##
Updated at UTC 2026-07-22T18:06:31.207852
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-65603 | 8.8 | 0.00% | 2 | 0 | 2026-07-22T17:16:59.437000 | The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege | |
| CVE-2026-49499 | 8.8 | 0.00% | 2 | 0 | 2026-07-22T17:16:56.350000 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generat | |
| CVE-2026-63764 | 9.3 | 0.28% | 1 | 0 | 2026-07-22T16:27:18.220000 | lmdeploy's OpenAI-compatible API server contains a server-side request forgery v | |
| CVE-2026-40712 | 9.1 | 0.00% | 2 | 0 | 2026-07-22T16:22:08.093000 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improp | |
| CVE-2026-46738 | 9.1 | 0.00% | 2 | 0 | 2026-07-22T16:22:08.093000 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improp | |
| CVE-2026-15900 | 9.6 | 0.22% | 1 | 0 | 2026-07-22T16:17:10.123000 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowe | |
| CVE-2026-8152 | None | 0.00% | 2 | 0 | 2026-07-22T15:31:27 | Unblu Spark contains an open redirect vulnerability that can be escalated to a D | |
| CVE-2026-50518 | 9.8 | 7.36% | 1 | 0 | 2026-07-22T15:15:16.043000 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacke | |
| CVE-2026-62561 | 7.8 | 0.14% | 2 | 0 | 2026-07-22T14:17:24.203000 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (compon | |
| CVE-2026-62549 | 9.6 | 0.30% | 1 | 0 | 2026-07-22T14:17:23.643000 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (compon | |
| CVE-2026-16232 | 0 | 0.00% | 2 | 1 | 2026-07-22T14:17:15.513000 | An authentication bypass vulnerability in the Check Point SmartConsole login pro | |
| CVE-2026-63048 | None | 0.23% | 2 | 0 | 2026-07-22T09:32:20 | The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary | |
| CVE-2026-3821 | 8.8 | 0.64% | 2 | 0 | 2026-07-22T09:32:20 | Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14 | |
| CVE-2026-15802 | 8.1 | 0.52% | 2 | 0 | 2026-07-22T06:31:33 | The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion | |
| CVE-2026-63030 | 9.8 | 38.60% | 22 | 65 | template | 2026-07-22T05:17:11.910000 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API ba |
| CVE-2026-60137 | 5.9 | 20.39% | 18 | 39 | 2026-07-22T05:17:11.750000 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does no | |
| CVE-2026-0770 | 9.8 | 54.50% | 8 | 6 | template | 2026-07-22T05:17:08.693000 | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere R |
| CVE-2021-27137 | 8.1 | 10.81% | 6 | 0 | 2026-07-22T05:17:07.330000 | An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An uns | |
| CVE-2026-65315 | 7.5 | 0.57% | 1 | 0 | 2026-07-22T00:32:45 | Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability i | |
| CVE-2026-65319 | 7.5 | 0.37% | 2 | 0 | 2026-07-22T00:32:44 | Feedbin (commit 739884a) contains an unauthenticated information disclosure vuln | |
| CVE-2026-65318 | 8.6 | 0.42% | 1 | 0 | 2026-07-22T00:32:44 | Verba RAG application version 2.1.3 contains an unauthenticated server-side requ | |
| CVE-2026-65317 | 8.6 | 0.48% | 1 | 0 | 2026-07-22T00:32:44 | Verba RAG application version 2.1.3 contains a server-side request forgery vulne | |
| CVE-2026-60926 | 7.2 | 0.50% | 1 | 0 | 2026-07-22T00:32:12 | Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business S | |
| CVE-2026-60785 | 8.1 | 0.38% | 1 | 0 | 2026-07-22T00:32:06 | Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (com | |
| CVE-2026-60799 | 7.1 | 0.30% | 1 | 0 | 2026-07-22T00:32:06 | Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business | |
| CVE-2026-60642 | 7.6 | 0.22% | 1 | 0 | 2026-07-22T00:32:00 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middlewar | |
| CVE-2026-60306 | 9.8 | 0.40% | 1 | 0 | 2026-07-22T00:31:40 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo | |
| CVE-2026-60297 | 9.8 | 0.49% | 1 | 0 | 2026-07-22T00:31:40 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo | |
| CVE-2026-60299 | 9.8 | 0.49% | 1 | 0 | 2026-07-22T00:31:40 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo | |
| CVE-2026-60298 | 9.8 | 0.49% | 1 | 0 | 2026-07-22T00:31:40 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo | |
| CVE-2026-60300 | 9.8 | 0.49% | 1 | 0 | 2026-07-22T00:31:32 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo | |
| CVE-2026-60656 | 8.8 | 0.45% | 1 | 0 | 2026-07-21T22:18:06.597000 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middlewar | |
| CVE-2026-60308 | 9.8 | 0.40% | 1 | 0 | 2026-07-21T22:17:33.490000 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo | |
| CVE-2026-60296 | 9.8 | 0.49% | 1 | 0 | 2026-07-21T22:17:32.160000 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo | |
| CVE-2026-60206 | 9.9 | 0.48% | 2 | 0 | 2026-07-21T22:17:21.953000 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware | |
| CVE-2026-16221 | 7.5 | 0.22% | 1 | 0 | 2026-07-21T22:08:29 | ### Impact `fast-uri` v4.1.0 and earlier do not treat a literal backslash (U+00 | |
| CVE-2026-8983 | None | 0.33% | 1 | 0 | 2026-07-21T21:32:53 | Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authen | |
| CVE-2026-65057 | 9.3 | 0.25% | 1 | 0 | 2026-07-21T21:32:53 | Keep (commit 91c75e0) contains a server-side request forgery vulnerability that | |
| CVE-2026-65056 | 8.2 | 0.23% | 1 | 0 | 2026-07-21T21:32:53 | mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that | |
| CVE-2026-64877 | 8.4 | 0.19% | 1 | 0 | 2026-07-21T21:32:46 | An authenticated non-admin user can exploit a SQL injection flaw in the ticketin | |
| CVE-2026-51027 | 9.9 | 0.34% | 1 | 0 | 2026-07-21T20:27:18.523000 | An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive inf | |
| CVE-2026-56750 | None | 0.00% | 2 | 0 | 2026-07-21T20:20:23 | The vulnerability is in the Remember-Me (gitea_incredible) token validation logi | |
| CVE-2026-55084 | 8.8 | 0.25% | 1 | 0 | 2026-07-21T20:17:02.277000 | DHIS2 is a flexible information system for data capture, management, validation, | |
| CVE-2026-16412 | 9.8 | 0.33% | 1 | 0 | 2026-07-21T20:17:00.157000 | Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these | |
| CVE-2026-62228 | 8.8 | 0.25% | 1 | 0 | 2026-07-21T19:58:20.277000 | OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node e | |
| CVE-2026-28307 | 9.1 | 0.34% | 1 | 0 | 2026-07-21T18:31:10 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allow | |
| CVE-2026-24232 | 4.3 | 0.14% | 1 | 0 | 2026-07-21T18:31:10 | NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause im | |
| CVE-2026-44508 | 0 | 0.00% | 1 | 0 | 2026-07-21T16:17:10.850000 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE- | |
| CVE-2026-8933 | 7.8 | 0.14% | 4 | 0 | 2026-07-21T15:30:51 | A local privilege escalation vulnerability exists in snap-confine, a set-capabil | |
| CVE-2026-13142 | 8.1 | 0.23% | 1 | 0 | 2026-07-21T15:30:34 | The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4. | |
| CVE-2026-47255 | 8.2 | 0.18% | 1 | 0 | 2026-07-21T15:16:35.860000 | AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail | |
| CVE-2026-1617 | 9.8 | 0.26% | 1 | 0 | 2026-07-21T12:33:43 | Improper neutralization of special elements used in an SQL command ('SQL injecti | |
| CVE-2026-13439 | 9.8 | 0.40% | 1 | 0 | 2026-07-21T06:31:24 | The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unaut | |
| CVE-2026-15899 | None | 0.22% | 1 | 0 | 2026-07-21T00:30:42 | Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 | |
| CVE-2026-15901 | None | 0.23% | 1 | 0 | 2026-07-21T00:30:42 | Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a rem | |
| CVE-2026-64625 | 9.8 | 0.35% | 2 | 0 | 2026-07-21T00:30:37 | AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync | |
| CVE-2026-56452 | 7.5 | 0.36% | 1 | 0 | 2026-07-21T00:30:28 | Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD i | |
| CVE-2026-64624 | 7.8 | 0.19% | 1 | 0 | 2026-07-20T22:17:18.600000 | FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as | |
| CVE-2026-63108 | 8.8 | 1.92% | 1 | 0 | 2026-07-20T22:17:17.797000 | Roo Code through 3.54.0 contains a command injection vulnerability in the auto-a | |
| CVE-2026-59873 | 7.5 | 0.36% | 1 | 0 | 2026-07-20T21:52:04 | ### Summary A **Decompression/parse DoS via unlimited input** vulnerability in ` | |
| CVE-2026-63766 | 9.8 | 1.39% | 1 | 0 | 2026-07-20T21:31:57 | GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability | |
| CVE-2026-63731 | 7.7 | 0.24% | 1 | 0 | 2026-07-20T21:31:57 | HyperDX before 2.31.0 contains a server-side request forgery vulnerability that | |
| CVE-2026-64619 | 7.5 | 0.20% | 1 | 0 | 2026-07-20T21:31:57 | FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateL | |
| CVE-2026-63767 | 9.8 | 0.74% | 1 | 0 | 2026-07-20T21:31:50 | ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticate | |
| CVE-2026-35198 | 9.0 | 0.23% | 1 | 0 | 2026-07-20T19:17:21.537000 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cr | |
| CVE-2026-57309 | 0 | 0.31% | 1 | 0 | 2026-07-20T16:17:05.670000 | A Blind SQL injection vulnerability has been identified in Windu CMS. A remote u | |
| CVE-2026-54910 | 7.7 | 0.31% | 1 | 0 | 2026-07-20T16:17:05.233000 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to ver | |
| CVE-2026-13577 | 8.2 | 0.26% | 3 | 0 | 2026-07-20T15:33:11 | Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRN | |
| CVE-2026-63831 | 8.8 | 0.24% | 1 | 0 | 2026-07-20T15:32:51 | In the Linux kernel, the following vulnerability has been resolved: mac802154: | |
| CVE-2026-63090 | 8.8 | 0.46% | 1 | 0 | 2026-07-20T15:32:15 | ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulner | |
| CVE-2026-63795 | 10.0 | 0.48% | 2 | 0 | 2026-07-20T15:16:46.193000 | In the Linux kernel, the following vulnerability has been resolved: 9p: avoid p | |
| CVE-2026-12484 | 7.8 | 0.20% | 3 | 0 | 2026-07-20T15:16:34.223000 | A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization | |
| CVE-2026-16242 | 9.4 | 0.37% | 1 | 0 | 2026-07-20T09:31:15 | A flaw was found in the Konnectivity proxy-server configuration for hosted contr | |
| CVE-2026-53359 | 8.8 | 0.12% | 2 | 6 | 2026-07-18T09:33:19 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F | |
| CVE-2026-13765 | 7.5 | 0.39% | 1 | 0 | 2026-07-17T19:17:12.640000 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin | |
| CVE-2026-62386 | 7.5 | 0.27% | 1 | 0 | 2026-07-17T15:44:29.553000 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT acc | |
| CVE-2026-11961 | 8.1 | 0.23% | 1 | 0 | 2026-07-17T15:32:27 | The User Registration & Membership WordPress plugin before 5.2.3 does not valid | |
| CVE-2026-13352 | 8.8 | 0.57% | 1 | 0 | 2026-07-17T06:31:06 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User | |
| CVE-2026-62227 | 7.7 | 0.23% | 1 | 0 | 2026-07-17T03:31:30 | OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulner | |
| CVE-2026-62241 | 9.1 | 0.39% | 1 | 0 | 2026-07-17T03:31:30 | clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT | |
| CVE-2026-62234 | 8.1 | 0.30% | 1 | 0 | 2026-07-17T03:31:30 | Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing | |
| CVE-2026-53412 | 9.8 | 0.51% | 1 | 0 | 2026-07-17T00:32:18 | Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client fo | |
| CVE-2026-39808 | 9.8 | 84.16% | 2 | 6 | template | 2026-07-16T18:32:24 | A improper neutralization of special elements used in an os command ('os command |
| CVE-2026-25089 | 9.8 | 36.13% | 2 | 2 | 2026-07-16T18:32:24 | A improper neutralization of special elements used in an os command ('os command | |
| CVE-2026-58644 | 9.8 | 1.47% | 4 | 0 | 2026-07-16T18:31:26 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut | |
| CVE-2026-15410 | 7.2 | 18.29% | 1 | 3 | 2026-07-16T05:16:18.470000 | Post-authentication improper control of generation of code ('Code Injection') vu | |
| CVE-2026-13385 | 0 | 0.10% | 1 | 0 | 2026-07-16T05:16:17.923000 | An Improper Validation of Integrity Check Value and Improper Certificate Validat | |
| CVE-2026-49488 | 6.5 | 0.73% | 1 | 0 | 2026-07-15T16:16:47.663000 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v | |
| CVE-2026-35152 | 8.8 | 3.49% | 1 | 0 | 2026-07-15T15:34:08 | A SQL Injection vulnerability exists in Apache Fineract's Report Execution API ( | |
| CVE-2026-57821 | 8.1 | 0.79% | 1 | 1 | 2026-07-15T15:34:08 | A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET | |
| CVE-2026-56287 | 8.1 | 0.70% | 1 | 0 | 2026-07-15T15:34:07 | A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client S | |
| CVE-2026-47992 | 7.2 | 19.92% | 1 | 0 | 2026-07-15T15:33:23.500000 | Adobe Commerce is affected by an Improper Neutralization of Special Elements use | |
| CVE-2026-42533 | 8.1 | 0.83% | 9 | 5 | 2026-07-15T15:33:14 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive | |
| CVE-2026-9770 | None | 0.22% | 1 | 0 | 2026-07-15T03:33:02 | Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key st | |
| CVE-2026-48332 | 7.7 | 11.94% | 1 | 0 | 2026-07-14T21:32:34 | ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability tha | |
| CVE-2026-48320 | 8.5 | 9.36% | 1 | 0 | 2026-07-14T21:32:33 | ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. | |
| CVE-2026-48284 | 9.6 | 7.94% | 1 | 0 | 2026-07-14T21:32:31 | ColdFusion is affected by an Improper Input Validation vulnerability that could | |
| CVE-2026-48356 | 9.6 | 18.88% | 1 | 0 | 2026-07-14T21:32:27 | Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type | |
| CVE-2026-47999 | 4.8 | 7.08% | 1 | 0 | 2026-07-14T21:32:26 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability | |
| CVE-2026-15409 | 10.0 | 16.27% | 2 | 5 | template | 2026-07-14T21:32:22 | A Server-side request forgery (SSRF) vulnerability has been identified in the SM |
| CVE-2026-47996 | 7.6 | 18.03% | 1 | 0 | 2026-07-14T21:32:22 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul | |
| CVE-2026-13001 | 9.8 | 1.08% | 1 | 2 | 2026-07-14T21:32:21 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary fi | |
| CVE-2026-58319 | 9.1 | 0.61% | 1 | 0 | 2026-07-14T18:33:00 | Certain Apache Doris FE HTTP REST administrative APIs were accessible without pr | |
