing the application authentication information together wi

1 repos

https://github.com/minanagehsalalma/zte-smartlife-app-pwned

_r_netsec@infosec.exchange at 2026-09-21T16:43:05.000Z ##

ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553 minanagehsalalma.github.io/zte

##

CVE-2026-11726
(8.1 HIGH)

EPSS: 0.46%

updated 2026-09-22T19:32:25.730000

1 posts

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

thehackerwire@mastodon.social at 2026-09-20T23:01:12.000Z ##

🟠 CVE-2026-11726 - High (8.1)

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11727
(8.1 HIGH)

EPSS: 0.61%

updated 2026-09-22T19:32:25.730000

1 posts

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.

thehackerwire@mastodon.social at 2026-09-20T22:04:17.000Z ##

🟠 CVE-2026-11727 - High (8.1)

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85279
(8.6 HIGH)

EPSS: 0.21%

updated 2026-09-22T19:16:54.623000

1 posts

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in PluginsManager::loadPluginFromPath in PowerEditor/src/MISC/PluginsManager/PluginsManager.cpp because the plugin-supplied GetLexerCount() result controls a loop that writes to containers[30] without enforcing NB_MAX_EXTERNAL_LANG. A malicious or compromised plugin that reports more

thehackerwire@mastodon.social at 2026-09-22T19:04:28.000Z ##

🟠 CVE-2026-85279 - High (8.6)

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in PluginsManager::loadPluginFromPath in PowerEditor/src/MISC/PluginsManager/PluginsManager.cpp because the plugin-supplied GetLexer...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84388
(9.6 CRITICAL)

EPSS: 0.38%

updated 2026-09-22T19:09:58.680000

1 posts

A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack

1 repos

https://github.com/ShadowForge-Cyber/CVE-2026-84388-POC

CVE-2026-88411
(7.5 HIGH)

EPSS: 0.28%

updated 2026-09-22T18:34:30

1 posts

Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application.

thehackerwire@mastodon.social at 2026-09-21T22:02:46.000Z ##

🟠 CVE-2026-88411 - High (7.5)

Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89275
(10.0 CRITICAL)

EPSS: 1.25%

updated 2026-09-22T18:33:43

1 posts

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

thehackerwire@mastodon.social at 2026-09-22T19:04:18.000Z ##

🔴 CVE-2026-89275 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93345
(7.5 HIGH)

EPSS: 0.49%

updated 2026-09-22T18:33:35

1 posts

MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum valid for a labelled-VPN NLRI, which passes validation while describing a route with

thehackerwire@mastodon.social at 2026-09-22T19:04:08.000Z ##

🟠 CVE-2026-93345 - High (7.5)

MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REA...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94099
(9.9 CRITICAL)

EPSS: 1.69%

updated 2026-09-22T16:18:17.183000

2 posts

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was c

offseq@infosec.exchange at 2026-09-21T13:30:28.000Z ##

CVE-2026-94099 | Netcore NBR200V2 (1.3.241127.071246): CRITICAL command injection via restore.cgi (QUERY_STRING). Remote exploit, no patch, vendor silent. Isolate devices & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #Netcore #CVE202694099 #infosec

##

thehackerwire@mastodon.social at 2026-09-21T02:03:39.000Z ##

🔴 CVE-2026-94099 - Critical (9.9)

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in comman...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81180
(8.8 HIGH)

EPSS: 0.36%

updated 2026-09-22T16:18:02.227000

2 posts

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operate in the shared temporary directory. An attacker can combine that behavior with a race involving GnuPG configuration files in temporary subdirectories to

hugovalters@mastodon.social at 2026-09-23T16:00:06.000Z ##

CVE-2026-81180 SysReptor: authed users chain Ghostscript image processing with a GnuPG temp-dir race to inject Python into app code, leading to RCE. CVSS 8.8, no patch yet. Restrict uploads and isolate temp dirs until a fix valtersit.com/cve/CVE-2026-811 #CVE #infosec #SysReptor

##

thehackerwire@mastodon.social at 2026-09-21T06:04:18.000Z ##

🟠 CVE-2026-81180 - High (8.8)

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57227
(7.5 HIGH)

EPSS: 0.40%

updated 2026-09-22T16:17:48.827000

1 posts

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appended to one transaction without a limit. Crafted MQTT traffic can grow transaction state indefinitely, consuming CPU and memory and causing slowdown or d

hugovalters@mastodon.social at 2026-09-23T11:10:52.000Z ##

CVE-2026-57227 Suricata MQTT parser DoS, CVSS 7.5. Unbounded PUBREC/PUBREL floods grow transaction state until CPU and memory exhaust. No patch confirmed yet. Update Suricata immediately. valtersit.com/cve/CVE-2026-572 #CVE #infosec #Suricata

##

CVE-2026-95675
(9.8 CRITICAL)

EPSS: 3.91%

updated 2026-09-22T15:32:43

1 posts

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the loc

DailyCyberSecurity@infosec.exchange at 2026-09-23T00:38:45.000Z ##

Technical details and a PoC for the D-Link DAP-1360 vulnerability (CVE-2026-95675) are public. Learn how this unauthenticated flaw impacts legacy routers.

#DLink #DAP1360 #CVE202695675 #RCE #RouterSecurity #Cybersecurity

securityonline.info/d-link-dap

##

CVE-2026-65113
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-09-22T15:32:43

1 posts

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.

CVE-2026-88406
(7.5 HIGH)

EPSS: 0.27%

updated 2026-09-22T15:32:31

1 posts

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

thehackerwire@mastodon.social at 2026-09-21T22:03:55.000Z ##

🟠 CVE-2026-88406 - High (7.5)

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76698
(6.5 MEDIUM)

EPSS: 4.44%

updated 2026-09-22T15:17:15.030000

1 posts

A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote attacker with limited access privileges could exploit this vulnerability through specially crafted input. Successful exploitation, under certain conditions, could result in the execution of arbitrary commands with elevated privileges or a denial-of-s

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-73512
(7.5 HIGH)

EPSS: 0.83%

updated 2026-09-22T14:17:14.037000

1 posts

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream recreation, including an internal redirect, replaces the ActiveStream and updates EnvoyQuicServerStream but does not update the handler's cached pointer. A subseque

thehackerwire@mastodon.social at 2026-09-21T21:03:01.000Z ##

🟠 CVE-2026-73512 - High (7.5)

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream recreation,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74849
(9.8 CRITICAL)

EPSS: 4.46%

updated 2026-09-22T12:30:32

2 posts

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.

undercodenews@mastodon.social at 2026-09-23T11:21:39.000Z ##

ManageEngine ADSelfService Plus Vulnerability Lets Attackers Execute Code as SYSTEM Before Windows Login + Video

A Critical Weakness at the Windows Sign-In Screen ManageEngine has addressed a high-severity remote code execution vulnerability in ADSelfService Plus that could allow an attacker with physical access to a Windows computer to execute arbitrary code with NT AUTHORITY\SYSTEM privileges—even before a legitimate user signs in. Tracked as CVE-2026-74849, the…

undercodenews.com/manageengine

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T16:23:55.000Z ##

A critical ManageEngine ADSelfService Plus vulnerability (CVE-2026-74849) allows system compromise. Update to build 7001 to secure your endpoints.

#ManageEngine #ADSelfServicePlus #CVE202674849 #Cybersecurity #Infosec #RCE

securityonline.info/manageengi

##

CVE-2026-25254
(9.8 CRITICAL)

EPSS: 0.73%

updated 2026-09-22T12:30:25

1 posts

Improper authorization leads to Remote Code Execution via SocketIO interface.

offseq@infosec.exchange at 2026-09-22T10:30:25.000Z ##

Qualcomm Snapdragon devices hit by CRITICAL CVE-2026-25254: improper authorization in SocketIO allows unauthenticated RCE. No patch yet; monitor advisories and review exposure. CVSS 9.8. radar.offseq.com/threat/cve-20 #OffSeq #CVE202625254 #Snapdragon #Infosec #Vuln

##

CVE-2026-7273
(8.8 HIGH)

EPSS: 2.41%

updated 2026-09-22T12:10:51.067000

8 posts

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

beyondmachines1 at 2026-09-23T10:01:13.231Z ##

Zyxel GS1900 Switches Targeted by Chinese Threat Actor in Data Theft Campaign

Zyxel GS1900 series switches are under active exploitation by a Chinese threat actor using a high-severity buffer overflow (CVE-2026-7273) to steal sensitive data from nearly 1,000 devices worldwide. The campaign has compromised government records and relies on unpatched firmware and default credentials to gain system control.

**If you have Zyxel GS1900 series switches, make sure their management interface is isolated from the internet, accessible from trusted networks only and all default passwords are changed. Then update the firmware to version 2.90(xxxx.2)C0 or later ASAP and check the switches for signs of breach. Attackers are actively exploiting this flaw.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-23T10:01:13.000Z ##

Zyxel GS1900 Switches Targeted by Chinese Threat Actor in Data Theft Campaign

Zyxel GS1900 series switches are under active exploitation by a Chinese threat actor using a high-severity buffer overflow (CVE-2026-7273) to steal sensitive data from nearly 1,000 devices worldwide. The campaign has compromised government records and relies on unpatched firmware and default credentials to gain system control.

