##
Updated at UTC 2026-07-28T18:13:01.339287
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-66754 | 5.9 | 0.00% | 2 | 0 | 2026-07-28T17:17:06.730000 | Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the | |
| CVE-2026-59878 | 7.5 | 0.00% | 2 | 0 | 2026-07-28T16:20:53.010000 | Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ | |
| CVE-2026-43698 | 7.8 | 0.15% | 1 | 0 | 2026-07-28T16:20:53.010000 | An injection issue was addressed with improved validation. This issue is fixed i | |
| CVE-2026-43776 | 7.8 | 0.15% | 1 | 0 | 2026-07-28T16:20:53.010000 | A buffer overflow was addressed with improved bounds checking. This issue is fix | |
| CVE-2026-66748 | 8.8 | 0.00% | 2 | 0 | 2026-07-28T16:20:16.310000 | Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code | |
| CVE-2026-61609 | 7.5 | 0.00% | 2 | 0 | 2026-07-28T16:19:28.693000 | Pterodactyl is a free, open-source game server management panel. From 1.7.0 unti | |
| CVE-2026-65440 | 7.1 | 0.15% | 1 | 0 | 2026-07-28T16:19:12.780000 | Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions. | |
| CVE-2026-63077 | 9.8 | 0.65% | 3 | 0 | 2026-07-28T16:17:58.820000 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe | |
| CVE-2026-49743 | 7.8 | 0.11% | 1 | 0 | 2026-07-28T16:17:58.820000 | Software installed and run as a non-privileged user may conduct improper GPU sys | |
| CVE-2026-7187 | 8.8 | 0.00% | 2 | 0 | 2026-07-28T16:10:09.517000 | Missing authentication for critical function vulnerability in Universal Software | |
| CVE-2026-66035 | 7.5 | 0.32% | 1 | 0 | 2026-07-28T16:07:41.440000 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication h | |
| CVE-2026-66034 | 7.5 | 0.25% | 1 | 0 | 2026-07-28T16:07:41.440000 | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check | |
| CVE-2026-13440 | 7.2 | 0.00% | 1 | 0 | 2026-07-28T16:07:15.840000 | The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Che | |
| CVE-2026-63727 | 8.8 | 0.00% | 2 | 0 | 2026-07-28T15:32:19 | Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper | |
| CVE-2026-14169 | 8.1 | 0.29% | 4 | 0 | 2026-07-28T15:16:51.580000 | Due to incorrect behavior order a low privileged remote attacker could trigger a | |
| CVE-2026-16812 | 10.0 | 0.98% | 8 | 0 | 2026-07-28T14:50:33.960000 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a | |
| CVE-2026-14785 | 7.5 | 0.00% | 1 | 0 | 2026-07-28T12:31:27 | The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injecti | |
| CVE-2026-16462 | 9.8 | 0.00% | 2 | 0 | 2026-07-28T12:31:27 | In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a | |
| CVE-2026-10207 | 7.5 | 0.00% | 1 | 0 | 2026-07-28T12:31:20 | The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Inject | |
| CVE-2026-64531 | None | 0.16% | 2 | 0 | 2026-07-28T12:31:19 | In the Linux kernel, the following vulnerability has been resolved: net: openvs | |
| CVE-2026-14167 | 8.8 | 0.28% | 4 | 0 | 2026-07-28T09:31:36 | A low privileged remote attacker can perform privileged configuration changes re | |
| CVE-2026-14168 | 8.8 | 0.28% | 4 | 0 | 2026-07-28T09:31:36 | A low privileged remote attacker can gain administrator privileges due to missin | |
| CVE-2026-14171 | 6.1 | 0.18% | 4 | 0 | 2026-07-28T09:31:35 | An unauthenticated remote attacker can abuse the improper validation of the post | |
| CVE-2026-43723 | 7.8 | 0.14% | 1 | 0 | 2026-07-28T00:32:06 | A path handling issue was addressed with improved validation. This issue is fixe | |
| CVE-2026-43749 | 7.8 | 0.14% | 1 | 0 | 2026-07-28T00:32:05 | A parsing issue in the handling of directory paths was addressed with improved p | |
| CVE-2026-39874 | 7.8 | 0.10% | 1 | 0 | 2026-07-28T00:32:04 | A permissions issue was addressed with additional restrictions. This issue is fi | |
| CVE-2026-66473 | 7.5 | 0.20% | 1 | 0 | 2026-07-28T00:31:11 | Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions. | |
| CVE-2026-65439 | 7.1 | 0.15% | 1 | 0 | 2026-07-28T00:31:10 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 | |
| CVE-2026-17107 | 8.5 | 0.26% | 1 | 0 | 2026-07-28T00:31:02 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Ad | |
| CVE-2026-15962 | 8.8 | 0.38% | 1 | 0 | 2026-07-27T21:16:48.080000 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Objec | |
| CVE-2026-17496 | 8.1 | 0.30% | 1 | 0 | 2026-07-27T20:37:16.927000 | NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with | |
| CVE-2026-65711 | 7.2 | 2.41% | 1 | 0 | 2026-07-27T20:36:13.407000 | sysPass through version 3.2.11 contains an OS command injection vulnerability th | |
| CVE-2026-66041 | 8.8 | 0.42% | 1 | 0 | 2026-07-27T20:34:24.887000 | FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds | |
| CVE-2026-55579 | 9.8 | 0.60% | 1 | 1 | 2026-07-27T20:32:11.620000 | Pheditor is a single-file editor and file manager written in PHP. From version 2 | |
| CVE-2026-12503 | 0 | 0.14% | 1 | 0 | 2026-07-27T20:32:11.620000 | Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L- | |
| CVE-2025-68686 | 5.9 | 1.26% | 8 | 0 | 2026-07-27T18:31:25 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE | |
| CVE-2025-71408 | 7.8 | 0.16% | 1 | 0 | 2026-07-27T18:16:50.790000 | NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection | |
| CVE-2026-61511 | 9.8 | 1.27% | 3 | 2 | 2026-07-27T15:32:39 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul | |
| CVE-2026-45813 | 8.8 | 0.35% | 1 | 0 | 2026-07-27T14:41:12.090000 | Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apa | |
| CVE-2026-45815 | 7.5 | 0.60% | 1 | 0 | 2026-07-27T14:41:01.180000 | Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read | |
| CVE-2026-66142 | 7.5 | 0.48% | 1 | 0 | 2026-07-27T14:35:32.197000 | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that | |
| CVE-2026-16806 | 8.8 | 0.40% | 1 | 0 | 2026-07-27T12:45:30.967000 | Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remo | |
| CVE-2026-14837 | 7.8 | 0.08% | 1 | 0 | 2026-07-27T09:31:26 | Multiple Lenze products are affected by an improper signature verification vulne | |
| CVE-2026-64600 | 7.8 | 0.49% | 8 | 6 | 2026-07-27T06:31:36 | In the Linux kernel, the following vulnerability has been resolved: xfs: resamp | |
| CVE-2026-17497 | 8.3 | 0.46% | 1 | 0 | 2026-07-26T15:30:32 | NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capabili | |
| CVE-2026-17457 | 4.3 | 0.32% | 1 | 0 | 2026-07-26T12:30:21 | A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by t | |
| CVE-2026-17458 | 6.3 | 0.23% | 1 | 0 | 2026-07-26T12:30:21 | A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the f | |
| CVE-2026-17459 | 4.3 | 0.32% | 1 | 0 | 2026-07-26T12:30:21 | A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerabilit | |
| CVE-2026-63720 | 7.5 | 0.42% | 2 | 0 | 2026-07-26T06:31:31 | datamodel-code-generator prior to version 0.70.0 contains a code injection vulne | |
| CVE-2026-66012 | 10.0 | 0.44% | 2 | 1 | 2026-07-25T12:31:47 | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST | |
| CVE-2026-10818 | 8.1 | 0.42% | 2 | 1 | 2026-07-25T09:30:31 | The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in a | |
| CVE-2026-56163 | 10.0 | 0.92% | 2 | 0 | 2026-07-25T05:16:35.420000 | Missing authentication for critical function in Microsoft Azure Kubernetes Servi | |
| CVE-2026-50517 | 9.9 | 1.25% | 1 | 0 | 2026-07-25T05:16:35.100000 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker | |
| CVE-2026-66374 | 8.1 | 0.39% | 1 | 1 | 2026-07-25T03:30:55 | Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer | |
| CVE-2026-66373 | 7.5 | 0.47% | 1 | 0 | 2026-07-25T03:30:55 | Redis before 8.8.0, in the unusual case where an authenticated attacker can exec | |
| CVE-2026-62835 | 9.3 | 1.03% | 3 | 0 | 2026-07-25T02:16:39.663000 | Improper authorization in Azure Portal allows an unauthorized attacker to disclo | |
| CVE-2026-61884 | 9.8 | 0.66% | 2 | 0 | 2026-07-25T00:31:53 | The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perf | |
| CVE-2026-60134 | 8.8 | 0.32% | 1 | 0 | 2026-07-25T00:31:53 | Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elev | |
| CVE-2026-61892 | 8.8 | 0.27% | 1 | 0 | 2026-07-25T00:31:53 | Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate p | |
| CVE-2026-12497 | 7.5 | 0.23% | 1 | 0 | 2026-07-24T21:33:30 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User | |
| CVE-2026-45811 | 7.5 | 0.34% | 1 | 0 | 2026-07-24T21:33:30 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerabi | |
| CVE-2026-66144 | 7.5 | 0.48% | 1 | 0 | 2026-07-24T21:33:30 | Although remote policy references are not retrieved during policy normalization, | |
| CVE-2026-66143 | 7.5 | 0.51% | 1 | 0 | 2026-07-24T21:33:30 | It is possible to bypass the maximum number of normalized policy alternatives th | |
| CVE-2026-12981 | 7.5 | 0.30% | 1 | 0 | 2026-07-24T21:33:29 | The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication | |
| CVE-2026-12877 | 9.1 | 0.24% | 1 | 0 | 2026-07-24T21:33:29 | The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5 | |
| CVE-2026-45816 | 7.5 | 0.61% | 1 | 0 | 2026-07-24T21:33:29 | NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Requ | |
| CVE-2026-66039 | 8.8 | 0.42% | 1 | 0 | 2026-07-24T21:32:28 | FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflo | |
| CVE-2026-66036 | 8.8 | 0.29% | 1 | 0 | 2026-07-24T21:32:28 | FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds wri | |
| CVE-2026-66040 | 8.8 | 0.55% | 1 | 0 | 2026-07-24T21:32:28 | FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds wri | |