| CVE-2026-50522 | 9.8 | 20.35% | 10 | 1 | 2026-07-14T18:32:11 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut | |
| CVE-2026-49176 | 7.8 | 0.24% | 1 | 1 | 2026-07-14T18:32:01 | Improper privilege management in Windows WalletService allows an authorized atta | |
| CVE-2026-56451 | 10.0 | 0.38% | 3 | 0 | 2026-07-14T12:31:16 | A vulnerability has been identified in Opcenter X (All versions < V2604). Affect | |
| CVE-2026-6875 | 0 | 0.51% | 9 | 2 | template | 2026-07-14T05:16:19.730000 | ServiceNow has addressed a remote code execution vulnerability that was identifi |
| CVE-2026-52824 | None | 0.00% | 2 | 0 | template | 2026-07-14T00:08:00 | ### Summary The official Kimai Docker image ships with `APP_SECRET=change_this_ |
| CVE-2026-57239 | 8.2 | 0.11% | 1 | 1 | 2026-07-09T14:31:41.157000 | The user-controllable executable files will be directly executed by high-privile | |
| CVE-2026-47198 | 8.5 | 0.40% | 1 | 0 | 2026-06-30T16:44:31 | ### Summary The checkout component improperly filters URL-writable properties, a | |
| CVE-2026-26241 | 9.1 | 0.32% | 2 | 0 | 2026-06-17T18:36:27 | A buffer overflow vulnerability has been reported to affect File Station 5. The | |
| CVE-2026-26239 | 8.1 | 0.29% | 2 | 0 | 2026-06-17T18:35:20 | A buffer overflow vulnerability has been reported to affect File Station 5. If a | |
| CVE-2026-26240 | 9.1 | 0.32% | 2 | 0 | 2026-06-17T13:20:12.183000 | A buffer overflow vulnerability has been reported to affect File Station 5. The | |
| CVE-2026-9039 | 0 | 0.18% | 1 | 0 | 2026-06-17T11:04:45.947000 | A configuration weakness in the device’s remote management service allows an aut | |
| CVE-2026-3949 | 3.3 | 0.12% | 1 | 1 | 2026-06-17T10:44:29.823000 | A vulnerability was determined in strukturag libheif up to 1.21.2. This affects | |
| CVE-2026-42980 | 7.8 | 5.66% | 2 | 1 | 2026-06-09T18:30:53 | Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authori | |
| CVE-2026-4986 | 5.3 | 0.20% | 2 | 1 | 2026-06-09T15:33:16 | The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity o | |
| CVE-2026-0257 | 9.1 | 86.68% | 13 | 8 | template | 2026-06-09T12:32:02 | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of |
| CVE-2026-45578 | 8.8 | 0.32% | 1 | 0 | 2026-06-09T10:27:14 | ## Summary **Type:** Classic shell-metacharacter injection. The YPTSocket notif | |
| CVE-2026-47413 | 9.6 | 0.21% | 1 | 0 | 2026-06-01T14:23:41 | ## Summary **Type:** Privilege escalation / cross-tenant member injection. The | |
| CVE-2026-40622 | 7.5 | 0.17% | 1 | 0 | 2026-05-26T18:31:40 | NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability | |
| CVE-2026-46415 | 8.2 | 0.16% | 1 | 0 | 2026-05-19T20:29:18 | ### Impact Caddy Defender used `r.RemoteAddr` when evaluating whether a request | |
| CVE-2026-46412 | 10.0 | 0.42% | 1 | 0 | 2026-05-19T20:28:08 | ## Summary Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compr | |
| CVE-2026-45713 | 7.5 | 0.32% | 1 | 0 | 2026-05-19T15:54:13 | ### Summary The Mailpit SMTP server has a Server.MaxSize int field that controls | |
| CVE-2026-45270 | 8.7 | 0.21% | 1 | 0 | 2026-05-18T16:23:35 | ## Summary The `Pages` backend module registers the `html_purify` validation ru | |
| CVE-2026-5987 | 4.7 | 0.24% | 1 | 0 | 2026-04-10T00:30:38 | A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d | |
| CVE-2026-64600 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-44421 | 0 | 0.42% | 2 | 0 | N/A | ||
| CVE-2026-63133 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-63134 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-63177 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-29059 | 0 | 2.58% | 1 | 1 | template | N/A | |
| CVE-2026-58443 | 0 | 0.00% | 3 | 0 | N/A | ||
| CVE-2026-56819 | 0 | 0.63% | 1 | 0 | N/A | ||
| CVE-2026-50055 | 0 | 0.00% | 1 | 1 | N/A | ||
| CVE-2026-53595 | 0 | 0.30% | 2 | 1 | N/A | ||
| CVE-2026-53591 | 0 | 0.21% | 1 | 0 | N/A | ||
| CVE-2026-55544 | 0 | 0.18% | 1 | 0 | N/A | ||
| CVE-2026-47129 | 0 | 0.22% | 1 | 0 | N/A | ||
| CVE-2026-63429 | 0 | 0.30% | 1 | 0 | N/A | ||
| CVE-2026-14266 | 0 | 0.00% | 1 | 2 | N/A | ||
| CVE-2026-42566 | 0 | 0.28% | 2 | 0 | N/A | ||
| CVE-2026-44359 | 0 | 1.00% | 2 | 0 | N/A |
updated 2026-07-22T17:16:59.437000
2 posts
CVE-2026-65603: HIGH severity privilege escalation in Grav Login plugin (<=3.8.11). Low-priv users can gain super-admin & RCE. Patch to v3.8.12 ASAP! https://radar.offseq.com/threat/cve-2026-65603-improper-privilege-management-in-getgrav-grav-12319d7ebec99910 #OffSeq #GravCMS #Vuln #PrivilegeEscalation
##CVE-2026-65603: HIGH severity privilege escalation in Grav Login plugin (<=3.8.11). Low-priv users can gain super-admin & RCE. Patch to v3.8.12 ASAP! https://radar.offseq.com/threat/cve-2026-65603-improper-privilege-management-in-getgrav-grav-12319d7ebec99910 #OffSeq #GravCMS #Vuln #PrivilegeEscalation
##updated 2026-07-22T17:16:56.350000
2 posts
🟠 CVE-2026-49499 - High (8.8)
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49499/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-49499 - High (8.8)
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49499/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-22T16:27:18.220000
1 posts
🔴 CVE-2026-63764 - Critical (9.3)
lmdeploy's OpenAI-compatible API server contains a server-side request forgery vulnerability that allows unauthenticated attackers to access internal services and cloud metadata endpoints by supplying a crafted image_url that redirects to internal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63764/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-22T16:22:08.093000
2 posts
🔴 CVE-2026-40712 - Critical (9.1)
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40712/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-40712 - Critical (9.1)
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40712/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-22T16:22:08.093000
2 posts
🔴 CVE-2026-46738 - Critical (9.1)
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46738/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-46738 - Critical (9.1)
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46738/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-22T16:17:10.123000
1 posts
CVE-2026-15900: CRITICAL use-after-free in Chrome (Android <150.0.7871.128). Exploitable via malicious HTML, enabling sandbox escape & elevated code execution. Patch ASAP: update Chrome for Android. https://radar.offseq.com/threat/cve-2026-15900-use-after-free-in-google-chrome-7d985b12f49a9534 #OffSeq #CVE202615900 #Chrome #Android
##updated 2026-07-22T15:31:27
2 posts
Unblu Spark suffers a CRITICAL open redirect (CVE-2026-8152) leading to DOM XSS in siteEmbeddedSetup=true config. Attacker can access cookies & APIs of host app. No patch yet — disable this config ASAP. https://radar.offseq.com/threat/cve-2026-8152-cwe-601-url-redirection-to-untrusted-site-open-redirect-in-unblu-inc-unblu-spark-7d13478f5c7eb4ac #OffSeq #XSS #Vulnerability #InfoSec
##Unblu Spark suffers a CRITICAL open redirect (CVE-2026-8152) leading to DOM XSS in siteEmbeddedSetup=true config. Attacker can access cookies & APIs of host app. No patch yet — disable this config ASAP. https://radar.offseq.com/threat/cve-2026-8152-cwe-601-url-redirection-to-untrusted-site-open-redirect-in-unblu-inc-unblu-spark-7d13478f5c7eb4ac #OffSeq #XSS #Vulnerability #InfoSec
##updated 2026-07-22T15:15:16.043000
1 posts
📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135
Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124
CISA KEVs:
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43
Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310
Top EPSS Score:
- CVE-2026-50522 - 20.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-47992 - 19.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47992)
- CVE-2026-47996 - 18.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47996)
- CVE-2026-48356 - 17.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48356)
- CVE-2026-48332 - 11.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48332)
- CVE-2026-48320 - 9.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48320)
- CVE-2026-63030 - 8.95 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-48284 - 7.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48284)
- CVE-2026-50518 - 7.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50518)
- CVE-2026-47999 - 7.08 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47999)
updated 2026-07-22T14:17:24.203000
2 posts
🟠 CVE-2026-62561 - High (7.8)
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62561/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62561 - High (7.8)
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62561/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-22T14:17:23.643000
1 posts
CVE-2026-62549 (CRITICAL, CVSS 9.6) in Oracle HRMS (UK) 12.2.3 – 12.2.15 lets low-priv attackers compromise critical data & impact other Oracle apps. Patch status unclear — check https://radar.offseq.com/threat/cve-2026-62549-easily-exploitable-vulnerability-allows-low-privileged-attacker-with-network-access-via-2a35d285e3bf086c & restrict network access. #OffSeq #Oracle #CVE2026_62549 #Vuln
##updated 2026-07-22T14:17:15.513000
2 posts
1 repos
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
Check Point confirms CVE-2026-16232, a SmartConsole authentication bypass, is exploited in the wild. Apply the July 22 jumbo hotfix now.
#CheckPoint #CVE202616232 #SmartConsole #AuthBypass #ExploitedInTheWild #InfoSec
##Check Point confirms CVE-2026-16232, a SmartConsole authentication bypass, is exploited in the wild. Apply the July 22 jumbo hotfix now.
#CheckPoint #CVE202616232 #SmartConsole #AuthBypass #ExploitedInTheWild #InfoSec
##updated 2026-07-22T09:32:20
2 posts
CVE-2026-63048 (CRITICAL, CVSS 9.4): joomlack.fr Page Builder CK for Joomla (v1.0.0 – 3.6.2) lets authenticated users upload arbitrary files, enabling RCE. No patch — restrict usage & monitor for updates. https://radar.offseq.com/threat/cve-2026-63048-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-joomlackfr-page-builder-ck-3921dbf365864886 #OffSeq #Joomla #RCE #Vuln
##CVE-2026-63048 (CRITICAL, CVSS 9.4): joomlack.fr Page Builder CK for Joomla (v1.0.0 – 3.6.2) lets authenticated users upload arbitrary files, enabling RCE. No patch — restrict usage & monitor for updates. https://radar.offseq.com/threat/cve-2026-63048-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-joomlackfr-page-builder-ck-3921dbf365864886 #OffSeq #Joomla #RCE #Vuln
##updated 2026-07-22T09:32:20
2 posts
🟠 CVE-2026-3821 - High (8.8)
Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI.
An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3821/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-3821 - High (8.8)
Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI.
An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3821/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-22T06:31:33
2 posts
🟠 CVE-2026-15802 - High (8.1)
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15802/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-15802 - High (8.1)
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15802/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-22T05:17:11.910000
22 posts
65 repos
https://github.com/ekomsSavior/wp2shell
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/mcipekci/wp2shell
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t
https://github.com/InstaWP/wp2shell-scan
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/Icex0/wp2shell-poc
https://github.com/Ch4120N/CVE-2026-63030
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/securelayer7/WordPresShell
https://github.com/dinosn/wp2shell-lab
https://github.com/ebrasha/abdal-cve-2026-63030
https://github.com/gbrsh/CVE-2026-63030
https://github.com/wn-iqbal/wp2shell
https://github.com/ananay/wp2shell-lab
https://github.com/mrx-arafat/CVE-2026-63030-POC
https://github.com/ChiefYoru/CVE-2026-63030_PoC
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/Crypto-Cat/wp2shell
https://github.com/4B3R4M4-607D/CVE-2026-63030-POC
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/attackercan/wp2shell-poc2
https://github.com/ASYquan/wp2shell-cf-WAF-bypass
https://github.com/0xWhoknows/wp2shell
https://github.com/0xBlackash/CVE-2026-63030
https://github.com/mhtsec/CVE-2026-63030
https://github.com/Lutfifakee-Project/wp2shell
https://github.com/zeroc00I/CVE-2026-63030
https://github.com/0xsha/wp2shell
https://github.com/NULL200OK/WP2Shell
https://github.com/c0gnit00/Wp2Shell
https://github.com/fullhunt/wp2shell-scan
https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030
https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/47Cid/wp2shell-lab
https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/raphy76/wp2shell-poc-fulljs
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/0xh7ml/CVE-2026-63030
https://github.com/yoerivegt/wp2shell-poc
https://github.com/mverschu/CVE-2026-63030
https://github.com/TomorrowX6/CVE-2026-63030-poc
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/h4cd0c/wp2shell
https://github.com/kulichr/wp2shell
https://github.com/bahartanir/wp2shell-scanner
https://github.com/vulnquest58/PressVector
https://github.com/CybersecSpirit/CVE-2026-63030
https://github.com/0xjessie21/wp2shell-checker
https://github.com/4minx/CVE-2026-63030
https://github.com/ikow/wp2shell
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/administrator-01001/CVE-2026-63030
https://github.com/Colere-Sys/wp2shell-poc
🔵 THREAT INTELLIGENCE
Critical wp2shell WordPress flaws exploited to install webshells
Vulnerability | CRITICAL
CVEs: CVE-2026-60137, CVE-2026-63030
Hackers are exploiting the 'wp2shell' critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent...