**If you have Zyxel GS1900 series switches, make sure their management interface is isolated from the internet, accessible from trusted networks only and all default passwords are changed. Then update the firmware to version 2.90(xxxx.2)C0 or later ASAP and check the switches for signs of breach. Attackers are actively exploiting this flaw.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

jbhall56@infosec.exchange at 2026-09-22T11:48:40.000Z ##

The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating system (OS) command execution. thehackernews.com/2026/09/zyxe

##

cyberworldops@infosec.exchange at 2026-09-22T10:40:00.000Z ##

CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 CGI handling, to KEV on Sept 21, 2026 after confirmed active exploitation. Unauthenticated LAN HTTP requests can yield OS command execution, risking switch takeover and lateral movement. #Zyxel #KnownExploitedVulnerabilities #NetworkSecurity

cyberworldops.eu/en/actively-e

##

cyberworldops@infosec.exchange at 2026-09-22T08:30:01.000Z ##

Zyxel GS1900 switches (CVE-2026-7273) and Veeam Agent for Microsoft Windows (CVE-2026-32996) are under active exploitation. The former allows unauthenticated LAN command execution via CGI buffer overflow, the latter enables SYSTEM-level access on endpoints. Both expand persistence and backup tampering risk. #Zyxel #Veeam #ThreatIntel #VulnManagement

cyberworldops.eu/en/active-att

##

thecybermind@infosec.exchange at 2026-09-21T23:33:43.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-7273 – Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

Analyze the executive impact of CVE-2026-7273 with our strategic Zyxel CSUITE brief, covering zero-trust network segmentation, asset risk assessment, and CISA compliance....

thecybermind.co/18gk

##

secdb@infosec.exchange at 2026-09-21T21:00:18.000Z ##

🚨 [CISA-2026:0921] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-7273 (secdb.nttzen.cloud/cve/detail/)
- Name: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Zyxel
- Product: GS1900 Series Switches
- Notes: zyxel.com/global/en/support/se ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260921 #cisa20260921 #cve_2026_7273 #cve20267273

##

cisakevtracker@mastodon.social at 2026-09-21T20:00:49.000Z ##

CVE ID: CVE-2026-7273
Vendor: Zyxel
Product: GS1900 Series Switches
Date Added: 2026-09-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-13355
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-09-22T06:30:35

1 posts

The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET parameter 'rwmb_frontend_field_object_id' without any authorization check, and Form::p

1 repos

https://github.com/murrez/CVE-2026-13355

offseq@infosec.exchange at 2026-09-22T07:30:24.000Z ##

Privilege escalation (CRITICAL, CVE-2026-13355) in Meta Box Frontend Submission <=4.5.6 & User Profile <=3.11.0 lets unauthenticated attackers gain admin on WordPress. Patch status TBD — restrict plugin use & monitor activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_13355

##

CVE-2026-19658
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-09-22T06:30:35

1 posts

The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is i

1 repos

https://github.com/murrez/CVE-2026-19658

offseq@infosec.exchange at 2026-09-22T06:00:28.000Z ##

LiquidWeb Give Tributes <=2.3.1 is vulnerable (CVE-2026-19658, CRITICAL) to PHP Object Injection via unsafe deserialization. Only exploitable if a POP chain is present from other plugins/themes. Mitigate by disabling "Allow Multiple Recipients" or enabling eCard msg. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202619658

##

CVE-2026-94301
(9.8 CRITICAL)

EPSS: 0.39%

updated 2026-09-22T04:18:02.810000

1 posts

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the  2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed a

cR0w@infosec.exchange at 2026-09-21T15:49:50.000Z ##

sev:CRIT bypass of CVE-2026-47065 in Apache MINA.

nvd.nist.gov/vuln/detail/cve-2

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.

##

CVE-2026-94493
(10.0 CRITICAL)

EPSS: 0.73%

updated 2026-09-22T03:31:06

1 posts

A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

offseq@infosec.exchange at 2026-09-22T01:30:25.000Z ##

CVE-2026-94493 (CRITICAL, CVSS 10) in Gigatech PDV5701 1.0.31_240305_112640: WebSocket Service has missing authentication. Remote exploit is public, no vendor fix. Isolate devices, monitor for attacks. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity

##

CVE-2026-94627
(7.5 HIGH)

EPSS: 0.45%

updated 2026-09-22T00:31:02

1 posts

vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by submitting completion requests with multiple prompts, causing orphaned KV cache blocks to accumulate until process restart and eventually preventing legitima

thehackerwire@mastodon.social at 2026-09-22T00:01:13.000Z ##

🟠 CVE-2026-94627 - High (7.5)

vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by subm...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94425
(8.8 HIGH)

EPSS: 0.11%

updated 2026-09-22T00:31:02

2 posts

A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege management. Attacking locally is a requirement. The vendor was contacted early about this disclosure but did not respond in any way.

thehackerwire@mastodon.social at 2026-09-22T00:01:02.000Z ##

🟠 CVE-2026-94425 - High (8.8)

A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege management. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-22T00:00:35.000Z ##

CVE-2026-94425 (CRITICAL, CVSS 9.3) hits Moore Threads MTT S80 Driver v340.150 🛡️. Improper privilege management in IOCTL Handler allows local escalation. No patch yet. Limit local access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vuln #PrivilegeEscalation #Infosec

##

CVE-2026-94624
(7.5 HIGH)

EPSS: 0.45%

updated 2026-09-22T00:31:02

1 posts

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that

thehackerwire@mastodon.social at 2026-09-21T23:02:35.000Z ##

🟠 CVE-2026-94624 - High (7.5)

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94623
(7.5 HIGH)

EPSS: 0.45%

updated 2026-09-22T00:31:01

1 posts

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of va

thehackerwire@mastodon.social at 2026-09-21T23:02:26.000Z ##

🟠 CVE-2026-94623 - High (7.5)

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12249
(9.0 None)

EPSS: 0.14%

updated 2026-09-21T22:27:11

1 posts

An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py), ADSys utilizes a plaintext HTTP connection (http://) instead of a secure HTTPS connection (https://) to request the CA ce

beyondmachines1@infosec.exchange at 2026-09-23T09:01:13.000Z ##

Canonical Patches Critical Trust Store Poisoning Flaw in ADSys

Canonical patched a critical vulnerability (CVE-2026-12249) in ADSys that allows attackers to poison the Ubuntu system trust store by intercepting unencrypted certificate enrollment requests. This flaw enables persistent decryption of TLS traffic and full compromise of encrypted communications on affected hosts.

**If you manage Ubuntu machines connected to Active Directory through ADSys, update ADSys to version 0.16.3 or later on all of them. Oder versions fetch certificates over unencrypted HTTP and let an attacker plant a fake root certificate that exposes all encrypted traffic on the machine. After updating, check each machine's trusted certificates for any unfamiliar root certificates and remove them, since a machine that was already compromised stays exposed even after the patch.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-81469
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-21T21:32:01

1 posts

Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges

thehackerwire@mastodon.social at 2026-09-21T21:00:59.000Z ##

🟠 CVE-2026-81469 - High (7.8)

Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94497
(8.3 HIGH)

EPSS: 0.26%

updated 2026-09-21T21:32:00

1 posts

jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers without authorization checks.

thehackerwire@mastodon.social at 2026-09-21T20:00:43.000Z ##

🟠 CVE-2026-94497 - High (8.3)

jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifier...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94424
(8.8 HIGH)

EPSS: 0.14%

updated 2026-09-21T21:31:57

1 posts

A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.

thehackerwire@mastodon.social at 2026-09-21T22:02:26.000Z ##

🟠 CVE-2026-94424 - High (8.8)

A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An att...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94411
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-21T21:31:53

1 posts

jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST request with type=UserRole, their own user ID, and a role ID list to escalate from low-privilege tenant user to tenant administrator.

thehackerwire@mastodon.social at 2026-09-21T20:01:05.000Z ##

🟠 CVE-2026-94411 - High (8.8)

jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST request with type=UserRole, their own user ID, and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77560
(8.1 HIGH)

EPSS: 0.33%

updated 2026-09-21T21:17:11.637000

1 posts

Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to bypass per-app access controls with a differently cased hostname. The lookup in internal/service/access_controls_service.go through lookupStaticACLs and Get

thehackerwire@mastodon.social at 2026-09-21T18:01:33.000Z ##

🟠 CVE-2026-77560 - High (8.1)

Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to byp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94142
(8.8 HIGH)

EPSS: 0.13%

updated 2026-09-21T20:17:40.953000

2 posts

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argument PhysicalAddress leads to write-what-where condition. The attack needs to be performed locally. The exploit has been disclosed publicly and may be use

thehackerwire@mastodon.social at 2026-09-21T06:03:51.000Z ##

🟠 CVE-2026-94142 - High (8.8)

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argum...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-21T06:00:25.000Z ##

BioStar Temp Monitor Utility v1.2.1806.2200 hit by CRITICAL CVE-2026-94142 (CVSS 9.3): write-what-where flaw in IOCTL handler. Local attackers can write arbitrary memory. No patch — restrict access. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202694142 #infosec #vuln

##

CVE-2026-93958
(9.1 CRITICAL)

EPSS: 2.17%

updated 2026-09-21T19:17:18.593000

1 posts

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

1 repos

https://github.com/HackSpeak/CVE-2026-93958

CVE-2026-68928
(8.6 HIGH)

EPSS: 0.13%

updated 2026-09-21T19:17:09.157000

1 posts

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins/terminal/src/android/TerminalService.java does not verify the caller. Any installed Android application can bind the service and send MSG_EXEC with an a

hugovalters@mastodon.social at 2026-09-23T17:30:27.000Z ##

CVE-2026-68928: Acode for Android exported TerminalService lets any installed app run arbitrary shell commands via MSG_EXEC. CVSS 8.6. No patch yet - restrict or update now. valtersit.com/cve/CVE-2026-689 #CVE #Android #infosec

##

CVE-2026-80521
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-21T15:32:39

4 posts

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: X -. A <-> B ^--' 2) Run the following concurrently: 2-1) send() sk-B to sk-B from sk-X 2-2) close() both A and B At 2-1), there is a sm

1 repos

https://github.com/Markakd/Container_escape

guru@thecybersecguru.com at 2026-09-23T12:54:00.000Z ##

Exploit released for unpatched Ubuntu kernel flaw that lets containers root the host (CVE-2026-80521)

CVE-2026-80521 is a Linux kernel AF_UNIX use-after-free that enables container escape to host root. Ubuntu 22.04, 24.04 and 26.04 remain vulnerable

thecybersecguru.com/news/cve-2

##

Analyst207@mastodon.social at 2026-09-23T12:53:05.000Z ##

Ubuntu Linux Flaw Exposed, Enabling Host-Root Container Escape

A newly discovered Linux kernel flaw, CVE-2026-80521, can allow code running inside a container to gain root access on the host, posing a significant security risk. This alarming vulnerability is just one of nearly 5,700 Linux kernel CVEs published in 2026, a record high.

osintsights.com/ubuntu-linux-f

#LinuxKernelFlaw #UbuntuLinux #Cve202680521 #ContainerSecurity #HostrootContainerEscape

##

undercodenews@mastodon.social at 2026-09-23T12:45:06.000Z ##

Linux Kernel Container Escape Warning: Unpatched AF_UNIX Flaw Comes With a Working Ubuntu Exploit + Video

A newly disclosed Linux kernel vulnerability is putting containerized workloads under renewed scrutiny after researchers demonstrated that an attacker operating inside a container can potentially escape isolation and obtain root-level control over the host. Tracked as CVE-2026-80521, the vulnerability is a use-after-free condition in the Linux kernel's AF_UNIX…

undercodenews.com/linux-kernel

##

guru@thecybersecguru.com at 2026-09-23T12:54:00.000Z ##

Exploit released for unpatched Ubuntu kernel flaw that lets containers root the host (CVE-2026-80521)