| CVE-2026-14603 | 7.5 | 0.24% | 1 | 0 | 2026-07-24T20:48:39.923000 | The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have | |
| CVE-2026-49745 | 7.8 | 0.11% | 1 | 0 | 2026-07-24T18:32:33 | Kernel software installed and running inside a Guest VM may post improper comman | |
| CVE-2026-16800 | 8.8 | 0.29% | 1 | 0 | 2026-07-24T18:32:33 | Improper control of generation of code ('Code Injection') in the schedule featur | |
| CVE-2026-49744 | 7.8 | 0.11% | 1 | 0 | 2026-07-24T18:32:32 | Kernel software installed and running inside a Guest VM may post improper comman | |
| CVE-2026-16801 | 8.8 | 0.29% | 1 | 0 | 2026-07-24T18:32:32 | Improper control of generation of code ('Code Injection') in the variables featu | |
| CVE-2026-65709 | 8.3 | 0.22% | 1 | 0 | 2026-07-24T18:31:41 | sysPass through version 3.2.11 contains a missing object-level authorization vul | |
| CVE-2026-66033 | 7.5 | 0.39% | 1 | 0 | 2026-07-24T18:31:41 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication i | |
| CVE-2026-65708 | 8.1 | 0.22% | 1 | 0 | 2026-07-24T18:31:37 | sysPass through version 3.2.11 contains an insecure direct object reference vuln | |
| CVE-2026-66032 | 8.8 | 0.29% | 1 | 0 | 2026-07-24T18:31:37 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerab | |
| CVE-2026-66027 | 8.3 | 0.26% | 1 | 0 | 2026-07-24T17:17:34.993000 | Suna before 0.9.102 contains a broken access control vulnerability in the messag | |
| CVE-2026-16807 | 8.8 | 0.26% | 1 | 0 | 2026-07-24T15:34:00 | Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a | |
| CVE-2026-16805 | 8.8 | 0.31% | 1 | 0 | 2026-07-24T15:34:00 | Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remot | |
| CVE-2026-16804 | 8.3 | 0.25% | 1 | 0 | 2026-07-24T15:34:00 | Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remot | |
| CVE-2026-8789 | 8.1 | 0.22% | 1 | 0 | 2026-07-24T15:33:10 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modific | |
| CVE-2026-58630 | 10.0 | 0.81% | 3 | 0 | 2026-07-24T15:33:09 | Improper access control in Azure App Service allows an unauthorized attacker to | |
| CVE-2026-57106 | 10.0 | 0.92% | 2 | 0 | 2026-07-24T15:33:03 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attack | |
| CVE-2026-66140 | 8.4 | 0.27% | 1 | 0 | 2026-07-24T06:34:11 | Exim before 4.99.5 allows directory traversal to access files outside of the spo | |
| CVE-2026-62144 | 9.1 | 20.62% | 1 | 1 | 2026-07-24T05:16:45.793000 | An authentication bypass vulnerability in Check Point Security Management and Mu | |
| CVE-2026-47668 | 10.0 | 4.34% | 1 | 1 | template | 2026-07-24T05:16:44.947000 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's |
| CVE-2026-35425 | 8.0 | 0.48% | 1 | 0 | 2026-07-24T03:32:01 | Improper access control in Azure API Management (APIM) allows an authorized atta | |
| CVE-2026-54120 | 9.9 | 0.71% | 2 | 0 | 2026-07-24T03:31:56 | Improper input validation in Microsoft Surface allows an authorized attacker to | |
| CVE-2026-56167 | 8.5 | 0.38% | 1 | 0 | 2026-07-24T03:31:56 | Server-side request forgery (ssrf) in Azure AI Search allows an authorized attac | |
| CVE-2026-42933 | 10.0 | 0.29% | 2 | 0 | 2026-07-24T00:32:40 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or inter | |
| CVE-2026-6516 | 10.0 | 4.73% | 1 | 0 | 2026-07-23T18:31:54 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthen | |
| CVE-2026-50522 | 9.8 | 57.10% | 4 | 3 | 2026-07-23T15:44:10.873000 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut | |
| CVE-2026-16723 | 9.0 | 0.41% | 5 | 3 | 2026-07-23T15:01:24.377000 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1. | |
| CVE-2026-46331 | 7.8 | 0.53% | 1 | 13 | 2026-07-23T12:18:18.287000 | In the Linux kernel, the following vulnerability has been resolved: net/sched: | |
| CVE-2026-63030 | 9.8 | 98.05% | 2 | 70 | template | 2026-07-22T23:10:00.110000 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API ba |
| CVE-2026-15342 | 6.5 | 0.22% | 1 | 0 | 2026-07-22T21:33:00 | Plane contains a multi‑tenant authorization flaw in its asset‑management API tha | |
| CVE-2026-13072 | 8.1 | 0.32% | 1 | 0 | 2026-07-22T21:32:15 | When compute mode is enabled on a standalone mongod instance, insufficient valid | |
| CVE-2026-16232 | 9.1 | 12.68% | 3 | 1 | 2026-07-22T21:32:05 | An authentication bypass vulnerability in the Check Point SmartConsole login pro | |
| CVE-2026-8933 | 7.8 | 0.21% | 1 | 0 | 2026-07-22T19:17:14.773000 | A local privilege escalation vulnerability exists in snap-confine, a set-capabil | |
| CVE-2026-53359 | 8.8 | 0.91% | 2 | 6 | 2026-07-22T19:07:43.103000 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F | |
| CVE-2026-49176 | 7.8 | 0.40% | 2 | 1 | 2026-07-22T16:17:28.753000 | Improper privilege management in Windows WalletService allows an authorized atta | |
| CVE-2026-62145 | 7.5 | 7.54% | 1 | 1 | 2026-07-22T15:31:34 | A vulnerability in Check Point Gaia Portal allows an authenticated attacker with | |
| CVE-2026-8985 | None | 4.19% | 1 | 0 | 2026-07-22T00:32:44 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command | |
| CVE-2026-64606 | 9.8 | 0.63% | 1 | 0 | 2026-07-21T21:33:35 | Deserialization of untrusted data vulnerability that may allow class-registratio | |
| CVE-2026-64879 | 9.9 | 2.59% | 1 | 0 | 2026-07-21T21:32:47 | A filename supplied during file upload is not properly sanitized before being us | |
| CVE-2026-54121 | 8.8 | 1.05% | 9 | 8 | 2026-07-21T19:54:33.623000 | Improper authorization in Active Directory Certificate Services (AD CS) allows a | |
| CVE-2026-40510 | 3.8 | 0.22% | 4 | 0 | 2026-07-21T12:10:00.090000 | OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overf | |
| CVE-2026-63108 | 8.8 | 1.92% | 1 | 0 | 2026-07-20T21:31:57 | Roo Code through 3.54.0 contains a command injection vulnerability in the auto-a | |
| CVE-2026-63766 | 9.8 | 1.75% | 1 | 1 | 2026-07-20T21:31:57 | GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability | |
| CVE-2026-2291 | 7.3 | 0.92% | 4 | 1 | 2026-07-20T21:31:40 | dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, | |
| CVE-2026-54298 | 4.2 | 0.23% | 1 | 0 | 2026-07-18T17:25:06 | ## Summary The `spreadAttributes` function in Astro's server-side rendering pip | |
| CVE-2026-53362 | 7.8 | 0.27% | 2 | 0 | 2026-07-18T09:32:17 | In the Linux kernel, the following vulnerability has been resolved: ipv6: accou | |
| CVE-2026-39808 | 9.8 | 89.69% | 1 | 6 | template | 2026-07-17T05:16:38.870000 | A improper neutralization of special elements used in an os command ('os command |
| CVE-2026-25089 | 9.8 | 69.83% | 1 | 2 | 2026-07-16T18:32:24 | A improper neutralization of special elements used in an os command ('os command | |
| CVE-2026-58644 | 9.8 | 5.06% | 1 | 0 | 2026-07-16T18:31:26 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut | |
| CVE-2026-42530 | 8.1 | 3.68% | 1 | 3 | 2026-07-16T12:17:51.630000 | NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI | |
| CVE-2023-4346 | 7.5 | 0.91% | 1 | 0 | 2026-07-16T05:16:16.603000 | KNX devices that use KNX Connection Authorization and support Option 1 are, dep | |
| CVE-2026-46817 | 9.8 | 13.31% | 1 | 2 | 2026-07-15T18:32:50 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone | |
| CVE-2026-42533 | 8.1 | 3.60% | 4 | 8 | 2026-07-15T15:33:14 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive | |
| CVE-2026-56155 | 7.8 | 2.33% | 1 | 0 | 2026-07-14T21:32:52 | Insufficient granularity of access control in Active Directory Federation Servic | |
| CVE-2026-15410 | 7.2 | 76.35% | 1 | 3 | 2026-07-14T21:32:21 | Post-authentication improper control of generation of code ('Code Injection') vu | |
| CVE-2026-50502 | 8.0 | 0.60% | 1 | 0 | 2026-07-14T18:32:33 | Insufficient granularity of access control in Windows Event Logging Service allo | |
| CVE-2026-50454 | 7.8 | 0.44% | 1 | 0 | 2026-07-14T18:32:32 | Relative path traversal in Windows User Interface Core allows an authorized atta | |
| CVE-2026-53264 | 7.8 | 0.12% | 2 | 1 | 2026-07-08T06:31:34 | In the Linux kernel, the following vulnerability has been resolved: net/sched: | |
| CVE-2026-55255 | 8.4 | 29.05% | 1 | 1 | 2026-07-07T22:14:37 | ## Summary Insecure Direct Object Reference (IDOR) vulnerability in `/api/v1/re | |
| CVE-2026-5172 | 7.3 | 2.68% | 4 | 2 | 2026-06-30T03:37:45 | A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker t | |
| CVE-2026-42945 | 8.1 | 61.47% | 2 | 42 | 2026-06-27T06:30:25 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo | |
| CVE-2026-12569 | 9.8 | 2.26% | 4 | 1 | 2026-06-26T15:33:15 | A critical remote code execution (RCE) vulnerability has been reported in PTC Wi | |
| CVE-2026-0160 | 8.8 | 0.23% | 2 | 0 | 2026-06-17T18:36:29 | In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there | |
| CVE-2026-0149 | 8.8 | 0.29% | 2 | 0 | 2026-06-17T17:34:19.580000 | In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap bu | |
| CVE-2025-69419 | 7.4 | 0.44% | 4 | 1 | 2026-06-17T10:00:39.850000 | Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously craft | |
| CVE-2025-68160 | 4.7 | 0.15% | 4 | 0 | 2026-06-17T09:58:39.407000 | Issue summary: Writing large, newline-free data into a BIO chain using the line- | |
| CVE-2024-1813 | 9.8 | 1.11% | 2 | 1 | 2026-06-17T07:05:03.993000 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection | |
| CVE-2013-4786 | 7.5 | 81.80% | 5 | 1 | 2026-06-16T23:57:53.617000 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R | |
| CVE-2026-22795 | 5.5 | 0.14% | 4 | 0 | 2026-05-12T15:32:20 | Issue summary: An invalid or NULL pointer dereference can happen in an applicati | |