Full analysis:
https://www.yazoul.net/news/article/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells
📰 CISA Adds Four Actively Exploited Flaws in DD-WRT, Langflow, WordPress
CISA adds 4 actively exploited vulnerabilities to its KEV catalog: CVE-2021-27137 (DD-WRT), CVE-2026-0770 (Langflow), and CVE-2026-63030 & CVE-2026-60137 (WordPress). Patching is urgent. #CISA #KEV #Vulnerability #PatchNow #WordPress
🌐 cyber[.]netsecops[.]io
##⚠️ CRITICAL THREAT: CVE-2026-63030 in WordPress Core enables SQL injection and RCE via interpretation conflicts. Active exploitation is confirmed! Get the forensic detection queries and hardening strategies needed to secure your web assets now. https://thecybermind.co/9k20
##⚠️ CRITICAL THREAT: CVE-2026-63030 in WordPress Core enables SQL injection and RCE via interpretation conflicts. Active exploitation is confirmed! Get the forensic detection queries and hardening strategies needed to secure your web assets now. https://thecybermind.co/9k20
##WordPressに認証不要でコード実行される緊急の脆弱性 即時更新を呼び掛け
https://www.itmedia.co.jp/news/articles/2607/21/news084.html
WordPressの開発チームは7月17日(米国時間)、深刻な2件の脆弱性を修正したセキュリティリリース「WordPress 7.0.2」を公開した。
1件は深刻度「Critical」(緊急)と評価された認証不要のリモートコード実行(RCE)の脆弱性(CVE-2026-63030)で、REST APIのバッチ処理エンドポイントを悪用されると、ログインやユーザーの操作なしに攻撃者が任意のコードを実行できる恐れがある。
もう1件は「High」(高)と評価されたSQLインジェクションの脆弱性(CVE-2026-60137)で、細工した入力によってデータベースへのクエリを改ざんされる可能性がある。なお、RCEはこのSQLインジェクションに起因しているという。
Critical wp2shell WordPress flaws exploited to install webshells
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy...
🔗️ [Bleepingcomputer] https://link.is.it/KxezNe
##🚨 [CISA-2026:0721] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2021-27137 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-27137)
- Name: DD-WRT Stack-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: DD-WRT
- Product: DD-WRT
- Notes: This vulnerability affects a common open-source component, third-party library, proprietary implementation, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://svn.dd-wrt.com/changeset/45724 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-27137
⚠️ CVE-2026-0770 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0770)
- Name: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Langflow
- Product: Langflow
- Notes: https://github.com/langflow-ai/langflow/releases/tag/v1.9.0 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-0770
⚠️ CVE-2026-60137 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- Name: WordPress Core SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-60137
⚠️ CVE-2026-63030 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- Name: WordPress Core Interpretation Conflict Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-63030
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260721 #cisa20260721 #cve_2021_27137 #cve_2026_0770 #cve_2026_60137 #cve_2026_63030 #cve202127137 #cve20260770 #cve202660137 #cve202663030
##CISA added four flaws to its KEV catalog, including WordPress RCE (CVE-2026-63030) and Langflow RCE (CVE-2026-0770). All are exploited in the wild.
##CVE ID: CVE-2026-63030
Vendor: WordPress
Product: Core
Date Added: 2026-07-21
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-63030
- Webserverlogs
`zgrep /batch/v1 *.log *.log.gz | egrep '45.79.167[.]238|34.81.132[.]62|79.177.131[.]206|15.157.135[.]170|94.100.52[.]128|172.235.128[.]52'`
- Wordpress-Verzeichnis
`find . -type f -print0 | xargs -0 md5sum | egrep '2a1410d8e2a8337ac2171cedea8c0fdc47c647a0|58eca847e9eae9e6b08cc211f1559817b71bc4cc|ebea44890f434d5d67ede22009a3f4bb5cac33f8|d9a220c8039f1c4d72cae7ccb8b3a33dec8815be|e9756e2338f84746007235e4cab7a70d5b3ca47f'`
https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137
##Broadcom has new advisories for two medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
CISA KEV updates:
- CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability https://www.cve.org/CVERecord?id=CVE-2021-27137
- CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-0770
- CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-63030
- CVE-2026-60137L WordPress Core SQL Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-60137 #CISA #WordPress #vulnerability #infosec
##wp2shell, a WordPress Core RCE chain (CVE-2026-63030, CVE-2026-60137), is exploited in the wild. Public PoC code is out. Patch WordPress now.
#wp2shell #WordPress #RCE #CVE202663030 #CVE202660137 #InfoSec #WebSecurity #PatchNow
##🤖 WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
📝 Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulner...
https://isc.sans.edu/diary/rss/33168
📰 SANS Internet Storm Center, InfoCON: green
##WordPress Exploitation Underway (CVE-2026-63030) https://isc.sans.edu/diary/33168
##W cyberpodziemiu opublikowano exploity wykorzystujące krytyczne luki RCE typu „wp2shell” występujące przed uwierzytelnieniem, które dotyczą jądra WordPressa. W wersjach WordPressa 6.9.5 i 7.0.2 naprawiono cały łańcuch ataków typu wp2shell. Atak typu wp2shell składa się z dwóch luk – CVE-2026-63030 i CVE-2026-60137, które można połączyć w celu zdalnego wykonania kodu przed uwierzytelnieniem w instalacjach WordPressa w wersjach 6.9. i 7.0.
##New.
Picus: CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained https://www.picussecurity.com/resource/blog/cve-2026-63030-and-cve-2026-60137-wp2shell-wordpress-rce-explained #infosec #vulnerability #WordPress
##⚠️ 📢 #Sicherheitswarnung: WordPress – Schwachstellen erlauben "Remote Code Execution"
Am 17. Juli 2026 wurde seitens #Wordpress eine Aktualisierung bekannt gegeben, die zwei #Schwachstellen in der Wordpress-Software behebt.
❗️ Die beiden Schwachstellen CVE-2026-60137 und CVE-2026-63030 ermöglichen einem nicht authentifizierten, entfernten Angreifer Code zur Ausführung zu bringen.
Mehr dazu hier: 👉️ https://www.bsi.bund.de/dok/1203360
##⚠️ Si vous administrez un site WordPress ou si vous connaissez quelqu’un qui en gère un faites passer l’information.
Une vulnérabilité critique baptisée WP2Shell touche directement le cœur de WordPress.
Cette fois, il ne s’agit pas d’un plugin abandonné ou d’un thème douteux : une installation standard peut être attaquée à distance, sans compte utilisateur, sans mot de passe et sans authentification préalable.
WP2Shell combine deux failles, CVE-2026-60137 et CVE-2026-63030, permettant à un attaquant d’exécuter du code sur le serveur et donc, potentiellement, de prendre le contrôle du site.
-> Des tentatives d’exploitation et des compromissions ont déjà été observées dans la nature.
Sont notamment concernées les versions :
➡️ WordPress 6.9.0 à 6.9.4
➡️ WordPress 7.0.0 à 7.0.1
Les correctifs sont disponibles dans les versions 6.9.5 et 7.0.2. WordPress a activé des mises à jour automatiques forcées en raison de la gravité de la faille, mais il ne faut pas supposer qu’elles ont forcément fonctionné : elles peuvent avoir été désactivées, bloquées par l’hébergeur ou empêchées par une configuration particulière.
À faire rapidement:
✅ vérifier la version réellement installée ;
✅ mettre WordPress à jour vers 6.9.5 ou 7.0.2 au minimum ;
✅ confirmer que la mise à jour s’est correctement terminée ;
✅ vérifier les comptes administrateurs, les fichiers récemment modifiés et les journaux du serveur ;
✅ rechercher d’éventuels fichiers PHP, plugins ou utilisateurs inconnus ;
✅ s’assurer que des sauvegardes propres et récentes sont disponibles.
En attendant la mise à jour, l’accès anonyme aux routes REST suivantes peut également être bloqué au niveau du WAF ou du serveur web :
/wp-json/batch/v1
?rest_route=/batch/v1
Point important : installer le correctif empêche une nouvelle exploitation, mais ne supprime pas une éventuelle compromission déjà présente. Si le site est resté exposé, une vérification minimale est donc nécessaire, même après la mise à jour.
Un site WordPress « qui fonctionne encore » n’est pas nécessairement un site sain : les attaquants cherchent souvent à rester discrets pour installer une porte dérobée, détourner le trafic, diffuser du spam ou préparer d’autres attaques...
🔍 wp2shell.com , pour vérifier si votre site est vulnérable.
Dans les news:
"WP2Shell - La faille qui permet de pirater WordPress sans aucun plugin"
👇
https://korben.info/wp2shell-exploits-prise-controle-wordpress.html
⚠️Alerte CERT-FR⚠️
Les vulnérabilités CVE-2026-60137 et CVE-2026-63030 affectent WordPress et permettent une exécution de code arbitraire à distance non authentifiée.
Une preuve de concept est disponible.
wp2shell (CVE-2026-63030, CVE-2026-60137) allows unauth RCE in WordPress core (HIGH severity). Active exploitation reported. Patch to 6.9.5, 7.0.2, or 6.8.6. Block REST API batch endpoint if needed. Details: https://radar.offseq.com/threat/wp2shell-critical-wordpress-core-vulnerability-enabling-unauthenticated-rce-detection-and-mitigation-fccca7b8b6429718 #OffSeq #WordPress #RCE #Vulnerability
##📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135
Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124
CISA KEVs:
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43
Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310
Top EPSS Score:
- CVE-2026-50522 - 20.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-47992 - 19.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47992)
- CVE-2026-47996 - 18.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47996)
- CVE-2026-48356 - 17.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48356)
- CVE-2026-48332 - 11.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48332)
- CVE-2026-48320 - 9.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48320)
- CVE-2026-63030 - 8.95 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-48284 - 7.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48284)
- CVE-2026-50518 - 7.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50518)
- CVE-2026-47999 - 7.08 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47999)
wp2shell: a defender’s guide (CVE-2026-63030 + CVE-2026-60137) with a list of forensic artifacts, a compromise scanner WordPress plugin and a free Chrome/Edge/Firefox browser extension to in-browser check if a website has been patched. https://research.eye.security/wp2shell-defenders-guide/
##updated 2026-07-22T05:17:11.750000
18 posts
39 repos
https://github.com/ekomsSavior/wp2shell
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/mcipekci/wp2shell
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/ebrasha/abdal-cve-2026-60137
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/Icex0/wp2shell-poc
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/securelayer7/WordPresShell
https://github.com/dinosn/wp2shell-lab
https://github.com/wn-iqbal/wp2shell
https://github.com/ananay/wp2shell-lab
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/Crypto-Cat/wp2shell
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/0xWhoknows/wp2shell
https://github.com/0xsha/wp2shell
https://github.com/NULL200OK/WP2Shell
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/47Cid/wp2shell-lab
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/yoerivegt/wp2shell-poc
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/h4cd0c/wp2shell
https://github.com/kulichr/wp2shell
https://github.com/bahartanir/wp2shell-scanner
https://github.com/vulnquest58/PressVector
https://github.com/0xjessie21/wp2shell-checker
https://github.com/ikow/wp2shell
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
🔵 THREAT INTELLIGENCE
Critical wp2shell WordPress flaws exploited to install webshells
Vulnerability | CRITICAL
CVEs: CVE-2026-60137, CVE-2026-63030
Hackers are exploiting the 'wp2shell' critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent...
Full analysis:
https://www.yazoul.net/news/article/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells
📰 CISA Adds Four Actively Exploited Flaws in DD-WRT, Langflow, WordPress
CISA adds 4 actively exploited vulnerabilities to its KEV catalog: CVE-2021-27137 (DD-WRT), CVE-2026-0770 (Langflow), and CVE-2026-63030 & CVE-2026-60137 (WordPress). Patching is urgent. #CISA #KEV #Vulnerability #PatchNow #WordPress
🌐 cyber[.]netsecops[.]io
##⚠️ THREAT ALERT: CVE-2026-60137 in WordPress Core enables unauthenticated SQL injection that chains for remote code execution! Active exploitation is confirmed. Get the forensic detection queries and hardening strategies you need to protect your web assets now. https://thecybermind.co/12b8
##⚠️ THREAT ALERT: CVE-2026-60137 in WordPress Core enables unauthenticated SQL injection that chains for remote code execution! Active exploitation is confirmed. Get the forensic detection queries and hardening strategies you need to protect your web assets now. https://thecybermind.co/12b8
##WordPressに認証不要でコード実行される緊急の脆弱性 即時更新を呼び掛け
https://www.itmedia.co.jp/news/articles/2607/21/news084.html
WordPressの開発チームは7月17日(米国時間)、深刻な2件の脆弱性を修正したセキュリティリリース「WordPress 7.0.2」を公開した。
1件は深刻度「Critical」(緊急)と評価された認証不要のリモートコード実行(RCE)の脆弱性(CVE-2026-63030)で、REST APIのバッチ処理エンドポイントを悪用されると、ログインやユーザーの操作なしに攻撃者が任意のコードを実行できる恐れがある。
もう1件は「High」(高)と評価されたSQLインジェクションの脆弱性(CVE-2026-60137)で、細工した入力によってデータベースへのクエリを改ざんされる可能性がある。なお、RCEはこのSQLインジェクションに起因しているという。
Critical wp2shell WordPress flaws exploited to install webshells
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy...