CVE-2026-80521 is a Linux kernel AF_UNIX use-after-free that enables container escape to host root. Ubuntu 22.04, 24.04 and 26.04 remain vulnerable

thecybersecguru.com/news/cve-2

##

CVE-2026-92701
(9.1 CRITICAL)

EPSS: 0.22%

updated 2026-09-21T15:17:35.313000

1 posts

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checkin

1 repos

https://github.com/muhammad-usama-sardar/intra-handshake-fail

thehackerwire@mastodon.social at 2026-09-21T00:01:18.000Z ##

🔴 CVE-2026-92701 - Critical (9.1)

trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote valid...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82187
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-09-21T15:17:32.223000

1 posts

The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.

offseq@infosec.exchange at 2026-09-21T09:00:25.000Z ##

Web to Print Online Designer plugin (v1.7.0 – 2.14.9) hit by CRITICAL CVE-2026-82187: unauthenticated attackers can upload & execute arbitrary files (incl. PHP), leading to RCE. Upgrade to 2.15.0+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202682187 #RCE

##

CVE-2026-87067
(8.5 HIGH)

EPSS: 0.28%

updated 2026-09-21T13:34:57.127000

1 posts

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Formina

thehackerwire@mastodon.social at 2026-09-20T16:01:30.000Z ##

🟠 CVE-2026-87067 - High (8.5)

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94097
(10.0 CRITICAL)

EPSS: 1.99%

updated 2026-09-21T13:33:33.387000

1 posts

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about t

thehackerwire@mastodon.social at 2026-09-21T01:01:54.000Z ##

🔴 CVE-2026-94097 - Critical (10)

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command inje...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94146
(8.8 HIGH)

EPSS: 0.12%

updated 2026-09-21T09:31:09

1 posts

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosur

offseq@infosec.exchange at 2026-09-21T07:30:25.000Z ##

BioStar BIOS Update Utility 1.9.7.3 hit by CRITICAL CVE-2026-94146: local write-what-where bug in BSMEM64_W10.sys (IOCTL handler). Exploit public; vendor silent. Restrict local access immediately. radar.offseq.com/threat/cve-20 #OffSeq #CVE202694146 #bios #infosec

##

CVE-2026-94128
(8.8 HIGH)

EPSS: 0.12%

updated 2026-09-21T03:30:29

2 posts

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where condition. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early abo

1 repos

https://github.com/lzty/CVE-2026-94128

offseq@infosec.exchange at 2026-09-21T04:30:23.000Z ##

BioStar VIVID LED DJ 4.0.2411.1500 hit by CRITICAL CVE-2026-94128: write-what-where in BS_LED64.sys allows local attackers arbitrary memory writes. No patch — restrict local access, monitor updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE202694128 #PrivilegeEscalation

##

thehackerwire@mastodon.social at 2026-09-21T03:02:01.000Z ##

🟠 CVE-2026-94128 - High (8.8)

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94101
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-09-21T03:30:27

2 posts

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did

offseq@infosec.exchange at 2026-09-21T12:00:26.000Z ##

Netcore NBR200V2 (v1.3.241127.071246) hit by CRITICAL CVE-2026-94101 buffer overflow in /usr/bin/routerd. Remote code exec possible. Public exploit, no patch. Restrict remote access ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Netcore #RouterSecurity #Infosec

##

thehackerwire@mastodon.social at 2026-09-21T03:02:20.000Z ##

🔴 CVE-2026-94101 - Critical (9.9)

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is possib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94129
(8.8 HIGH)

EPSS: 0.12%

updated 2026-09-21T03:30:27

2 posts

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-what-where condition. The attack needs to be approached locally. The exploit is now public and may be used. The vendor was contacted early about this dis

1 repos

https://github.com/lzty/CVE-2026-94129

thehackerwire@mastodon.social at 2026-09-21T03:02:10.000Z ##

🟠 CVE-2026-94129 - High (8.8)

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-21T03:00:26.000Z ##

CVE-2026-94129 (CRITICAL, CVSS 9.3) impacts BioStar VALKYRIE AURORA 2.10.2411.0800: local write-what-where in IOCTL Handler (BS_RVSIO64.sys) enables privilege escalation. No patch, public exploit exists. Limit local access. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec

##

CVE-2026-94100
(9.9 CRITICAL)

EPSS: 0.46%

updated 2026-09-21T03:30:23

2 posts

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The v

thehackerwire@mastodon.social at 2026-09-21T02:03:21.000Z ##

🔴 CVE-2026-94100 - Critical (9.9)

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-21T01:30:23.000Z ##

Netcore NBR200V2 v1.3.241127.071246 has a CRITICAL buffer overflow (CVE-2026-94100) in WAN VLAN config. Remotely exploitable, public exploit out. Restrict access — no patch yet. radar.offseq.com/threat/cve-20 #OffSeq #Netcore #CVE202694100 #Infosec

##

CVE-2026-94098
(9.1 CRITICAL)

EPSS: 2.38%

updated 2026-09-21T03:30:22

1 posts

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this di

thehackerwire@mastodon.social at 2026-09-21T02:03:30.000Z ##

🔴 CVE-2026-94098 - Critical (9.1)

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94096
(9.9 CRITICAL)

EPSS: 1.65%

updated 2026-09-21T00:30:33

2 posts

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this d

thehackerwire@mastodon.social at 2026-09-21T01:01:44.000Z ##

🔴 CVE-2026-94096 - Critical (9.9)

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-21T00:00:35.000Z ##

Netcore NBR200V2 (v1.3.241127.071246) hit by CRITICAL (CVSS 9.4) command injection (CVE-2026-94096) in /usr/bin/network_tools. Remote exploit is public, no patch. Isolate devices and monitor traffic. radar.offseq.com/threat/cve-20 #OffSeq #CVE202694096 #Netcore #Infosec

##

CVE-2026-94095
(9.9 CRITICAL)

EPSS: 1.67%

updated 2026-09-21T00:30:33

1 posts

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacte

1 repos

https://github.com/HackSpeak/CVE-2026-94095

thehackerwire@mastodon.social at 2026-09-21T01:01:34.000Z ##

🔴 CVE-2026-94095 - Critical (9.9)

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument ur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94089
(10.0 CRITICAL)

EPSS: 0.98%

updated 2026-09-20T21:31:45

1 posts

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

thehackerwire@mastodon.social at 2026-09-20T22:02:07.000Z ##

🔴 CVE-2026-94089 - Critical (10)

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94036
(8.8 HIGH)

EPSS: 0.47%

updated 2026-09-20T18:31:25

1 posts

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.

1 repos

https://github.com/djzzlim/CVE-2026-94036

thehackerwire@mastodon.social at 2026-09-20T17:03:09.000Z ##

🟠 CVE-2026-94036 - High (8.8)

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85017
(7.5 HIGH)

EPSS: 0.24%

updated 2026-09-20T15:31:26

1 posts

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable ac

thehackerwire@mastodon.social at 2026-09-20T16:01:21.000Z ##

🟠 CVE-2026-85017 - High (7.5)

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87839
(7.5 HIGH)

EPSS: 0.21%

updated 2026-09-20T15:30:26

1 posts

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.

thehackerwire@mastodon.social at 2026-09-20T17:03:48.000Z ##

🟠 CVE-2026-87839 - High (7.5)

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94084
(9.4 CRITICAL)

EPSS: 0.40%

updated 2026-09-20T03:30:29

2 posts

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

cR0w@infosec.exchange at 2026-09-21T13:27:36.000Z ##

RE: infosec.exchange/@suricata/117

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

##

beyondmachines1@infosec.exchange at 2026-09-21T08:01:12.000Z ##

Suricata Patches Flaws Allowing Network Monitoring Bypass

Suricata 8.0.7 fixes two vulnerabilities (CVE-2026-94084 and CVE-2026-94083) that allow unauthenticated attackers to crash the IDS/IPS engine. These flaws exploit the HTTP/2 and DoH2 parsers to create a monitoring blind spot for network bypass.

**If you run Suricata for network monitoring, update it to version 8.0.7 ASAP. Older versions can be crashed remotely, leaving your network unmonitored and your attack detection blind. Until you patch, closely monitor that the Suricata service is actually running, because an unexpected stop may mean someone is already attacking you.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-94083
(9.4 CRITICAL)

EPSS: 0.40%

updated 2026-09-20T03:30:29

2 posts

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.

cR0w@infosec.exchange at 2026-09-21T13:27:36.000Z ##

RE: infosec.exchange/@suricata/117

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

##

beyondmachines1@infosec.exchange at 2026-09-21T08:01:12.000Z ##

Suricata Patches Flaws Allowing Network Monitoring Bypass

Suricata 8.0.7 fixes two vulnerabilities (CVE-2026-94084 and CVE-2026-94083) that allow unauthenticated attackers to crash the IDS/IPS engine. These flaws exploit the HTTP/2 and DoH2 parsers to create a monitoring blind spot for network bypass.

**If you run Suricata for network monitoring, update it to version 8.0.7 ASAP. Older versions can be crashed remotely, leaving your network unmonitored and your attack detection blind. Until you patch, closely monitor that the Suricata service is actually running, because an unexpected stop may mean someone is already attacking you.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-93485
(7.1 HIGH)

EPSS: 0.16%

updated 2026-09-19T15:17:08.323000

2 posts

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.1

2 repos

https://github.com/0xBlackash/CVE-2026-93485

https://github.com/HORKimhab/CVE-2026-93485

DailyCyberSecurity at 2026-09-23T12:59:52.725Z ##

Details and PoC exploit code for a critical WordPress stored XSS are public. Learn how CVE-2026-93485 enables RCE and patch WordPress today.

securityonline.info/wordpress-

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T12:59:52.000Z ##

Details and PoC exploit code for a critical WordPress stored XSS are public. Learn how CVE-2026-93485 enables RCE and patch WordPress today.