| CVE-2025-69421 | 7.5 | 0.84% | 4 | 1 | 2026-05-12T15:31:14 | Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer de | |
| CVE-2025-69420 | 7.5 | 0.77% | 4 | 1 | 2026-05-12T15:31:14 | Issue summary: A type confusion vulnerability exists in the TimeStamp Response v | |
| CVE-2026-22796 | 5.3 | 0.50% | 4 | 0 | 2026-05-12T15:31:14 | Issue summary: A type confusion vulnerability exists in the signature verificati | |
| CVE-2025-69418 | 4.0 | 0.11% | 4 | 1 | 2026-05-12T15:31:14 | Issue summary: When using the low-level OCB API directly with AES-NI or<br>other | |
| CVE-2026-4893 | 5.3 | 2.68% | 4 | 5 | 2026-05-11T21:31:33 | An information disclosure vulnerability in dnsmasq allows remote attackers to by | |
| CVE-2026-32194 | 9.8 | 0.70% | 1 | 1 | 2026-03-20T00:31:34 | Improper neutralization of special elements used in a command ('command injectio | |
| CVE-2026-32191 | 9.8 | 0.56% | 1 | 0 | 2026-03-19T21:30:31 | Improper neutralization of special elements used in an os command ('os command i | |
| CVE-2025-66376 | 7.2 | 21.62% | 1 | 0 | 2026-03-18T18:31:10 | Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas | |
| CVE-2025-29827 | 9.9 | 1.25% | 1 | 0 | 2025-06-05T15:32:29 | Improper Authorization in Azure Automation allows an authorized attacker to elev | |
| CVE-2023-5217 | 8.8 | 49.01% | 2 | 3 | 2024-02-15T15:02:28 | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5 | |
| CVE-2008-1028 | None | 4.55% | 1 | 0 | 2023-01-31T05:05:55 | Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-as | |
| CVE-2026-53921 | 0 | 0.00% | 1 | 2 | N/A | ||
| CVE-2026-60137 | 0 | 77.97% | 1 | 45 | N/A | ||
| CVE-2026-25589 | 0 | 1.38% | 1 | 1 | N/A | ||
| CVE-2026-25243 | 0 | 3.30% | 1 | 3 | N/A | ||
| CVE-2026-16766 | 0 | 1.30% | 1 | 0 | N/A | ||
| CVE-2026-48021 | 0 | 0.12% | 2 | 0 | N/A | ||
| CVE-2026-54342 | 0 | 0.12% | 1 | 0 | N/A |
updated 2026-07-28T17:17:06.730000
2 posts
🟠 CVE-2026-66754 - High (7.5)
Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66754/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-66754 - High (7.5)
Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66754/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:20:53.010000
2 posts
🟠 CVE-2026-59878 - High (7.5)
Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All.
A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59878/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-59878 - High (7.5)
Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All.
A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59878/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:20:53.010000
1 posts
🟠 CVE-2026-43698 - High (7.8)
An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:20:53.010000
1 posts
🟠 CVE-2026-43776 - High (7.8)
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43776/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:20:16.310000
2 posts
🟠 CVE-2026-66748 - High (8.8)
Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_ev...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66748/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-66748 - High (8.8)
Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_ev...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66748/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:19:28.693000
2 posts
🟠 CVE-2026-61609 - High (7.5)
Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket to the login and two-factor checkpoin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61609/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61609 - High (7.5)
Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket to the login and two-factor checkpoin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61609/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:19:12.780000
1 posts
CVE-2026-65440 - XSS in GetGenie <=4.4.3. Unauthenticated. CVSS 7.1. No patch yet - apply WAF rules. #CVE #GetGenie #infosec
##updated 2026-07-28T16:17:58.820000
3 posts
#TeamCity #CVE202663077 #RCE #RemoteCodeExecution #JetBrains #CyberSecurity
##TeamCity Flaw Enables Unauthenticated Remote Code Execution
A critical TeamCity vulnerability, CVE-2026-63077, with a near-perfect CVSS score of 9.8, leaves all on-premise servers open to unauthenticated remote code execution - allowing attackers to run malicious commands with ease. Update your TeamCity server immediately to prevent exploitation.
#Cve202663077 #Teamcity #UnauthenticatedRemoteCodeExecution #Jetbrains #SupplyChain
###TeamCity #CVE202663077 #RCE #RemoteCodeExecution #JetBrains #CyberSecurity
##updated 2026-07-28T16:17:58.820000
1 posts
🟠 CVE-2026-49743 - High (7.8)
Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs.
During workload submission involving a fence exported by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49743/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:10:09.517000
2 posts
🟠 CVE-2026-7187 - High (8.8)
Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects UKBS: through 28072026.
NOTE: The vendor was contacted and it was learn...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7187/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-7187 - High (8.8)
Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects UKBS: through 28072026.
NOTE: The vendor was contacted and it was learn...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7187/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:07:41.440000
1 posts
🟠 CVE-2026-66035 - High (7.5)
libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:07:41.440000
1 posts
🟠 CVE-2026-66034 - High (7.5)
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsy...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66034/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:07:15.840000
1 posts
CVE-2026-13440 - Stored XSS in StoreGrowth WooCommerce. Unauthenticated inject scripts via message_popup. CVSS 7.2. No patch. Remove plugin until update. #CVE #WordPress #infosec
##updated 2026-07-28T15:32:19
2 posts
🟠 CVE-2026-63727 - High (8.8)
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capab...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63727/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63727 - High (8.8)
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capab...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63727/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T15:16:51.580000
4 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-28T14:50:33.960000
8 posts
🔵 THREAT INTELLIGENCE
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Vulnerability | CRITICAL
CVEs: CVE-2026-16812
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively...
Full analysis:
https://www.yazoul.net/news/article/attackers-exploit-arista-velocloud-orchestrator-command-injection-flaw
🏆 New Achievement! Ten Out of Ten, Would Exploit Again!
Step right up, valued on-premises customer! Today's featured item is CVE-2026-16812, a perfect-score CVSS 10.0 OS command injection in Arista's VeloCloud Orchestrator — the centralized management platform you trusted with the confidentiality, integrity, and availability of, well, everything. Unknown attackers are already browsing your privileged internal functionality like it's a clearance rack. (1/2)
##Arista VeloCloud Flaw Exposes On-Premises Networks to Active Exploitation
A critical security flaw in Arista VeloCloud, tracked as CVE-2026-16812, is under active exploitation, allowing remote attackers to access sensitive internal functionality and potentially leading to arbitrary code execution. This maximum-severity vulnerability could compromise the confidentiality, integrity, and availability of…
#Cve202616812 #Arista #Velocloud #SupplyChain #EmergingThreats
##🏆 New Achievement! Ten Out of Ten, Would Exploit Again!
Step right up, valued on-premises customer! Today's featured item is CVE-2026-16812, a perfect-score CVSS 10.0 OS command injection in Arista's VeloCloud Orchestrator — the centralized management platform you trusted with the confidentiality, integrity, and availability of, well, everything. Unknown attackers are already browsing your privileged internal functionality like it's a clearance rack. (1/2)
##(CISA TS-SOC) CVE-2026-16812 – Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Severity: CRITICAL Impact Summary: Remote attackers may access privileged internal functionality and impact the VCO host, compromising the confidentiality, integrity, and availability of the orchestrator and managed data....
##CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.
#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity
##CVE ID: CVE-2026-16812
Vendor: Arista
Product: VeloCloud Orchestrator
Date Added: 2026-07-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16812
CVE-2026-16812, a VeloCloud command injection scored CVSS 10, is exploited in the wild. Patch VeloCloud Orchestrator now, plus two related bugs.
#VeloCloud #Arista #CVE202616812 #CommandInjection #ExploitedInTheWild #VCO #SSRF #Cybersecurity
##updated 2026-07-28T12:31:27
1 posts
CVE-2026-14785 - SQLi in Web Directory Free WordPress plugin. Unauthenticated attackers can extract sensitive data. CVSS 7.5. No patch available - update or disable immediately. #CVE #WordPress #infosec
##updated 2026-07-28T12:31:27
2 posts
#OT #Advisory VDE-2026-085
Weidmueller: SQL Injection Vulnerability in PROCON-WEB SCADA
A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands.