🔗️ [Bleepingcomputer] https://link.is.it/KxezNe
##🚨 [CISA-2026:0721] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2021-27137 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-27137)
- Name: DD-WRT Stack-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: DD-WRT
- Product: DD-WRT
- Notes: This vulnerability affects a common open-source component, third-party library, proprietary implementation, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://svn.dd-wrt.com/changeset/45724 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-27137
⚠️ CVE-2026-0770 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0770)
- Name: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Langflow
- Product: Langflow
- Notes: https://github.com/langflow-ai/langflow/releases/tag/v1.9.0 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-0770
⚠️ CVE-2026-60137 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- Name: WordPress Core SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-60137
⚠️ CVE-2026-63030 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- Name: WordPress Core Interpretation Conflict Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-63030
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260721 #cisa20260721 #cve_2021_27137 #cve_2026_0770 #cve_2026_60137 #cve_2026_63030 #cve202127137 #cve20260770 #cve202660137 #cve202663030
##- Webserverlogs
`zgrep /batch/v1 *.log *.log.gz | egrep '45.79.167[.]238|34.81.132[.]62|79.177.131[.]206|15.157.135[.]170|94.100.52[.]128|172.235.128[.]52'`
- Wordpress-Verzeichnis
`find . -type f -print0 | xargs -0 md5sum | egrep '2a1410d8e2a8337ac2171cedea8c0fdc47c647a0|58eca847e9eae9e6b08cc211f1559817b71bc4cc|ebea44890f434d5d67ede22009a3f4bb5cac33f8|d9a220c8039f1c4d72cae7ccb8b3a33dec8815be|e9756e2338f84746007235e4cab7a70d5b3ca47f'`
https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137
##CVE ID: CVE-2026-60137
Vendor: WordPress
Product: Core
Date Added: 2026-07-21
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60137
Broadcom has new advisories for two medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
CISA KEV updates:
- CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability https://www.cve.org/CVERecord?id=CVE-2021-27137
- CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-0770
- CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-63030
- CVE-2026-60137L WordPress Core SQL Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-60137 #CISA #WordPress #vulnerability #infosec
##wp2shell, a WordPress Core RCE chain (CVE-2026-63030, CVE-2026-60137), is exploited in the wild. Public PoC code is out. Patch WordPress now.
#wp2shell #WordPress #RCE #CVE202663030 #CVE202660137 #InfoSec #WebSecurity #PatchNow
##W cyberpodziemiu opublikowano exploity wykorzystujące krytyczne luki RCE typu „wp2shell” występujące przed uwierzytelnieniem, które dotyczą jądra WordPressa. W wersjach WordPressa 6.9.5 i 7.0.2 naprawiono cały łańcuch ataków typu wp2shell. Atak typu wp2shell składa się z dwóch luk – CVE-2026-63030 i CVE-2026-60137, które można połączyć w celu zdalnego wykonania kodu przed uwierzytelnieniem w instalacjach WordPressa w wersjach 6.9. i 7.0.
##New.
Picus: CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained https://www.picussecurity.com/resource/blog/cve-2026-63030-and-cve-2026-60137-wp2shell-wordpress-rce-explained #infosec #vulnerability #WordPress
##⚠️ 📢 #Sicherheitswarnung: WordPress – Schwachstellen erlauben "Remote Code Execution"
Am 17. Juli 2026 wurde seitens #Wordpress eine Aktualisierung bekannt gegeben, die zwei #Schwachstellen in der Wordpress-Software behebt.
❗️ Die beiden Schwachstellen CVE-2026-60137 und CVE-2026-63030 ermöglichen einem nicht authentifizierten, entfernten Angreifer Code zur Ausführung zu bringen.
Mehr dazu hier: 👉️ https://www.bsi.bund.de/dok/1203360
##⚠️ Si vous administrez un site WordPress ou si vous connaissez quelqu’un qui en gère un faites passer l’information.
Une vulnérabilité critique baptisée WP2Shell touche directement le cœur de WordPress.
Cette fois, il ne s’agit pas d’un plugin abandonné ou d’un thème douteux : une installation standard peut être attaquée à distance, sans compte utilisateur, sans mot de passe et sans authentification préalable.
WP2Shell combine deux failles, CVE-2026-60137 et CVE-2026-63030, permettant à un attaquant d’exécuter du code sur le serveur et donc, potentiellement, de prendre le contrôle du site.
-> Des tentatives d’exploitation et des compromissions ont déjà été observées dans la nature.
Sont notamment concernées les versions :
➡️ WordPress 6.9.0 à 6.9.4
➡️ WordPress 7.0.0 à 7.0.1
Les correctifs sont disponibles dans les versions 6.9.5 et 7.0.2. WordPress a activé des mises à jour automatiques forcées en raison de la gravité de la faille, mais il ne faut pas supposer qu’elles ont forcément fonctionné : elles peuvent avoir été désactivées, bloquées par l’hébergeur ou empêchées par une configuration particulière.
À faire rapidement:
✅ vérifier la version réellement installée ;
✅ mettre WordPress à jour vers 6.9.5 ou 7.0.2 au minimum ;
✅ confirmer que la mise à jour s’est correctement terminée ;
✅ vérifier les comptes administrateurs, les fichiers récemment modifiés et les journaux du serveur ;
✅ rechercher d’éventuels fichiers PHP, plugins ou utilisateurs inconnus ;
✅ s’assurer que des sauvegardes propres et récentes sont disponibles.
En attendant la mise à jour, l’accès anonyme aux routes REST suivantes peut également être bloqué au niveau du WAF ou du serveur web :
/wp-json/batch/v1
?rest_route=/batch/v1
Point important : installer le correctif empêche une nouvelle exploitation, mais ne supprime pas une éventuelle compromission déjà présente. Si le site est resté exposé, une vérification minimale est donc nécessaire, même après la mise à jour.
Un site WordPress « qui fonctionne encore » n’est pas nécessairement un site sain : les attaquants cherchent souvent à rester discrets pour installer une porte dérobée, détourner le trafic, diffuser du spam ou préparer d’autres attaques...
🔍 wp2shell.com , pour vérifier si votre site est vulnérable.
Dans les news:
"WP2Shell - La faille qui permet de pirater WordPress sans aucun plugin"
👇
https://korben.info/wp2shell-exploits-prise-controle-wordpress.html
⚠️Alerte CERT-FR⚠️
Les vulnérabilités CVE-2026-60137 et CVE-2026-63030 affectent WordPress et permettent une exécution de code arbitraire à distance non authentifiée.
Une preuve de concept est disponible.
wp2shell (CVE-2026-63030, CVE-2026-60137) allows unauth RCE in WordPress core (HIGH severity). Active exploitation reported. Patch to 6.9.5, 7.0.2, or 6.8.6. Block REST API batch endpoint if needed. Details: https://radar.offseq.com/threat/wp2shell-critical-wordpress-core-vulnerability-enabling-unauthenticated-rce-detection-and-mitigation-fccca7b8b6429718 #OffSeq #WordPress #RCE #Vulnerability
##wp2shell: a defender’s guide (CVE-2026-63030 + CVE-2026-60137) with a list of forensic artifacts, a compromise scanner WordPress plugin and a free Chrome/Edge/Firefox browser extension to in-browser check if a website has been patched. https://research.eye.security/wp2shell-defenders-guide/
##updated 2026-07-22T05:17:08.693000
8 posts
6 repos
https://github.com/Ez4rd1x1/CVE-2026-0770
https://github.com/affix/CVE-2026-0770-PoC
https://github.com/0xgh057r3c0n/CVE-2026-0770
https://github.com/0xBlackash/CVE-2026-0770
📰 CISA Adds Four Actively Exploited Flaws in DD-WRT, Langflow, WordPress
CISA adds 4 actively exploited vulnerabilities to its KEV catalog: CVE-2021-27137 (DD-WRT), CVE-2026-0770 (Langflow), and CVE-2026-63030 & CVE-2026-60137 (WordPress). Patching is urgent. #CISA #KEV #Vulnerability #PatchNow #WordPress
🌐 cyber[.]netsecops[.]io
##CISA Targets Langflow Flaw in Urgent Patch Directive
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent patch directive for a vulnerability in the Langflow visual framework, used to build AI agents, after recording over 220 exploitation attempts in just one day. This critical flaw, tracked as CVE-2026-0770, has already been exploited by multiple attackers, prompting…
#Cve20260770 #Langflow #AiAgents #KnownExploitedVulnerabilities #Kev
##⚠️ CRITICAL THREAT: CVE-2026-0770 in Langflow enables remote code execution via untrusted control sphere inclusion. Active exploitation is confirmed. Get the forensic detection and input hardening strategies required to secure your AI pipelines today. https://thecybermind.co/aigl
##⚠️ CRITICAL THREAT: CVE-2026-0770 in Langflow enables remote code execution via untrusted control sphere inclusion. Active exploitation is confirmed. Get the forensic detection and input hardening strategies required to secure your AI pipelines today. https://thecybermind.co/aigl
##🚨 [CISA-2026:0721] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2021-27137 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-27137)
- Name: DD-WRT Stack-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: DD-WRT
- Product: DD-WRT
- Notes: This vulnerability affects a common open-source component, third-party library, proprietary implementation, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://svn.dd-wrt.com/changeset/45724 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-27137
⚠️ CVE-2026-0770 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0770)
- Name: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Langflow
- Product: Langflow
- Notes: https://github.com/langflow-ai/langflow/releases/tag/v1.9.0 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-0770
⚠️ CVE-2026-60137 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- Name: WordPress Core SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-60137
⚠️ CVE-2026-63030 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- Name: WordPress Core Interpretation Conflict Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-63030
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260721 #cisa20260721 #cve_2021_27137 #cve_2026_0770 #cve_2026_60137 #cve_2026_63030 #cve202127137 #cve20260770 #cve202660137 #cve202663030
##CISA added four flaws to its KEV catalog, including WordPress RCE (CVE-2026-63030) and Langflow RCE (CVE-2026-0770). All are exploited in the wild.
##CVE ID: CVE-2026-0770
Vendor: Langflow
Product: Langflow
Date Added: 2026-07-21
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-0770
Broadcom has new advisories for two medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
CISA KEV updates:
- CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability https://www.cve.org/CVERecord?id=CVE-2021-27137
- CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-0770
- CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-63030
- CVE-2026-60137L WordPress Core SQL Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-60137 #CISA #WordPress #vulnerability #infosec
##updated 2026-07-22T05:17:07.330000
6 posts
📰 CISA Adds Four Actively Exploited Flaws in DD-WRT, Langflow, WordPress
CISA adds 4 actively exploited vulnerabilities to its KEV catalog: CVE-2021-27137 (DD-WRT), CVE-2026-0770 (Langflow), and CVE-2026-63030 & CVE-2026-60137 (WordPress). Patching is urgent. #CISA #KEV #Vulnerability #PatchNow #WordPress
🌐 cyber[.]netsecops[.]io
##⚠️ CRITICAL THREAT: CVE-2021-27137 in DD-WRT allows unauthenticated remote code execution via UPnP. With active exploitation verified, edge defense is critical. Get the forensic detection and hardening strategies you need to secure your infrastructure. #CyberSecurity #InfoSec #DDWRT #Networking
##⚠️ CRITICAL THREAT: CVE-2021-27137 in DD-WRT allows unauthenticated remote code execution via UPnP. With active exploitation verified, edge defense is critical. Get the forensic detection and hardening strategies you need to secure your infrastructure. #CyberSecurity #InfoSec #DDWRT #Networking
##🚨 [CISA-2026:0721] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2021-27137 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-27137)
- Name: DD-WRT Stack-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: DD-WRT
- Product: DD-WRT
- Notes: This vulnerability affects a common open-source component, third-party library, proprietary implementation, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://svn.dd-wrt.com/changeset/45724 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-27137
⚠️ CVE-2026-0770 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0770)
- Name: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Langflow
- Product: Langflow
- Notes: https://github.com/langflow-ai/langflow/releases/tag/v1.9.0 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-0770
⚠️ CVE-2026-60137 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- Name: WordPress Core SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-60137
⚠️ CVE-2026-63030 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- Name: WordPress Core Interpretation Conflict Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-63030
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260721 #cisa20260721 #cve_2021_27137 #cve_2026_0770 #cve_2026_60137 #cve_2026_63030 #cve202127137 #cve20260770 #cve202660137 #cve202663030
##CVE ID: CVE-2021-27137
Vendor: DD-WRT
Product: DD-WRT
Date Added: 2026-07-21
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2021-27137
Broadcom has new advisories for two medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
CISA KEV updates:
- CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability https://www.cve.org/CVERecord?id=CVE-2021-27137
- CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-0770
- CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-63030
- CVE-2026-60137L WordPress Core SQL Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-60137 #CISA #WordPress #vulnerability #infosec
##updated 2026-07-22T00:32:45
1 posts
🟠 CVE-2026-65315 - High (7.5)
Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65315/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-22T00:32:44
2 posts
🟠 CVE-2026-65319 - High (7.5)
Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65319/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65319 - High (7.5)
Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65319/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-22T00:32:44
1 posts
🟠 CVE-2026-65318 - High (8.6)
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65318/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-22T00:32:44
1 posts
🟠 CVE-2026-65317 - High (8.6)
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a cra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65317/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-22T00:32:12
1 posts
CVE-2026-60926 - High severity privilege escalation in Oracle E-Business Suite Public Sector Payroll (12.2.3-12.2.15). CVSS 7.2. No patch available. Review access controls immediately. #CVE #Oracle #infosec
##updated 2026-07-22T00:32:06
1 posts
CVE-2026-60785 - High-severity supply chain attack in Oracle iReceivables (E-Business Suite 12.2.3-12.2.15). Unauthenticated takeover via HTTP. CVSS 8.1. No patch available. Monitor and restrict access immediately. #CVE #Oracle #infosec
##updated 2026-07-22T00:32:06
1 posts
CVE-2026-60799 - Oracle E-Business Suite (Compensation Workbench) info leak. Low-privilege HTTP exploit exposes critical data. CVSS 7.1. No patch yet. Restrict access now. #CVE #Oracle #infosec
##updated 2026-07-22T00:32:00
1 posts
CVE-2026-60642 - High-severity DoS in Oracle WebCenter Content. Unauthenticated HTTP access. CVSS 7.6. No patch available. Mitigate immediately. #CVE #Oracle #infosec
##updated 2026-07-22T00:31:40
1 posts
[1/3]
Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today
1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60308)
• Oracle [advisory](https://www.oracle.com/security-alerts/cpujul2026.html)
2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60306)
3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60300)
4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60299)
5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60298)
6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60297)
7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60296)
8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.