#WordPress #CVE202693485 #StoredXSS #RCE #Cybersecurity #Infosec

securityonline.info/wordpress-

##

CVE-2026-61821
(8.5 HIGH)

EPSS: 0.29%

updated 2026-09-19T15:17:00.153000

1 posts

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for ALTER TABLE SET SCHEMA and accept any nonempty schema name. A role with partman_user access can select a target schema where the role lacks the normal CREATE privilege, and the background worker performs

thehackerwire@mastodon.social at 2026-09-20T19:00:56.000Z ##

🟠 CVE-2026-61821 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for ALTER TABLE SET SCHEMA and accept any nonempty sch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61818
(8.5 HIGH)

EPSS: 0.41%

updated 2026-09-19T15:17:00.040000

1 posts

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with partman_user access can store SQL rather than a function name, and the SQL executes with the privileges of the caller that inv

thehackerwire@mastodon.social at 2026-09-20T20:01:02.000Z ##

🟠 CVE-2026-61818 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting into a dynamically executed SEL...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-39964
(7.8 HIGH)

EPSS: 0.79%

updated 2026-09-19T04:17:48.307000

2 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates

3 repos

https://github.com/mc493/linux-kernel-zero-day-mitigation-zero-downtime-kernel-defense-

https://github.com/n1k0oowang/CVE-2025-39964_EXP

https://github.com/suominen/CVE-2025-39964

thecybermind@infosec.exchange at 2026-09-21T12:02:57.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2025-39964 – Linux Kernel Race Condition Vulnerability

Analyze the mechanics of CVE-2025-39964 with our technical Linux TSUITE brief, covering AF_ALG race conditions, CrowdStrike CQL queries, and endpoint hardening....

thecybermind.co/dxag

##

cyberworldops@infosec.exchange at 2026-09-21T10:40:00.000Z ##

CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV

cyberworldops.eu/en/three-expl

##

CVE-2026-81626
(8.6 HIGH)

EPSS: 0.27%

updated 2026-09-18T21:32:37

1 posts

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T17:04:07.000Z ##

🟠 CVE-2026-81626 - High (8.6)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84071
(7.2 HIGH)

EPSS: 1.45%

updated 2026-09-18T21:32:36

1 posts

IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.

hugovalters@mastodon.social at 2026-09-23T12:50:03.000Z ##

CVE-2026-84071: IBM Guardium Data Protection 12.2 OS command injection in Universal Connector plugin upload. Auth attacker can run commands as root. CVSS 7.2, no patch yet. Restrict access and monitor. valtersit.com/cve/CVE-2026-840 #CVE #infosec #IBM

##

CVE-2026-75878
(9.1 CRITICAL)

EPSS: 0.48%

updated 2026-09-18T21:32:35

1 posts

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

thehackerwire@mastodon.social at 2026-09-20T18:01:11.000Z ##

🔴 CVE-2026-75878 - Critical (9.1)

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81656
(8.8 HIGH)

EPSS: 0.29%

updated 2026-09-18T21:32:35

1 posts

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T18:00:51.000Z ##

🟠 CVE-2026-81656 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resultin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11716
(7.5 HIGH)

EPSS: 0.45%

updated 2026-09-18T21:32:28

1 posts

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.

thehackerwire@mastodon.social at 2026-09-20T23:01:21.000Z ##

🟠 CVE-2026-11716 - High (7.5)

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11725
(8.8 HIGH)

EPSS: 0.40%

updated 2026-09-18T21:32:28

1 posts

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

thehackerwire@mastodon.social at 2026-09-20T22:04:27.000Z ##

🟠 CVE-2026-11725 - High (8.8)

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17619
(8.6 HIGH)

EPSS: 0.30%

updated 2026-09-18T21:32:26

1 posts

IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

thehackerwire@mastodon.social at 2026-09-20T22:04:07.000Z ##

🟠 CVE-2026-17619 - High (8.6)

IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-39682
(7.1 HIGH)

EPSS: 2.03%

updated 2026-09-18T21:31:33

1 posts

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we break out of the main processing loop. If the record has already been decrypted

3 repos

https://github.com/mc493/linux-kernel-zero-day-mitigation-zero-downtime-kernel-defense-

https://github.com/khoatran107/cve-2025-39682

https://github.com/suominen/CVE-2025-39682

cyberworldops@infosec.exchange at 2026-09-21T10:40:00.000Z ##

CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV

cyberworldops.eu/en/three-expl

##

CVE-2026-81179
(8.1 HIGH)

EPSS: 0.26%

updated 2026-09-18T20:17:23.470000

1 posts

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password reset link. An unauthenticated attacker can request a reset email whose link points to an attacker-controlled system, and a victim who follows that link

thehackerwire@mastodon.social at 2026-09-21T01:03:02.000Z ##

🟠 CVE-2026-81179 - High (8.1)

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13639
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-18T20:17:06.860000

1 posts

An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

cyberveille@mastobot.ping.moi at 2026-09-22T07:30:06.000Z ##

📢 [VULN] Alerte sécurité : deux vulnérabilités majeures menacent vos NAS Synology - CVE-2026-13684 CVE-2026-13639

Huit vulnérabilités viennent d'être identifiées dans le système d'exploitation DiskStation Manager de Synology, dont deux atteignent un score de gravité maximal de 9.8. Ces failles critiques permettent à des attaquants distants de lire, d'écrire ou d'effacer vos fichiers sans aucune…

🔗 generation-nt.com/actualites/a
💬 discussion : infosec.pub/post/52624526
#Vulnérabilité #CVE #Cyberveille

##

CVE-2026-93749
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-18T18:32:09

1 posts

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event loop blocking for extended periods, preventing the service from handling other requests.

thehackerwire@mastodon.social at 2026-09-21T00:01:08.000Z ##

🟠 CVE-2026-93749 - High (7.5)

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event lo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93748
(7.5 HIGH)

EPSS: 0.40%

updated 2026-09-18T18:32:07

1 posts

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zero

thehackerwire@mastodon.social at 2026-09-20T23:01:32.000Z ##

🟠 CVE-2026-93748 - High (7.5)

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can reques...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93762
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-09-18T18:32:01

1 posts

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.

DailyCyberSecurity@infosec.exchange at 2026-09-21T01:16:31.000Z ##

Critical MongoDB driver vulnerabilities, including CVE-2026-93762, expose systems to data loss and DoS. Learn about these flaws and patch immediately.

#MongoDB #Cybersecurity #Vulnerability #Infosec #CVE

securityonline.info/mongodb-dr

##

CVE-2026-10747
(10.0 CRITICAL)

EPSS: 0.52%

updated 2026-09-18T18:31:55

2 posts

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

censys@infosec.exchange at 2026-09-21T16:20:25.000Z ##

🚨 RAPID RESPONSE: IBM MQ Pre-Authentication RCE [CVE-2026-10747]

A critical heap buffer overflow in IBM MQ could allow remote code execution before authentication. CVSS: 10.0.

Censys ARC observes IBM MQ web consoles on 120 hosts and 149 web properties Internet-wide. These numbers indicate IBM MQ presence, not confirmed vulnerable systems.

IBM has released fixes for affected MQ Server and MQ Appliance versions. No public PoC or reported active exploitation is known at this time.

Read the full analysis for affected versions, Internet observations, and remediation guidance. censys.com/advisory/cve-2026-1

#CensysARC #IBMMQ #Cybersecurity #Vulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-09-20T19:21:35.000Z ##

Critical IBM MQ vulnerabilities allow remote code execution. Learn how CVE-2026-10747 and CVE-2026-10858 hit 10.0 CVSS and require urgent patching.

#IBMMQ #CVE202610747 #CVE202610858 #Cybersecurity #Infosec

securityonline.info/ibm-mq-vul

##

CVE-2026-10858
(9.9 CRITICAL)

EPSS: 0.33%

updated 2026-09-18T18:31:53

1 posts

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.

DailyCyberSecurity@infosec.exchange at 2026-09-20T19:21:35.000Z ##

Critical IBM MQ vulnerabilities allow remote code execution. Learn how CVE-2026-10747 and CVE-2026-10858 hit 10.0 CVSS and require urgent patching.

#IBMMQ #CVE202610747 #CVE202610858 #Cybersecurity #Infosec

securityonline.info/ibm-mq-vul

##

CVE-2026-85058
(7.5 HIGH)

EPSS: 0.27%

updated 2026-09-18T17:58:41

1 posts

## Summary Moquette MQTT Broker fails to enforce ACL write permission checks when publishing Will (Last Will and Testament) messages on behalf of disconnected clients. All normal PUBLISH paths (`receivedPublishQos0`, `receivedPublishQos1`, `receivedPublishQos2`) correctly invoke `authorizator.canWrite()` before publishing, but the Will message publishing path (`fireWill()` → `publishWill()` → `pu

thehackerwire@mastodon.social at 2026-09-21T01:02:52.000Z ##

🟠 CVE-2026-85058 - High (7.5)

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths. When ano...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91127
(8.2 HIGH)

EPSS: 0.24%

updated 2026-09-18T17:19:44

1 posts

### Summary Before 2.3.1, the legacy `.doc` renderer emitted document hyperlink targets after HTML escaping but without a URL-scheme allowlist. A crafted `.doc` could therefore render a live `javascript:`, `vbscript:`, `data:`, or similarly unsafe link. Script could execute in the embedding origin if a viewer clicked it. ### Impact Applications rendering untrusted legacy `.doc` files with `@fil

thehackerwire@mastodon.social at 2026-09-21T01:02:43.000Z ##

🟠 CVE-2026-91127 - High (8.2)

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled hyperlink t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53266
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-18T15:32:49

2 posts

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Aski

2 repos

https://github.com/mc493/linux-kernel-zero-day-mitigation-zero-downtime-kernel-defense-

https://github.com/suominen/CVE-2026-53266

thecybermind@infosec.exchange at 2026-09-21T18:47:53.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53266 – Linux Kernel Out-of-Bounds Write Vulnerability

Analyze the executive impact of CVE-2026-53266 with our strategic Linux CSUITE brief, covering kernel out-of-bounds write risks, compliance assurance, and board-level risk communication....

thecybermind.co/n7ln

##

cyberworldops@infosec.exchange at 2026-09-21T10:40:00.000Z ##

CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV

cyberworldops.eu/en/three-expl

##

CVE-2026-20283
(6.5 MEDIUM)

EPSS: 0.43%

updated 2026-09-18T13:28:28.567000

1 posts

A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system.&nbsp; This vulnerability is due to insufficient validation of user-supplied input in IPsec Open API calls. An attacker could exploit this vulnerability by sending crafted input to the IPsec Open API endpoint on an affected dev

cyberworldops@infosec.exchange at 2026-09-21T02:20:00.000Z ##

Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise. #CiscoSecurity #NetworkSecurity #VulnManagement

cyberworldops.eu/en/cisco-fixe

##

CVE-2026-13684
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-09-18T09:31:20

1 posts

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

cyberveille@mastobot.ping.moi at 2026-09-22T07:30:06.000Z ##

📢 [VULN] Alerte sécurité : deux vulnérabilités majeures menacent vos NAS Synology - CVE-2026-13684 CVE-2026-13639

Huit vulnérabilités viennent d'être identifiées dans le système d'exploitation DiskStation Manager de Synology, dont deux atteignent un score de gravité maximal de 9.8. Ces failles critiques permettent à des attaquants distants de lire, d'écrire ou d'effacer vos fichiers sans aucune…

🔗 generation-nt.com/actualites/a
💬 discussion : infosec.pub/post/52624526
#Vulnérabilité #CVE #Cyberveille

##

CVE-2026-85889
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-09-18T00:31:16

1 posts

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

security_crawler_carl@infosec.exchange at 2026-09-20T22:43:27.000Z ##

CVE-2026-85889 in Microsoft's Azure AI Foundry enabled unauthorized privilege escalation at the highest possible severity rating, discovered by researcher Rémy Marot and quietly fixed before a single attacker could find it in the wild.