#CVE CVE-2026-16462
https://certvde.com/en/advisories/vde-2026-085/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-085.json
###OT #Advisory VDE-2026-085
Weidmueller: SQL Injection Vulnerability in PROCON-WEB SCADA
A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands.
#CVE CVE-2026-16462
https://certvde.com/en/advisories/vde-2026-085/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-085.json
##updated 2026-07-28T12:31:20
1 posts
CVE-2026-10207 - SQLi in PickPlugins Question Answer plugin for WordPress. CVSS 7.5. Unauthenticated injection via 'id' param. No patch yet — disable or remove plugin immediately. #CVE #WordPress #infosec
##updated 2026-07-28T12:31:19
2 posts
The OVSwrap local root flaw hits the Linux kernel Open vSwitch datapath. CVE-2026-64531 now has a public patch and PoC. See affected distros and fixes.
#OVSwrap #CVE202664531 #LinuxKernel #OpenvSwitch #LocalRoot #PrivilegeEscalation
##The OVSwrap local root flaw hits the Linux kernel Open vSwitch datapath. CVE-2026-64531 now has a public patch and PoC. See affected distros and fixes.
#OVSwrap #CVE202664531 #LinuxKernel #OpenvSwitch #LocalRoot #PrivilegeEscalation
##updated 2026-07-28T09:31:36
4 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-28T09:31:36
4 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-28T09:31:35
4 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-28T00:32:06
1 posts
🟠 CVE-2026-43723 - High (7.8)
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root pri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43723/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T00:32:05
1 posts
🟠 CVE-2026-43749 - High (7.8)
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43749/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T00:32:04
1 posts
🟠 CVE-2026-39874 - High (7.8)
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-39874/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T00:31:11
1 posts
🟠 CVE-2026-66473 - High (7.5)
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66473/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T00:31:10
1 posts
CVE-2026-65439 - XSS in Ultimate Addons for Contact Form 7 ≤3.5.45. Unauthenticated. CVSS 7.1. No patch; apply WAF or disable plugin. #CVE #WordPress #infosec
##updated 2026-07-28T00:31:02
1 posts
🟠 CVE-2026-17107 - High (8.5)
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17107/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T21:16:48.080000
1 posts
🟠 CVE-2026-15962 - High (8.8)
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-lev...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15962/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T20:37:16.927000
1 posts
🟠 CVE-2026-17496 - High (8.1)
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17496/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T20:36:13.407000
1 posts
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-27T20:34:24.887000
1 posts
🟠 CVE-2026-66041 - High (8.8)
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimension...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66041/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T20:32:11.620000
1 posts
1 repos
🔴 New security advisory:
CVE-2026-55579 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-55579-pheditor-hardcoded-admin-rce-poc
updated 2026-07-27T20:32:11.620000
1 posts
CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! https://radar.offseq.com/threat/cve-2026-12503-cwe-59-improper-link-resolution-before-file-access-link-following-in-loytec-lip-me20xc-acfbe89cb621dc0e #OffSeq #Vulnerability #ICS #Loytec #CVE2026
##updated 2026-07-27T18:31:25
8 posts
CISA warnt vor aktiv ausgenutzter FortiOS-Sicherheitslücke
Grundlage dafür sind bestätigte Hinweise auf laufende Angriffe, bei denen die Lücke mit der Kennung CVE-2025-68686 zum Einsatz kommt.
https://www.all-about-security.de/cisa-warnt-vor-aktiv-ausgenutzter-fortios-sicherheitsluecke/
##CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass
CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.
**If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-in-fortinet-fortios-ssl-vpn-patch-bypass-h-6-5-r-8/gD2P6Ple2L
CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass
CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.
**If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-in-fortinet-fortios-ssl-vpn-patch-bypass-h-6-5-r-8/gD2P6Ple2L
CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.
#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity
##🚨 [CISA-2026:0727] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-68686 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-68686)
- Name: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: FortiOS
- Notes: https://fortiguard.fortinet.com/psirt/FG-IR-25-934 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-68686
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260727 #cisa20260727 #cve_2025_68686 #cve202568686
##(CISA TS-SOC) CVE-2025-68686 – Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Severity: MEDIUM Impact Summary: Exposure of sensitive information to unauthorized actors due to patch bypass, potentially leaking data after prior compromise....
##CVE ID: CVE-2025-68686
Vendor: Fortinet
Product: FortiOS
Date Added: 2026-07-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2025-68686
CISA has added a vulnerability to the KEV catalogue.
- CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-68686
Also:
Cisco tagged Apple yesterday for zero-day reports https://talosintelligence.com/vulnerability_reports#zerodays @TalosSecurity #Fortinet #CISA #infosec #vulnerability #Apple #zeroday
##updated 2026-07-27T18:16:50.790000
1 posts
🟠 CVE-2025-71408 - High (7.8)
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is inv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71408/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T15:32:39
3 posts
2 repos
PoC for CVE-2026-61511, unauthenticated vBulletin RCE https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
##🚨‼️ CVE-2026-61511: A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server.
CVSS: 9.8
Exploit: https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
##A public PoC now targets CVE-2026-61511, a vBulletin preauth RCE via runMaths eval. Patch to vBulletin 6.2.2 to block remote code execution.
#vBulletin #CVE202661511 #RCE #PreauthRCE #RemoteCodeExecution #PoC #WebSecurity #Cybersecurity
##updated 2026-07-27T14:41:12.090000
1 posts
🟠 CVE-2026-45813 - High (8.8)
Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service.
Improper validation when parsing BASS service "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45813/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T14:41:01.180000
1 posts
🟠 CVE-2026-45815 - High (7.5)
Reachable Assertion vulnerability in Apache NimBLE.
A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.
Severity is medium as this requires DUT to first send ATT Read Multiple ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45815/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T14:35:32.197000
1 posts
🟠 CVE-2026-66142 - High (7.5)
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recom...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66142/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T12:45:30.967000
1 posts
🟠 CVE-2026-16806 - High (8.8)
Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16806/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T09:31:26
1 posts
#OT #Advisory VDE-2026-077
Lenze: Incorrect signature validation in the enable SSH routine
The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.
#CVE CVE-2026-14837
https://certvde.com/en/advisories/vde-2026-077/
#CSAF https://lenze.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-077.json
##updated 2026-07-27T06:31:36
8 posts
6 repos
https://github.com/bha-vin/CVE-2026-64600-Exploit
https://github.com/letsr00t/RefluxFS_CVE-2026-64600
https://github.com/vulnquest58/VQ-RefluxCore
https://github.com/HORKimhab/CVE-2026-64600
RefluXFS : cette faille dans XFS donne un accès root sur RHEL, CentOS et AlmaLinux https://www.it-connect.fr/refluxfs-cve-2026-64600-faille-xfs-acces-root-linux/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Linux
##⚪️ New RefluXFS Vulnerability Enables Root Access on Linux
🗨️ Researchers at Qualys have discovered a nine-year-old vulnerability in the XFS file system. The bug, tracked as CVE-2026-64600 and dubbed RefluXFS, allows a local unprivileged user to overwrite protected files and gain root privileges. According to researchers, the bug was…
##📢 RefluXFS (CVE-2026-64600) : élévation de privilèges locale vers root dans le noyau Linux via XFS
📝 ## 🔍 Contexte
Le 22 juillet 2026...
📖 cyberveille : https://cyberveille.ch/posts/2026-07-26-refluxfs-cve-2026-64600-elevation-de-privileges-locale-vers-root-dans-le-noyau-linux-via-xfs/
🌐 source : https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600
#CVE_2026_64600 #IOC #Cyberveille
CVE-2026-64600, dubbed RefluXFS by Qualys Threat Research Unit, is a nine-year-old race condition that lets a local attacker clone a root-owned file — /etc/passwd, a SUID binary, you name it — then hammer it with concurrent O_DIRECT writes until they win the race and own the box. Highly reliable exploitation. Survives reboot. A beautiful, silent corpse. (2/3)
##🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
xfs: resample the data fork mapping after cycling ILOCK
RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access.
ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/1d26eb14-ce27-4846-a8ce-bae087fb1e46/refluxfs-vulnerability
#infosec #refluxfs #linux #kernel #xfs #lpe
#nttdata #zen #secdb
Na, zumindest das kriegen die angelernten neuronalen netzwerke sehr zuverlässig hin: einen haufen uralter fehler in linux aufzufinden. Schön die sicherheitsaktualisierungen einspielen!
#Epic #Fail #Golem #Link #Linux #Security ##⚠️ CRITICAL: New RefluXFS Linux flaw lets attackers gain root privileges
A nine-year-old race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite protected files and escalate to root. Systems running kernel v4.11+ with XFS and reflink enabled are vulnerable. The exploit leaves no kernel logs and persists across reboots, making dete…
##Discover the RefluXFS Linux vulnerability (CVE-2026-64600) in XFS that allows local users to overwrite protected files and gain root privileges.