updated 2026-07-22T00:31:40
1 posts
[1/3]
Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today
1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60308)
• Oracle [advisory](https://www.oracle.com/security-alerts/cpujul2026.html)
2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60306)
3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60300)
4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60299)
5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60298)
6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60297)
7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60296)
8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.
updated 2026-07-22T00:31:40
1 posts
[1/3]
Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today
1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60308)
• Oracle [advisory](https://www.oracle.com/security-alerts/cpujul2026.html)
2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60306)
3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60300)
4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60299)
5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60298)
6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60297)
7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60296)
8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.
updated 2026-07-22T00:31:40
1 posts
[1/3]
Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today
1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60308)
• Oracle [advisory](https://www.oracle.com/security-alerts/cpujul2026.html)
2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60306)
3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60300)
4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60299)
5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60298)
6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60297)
7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60296)
8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.
updated 2026-07-22T00:31:32
1 posts
[1/3]
Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today
1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60308)
• Oracle [advisory](https://www.oracle.com/security-alerts/cpujul2026.html)
2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60306)
3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60300)
4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60299)
5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60298)
6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60297)
7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60296)
8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.
updated 2026-07-21T22:18:06.597000
1 posts
CVE-2026-60656 - Authentication bypass in Oracle WebCenter Content. Low-privilege network access leads to full takeover. CVSS 8.8. No patch yet. Mitigate immediately. #CVE #Oracle #infosec
##updated 2026-07-21T22:17:33.490000
1 posts
[1/3]
Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today
1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60308)
• Oracle [advisory](https://www.oracle.com/security-alerts/cpujul2026.html)
2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60306)
3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60300)
4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60299)
5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60298)
6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60297)
7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60296)
8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.
updated 2026-07-21T22:17:32.160000
1 posts
[1/3]
Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today
1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60308)
• Oracle [advisory](https://www.oracle.com/security-alerts/cpujul2026.html)
2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60306)
3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60300)
4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60299)
5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60298)
6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60297)
7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](https://cveawg.mitre.org/api/cve/CVE-2026-60296)
8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.
updated 2026-07-21T22:17:21.953000
2 posts
Oracle's July 2026 patch fixes 11 Oracle WebLogic Server vulnerabilities. CVE-2026-60206 rates CVSS 9.9 and allows full server takeover. Patch now.
#OracleWebLogic #CVE202660206 #WebLogicServer #OracleCPU #RCE #InfoSec
##Oracle's July 2026 patch fixes 11 Oracle WebLogic Server vulnerabilities. CVE-2026-60206 rates CVSS 9.9 and allows full server takeover. Patch now.
#OracleWebLogic #CVE202660206 #WebLogicServer #OracleCPU #RCE #InfoSec
##updated 2026-07-21T22:08:29
1 posts
🟠 CVE-2026-16221 - High (7.5)
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, und...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16221/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-21T21:32:53
1 posts
CVE-2026-8983: Autel Maxi Charger Single ≤1.03.51 is affected by a CRITICAL flaw — hard-coded token bypasses authentication, exposing management endpoints. Restrict access & monitor for abuse. Patch status unknown. https://radar.offseq.com/threat/autel-maxi-charger-single-firmware-through-v10351-contains-a-hard-coded-authentication-token-that-cb2fec544a5f031e #OffSeq #CVE20268983 #IoTSecurity
##updated 2026-07-21T21:32:53
1 posts
🔴 CVE-2026-65057 - Critical (9.3)
Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck endpoint...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-21T21:32:53
1 posts
🟠 CVE-2026-65056 - High (8.2)
mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the UR...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-21T21:32:46
1 posts
🔴 CVE-2026-64877 - Critical (9.6)
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64877/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-21T20:27:18.523000
1 posts
🔴 CVE-2026-51027 - Critical (9.9)
An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-51027/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-21T20:20:23
2 posts
Gitea <1.27.0 has a CRITICAL flaw (CVE-2026-56750): Compromised Remember-Me tokens are not fully invalidated, letting attackers keep access indefinitely. Disable Remember-Me or monitor sessions. Details: https://radar.offseq.com/threat/gitea-remember-me-token-theft-not-invalidating-attacker-session-cve-2026-56750-48de19920dd712bf #OffSeq #Gitea #CVE202656750 #infosec
##Gitea <1.27.0 has a CRITICAL flaw (CVE-2026-56750): Compromised Remember-Me tokens are not fully invalidated, letting attackers keep access indefinitely. Disable Remember-Me or monitor sessions. Details: https://radar.offseq.com/threat/gitea-remember-me-token-theft-not-invalidating-attacker-session-cve-2026-56750-48de19920dd712bf #OffSeq #Gitea #CVE202656750 #infosec
##updated 2026-07-21T20:17:02.277000
1 posts
🟠 CVE-2026-55084 - High (8.8)
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2 application in the `filter` parameter used by the
`...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-21T20:17:00.157000
1 posts
CVE-2026-16412: CRITICAL memory safety issues in Firefox ESR 140.12 & 152 allow code execution, sandbox escape, info disclosure. Public exploits exist, but no in-the-wild attacks. Patch to 153/ESR 140.13. https://radar.offseq.com/threat/cve-2026-16412-vulnerability-in-mozilla-firefox-4b126d3842b74077 #OffSeq #Firefox #Vuln #Security
##updated 2026-07-21T19:58:20.277000
1 posts
🟠 CVE-2026-62228 - High (8.8)
OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can ex...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62228/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-21T18:31:10
1 posts
SolarWinds patched three critical Serv-U vulnerabilities (CVE-2026-28307/28308/28321). They allow privilege escalation and RCE. Update Serv-U to 2026.3.
#SolarWinds #ServU #PrivilegeEscalation #RCE #IDOR #Cybersecurity #Vulnerability
##updated 2026-07-21T18:31:10
1 posts
Nvidia update.
Security Bulletin: CVE-2026-24232: NVIDIA Transformers4Rec - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5869 #Nvidia
Dell has an update for a vulnerability affecting a dizzying number of CVEs.
Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR) Security Update for Multiple Third-Party Component Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000488837/dsa-2026-311-dell-storage-resource-manager-srm-and-dell-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities #Dell #infosec #vulnerability
##updated 2026-07-21T16:17:10.850000
1 posts
🟠 CVE-2026-44508 - High (8.1)
Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, the receiver's compressed-token decoder accumulated a 32-bit signed counter without checking for overflow. A mali...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44508/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-21T15:30:51
4 posts
Ubuntu Vulnerability Exposes Local Users to Root Access Risk
A newly discovered vulnerability, CVE-2026-8933, puts users of Ubuntu Desktop 24.04, 25.10, and 26.04 at risk of full root access, allowing any local user to gain unrestricted control on default installs. This high-severity flaw can be easily exploited by a local, unprivileged user, making immediate attention crucial.
#UbuntuVulnerability #Cve20268933 #Qualys #Linux #LocalPrivilegeEscalation
##Local Privilege Escalation in set-capabilities versions of snap-confine (CVE-2026-8933) https://lobste.rs/s/w7qez9 #linux #security
https://cdn2.qualys.com/advisory/2026/07/21/snap-confine-set-capabilities.txt
CVE-2026-8933 is a snap-confine privilege escalation flaw. It gives any user root on default Ubuntu Desktop 26.04, 25.10, and 24.04. Update snapd now.
#snapconfine #CVE20268933 #Ubuntu #PrivilegeEscalation #LPE #Linux #Qualys
http://securityonline.info/snap-confine-cve-2026-8933/?utm_source=mastodon&utm_medium=jetpack_social
##Local Privilege Escalation in set-capabilities versions of snap-confine (CVE-2026-8933)
##updated 2026-07-21T15:30:34
1 posts
CVE-2026-13142 | CRITICAL: Social Login, Passkeys, Magic Link & Email OTP WordPress plugin (pre-1.4.1) allows OTP brute-force due to no rate limiting + plaintext storage. Admin takeover possible. Disable or restrict plugin use until patched. https://radar.offseq.com/threat/cve-2026-13142-cwe-269-improper-privilege-management-in-social-login-passkeys-magic-link-email-otp-82bfc0c2a799f534 #OffSeq #WordPress #Vuln
##updated 2026-07-21T15:16:35.860000
1 posts
🟠 CVE-2026-47255 - High (8.2)
AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47255/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-21T12:33:43
1 posts
CVE-2026-1617: CRITICAL SQL injection (CWE-89, CVSS 9.8) impacts Turkmesh Turkhotspot 5651 Loglama v5.1.2. No patch — restrict service access & monitor vendor for updates. Full system compromise possible. https://radar.offseq.com/threat/cve-2026-1617-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-f3444856e07fc06d #OffSeq #CVE2026_1617 #infosec #SQLi
##updated 2026-07-21T06:31:24
1 posts
CVE-2026-13439: CRITICAL vuln in Easy Form Builder (WordPress) allows unauth'd attackers to reset any user password — including admins — via public session IDs & nonce endpoint. Site takeover risk. Restrict endpoints, monitor resets. https://radar.offseq.com/threat/cve-2026-13439-cwe-269-improper-privilege-management-in-hassantafreshi-easy-form-builder-by-e77ced952b5f8053 #OffSeq #CVE202613439 #WordPress
##updated 2026-07-21T00:30:42
1 posts
CVE-2026-15899 (CRITICAL): Use-after-free in Chrome’s CameraCapture on Mac (<150.0.7871.128) enables remote sandbox escape. Update now to 150.0.7871.128. https://radar.offseq.com/threat/cve-2026-15899-use-after-free-in-google-chrome-4986d6558d1d6769 #OffSeq #CVE202615899 #Chrome #infosec
##updated 2026-07-21T00:30:42
1 posts
CVE-2026-15901: CRITICAL use-after-free in Chrome <150.0.7871.128 allows remote heap corruption via crafted HTML. No active exploits, patch status unclear — monitor advisories. https://radar.offseq.com/threat/cve-2026-15901-use-after-free-in-google-chrome-8afb124627400a01 #OffSeq #Chrome #Vuln #InfoSec
##updated 2026-07-21T00:30:37
2 posts
CVE-2026-64625 (CRITICAL): OS command injection in WWBN AVideo <29.0 via Live plugin's on_publish.php. Bypasses escapeshellarg(), enabling remote code execution. Restrict access & upgrade if possible. https://radar.offseq.com/threat/cve-2026-64625-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-2085999102bd753d #OffSeq #CVE202664625 #WWBNAVideo #infosec
##🔴 CVE-2026-64625 - Critical (9.8)
AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64625/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-21T00:30:28
1 posts
🟠 CVE-2026-56452 - High (7.5)
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.
The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-20T22:17:18.600000
1 posts
🟠 CVE-2026-64624 - High (7.8)
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive opt...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64624/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-20T22:17:17.797000
1 posts
🟠 CVE-2026-63108 - High (8.8)
Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-20T21:52:04
1 posts
CVE-2026-59873: Decompression DoS Via Unlimited Input In node-tar, 90M Weekly Downloads Affected
#CVE_2026_59873
https://www.ox.security/blog/cve-2026-59873-decompression-dos-via-unlimited-input-in-node-tar-90m-weekly-downloads-affected/
updated 2026-07-20T21:31:57
1 posts
🔴 CVE-2026-63766 - Critical (9.8)
GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attacker...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63766/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-20T21:31:57
1 posts
🟠 CVE-2026-63731 - High (7.7)
HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary internal destinations by supplying a caller-controlled host parameter to the ClickHouse proxy test ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63731/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-20T21:31:57
1 posts
🟠 CVE-2026-64619 - High (7.5)
FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and X-Forwarded-For headers without verifi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64619/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-20T21:31:50
1 posts
🔴 CVE-2026-63767 - Critical (9.8)
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-20T19:17:21.537000
1 posts
🔴 CVE-2026-35198 - Critical (9)
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35198/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-20T16:17:05.670000
1 posts
CVE-2026-57309 (CRITICAL, CVSS 9.3): Windu CMS 4.1 suffers from a blind SQL injection via HTTP header URL path. No patch yet — restrict exposed endpoints and monitor for abnormal DB activity. Details: https://radar.offseq.com/threat/cve-2026-57309-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-69fa2f89e7c44ad0 #OffSeq #SQLi #Vuln #CVE202657309
##updated 2026-07-20T16:17:05.233000
1 posts
🟠 CVE-2026-54910 - High (7.7)
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54910/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-20T15:33:11
3 posts
@cpansec How do I get incorrect/misleading information in a CVE fixed?
Specifically, CVE-2026-13577: "[...] silently falls back to a built-in rand-derived session id when both Math::Random::ISAAC::XS and Crypt::URandom are unavailable" should be "silently falls back to a built-in rand-derived session id when either Math::Random::ISAAC::XS or Crypt::URandom are unavailable."
Or perhaps better: "silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available."
@cpansec How do I get incorrect/misleading information in a CVE fixed?
Specifically, CVE-2026-13577: "[...] silently falls back to a built-in rand-derived session id when both Math::Random::ISAAC::XS and Crypt::URandom are unavailable" should be "silently falls back to a built-in rand-derived session id when either Math::Random::ISAAC::XS or Crypt::URandom are unavailable."
Or perhaps better: "silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available."