The good news — and do write this down — no customer action is required. Microsoft has fully mitigated the issue on their end. This concludes the portion of the training where you feel relief. Please do not grow accustomed to it. (2/3)

##

CVE-2026-20284
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-09-16T21:32:50

1 posts

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underl

cyberworldops@infosec.exchange at 2026-09-21T02:20:00.000Z ##

Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise. #CiscoSecurity #NetworkSecurity #VulnManagement

cyberworldops.eu/en/cisco-fixe

##

CVE-2024-20260
(8.6 HIGH)

EPSS: 0.59%

updated 2026-09-16T21:17:05.947000

2 posts

Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms

AAKL at 2026-09-23T15:33:07.275Z ##

Broadcom has a long list of advisories addressing some critical vulnerabilities, among others support.broadcom.com/web/ecx/s

Cisco:

This addresses high-severity CVE-2024-20260, first published in October.

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity

##

AAKL@infosec.exchange at 2026-09-23T15:33:07.000Z ##

Broadcom has a long list of advisories addressing some critical vulnerabilities, among others support.broadcom.com/web/ecx/s #Broadcom

Cisco:

This addresses high-severity CVE-2024-20260, first published in October.

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-79994
(0 None)

EPSS: 0.11%

updated 2026-09-16T20:38:33.883000

1 posts

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary AF_UNIX socket outside the shared workspace. This can expose data or host-side cap

CVE-2026-92398
(9.1 CRITICAL)

EPSS: 2.47%

updated 2026-09-16T18:32:09

1 posts

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Name results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-92397
(9.1 CRITICAL)

EPSS: 2.30%

updated 2026-09-16T18:32:09

1 posts

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-58704
(8.0 HIGH)

EPSS: 0.21%

updated 2026-09-16T15:30:57

1 posts

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

hackmag@infosec.exchange at 2026-09-21T15:30:23.000Z ##

⚪️ Google Patches Zero-Day Vulnerability in Pixel Devices

🗨️ Google has released September patches for Pixel smartphones, fixing 110 vulnerabilities. Among them is a zero-day flaw found in the cellular modem (CVE-2026-58704). The company warned that the issue is already being exploited by hackers in targeted attacks. CVE-2026-58704 has…

🔗 hackmag.com/news/pixel-0-day?u

#news

##

CVE-2026-27561
(7.2 HIGH)

EPSS: 2.23%

updated 2026-09-16T09:30:35

1 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-27560
(7.2 HIGH)

EPSS: 2.23%

updated 2026-09-16T09:30:34

1 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-27562
(7.2 HIGH)

EPSS: 2.23%

updated 2026-09-16T09:30:34

1 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-77179(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-09-16T00:32:25

1 posts

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

1 repos

https://github.com/HORKimhab/CVE-2026-77179

CVE-2026-90847
(9.1 CRITICAL)

EPSS: 2.18%

updated 2026-09-15T19:17:46.767000

1 posts

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

1 repos

https://github.com/shlln/CVE-2026-90847

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-90703
(9.1 CRITICAL)

EPSS: 2.80%

updated 2026-09-15T18:19:38.113000

1 posts

A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-89308(CVSS UNKNOWN)

EPSS: 2.97%

updated 2026-09-15T12:31:54

1 posts

An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-76461
(9.8 CRITICAL)

EPSS: 2.01%

updated 2026-09-14T21:32:49

1 posts

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that cont

4 repos

https://github.com/HORKimhab/CVE-2026-76461

https://github.com/fevar54/CVE-2026-76461-Detection-Kit-

https://github.com/0xBlackash/CVE-2026-76461

https://github.com/S3v3n-JG/CVE-2026-76461

8bitsecurity@mastodon.social at 2026-09-21T07:05:00.000Z ##

🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and…

Also tracked this week: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping · Check Point, Kaspersky, Tanium…

nexus8.8bitsecurity.com/entity

##

CVE-2026-19499
(7.7 HIGH)

EPSS: 0.38%

updated 2026-09-14T18:31:23

1 posts

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the int

hugovalters@mastodon.social at 2026-09-22T03:30:31.000Z ##

CVE-2026-19499: glibc 2.38-2.44 strfmon buffer overflow via right-justified padding. CVSS 7.7. Unpatched. Audit risky calls, update now.
valtersit.com/cve/CVE-2026-194
#CVE #infosec #glibc

##

CVE-2026-90894
(7.8 HIGH)

EPSS: 0.15%

updated 2026-09-14T12:31:44

1 posts

Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon unpacks with one string, tar -xf "%1" -C "%2", then Qt QProcess::splitCommand 

hugovalters@mastodon.social at 2026-09-23T14:20:25.000Z ##

CVE-2026-90894 Parallels Desktop: local root RCE via unsanitized sVmParentPath, tar injection in prl_disp_service. CVSS 7.8. Unpatched. Patch or restrict socket access now. valtersit.com/cve/CVE-2026-908 #CVE #infosec #Parallels

##

CVE-2026-90702
(9.1 CRITICAL)

EPSS: 2.80%

updated 2026-09-14T12:31:44

1 posts

A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-49881
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-10T15:34:08

1 posts

In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

2 repos

https://github.com/Supersonic/TLPE

https://github.com/LSPosed/LSPromise

DailyCyberSecurity@infosec.exchange at 2026-09-22T00:24:53.000Z ##

A critical Android Telecom vulnerability (CVE-2026-49881) allows remote code execution. Read the analysis and learn how to secure your device today.

#Android #CVE202649881 #Cybersecurity #Infosec #ZeroDay

securityonline.info/android-te

##

CVE-2026-81963
(7.8 HIGH)

EPSS: 0.63%

updated 2026-09-09T05:18:17.173000

1 posts

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

cyberworldops@infosec.exchange at 2026-09-22T05:10:01.000Z ##

Microsoft shipped its largest patch batch to date with at least 974 fixes, including 113 rated Critical. Two local EoP flaws, CVE-2026-81963 and CVE-2026-85880, are under active exploitation and enable SYSTEM privileges, making immediate triage essential. #PatchTuesday #WindowsSecurity #VulnManagement

cyberworldops.eu/en/microsoft-

##

CVE-2026-85880
(7.8 HIGH)

EPSS: 0.57%

updated 2026-09-08T21:34:12

1 posts

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

cyberworldops@infosec.exchange at 2026-09-22T05:10:01.000Z ##

Microsoft shipped its largest patch batch to date with at least 974 fixes, including 113 rated Critical. Two local EoP flaws, CVE-2026-81963 and CVE-2026-85880, are under active exploitation and enable SYSTEM privileges, making immediate triage essential. #PatchTuesday #WindowsSecurity #VulnManagement

cyberworldops.eu/en/microsoft-

##

CVE-2026-50093
(9.0 None)

EPSS: 0.19%

updated 2026-09-08T09:35:45

1 posts

A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this

beyondmachines1@infosec.exchange at 2026-09-23T08:01:13.000Z ##

Siemens Patches Root-Level File Upload Flaw in Siveillance Control OIS Module

Siemens patched a critical root-level file upload vulnerability (CVE-2026-50093) in the Siveillance Control OIS web module that affects physical security management systems worldwide.

**If you use Siemens Siveillance Control or Control Pro, make sure all these systems are isolated from the internet and the OIS web module is reachable only from trusted internal networks. Then update right away to the fixed version for your edition.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-43499
(7.8 HIGH)