#RefluXFS #CVE202664600 #LinuxKernel #Cybersecurity #XFS
https://meterpreter.org/refluxfs-linux-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-26T15:30:32
1 posts
🟠 CVE-2026-17497 - High (8.3)
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17497/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-26T12:30:21
1 posts
mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. https://radar.offseq.com/threat/cve-2026-17457-information-disclosure-in-mf-yang-openclaw-cn-1d4fae9414fd0132 #OffSeq #Vuln #InfoSec #CVE202617457
##updated 2026-07-26T12:30:21
1 posts
SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. https://radar.offseq.com/threat/cve-2026-17458-server-side-request-forgery-in-mf-yang-openclaw-cn-a8d78509307a6c7f #OffSeq #SSRF #Vuln #mfyang
##updated 2026-07-26T12:30:21
1 posts
CVE-2026-17459: perwendel spark 2.9.0 – 2.9.4 affected by symlink following in staticFiles.externalLocation. Exploit public, MEDIUM severity. Restrict external resource access and monitor for patches. https://radar.offseq.com/threat/cve-2026-17459-symlink-following-in-perwendel-spark-e9c7a3ae8bd59674 #OffSeq #CVE202617459 #Java #Security
##updated 2026-07-26T06:31:31
2 posts
CVE-2026-63720 (HIGH): koxudaxi datamodel-code-generator <0.70.0 is vulnerable to code injection. Malicious input schemas can trigger remote Python code execution. Avoid untrusted schemas & update when possible. https://radar.offseq.com/threat/cve-2026-63720-improper-control-of-generation-of-code-code-injection-in-koxudaxi-datamodel-code-a0a27f1d30c87e2e #OffSeq #infosec #Python #CVE202663720
##🟠 CVE-2026-63720 - High (7.5)
datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63720/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-25T12:31:47
2 posts
1 repos
https://github.com/Hunt-Benito/siyuan-mcp-admin-takeover-cve-2026-66012-missing-authorization
CVE-2026-66012: CRITICAL flaw in siyuan-note siyuan (<3.7.2). Missing authorization on /mcp lets remote attackers read secrets & plant malicious plugins for admin takeover. Disable anonymous Publish mode & restrict /mcp access. https://radar.offseq.com/threat/cve-2026-66012-missing-authorization-in-siyuan-note-siyuan-af31715ea5b396b1 #OffSeq #CVE #Infosec
##🔴 CVE-2026-66012 - Critical (10)
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66012/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-25T09:30:31
2 posts
1 repos
CVE-2026-10818: WPForms Pro <=1.10.1.1 has a HIGH severity file upload vuln (CVSS 8.1). Unauthenticated RCE possible via ajax_chunk_upload_finalize. Restrict access & monitor uploads until a patch is released. https://radar.offseq.com/threat/cve-2026-10818-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-wpforms-wpforms-pro-98bc8d14f7da8c03 #OffSeq #WordPress #Infosec #CVE202610818
##🟠 CVE-2026-10818 - High (8.1)
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10818/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-25T05:16:35.420000
2 posts
CVE-2026-56163: CRITICAL (CVSS 10) in Azure Kubernetes Service — Missing authentication allows remote privilege escalation. Microsoft has released a fix; verify your AKS is updated. https://radar.offseq.com/threat/cve-2026-56163-cwe-306-missing-authentication-for-critical-function-in-microsoft-azure-kubernetes-c5571c5da7b404e3 #OffSeq #Azure #Kubernetes #CloudSecurity
##🔴 CVE-2026-56163 - Critical (10)
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56163/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-25T05:16:35.100000
1 posts
🔴 CVE-2026-50517 - Critical (9.9)
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50517/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-25T03:30:55
1 posts
1 repos
🟠 CVE-2026-66374 - High (8.1)
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66374/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-25T03:30:55
1 posts
🟠 CVE-2026-66373 - High (7.5)
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both cons...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66373/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-25T02:16:39.663000
3 posts
CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at https://radar.offseq.com/threat/cve-2026-62835-cwe-285-improper-authorization-in-microsoft-azure-portal-defd11bbcf2e17c7 #OffSeq #Azure #Vuln #CloudSecurity
##🔴 CVE-2026-62835 - Critical (9.3)
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62835/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🚨 CVE-2026-62835: Microsoft Azure Portal Information Disclosure Vulnerability
CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.
CVSS: 9.3
More information: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62835
##updated 2026-07-25T00:31:53
2 posts
CVE-2026-61884 (CRITICAL, CVSS 9.8) in Tycon TPDIN-Monitor-WEB2 v2.3.9: Server-side auth validation missing — empty creds grant admin access. Restrict management interface, monitor for unauthorized logins. https://radar.offseq.com/threat/cve-2026-61884-cwe-288-in-tycon-systems-tpdin-monitor-web2-38fd252c1e4f018a #OffSeq #CVE #IoT #Infosec
##🔴 CVE-2026-61884 - Critical (9.8)
The web management interface of Tycon Systems TPDIN-Monitor-WEB2
does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can byp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61884/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-25T00:31:53
1 posts
🟠 CVE-2026-60134 - High (8.8)
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-60134/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-25T00:31:53
1 posts
🟠 CVE-2026-61892 - High (8.8)
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61892/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T21:33:30
1 posts
🟠 CVE-2026-12497 - High (7.5)
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12497/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T21:33:30
1 posts
🟠 CVE-2026-45811 - High (7.5)
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.
The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer ove...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45811/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T21:33:30
1 posts
🟠 CVE-2026-66144 - High (7.5)
Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66144/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T21:33:30
1 posts
🟠 CVE-2026-66143 - High (7.5)
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66143/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T21:33:29
1 posts
🟠 CVE-2026-12981 - High (7.5)
The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12981/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T21:33:29
1 posts
🔴 CVE-2026-12877 - Critical (9.1)
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is expl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12877/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T21:33:29
1 posts
🟠 CVE-2026-45816 - High (7.5)
NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.
This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.
This...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45816/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T21:32:28
1 posts
🟠 CVE-2026-66039 - High (8.8)
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attack...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66039/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T21:32:28
1 posts
🟠 CVE-2026-66036 - High (8.8)
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66036/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T21:32:28
1 posts
🟠 CVE-2026-66040 - High (8.8)
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66040/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T20:48:39.923000
1 posts
🟠 CVE-2026-14603 - High (7.5)
The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the d...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14603/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T18:32:33
1 posts
🟠 CVE-2026-49745 - High (7.8)
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.
Software installed and run under a Guest VM can send commands to the G...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49745/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T18:32:33
1 posts
🟠 CVE-2026-16800 - High (8.8)
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via craf...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16800/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T18:32:32
1 posts
🟠 CVE-2026-49744 - High (7.8)
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.
Out of bounds accesses triggered by malware introduced to a Guest KMD ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49744/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T18:32:32
1 posts
🟠 CVE-2026-16801 - High (8.8)
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a craf...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16801/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T18:31:41
1 posts
🟠 CVE-2026-65709 - High (8.3)
sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without pe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65709/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T18:31:41
1 posts
🟠 CVE-2026-66033 - High (7.5)
libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AE...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66033/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T18:31:37
1 posts
🟠 CVE-2026-65708 - High (8.1)
sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing au...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65708/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T18:31:37
1 posts
🟠 CVE-2026-66032 - High (8.8)
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66032/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T17:17:34.993000
1 posts
🟠 CVE-2026-66027 - High (8.3)
Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66027/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T15:34:00
1 posts
🟠 CVE-2026-16807 - High (8.8)
Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T15:34:00
1 posts
🟠 CVE-2026-16805 - High (8.8)
Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16805/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T15:34:00
1 posts
🟠 CVE-2026-16804 - High (8.3)
Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16804/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T15:33:10
1 posts
🟠 CVE-2026-8789 - High (8.1)
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T15:33:09
3 posts
CVE-2026-58630: Improper access control in Azure App Service for Linux (CVSS 10, CRITICAL) lets remote attackers escalate privileges with no auth or user action. Patched by Microsoft — verify updates. Details: https://radar.offseq.com/threat/cve-2026-58630-cwe-284-improper-access-control-in-microsoft-azure-app-service-for-linux-12c1219307778a3e #OffSeq #Azure #Infosec #CVE2026_58630
##‼️ CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVSS: 10
Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58630
##🔴 CVE-2026-58630 - Critical (10)
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58630/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T15:33:03
2 posts
Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: https://radar.offseq.com/threat/cve-2026-57106-cwe-918-server-side-request-forgery-ssrf-in-microsoft-microsoft-purview-data-governance-0983080847f54f67 #OffSeq #Vuln #SSRF #Microsoft #CyberSec
##🔴 CVE-2026-57106 - Critical (10)
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T06:34:11
1 posts
🟠 CVE-2026-66140 - High (8.4)
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66140/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T05:16:45.793000
1 posts
1 repos
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-24T05:16:44.947000
1 posts
1 repos
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-24T03:32:01
1 posts
🟠 CVE-2026-35425 - High (8)
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35425/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T03:31:56
2 posts
🔴 CVE-2026-54120 - Critical (9.9)
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54120/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-54120 (CRITICAL, CVSS 9.9): Improper input validation in Microsoft Surface Management Services lets authorized attackers run code remotely. Patch now: https://radar.offseq.com/threat/cve-2026-54120-cwe-20-improper-input-validation-in-microsoft-surface-management-services-203a5e59f513d748 🖥️ #OffSeq #infosec #Microsoft #CVE202654120
##updated 2026-07-24T03:31:56
1 posts
🟠 CVE-2026-56167 - High (8.5)
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56167/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T00:32:40
2 posts
A Panduit IntraVUE vulnerability tracked as CVE-2026-42933 scores CVSS 10. Five flaws let attackers cross OT segmentation and steal credentials.
##A Panduit IntraVUE vulnerability tracked as CVE-2026-42933 scores CVSS 10. Five flaws let attackers cross OT segmentation and steal credentials.
##updated 2026-07-23T18:31:54
1 posts
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-23T15:44:10.873000
4 posts
3 repos
https://github.com/HORKimhab/CVE-2026-50522
State of (in)security - Week 30, 2026
During week 30 of 2026, cybersecurity monitoring recorded 7 advisories and 28 incidents/breaches affecting roughly 80 million individuals. The largest breach is Suno exposing 55.3 million users and AI training source code. Malware/ransomware and unauthorized access are the leading causes of incidents and healthcare and IT/software as the most-targeted industries.
**Patch the actively exploited on-premises SharePoint (CVE-2026-50522), self-hosted ServiceNow, Fastjson 1.x Java apps, Oracle systems (July 2026 Critical Patch Update), and WordPress. Then update Firefox and Thunderbird and confirm your Adobe Acrobat Chrome extension is running version 26.5.2.3 or later.**
#cybersecurity #infosec #knowledge #weeklyreport
https://beyondmachines.net/event_details/state-of-in-security-week-30-2026-w-0-e-b-i/gD2P6Ple2L
🏆 New Achievement! Stand In the Fire, Lose the SharePoint!
MOVE OUT OF THE DESERIALIZATION FLAW. I AM NOT KIDDING. CVE-2026-50522 is a CVSS 9.8 critical hole in on-premises Microsoft SharePoint — remote code execution, low complexity, no special system knowledge required. Researchers at watchTowr and Defused are screaming in chat right now because exploit code just dropped and attackers are already in your server. (1/2)
##Active exploitation verified for CVE-2026-50522. Microsoft SharePoint's deserialization flaw demands immediate C-Suite oversight, patch prioritization, and strict endpoint hardening. Protect your enterprise assets today. https://thecybermind.co/kc88
##(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data....
##updated 2026-07-23T15:01:24.377000
5 posts
3 repos
https://github.com/HORKimhab/CVE-2026-16723
⚠️ CRITICAL: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Attackers are actively exploiting CVE-2026-16723, a critical RCE in Alibaba Fastjson 1.x used by Spring Boot applications. Unauthenticated code execution is possible with Java process privileges. No patch exists for 1.x versions yet.
##🏆 New Achievement! Critical Hit: JSON and the Argonauts!
You have looted a CURSED ITEM: Fastjson 1.x (versions 1.2.68–1.2.83). Equip penalty: unauthenticated attackers may now execute arbitrary code on your Spring Boot applications via crafted JSON requests, bypassing default security configurations entirely. CVE-2026-16723 is active in the wild, no patch exists for the 1.x branch, and yes, that means you.
Inventory is full of regret. (1/2)
##FastJson 1.2.83 RCE (CVE-2026-16723) https://fearsoff.org/research/fastjson-1-2-83-rce
##Critical Fastjson 1.x Zero-Day RCE Exploited in the Wild
Alibaba's Fastjson 1.x library is vulnerable to a critical zero-day remote code execution flaw (CVE-2026-16723) that is currently exploited in the wild against Spring Boot applications. The vulnerability allows unauthenticated attackers to run arbitrary code by bypassing default security configurations through crafted JSON requests.
**If you run Java apps using Fastjson 1.x (versions 1.2.68–1.2.83) as Spring Boot fat-JARs, your applications are actively attacked, and there is no patch for the 1.x branch. Migrate to Fastjson2 ASAP. If you can't migrate, immediately enable SafeMode by adding `-Dfastjson.parser.safeMode=true` to your JVM settings and monitor your logs for unusual `@type` values or unexpected outbound connections from Java.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/critical-fastjson-1-x-zero-day-rce-exploited-in-the-wild-d-d-0-w-k/gD2P6Ple2L
FastJson RCE vulnerability CVE-2026-16723 is exploited in the wild. Details and PoC exploit code are public for this critical remote code execution flaw.
##updated 2026-07-23T12:18:18.287000
1 posts
13 repos
https://github.com/g0thamRabb1t/CVE-2026-46331-pedit-COW-detection
https://github.com/rjt-gupta/page-cache-corruption-lpes
https://github.com/cherrycherrymay/PoC-CVE-2026-46331
https://github.com/sgkdev/packet_edit_meme
https://github.com/vulnquest58/dirtyclone-exploit
https://github.com/MarwahHadi/CVE-2026-46331-pedit-cow
https://github.com/V0IDNETWORK/CVE-2026-46331
https://github.com/yanxinwu946/CVE-2026-46331
https://github.com/0xBlackash/CVE-2026-46331
https://github.com/douglasmun/pagecache-lpe-containment-kit
https://github.com/Quaerendir/cve-2026-46331-audit
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/
##updated 2026-07-22T23:10:00.110000
2 posts
70 repos
https://github.com/Lutfifakee-Project/wp2shell
https://github.com/ekomsSavior/wp2shell
https://github.com/zeroc00I/CVE-2026-63030
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/fullhunt/wp2shell-scan
https://github.com/ChiefYoru/CVE-2026-63030_PoC
https://github.com/gbrsh/CVE-2026-63030
https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/mverschu/CVE-2026-63030
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t
https://github.com/0xh7ml/CVE-2026-63030
https://github.com/imXur/WordPress-CVE-2026-63030-Analysis
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/mhtsec/CVE-2026-63030
https://github.com/bahartanir/wp2shell-scanner
https://github.com/yuag/wp2shell
https://github.com/vulnquest58/PressVector
https://github.com/0xWhoknows/wp2shell
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/mcipekci/wp2shell
https://github.com/0xsha/wp2shell
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/securelayer7/WordPresShell
https://github.com/Crypto-Cat/wp2shell
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/ananay/wp2shell-lab
https://github.com/Icex0/wp2shell-poc
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/CybersecSpirit/CVE-2026-63030
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/ikow/wp2shell
https://github.com/h4cd0c/wp2shell
https://github.com/raphy76/wp2shell-poc-fulljs
https://github.com/dinosn/wp2shell-lab
https://github.com/InstaWP/wp2shell-scan
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/zi3lak/wp2shell_scanner
https://github.com/0xjessie21/wp2shell-checker
https://github.com/Ch4120N/CVE-2026-63030
https://github.com/shinthink/CVE-2026-63030
https://github.com/4minx/CVE-2026-63030
https://github.com/administrator-01001/CVE-2026-63030
https://github.com/kulichr/wp2shell
https://github.com/Iqbalx7/wp2shell
https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030
https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030
https://github.com/mrx-arafat/CVE-2026-63030-POC
https://github.com/c0gnit00/Wp2Shell
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/TomorrowX6/CVE-2026-63030-poc
https://github.com/ebrasha/abdal-cve-2026-63030
https://github.com/ZenithGenius/wordpress-batch-rce-lab
https://github.com/NULL200OK/WP2Shell
https://github.com/4B3R4M4-607D/CVE-2026-63030-POC
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/47Cid/wp2shell-lab
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/attackercan/wp2shell-poc2
Holy shit
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."
##WordPress Gets RCE’d, and the Internet Pretends This Wasn’t Predictable
PANIC 82% | Lag 0.0h | wp2shell is an exploited WordPress Core remote code execution chain involving CVE-2026-63030 and CVE
#AfterShockIndex
updated 2026-07-22T21:33:00
1 posts
CERT/CC warns of a Plane authorization bypass, CVE-2026-15342. It lets users reach other workspaces' files, and no patch exists yet.
#Plane #CVE202615342 #AuthorizationBypass #MultiTenant #CERTCC #Vulnerability #Cybersecurity
##updated 2026-07-22T21:32:15
1 posts
MongoDB Patches 26 Vulnerabilities Including Critical Memory Corruption Flaw
MongoDB released security updates to fix 26 vulnerabilities, including a critical memory corruption flaw (CVE-2026-13072) and multiple high-severity issues that allow unauthorized data access and service crashes.
**If you run self-hosted MongoDB, update your servers now to the latest patched version (7.0.39, 8.0.28, 8.2.12, 8.3.7, or 9.0.0-rc1). There's a critical flaw that could let attackers crash your database or run their own code. If you use MongoDB Atlas or another managed service, you're already covered and don't need to do anything.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/mongodb-patches-26-vulnerabilities-including-critical-memory-corruption-flaw-0-u-a-i-s/gD2P6Ple2L
updated 2026-07-22T21:32:05
3 posts
1 repos
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
Discover the critical CVE-2026-16232 vulnerability in Check Point Security Management servers, allowing remote attackers to gain full administrative privileges without a password.
#CheckPoint #CyberSecurity #CVE202616232 #NetworkSecurity #Vulnerability
##‼️ CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
CVSS: 9.1
Scanner: https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
Details and Mitigation: https://support.checkpoint.com/results/sk/sk185169/
##updated 2026-07-22T19:17:14.773000
1 posts
CVE-2026-8933, lovingly documented by the Qualys Threat Research Unit, lets a local user squeeze through that gap, drop a malicious AppArmor rules file, prod systemd-udevd into running commands as root, and collect full root access like a door prize. Ubuntu Desktop 24.04, 25.10, and 26.04 ship this by default. It is a trap room with the pressure plate installed by the architect. (2/3)
##updated 2026-07-22T19:07:43.103000
2 posts
6 repos
https://github.com/chuzhongyun/CVE-2026-53359-Kernel-Fix
https://github.com/HORKimhab/CVE-2026-53359
https://github.com/ndouglas-cloudsmith/CVE-2026-53359
https://github.com/0xBlackash/CVE-2026-53359
Lessons learned from handling a KVM flaw on tens of thousands of machines
OVHcloud는 Linux KVM x86의 shadow paging use-after-free 취약점(CVE-2026-53359)에 대응해 수만 대의 하이퍼바이저와 약 100만 VM을 대상으로 일주일간 패치 캠페인을 수행한 운영 사례를 공개했다. 취약점은 해제된 페이지를 RMAP이 참조하는 문제로, 악성 테넌트가 호스트를 크래시시키거나 최악의 경우 호스트 권한 상승을 유발할 수 있으며, 내부 재현에서는 미패치 호스트가 약 2분 내 크래시했다. OVHcloud는 라이브 패치, nested virtualiza...
https://blog.ovhcloud.com/en/posts/cve-2026-53359-kvm-patching-lessons-learned/
##I wonder how many hosters are vulnerable to CVE-2026-53359 (Januscape). Probably a lot.
##updated 2026-07-22T16:17:28.753000
2 posts
1 repos
CVE-2026-49176 is a Windows WalletService elevation of privilege flaw. Full details and a public PoC exploit are out, so patch Windows now.
#CVE202649176 #WalletService #Windows #PrivilegeEscalation #EoP #PoC #Microsoft
##CVE-2026-49176 Exploit Development: WalletService to SYSTEM https://lobste.rs/s/dxhdqx #security #windows
https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/
updated 2026-07-22T15:31:34
1 posts
1 repos
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-22T00:32:44
1 posts
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-21T21:33:35
1 posts
Apache Fory vulnerabilities hit Java, C++, and Rust deserialization, including CVE-2026-64606. Upgrade to Fory 1.4.0 to fix all four flaws.
#ApacheFory #Deserialization #Java #Rust #Cpp #Vulnerability #OpenSource #Cybersecurity
##updated 2026-07-21T21:32:47
1 posts
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-21T19:54:33.623000
9 posts
8 repos
https://github.com/GlendonNotGlen/certighost-cve-2026-54121-slides
https://github.com/ChPratik/CVE-2026-54121
https://github.com/0xBlackash/CVE-2026-54121
https://github.com/mwnickerson/certighost-bof
https://github.com/marcgoam/CVE-2026-54121-CertiGhost
https://github.com/aniqfakhrul/CVE-2026-54121
Exploit público para a falha Certighost expôs domínios do Windows a controlo total. Uma nova vulnerabilidade, rastreada como CVE-2026-54121, coloca redes empresariais em risco e permite que um atacante assuma o controlo completo de um domínio informático. 🚨
##Exploit público para a falha Certighost expôs domínios do Windows a controlo total. Uma nova vulnerabilidade, rastreada como CVE-2026-54121, coloca redes empresariais em risco e permite que um atacante assuma o controlo completo de um domínio informático. 🚨
##CertiGhost fork - Patched SAN handling + MAQ-safe account reuse https://github.com/marcgoam/CVE-2026-54121-CertiGhost
##Detect the Certighost with NetExec🔥
Thanks to Xed_sama, the enum_cve module of NetExec will now detect if a host has not been patched and is potentially vulnerable to the Certighost vulnerability (CVE-2026-54121)🚀
https://thecybersecguru.com/news/certighost-cve-2026-54121-ad-cs-domain-controller-impersonation/
##Certighost (CVE-2026-54121) : un compte AD standard suffit pour usurper un contrôleur de domaine https://www.it-connect.fr/certighost-cve-2026-54121-ad-cs-controleur-de-domaine/ #ActuCybersécurité #ActiveDirectory #Cybersécurité #Vulnérabilité #Microsoft
##⚠️ CRITICAL: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Certighost (CVE-2026-54121) allows any domain user to obtain a Domain Controller certificate and execute DCSync attacks to steal the krbtgt secret without admin rights. This gives attackers a direct path to full domain compromise. Any organization running unpatched Active Directory is at immediate…
##‼️ PoC released for CVE-2026-54121 codenamed Certighost
CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.
##New.
GitHub/H0j3n: Certighost (CVE-2026-54121) https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26
More:
The Hacker News: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html @thehackernews #infosec #vulnerability #Microsoft #Windows
##updated 2026-07-21T12:10:00.090000
4 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-20T21:31:57
1 posts
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-20T21:31:57
1 posts
1 repos
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-20T21:31:40
4 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-18T17:25:06
1 posts
🚨 EUVD-2026-49580
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: astro
🏢 Vendor: withastro
📅 Published: 2026-07-27 | Updated: 2026-07-28
📝 Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped spread attribute names in renderHTMLElement. The fix for CVE-2026-54298 (GHSA-jrpj-wcv7-9fh9) added an INVALID_ATTR_...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-49580
##updated 2026-07-18T09:32:17
2 posts
Fraggap Linux Kernel Vulnerability: Full Details and PoC Exploit Code Now Public
##Fraggap Linux Kernel Vulnerability: Full Details and PoC Exploit Code Now Public
##updated 2026-07-17T05:16:38.870000
1 posts
6 repos
https://github.com/error-inside/CVE-2026-39808
https://github.com/samu-delucas/CVE-2026-39808
https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808
https://github.com/0xBlackash/CVE-2026-39808
(CISA TS-SOC) CVE-2026-39808 – Fortinet FortiSandbox OS Command Injection Vulnerability
Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to execute unauthorized code or commands on the affected system via crafted HTTP requests....
##updated 2026-07-16T18:32:24
1 posts
2 repos
(CISA TS-SOC) CVE-2026-25089 – Fortinet FortiSandbox OS Command Injection Vulnerability
Severity: CRITICAL Impact Summary: Allows remote, unauthenticated attackers to execute arbitrary operating system commands on affected FortiSandbox products via HTTP....
##updated 2026-07-16T18:31:26
1 posts
(CISA TS-SOC) CVE-2026-58644 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data....
##updated 2026-07-16T12:17:51.630000
1 posts
3 repos
https://github.com/v4ltonn/CVE-2026-42530
PoC's for nginx RCE (CVE-2026-42530, CVE-2026-42533) https://github.com/DepthFirstDisclosures/Nginx-Rift/
##updated 2026-07-16T05:16:16.603000
1 posts
(CISA TS-MAN) CVE-2023-4346 – KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
Severity: HIGH Impact Summary: An attacker could purge all devices and set a BCU key to lock the device, potentially resulting in denial of service if additional security options are not enabled....
##updated 2026-07-15T18:32:50
1 posts
2 repos
(CISA TS-MAN) CVE-2026-46817 – Oracle E-Business Suite Improper Privilege Management Vulnerability
Severity: CRITICAL Impact Summary: Allows unauthenticated attacker to compromise Oracle Payments, potentially resulting in full takeover....
##updated 2026-07-15T15:33:14
4 posts
8 repos
https://github.com/suominen/CVE-2026-42533
https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report
https://github.com/Daniyal48/ghostlock-vagrant-box
https://github.com/srkyn/nginx-map-risk-audit
https://github.com/gagaltotal/CVE-2026-42533-nginx
https://github.com/imbas007/CVE-2026-42533
https://github.com/seguridadentrerios/CVE-2026-42533
https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner
A public PoC now details CVE-2026-42533, an NGINX heap overflow with an ASLR bypass and possible RCE. Upgrade to NGINX 1.31.3 or 1.30.4 now.
#NGINX #CVE202642533 #RCE #HeapOverflow #ASLRBypass #NGINXPlus #PoC #Cybersecurity
##A public PoC now details CVE-2026-42533, an NGINX heap overflow with an ASLR bypass and possible RCE. Upgrade to NGINX 1.31.3 or 1.30.4 now.
#NGINX #CVE202642533 #RCE #HeapOverflow #ASLRBypass #NGINXPlus #PoC #Cybersecurity
##PoC's for nginx RCE (CVE-2026-42530, CVE-2026-42533) https://github.com/DepthFirstDisclosures/Nginx-Rift/
##15-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533 – cyberstan #devopsish https://cyberstan.co.uk/nginx-rce/
##updated 2026-07-14T21:32:52
1 posts
(CISA TS-MAN) CVE-2026-56155 – Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Severity: HIGH Impact Summary: Allows an authorized attacker to locally elevate privileges due to insufficient granularity of access control....
##updated 2026-07-14T21:32:21
1 posts
3 repos
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
🚨 Active Exploit Warning: SonicWall SMA1000 appliances are under fire from a high-severity code injection flaw (CVE-2026-15410). Our latest TSUITE brief breaks down the CrowdStrike detection logic and immediate hardening steps to secure your management interfaces. Command the wire: https://thecybermind.co/jily
##updated 2026-07-14T18:32:33
1 posts
Microsoft has patched a critical Windows Event Logging vulnerability (CVE-2026-50502) allowing remote code execution. Update your systems immediately.
#Microsoft #Vulnerability #CyberSecurity #WindowsServer #CVE202650502
##updated 2026-07-14T18:32:32
1 posts
A public proof-of-concept details the Windows AppResolver LPE (CVE-2026-50454), a UAC bypass that chains an admin token to a SYSTEM shell.
#Windows #CVE202650454 #PrivilegeEscalation #UACBypass #InfoSec
##updated 2026-07-08T06:31:34
2 posts
1 repos
AI-Assisted Research Exposes Linux Kernel Zero-Day Flaw
Researchers have uncovered a long-standing vulnerability in the Linux kernel, known as CVE-2026-53264, which allows a local user to gain root privileges by exploiting a flaw in the packet-scheduling code. This zero-day flaw was identified with the help of AI-assisted research and has since been patched.
#LinuxKernel #ZeroDay #AiassistedResearch #StarLabs #Cve202653264
##AI-Assisted Linux Exploit Turns Local Users into Root
Researchers have uncovered a significant Linux exploit, CVE-2026-53264, that can turn local users into root users, highlighting the importance of human judgement in AI-assisted security work. This flaw, patched in June 2026, shows AI still has limitations, emphasizing the need for human oversight.
#LinuxExploit #Cve202653264 #LocalPrivilegeEscalation #AiassistedExploit #StarLabs
##updated 2026-07-07T22:14:37
1 posts
1 repos
(CISA TS-MAN) CVE-2026-55255 – Langflow Authorization Bypass Through User-Controlled Key Vulnerability
Severity: HIGH Impact Summary: An authenticated attacker can execute any flow belonging to another user by specifying the victim's flow ID in the request, bypassing authorization controls....
##updated 2026-06-30T03:37:45
4 posts
2 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-27T06:30:25
2 posts
42 repos
https://github.com/simota/nginx-rift-scanner
https://github.com/F2u0a0d3/CVE-2026-42945-nginx-rift-poc
https://github.com/ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945
https://github.com/edgecases-PurpleHax/cve-images
https://github.com/BarAppTeam/nginx-cve-fix
https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC
https://github.com/nanwinata/nginxrift-CVE-2026-42945
https://github.com/0xBlackash/CVE-2026-42945
https://github.com/oseasfr/Scanner_CVE_2026-42945
https://github.com/sec-sys/CVE-2026-42945-Reverse-Shell-POC
https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab
https://github.com/forxiucn/nginx-cve-2026-42945-poc
https://github.com/iammerrida-source/nginx-rift-detect
https://github.com/rheodev/CVE-2026-42945
https://github.com/RedCrazyGhost/CVE-2026-42945
https://github.com/limo57640-crypto/nginx-rift-detector
https://github.com/imSre9/CVE-2026-42945
https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift
https://github.com/MateusVerass/nGixshell
https://github.com/realityone/cve-2026-42945-scan
https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945
https://github.com/tal7aouy/nginx-cve-2026-42945
https://github.com/nu0l/NGINX-Rift
https://github.com/hulina9900-boop/DIY-CVE-2026-42945-POC
https://github.com/dinosn/cve-2026-42945-nginx32-lab
https://github.com/quantumworld-dpdns-io/CVE-2026-42945
https://github.com/sibersan/web-server-audit_CVE-2026-42945
https://github.com/fkj-src/fix_nginx_cve_2026_42945
https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945
https://github.com/byezero/nginx-cve-2026-42945-check
https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script
https://github.com/cipherspy/CVE-2026-42945-POC
https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945
https://github.com/josephfelix/CVE-2026-42945-nginx-rift
https://github.com/strivepan/Nginx_cve-2026-42945-scanner-gui
https://github.com/yusufdalbudak/CVE-2026-42945
https://github.com/aratane/CVE-2026-42945
https://github.com/hnytgl/CVE-2026-42945
https://github.com/jelasin/CVE-2026-42945
https://github.com/azilRababe/CVE-2026-42945
https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit
You do not get to respawn. The debuff is applied to all servers simultaneously. Enjoy your stay.
Patch NGINX now to address CVE-2026-42945 before the PoC makes your threat landscape significantly more crowded.
Reward: You've received the Mandatory Participation Trophy — it's just a heap of broken memory.
#Nginx #RCE #CyberSecurity #ZeroDay #BufferOverflow #ExploitUnlocked (2/2)
##🏆 New Achievement! Heap Today, Gone Tomorrow!
Welcome, new player, to the NGINX Rift tutorial! This mandatory onboarding introduces CVE-2026-42945, a critical heap buffer overflow in NGINX that enables remote code execution. A proof-of-concept exploit has now been published publicly, which means this mechanic is fully unlocked for every participant — including the ones you did not invite.
Think of it like Minecraft's Hardcore Mode, except the world was already on fire when you loaded in. (1/2)
##updated 2026-06-26T15:33:15
4 posts
1 repos
⚠️ CRITICAL: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Cl0p ransomware affiliates are actively exploiting unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM instances by chaining CVE-2026-12569 with a separate information disclosure flaw. Affected organizations in manufacturing, automotive, aerospace, and retail face data…
##Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)
#Cl0p #CVE_2026_12569
https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/
2026-W30 — Weekly Threat Roundup
🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required.
🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da…
CVE-2026-12569 - Changed to Known Ransomware Status
PTC Windchill and FlexPLM Improper Input Validation VulnerabilityVendor: PTCProduct: Windchill and FlexPLMPTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: July 24,https://nvd.nist.gov/vuln/detail/CVE-2026-12569
##updated 2026-06-17T18:36:29
2 posts
@drwhax also CVE-2026-0160 affecting RTT (US mandated). Reachability is via RTT call.
##@drwhax also CVE-2026-0160 affecting RTT (US mandated). Reachability is via RTT call.
##updated 2026-06-17T17:34:19.580000
2 posts
CVE-2026-0149
##CVE-2026-0149
##updated 2026-06-17T10:00:39.850000
4 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-17T09:58:39.407000
4 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-17T07:05:03.993000
2 posts
1 repos
Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) https://mobeta.fr/simple-job-board-unauth-rce-cve-2024-1813/
##Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) https://mobeta.fr/simple-job-board-unauth-rce-cve-2024-1813/
##updated 2026-06-16T23:57:53.617000
5 posts
1 repos
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
Lava 연구진은 인터넷에 노출된 IPMI/BMC 호스트 36,872개 중 24,650개가 CVE-2013-4786으로 인해 오프라인 크래킹 가능한 인증 응답을 노출한다고 보고했다. 이 취약점은 공격자가 UDP 623 포트의 IPMI 인증 핸드셰이크를 악용해 비밀번호 해시 유래 정보를 수집한 뒤 GPU 등으로 크래킹할 수 있게 하며, 약한 기본 자격 증명과 결합될 경우 서버의 전원·펌웨어·가상 미디어를 제어할 수 있다. 특히 GPU 가상화·...
##IPMI Vulnerability Exposes 24,650 Server Management Interfaces
A recent security researcher found that over 30% of server management interface passwords can be easily cracked using common wordlists and factory default patterns, exposing a massive 24,650 interfaces to potential threats. This startling vulnerability, CVE-2013-4786, allows hackers to gain unauthorized access to…
#IpmiVulnerability #Cve20134786 #ServerManagement #EmergingThreats #InformationDisclosure
##Decades-Old BMC Flaw Exposes 24,000 Servers to Password Cracking
A decades-old security flaw in Baseboard Management Controller (BMC) interfaces is putting over 24,000 internet-exposed servers at risk of password cracking, thanks to a vulnerability that allows attackers to capture and crack authentication responses. This two-decade-old weakness, tracked as CVE-2013-4786, is a pressing concern for server…
##RE: https://infosec.exchange/@BleepingComputer/116997530501171992
The firm that provided the story to BC is a new startup aiming to help "Manage and Secure Data Centers".
They exploited CVE-2013-4786
This is advertising a new startup by flogging a report by extremely lazy "researchers" (did they even do *any* "is this a honeypot" tests?)
Perhaps don't let your C-suite give Lava any business?
##RE: https://infosec.exchange/@BleepingComputer/116997530501171992
The firm that provided the story to BC is a new startup aiming to help "Manage and Secure Data Centers".
They exploited CVE-2013-4786
This is advertising a new startup by flogging a report by extremely lazy "researchers" (did they even do *any* "is this a honeypot" tests?)
Perhaps don't let your C-suite give Lava any business?
##updated 2026-05-12T15:32:20
4 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-05-12T15:31:14
4 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-05-12T15:31:14
4 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-05-12T15:31:14
4 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-05-12T15:31:14
4 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-05-11T21:31:33
4 posts
5 repos
https://github.com/Polosss/By-Poloss..-..CVE-2026-48939
https://github.com/shinthink/CVE-2026-48939
https://github.com/lottiedeyan/CVE20264893poc
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
###OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-03-20T00:31:34
1 posts
1 repos
⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im…
##updated 2026-03-19T21:30:31
1 posts
⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im…
##updated 2026-03-18T18:31:10
1 posts
2026-W30 — Weekly Threat Roundup
🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required.
🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da…
updated 2025-06-05T15:32:29
1 posts
By continuing to run Azure Automation with default settings, you hereby agree to the following terms: (1) your tenant identity may be made available to any registered Azure user who wishes to borrow it, (2) your credentials, cloud workloads, and data shall be considered shared resources, and (3) you waive all complaints regarding CVE-2025-29827, CVSS 9.9, which allowed any attacker with their own Azure Automation account to vault the trust boundary and impersonate another tenant entirely. (2/3)
##updated 2024-02-15T15:02:28
2 posts
3 repos
https://github.com/Trinadh465/platform_external_libvpx_v1.4.0_CVE-2023-5217
https://github.com/UT-Security/cve-2023-5217-poc
https://github.com/Trinadh465/platform_external_libvpx_v1.8.0_CVE-2023-5217
now to figure out if CVE-2023-5217 on our NAS actually matters...
##now to figure out if CVE-2023-5217 on our NAS actually matters...
##updated 2023-01-31T05:05:55
1 posts
Apple was much more verbose in describing security issues in 2008 (look at CVE-2008-1028)
https://support.apple.com/en-ie/102486
1 posts
2 repos
OpenWrt Fixes Critical DHCPv6 Flaw That Exposes Root Code Execution Risk
OpenWrt has patched a critical DHCPv6 flaw, known as CVE-2026-53921, that could allow an unauthenticated attacker to execute root code by sending a crafted request to the DHCPv6 server. This severe vulnerability, rated 9.8 out of 10, highlights the importance of updating your OpenWrt setup to prevent potential security breaches.
##1 posts
45 repos
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/ekomsSavior/wp2shell
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/yuag/wp2shell
https://github.com/bahartanir/wp2shell-scanner
https://github.com/vulnquest58/PressVector
https://github.com/0xWhoknows/wp2shell
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/mcipekci/wp2shell
https://github.com/0xsha/wp2shell
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/securelayer7/WordPresShell
https://github.com/Crypto-Cat/wp2shell
https://github.com/ebrasha/abdal-cve-2026-60137
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/Icex0/wp2shell-poc
https://github.com/ananay/wp2shell-lab
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/ikow/wp2shell
https://github.com/h4cd0c/wp2shell
https://github.com/dinosn/wp2shell-lab
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/zi3lak/wp2shell_scanner
https://github.com/0xjessie21/wp2shell-checker
https://github.com/shinthink/CVE-2026-63030
https://github.com/kulichr/wp2shell
https://github.com/northsia/CVE-2026-60137-With-Skip-SSL
https://github.com/Iqbalx7/wp2shell
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/NULL200OK/WP2Shell
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/47Cid/wp2shell-lab
Holy shit
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."
##1 posts
1 repos
https://github.com/mgiay/CVE-2026-25589-25588-25243-23631-23479-REDIS
Discover how new Redis RCE exploit PoC code bypasses fixes for CVE-2026-25243 and CVE-2026-25589 across multiple Redis versions.
#Redis #Cybersecurity #RCE #Vulnerability #ExploitPoC
https://meterpreter.org/redis-rce-exploit-poc/?utm_source=mastodon&utm_medium=jetpack_social
##1 posts
3 repos
https://github.com/mgiay/CVE-2026-25589-25588-25243-23631-23479-REDIS
Discover how new Redis RCE exploit PoC code bypasses fixes for CVE-2026-25243 and CVE-2026-25589 across multiple Redis versions.
#Redis #Cybersecurity #RCE #Vulnerability #ExploitPoC
https://meterpreter.org/redis-rce-exploit-poc/?utm_source=mastodon&utm_medium=jetpack_social
##CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. https://radar.offseq.com/threat/cve-2026-16766-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-9e7c09567b0712f8 #OffSeq #infosec #perl #vuln
##CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: https://radar.offseq.com/threat/cve-2026-48021-cwe-295-improper-certificate-validation-in-med-united-epa4all-26e8e441c1a877ee #OffSeq #HealthcareSecurity #Vuln #CVE202648021
##🔴 CVE-2026-48021 - Critical (9.1)
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traff...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48021/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54342 - High (8.1)
In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnek...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54342/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##