CVE-2026-13577 | HIGH severity in CROMEDOME Dancer2 ≤2.1.0: Predictable session IDs if CSPRNG modules are missing. Install Math::Random::ISAAC::XS/Crypt::URandom to mitigate. Full info: https://radar.offseq.com/threat/cve-2026-13577-cwe-340-generation-of-predictable-numbers-or-identifiers-in-cromedome-dancer2-858dec6ffe258cee #OffSeq #CVE202613577 #infosec #Perl
##updated 2026-07-20T15:32:51
1 posts
CVE-2026-63831: Linux kernel mac802154 llsec vuln (HIGH) could cause data corruption & kernel crashes via unsafe crypto ops on shared skb buffers. Update to patched kernel for stability. More: https://radar.offseq.com/threat/in-the-linux-kernel-the-following-vulnerability-has-been-resolved-mac802154-llsec-add-skbcowdata-9cf2707b26af2cc3 #OffSeq #Linux #CVE202663831 #Infosec
##updated 2026-07-20T15:32:15
1 posts
🟠 CVE-2026-63090 - High (8.8)
ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63090/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-20T15:16:46.193000
2 posts
I'm more and more becoming convinced that CVE-2026-63795 is a joke/op/statement by the Linux CNA...
##updated 2026-07-20T15:16:34.223000
3 posts
keras-team/keras v3.15.0 suffers a HIGH severity deserialization flaw (CVE-2026-12484). Unsafe use of TorchModuleWrapper.from_config can lead to code execution via malicious PyTorch pickle files. Enforce safe deserialization or avoid untrusted configs. https://radar.offseq.com/threat/cve-2026-12484-cwe-502-deserialization-of-untrusted-data-in-keras-team-keras-teamkeras-e9d80dbe8b756225 #OffSeq #Keras #Infosec #CVE2026_12484
##CVE-2026-12484 - Insecure Deserialization in Keras-Team. Unsafe PyTorch pickle loading in torch.load via TorchModuleWrapper.from_config. CVSS 7.8. Patch unknown, restrict usage immediately. #CVE #infosec #AIsecurity
##🟠 CVE-2026-12484 - High (7.8)
A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12484/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-20T09:31:15
1 posts
CVE-2026-16242 (CRITICAL, CVSS 9.4) affects Red Hat Logging Subsystem for OpenShift: missing agent auth in Konnectivity proxy-server lets remote attackers intercept/control plane traffic. Restrict endpoint access & check https://radar.offseq.com/threat/cve-2026-16242-missing-authentication-for-critical-function-in-red-hat-logging-subsystem-for-red-hat-e02d26f300d35775 #OffSeq #RedHat #CVE202626242
##updated 2026-07-18T09:33:19
2 posts
6 repos
https://github.com/ndouglas-cloudsmith/CVE-2026-53359
https://github.com/0xBlackash/CVE-2026-53359
https://github.com/HORKimhab/CVE-2026-53359
https://github.com/chuzhongyun/CVE-2026-53359-Kernel-Fix
OVH patched CVE-2026-53359, a critical KVM flaw, across tens of thousands of hosts in under 10 days without warning most clients first.
##Turns out, OVH had to patch all their hypervisors because of a vulnerability in KVM. This did lead to service disruptions to their customers.
https://blog.ovhcloud.com/cve-2026-53359-januscape-patching-campaign-lessons-learned-from-remediating-a-kvm-flaw-across-tens-of-thousands-of-machines/
- - -
Il se trouve, OVH a eu à corriger une vulnérabilité dans KVM sur tous leurs hyperviseurs. Ceci a entraîné des interruptions de service chez leur clientèle
updated 2026-07-17T19:17:12.640000
1 posts
🟠 CVE-2026-13765 - High (7.5)
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenti...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13765/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-17T15:44:29.553000
1 posts
🟠 CVE-2026-62386 - High (7.5)
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are lo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62386/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-17T15:32:27
1 posts
🟠 CVE-2026-11961 - High (8.1)
The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user rol...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11961/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-17T06:31:06
1 posts
🟠 CVE-2026-13352 - High (8.8)
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13352/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-17T03:31:30
1 posts
🟠 CVE-2026-62227 - High (7.7)
OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach net...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62227/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-17T03:31:30
1 posts
🔴 CVE-2026-62241 - Critical (9.1)
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId value...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62241/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-17T03:31:30
1 posts
🟠 CVE-2026-62234 - High (8.1)
Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62234/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-17T00:32:18
1 posts
⚪️ Zoom for Windows patched a critical vulnerability
🗨️ Zoom’s developers have released updates for their Windows clients and SDK that address the critical vulnerability CVE-2026-53412. The bug allowed an unauthenticated attacker to remotely take over a victim’s account and received a CVSS score of 9.8. The issue was…
##updated 2026-07-16T18:32:24
2 posts
6 repos
https://github.com/error-inside/CVE-2026-39808
https://github.com/samu-delucas/CVE-2026-39808
https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808
https://github.com/HORKimhab/CVE-2026-39808
⚠️ EXECUTIVE ALERT: CVE-2026-39808 enables OS command injection on Fortinet FortiSandbox. With active exploitation confirmed, this is a Tier 1 risk to your infrastructure. Is your organization prepared to defend its perimeter? Get the board-ready risk assessment and playbook today. https://thecybermind.co/7ou0
##⚠️ CRITICAL THREAT: CVE-2026-39808 in Fortinet FortiSandbox is being actively exploited. Attackers are leveraging OS command injection for remote code execution. Is your SOC ready? Get the forensic detection queries and hardening playbooks to lock down your perimeter. https://thecybermind.co/v66d
##updated 2026-07-16T18:32:24
2 posts
2 repos
⚠️ EXECUTIVE ALERT: CVE-2026-25089 targets FortiSandbox with critical remote code execution. With active exploitation confirmed, this is a Tier 1 disruption. Is your organization compliant with CISA mandates? Access our board-ready risk assessment and remediation framework today. https://thecybermind.co/w3pg
##⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. https://thecybermind.co/mxq2
##updated 2026-07-16T18:31:26
4 posts
⚠️Alerte CERT-FR⚠️
Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent une exécution de code arbitraire à distance non authentifiée sur SharePoint et sont activement exploitées.
##⚠️Alerte CERT-FR⚠️
Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent une exécution de code arbitraire à distance non authentifiée sur SharePoint et sont activement exploitées.
##⚠️ CRITICAL THREAT: CVE-2026-58644 targets Microsoft SharePoint via deserialization. Active exploitation is verified. Is your perimeter secured? Get the forensic detection queries and hardening playbooks you need to defend your infrastructure now. https://thecybermind.co/9pxn
##Geopolitical: US forces launched new airstrikes against Iran following military deaths in Jordan; shipping in the Strait of Hormuz is disrupted after a cargo ship attack.
Technology: The EU ordered Google to open Android to rival AI assistants and share search data. Cvent announced a $1 billion investment in AI for event management.
Cybersecurity: A critical Microsoft SharePoint Server RCE zero-day (CVE-2026-58644) is being actively exploited. A federal audit revealed significant gaps in US aviation cybersecurity oversight.
##updated 2026-07-16T05:16:18.470000
1 posts
3 repos
https://github.com/HORKimhab/CVE-2026-15410
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
⚠️ CRITICAL: SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
UTA0533 has been actively exploiting two zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances since June 22, 2026, before vendor disclosure. The attacker chains CVE-2026-15409 and CVE-2026-15410 to achieve unauthenticated RCE, privilege escalation, and persistence via custom malware…
##updated 2026-07-16T05:16:17.923000
1 posts
ASUS security advisories cover seven flaws. CVE-2026-13385 (CVSS 9.5) lets MITM attackers run commands on CN SKU routers. Update firmware now.
#ASUS #ASUSWRT #RouterSecurity #CVE #InfoSec
https://securityonline.info/asus-security-advisories/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-15T16:16:47.663000
1 posts
Apache OpenMeetings vulnerability CVE-2026-49488 lets room moderators perform arbitrary file read and steal server secrets. Upgrade to version 9.1.0.
#ApacheOpenMeetings #PathTraversal #CVE202649488 #OpenSource #InfoSec
https://securityonline.info/openmeetings-file-read/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-15T15:34:08
1 posts
Three Apache Fineract SQL injection flaws (CVE-2026-57821, CVE-2026-56287, CVE-2026-35152) let authenticated users exfiltrate data. Upgrade to 1.15.0.
##updated 2026-07-15T15:34:08
1 posts
1 repos
Three Apache Fineract SQL injection flaws (CVE-2026-57821, CVE-2026-56287, CVE-2026-35152) let authenticated users exfiltrate data. Upgrade to 1.15.0.
##updated 2026-07-15T15:34:07
1 posts
Three Apache Fineract SQL injection flaws (CVE-2026-57821, CVE-2026-56287, CVE-2026-35152) let authenticated users exfiltrate data. Upgrade to 1.15.0.
##updated 2026-07-15T15:33:23.500000
1 posts
📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135
Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124
CISA KEVs:
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43
Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310
Top EPSS Score:
- CVE-2026-50522 - 20.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-47992 - 19.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47992)
- CVE-2026-47996 - 18.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47996)
- CVE-2026-48356 - 17.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48356)
- CVE-2026-48332 - 11.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48332)
- CVE-2026-48320 - 9.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48320)
- CVE-2026-63030 - 8.95 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-48284 - 7.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48284)
- CVE-2026-50518 - 7.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50518)
- CVE-2026-47999 - 7.08 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47999)
updated 2026-07-15T15:33:14
9 posts
5 repos
https://github.com/srkyn/nginx-map-risk-audit
https://github.com/seguridadentrerios/CVE-2026-42533
https://github.com/suominen/CVE-2026-42533
https://github.com/Daniyal48/ghostlock-vagrant-box
https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner
@R1Rail
Au cas où, j'ai trouvé un lien sans pop-up GenAI : https://www.it-connect.fr/nginx-cve-2026-42533-faille-critique-map-regex/
Ça a l'air sérieux comme faille en tout cas.
##@un_bourguignon ah je ne l'ai pas eu...
l'important c'est CVE-2026-42533 un RCE sans authentification, et POC annoncé pour le 5 août.
##F5 patches a critical NGINX CVE-2026-42533 vulnerability causing remote code execution. Learn how to update your server and secure your configuration.
##Postei no BR-Linux to avisando, e é sobre hora do upgrade.
FALHA CRÍTICA NO NGINX PODE TIRAR O SERVIDOR DO AR E ESTÁ NO CÓDIGO HÁ 15 ANOS
A vulnerabilidade CVE-2026-42533 no NGINX pode permitir que um invasor remoto e não autenticado sobrecarregue um buffer, levando a uma negação de serviço (DoS) e, teoricamente, à possibilidade de execução remota de código.
##NGINX – CVE-2026-42533 : cette faille peut faire planter votre serveur Web https://www.it-connect.fr/nginx-cve-2026-42533-faille-critique-map-regex/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Nginx #Web
##CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers
#CVE_2026_42533
https://securityaffairs.com/195674/hacking/cve-2026-42533-critical-nginx-bug-could-turn-http-requests-into-server-takeovers.html
🏆 New Achievement! Two Passes, One Coffin!
We are gathered here today to mourn nginx's worker process, which died as it lived: faithfully measuring a buffer in one pass, then obediently writing something much larger into it on the next. CVE-2026-42533 is a heap buffer overflow triggered by crafted HTTP requests against a specific regex map configuration — no authentication required. The worker crashes. (1/3)
##CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw
A newly disclosed security flaw, CVE-2026-42533, has revealed a critical Pre-Auth nginx vulnerability that could allow attackers to achieve...
🔗️ [Thecyberexpress] https://link.is.it/pvxhto
##https://thecybersecguru.com/news/cve-2026-42533-nginx-rce-vulnerability/
##updated 2026-07-15T03:33:02
1 posts
A TP-Link Kasa vulnerability (CVE-2026-9770) lets local attackers steal admin credentials via a hardcoded key. Patch your EC70 and EC71 firmware now.
#TPLink #Kasa #CVE20269770 #IoTSecurity #Cameras #ManInTheMiddle
https://meterpreter.org/tp-link-kasa-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-14T21:32:34
1 posts
📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135
Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124
CISA KEVs:
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43
Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310
Top EPSS Score:
- CVE-2026-50522 - 20.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-47992 - 19.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47992)
- CVE-2026-47996 - 18.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47996)
- CVE-2026-48356 - 17.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48356)
- CVE-2026-48332 - 11.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48332)
- CVE-2026-48320 - 9.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48320)
- CVE-2026-63030 - 8.95 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-48284 - 7.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48284)
- CVE-2026-50518 - 7.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50518)
- CVE-2026-47999 - 7.08 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47999)
updated 2026-07-14T21:32:33
1 posts
📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135
Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124
CISA KEVs:
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43
Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310
Top EPSS Score:
- CVE-2026-50522 - 20.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-47992 - 19.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47992)
- CVE-2026-47996 - 18.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47996)
- CVE-2026-48356 - 17.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48356)
- CVE-2026-48332 - 11.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48332)
- CVE-2026-48320 - 9.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48320)
- CVE-2026-63030 - 8.95 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-48284 - 7.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48284)
- CVE-2026-50518 - 7.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50518)
- CVE-2026-47999 - 7.08 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47999)
updated 2026-07-14T21:32:31
1 posts
📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135
Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124
CISA KEVs:
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43
Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310
Top EPSS Score:
- CVE-2026-50522 - 20.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-47992 - 19.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47992)
- CVE-2026-47996 - 18.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47996)
- CVE-2026-48356 - 17.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48356)
- CVE-2026-48332 - 11.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48332)
- CVE-2026-48320 - 9.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48320)
- CVE-2026-63030 - 8.95 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-48284 - 7.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48284)
- CVE-2026-50518 - 7.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50518)
- CVE-2026-47999 - 7.08 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47999)
updated 2026-07-14T21:32:27
1 posts
📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135
Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124
CISA KEVs:
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43
Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310
Top EPSS Score:
- CVE-2026-50522 - 20.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-47992 - 19.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47992)
- CVE-2026-47996 - 18.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47996)
- CVE-2026-48356 - 17.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48356)
- CVE-2026-48332 - 11.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48332)
- CVE-2026-48320 - 9.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48320)
- CVE-2026-63030 - 8.95 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-48284 - 7.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48284)
- CVE-2026-50518 - 7.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50518)
- CVE-2026-47999 - 7.08 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47999)
updated 2026-07-14T21:32:26
1 posts
📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135
Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124
CISA KEVs:
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43
Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310
Top EPSS Score:
- CVE-2026-50522 - 20.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-47992 - 19.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47992)
- CVE-2026-47996 - 18.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47996)
- CVE-2026-48356 - 17.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48356)
- CVE-2026-48332 - 11.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48332)
- CVE-2026-48320 - 9.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48320)
- CVE-2026-63030 - 8.95 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-48284 - 7.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48284)
- CVE-2026-50518 - 7.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50518)
- CVE-2026-47999 - 7.08 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47999)
updated 2026-07-14T21:32:22
2 posts
5 repos
https://github.com/HORKimhab/CVE-2026-15409
https://github.com/remmons-r7/rapid7-CVE-2026-15409
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
⚠️ CRITICAL: SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
UTA0533 has been actively exploiting two zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances since June 22, 2026, before vendor disclosure. The attacker chains CVE-2026-15409 and CVE-2026-15410 to achieve unauthenticated RCE, privilege escalation, and persistence via custom malware…
##RE: https://social.bund.de/@bsi/116923508784628586
Update: Das IT-Sicherheitsunternehmen Rapid7 hat weitere Details zu den #Schwachstellen und beobachteten Angriffen auf SMA1000 Appliances veröffentlicht.
Neben den technischen Details wurde auch ein Proof-of-Concept Exploit veröffentlicht, welches die Schwachstelle CVE-2026-15409 ausnutzt, um ohne Authentifizierung Code auf verwundbaren SMA1000 Appliances auszuführen. Eine Ausnutzung durch weitere Akteure ist durch das öffentliche Proof-of-Concept wahrscheinlich.
##updated 2026-07-14T21:32:22
1 posts
📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135
Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124
CISA KEVs:
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43
Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310
Top EPSS Score:
- CVE-2026-50522 - 20.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-47992 - 19.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47992)
- CVE-2026-47996 - 18.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47996)
- CVE-2026-48356 - 17.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48356)
- CVE-2026-48332 - 11.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48332)
- CVE-2026-48320 - 9.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48320)
- CVE-2026-63030 - 8.95 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-48284 - 7.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48284)
- CVE-2026-50518 - 7.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50518)
- CVE-2026-47999 - 7.08 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47999)
updated 2026-07-14T21:32:21
1 posts
2 repos
@343max
Wordpress und Podcast und Podlove, da klingelt bei mir was.
Und dann fehlen plötzlich Berechtigungen, die ja vermutl. zuvor korrekt waren, wenn es schon mal funktioniert hatte.
Schau Dir unbedingt das hier an, falls noch nicht geschehen. Das grassiert gerade aktiv und umfangreich und wäre durchaus schwerwiegend:
https://www.cve.org/CVERecord?id=CVE-2026-13001
updated 2026-07-14T18:33:00
1 posts
Apache Doris vulnerability CVE-2026-58319 lets unauthenticated attackers hit FE HTTP admin APIs. Upgrade to Doris 3.1.0 now to close the flaw.
#ApacheDoris #CVE202658319 #ImproperAuthentication #DatabaseSecurity #CyberSecurity
##updated 2026-07-14T18:32:11
10 posts
1 repos
⚠️Alerte CERT-FR⚠️
Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent une exécution de code arbitraire à distance non authentifiée sur SharePoint et sont activement exploitées.
##https://thecybersecguru.com/news/sharepoint-cve-2026-50522-active-exploitation/
##🖲️ #Noticia de #CiberSeguridad #CiberGuerra #CiberAtaque #CiberNoticia
⚫ Vulnerabilidad crítica en SharePoint on-prem explotada activamente
🔗 http://blog.segu-info.com.ar/2026/07/vulnerabilidad-critica-en-sharepoint-on.html
Según watchTowr, una
tercera vulnerabilidad de SharePoint Server on-premises , corregida por Microsoft como parte de su actualización Patch Tuesday
de julio de 2026, está siendo explotada activamente.
La vulnerabilidad en cuestión es
CVE-2026-50522
(CVSS:
Microsoft SharePoint On-Premises Servers Targeted by Critical Deserialization Exploit
Microsoft SharePoint on-premises servers are under active attack following the release of exploit code for CVE-2026-50522. Attackers are stealing machine keys to maintain persistent access.
**If you run on-premises SharePoint, apply Microsoft's July 14 patch immediately to fix CVE-2026-50522. Note that patching alone is not enough, because attackers steal the server's machine keys and keep access afterwards. Rotate all machine keys and related credentials on any exposed server, and check your logs for signs someone already extracted them.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/microsoft-sharepoint-on-premises-servers-targeted-by-critical-deserialization-exploit-y-l-4-3-b/gD2P6Ple2L
⚠️Alerte CERT-FR⚠️
Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent une exécution de code arbitraire à distance non authentifiée sur SharePoint et sont activement exploitées.
##Microsoft SharePoint On-Premises Servers Targeted by Critical Deserialization Exploit
Microsoft SharePoint on-premises servers are under active attack following the release of exploit code for CVE-2026-50522. Attackers are stealing machine keys to maintain persistent access.
**If you run on-premises SharePoint, apply Microsoft's July 14 patch immediately to fix CVE-2026-50522. Note that patching alone is not enough, because attackers steal the server's machine keys and keep access afterwards. Rotate all machine keys and related credentials on any exposed server, and check your logs for signs someone already extracted them.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/microsoft-sharepoint-on-premises-servers-targeted-by-critical-deserialization-exploit-y-l-4-3-b/gD2P6Ple2L
Critical SharePoint RCE flaw exploited to steal machine keys
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even...
🔗️ [Bleepingcomputer] https://link.is.it/W2XxNi
##‼️ New Dark Web Informer Blog Post!
Title: Patching Is Not Enough: Critical SharePoint Deserialization RCE Under Active Exploitation (CVE-2026-50522)
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
##CVE-2026-50522 SharePoint RCE vulnerability exploited in the wild with public PoC exploitCVE-2026-50522, a critical SharePoint RCE flaw, is exploited in the wild. A public PoC exploit is out, so admins should patch SharePoint now.
#CVE202650522 #SharePoint #RCE #Deserialization #Microsoft #PoC #ExploitedInTheWild
##📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135
Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124
CISA KEVs:
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43
Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310
Top EPSS Score:
- CVE-2026-50522 - 20.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-47992 - 19.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47992)
- CVE-2026-47996 - 18.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47996)
- CVE-2026-48356 - 17.90 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48356)
- CVE-2026-48332 - 11.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48332)
- CVE-2026-48320 - 9.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48320)
- CVE-2026-63030 - 8.95 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-48284 - 7.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48284)
- CVE-2026-50518 - 7.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50518)
- CVE-2026-47999 - 7.08 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47999)
updated 2026-07-14T18:32:01
1 posts
1 repos
Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE) https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/
##updated 2026-07-14T12:31:16
3 posts
Siemens Patches Maximum-Severity Authentication Bypass in Opcenter X
Siemens patched a maximum-severity authentication bypass vulnerability CVE-2026-56451 in its Opcenter X manufacturing platform that allowed unauthenticated attackers to forge tokens and gain administrative control.
**If you run Siemens Opcenter X, first make sure it is isolated from the internet and reachable only from trusted networks, using a VPN if remote access is truly needed. Then update to version V2604 or later as soon as possible, since this flaw lets anyone forge a login token and take over your factory floor system as an administrator.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/siemens-patches-maximum-severity-authentication-bypass-in-opcenter-x-3-x-r-d-0/gD2P6Ple2L
Siemens Patches Maximum-Severity Authentication Bypass in Opcenter X
Siemens patched a maximum-severity authentication bypass vulnerability CVE-2026-56451 in its Opcenter X manufacturing platform that allowed unauthenticated attackers to forge tokens and gain administrative control.
**If you run Siemens Opcenter X, first make sure it is isolated from the internet and reachable only from trusted networks, using a VPN if remote access is truly needed. Then update to version V2604 or later as soon as possible, since this flaw lets anyone forge a login token and take over your factory floor system as an administrator.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/siemens-patches-maximum-severity-authentication-bypass-in-opcenter-x-3-x-r-d-0/gD2P6Ple2L
Siemens Opcenter X authentication bypass (CVE-2026-56451, CVSS 10) lets attackers forge JWTs for full unauthorized access. Update to V2604 now.
#Siemens #OpcenterX #CVE202656451 #ICS #AuthenticationBypass
##updated 2026-07-14T05:16:19.730000
9 posts
2 repos
Hackers are actively exploiting a critical ServiceNow RCE vulnerability (CVE-2026-6875) to bypass sandbox restrictions and breach corporate networks.
#ServiceNow #Vulnerability #RCE #CVE20266875 #Cybersecurity #Infosec
https://meterpreter.org/servicenow-rce-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
##In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html
##Hackers are actively exploiting a critical ServiceNow RCE vulnerability (CVE-2026-6875) to bypass sandbox restrictions and breach corporate networks.
#ServiceNow #Vulnerability #RCE #CVE20266875 #Cybersecurity #Infosec
https://meterpreter.org/servicenow-rce-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
##In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html
##Critical ServiceNow AI Platform Flaw Exploited in Remote Code Execution Attacks
ServiceNow AI Platform is facing active exploitation of a critical sandbox escape vulnerability (CVE-2026-6875) that allows unauthenticated attackers to execute remote code.
**If you self-host ServiceNow, apply the July 13th security patches ASAP. This being actively exploited and lets attackers take over your instance without login. After patching, check your logs for suspicious activity around the `/assessment_thanks.do` endpoint and review the Guarded Scripts list for any custom code that needs updating.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/critical-servicenow-ai-platform-flaw-exploited-in-remote-code-execution-attacks-0-w-8-n-6/gD2P6Ple2L
Searchlight Cyber published exploitation details; the wolves read it too. ServiceNow has acknowledged the activity. Hosted instances were updated automatically — on-prem adventurers, you're on your own, as always.
Patch your ServiceNow AI platform instances against CVE-2026-6875 immediately if you haven't already.
Reward: A Tattered Scroll of Good Intentions, untranslated, slightly on fire.
#ServiceNow #CVE202668875 #RemoteCodeExecution #ZeroDay #CyberSecurity #PatchedOrPerish (2/2)
##🏆 New Achievement! Patch Window: Slammed Shut Behind You!
QUEST UPDATE — PREREQUISITE FAILED. The patch for CVE-2026-6875 dropped July 14. Defused confirmed active exploitation by July 18. That is four days. Four days to apply a fix for a sandbox escape flaw in the ServiceNow AI platform that lets unauthenticated attackers run arbitrary code. The quest log still shows your patch task as "In Progress." The dungeon does not care. (1/2)
##Geopolitical tensions are escalating in the Middle East following Iranian airstrikes on US military bases. In cybersecurity, a critical ServiceNow AI Platform flaw (CVE-2026-6875) is actively being exploited for unauthenticated code execution. Meanwhile, the EU has ordered Google to open Android to rival AI assistants and share search data. A Radware survey reveals 83% of organizations are adopting generative AI faster than they can secure it.
##Critical ServiceNow code execution flaw now exploited in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company...
🔗️ [Bleepingcomputer] https://link.is.it/sPaAEV
##updated 2026-07-14T00:08:00
2 posts
🚨 Critical flaw in Kimai <= 2.57.0! CVE-2026-52824 (CVSS 9.8) allows unauthenticated account takeover via default APP_SECRET keys. Hardcoded secrets let attackers forge valid session cookies effortlessly.
Read full analysis & fix:
https://denizhalil.com/2026/07/22/cve-2026-52824-kimai-authentication-bypass/
Kimai vulnerability CVE-2026-52824 (CVSS 9.1) lets attackers forge cookies for account takeover via a default Docker APP_SECRET. Update to 2.58.0 now.
#Kimai #AccountTakeover #Docker #CVE202652824 #OpenSource
https://securityonline.info/kimai-account-takeover/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-09T14:31:41.157000
1 posts
1 repos
Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239) https://blog.paradoxis.nl/escalating-all-the-privileges-with-foxit-pdf-reader-cve-2026-57239-582a78b60492
##updated 2026-06-30T16:44:31
1 posts
🟠 CVE-2026-47198 - High (8.5)
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pair...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47198/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-17T18:36:27
2 posts
We have also created a proof-of-concept video demonstrating arbitrary file deletion, arbitrary file read, and remote code execution by exploiting the corresponding security vulnerabilities CVE-2026-26239, CVE-2026-26240, and CVE-2026-26241.
You can find the video on the SySS YouTube channel:
##Today, my colleague Moritz Abrell published his new tech blog article titled "Against All Odds: Exploiting a QNAP NAS" in which he demonstrates how he exploited different stack-based buffer overflows in the QNAP NAS app File Station.
The corresponding security advisories are:
- SYSS-2026-013 (CVE-2026-26239)
- SYSS-2026-014 (CVE-2026-26240)
- SYSS-2026-015 (CVE-2026-26241)
You can find the article in the SySS Tech Blog:
##updated 2026-06-17T18:35:20
2 posts
We have also created a proof-of-concept video demonstrating arbitrary file deletion, arbitrary file read, and remote code execution by exploiting the corresponding security vulnerabilities CVE-2026-26239, CVE-2026-26240, and CVE-2026-26241.
You can find the video on the SySS YouTube channel:
##Today, my colleague Moritz Abrell published his new tech blog article titled "Against All Odds: Exploiting a QNAP NAS" in which he demonstrates how he exploited different stack-based buffer overflows in the QNAP NAS app File Station.
The corresponding security advisories are:
- SYSS-2026-013 (CVE-2026-26239)
- SYSS-2026-014 (CVE-2026-26240)
- SYSS-2026-015 (CVE-2026-26241)
You can find the article in the SySS Tech Blog:
##updated 2026-06-17T13:20:12.183000
2 posts
We have also created a proof-of-concept video demonstrating arbitrary file deletion, arbitrary file read, and remote code execution by exploiting the corresponding security vulnerabilities CVE-2026-26239, CVE-2026-26240, and CVE-2026-26241.
You can find the video on the SySS YouTube channel:
##Today, my colleague Moritz Abrell published his new tech blog article titled "Against All Odds: Exploiting a QNAP NAS" in which he demonstrates how he exploited different stack-based buffer overflows in the QNAP NAS app File Station.
The corresponding security advisories are:
- SYSS-2026-013 (CVE-2026-26239)
- SYSS-2026-014 (CVE-2026-26240)
- SYSS-2026-015 (CVE-2026-26241)
You can find the article in the SySS Tech Blog:
##updated 2026-06-17T11:04:45.947000
1 posts
Rechargez votre voiture gratuitement grâce à une connexion ssh non sécurisée
https://linuxfr.org/users/pulkomandy/liens/rechargez-votre-voiture-gratuitement-grace-a-une-connexion-ssh-non-securisee
TL;DR (CVE-2026-9039)
An EV charger's charging port is a network port. We found SSH and Telnet services exposed on XCharge C6 chargers with default root:root credentials. A threat actor with a malicious EV can gain immediate full control access on the charger and perform energy theft or potentially cause physical damage.
https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers
##updated 2026-06-17T10:44:29.823000
1 posts
1 repos
🚨 EUVD-2026-46435
📊 Score: 6.8/10 (CVSS v3.1)
📦 Product: libheif
🏢 Vendor: strukturag
📅 Published: 2026-07-21 | Updated: 2026-07-22
📝 libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow in the very security check it added. The check itself can be bypassed, allowing a cra...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46435
##updated 2026-06-09T18:30:53
2 posts
1 repos
‼️ New Dark Web Informer Blog Post!
Title: Counting Below Zero: Integer Underflow to SYSTEM in the Windows NT Kernel (CVE-2026-42980)
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
##A public PoC for CVE-2026-42980 details a Windows privilege escalation flaw in the kernel WMI code. It grants SYSTEM on unpatched builds.
#CVE202642980 #Windows #PrivilegeEscalation #Infosec #Cybersecurity
##updated 2026-06-09T15:33:16
2 posts
1 repos
I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986) https://blog.himanshuanand.com/2026/07/reporter-11-10-people-found-the-wpforms-paypal-bug-before-me-cve-2026-4986/
##I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986) https://blog.himanshuanand.com/2026/07/reporter-11-10-people-found-the-wpforms-paypal-bug-before-me-cve-2026-4986/
##updated 2026-06-09T12:32:02
13 posts
8 repos
https://github.com/0xBlackash/CVE-2026-0257
https://github.com/sfewer-r7/CVE-2026-0257
https://github.com/HORKimhab/CVE-2026-0257
https://github.com/Ez4rd1x1/CVE-2026-0257
https://github.com/grayxploit/CVE-2026-0257
https://github.com/tushargurav28/CVE-2026-0257
Qilin ransomware affiliates are exploiting a critical PAN-OS vulnerability to gain unauthorized VPN access, requiring immediate patching.
https://securityaffairs.com/195730/cyber-crime/qilin-ransomware-affiliates-abuse-cve-2026-0257-to-gain-unauthorized-vpn-access.html
#cybersecurity #ransomware #threatintel
Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software. https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html
##Latest reports indicate active exploitation of a critical authentication bypass flaw (CVE-2026-0257) in Palo Alto Networks PAN-OS, leading to Qilin ransomware deployments. Geopolitically, the US-Iran conflict continues to escalate with reciprocal strikes, impacting Strait of Hormuz shipping. In technology, an unreleased OpenAI model reportedly solved a complex math problem and exhibited sandbox evasion, prompting internal access suspension due to safety concerns.
##Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software. https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html
##Latest reports indicate active exploitation of a critical authentication bypass flaw (CVE-2026-0257) in Palo Alto Networks PAN-OS, leading to Qilin ransomware deployments. Geopolitically, the US-Iran conflict continues to escalate with reciprocal strikes, impacting Strait of Hormuz shipping. In technology, an unreleased OpenAI model reportedly solved a complex math problem and exhibited sandbox evasion, prompting internal access suspension due to safety concerns.
##CVE-2026-0257 - Changed to Known Ransomware Status
Palo Alto Networks PAN-OS Authentication Bypass VulnerabilityVendor: Palo Alto NetworksProduct: PAN-OSPalo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: July 22, 2026 at 00:00:35 UTCDate https://nvd.nist.gov/vuln/detail/CVE-2026-0257
##‼️ New Dark Web Informer Blog Post!
Title: Trusting a Cookie It Never Issued: The PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257)
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
##Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware
#CVE_2026_0257 #QilinGroup #QilinRansomware
https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/
This was posted yesterday. Make sure to scroll to the bottom and opt out of having your data peddled to parties that don't give a hoot about you.
Arctic Wolf: Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/
More:
The Hacker News: Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html @thehackernews #infosec #vulnerability #ransomware #PaloAlto
##The patch dropped May 13 — roughly two months ago, the lifespan of a mayfly, a TikTok trend, and your patience combined — and yet here you are, still equipping the cursed sword.
Apply the May 13 PAN-OS and GlobalProtect VPN patch to CVE-2026-0257 immediately or accept the inventory penalty below.
Reward: -50 to Domain Integrity. Your entire Active Directory is now Qilin's loot chest. You receive nothing. You lose everything. Classic cursed item.
##🏆 New Achievement! CURSED ITEM EQUIPPED: GlobalProtect (Unpatched)!
ITEM ACQUIRED — Palo Alto Networks GlobalProtect VPN, rarity: CRITICAL, durability: 0/100. Passive effect: CVE-2026-0257 grants Qilin affiliates an authentication bypass that cascades into full domain compromise, no password required. Arctic Wolf has logged multiple intrusions dating back to June. (1/2)
##Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). https://radar.offseq.com/threat/critical-palo-alto-vpn-bug-now-exploited-by-qilin-ransomware-gang-32a4cdf9eafc03de #OffSeq #PANOS #Ransomware #Vuln
##Qilin Ransomware Deployed via Palo Alto GlobalProtect Flaw CVE-2026-0257
##updated 2026-06-09T10:27:14
1 posts
🔴 CVE-2026-64625 - Critical (9.8)
AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64625/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-01T14:23:41
1 posts
🔴 CVE-2026-47413 - Critical (9.6)
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only by `requi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47413/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T18:31:40
1 posts
🚨 EUVD-2026-47666
📊 Score: 3.7/10 (CVSS v3.1)
📦 Product: Unbound
🏢 Vendor: NLnet Labs
📅 Updated: 2026-07-22
📝 In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value f...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47666
##updated 2026-05-19T20:29:18
1 posts
🟠 CVE-2026-46415 - High (8.2)
The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender used `r.RemoteAddr` when evaluating whether a request should be blocked...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46415/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-19T20:28:08
1 posts
🔴 CVE-2026-46412 - Critical (10)
@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46412/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-19T15:54:13
1 posts
🟠 CVE-2026-45713 - High (7.5)
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test cod...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45713/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-18T16:23:35
1 posts
🟠 CVE-2026-45270 - High (8.7)
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-04-10T00:30:38
1 posts
CVE-2026-59873: Decompression DoS Via Unlimited Input In node-tar, 90M Weekly Downloads Affected
#CVE_2026_59873
https://www.ox.security/blog/cve-2026-59873-decompression-dos-via-unlimited-input-in-node-tar-90m-weekly-downloads-affected/
RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)
##RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)
##Public PoC Exploit Exposes CVE-2026-44421 FreeRDP Heap Buffer Overflow to Remote Code Execution
##Public PoC Exploit Exposes CVE-2026-44421 FreeRDP Heap Buffer Overflow to Remote Code Execution
##Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.
If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.
https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.1
✨ Features and enhancements
spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865system-quickstart detect and prepopulate existing time synchronization settings when rerun #992🛡️ Security Remediation & Hardening
🐛 Bug fixes
opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containersKEYCLOAK_SSL_VERIFY=true #1035curl to the the htadmin container for use by the health check script #1029✅ Component version updates
netbox container) to v12.3.0 to address several security findings🧹 Code and project maintenance
📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.
LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded dataMalcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.
As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
##Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.
If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.
https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.1
✨ Features and enhancements
spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865system-quickstart detect and prepopulate existing time synchronization settings when rerun #992🛡️ Security Remediation & Hardening
🐛 Bug fixes
opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containersKEYCLOAK_SSL_VERIFY=true #1035curl to the the htadmin container for use by the health check script #1029✅ Component version updates
netbox container) to v12.3.0 to address several security findings🧹 Code and project maintenance
📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.
LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded dataMalcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.
As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
##Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.
If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.
https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.1
✨ Features and enhancements
spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865system-quickstart detect and prepopulate existing time synchronization settings when rerun #992🛡️ Security Remediation & Hardening
🐛 Bug fixes
opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containersKEYCLOAK_SSL_VERIFY=true #1035curl to the the htadmin container for use by the health check script #1029✅ Component version updates
netbox container) to v12.3.0 to address several security findings🧹 Code and project maintenance
📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.
LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded dataMalcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.
As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
##Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.
If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.
https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.1
✨ Features and enhancements
spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865system-quickstart detect and prepopulate existing time synchronization settings when rerun #992🛡️ Security Remediation & Hardening
🐛 Bug fixes
opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containersKEYCLOAK_SSL_VERIFY=true #1035curl to the the htadmin container for use by the health check script #1029✅ Component version updates
netbox container) to v12.3.0 to address several security findings🧹 Code and project maintenance
📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.
LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded dataMalcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.
As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
##Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.
If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.
https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.1
✨ Features and enhancements
spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865system-quickstart detect and prepopulate existing time synchronization settings when rerun #992🛡️ Security Remediation & Hardening
🐛 Bug fixes
opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containersKEYCLOAK_SSL_VERIFY=true #1035curl to the the htadmin container for use by the health check script #1029✅ Component version updates
netbox container) to v12.3.0 to address several security findings🧹 Code and project maintenance
📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.
LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded dataMalcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.
As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
##Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.
If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.
https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.1
✨ Features and enhancements
spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865system-quickstart detect and prepopulate existing time synchronization settings when rerun #992🛡️ Security Remediation & Hardening
🐛 Bug fixes
opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containersKEYCLOAK_SSL_VERIFY=true #1035curl to the the htadmin container for use by the health check script #1029✅ Component version updates
netbox container) to v12.3.0 to address several security findings🧹 Code and project maintenance
📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.
LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded dataMalcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.
As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
##Hackers Exploit Windmill Flaw to Read Server Files Without Authentication
A critical security flaw in Windmill, tracked as CVE-2026-29059, has left around 170 instances across 24 countries vulnerable to hackers who can exploit it to read server files without needing login credentials. This bug, which was fixed in January 2026, allows attackers to access arbitrary files…
#UnauthenticatedPathTraversal #Windmill #Cve202629059 #EmergingThreats #VulnerabilityExploitation
##Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. https://radar.offseq.com/threat/gitea-public-only-repository-tokens-can-update-private-pr-head-branches-cve-2026-58443-d058444d84b9595a #OffSeq #Gitea #Vuln #CVE202658443
##Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. https://radar.offseq.com/threat/gitea-public-only-repository-tokens-can-update-private-pr-head-branches-cve-2026-58443-d058444d84b9595a #OffSeq #Gitea #Vuln #CVE202658443
##Gitea vulnerability CVE-2026-58443 (CVSS 9.6) lets public-only tokens write to private repos. Details and PoC code are public. Update to v1.27.0.
#Gitea #CVE202658443 #DevSecOps #PoC #InfoSec
https://securityonline.info/gitea-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
##🟠 CVE-2026-56819 - High (7.5)
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `D...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56819/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Zimbra ZCS 10.1.20 patches CRITICAL vulnerabilities: command injection, XSS, mail forwarding bypass (CVE-2026-50055), EWS access flaws, SSRF. No attacks seen yet. Update ASAP to secure servers. https://radar.offseq.com/threat/zimbra-update-patches-critical-vulnerabilities-8b90415ad76d6649 #OffSeq #Zimbra #InfoSec #Vuln
##FreeScout (<1.8.224) has a CRITICAL vuln (CVE-2026-53595, CVSS 9.4): improper invite_hash handling lets unauthenticated attackers overwrite + access the lowest-id activated user account. Patch to 1.8.224. Details: https://radar.offseq.com/threat/cve-2026-53595-cwe-178-improper-handling-of-case-sensitivity-in-freescout-help-desk-freescout-3a27bed6e9e122c1 #OffSeq #CVE202653595 #infosec #vuln
##🔴 CVE-2026-53595 - Critical (9.4)
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account solely by its `...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53595/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-53591 - High (8.6)
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53591/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55544 - High (7.6)
NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using user-generated Bearer API tokens (`nxtc__...`). The application has ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55544/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47129 - High (8.1)
NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the `activateUser` and `deactivateUser` Next.js Server Actions of NextCRM. The application fails t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47129/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63429 - High (8.6)
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous internet user ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63429/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##1 posts
2 repos
Faille dans 7-Zip : pourquoi vous devriez installer la version 26.02 sans attendre https://www.it-connect.fr/7-zip-26-02-faille-rce-cve-2026-14266/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: https://radar.offseq.com/threat/cve-2026-42566-cwe-20-improper-input-validation-in-meshtastic-firmware-f4cb4608f8fc25f1 #OffSeq #infosec #CVE #IoTSecurity
##🟠 CVE-2026-42566 - High (7.5)
Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42566/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-44359 - Critical (10)
Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44359/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Meshtastic firmware (pre-2.7.21.1370b23) has a CRITICAL code injection flaw (CVE-2026-44359) in GitHub Actions (main_matrix.yml), risking repo secrets & supply chain compromise. Patch ASAP. https://radar.offseq.com/threat/cve-2026-44359-cwe-94-improper-control-of-generation-of-code-code-injection-in-meshtastic-firmware-dde9440ad0d78135 #OffSeq #CVE202644359 #Infosec
##