EPSS: 0.79%

updated 2026-09-08T09:18:05.213000

1 posts

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue oper

100 repos

https://github.com/jason5545/ghostlock-myron-tw

https://github.com/accessmodifier364/cve-2026-43499-firetv-sheldonp-writeup

https://github.com/2932796375github/CVE-2026-43499_OPPO-MT6835

https://github.com/woshimaniubi8/CVE-2026-43499-root-KernelSU

https://github.com/cuteaplane/GhostLock-for-OnePlus15T

https://github.com/NanoTurtle1145/root-my-s24

https://github.com/Bobikl/CVE-2026-43499-T807D

https://github.com/Colorful-glassblock/duchamp-root

https://github.com/ccp-p/ghostlock-cve-2026-43499-4.19-k40

https://github.com/MobiusM/CVE-2026-43499

https://github.com/hybLOVE/iqoo-temp-root

https://github.com/fusiondrive/CVE-2026-43499-A36

https://github.com/mumaosong/cve-2026-43499-CyberMeowfia

https://github.com/yakidango-official/GhostLock-H80GT

https://github.com/BuSung-dev/CVE-2026-43499-S25U

https://github.com/CakesTwix/Android-CVE-2026-43499

https://github.com/Bailan766/rmx3888-cve-2026-43499-config

https://github.com/xiaohj233/ghostlock-x200-root

https://github.com/YuKongA/ghostlock-app

https://github.com/PeronGH/ghostlock-selinux-disabler

https://github.com/ctn-Qvo/auto_extract_offsets

https://github.com/knowlily/cve-2026-43499-honor

https://github.com/xianwan1314/CVE-2026-43499-Poc-Analysis

https://github.com/pimpamebanihah/cve-2026-43499-app.so

https://github.com/Linuxoid-cn/Mi8E5-Unlocker-by-CVE-2026-43499

https://github.com/p2p3p/GhostLock-for-OnePlus

https://github.com/1ndevelopment/ghostlock-s26

https://github.com/hackyangwen-lgtm/rmg-s9180-fzg1

https://github.com/WitAqua-tools/Root-My-Device

https://github.com/yijiacloud/ghostlock-cve-2026-43499-4.19-k40

https://github.com/gagaltotal/CVE-2026-43499-PoC-Scanner

https://github.com/soralis0912/CVE-2026-43499-aristotle-apk

https://github.com/Petalrain224/CVE-2026-43499-Redmi-Turbo5

https://github.com/ankitrawatgit/iQOO-Z9_5G-vivo-T3_5G-Root-GhostLock

https://github.com/XingChenRS/CyberMeowfiaNS

https://github.com/boxiaolanya2008/CVE-2026-43499-Neo11Plus

https://github.com/wxxsfxyzm/GhostLock-Galaxy

https://github.com/caspy123/CVE-2026-43499

https://github.com/soralis0912/CVE-2026-43499-pmg110-root

https://github.com/tc3650/CVE-2026-43499-armv7

https://github.com/justsoman/CVE-2026-43499-jinghu

https://github.com/datfooldive/ghostlock-emerald

https://github.com/dmcdtc/openvz-cve-patch-2026

https://github.com/hui191/cve-2026-43499-aak-an00

https://github.com/pubglite55/oppo-ghostlock

https://github.com/xrzcc/s26-m1q-ghostlock-selinux

https://github.com/TheAndersMadsen/humane-aipin-ghostlock

https://github.com/alex193a/Root-My-Pixel

https://github.com/HYCQAQ/Logitech-G-Cloud-GhostLock-CVE-2026-43499

https://github.com/gitchw/ghostlock-cve-2026-43499

https://github.com/MiaPatsune/cve-2026-43499

https://github.com/233laoliu/mt6985-CVE-2026-43499

https://github.com/joehquak/Mi8E5-Unlocker-by-CVE-2026-43499

https://github.com/soralis0912/CVE-2026-43499-aristotle

https://github.com/NothingFumo/ghostlock-aresin

https://github.com/mobilehackinglab/ghostlock-a17

https://github.com/ctn-Qvo/CVE-2026-43499-so-build

https://github.com/huaguiqi/asus-i005-cve-2026-43499

https://github.com/R0rt1z2/GhostLock

https://github.com/yijiacloud/GhostLock-OPPO-PCKM00

https://github.com/slapah/ghostlock-h8q

https://github.com/oopnv70-lab/ghostlock-honor-aak

https://github.com/eroorvbsyes-hotmail/CVE-2026-43499_x86_Exploit

https://github.com/soralis0912/CVE-2026-43499-warhol-root

https://github.com/x-spy/CVE-2026-43499-popsicle

https://github.com/k-o-n-t-o-r/ghostlock-sabrina

https://github.com/dorlow/hazel-cve-2026-43499

https://github.com/Meowkis/tcp-zerocopy-sm

https://github.com/sorrow404Null/CVE-2026-43499-RMX5200

https://github.com/inforcqb/CVE-2026-43499-pja110

https://github.com/XiaoBaiLovesStirring/ghostlock-k419-adapter

https://github.com/fusiondrive/CVE-2026-43499-ZFOLD4

https://github.com/zenyxx-xd/RootMyVivo

https://github.com/dnlid/CVE-2026-43499

https://github.com/CatXiaoShi/cve-2026-43499

https://github.com/fancyzll/CVE-2026-43499_OPPO-MT6835

https://github.com/Bartixxx32/CVE-2026-43499-OnePlus15

https://github.com/Wtrwx/smt878u-ionstack-poc

https://github.com/zhubaohe123/ghostlock-kit

https://github.com/sarabpal-dev/IonStack-S22U

https://github.com/onesmiledx/CVE-2026-43499

https://github.com/Cxyofficial/x200-cve-2026-43499

https://github.com/fusiondrive/CVE-2026-43499-S24U

https://github.com/ReBiliBin/ghostlock-oppo-watch3pro

https://github.com/BuSung-dev/Root-My-Galaxy

https://github.com/snothin/ghostlock-s26

https://github.com/HORKimhab/CVE-2026-43499

https://github.com/Thiasap/oppo-pgem10-ghostlock

https://github.com/oopnv70-lab/ghostlock-apk

https://github.com/SammyEnigma/CVE-2026-43499-S26

https://github.com/0xBlackash/CVE-2026-43499

https://github.com/veygax/HORiZonstack

https://github.com/Bugel/cve-2026-43499-m3q-azf1

https://github.com/hmascs/KSuRoot

https://github.com/lkeld/CVE-2026-43499-poc

https://github.com/oopnv70-lab/ghostlock-aak-apk

https://github.com/No-22-Github/UnPlus

https://github.com/zzzxxxxxxxxxx/GhostLock-GOT-W29

https://github.com/JoinChang/ghostlock-oneplus

https://github.com/Linuxoid-cn/CVE-2026-43499-Poc-Analysis

sayzard@mastodon.sayzard.org at 2026-09-23T17:46:08.000Z ##

IonStack: 1-Click Browser to Kernel Full-Chain to Get Root Shell on Android 17

Nebula Security는 Firefox JIT 취약점(CVE-2026-10702)과 Linux 커널 futex priority-inheritance 경로의 15년 된 stack use-after-free인 GhostLock(CVE-2026-43499)을 연결해, 웹페이지 한 번의 방문만으로 Pixel 10의 Android 17에서 루트 셸을 얻는 체인을 발표했다. 첫 취약점은 Fire...

blackhat.com/europe/briefings/

##

CVE-2026-86296
(10.0 CRITICAL)

EPSS: 1.35%

updated 2026-09-07T12:30:36

5 posts

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

cyberveille@mastobot.ping.moi at 2026-09-23T14:00:06.000Z ##

📢 [VULN] D-Link alerte sur une faille de gravité maximale dans l’un de ses routeurs, le code pour l’exploiter est déjà public CVE-2026-86296

D-Link enquête sur une faille critique qui touche ses routeurs DIR-822A. Exploitable sans authentification, elle dispose déjà d’un code d’exploitation public et n’a pour l’heure aucun correctif.

🔗 clubic.com/actualite-630922-d-
💬 discussion : infosec.pub/post/52678117
#CVE #Cyberveille

##

DailyCyberSecurity at 2026-09-23T13:31:12.007Z ##

Discover the critical CVE-2026-86296 vulnerability in D-Link DIR-822A routers. Learn how this DHCP flaw allows attackers to execute arbitrary code locally.

meterpreter.org/dlink-dir-822a

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T13:31:12.000Z ##

Discover the critical CVE-2026-86296 vulnerability in D-Link DIR-822A routers. Learn how this DHCP flaw allows attackers to execute arbitrary code locally.

#DLink #RouterSecurity #CVE #CyberSecurity #TechNews

meterpreter.org/dlink-dir-822a

##

campuscodi@mastodon.social at 2026-09-22T13:25:37.000Z ##

D-Link warns of two major bugs with public POCs

CVE-2026-86296: supportannouncement.us.dlink.c

POC: tzh00203.notion.site/D-Link-DI

CVE-2026-93958: supportannouncement.us.dlink.c

POC: github.com/FoundTL/D-Link-R95-

##

oversecurity@mastodon.social at 2026-09-22T13:20:34.000Z ##

D-Link warns of max severity zero-day bug in DIR-822A routers

D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch,...

🔗️ [Bleepingcomputer] link.is.it/hXngI9

##

CVE-2026-75925
(9.6 CRITICAL)

EPSS: 0.67%

updated 2026-09-05T00:31:10

1 posts

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface

certvde@infosec.exchange at 2026-09-21T14:13:08.000Z ##

🔒 New CSAF advisory published

VDE-2026-089
Lenze: VPN Client Remote Code Execution in combination with Lenze x500 IoT Gateway
CVE-2026-75925

The Lenze VPN client is vulnerable to a Remote Code Execution. The vulnerability would allow an attacker to perform a remote code execution on the computer running the client with elevated privile…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: lenze.csaf-tp.certvde.com/.wel

#OT #Advisory

##

CVE-2026-41293
(9.8 CRITICAL)

EPSS: 1.68%

updated 2026-08-31T21:04:41

1 posts

Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.21 Apache Tomcat 10.1.0-M1 to 10.1.54 Apache Tomcat 9.0.0.M1 to 9.0.117 Older, unsupported versions may also be affected Description: HTTP/2 request headers were not validated which may have triggered unexpected application behaviour if the application (quite reasonably) assumed that header value exposed through the Servlet API would be specifica

1 repos

https://github.com/xiaoqiMikko/tomcat-check

EUVD_Bot@mastodon.social at 2026-09-23T12:01:09.000Z ##

🚨 EUVD-2026-85235

📊 Score: n/a
📦 Product: Apache Tomcat, Apache Tomcat, Apache Tomcat
🏢 Vendor: Apache Software Foundation
📅 Updated: 2026-09-23

📝 Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up.

This issue affect...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-78306
(0 None)

EPSS: 0.15%

updated 2026-08-26T16:49:18.760000

2 posts

DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone's internal Wi-Fi network, potentially gaining access to the flight

1 repos

https://github.com/Wh02m1/CVE-2026-78306

DailyCyberSecurity at 2026-09-23T14:45:15.837Z ##

The DJI Bluetooth vulnerability CVE-2026-78306 lets a nearby attacker send unauthenticated DUML commands to 16 drone models. Update firmware now.

meterpreter.org/dji-bluetooth-

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T14:45:15.000Z ##

The DJI Bluetooth vulnerability CVE-2026-78306 lets a nearby attacker send unauthenticated DUML commands to 16 drone models. Update firmware now.

#DJI #CVE202678306 #Bluetooth #DroneSecurity #DUML #CyberSecurity

meterpreter.org/dji-bluetooth-

##

CVE-2026-42945
(8.1 HIGH)

EPSS: 68.05%

updated 2026-08-25T15:33:26

1 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond it

45 repos

https://github.com/josephfelix/CVE-2026-42945-nginx-rift

https://github.com/Kentox493/CVE-2026-42945_NginxRift

https://github.com/forxiucn/nginx-cve-2026-42945-poc

https://github.com/azilRababe/CVE-2026-42945

https://github.com/BarAppTeam/nginx-cve-fix

https://github.com/cipherspy/CVE-2026-42945-POC

https://github.com/dinosn/cve-2026-42945-nginx32-lab

https://github.com/quantumworld-dpdns-io/CVE-2026-42945

https://github.com/ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945

https://github.com/limo57640-crypto/nginx-rift-detector

https://github.com/nanwinata/nginxrift-CVE-2026-42945

https://github.com/strivepan/Nginx_cve-2026-42945-scanner-gui

https://github.com/hulina9900-boop/DIY-CVE-2026-42945-POC

https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab

https://github.com/oseasfr/Scanner_CVE_2026-42945

https://github.com/MateusVerass/nGixshell

https://github.com/byezero/nginx-cve-2026-42945-check

https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945

https://github.com/realityone/cve-2026-42945-scan

https://github.com/CynepMyx/nginx-rift-check

https://github.com/aratane/CVE-2026-42945

https://github.com/sibersan/web-server-audit_CVE-2026-42945

https://github.com/jelasin/CVE-2026-42945

https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit

https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945

https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script

https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift

https://github.com/0xBlackash/CVE-2026-42945

https://github.com/imSre9/CVE-2026-42945

https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945

https://github.com/yusufdalbudak/CVE-2026-42945

https://github.com/FranklinF25/cve-2026-42945

https://github.com/rheodev/CVE-2026-42945

https://github.com/hnytgl/CVE-2026-42945

https://github.com/RedCrazyGhost/CVE-2026-42945

https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC

https://github.com/F2u0a0d3/CVE-2026-42945-nginx-rift-poc

https://github.com/iammerrida-source/nginx-rift-detect

https://github.com/sec-sys/CVE-2026-42945-Reverse-Shell-POC

https://github.com/simota/nginx-rift-scanner

https://github.com/nu0l/NGINX-Rift

https://github.com/fkj-src/fix_nginx_cve_2026_42945

https://github.com/chenqin231/CVE-2026-42945

https://github.com/tal7aouy/nginx-cve-2026-42945

https://github.com/edgecases-PurpleHax/cve-images

kubesploit@learnk8s.news at 2026-09-21T19:16:02.000Z ##

Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives
The README lists affected and fixed versions

ku.bz/PQSlZ7Khl

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 50.38%

updated 2026-08-19T04:17:24.940000

3 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

2 repos

https://github.com/BiuTrap/CVE-2026-59310

https://github.com/HORKimhab/CVE-2026-59310

christopherkunz@chaos.social at 2026-09-23T13:06:38.000Z ##

@nyanbinary @cR0w here's one
(from the writeup to CVE-2026-59310 from July/August).
Point at the variables in the picture that traversed your path inappropriately...
mobeta.fr/blog/vcenter-cve-202

##

christopherkunz@chaos.social at 2026-09-23T13:06:38.000Z ##

@nyanbinary @cR0w here's one
(from the writeup to CVE-2026-59310 from July/August).
Point at the variables in the picture that traversed your path inappropriately...
mobeta.fr/blog/vcenter-cve-202

##

_r_netsec@infosec.exchange at 2026-09-22T08:13:04.000Z ##

vCenter pre-auth RCE: CVE-2026-59309/59310 mobeta.fr/blog/vcenter-cve-202

##

CVE-2026-55040
(9.1 CRITICAL)

EPSS: 50.59%

updated 2026-08-18T18:32:50

1 posts

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

5 repos

https://github.com/virologi-info/mssharepoint-scanner

https://github.com/sfewer-r7/CVE-2026-55040

https://github.com/maxprog-svg/CVE-2026-55040-Mass-Exploit

https://github.com/zenzue/CVE-2026-55040

https://github.com/l0ggg/CVE-2026-55040

CVE-2026-33824
(9.8 CRITICAL)

EPSS: 72.69%

updated 2026-08-18T18:31:46

1 posts

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/kaleth4/CVE-2026-33824

https://github.com/EpSiLoNPoInTOrI/IKEV2-POC

CVE-2026-68820
(7.0 HIGH)

EPSS: 6.18%

updated 2026-08-16T19:17:24.183000

1 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

4 repos

https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation

https://github.com/maxprog-svg/CVE-2026-68820_Mass_Exploit

https://github.com/fevar54/CVE-2026-68820-Mitigation-PoC-

https://github.com/HORKimhab/CVE-2026-68820

CVE-2026-65660
(6.5 MEDIUM)

EPSS: 0.81%

updated 2026-08-11T18:31:43

5 posts

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

oversecurity@mastodon.social at 2026-09-23T10:20:31.000Z ##

Microsoft Upgrades SharePoint Flaw From Spoofing to 8.8 RCE

A SharePoint Server vulnerability tracked as CVE-2026-65660 turned out to be far more serious than Microsoft first indicated. The company

🔗️ [Thecyberexpress] link.is.it/qUvtLM

##

oversecurity@mastodon.social at 2026-09-23T10:20:31.000Z ##

Microsoft Upgrades SharePoint Flaw From Spoofing to 8.8 RCE

A SharePoint Server vulnerability tracked as CVE-2026-65660 turned out to be far more serious than Microsoft first indicated. The company

🔗️ [Thecyberexpress] link.is.it/qUvtLM

##

obivan@infosec.exchange at 2026-09-23T08:53:09.000Z ##

SharePoint CVE-2026-65660: From Anonymous Access to Pre-Auth RCE via EditingPageParser Type-Check Bypass blog.viettelcybersecurity.com/

##

guru@thecybersecguru.com at 2026-09-22T14:06:40.000Z ##

Microsoft Called CVE-2026-65660 a Spoofing Bug. It’s an Authenticated SharePoint RCE

CVE-2026-65660 is an authenticated SharePoint RCE, not just spoofing. Learn about the ToolPane flaw, XAML exploit chain, affected versions, and fixes

thecybersecguru.com/news/cve-2

##

cyberworldops@infosec.exchange at 2026-09-22T12:50:01.000Z ##

CVE-2026-65660 reportedly enables authenticated, low-privilege attackers to execute arbitrary code remotely on SharePoint Server. Its initial spoofing classification makes accurate advisory tracking and impact reassessment especially important. #SharePointSecurity #VulnerabilityManagement #ThreatIntelligence

cyberworldops.eu/en/sharepoint

##

1337core@social.1337core.de at 2026-09-20T16:03:04.000Z ##

Ungepatchte Exchange-Server mit kritischer Sicherheitslücke
CVE-2021-34473: "Microsoft Exchange Server Remote Code Execution Vulnerability"
Volkshochschule in Amberg, Landkreis Merzig-Wadern und mehreren Stadtverwaltungen: Bernsdorf, Bleckede, Dachau, Erkner, Heilbald Heiligenstadt, Klötze, Mölln, Plauen, Rendsburg, Sassnitz, Stadtbergen, Sulzbach Saar, Vellmar und im Exchange-Server im Theater in Freiburg, ...

#Hacks

c't Artikel: heise.de/news/Verwundbare-Exch

##

CVE-2026-39364
(7.5 HIGH)

EPSS: 2.00%

updated 2026-08-04T13:18:24.733000

1 posts

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 7.94%

updated 2026-07-30T15:31:54

3 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

christopherkunz@chaos.social at 2026-09-23T13:06:38.000Z ##

@nyanbinary @cR0w here's one
(from the writeup to CVE-2026-59310 from July/August).
Point at the variables in the picture that traversed your path inappropriately...
mobeta.fr/blog/vcenter-cve-202

##

christopherkunz@chaos.social at 2026-09-23T13:06:38.000Z ##

@nyanbinary @cR0w here's one
(from the writeup to CVE-2026-59310 from July/August).
Point at the variables in the picture that traversed your path inappropriately...
mobeta.fr/blog/vcenter-cve-202

##

_r_netsec@infosec.exchange at 2026-09-22T08:13:04.000Z ##

vCenter pre-auth RCE: CVE-2026-59309/59310 mobeta.fr/blog/vcenter-cve-202

##

CVE-2025-68686
(5.9 MEDIUM)

EPSS: 29.60%

updated 2026-07-27T18:31:25

1 posts

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases

CVE-2026-12495(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-07-27T12:32:01

1 posts

Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration se

CVE-2026-41091
(7.8 HIGH)

EPSS: 8.20%

updated 2026-07-24T10:10:00.197000

1 posts

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

4 repos

https://github.com/0xBlackash/CVE-2026-41091

https://github.com/tc4dy/CVE-2026-41091-PoC-Exploit

https://github.com/ridhinva/defender-privilege-escalation-scanner

https://github.com/s4m98/RedSun-

CVE-2026-45659
(8.8 HIGH)

EPSS: 76.08%

updated 2026-07-23T11:10:00.120000

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

2 repos

https://github.com/WismanSec/sharepoint-2026-poc

https://github.com/HORKimhab/CVE-2026-45659

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 85.40%

updated 2026-07-22T21:31:51

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

5 repos

https://github.com/HORKimhab/CVE-2026-50522

https://github.com/darses/CVE-2026-50522

https://github.com/4minx/CVE-2026-50522

https://github.com/ChPratik/CVE-2026-50522

https://github.com/WismanSec/sharepoint-2026-poc

CVE-2026-10702
(4.3 MEDIUM)

EPSS: 0.86%

updated 2026-07-22T19:10:00.120000

1 posts

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

1 repos

https://github.com/HORKimhab/CVE-2026-10702

sayzard@mastodon.sayzard.org at 2026-09-23T17:46:08.000Z ##

IonStack: 1-Click Browser to Kernel Full-Chain to Get Root Shell on Android 17

Nebula Security는 Firefox JIT 취약점(CVE-2026-10702)과 Linux 커널 futex priority-inheritance 경로의 15년 된 stack use-after-free인 GhostLock(CVE-2026-43499)을 연결해, 웹페이지 한 번의 방문만으로 Pixel 10의 Android 17에서 루트 셸을 얻는 체인을 발표했다. 첫 취약점은 Fire...

blackhat.com/europe/briefings/

##

CVE-2026-47065
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-07-13T17:24:48

1 posts

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which performs C

cR0w@infosec.exchange at 2026-09-21T15:49:50.000Z ##

sev:CRIT bypass of CVE-2026-47065 in Apache MINA.

nvd.nist.gov/vuln/detail/cve-2

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.

##

CVE-2026-4575
(2.4 LOW)

EPSS: 0.21%

updated 2026-06-17T10:56:50.843000

1 posts

A flaw has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file /admin/update_s2.php. This manipulation of the argument sname causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.

_r_netsec@infosec.exchange at 2026-09-22T11:28:04.000Z ##

CVE-2026-45756: attacker-controlled regex in Symfony JsonPath filters (ReDoS) daubois.dev/blog/cve-2026-4575

##

CVE-2025-6625
(7.5 HIGH)

EPSS: 0.48%

updated 2026-06-17T10:02:16.587000

1 posts

CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to the device.

cyberworldops@infosec.exchange at 2026-09-22T02:50:00.000Z ##

Schneider Electric Modicon M340 controllers and comm modules are vulnerable to DoS via crafted FTP command (CVE-2025-6625, CVSS 7.5, CWE-20). Remote low-complexity exploitation can take OT devices offline, impacting process availability. Apply vendor mitigations and restrict FTP exposure. #IcsSecurity #SchneiderElectric #Cve20256625

cyberworldops.eu/en/crafted-ft

##

CVE-2023-20118
(6.5 MEDIUM)

EPSS: 54.11%

updated 2026-06-17T05:29:31.353000

4 posts

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted

oversecurity@mastodon.social at 2026-09-23T10:39:29.000Z ##

PolarEdge: Unveiling an uncovered ORB network

Discover PolarEdge, a newly identified botnet targeting edge devices via CVE-2023-20118, using a stealthy TLS backdoor.

🔗️ [Sekoia] link.is.it/PmRTZ9

##

oversecurity@mastodon.social at 2026-09-23T10:38:41.000Z ##

PolarEdge: Unveiling an uncovered ORB network

Discover PolarEdge, a newly identified botnet targeting edge devices via CVE-2023-20118, using a stealthy TLS backdoor.

🔗️ [Sekoia] link.is.it/PmRTZ9

##

oversecurity@mastodon.social at 2026-09-23T10:39:29.000Z ##

PolarEdge: Unveiling an uncovered ORB network

Discover PolarEdge, a newly identified botnet targeting edge devices via CVE-2023-20118, using a stealthy TLS backdoor.

🔗️ [Sekoia] link.is.it/PmRTZ9

##

oversecurity@mastodon.social at 2026-09-23T10:38:41.000Z ##

PolarEdge: Unveiling an uncovered ORB network

Discover PolarEdge, a newly identified botnet targeting edge devices via CVE-2023-20118, using a stealthy TLS backdoor.

🔗️ [Sekoia] link.is.it/PmRTZ9

##

CVE-2022-42475
(9.8 CRITICAL)

EPSS: 99.47%

updated 2026-06-17T05:04:59.630000

1 posts

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

9 repos

https://github.com/scrt/cve-2022-42475

https://github.com/ArthurHendrich/CVE-2022-42475-POC

https://github.com/uLl0a/cve-2022-42475-poc

https://github.com/Mustafa1986/cve-2022-42475-Fortinet

https://github.com/0xhaggis/CVE-2022-42475

https://github.com/bryanster/ioc-cve-2022-42475

https://github.com/Amir-hy/cve-2022-42475

https://github.com/natceil/cve-2022-42475

https://github.com/P4x1s/CVE-2022-42475-RCE-POC

CVE-2020-4428
(9.1 CRITICAL)

EPSS: 61.69%

updated 2026-06-17T03:19:58.553000

1 posts

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.

CVE-2026-45756(CVSS UNKNOWN)

EPSS: 0.63%

updated 2026-05-28T17:34:56

1 posts

### Description The `JsonPath` component's `match()` and `search()` filter functions compile a caller-supplied pattern straight into `preg_match()`: ```php 'match' => @preg_match(\sprintf('/^%s$/u', $this->transformJsonPathRegex($argList[1])), $value), 'search' => @preg_match("/{$this->transformJsonPathRegex($argList[1])}/u", $value), ``` `transformJsonPathRegex()` only performs cosmetic escap

_r_netsec@infosec.exchange at 2026-09-22T11:28:04.000Z ##

CVE-2026-45756: attacker-controlled regex in Symfony JsonPath filters (ReDoS) daubois.dev/blog/cve-2026-4575

##

CVE-2026-32996(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-05-28T06:31:09

3 posts

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

1 repos

https://github.com/suce0155/CVE-2026-32996

obivan@infosec.exchange at 2026-09-22T11:20:45.000Z ##

Veeam Agent LPE PoC github.com/suce0155/CVE-2026-3

##

cyberworldops@infosec.exchange at 2026-09-22T08:30:01.000Z ##

Zyxel GS1900 switches (CVE-2026-7273) and Veeam Agent for Microsoft Windows (CVE-2026-32996) are under active exploitation. The former allows unauthenticated LAN command execution via CGI buffer overflow, the latter enables SYSTEM-level access on endpoints. Both expand persistence and backup tampering risk. #Zyxel #Veeam #ThreatIntel #VulnManagement

cyberworldops.eu/en/active-att

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T07:35:44.000Z ##

A critical exploited Veeam Agent vulnerability (CVE-2026-32996) is under active attack. Public PoC exploit code has been disclosed. Update systems now.

#Veeam #CVE202632996 #Cybersecurity #Vulnerability #Infosec

securityonline.info/actively-e

##

CVE-2026-21513
(8.8 HIGH)

EPSS: 15.64%

updated 2026-03-27T21:32:39

1 posts

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-21525
(6.2 MEDIUM)

EPSS: 5.04%

updated 2026-03-27T21:31:32

1 posts

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

CVE-2026-21519
(7.8 HIGH)

EPSS: 2.46%

updated 2026-02-10T21:31:29

1 posts

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2020-4427
(9.8 CRITICAL)

EPSS: 70.03%

updated 2025-11-04T00:30:30

1 posts

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.

CVE-2023-48788
(9.8 CRITICAL)

EPSS: 98.45%

updated 2025-10-22T00:34:05

1 posts

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

1 repos

https://github.com/horizon3ai/CVE-2023-48788

CVE-2021-44168
(7.8 HIGH)

EPSS: 0.87%

updated 2025-10-22T00:32:27

1 posts

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

1 repos

https://github.com/0xhaggis/CVE-2021-44168

sayzard@mastodon.sayzard.org at 2026-09-23T10:43:11.000Z ##

Next.js 16.3.6 fixes critical ImageResponse RCE (CVE-2026-94545)

Next.js가 Node.js 기반 `next/og`의 ImageResponse에서 원격 코드 실행(RCE)으로 이어질 수 있는 치명적 취약점(CVE-2026-94545)을 수정한 16.3.6 긴급 업데이트를 배포했다. 영향 범위는 Next.js 16.2.0 이상 16.3.6 미만이며, Satori가 생성하는 SVG의 부적절한 이스케이프와 상위 의존성 취약점 조합이 원인이다. Edge ImageResponse 구현은 영향받지 않지만, Node.js 런타임에서 OG 이미지 생성 기능을 쓰는 서비스는 즉시 `next@16.3.6`으로 업데이트해야 한다....

nextjs.org/blog/nextjs-securit

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T07:55:06.000Z ##

Vercel fixed a critical Next.js RCE vulnerability in image generation. Update to patch this Next.js RCE vulnerability and secure your apps.

#Nextjs #CVE202694545 #RCE #Cybersecurity #WebSecurity #Vulnerability

securityonline.info/nextjs-rce

##

CVE-2024-87491
(0 None)

EPSS: 0.00%

1 posts

N/A

security_crawler_carl@infosec.exchange at 2026-09-23T04:54:36.000Z ##

🏆 New Achievement! Triple Threat, Zero Regrets!

PATCH NOTES v0.0.0 — KNOWN ISSUES: A China-aligned threat group has successfully shipped a three-zero-day exploit chain targeting Google Chrome and Microsoft Windows. ADDED: coordinated weaponization across CVE-2024-85046, CVE-2024-87491, and CVE-2024-85880. FIXED: nothing on your end, apparently. DEPRECATED: the assumption that one vendor's unpatched flaw is somebody else's problem. (1/2)

##

CVE-2024-85880
(0 None)

EPSS: 0.00%

1 posts

N/A

security_crawler_carl@infosec.exchange at 2026-09-23T04:54:36.000Z ##

🏆 New Achievement! Triple Threat, Zero Regrets!

PATCH NOTES v0.0.0 — KNOWN ISSUES: A China-aligned threat group has successfully shipped a three-zero-day exploit chain targeting Google Chrome and Microsoft Windows. ADDED: coordinated weaponization across CVE-2024-85046, CVE-2024-87491, and CVE-2024-85880. FIXED: nothing on your end, apparently. DEPRECATED: the assumption that one vendor's unpatched flaw is somebody else's problem. (1/2)

##

CVE-2024-85046
(0 None)

EPSS: 0.00%

1 posts

N/A

security_crawler_carl@infosec.exchange at 2026-09-23T04:54:36.000Z ##

🏆 New Achievement! Triple Threat, Zero Regrets!

PATCH NOTES v0.0.0 — KNOWN ISSUES: A China-aligned threat group has successfully shipped a three-zero-day exploit chain targeting Google Chrome and Microsoft Windows. ADDED: coordinated weaponization across CVE-2024-85046, CVE-2024-87491, and CVE-2024-85880. FIXED: nothing on your end, apparently. DEPRECATED: the assumption that one vendor's unpatched flaw is somebody else's problem. (1/2)

##

CVE-2026-89090
(0 None)

EPSS: 0.31%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-09-22T20:00:01.000Z ##

CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2

Bulletin ID: 2026-110-AWS

Scope: AWS

Content Type: Important (requires attention)

Publication Date: 09/11/2026 10:00 AM PDT
Description:
An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versio...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-79916
(0 None)

EPSS: 0.27%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-21T22:04:14.000Z ##

🔴 CVE-2026-79916 - Critical (9.1)

MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credentials writes to /root/.aws/c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73550
(0 None)

EPSS: 0.88%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-21T21:02:36.000Z ##

🟠 CVE-2026-73550 - High (7.5)

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy copies every decoded HTTP/2 Host header value before discarding it when :authority is already present. The d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73552
(0 None)

EPSS: 0.66%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-21T21:02:50.000Z ##

🟠 CVE-2026-73552 - High (7.5)

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 subject sem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73548
(0 None)

EPSS: 0.66%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-21T21:01:20.000Z ##

🟠 CVE-2026-73548 - High (7.5)

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a configured non-WebSocket HTTP upgrade before the upstream accepts the upgrade. An unauth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79920
(0 None)

EPSS: 0.36%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-21T18:01:21.000Z ##

🔴 CVE-2026-79920 - Critical (9.9)

Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management aut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83621
(0 None)

EPSS: 0.29%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-21T18:01:13.000Z ##

🟠 CVE-2026-83621 - High (8.1)

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69184
(0 None)

EPSS: 0.68%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-21T06:04:28.000Z ##

🟠 CVE-2026-69184 - High (7.5)

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a response containing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T00:01:27.000Z ##

🔴 CVE-2026-92702 - Critical (9.1)

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61721
(0 None)

EPSS: 0.15%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-20T21:01:21.000Z ##

🟠 CVE-2026-61721 - High (8)

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58264
(0 None)

EPSS: 0.59%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-20T21:01:01.000Z ##

🔴 CVE-2026-58264 - Critical (9.8)

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is writt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61819
(0 None)

EPSS: 0.58%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-20T20:01:12.000Z ##

🟠 CVE-2026-61819 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verbatim insid...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61817
(0 None)

EPSS: 0.58%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-20T20:00:52.000Z ##

🟠 CVE-2026-61817 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_config.time_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61781
(0 None)

EPSS: 0.57%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-20T19:01:06.000Z ##

🔴 CVE-2026-61781 - Critical (9.9)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61820
(0 None)

EPSS: 0.58%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-20T19:00:46.000Z ##

🟠 CVE-2026-61820 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with double quotes without escaping embedded do...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites