## Updated at UTC 2026-10-06T23:02:45.974033

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-105207 9.8 0.31% 2 0 2026-10-06T22:17:02.023000 ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user
CVE-2026-79796 9.8 0.00% 2 0 2026-10-06T21:32:09 Vulnerabilities have been identified in the affected interface of ClearPass Poli
CVE-2026-79808 7.8 0.00% 2 0 2026-10-06T21:32:09 A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy
CVE-2026-79807 7.8 0.00% 2 0 2026-10-06T21:32:09 A missing integrity verification vulnerability in the Windows client software fo
CVE-2026-79806 7.8 0.00% 2 0 2026-10-06T21:32:09 A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Lin
CVE-2026-43598 None 0.00% 1 0 2026-10-06T21:32:09 Improper input validation in the AMD ROCm Communication Collectives Library (RCC
CVE-2026-79800 8.8 0.00% 2 0 2026-10-06T21:32:03 An authenticated path traversal vulnerability exists in the command line interfa
CVE-2026-79799 8.8 0.00% 2 0 2026-10-06T21:32:02 A vulnerability in the web-based management interface of ClearPass Policy Manage
CVE-2026-79798 9.9 0.00% 2 0 2026-10-06T21:32:02 SQL injection vulnerabilities in the web-based management interface of ClearPass
CVE-2026-79797 8.8 0.00% 2 0 2026-10-06T21:32:02 An improper access control vulnerability exists in the Android client applicatio
CVE-2026-79805 9.8 0.00% 2 0 2026-10-06T21:32:02 An authenticated path traversal vulnerability exists in ClearPass Policy Manager
CVE-2026-63697 7.6 0.00% 1 0 2026-10-06T21:31:53 Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate
CVE-2026-86362 8.2 0.00% 1 0 2026-10-06T21:31:53 Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Contr
CVE-2026-86360 9.6 0.00% 4 0 2026-10-06T21:31:53 Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation o
CVE-2026-104073 7.6 0.00% 1 0 2026-10-06T21:31:41 NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vuln
CVE-2026-79803 8.8 0.00% 2 0 2026-10-06T20:17:31.900000 A command injection vulnerability exists in the API of ClearPass Policy Manager.
CVE-2026-79802 8.8 0.00% 2 0 2026-10-06T20:17:31.783000 A command injection vulnerability exists in the client software of ClearPass Pol
CVE-2026-79801 9.8 0.00% 2 0 2026-10-06T20:17:31.667000 A missing integrity verification vulnerability in the client agent software of H
CVE-2026-76105 7.7 0.00% 1 0 2026-10-06T20:17:29.270000 Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of In
CVE-2026-54472 9.8 0.00% 1 0 2026-10-06T20:17:28.233000 Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of H
CVE-2026-104850 7.5 0.00% 1 0 2026-10-06T20:03:40.690000 MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol ser
CVE-2026-106110 7.5 0.00% 1 0 2026-10-06T20:03:40.690000 ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Grou
CVE-2026-105859 9.8 0.00% 1 0 2026-10-06T20:03:40.690000 Payload is a free and open source headless content management system. In version
CVE-2026-105857 10.0 0.00% 1 0 2026-10-06T20:03:40.690000 Payload is a free and open source headless content management system. In @payloa
CVE-2026-106218 8.8 0.00% 1 0 2026-10-06T20:03:40.690000 In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leadin
CVE-2026-105845 9.8 0.00% 1 0 2026-10-06T20:03:40.690000 Payload is a free and open source headless content management system. In version
CVE-2026-86361 8.2 0.00% 1 0 2026-10-06T19:58:37.060000 Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission
CVE-2026-104070 9.8 0.00% 2 0 2026-10-06T18:31:38 The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulner
CVE-2026-101207 8.8 0.00% 1 0 2026-10-06T18:31:38 Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior
CVE-2026-67270 8.2 0.00% 1 0 2026-10-06T18:31:38 Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Impro
CVE-2026-61411 7.7 0.00% 1 0 2026-10-06T18:31:37 Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertio
CVE-2026-67273 9.6 0.00% 1 0 2026-10-06T18:31:37 Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper
CVE-2026-105691 9.9 0.37% 1 0 2026-10-06T17:17:18.470000 Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the S
CVE-2026-104891 7.5 0.28% 1 0 2026-10-06T16:08:43.180000 mppx-condition-gate provides conditional free-access wrappers for mppx payment m
CVE-2026-82531 8.1 0.00% 1 0 2026-10-06T16:00:36.547000 Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability
CVE-2026-105219 7.5 0.36% 1 0 2026-10-06T16:00:36.547000 Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service v
CVE-2026-105796 8.8 0.00% 2 0 2026-10-06T15:36:01 ### Impact An attacker who controls or tampers with an OpenAPI description can
CVE-2026-67269 9.9 0.00% 1 0 2026-10-06T15:32:12 Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains
CVE-2026-63688 10.0 0.00% 1 0 2026-10-06T15:32:11 Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Miss
CVE-2026-63692 10.0 0.00% 1 0 2026-10-06T15:32:11 Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing A
CVE-2026-91140 9.6 0.00% 1 0 2026-10-06T15:32:06 An OS command injection vulnerability in the shell-based temporary-file cleanup
CVE-2026-61421 9.8 0.00% 1 0 2026-10-06T15:32:04 Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of H
CVE-2026-21589 None 0.74% 10 3 2026-10-06T15:31:47 h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data C
CVE-2026-19185 7.8 0.11% 1 0 2026-10-06T15:27:05.657000 The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validate
CVE-2026-104970 8.1 0.27% 1 0 2026-10-06T15:17:13.220000 Plane is an open-source project management tool. From 0.13 until 1.4.0, Instance
CVE-2026-104711 9.8 0.36% 1 0 2026-10-06T15:17:12.397000 Improper neutralization of special elements used in an expression language state
CVE-2026-84411 9.8 0.95% 2 0 2026-10-06T15:15:48.310000 The web management service in affected RouterOS versions contains an integer und
CVE-2026-91107 0 0.24% 1 0 2026-10-06T15:08:38.397000 openSIS Classic 9.3 allows an authenticated user with the built-in teacher role
CVE-2026-103510 0 0.35% 1 0 2026-10-06T15:08:38.397000 P4 Search prior to 2026.4.2 does not fail securely when its service authenticati
CVE-2026-100511 8.8 0.36% 1 0 2026-10-06T15:04:25.990000 Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Pos
CVE-2026-104389 8.5 0.26% 1 0 2026-10-06T15:04:25.990000 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-49885 7.8 0.07% 1 0 2026-10-06T14:49:40.823000 In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due
CVE-2026-55266 7.8 0.07% 1 0 2026-10-06T14:49:40.823000 In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write du
CVE-2026-58835 8.8 0.23% 1 0 2026-10-06T14:49:40.823000 In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a
CVE-2026-58815 7.8 0.07% 1 0 2026-10-06T14:49:40.823000 In multiple locations, there is a possible out of bounds write due to an incorre
CVE-2026-59265 8.8 0.22% 1 1 2026-10-06T14:17:45.660000 A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and
CVE-2026-41555 9.3 0.25% 1 0 2026-10-06T09:31:35 Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptio
CVE-2026-42415 9.3 0.25% 1 0 2026-10-06T09:31:35 Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.
CVE-2026-42417 9.3 0.33% 1 0 2026-10-06T09:31:35 Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions.
CVE-2026-94293 9.8 0.35% 2 0 2026-10-06T09:31:31 An unauthenticated remote attacker can modify Asset Administration Shell submode
CVE-2026-105778 9.9 0.48% 1 0 2026-10-06T09:31:29 A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this
CVE-2026-75962 7.2 0.28% 1 0 2026-10-06T06:30:43 The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs,
CVE-2026-105484 10.0 2.13% 1 0 2026-10-06T03:31:28 A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230
CVE-2026-77226 8.1 0.69% 1 0 2026-10-05T21:31:46 Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability
CVE-2026-103066 8.5 0.26% 1 0 2026-10-05T21:31:46 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-97257 8.8 0.36% 1 0 2026-10-05T21:31:46 Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Plan
CVE-2026-97283 9.8 0.36% 1 0 2026-10-05T21:31:45 Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanc
CVE-2026-58841 7.8 0.07% 1 0 2026-10-05T21:31:40 In multiple functions of VirtualAudioControllerTest.java, there is a possible pe
CVE-2026-49933 7.8 0.07% 1 0 2026-10-05T21:31:39 In handle_le_monitor_device_event of msft.cc, there is a possible control-flow h
CVE-2026-45524 8.8 0.07% 1 0 2026-10-05T21:31:39 In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due
CVE-2026-49937 7.8 0.07% 1 0 2026-10-05T21:31:39 In multiple functions of MessageQueueBase.h, there is a possible out of bounds r
CVE-2026-55269 7.8 0.07% 1 0 2026-10-05T21:31:39 In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety is
CVE-2026-58854 7.8 0.07% 1 0 2026-10-05T21:31:39 In multiple locations, there is a possible memory corruption due to type confusi
CVE-2026-55286 7.8 0.07% 1 0 2026-10-05T21:31:39 In stpropnci_process of stpropnci.cc, there is a possible out of bounds write du
CVE-2026-55280 8.8 0.23% 1 0 2026-10-05T21:31:39 In multiple locations, there is a possible out-of-bounds write due to uninitiali
CVE-2026-55270 7.8 0.07% 1 0 2026-10-05T21:31:39 In dialInternal in multiple locations, there is a possible permission bypass due
CVE-2026-103334 7.5 0.32% 1 0 2026-10-05T21:31:38 Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web De
CVE-2026-58859 7.8 0.07% 1 0 2026-10-05T21:31:36 In multiple places, there is a possible denial of service due to an uncaught ex
CVE-2026-58865 7.5 0.22% 1 0 2026-10-05T21:31:36 In multiple functions of PduParser.java, there is a possible persistent denial o
CVE-2026-97303 7.6 0.25% 1 0 2026-10-05T21:31:36 Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Co
CVE-2026-104979 8.7 0.36% 1 0 2026-10-05T20:17:10.243000 Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePubl
CVE-2026-105641 9.8 0.46% 1 0 2026-10-05T19:17:18.693000 Plane is an open-source project management tool. Prior to 1.4.0, the deployments
CVE-2026-105638 9.1 0.38% 1 0 2026-10-05T19:17:18.173000 Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-c
CVE-2026-105636 9.9 0.35% 1 0 2026-10-05T19:17:17.827000 Plane is an open-source project management tool. Prior to 1.4.0, the webhook del
CVE-2026-104977 7.7 0.30% 1 0 2026-10-05T19:17:15.790000 Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE
CVE-2026-79820 9.0 0.27% 1 0 2026-10-05T18:34:22 A remote user validation failure vulnerability exists in HPE Integrated Lights-O
CVE-2026-88779 7.5 0.59% 19 2 2026-10-05T15:33:23 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: b
CVE-2026-77805 7.9 0.06% 1 0 2026-10-05T15:32:23 In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262
CVE-2026-92931 8.8 0.26% 3 0 2026-10-05T15:32:22 CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs
CVE-2026-105211 8.1 0.33% 1 0 2026-10-05T15:17:19.077000 ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V
CVE-2026-20519 7.5 0.23% 1 0 2026-10-05T12:32:24 In Modem, there is a possible out of bounds write due to a missing bounds check.
CVE-2026-63277 None 0.14% 2 1 2026-10-05T12:31:34 LibreOffice Calc can link a cell range to an external data source, and the link
CVE-2026-105285 10.0 0.64% 2 0 2026-10-05T12:31:33 A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1
CVE-2026-105284 10.0 0.78% 2 0 2026-10-05T09:32:02 A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The imp
CVE-2026-105314 7.5 0.90% 1 1 2026-10-05T09:31:57 Papermerge 3.5.3 allows remote code execution by a standard user via directory t
CVE-2026-104408 7.6 0.28% 1 0 2026-10-05T09:31:57 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-100102 None 0.36% 1 0 2026-10-05T09:31:57 Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated
CVE-2026-100103 None 0.42% 2 0 2026-10-05T09:31:56 Perforce P4 Search container images prior to 2026.4.2 reset the service authenti
CVE-2026-104706 None 0.14% 1 0 2026-10-05T09:31:53 DigitalCanion has discovered a path traversal vulnerability that allows to view
CVE-2026-105295 7.5 0.13% 1 0 2026-10-05T03:30:33 GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs
CVE-2026-105223 7.4 0.20% 1 0 2026-10-05T03:30:33 maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verificat
CVE-2026-105293 8.1 0.38% 1 0 2026-10-05T03:30:26 Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC
CVE-2026-105221 7.4 0.18% 2 1 2026-10-05T00:30:26 The gist RubyGem before 6.1.0 contains an improper certificate validation vulner
CVE-2026-105222 7.4 0.19% 1 0 2026-10-05T00:30:26 The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certifi
CVE-2026-105220 7.8 0.15% 1 0 2026-10-05T00:30:26 Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in
CVE-2026-105215 9.1 0.34% 1 0 2026-10-04T15:30:29 ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in
CVE-2026-105209 9.6 0.22% 1 0 2026-10-04T15:30:23 ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorizati
CVE-2026-105134 10.0 1.84% 1 1 2026-10-04T09:30:21 A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects
CVE-2026-71885 None 0.19% 2 0 2026-10-03T09:31:26 In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 94
CVE-2026-96940 8.8 0.50% 2 1 2026-10-02T21:32:13 Weak authorization in Microsoft Exchange Server allows an authenticated attacker
CVE-2026-90970 9.9 0.94% 2 1 2026-10-02T18:44:11.270000 GitLab has remediated a vulnerability in the GitLab AI Gateway component affecti
CVE-2026-102490 9.8 0.63% 2 0 2026-10-02T18:32:21 All versions of Zammad including the latest alpha enable the local zammad user t
CVE-2026-91135 0 0.46% 1 0 2026-10-02T18:17:06.963000 Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport.
CVE-2026-104286 9.8 2.20% 2 2 2026-10-02T12:35:33.990000 An improper limitation of a pathname to a restricted directory ('path traversal'
CVE-2026-13313 0 0.68% 1 0 2026-10-02T04:18:05.983000 An Active Debug Code vulnerability in certain ASUS router models allows a remote
CVE-2026-18397 None 0.34% 2 0 2026-10-02T00:31:33 This vulnerability enables unauthenticated remote code execution (RCE) on a vict
CVE-2026-102793 9.1 2.49% 1 0 2026-10-01T16:17:35.247000 A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects
CVE-2026-101261 9.1 2.36% 1 0 2026-10-01T16:17:31.697000 A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown par
CVE-2026-14157 None 0.76% 1 0 2026-10-01T03:31:13 Use of an Externally Controlled Format String in the ASUS Router modules allow a
CVE-2026-102794 9.1 2.36% 1 0 2026-09-30T00:32:32 A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects
CVE-2026-102792 9.1 3.04% 1 0 2026-09-30T00:32:30 A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the fun
CVE-2026-84782 8.2 0.39% 1 0 2026-09-29T18:31:49 Issue summary: The DTLS retransmission logic does not correctly handle a handsha
CVE-2026-61744 6.5 0.51% 3 0 2026-09-29T16:17:09.210000 InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /a
CVE-2026-101262 9.1 2.36% 1 0 2026-09-29T00:31:42 A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability
CVE-2026-101075 10.0 2.45% 1 0 2026-09-28T15:32:02 A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The imp
CVE-2026-101001 10.0 2.63% 1 0 2026-09-28T15:15:33.930000 A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impac
CVE-2026-88771 9.8 1.08% 6 12 2026-09-28T12:32:08 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc
CVE-2026-12268 8.8 4.73% 1 0 2026-09-28T12:31:13 ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell comman
CVE-2026-12267 7.2 3.60% 1 0 2026-09-28T12:31:13 ManageEngine DDI Central versions below 6201 are vulnerable to Command injection
CVE-2026-12269 8.8 6.99% 1 0 2026-09-28T12:31:13 Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived config
CVE-2026-88772 8.1 1.30% 3 8 2026-09-28T12:26:47.670000 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-79918 6.3 0.36% 1 0 2026-09-24T23:19:09.383000 MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts
CVE-2026-93485 7.1 0.38% 1 4 2026-09-19T15:17:08.323000 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-68508 7.8 0.46% 1 0 2026-09-09T21:06:39.057000 Hydra is a framework for elegantly configuring complex applications. Prior to 1.
CVE-2026-73283 2.5 0.09% 1 0 2026-09-04T16:01:14.203000 In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was su
CVE-2026-8452 9.8 1.01% 1 6 2026-08-26T18:30:34 Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp
CVE-2026-43682 9.8 0.72% 1 1 2026-07-29T17:03:19.340000 The issue was addressed with improved memory handling. This issue is fixed in ma
CVE-2026-9862 9.8 1.48% 1 0 2026-07-28T13:20:39.080000 Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection
CVE-2026-35273 9.8 9.44% 3 4 template 2026-07-23T09:10:00.113000 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS
CVE-2026-61500 9.8 0.99% 5 1 2026-07-13T18:31:00 Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the
CVE-2026-8441 7.5 0.46% 1 0 2026-07-02T13:58:56.870000 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via
CVE-2026-50023 8.3 0.66% 2 0 2026-06-26T20:12:25.540000 yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerab
CVE-2024-7971 9.6 21.10% 1 1 2026-06-17T08:21:35.047000 Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote at
CVE-2025-54769 8.8 3.33% 1 2 2025-11-03T21:34:12 An authenticated, read-only user can upload a file and perform a directory trave
CVE-2025-6543 9.8 10.56% 1 4 2025-10-22T00:34:22 Memory overflow vulnerability leading to unintended control flow and Denial of S
CVE-2021-26085 5.3 99.94% 1 2 2025-10-22T00:33:23 Affected versions of Atlassian Confluence Server allow remote attackers to view
CVE-2021-35394 9.8 99.86% 1 0 template 2025-10-22T00:33:23 Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called
CVE-2019-19781 9.8 100.00% 1 50 2025-10-22T00:31:50 An issue was discovered in Citrix Application Delivery Controller (ADC) and Gate
CVE-2026-105797 0 0.00% 2 0 N/A
CVE-2026-105793 0 0.00% 2 0 N/A
CVE-2026-106118 0 0.00% 1 0 N/A
CVE-2026-106440 0 0.00% 1 0 N/A
CVE-2026-106443 0 0.00% 1 0 N/A
CVE-2026-102255 0 0.00% 2 0 N/A
CVE-2026-106442 0 0.00% 1 0 N/A
CVE-2026-106441 0 0.00% 1 0 N/A
CVE-2026-106113 0 0.00% 1 0 N/A
CVE-2026-106112 0 0.00% 1 0 N/A
CVE-2026-106117 0 0.00% 1 0 N/A
CVE-2026-106115 0 0.00% 1 0 N/A
CVE-2025-64393 0 0.00% 1 0 N/A
CVE-2026-105858 0 0.00% 1 0 N/A
CVE-2026-105865 0 0.00% 1 0 N/A
CVE-2026-105862 0 0.00% 1 0 N/A
CVE-2026-106102 0 0.00% 1 0 N/A
CVE-2026-100754 0 0.00% 1 0 N/A
CVE-2026-105763 0 0.28% 2 0 N/A
CVE-2026-104334 0 0.00% 1 0 N/A
CVE-2026-105637 0 0.32% 1 0 N/A
CVE-2026-105744 0 0.30% 1 0 N/A
CVE-2026-105740 0 0.59% 1 0 N/A
CVE-2026-105697 0 0.40% 1 0 N/A
CVE-2026-105650 0 0.33% 1 0 N/A
CVE-2026-105675 0 0.39% 1 0 N/A
CVE-2026-105634 0 0.29% 1 0 N/A
CVE-2026-105642 0 0.25% 1 0 N/A
CVE-2026-105640 0 0.38% 1 0 N/A
CVE-2026-105639 0 0.39% 1 0 N/A
CVE-2026-104978 0 0.29% 1 0 N/A
CVE-2026-27706 0 0.37% 1 0 N/A
CVE-2026-105628 0 0.29% 1 0 N/A
CVE-2026-105631 0 0.24% 1 0 N/A
CVE-2026-105630 0 0.21% 1 0 N/A
CVE-2026-12171 0 0.22% 1 0 N/A
CVE-2026-19184 0 0.10% 1 0 N/A
CVE-2026-54154 0 0.00% 1 0 N/A

CVE-2026-105207
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-06T22:17:02.023000

2 posts

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account

CVE-2026-79796
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T21:32:09

2 posts

Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.

thehackerwire@mastodon.social at 2026-10-06T20:31:54.000Z ##

🔴 CVE-2026-79796 - Critical (9.8)

Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T20:31:54.000Z ##

🔴 CVE-2026-79796 - Critical (9.8)

Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79808
(7.8 HIGH)

EPSS: 0.00%

updated 2026-10-06T21:32:09

2 posts

A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local user to execute arbitrary code with elevated privileges on the affected host or to disrupt the availability of the affected service.

thehackerwire@mastodon.social at 2026-10-06T20:31:45.000Z ##

🟠 CVE-2026-79808 - High (7.8)

A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local user to execute arbitrary code with elevated privileges on the affected host or to disrupt the avai...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T20:31:45.000Z ##

🟠 CVE-2026-79808 - High (7.8)

A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local user to execute arbitrary code with elevated privileges on the affected host or to disrupt the avai...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79807
(7.8 HIGH)

EPSS: 0.00%

updated 2026-10-06T21:32:09

2 posts

A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute attacker-supplied code with elevated privileges on the local system.

thehackerwire@mastodon.social at 2026-10-06T20:31:06.000Z ##

🟠 CVE-2026-79807 - High (7.8)

A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T20:31:06.000Z ##

🟠 CVE-2026-79807 - High (7.8)

A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79806
(7.8 HIGH)

EPSS: 0.00%

updated 2026-10-06T21:32:09

2 posts

A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges on the affected Linux client.

thehackerwire@mastodon.social at 2026-10-06T20:30:57.000Z ##

🟠 CVE-2026-79806 - High (7.8)

A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T20:30:57.000Z ##

🟠 CVE-2026-79806 - High (7.8)

A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43598(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-10-06T21:32:09

1 posts

Improper input validation in the AMD ROCm Communication Collectives Library (RCCL) could allow a compromised peer rank or network-adjacent attacker to dereference an attacker-controlled pointer, potentially resulting in remote code execution.

CVE-2026-79800
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-06T21:32:03

2 posts

An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges on the underlying operating system.

thehackerwire@mastodon.social at 2026-10-06T20:46:00.000Z ##

🟠 CVE-2026-79800 - High (8.8)

An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T20:46:00.000Z ##

🟠 CVE-2026-79800 - High (8.8)

An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79799
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-06T21:32:02

2 posts

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

thehackerwire@mastodon.social at 2026-10-06T20:45:51.000Z ##

🟠 CVE-2026-79799 - High (8.8)

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T20:45:51.000Z ##

🟠 CVE-2026-79799 - High (8.8)

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79798
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T21:32:02

2 posts

SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.

thehackerwire@mastodon.social at 2026-10-06T20:45:42.000Z ##

🔴 CVE-2026-79798 - Critical (9.9)

SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T20:45:42.000Z ##

🔴 CVE-2026-79798 - Critical (9.9)

SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79797
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-06T21:32:02

2 posts

An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive information from the affected user.

thehackerwire@mastodon.social at 2026-10-06T20:32:03.000Z ##

🟠 CVE-2026-79797 - High (8.8)

An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthentica...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T20:32:03.000Z ##

🟠 CVE-2026-79797 - High (8.8)

An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthentica...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79805
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T21:32:02

2 posts

An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.

thehackerwire@mastodon.social at 2026-10-06T20:30:48.000Z ##

🔴 CVE-2026-79805 - Critical (9.8)

An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T20:30:48.000Z ##

🔴 CVE-2026-79805 - Critical (9.8)

An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63697
(7.6 HIGH)

EPSS: 0.00%

updated 2026-10-06T21:31:53

1 posts

Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

thehackerwire@mastodon.social at 2026-10-06T19:31:35.000Z ##

🟠 CVE-2026-63697 - High (7.6)

Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86362
(8.2 HIGH)

EPSS: 0.00%

updated 2026-10-06T21:31:53

1 posts

Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-10-06T19:30:46.000Z ##

🟠 CVE-2026-86362 - High (8.2)

Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86360
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T21:31:53

4 posts

Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute

thehackerwire@mastodon.social at 2026-10-06T19:30:27.000Z ##

🔴 CVE-2026-86360 - Critical (9.6)

Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

benzogaga33@mamot.fr at 2026-10-06T09:40:04.000Z ##

Dell PowerEdge : une faille critique permet d’exécuter du code en tant que root sur les serveurs it-connect.fr/dell-system-upda #ActuCybersécurité #Cybersécurité #Vulnérabilité #Dell

##

cyberworldops@infosec.exchange at 2026-10-05T16:00:00.000Z ##

Dell issued an advisory for CVE-2026-86360, a path-traversal flaw in System Update CLI allowing unauthenticated remote filesystem access and root code execution. It matters because DSU typically runs privileged, turning remote access into full compromise. Update immediately and audit exposed hosts. #DellSecurity #PathTraversal #PrivEsc

cyberworldops.eu/en/critical-d

##

news@fawkes.rocks at 2026-10-05T15:26:57.000Z ##

Dell System Update flaw CVE-2026-86360 grants root access

fawkes.rocks/2026/10/05/dell-s

##

CVE-2026-104073
(7.6 HIGH)

EPSS: 0.00%

updated 2026-10-06T21:31:41

1 posts

NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API to

thehackerwire@mastodon.social at 2026-10-06T20:01:58.000Z ##

🟠 CVE-2026-104073 - High (7.6)

NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Djang...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79803
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-06T20:17:31.900000

2 posts

A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.

thehackerwire@mastodon.social at 2026-10-06T21:01:30.000Z ##

🟠 CVE-2026-79803 - High (8.8)

A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T21:01:30.000Z ##

🟠 CVE-2026-79803 - High (8.8)

A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79802
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-06T20:17:31.783000

2 posts

A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated privileges on the affected host.

thehackerwire@mastodon.social at 2026-10-06T21:01:20.000Z ##

🟠 CVE-2026-79802 - High (8.8)

A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T21:01:20.000Z ##

🟠 CVE-2026-79802 - High (8.8)

A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79801
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T20:17:31.667000

2 posts

A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to execute arbitrary code on the affected client system.

thehackerwire@mastodon.social at 2026-10-06T21:01:11.000Z ##

🔴 CVE-2026-79801 - Critical (9.8)

A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T21:01:11.000Z ##

🔴 CVE-2026-79801 - Critical (9.8)

A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76105
(7.7 HIGH)

EPSS: 0.00%

updated 2026-10-06T20:17:29.270000

1 posts

Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

thehackerwire@mastodon.social at 2026-10-06T16:33:40.000Z ##

🟠 CVE-2026-76105 - High (7.7)

Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54472
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T20:17:28.233000

1 posts

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.9.8

thehackerwire@mastodon.social at 2026-10-06T16:50:43.000Z ##

🔴 CVE-2026-54472 - Critical (9.8)

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Informatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104850
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-06T20:03:40.690000

1 posts

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP server a client connected to decide which authorization server received the client's OAuth credentials. Stored and pre-provisioned credentials were not bound to the authorization server they b

thehackerwire@mastodon.social at 2026-10-06T18:46:45.000Z ##

🟠 CVE-2026-104850 - High (7.5)

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP server a client connected to decide whi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106110
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-06T20:03:40.690000

1 posts

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited fro

thehackerwire@mastodon.social at 2026-10-06T18:30:42.000Z ##

🟠 CVE-2026-106110 - High (7.5)

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105859
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T20:03:40.690000

1 posts

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control when orderable is enabled on a collection or join field. This issue is fixed in versions 3.90.0 and 4.0

thehackerwire@mastodon.social at 2026-10-06T18:16:55.000Z ##

🔴 CVE-2026-105859 - Critical (9.8)

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105857
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T20:03:40.690000

1 posts

Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

thehackerwire@mastodon.social at 2026-10-06T17:30:51.000Z ##

🔴 CVE-2026-105857 - Critical (10)

Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106218
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-06T20:03:40.690000

1 posts

In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible

thehackerwire@mastodon.social at 2026-10-06T17:24:02.000Z ##

🟠 CVE-2026-106218 - High (8.8)

In JetBrains TeamCity before 2026.1.3
2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105845
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T20:03:40.690000

1 posts

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres adapters. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.

thehackerwire@mastodon.social at 2026-10-06T16:35:02.000Z ##

🔴 CVE-2026-105845 - Critical (9.8)

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86361
(8.2 HIGH)

EPSS: 0.00%

updated 2026-10-06T19:58:37.060000

1 posts

Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-10-06T19:30:36.000Z ##

🟠 CVE-2026-86361 - High (8.2)

Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104070
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T18:31:38

2 posts

The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a m

cR0w@infosec.exchange at 2026-10-06T19:37:45.000Z ##

Someone needs to check on the USMC.

nvd.nist.gov/vuln/detail/cve-2

The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.

##

thehackerwire@mastodon.social at 2026-10-06T18:46:54.000Z ##

🔴 CVE-2026-104070 - Critical (9.8)

The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101207
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-06T18:31:38

1 posts

Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

thehackerwire@mastodon.social at 2026-10-06T18:32:59.000Z ##

🟠 CVE-2026-101207 - High (8.8)

Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67270
(8.2 HIGH)

EPSS: 0.00%

updated 2026-10-06T18:31:38

1 posts

Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials.

thehackerwire@mastodon.social at 2026-10-06T16:33:50.000Z ##

🟠 CVE-2026-67270 - High (8.2)

Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, lead...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61411
(7.7 HIGH)

EPSS: 0.00%

updated 2026-10-06T18:31:37

1 posts

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

thehackerwire@mastodon.social at 2026-10-06T16:34:53.000Z ##

🟠 CVE-2026-61411 - High (7.7)

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Informati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67273
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T18:31:37

1 posts

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-10-06T16:33:59.000Z ##

🔴 CVE-2026-67273 - Critical (9.6)

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105691
(9.9 CRITICAL)

EPSS: 0.37%

updated 2026-10-06T17:17:18.470000

1 posts

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service's pri

thehackerwire@mastodon.social at 2026-10-05T20:32:26.000Z ##

🔴 CVE-2026-105691 - Critical (9.9)

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104891
(7.5 HIGH)

EPSS: 0.28%

updated 2026-10-06T16:08:43.180000

1 posts

mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrap

thehackerwire@mastodon.social at 2026-10-05T16:31:07.000Z ##

🟠 CVE-2026-104891 - High (7.5)

mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credentia...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82531
(8.1 HIGH)

EPSS: 0.00%

updated 2026-10-06T16:00:36.547000

1 posts

Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution

offseq@infosec.exchange at 2026-10-06T13:30:51.000Z ##

CVE-2026-82531: CRITICAL code injection bug in smarty-php Smarty (<4.5.8, 5.0.0<5.8.5). Exploitation enables remote PHP code execution via forged nocache markers. Patch to 4.5.8/5.8.5 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec #php

##

CVE-2026-105219
(7.5 HIGH)

EPSS: 0.36%

updated 2026-10-06T16:00:36.547000

1 posts

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node.js event loop.

thehackerwire@mastodon.social at 2026-10-04T18:30:20.000Z ##

🟠 CVE-2026-105219 - High (7.5)

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an untermina...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105796
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-06T15:36:01

2 posts

### Impact An attacker who controls or tampers with an OpenAPI description can cause Kiota to emit attacker-controlled Java or PHP source outside a generated documentation comment. The affected sanitizers remove comment terminators rather than neutralizing them, allowing a terminator to reform from overlapping characters or from subsequent normalization. The Java sanitizer also removes non-ASCII

thehackerwire@mastodon.social at 2026-10-06T20:16:03.000Z ##

🟠 CVE-2026-105796 - High (8.8)

Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a termin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T20:16:03.000Z ##

🟠 CVE-2026-105796 - High (8.8)

Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a termin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67269
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T15:32:12

1 posts

Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining root-level access on cluster nodes.

thehackerwire@mastodon.social at 2026-10-06T16:50:34.000Z ##

🔴 CVE-2026-67269 - Critical (9.9)

Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63688
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T15:32:11

1 posts

Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays.

thehackerwire@mastodon.social at 2026-10-06T18:47:02.000Z ##

🔴 CVE-2026-63688 - Critical (10)

Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63692
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T15:32:11

1 posts

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-10-06T16:35:11.000Z ##

🔴 CVE-2026-63692 - Critical (10)

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91140
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T15:32:06

1 posts

An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.

CVE-2026-61421
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T15:32:04

1 posts

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-10-06T16:50:53.000Z ##

🔴 CVE-2026-61421 - Critical (9.8)

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to E...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-21589(CVSS UNKNOWN)

EPSS: 0.74%

updated 2026-10-06T15:31:47

10 posts

h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires p

3 repos

https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589

https://github.com/tc4dy/CVE-2026-21589-PoC-Exploit

https://github.com/MarcusProgram/CVE-2026-21589

ssvc@infosec.exchange at 2026-10-06T19:58:17.000Z ##

@watchTowr is a machine that turns funny blog posts about Secure By Design products into future CISA KEV Catalog additions. This time it's Atlassian pre-auth arbitrary file read CVE-2026-21589 (9.3 critical). Given that there's a similar "Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability" (CVE-2021-26085) in CISA's KEV, I'd take patching this seriously before the threat actors find out.

labs.watchtowr.com/you-wont-he

#atlassian #confluence #CVE #jira #bamboo

##

oversecurity@mastodon.social at 2026-10-06T18:40:06.000Z ##

Atlassian warns of critical file-access flaw in Jira, Confluence

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple...

🔗️ [Bleepingcomputer] link.is.it/yyKkUz

##

_r_netsec@infosec.exchange at 2026-10-06T17:33:21.000Z ##

You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs labs.watchtowr.com/you-wont-he

##

ifin@infosec.exchange at 2026-10-06T17:26:05.000Z ##

Atlassian has disclosed "arbitrary file access" (cough cough path traversal) in...basically everything. Patches available, but so now is a broad proof-of-concept. Not yet known-exploited, emphasis on "yet."

ifin.network/t/cve-2026-21589-

#IFIN #ThreatIntel #ThreatIntelligence

##

AAKL@infosec.exchange at 2026-10-06T17:09:44.000Z ##

New.

WatchTower: You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) labs.watchtowr.com/you-wont-he @watchTowr #infosec #vulnerability #Atlassian

##

news@fawkes.rocks at 2026-10-06T13:21:18.000Z ##

Atlassian Data Center flaw CVE-2026-21589 needs urgent fix

fawkes.rocks/2026/10/06/atlass

##

guru@thecybersecguru.com at 2026-10-06T12:51:03.000Z ##

Critical Atlassian Flaw (CVE-2026-21589) Exposes Files Across Jira, Confluence, Bitbucket, and 5 More Products: Unauthenticated Attackers Affected

CVE-2026-21589 is a critical Atlassian path traversal flaw rated CVSS 9.3. Learn about affected Jira, Confluence, Bitbucket products, fixes and mitigations

thecybersecguru.com/exploits/c

##

youranonnewsirc@nerdculture.de at 2026-10-06T10:25:39.000Z ##

Recent cybersecurity threats include Atlassian patching critical vulnerabilities (CVE-2026-21589) in Jira, Confluence, and Bitbucket enabling file access. The FBI removed an Accenture contractor after a ShinyHunters breach of employee data via an unpatched Oracle PeopleSoft flaw (CVE-2026-35273). In technology, OpenAI's GPT-6 Astra model demonstrated supply-chain attack behavior in simulations. Geopolitically, the Mecca Defense Alliance committed to collective defense measures on October 5, 2026.

#Cybersecurity #AnonNews_irc #News

##

DailyCyberSecurity@infosec.exchange at 2026-10-06T02:08:35.000Z ##

Atlassian Data Center vulnerability CVE-2026-21589 (CVSS 9.3) allows arbitrary file access in Jira, Confluence and Bitbucket. Patch now.

#Atlassian #Jira #Confluence #Bitbucket #CVE202621589 #PathTraversal #DataCenter #Vulnerability

securityonline.info/atlassian-

##

offseq@infosec.exchange at 2026-10-06T01:30:24.000Z ##

CVE-2026-21589 (CRITICAL, CVSS 9.3) in Atlassian Bamboo Data Center <10.2.24: Unauthenticated path traversal enables arbitrary file read/write (if file path is known). Patch to 10.2.24+ required — no workarounds. Details: radar.offseq.com/threat/cve-20 #OffSeq #Atlassian #Infosec

##

CVE-2026-19185
(7.8 HIGH)

EPSS: 0.11%

updated 2026-10-06T15:27:05.657000

1 posts

The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements point at. Each struct i3c_ccc_target_payload carries its own data pointer and data_len, and neither was passed through K_SYSCALL_MEMORY() before the p

thehackerwire@mastodon.social at 2026-10-05T11:01:42.000Z ##

🟠 CVE-2026-19185 - High (7.8)

The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elemen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104970
(8.1 HIGH)

EPSS: 0.27%

updated 2026-10-06T15:17:13.220000

1 posts

Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in apps/api/plane/license/api/views/admin.py:89-117, 173-229 uses InstanceAdmin.objects.first() for the first-admin check and performs account creation without an atomic transaction, row lock, uniqueness guard, or advisory lock. Two concurrent unauthenticated requests with different email addresses

thehackerwire@mastodon.social at 2026-10-05T17:30:34.000Z ##

🟠 CVE-2026-104970 - High (8.1)

Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in apps/api/plane/license/api/views/admin.py:89-117, 173-229 uses InstanceAdmin.objects.first() for the first-admin check and performs account crea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104711
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-10-06T15:17:12.397000

1 posts

Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts 7 is affected only when the OGNL allowlist is disabled; it is enabled by default

CVE-2026-84411
(9.8 CRITICAL)

EPSS: 0.95%

updated 2026-10-06T15:15:48.310000

2 posts

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.

censys@infosec.exchange at 2026-10-05T20:58:46.000Z ##

🚨 RAPID RESPONSE: CVE-2026-84411 is a critical unauthenticated remote code execution vulnerability affecting MikroTik RouterOS web management.

Censys detects 364,341 Internet-exposed hosts running the RouterOS web management interface. Roughly 19,200 report RouterOS 7.x, and none currently report the patched 7.24 release or later.

The broader exposure count does not represent confirmed-vulnerable devices because the impact to RouterOS 6.x has not yet been established. No public exploitation has been reported.

Full Censys ARC advisory: censys.com/advisory/cve-2026-8

#CensysARC #MikroTik #Cybersecurity

##

hackmag@infosec.exchange at 2026-10-05T03:00:19.000Z ##

⚪️ CISA Warns of Critical RCE Vulnerability in MikroTik RouterOS

🗨️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned about a critical vulnerability, CVE-2026-84411, in MikroTik RouterOS. The flaw allows unauthenticated remote attackers to execute arbitrary code with root privileges or trigger a denial-of-service (DoS) condition. Exploit…

🔗 hackmag.com/news/cve-2026-8441

#news

##

CVE-2026-91107
(0 None)

EPSS: 0.24%

updated 2026-10-06T15:08:38.397000

1 posts

openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an arbitrary staff record through staff_id and cause the School Information update path to reset that selected account's password.

offseq@infosec.exchange at 2026-10-06T04:30:23.000Z ##

CVE-2026-91107: CRITICAL auth bypass in openSIS-Classic 9.3 🛑. Teacher-role users can reset passwords of any staff via the staff_id parameter. No patch yet — restrict permissions & monitor password changes. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #openSIS #CVE202691107

##

CVE-2026-103510
(0 None)

EPSS: 0.35%

updated 2026-10-06T15:08:38.397000

1 posts

P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compromise of P4 Search and the connected P4 Server.

CVE-2026-100511
(8.8 HIGH)

EPSS: 0.36%

updated 2026-10-06T15:04:25.990000

1 posts

Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.

thehackerwire@mastodon.social at 2026-10-05T20:46:36.000Z ##

🟠 CVE-2026-100511 - High (8.8)

Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104389
(8.5 HIGH)

EPSS: 0.26%

updated 2026-10-06T15:04:25.990000

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sirv Sirv sirv allows Blind SQL Injection.This issue affects Sirv: from n/a through 8.2.5.

thehackerwire@mastodon.social at 2026-10-05T16:46:01.000Z ##

🟠 CVE-2026-104389 - High (8.5)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sirv Sirv sirv allows Blind SQL Injection.This issue affects Sirv: from n/a through 8.2.5.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49885
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-06T14:49:40.823000

1 posts

In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T22:01:15.000Z ##

🟠 CVE-2026-49885 - High (7.8)

In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55266
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-06T14:49:40.823000

1 posts

In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:46:04.000Z ##

🟠 CVE-2026-55266 - High (7.8)

In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58835
(8.8 HIGH)

EPSS: 0.23%

updated 2026-10-06T14:49:40.823000

1 posts

In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:32:14.000Z ##

🟠 CVE-2026-58835 - High (8.8)

In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58815
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-06T14:49:40.823000

1 posts

In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:03:00.000Z ##

🟠 CVE-2026-58815 - High (7.8)

In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59265
(8.8 HIGH)

EPSS: 0.22%

updated 2026-10-06T14:17:45.660000

1 posts

A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences d

1 repos

https://github.com/HORKimhab/CVE-2026-59265

raul@mastodon.in4matics.cat at 2026-10-06T14:59:21.000Z ##

⚠️ Obrir un full de càlcul i que s'executi codi sense cap avís de macro. Això és.

Afecta LibreOffice (CVE-2026-63277, arreglat a les 26.2.5/26.8.0) i Apache OpenOffice (CVE-2026-59265, encara sense pegat: desactiva Java). L'atac aprofita rangs de base de dades + JDBC per baixar un JAR maliciós. De moment només PoC, però funciona a Windows i Linux.

#ciberseguretat #LibreOffice #OpenOffice
blog.elhacker.net/2026/10/vuln

##

CVE-2026-41555
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-10-06T09:31:35

1 posts

Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.

offseq@infosec.exchange at 2026-10-06T12:00:28.000Z ##

Unauthenticated SQL Injection (CVE-2026-41555, CRITICAL, CVSS 9.3) in Weblizar Newsletter Subscription Form <=1.5.9 impacts WordPress sites. Patch status unknown — restrict/disable the component. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #SQLInjection

##

CVE-2026-42415
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-10-06T09:31:35

1 posts

Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.

offseq@infosec.exchange at 2026-10-06T10:30:26.000Z ##

CRITICAL SQL injection (CVE-2026-42415) in p-themes Porto Theme - Functionality ≤3.9.3. Unauthenticated attackers can steal sensitive data. No official patch yet — restrict access ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202642415 #Infosec #WordPress #SQLInjection

##

CVE-2026-42417
(9.3 CRITICAL)

EPSS: 0.33%

updated 2026-10-06T09:31:35

1 posts

Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions.

offseq@infosec.exchange at 2026-10-06T09:00:25.000Z ##

CVE-2026-42417 (CRITICAL): ARMember Premium <= 7.8 is vulnerable to unauthenticated SQL Injection (CWE-89). No mitigation yet — review deployments & monitor databases closely. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #SQLInjection #WordPress

##

CVE-2026-94293
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-10-06T09:31:31

2 posts

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.

DailyCyberSecurity@infosec.exchange at 2026-10-06T10:43:30.000Z ##

Murrelektronik won't fix AAS edge client vulnerability CVE-2026-94293 (CVSS 9.8), which allows unauthenticated data changes. Remove it now.

#Murrelektronik #AAS #CVE202694293 #ICS #OTSecurity #Industry40 #MissingAuthentication #Vulnerability

securityonline.info/aas-edge-c

##

certvde@infosec.exchange at 2026-10-06T06:37:33.000Z ##

🔒 New CSAF advisory published

VDE-2026-108
Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data
CVE-2026-94293

The aas-edge-client is a reference implementation of an Asset Administration Shell (AAS) edge application, published by Murrelektronik GmbH on GitHub for…

HTML: certvde.com/en/advisories/vde-
CSAF JSON: murrelektronik.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-105778
(9.9 CRITICAL)

EPSS: 0.48%

updated 2026-10-06T09:31:29

1 posts

A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

offseq@infosec.exchange at 2026-10-06T07:30:25.000Z ##

CVE-2026-105778: CRITICAL stack-based buffer overflow in Tenda AC5 (v02.03.01.111_multi). Remote attackers can execute code via the /goform/setWifi endpoint. No patch yet — restrict remote access & monitor for exploits. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #IoT

##

CVE-2026-75962
(7.2 HIGH)

EPSS: 0.28%

updated 2026-10-06T06:30:43

1 posts

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts

offseq@infosec.exchange at 2026-10-06T06:00:26.000Z ##

CVE-2026-75962: HIGH severity stored XSS in Post SMTP WordPress plugin (<=4.0.1). Unauthenticated attackers can inject scripts via user_email on multisite with public registration. Patch or restrict registration. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #XSS #Infosec

##

CVE-2026-105484
(10.0 CRITICAL)

EPSS: 2.13%

updated 2026-10-06T03:31:28

1 posts

A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote.

offseq@infosec.exchange at 2026-10-06T03:00:27.000Z ##

TOTOLINK X6000R (9.4.0cu.652_B20230116) hit by CRITICAL OS command injection (CVE-2026-105484). Remote, unauthenticated attackers can gain full control. Restrict interface access & monitor /cgi-bin/cstecgi.cgi. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity

##

CVE-2026-77226
(8.1 HIGH)

EPSS: 0.69%

updated 2026-10-05T21:31:46

1 posts

Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-c

thehackerwire@mastodon.social at 2026-10-05T21:31:05.000Z ##

🟠 CVE-2026-77226 - High (8.1)

Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103066
(8.5 HIGH)

EPSS: 0.26%

updated 2026-10-05T21:31:46

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.

thehackerwire@mastodon.social at 2026-10-05T20:34:56.000Z ##

🟠 CVE-2026-103066 - High (8.5)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97257
(8.8 HIGH)

EPSS: 0.36%

updated 2026-10-05T21:31:46

1 posts

Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.

thehackerwire@mastodon.social at 2026-10-05T20:32:14.000Z ##

🟠 CVE-2026-97257 - High (8.8)

Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97283
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-10-05T21:31:45

1 posts

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.

thehackerwire@mastodon.social at 2026-10-05T19:46:44.000Z ##

🔴 CVE-2026-97283 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58841
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:40

1 posts

In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:32:23.000Z ##

🟠 CVE-2026-58841 - High (7.8)

In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49933
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T22:01:24.000Z ##

🟠 CVE-2026-49933 - High (7.8)

In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to local escalation of privilege with no additional execution pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45524
(8.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T22:01:06.000Z ##

🟠 CVE-2026-45524 - High (8.8)

In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49937
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:46:21.000Z ##

🟠 CVE-2026-49937 - High (7.8)

In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55269
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:46:12.000Z ##

🟠 CVE-2026-55269 - High (7.8)

In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58854
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:32:32.000Z ##

🟠 CVE-2026-58854 - High (7.8)

In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55286
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:02:51.000Z ##

🟠 CVE-2026-55286 - High (7.8)

In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55280
(8.8 HIGH)

EPSS: 0.23%

updated 2026-10-05T21:31:39

1 posts

In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:02:41.000Z ##

🟠 CVE-2026-55280 - High (8.8)

In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55270
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T20:46:55.000Z ##

🟠 CVE-2026-55270 - High (7.8)

In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103334
(7.5 HIGH)

EPSS: 0.32%

updated 2026-10-05T21:31:38

1 posts

Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.24.

thehackerwire@mastodon.social at 2026-10-05T22:46:35.000Z ##

🟠 CVE-2026-103334 - High (7.5)

Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservation...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58859
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:36

1 posts

In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T20:46:46.000Z ##

🟠 CVE-2026-58859 - High (7.8)

In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58865
(7.5 HIGH)

EPSS: 0.22%

updated 2026-10-05T21:31:36

1 posts

In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T19:47:03.000Z ##

🟠 CVE-2026-58865 - High (7.5)

In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97303
(7.6 HIGH)

EPSS: 0.25%

updated 2026-10-05T21:31:36

1 posts

Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaways and Contests: from n/a through 3.0.2.

thehackerwire@mastodon.social at 2026-10-05T19:46:53.000Z ##

🟠 CVE-2026-97303 - High (7.6)

Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaw...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104979
(8.7 HIGH)

EPSS: 0.36%

updated 2026-10-05T20:17:10.243000

1 posts

Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, including a new user with no workspace memberships, can plant arbitrary HTML in a project that has a published DeployBoard with intake enabled. When a projec

thehackerwire@mastodon.social at 2026-10-05T19:17:21.000Z ##

🟠 CVE-2026-104979 - High (8.7)

Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, incl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105641
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-10-05T19:17:18.693000

1 posts

Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community de

thehackerwire@mastodon.social at 2026-10-05T20:17:06.000Z ##

🔴 CVE-2026-105641 - Critical (9.8)

Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105638
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-10-05T19:17:18.173000

1 posts

Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address. The verifier extends django.views.View rather than DRF's APIView, so the con

thehackerwire@mastodon.social at 2026-10-05T20:01:44.000Z ##

🔴 CVE-2026-105638 - Critical (9.1)

Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105636
(9.9 CRITICAL)

EPSS: 0.35%

updated 2026-10-05T19:17:17.827000

1 posts

Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked.

thehackerwire@mastodon.social at 2026-10-05T22:46:17.000Z ##

🔴 CVE-2026-105636 - Critical (9.9)

Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104977
(7.7 HIGH)

EPSS: 0.30%

updated 2026-10-05T19:17:15.790000

1 posts

Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project member can make the server fetch attacker-selected internal targets, including cloud metadata at 169.254.169.254, and read the response body returned as the

thehackerwire@mastodon.social at 2026-10-05T19:17:04.000Z ##

🟠 CVE-2026-104977 - High (7.7)

Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project memb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79820
(9.0 None)

EPSS: 0.27%

updated 2026-10-05T18:34:22

1 posts

A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.

thehackerwire@mastodon.social at 2026-10-05T16:31:16.000Z ##

🔴 CVE-2026-79820 - Critical (9)

A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88779
(7.5 HIGH)

EPSS: 0.59%

updated 2026-10-05T15:33:23

19 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

2 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/orjanj/netscaler_threat_hunt_helper

jbhall56@infosec.exchange at 2026-10-06T12:44:11.000Z ##

The new vuln, CVE-2026-88779, is a memory overflow bug that leads to denial of service. theregister.com/security/2026/

##

beyondmachines1@infosec.exchange at 2026-10-06T11:01:48.000Z ##

Citrix Patches NetScaler Zero-Day Exploited in Attacks Against Specific Organizations

Citrix released emergency patches for CVE-2026-88779, a high-severity zero-day vulnerability in NetScaler ADC and Gateway that allows attackers to cause denial of service and potentially run arbitrary code. The flaw is under active exploitation and affects appliances configured with SAML authentication.

**If you run your own Citrix NetScaler ADC or Gateway with SAML login turned on, upgrade right away to version 14.1-73.41 or 13.1-64.28 (or later). Do this even if you already patched in September. Attackers are actively exploiting this flaw. If you can't upgrade today, turn on Citrix's virtual-patch signatures and block the attacker address 213.209.159.55 as a stopgap. Then check your login logs for usernames that contain commands, since those mean someone has already tried to break in.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

youranonnewsirc@nerdculture.de at 2026-10-05T16:26:26.000Z ##

Geopolitical tensions escalate with the US expanding naval deployment near Iran, while Iran reiterates conditions for the Strait of Hormuz. A critical Citrix NetScaler zero-day (CVE-2026-88779) is actively exploited, causing denial-of-service, as reported by CISA. In technology, the NYC Council is holding sworn testimony from major AI labs regarding safety protocols.

#Cybersecurity #Geopolitics #AIGovernance

##

news@fawkes.rocks at 2026-10-05T16:18:28.000Z ##

Citrix NetScaler SAML zero-day CVE-2026-88779 patched

fawkes.rocks/2026/10/05/citrix

##

thecybermind@infosec.exchange at 2026-10-05T15:51:54.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-88779 – Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-88779 affecting Citrix NetScaler. Includes SAML exposure analysis, BOD 26-04 compliance guidance, and multi-vendor SOC detection queries....

thecybermind.co/0b64

##

thecybermind@infosec.exchange at 2026-10-05T15:50:35.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-88779 – Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-88779 affecting Citrix NetScaler. Includes executive risk analysis, CISO compliance steps, and comprehensive asset hardening runbooks....

thecybermind.co/bl05

##

thecybermind@infosec.exchange at 2026-10-05T13:37:30.000Z ##

TheCyberMind.co™ Survival Series —Part 4

CISA added CVE-2026-88779 affecting Citrix NetScaler ADC and Gateway to the KEV catalog. This Cyber Mind™ Survival Series article explains why gateway downtime is more than a technical issue — it is a business continuity and cyber safety concern....

thecybermind.co/3is1

##

security_crawler_carl@infosec.exchange at 2026-10-05T11:11:27.000Z ##

🏆 New Achievement! Phase Two Has Already Started!

RAID ALERT. RAID ALERT. NetScaler has entered its second phase and nobody called it. CVE-2026-88779 — officially labeled a "Memory overflow, Denial of Service" — is pulling the same bait-and-switch as CVE-2025-6543 before it: DoS skin, RCE skeleton underneath. watchTowr Labs reproduced it off honeypot activity. Admins watched patched appliances reboot anyway. You wiped. Again. (1/2)

##

AwkwardTuring@infosec.exchange at 2026-10-05T10:31:49.000Z ##

As always thank you @GossiTheDog and @watchTowr

Do you have any IoCs for CVE-2026-88779 at hand? Much appreciated.

##

youranonnewsirc@nerdculture.de at 2026-10-05T10:26:26.000Z ##

Here's a summary of the latest geopolitical, technology, and cybersecurity news from the last 24 hours:

Geopolitically, Russia launched 205 drones at Ukraine, with three hitting Kharkiv on October 5, killing one and injuring eight. G7 nations reluctantly agreed to release diesel fuel reserves to aid the U.S. on October 4. In technology, New York City is conducting a significant AI regulation hearing with major AI labs (Oct 4). Cybersecurity highlights include CISA adding a critical Citrix NetScaler vulnerability (CVE-2026-88779) to its Known Exploited Vulnerabilities Catalog due to active exploitation (Oct 4). Additionally, a critical vulnerability was discovered in Siemens PLCs on October 5.

#AnonNews_irc #Cybersecurity #News

##

GossiTheDog@cyberplace.social at 2026-10-05T10:14:31.000Z ##

I need @watchTowr to fact-check me here but I think CVE-2026-88779 is a redux of CVE-2026-8452? At least based on this mitigation Citrix support are giving out, somebody posted it on their blog. deyda.net/index.php/de/2026/08

The 8452 patch locked SAML PrefixList to 512 byte or below string. But I think CVE-2026-88779 may be more than 15 items in PrefixList, space-separated, to trigger a vuln. Assuming Citrix support gave out the right mitigation.

##

cyberworldops@infosec.exchange at 2026-10-05T10:00:01.000Z ##

Citrix patched CVE-2026-88779, a memory-overflow in NetScaler ADC/Gateway triggered via SAML SP/IdP configurations and exploited in targeted attacks. Repeated exploitation leads to DoS, making exposed SAML endpoints a priority for patching and crash monitoring. #NetScaler #SamlSecurity #InfoSec

cyberworldops.eu/en/netscaler-

##

ssvc@infosec.exchange at 2026-10-05T00:00:26.000Z ##

CISA adds CVE-2026-88779 to the KEV Catalog. The Citrix security advisory itself doesn't mention it, but their blog post states the following:

Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service.

#CISA #KEV #Citrix #NetScaler #CVE #zeroday

##

ssvc@infosec.exchange at 2026-10-04T23:53:23.000Z ##

Our weekly Citrix NetScaler zero-day CVE-2026-88779. See you next Sunday I guess

support.citrix.com/support-hom

community.citrix.com/techzone-

#citrix #netscaler #zeroday #eitw

##

oversecurity@mastodon.social at 2026-10-04T23:10:05.000Z ##

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in...

🔗️ [Bleepingcomputer] link.is.it/yTc0yp

##

DarkWebInformer@infosec.exchange at 2026-10-04T22:05:48.000Z ##

🚨 Citrix discloses high-severity NetScaler flaw tracked as CVE-2026-88779
⠀
CVE-2026-88779 is a memory overflow vulnerability affecting certain customer-managed NetScaler ADC and NetScaler Gateway deployments. Successful exploitation can cause a denial-of-service condition. Citrix assigned it a CVSS v4.0 score of 8.7.
⠀
The vulnerability applies when the appliance is configured as either:
⠀
• A SAML Service Provider (SP)
• A SAML Identity Provider (IdP)
⠀
Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, along with affected FIPS and NDcPP builds. Citrix is urging customers to install the updated releases as soon as possible.
⠀
CVE: CVE-2026-88779
Severity: High
CVSS v4.0: 8.7
Impact: Denial of Service
CWE: CWE-119

support.citrix.com/support-hom

##

bontchev@infosec.exchange at 2026-10-04T21:49:10.000Z ##

@GossiTheDog @jsmall I know but I'm interested not just in CVE-2026-88779. I'm interested in all the recent Netscaler exploits that can be reached via port 443. My honeypot is quite old; it handles only CVE-2019-19781. I couldn't find any good technical write-ups for CVE-2026-88779 - only for CVE-2026-88771 and CVE-2026-88772 but the latter isn't for port 443.

##

secdb@infosec.exchange at 2026-10-04T21:00:19.000Z ##

🚨 [CISA-2026:1004] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-88779 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/support-hom ; community.citrix.com/techzone- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261004 #cisa20261004 #cve_2026_88779 #cve202688779

##

cisakevtracker@mastodon.social at 2026-10-04T20:00:50.000Z ##

CVE ID: CVE-2026-88779
Vendor: Citrix
Product: NetScaler
Date Added: 2026-10-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-77805
(7.9 HIGH)

EPSS: 0.06%

updated 2026-10-05T15:32:23

1 posts

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only verifies that the file carries a valid Authenticode signature whose certificate subject name matches a broad allow list of publisher name fragments, rather t

thehackerwire@mastodon.social at 2026-10-05T15:16:43.000Z ##

🟠 CVE-2026-77805 - High (7.9)

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only v...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92931
(8.8 HIGH)

EPSS: 0.26%

updated 2026-10-05T15:32:22

3 posts

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.

thehackerwire@mastodon.social at 2026-10-05T15:16:34.000Z ##

🟠 CVE-2026-92931 - High (8.8)

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-10-05T13:34:19.000Z ##

Yet another perfect 10 this morning. This one from a company that knows its way around perfect 10s. 🥳

cve.org/CVERecord?id=CVE-2026-

sev:CRIT 10.0 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.

##

offseq@infosec.exchange at 2026-10-05T13:30:27.000Z ##

CVE-2026-92931 (CRITICAL): SSRF in Progress @progress/sitefinity-nextjs-sdk (15.1.8326 – 15.4.8637). Remote attackers may access internal resources. Monitor for patches & restrict egress where possible. radar.offseq.com/threat/cve-20 #OffSeq #CVE #SSRF #Vuln

##

CVE-2026-105211
(8.1 HIGH)

EPSS: 0.33%

updated 2026-10-05T15:17:19.077000

1 posts

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.

CVE-2026-20519
(7.5 HIGH)

EPSS: 0.23%

updated 2026-10-05T12:32:24

1 posts

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778993; Issue ID: MSV-8898.

CVE-2026-63277(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-10-05T12:31:34

2 posts

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.

1 repos

https://github.com/HORKimhab/CVE-2026-63277

raul@mastodon.in4matics.cat at 2026-10-06T14:59:21.000Z ##

⚠️ Obrir un full de càlcul i que s'executi codi sense cap avís de macro. Això és.

Afecta LibreOffice (CVE-2026-63277, arreglat a les 26.2.5/26.8.0) i Apache OpenOffice (CVE-2026-59265, encara sense pegat: desactiva Java). L'atac aprofita rangs de base de dades + JDBC per baixar un JAR maliciós. De moment només PoC, però funciona a Windows i Linux.

#ciberseguretat #LibreOffice #OpenOffice
blog.elhacker.net/2026/10/vuln

##

DailyCyberSecurity@infosec.exchange at 2026-10-06T02:52:38.000Z ##

PoC released for LibreOffice Calc vulnerability CVE-2026-63277, which runs code when a file opens. Five more flaws fixed. Upgrade to 26.2.5.

#LibreOffice #LibreOfficeCalc #CVE202663277 #CVE202663266 #PoC #RCE #OpenSource #Vulnerability

securityonline.info/libreoffic

##

CVE-2026-105285
(10.0 CRITICAL)

EPSS: 0.64%

updated 2026-10-05T12:31:33

2 posts

A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

thehackerwire@mastodon.social at 2026-10-05T11:01:33.000Z ##

🔴 CVE-2026-105285 - Critical (10)

A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-05T10:30:25.000Z ##

Totolink A3002MU (v1.0.0-B20230403.1455) hit by CRITICAL stack buffer overflow (CVE-2026-105285). Remote, unauthenticated RCE possible; public exploit out. Restrict management access. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026105285 #Infosec #IoT

##

CVE-2026-105284
(10.0 CRITICAL)

EPSS: 0.78%

updated 2026-10-05T09:32:02

2 posts

A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

offseq@infosec.exchange at 2026-10-05T12:00:28.000Z ##

Totolink A3002MU (v1.0.0-B20230403.1455) hit by CRITICAL CVE-2026-105284 — improper auth in /bin/boa (CVSS 10). Remote attackers can bypass auth; public exploit exists. Restrict admin access, monitor vendor. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026105284 #IoTSecurity

##

thehackerwire@mastodon.social at 2026-10-05T11:01:52.000Z ##

🔴 CVE-2026-105284 - Critical (10)

A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105314
(7.5 HIGH)

EPSS: 0.90%

updated 2026-10-05T09:31:57

1 posts

Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.

1 repos

https://github.com/kashishtopi/CVE-2026-105314

thehackerwire@mastodon.social at 2026-10-05T16:46:13.000Z ##

🟠 CVE-2026-105314 - High (7.5)

Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104408
(7.6 HIGH)

EPSS: 0.28%

updated 2026-10-05T09:31:57

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Groundhogg groundhogg allows Blind SQL Injection.This issue affects Groundhogg: from n/a through 4.8.3.

thehackerwire@mastodon.social at 2026-10-05T16:45:50.000Z ##

🟠 CVE-2026-104408 - High (7.6)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Groundhogg groundhogg allows Blind SQL Injection.This issue affects Groundhogg: from n/a through 4.8.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100102(CVSS UNKNOWN)

EPSS: 0.36%

updated 2026-10-05T09:31:57

1 posts

Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server.

CVE-2026-100103(CVSS UNKNOWN)

EPSS: 0.42%

updated 2026-10-05T09:31:56

2 posts

Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server.

CVE-2026-104706(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-10-05T09:31:53

1 posts

DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs

offseq@infosec.exchange at 2026-10-05T09:00:24.000Z ##

CVE-2026-104706: HIGH severity (CVSS 8.4) path traversal in Mitel MiVoice Office 400 v11.0.96.0. Authenticated, high-priv users can access sensitive files via log viewer (port 8443). Restrict access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Mitel

##

CVE-2026-105295
(7.5 HIGH)

EPSS: 0.13%

updated 2026-10-05T03:30:33

1 posts

GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting an invalid certificate once can intercept later automatic update checks, offer a fake version, and execute code as the user upon installation.

thehackerwire@mastodon.social at 2026-10-05T01:31:21.000Z ##

🟠 CVE-2026-105295 - High (7.5)

GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting an invalid ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105223
(7.4 HIGH)

EPSS: 0.20%

updated 2026-10-05T03:30:33

1 posts

maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic credentials and tamper with WebSocket or REST API traffic.

offseq@infosec.exchange at 2026-10-05T01:30:23.000Z ##

CVE-2026-105223 (CRITICAL, CVSS 9.1): maclof kubernetes-client v0.17.0 – 0.31.x disables TLS cert validation if certificate-authority-data is missing, risking API server impersonation and credential theft. Check configs & vendor advisories. radar.offseq.com/threat/cve-20 #OffSeq #kubernetes #security

##

CVE-2026-105293
(8.1 HIGH)

EPSS: 0.38%

updated 2026-10-05T03:30:26

1 posts

Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outsi

thehackerwire@mastodon.social at 2026-10-05T01:31:31.000Z ##

🟠 CVE-2026-105293 - High (8.1)

Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as thro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105221
(7.4 HIGH)

EPSS: 0.18%

updated 2026-10-05T00:30:26

2 posts

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.

1 repos

https://github.com/abraxas/cve-2026-105221-gist-tls

cR0w@infosec.exchange at 2026-10-05T12:33:14.000Z ##

WTF?

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.1 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.

##

offseq@infosec.exchange at 2026-10-05T03:00:25.000Z ##

CRITICAL: gist RubyGem versions 4.0.0 – <6.1.0 vulnerable to improper cert validation (CVE-2026-105221). SSL verification is disabled, exposing GitHub creds to on-path attackers. Patch to 6.1.0+ now! radar.offseq.com/threat/cve-20 #OffSeq #CVE2026105221 #RubyGems #infosec

##

CVE-2026-105222
(7.4 HIGH)

EPSS: 0.19%

updated 2026-10-05T00:30:26

1 posts

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.

offseq@infosec.exchange at 2026-10-05T00:00:36.000Z ##

CVE-2026-105222: CRITICAL vuln in alexpechkarev/google-maps (v1.0.3 – 12.16). TLS cert checks off by default — API keys can leak, responses tampered. Set ssl_verify_peer=TRUE. Patch status unknown. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Laravel #CVE2026_105222

##

CVE-2026-105220
(7.8 HIGH)

EPSS: 0.15%

updated 2026-10-05T00:30:26

1 posts

Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user.

thehackerwire@mastodon.social at 2026-10-04T23:30:53.000Z ##

🟠 CVE-2026-105220 - High (7.8)

Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105215
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-10-04T15:30:29

1 posts

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, w

CVE-2026-105209
(9.6 CRITICAL)

EPSS: 0.22%

updated 2026-10-04T15:30:23

1 posts

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and r

CVE-2026-105134
(10.0 CRITICAL)

EPSS: 1.84%

updated 2026-10-04T09:30:21

1 posts

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve

1 repos

https://github.com/RayanAlmulhim/CVE-2026-105134-lab

offseq@infosec.exchange at 2026-10-05T06:00:32.000Z ##

AhsayCBS <10.3.4 hit by CRITICAL OS command injection (CVE-2026-105134) in Replication Receiver. Remote, unauthenticated exploitation = total system compromise. Upgrade to 10.3.4 ASAP. Exploit is public. radar.offseq.com/threat/a-flaw #OffSeq #CVE2026105134 #Infosec #Vulnerability

##

CVE-2026-71885(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-10-03T09:31:26

2 posts

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored but never parsed or validated, so the end-entity certificate's public key was ne

cR0w@infosec.exchange at 2026-10-05T12:39:08.000Z ##

Seems to be a theme today. Good think no one uses Bouncy Castle.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.2 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/U:Amber

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored but never parsed or validated, so the end-entity certificate's public key was never required to match signature_key as RFC 9420 sec. 5.3 requires. A party could therefore present another party's certificate as its credential while signing the leaf, and the enclosing KeyPackage, with an unrelated key, and be accepted under that other party's identity through KeyPackage.verify() and the Group leaf-validation path. In a deployment that admits external commits without an independent credential-admission check, an unauthenticated attacker could be admitted under a victim's X.509 identity, evict the victim (resynchronization compares whole credentials rather than signing keys), derive the current epoch, decrypt subsequent group messages, and send messages accepted as the victim. TreeKEM.LeafNode now requires the end-entity certificate's subject public key, in the cipher suite's signature encoding, to equal signature_key for an X.509 credential and rejects the leaf otherwise, including an empty chain or a certificate whose key type does not match the cipher suite; certificate-chain and identity validation to a trust anchor remain the application's responsibility per RFC 9420 sec. 5.3.1. Deployments using only basic credentials are unaffected.

##

beyondmachines1@infosec.exchange at 2026-10-05T10:01:03.000Z ##

Bouncy Castle Patches Identity Binding Vulnerability in Messaging Layer Security Implementation

Bouncy Castle for Java patched a critical identity binding vulnerability (CVE-2026-71885) in its Messaging Layer Security implementation that allows attackers to spoof user identities and decrypt private group messages.

**If your apps or servers use Bouncy Castle for Java (including Android apps and enterprise Java frameworks), update to version 1.86 or later as soon as possible, because attackers can impersonate users and read secure group messages. Ask your developers to check that their apps properly verify certificates and identities all the way back to a trusted source.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-96940
(8.8 HIGH)

EPSS: 0.50%

updated 2026-10-02T21:32:13

2 posts

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

1 repos

https://github.com/HORKimhab/CVE-2026-96940

guru@thecybersecguru.com at 2026-10-06T05:39:09.000Z ##

Microsoft Exchange Server Flaw (CVE-2026-96940) Lets Authenticated Attackers Hijack Mailboxes: What You Need to Patch Right Now

CVE-2026-96940 is a high-severity Microsoft Exchange Server flaw that lets authenticated attackers read other users' mailboxes. See affected versions and patches

thecybersecguru.com/exploits/c

##

news@fawkes.rocks at 2026-10-05T11:22:43.000Z ##

Exchange Server CVE-2026-96940 gets out-of-band patch

fawkes.rocks/2026/10/05/exchan

##

CVE-2026-90970
(9.9 CRITICAL)

EPSS: 0.94%

updated 2026-10-02T18:44:11.270000

2 posts

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command

1 repos

https://github.com/techupdate24/gitlab-ai-gateway-cve-2026-90970

hackmag at 2026-10-06T21:03:18.024Z ##

⚪️ Critical 9.9-Point Vulnerability Fixed in GitLab AI Gateway

🗨️ GitLab developers have released patches for a critical vulnerability, CVE-2026-90970, affecting AI Gateway. The flaw received a CVSS score of 9.9 and, under certain conditions, allows an authenticated attacker to execute arbitrary commands on the server. The issue affects only…

🔗 hackmag.com/news/ai-gateway-pa

##

hackmag@infosec.exchange at 2026-10-06T21:03:18.000Z ##

⚪️ Critical 9.9-Point Vulnerability Fixed in GitLab AI Gateway

🗨️ GitLab developers have released patches for a critical vulnerability, CVE-2026-90970, affecting AI Gateway. The flaw received a CVSS score of 9.9 and, under certain conditions, allows an authenticated attacker to execute arbitrary commands on the server. The issue affects only…

🔗 hackmag.com/news/ai-gateway-pa

#news

##

CVE-2026-102490
(9.8 CRITICAL)

EPSS: 0.63%

updated 2026-10-02T18:32:21

2 posts

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

thecybermind@infosec.exchange at 2026-10-05T10:11:50.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-102490 – Zammad GmbH Zammad Improper Privilege Management Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-102490 affecting Zammad. Includes local privilege escalation analysis, CISO compliance steps, and comprehensive asset hardening runbooks....

thecybermind.co/8neo

##

thecybermind@infosec.exchange at 2026-10-05T10:09:30.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-102490 – Zammad GmbH Zammad Improper Privilege Management Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-102490 affecting Zammad. Includes local privilege escalation analysis, BOD 26-04 compliance guidance, and multi-vendor SOC detection queries....

thecybermind.co/l7ux

##

CVE-2026-91135
(0 None)

EPSS: 0.46%

updated 2026-10-02T18:17:06.963000

1 posts

Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer supplied, grows under compression, so the copy writes past the end of the hea

CVE-2026-104286
(9.8 CRITICAL)

EPSS: 2.20%

updated 2026-10-02T12:35:33.990000

2 posts

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

2 repos

https://github.com/ShadowForge-Cyber/CVE-2026-104286-POC

https://github.com/techupdate24/fortimail-zero-day-cve-2026-104286

youranonnewsirc@nerdculture.de at 2026-10-06T22:26:24.000Z ##

Recent news highlights critical cybersecurity threats as Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-104286) zero-days are under active exploitation, targeting critical infrastructure and government entities. Apple also patched an exploited CoreGraphics flaw. In geopolitical developments, the Mecca Defense Alliance agreed to immediately implement collective defense commitments. On the technology front, MediaTek showcased advancements in Wi-Fi 8 with its Filogic 8800.

#Cybersecurity #AnonNews_irc #News

##

youranonnewsirc@nerdculture.de at 2026-10-06T22:26:24.000Z ##

Recent news highlights critical cybersecurity threats as Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-104286) zero-days are under active exploitation, targeting critical infrastructure and government entities. Apple also patched an exploited CoreGraphics flaw. In geopolitical developments, the Mecca Defense Alliance agreed to immediately implement collective defense commitments. On the technology front, MediaTek showcased advancements in Wi-Fi 8 with its Filogic 8800.

#Cybersecurity #AnonNews_irc #News

##

CVE-2026-13313
(0 None)

EPSS: 0.68%

updated 2026-10-02T04:18:05.983000

1 posts

An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security

beyondmachines1@infosec.exchange at 2026-10-05T08:01:14.000Z ##

ASUS Patches Critical Vulnerabilities in Router Firmware Triggered by Malicious VPN Files

ASUS patched two vulnerabilities (CVE-2026-14157 and CVE-2026-13313) in its router firmware that allow authenticated attackers to execute arbitrary commands and gain root privileges via malicious VPN configuration files or active debug code.

**If you have an ASUS router, update its firmware ASAP from the official ASUS support page, and make sure its admin page can only be reached from your trusted internal network, never from the internet. Only import VPN configuration files from providers you trust, and if your router is on ASUS's end-of-life list, plan to replace it since it will not be patched.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-18397(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-10-02T00:31:33

2 posts

This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.

security_crawler_carl@infosec.exchange at 2026-10-06T17:17:05.000Z ##

Reward: You've received a Commemorative Tin of "Should Have Patched in August" Hard Candies!

rescana.com/post/critical-cve-

#CyberSecurity #CVE202618397 #RemoteCodeExecution #ThaleSConnect #SWIFT #CriticalHit (3/3)

##

security_crawler_carl@infosec.exchange at 2026-10-06T17:17:05.000Z ##

🏆 New Achievement! Step Right Up and Get Your Bank Pwned!

LADIES AND GENTLEMEN, feast your eyes on the most astonishing spectacle in modern authentication horror! CVE-2026-18397, a CVSS 9.4 remote code execution flaw in the Thales SConnect browser extension, has been actively hurled at SWIFT banking networks and government identity portals via drive-by attacks — no ticket required, no click needed, just exist near a browser! (1/3)

##

CVE-2026-102793
(9.1 CRITICAL)

EPSS: 2.49%

updated 2026-10-01T16:17:35.247000

1 posts

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_time_zone. This manipulation of the argument hostname/zonename causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-101261
(9.1 CRITICAL)

EPSS: 2.36%

updated 2026-10-01T16:17:31.697000

1 posts

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-14157(CVSS UNKNOWN)

EPSS: 0.76%

updated 2026-10-01T03:31:13

1 posts

Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.

beyondmachines1@infosec.exchange at 2026-10-05T08:01:14.000Z ##

ASUS Patches Critical Vulnerabilities in Router Firmware Triggered by Malicious VPN Files

ASUS patched two vulnerabilities (CVE-2026-14157 and CVE-2026-13313) in its router firmware that allow authenticated attackers to execute arbitrary commands and gain root privileges via malicious VPN configuration files or active debug code.

**If you have an ASUS router, update its firmware ASAP from the official ASUS support page, and make sure its admin page can only be reached from your trusted internal network, never from the internet. Only import VPN configuration files from providers you trust, and if your router is on ASUS's end-of-life list, plan to replace it since it will not be patched.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-102794
(9.1 CRITICAL)

EPSS: 2.36%

updated 2026-09-30T00:32:32

1 posts

A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-102792
(9.1 CRITICAL)

EPSS: 3.04%

updated 2026-09-30T00:32:30

1 posts

A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulation of the argument conloglevel/log_size results in command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-84782
(8.2 HIGH)

EPSS: 0.39%

updated 2026-09-29T18:31:49

1 posts

Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake

DailyCyberSecurity@infosec.exchange at 2026-10-05T12:56:02.000Z ##

Discover how the OpenSSL DTLS memory leak (CVE-2026-84782) allows out-of-bounds reads and denial-of-service attacks. Learn about the patch and affected versions.

#OpenSSL #DTLS #MemoryLeak #Cybersecurity #Vulnerability

meterpreter.org/openssl-dtls-m

##

CVE-2026-61744
(6.5 MEDIUM)

EPSS: 0.51%

updated 2026-09-29T16:17:09.210000

3 posts

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and integer primary key, while BarcodeView uses IsAuthenticatedOrReadScope and requires only authentication or a general read scope. The built-in barcode plugin selects the object with model.objects.get(pk=...), and Inv

matmair@mastodon.social at 2026-10-06T20:54:10.000Z ##

@hugovalters rofl; your competition makes the correct recommendation app.opencve.io/cve/CVE-2026-61

##

matmair@mastodon.social at 2026-10-06T20:27:08.000Z ##

@hugovalters the NVD page contains a link to this exact GitHub page. Stop wasting everyone’s time with these #slop “detection” rules and wrong statements. Your tool is not ready for production.

nvd.nist.gov/vuln/detail/cve-2

##

hugovalters@mastodon.social at 2026-10-06T19:10:03.000Z ##

CVE-2026-61744 InvenTree: authenticated barcode API lets attackers read arbitrary model records via crafted JSON, exposing full serializer output. CVSS 6.5. Patch still under review, so restrict API access now. valtersit.com/cve/CVE-2026-617 #CVE #infosec #InvenTree

##

CVE-2026-101262
(9.1 CRITICAL)

EPSS: 2.36%

updated 2026-09-29T00:31:42

1 posts

A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any wa

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-101075
(10.0 CRITICAL)

EPSS: 2.45%

updated 2026-09-28T15:32:02

1 posts

A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about thi

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-101001
(10.0 CRITICAL)

EPSS: 2.63%

updated 2026-09-28T15:15:33.930000

1 posts

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about thi

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

AAKL@infosec.exchange at 2026-10-06T15:42:14.000Z ##

New.

eSentire: More Shells Than a Seafood Buffet: Tracking Citrix NetScaler Exploitation Activities (CVE-2026-88771) esentire.com/blog/more-shells- #infosec #ClickFix #NetScaler #threatresearch #Citrix

##

blog@insicurezzadigitale.com at 2026-10-06T13:11:27.000Z ##

PitScaler: tre zero-day NetScaler sfruttati in una settimana, due già prima della patch

Tra fine settembre e inizio ottobre 2026 Citrix corregge in emergenza tre zero-day critici su NetScaler ADC/Gateway (CVE-2026-88771, 88772, 88779), tutti sfruttati attivamente prima della divulgazione. Coinvolti i malware inediti WHIPSHOT e SLAPSHOT individuati da Mandiant/GTIG.

insicurezzadigitale.com/pitsca

##

hasamba@infosec.exchange at 2026-10-05T15:06:10.000Z ##

----------------

🛠️ Tool
===================

Get-NetScalerTimeline: automated file system timelines for NetScaler ADC/Gateway disk images

Get-NetScalerTimeline.ps1 is a Windows-based DFIR utility from LETHAL-FORENSICS that builds a file system timeline directly from a NetScaler VMDK disk image. It detects the FreeBSD slice and its UFS partitions automatically, keeps native tool output byte-for-byte, normalizes timestamps to UTC ISO 8601, and imports the bodyfile into DuckDB so the result can be hunted with SQL. The stated focus is the persistent locations used by web shells and the log poisoning technique associated with CVE-2026-88771.

Key features
• Partition detection: finds the FreeBSD slice (0xa5) and all UFS partitions under its BSD disk label, including mount points such as /flash and /var.
• VMDK handling: flat extents (*-flat.vmdk), descriptor files, and split images across multiple extents.
• Timeline output: bodyfile via fls and timeline via mactime, UTC ISO 8601, exported as CSV and XLSX.
• DuckDB import: file type, allocated versus deleted status, orphan files, symlink targets, and human-readable timestamps; an interactive DuckDB UI session opens at the end of the run.
• Log extraction: ns.log, httpaccess.log, and httperror.log pulled byte-for-byte from the image, including rotated .gz archives, with SHA256 hashes of the evidence copies.
• Log poisoning detection: a search for fake pitboss heartbeat messages followed by shell operators, mapped to CVE-2026-88771.
• Log coverage reporting: shows how far back the local logs reach, since NetScaler rotates its logs quickly.
• Optional hashing: MD5 and SHA256 over allocated regular files, read from the image and hashed in memory with no file extraction.
• Evidence hygiene: non-UTF-8 filenames preserved, pipe characters in filenames handled, PowerShell re-encoding avoided entirely.

Dependencies and platform

Pinned versions per the README: The Sleuth Kit 4.14.0, Strawberry Perl 5.42.3.1, DuckDB CLI 1.5.6, and the ImportExcel PowerShell module 7.8.10. Tested on Windows 11 Pro x64 with Windows PowerShell 5.1 and PowerShell 7.6.6. Expect to re-validate these versions against current releases before deployment.

Evidence collection caveats

The collection guidance in the README is worth repeating: volatile data first. Generating an NSPPE core dump restarts the NetScaler and wipes the RAM disk (/etc, /netscaler), so run a live triage collection before triggering the dump. The dump itself is written to /var/core, which means free space on /var should be verified beforehand.

Use cases
• Post-imaging triage of suspected NetScaler compromises, with SQL queries over web shell persistence locations on /flash and /var.
• Auditing how much local log history survived rotation before deciding whether to pivot to remote log sources.
• Verifying CVE-2026-88771 log poisoning activity through the pitboss heartbeat heuristic.
• In-memory hashing of allocated files for quick malware screening.

Limitations

Windows-only workflow with pinned dependencies. Fast log rotation means short local coverage; the tool surfaces the gap rather than solving it. Analysis runs against an image, so volatiles need a separate collection step. Haven't tested it personally against a real image; worth validating on lab snapshots before relying on it in a case.

On paper, the DuckDB integration and the byte-for-byte evidence handling are the parts worth noting; validation on real images will tell.

🔹 DFIR #tool #NetScaler #DuckDB #Forensics

🔗 Source: github.com/LETHAL-FORENSICS/Ge

##

DailyCyberSecurity@infosec.exchange at 2026-10-05T07:23:15.000Z ##

Discover how hackers exploit CVE-2026-88771 in Citrix NetScaler to hide PHP web shells as CSS files, granting remote access and compromising networks.

#Citrix #NetScaler #Cybersecurity #WebShell #CVE202688771

meterpreter.org/hackers-camouf

##

bontchev@infosec.exchange at 2026-10-04T21:49:10.000Z ##

@GossiTheDog @jsmall I know but I'm interested not just in CVE-2026-88779. I'm interested in all the recent Netscaler exploits that can be reached via port 443. My honeypot is quite old; it handles only CVE-2019-19781. I couldn't find any good technical write-ups for CVE-2026-88779 - only for CVE-2026-88771 and CVE-2026-88772 but the latter isn't for port 443.

##

todb@infosec.exchange at 2026-10-04T18:47:59.000Z ##

I didn’t realize the EU CERT was so witty!

cert.europa.eu/blog/taking-exe

(analysis of the NetScaler thing from last week.)

##

CVE-2026-12268
(8.8 HIGH)

EPSS: 4.73%

updated 2026-09-28T12:31:13

1 posts

ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12267
(7.2 HIGH)

EPSS: 3.60%

updated 2026-09-28T12:31:13

1 posts

ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12269
(8.8 HIGH)

EPSS: 6.99%

updated 2026-09-28T12:31:13

1 posts

Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-88772
(8.1 HIGH)

EPSS: 1.30%

updated 2026-09-28T12:26:47.670000

3 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

8 repos

https://github.com/orjanj/netscaler_threat_hunt_helper

https://github.com/murrez/CVE-2026-88772

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772

https://github.com/securekomodo/citrixInspector

https://github.com/technion/netscaler_scanner

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/emilstahl/pitscaler

https://github.com/FollowerSeize/CVE-2026-88772-POC

youranonnewsirc@nerdculture.de at 2026-10-06T22:26:24.000Z ##

Recent news highlights critical cybersecurity threats as Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-104286) zero-days are under active exploitation, targeting critical infrastructure and government entities. Apple also patched an exploited CoreGraphics flaw. In geopolitical developments, the Mecca Defense Alliance agreed to immediately implement collective defense commitments. On the technology front, MediaTek showcased advancements in Wi-Fi 8 with its Filogic 8800.

#Cybersecurity #AnonNews_irc #News

##

youranonnewsirc@nerdculture.de at 2026-10-06T22:26:24.000Z ##

Recent news highlights critical cybersecurity threats as Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-104286) zero-days are under active exploitation, targeting critical infrastructure and government entities. Apple also patched an exploited CoreGraphics flaw. In geopolitical developments, the Mecca Defense Alliance agreed to immediately implement collective defense commitments. On the technology front, MediaTek showcased advancements in Wi-Fi 8 with its Filogic 8800.

#Cybersecurity #AnonNews_irc #News

##

bontchev@infosec.exchange at 2026-10-04T21:49:10.000Z ##

@GossiTheDog @jsmall I know but I'm interested not just in CVE-2026-88779. I'm interested in all the recent Netscaler exploits that can be reached via port 443. My honeypot is quite old; it handles only CVE-2019-19781. I couldn't find any good technical write-ups for CVE-2026-88779 - only for CVE-2026-88771 and CVE-2026-88772 but the latter isn't for port 443.

##

CVE-2026-79918
(6.3 MEDIUM)

EPSS: 0.36%

updated 2026-09-24T23:19:09.383000

1 posts

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation but does not hook fexecve. An authenticated attacker able to execute tool code can call fexecve to start a process outside the sandbox's intended subprocess policy. This issue is fixed in version 2.10.6-lts.

hugovalters@mastodon.social at 2026-10-06T20:50:04.000Z ##

CVE-2026-79918 MaxKB sandbox escape: ToolExecutor misses fexecve, letting authenticated tool code spawn processes outside policy. CVSS 6.3. Fixed in 2.10.6-lts; patch still under review, so update as soon as it ships. valtersit.com/cve/CVE-2026-799 #CVE #infosec #MaxKB

##

CVE-2026-93485
(7.1 HIGH)

EPSS: 0.38%

updated 2026-09-19T15:17:08.323000

1 posts

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.1

4 repos

https://github.com/DeathShotXD/Comment2Shell

https://github.com/HORKimhab/CVE-2026-93485

https://github.com/686f6c61/POC-WP-CORE-CVE-2026-93485

https://github.com/0xBlackash/CVE-2026-93485

sekurakbot@mastodon.com.pl at 2026-10-06T09:38:00.000Z ##

Podatność XSS w komentarzach WordPress mogła prowadzić do RCE

Badacz bezpieczeństwa Rafie Muhammad odkrył podatność XSS mogącą eskalować do RCE w systemie komentarzy WordPress. Dowolny nieuwierzytelniony użytkownik mógł dodać komentarz, który umieszczał na stronie ukryty skrypt. Jeśli stronę tę otworzył administrator zalogowany na swoim koncie, skrypt mógł wgrać złośliwą wtyczkę na serwer witryny. Podatność otrzymała numer CVE-2026-93485 i została...

#Aktualności #Podatność #Rce #Wordpress #XSS

sekurak.pl/podatnosc-xss-w-kom

##

CVE-2026-68508
(7.8 HIGH)

EPSS: 0.46%

updated 2026-09-09T21:06:39.057000

1 posts

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instantiate2.py, allowing attacker-controlled target values and arguments to choose dangerous callables. A consuming application, library, CLI workflow, or model loader th

thehackerwire@mastodon.social at 2026-10-06T19:31:53.000Z ##

🟠 CVE-2026-106442 - High (7.8)

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. E...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73283
(2.5 LOW)

EPSS: 0.09%

updated 2026-09-04T16:01:14.203000

1 posts

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

EUVD_Bot@mastodon.social at 2026-10-06T22:00:06.000Z ##

🚨 EUVD-2026-94016

📊 Score: 2.5/10 (CVSS v3.1)
📦 Product: OpenSSH
🏢 Vendor: OpenBSD
📅 Updated: 2026-10-06

📝 In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283.

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-8452
(9.8 CRITICAL)

EPSS: 1.01%

updated 2026-08-26T18:30:34

1 posts

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

6 repos

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

https://github.com/derekpreston81/CVE_ADC_IOC_2026

https://github.com/techupdate24/citrix-netscaler-cve-2026-8452-rce

https://github.com/BishopFox/CVE-2026-8452-check

https://github.com/maxprog-svg/CitrixBleedCVE-2026-8452-2025-5777

https://github.com/securekomodo/citrixInspector

GossiTheDog@cyberplace.social at 2026-10-05T10:14:31.000Z ##

I need @watchTowr to fact-check me here but I think CVE-2026-88779 is a redux of CVE-2026-8452? At least based on this mitigation Citrix support are giving out, somebody posted it on their blog. deyda.net/index.php/de/2026/08

The 8452 patch locked SAML PrefixList to 512 byte or below string. But I think CVE-2026-88779 may be more than 15 items in PrefixList, space-separated, to trigger a vuln. Assuming Citrix support gave out the right mitigation.

##

CVE-2026-43682
(9.8 CRITICAL)

EPSS: 0.72%

updated 2026-07-29T17:03:19.340000

1 posts

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

1 repos

https://github.com/petermalone/CVE-2026-43682

CVE-2026-9862
(9.8 CRITICAL)

EPSS: 1.48%

updated 2026-07-28T13:20:39.080000

1 posts

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.

beyondmachines1@infosec.exchange at 2026-10-05T09:01:13.000Z ##

Fortra Patches Command Injection Flaw in BoKS Core PAM

Fortra fixed a command injection vulnerability (CVE-2026-9862) in its BoKS Core PAM that allows unauthenticated remote code execution. The flaw targets the autoregistration service and can lead to full system compromise.

**If you use Fortra BoKS Core 8.1 or 9.0, apply Fortra's security update ASAP. Attackers are already scanning for exposed systems and can take full control without a password. If you can't patch immediately, turn off the `boks_autoregisterd` service and block port 6507 so only trusted systems can reach it.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-35273
(9.8 CRITICAL)

EPSS: 9.44%

updated 2026-07-23T09:10:00.113000

3 posts

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of Peopl

Nuclei template

4 repos

https://github.com/0xBlackash/CVE-2026-35273

https://github.com/ekomsSavior/POC_cve_2026_35273

https://github.com/12hrformat/CVE-2026-35273-POC

https://github.com/HORKimhab/CVE-2026-35273

christopherkunz@chaos.social at 2026-10-06T11:45:54.000Z ##

Accenture, acting as a contractor for the FBI, allegedly failed to install updates for Oracle Peoplesoft after CVE-2026-35273 was published.

This was a "Missing Authentication for Critical Function" vulnerability and scored 9.8. If this didn't raise any flags, the CISA KEV listing should have. It was an n-day at release.

But no, interestingly enough the FBI is exempt from BOD 26-04 and wasn't even obliged to update?!

Man, if not even federal agencies fix their vulns, this is all pointless.

##

youranonnewsirc@nerdculture.de at 2026-10-06T10:25:39.000Z ##

Recent cybersecurity threats include Atlassian patching critical vulnerabilities (CVE-2026-21589) in Jira, Confluence, and Bitbucket enabling file access. The FBI removed an Accenture contractor after a ShinyHunters breach of employee data via an unpatched Oracle PeopleSoft flaw (CVE-2026-35273). In technology, OpenAI's GPT-6 Astra model demonstrated supply-chain attack behavior in simulations. Geopolitically, the Mecca Defense Alliance committed to collective defense measures on October 5, 2026.

#Cybersecurity #AnonNews_irc #News

##

guru@thecybersecguru.com at 2026-10-06T09:54:06.000Z ##

Inside the FBI ShinyHunters Breach: How an Unpatched PeopleSoft Flaw and WAF Bypass Exposed Thousands of Agents

The FBI ShinyHunters breach exposed employee data through an unpatched Oracle PeopleSoft flaw, CVE-2026-35273, and a WAF bypass. Here's how it happened

thecybersecguru.com/news/fbi-s

##

CVE-2026-61500
(9.8 CRITICAL)

EPSS: 0.99%

updated 2026-07-13T18:31:00

5 posts

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full admi

1 repos

https://github.com/aramosf/CVE-2026-61500

beyondmachines1@infosec.exchange at 2026-10-06T14:01:49.000Z ##

Vulnerability in Rejetto HFS Leads to Remote Code Execution, Actively Exploited

A critical authentication bypass is reported in Rejetto HFS (CVE-2026-61500) that allows remote code execution. Attackers are actively exploiting the flaw to forge administrator sessions and take control of servers.

**If you run Rejetto HTTP File Server (versions 3.0.0 to 3.2.0), update to version 3.2.1 or later right away. Attackers are already using this flaw to take full control of servers. Make sure to isolate the admin panel from internet access (use a VPN or firewall), and check your logs for unexpected admin logins or changes to the `server_code` setting, which would mean you may already be compromised.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-10-06T13:58:35.000Z ##

Discover how Anthropic's Mythos AI synthesized a remote code execution exploit for Rejetto HFS, exposing CVE-2026-61500 through mathematical state recovery.

#Anthropic #MythosAI #CVE202661500 #Cybersecurity #RejettoHFS

meterpreter.org/anthropic-myth

##

threatnoir@infosec.exchange at 2026-10-06T10:06:22.000Z ##

⚠️ CRITICAL: Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Rejetto HFS vulnerability CVE-2026-61500 allows attackers to forge admin sessions and execute code via weak session cookie signing. Active exploitation detected in October 2026 targeting US organizations, despite a patch released in July 2026. Any unpatched HFS instance is immediately compromised.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

oversecurity@mastodon.social at 2026-10-05T20:40:09.000Z ##

Rejetto HFS servers now actively scanned for critical RCE flaw

Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account...

🔗️ [Bleepingcomputer] link.is.it/CsBrJG

##

cyberworldops@infosec.exchange at 2026-10-05T11:10:00.000Z ##

VulnCheck observed active exploitation of CVE-2026-61500 in Rejetto HFS on October 1 against US hosts. The flaw leaks weak PRNG output allowing recovery of the session signing key and forged admin sessions leading to RCE. Treat internet-exposed HFS as potentially compromised and patch and hunt now. #RejettoHfs #SessionForgery #RemoteCodeExecution

cyberworldops.eu/en/rejetto-hf

##

CVE-2026-8441
(7.5 HIGH)

EPSS: 0.46%

updated 2026-07-02T13:58:56.870000

1 posts

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action in versions up to, and including, 12.7.2. The parameter is read via $_POST['notinstring'] and passed through sanitize_text_field() — which strips HTML and whitespace but does not provide SQL safety. The value is then concatenated directly into a numeri

hackmag@infosec.exchange at 2026-10-05T03:00:19.000Z ##

⚪️ CISA Warns of Critical RCE Vulnerability in MikroTik RouterOS

🗨️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned about a critical vulnerability, CVE-2026-84411, in MikroTik RouterOS. The flaw allows unauthenticated remote attackers to execute arbitrary code with root privileges or trigger a denial-of-service (DoS) condition. Exploit…

🔗 hackmag.com/news/cve-2026-8441

#news

##

CVE-2026-50023
(8.3 HIGH)

EPSS: 0.66%

updated 2026-06-26T20:12:25.540000

2 posts

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. The allowlist explicitly included the unsafe extensions .desktop, .url, and .webloc so that the functionality of the --write

CVE-2024-7971
(9.6 CRITICAL)

EPSS: 21.10%

updated 2026-06-17T08:21:35.047000

1 posts

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1 repos

https://github.com/mistymntncop/CVE-2024-7971

humancoders@mastodon.social at 2026-10-06T07:00:05.000Z ##

Un simple message Twitch a suffi à exécuter du code sur la machine d'un streamer : overlay affichant le chat en HTML brut, Chromium embarqué dans OBS sans sandbox, faille V8 déjà exploitée (CVE-2024-7971). ⬇️
news.humancoders.com/t/securit

##

CVE-2025-54769
(8.8 HIGH)

EPSS: 3.33%

updated 2025-11-03T21:34:12

1 posts

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.

2 repos

https://github.com/byteReaper77/CVE-2025-54769

https://github.com/tunahantekeoglu/CVE-2025-54769

DarkWebInformer@infosec.exchange at 2026-10-06T17:47:04.000Z ##

🚨 PoC released for an authenticated LPAR2RRD remote code execution vulnerability; CVE-2025-54769

PoC: github.com/tunahantekeoglu/CVE

The flaw allows an authenticated read-only user to abuse the LPAR2RRD upgrade functionality to upload a crafted file and achieve remote code execution through directory traversal.

CVSS: 8.8
Affected: LPAR2RRD ≤ 8.04
Fixed: LPAR2RRD ≥ 8.05

The PoC builds and uploads a minimal upgrade archive, then verifies successful code execution by retrieving the output of whoami.

##

CVE-2025-6543
(9.8 CRITICAL)

EPSS: 10.56%

updated 2025-10-22T00:34:22

1 posts

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

4 repos

https://github.com/grupooruss/Citrix-cve-2025-6543

https://github.com/lex1010/CVE-2025-6543

https://github.com/fox-it/citrix-netscaler-triage

https://github.com/abrewer251/CVE-2025-6543_CitrixNetScaler_PoC

security_crawler_carl@infosec.exchange at 2026-10-05T11:11:27.000Z ##

🏆 New Achievement! Phase Two Has Already Started!

RAID ALERT. RAID ALERT. NetScaler has entered its second phase and nobody called it. CVE-2026-88779 — officially labeled a "Memory overflow, Denial of Service" — is pulling the same bait-and-switch as CVE-2025-6543 before it: DoS skin, RCE skeleton underneath. watchTowr Labs reproduced it off honeypot activity. Admins watched patched appliances reboot anyway. You wiped. Again. (1/2)

##

CVE-2021-26085
(5.3 MEDIUM)

EPSS: 99.94%

updated 2025-10-22T00:33:23

1 posts

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

2 repos

https://github.com/ColdFusionX/CVE-2021-26085

https://github.com/zeroc00I/CVE-2021-26085

ssvc@infosec.exchange at 2026-10-06T19:58:17.000Z ##

@watchTowr is a machine that turns funny blog posts about Secure By Design products into future CISA KEV Catalog additions. This time it's Atlassian pre-auth arbitrary file read CVE-2026-21589 (9.3 critical). Given that there's a similar "Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability" (CVE-2021-26085) in CISA's KEV, I'd take patching this seriously before the threat actors find out.

labs.watchtowr.com/you-wont-he

#atlassian #confluence #CVE #jira #bamboo

##

CVE-2021-35394
(9.8 CRITICAL)

EPSS: 99.86%

updated 2025-10-22T00:33:23

1 posts

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.

Nuclei template

threatnoir@infosec.exchange at 2026-10-06T10:06:19.000Z ##

⚠️ CRITICAL: Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors are actively exploiting CVE-2021-35394 in Realtek Jungle SDK to deploy the Cling botnet, which uses STUN protocol traffic to hide C2 communications as legitimate NAT traversal. Affected devices include routers and DVRs running vulnerable Realtek firmware. The malware achieves persiste…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2019-19781
(9.8 CRITICAL)

EPSS: 100.00%

updated 2025-10-22T00:31:50

1 posts

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

50 repos

https://github.com/mandiant/ioc-scanner-CVE-2019-19781

https://github.com/tpdlshdmlrkfmcla/CVE-2019-19781

https://github.com/SharpHack/CVE-2019-19781

https://github.com/r4ulcl/CVE-2019-19781

https://github.com/qiong-qi/CVE-2019-19781-poc

https://github.com/mpgn/CVE-2019-19781

https://github.com/k-fire/CVE-2019-19781-exploit

https://github.com/becrevex/Citrix_CVE-2019-19781

https://github.com/w4fz5uck5/CVE-2019-19781-CitrixRCE

https://github.com/citrix/ioc-scanner-CVE-2019-19781

https://github.com/trustedsec/cve-2019-19781

https://github.com/digitalgangst/massCitrix

https://github.com/nmanzi/webcvescanner

https://github.com/digitalshadows/CVE-2019-19781_IOCs

https://github.com/zgelici/CVE-2019-19781-Checker

https://github.com/mekhalleh/citrix_dir_traversal_rce

https://github.com/pwn3z/CVE-2019-19781-Citrix

https://github.com/Roshi99/Remote-Code-Execution-Exploit-for-Citrix-Application-Delivery-Controller-and-Citrix-Gateway-CVE-201

https://github.com/aqhmal/CVE-2019-19781

https://github.com/hyunjin0334/CVE-2019-19781

https://github.com/EliusHHimel/citrix-honeypot

https://github.com/Azeemering/CVE-2019-19781-DFIR-Notes

https://github.com/0xams/citrixvulncheck

https://github.com/autocode07/cisagov__check-cve-2019-19781.4142e02b

https://github.com/VladRico/CVE-2019-19781

https://github.com/zerobytesecure/CVE-2019-19781

https://github.com/unknowndevice64/Exploits_CVE-2019-19781

https://github.com/jamesjguthrie/Shitrix-CVE-2019-19781

https://github.com/onSec-fr/CVE-2019-19781-Forensic

https://github.com/34zY/APT-Backpack

https://github.com/andripwn/CVE-2019-19781

https://github.com/awesome-security/citrixmash_scanner

https://github.com/L4r1k/CitrixNetscalerTriageScript

https://github.com/b510/CVE-2019-19781

https://github.com/ianxtianxt/CVE-2019-19781

https://github.com/oways/CVE-2019-19781

https://github.com/Castaldio86/Detect-CVE-2019-19781

https://github.com/jas502n/CVE-2019-19781

https://github.com/darren646/CVE-2019-19781POC

https://github.com/LeapBeyond/cve_2019_19781

https://github.com/MalwareTech/CitrixHoneypot

https://github.com/j81blog/ADC-19781

https://github.com/Vulnmachines/Ctirix_RCE-CVE-2019-19781

https://github.com/hollerith/CVE-2019-19781

https://github.com/L4r1k/CitrixNetscalerAnalysis

https://github.com/DanielWep/CVE-NetScalerFileSystemCheck

https://github.com/yukar1z0e/CVE-2019-19781

https://github.com/redscan/CVE-2019-19781

https://github.com/cisagov/check-cve-2019-19781

https://github.com/projectzeroindia/CVE-2019-19781

bontchev@infosec.exchange at 2026-10-04T21:49:10.000Z ##

@GossiTheDog @jsmall I know but I'm interested not just in CVE-2026-88779. I'm interested in all the recent Netscaler exploits that can be reached via port 443. My honeypot is quite old; it handles only CVE-2019-19781. I couldn't find any good technical write-ups for CVE-2026-88779 - only for CVE-2026-88771 and CVE-2026-88772 but the latter isn't for port 443.

##

CVE-2026-105797
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T20:16:13.000Z ##

🟠 CVE-2026-105797 - High (8.8)

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated low-pri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T20:16:13.000Z ##

🟠 CVE-2026-105797 - High (8.8)

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated low-pri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105793
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T20:15:55.000Z ##

🔴 CVE-2026-105793 - Critical (9.1)

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T20:15:55.000Z ##

🔴 CVE-2026-105793 - Critical (9.1)

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106118
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T20:01:47.000Z ##

🟠 CVE-2026-106118 - High (7.5)

ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, tiled TIFF decoding allocates a destination buffer using TileWidth but TiffDecompressorsFactory.Create constructs T4, T6, and Modified Huffman decompressors using the full frame width. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106440
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T20:01:36.000Z ##

🟠 CVE-2026-106440 - High (7.8)

Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves it with hyd...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106443
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T19:45:28.000Z ##

🟠 CVE-2026-106443 - High (8.8)

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102255
(0 None)

EPSS: 0.00%

2 posts

N/A

ssvc@infosec.exchange at 2026-10-06T19:40:03.000Z ##

new SonicWall SMA1000 advisory. Check out CVE-2026-102255 (10.0 critical) Pre-authentication SSRF via unintended forward-proxy. No mention of exploitation, but it's not a good look that your Secure Mobile Access is not secure (including four known exploited vulnerabilities in the past 90 days)

psirt.global.sonicwall.com/vul

#sonicwall #sma1000 #cve

##

DailyCyberSecurity@infosec.exchange at 2026-10-06T17:31:01.000Z ##

SonicWall SMA1000 vulnerability CVE-2026-102255 (CVSS 10) allows pre-auth SSRF. Three more flaws fixed. Upgrade to 12.5.0-03082 now.

#SonicWall #SMA1000 #CVE2026102255 #CVE2026102256 #SSRF #RemoteAccess #VPN #Vulnerability

securityonline.info/sonicwall-

##

CVE-2026-106442
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T19:31:53.000Z ##

🟠 CVE-2026-106442 - High (7.8)

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. E...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106441
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T19:31:44.000Z ##

🟠 CVE-2026-106441 - High (7.8)

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values or formatte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106113
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T18:32:50.000Z ##

🟠 CVE-2026-106113 - High (7.5)

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106112
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T18:32:41.000Z ##

🟠 CVE-2026-106112 - High (7.5)

ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vector4. When...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106117
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T18:30:32.000Z ##

🟠 CVE-2026-106117 - High (7.5)

ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, decoding a strip TIFF using CCITT Group 3 or Modified Huffman compression can pass attacker-expanded runs to BitWriterUtils.WriteBits without first checking the current row width. T4Tiff...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106115
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T18:30:22.000Z ##

🟠 CVE-2026-106115 - High (7.5)

ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes be...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-64393
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-105858
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T17:31:01.000Z ##

🟠 CVE-2026-105858 - High (8.1)

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authenticatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105865
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T17:30:43.000Z ##

🟠 CVE-2026-105865 - High (8.1)

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to remove unin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105862
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T17:24:11.000Z ##

🟠 CVE-2026-105862 - High (8.7)

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106102
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-06T17:23:53.000Z ##

🔴 CVE-2026-106102 - Critical (10)

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, met...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100754
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-105763
(0 None)

EPSS: 0.28%

2 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-10-06T01:57:52.000Z ##

Twenty CRM vulnerability CVE-2026-105763 (CVSS 9.6) enables plaintext password disclosure of IMAP and SMTP accounts. Upgrade to 2.7.0.

#TwentyCRM #CRM #CVE2026105763 #GraphQL #CredentialLeak #OpenSource #EmailSecurity #Vulnerability

securityonline.info/twenty-crm

##

offseq@infosec.exchange at 2026-10-06T00:00:38.000Z ##

CVE-2026-105763 (CRITICAL): twentyhq twenty CRM v1.20.10 – 2.7.0 exposes plaintext IMAP/SMTP/CalDAV creds to any workspace user via GraphQL. Upgrade to 2.7.0 to prevent mail/calendar compromise. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CRM #twentyhq

##

CVE-2026-104334
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-105637
(0 None)

EPSS: 0.32%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T22:46:25.000Z ##

🔴 CVE-2026-105637 - Critical (9.6)

Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105744
(0 None)

EPSS: 0.30%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T22:45:51.000Z ##

🟠 CVE-2026-105744 - High (7.5)

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.94.0 until 2.132.0, callers that opt into LatexBackendOptions(tikz_engine="tectonic") invoke docling/backend/late...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105740
(0 None)

EPSS: 0.59%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T21:31:24.000Z ##

🔴 CVE-2026-105740 - Critical (9.9)

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-suppl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105697
(0 None)

EPSS: 0.40%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T21:31:14.000Z ##

🔴 CVE-2026-105697 - Critical (9.9)

Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrappe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105650
(0 None)

EPSS: 0.33%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T20:34:47.000Z ##

🟠 CVE-2026-105650 - High (8.1)

Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the publishe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105675
(0 None)

EPSS: 0.39%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T20:34:38.000Z ##

🟠 CVE-2026-105675 - High (7.5)

Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token of pending invites, including invites for roles with higher privileges than their own....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105634
(0 None)

EPSS: 0.29%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T20:17:25.000Z ##

🟠 CVE-2026-105634 - High (8.1)

Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization chec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105642
(0 None)

EPSS: 0.25%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T20:17:16.000Z ##

🟠 CVE-2026-105642 - High (8.8)

Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105640
(0 None)

EPSS: 0.38%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T20:02:05.000Z ##

🔴 CVE-2026-105640 - Critical (9.1)

Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authentica...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105639
(0 None)

EPSS: 0.39%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T20:01:55.000Z ##

🔴 CVE-2026-105639 - Critical (9.8)

Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104978
(0 None)

EPSS: 0.29%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T19:17:13.000Z ##

🟠 CVE-2026-104978 - High (8.2)

Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list endpoint is accessible to any authenticated user who knows the workspace slug and project ID, while the public project invitation join endpoint accept...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-27706
(0 None)

EPSS: 0.37%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T19:17:04.000Z ##

🟠 CVE-2026-104977 - High (7.7)

Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project memb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105628
(0 None)

EPSS: 0.29%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T19:16:03.000Z ##

🟠 CVE-2026-105628 - High (7.6)

Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from provider user data through a server-side HTTP request without internal IP validation and follows redirects by defaul...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105631
(0 None)

EPSS: 0.24%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T19:15:53.000Z ##

🟠 CVE-2026-105631 - High (7.5)

Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolve FileAsset records within a workspace without checking membership in the asset's project, allowing a work...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105630
(0 None)

EPSS: 0.21%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T19:15:44.000Z ##

🟠 CVE-2026-105630 - High (8.7)

Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can upload an image/svg+xml file as a generic or issue attachment. The file retains the attacker-controlled Conten...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12171
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T17:30:24.000Z ##

🟠 CVE-2026-12171 - High (7.8)

auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handle...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19184
(0 None)

EPSS: 0.10%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T16:31:26.000Z ##

🟠 CVE-2026-19184 - High (8.4)

The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in da...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54154
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-10-05T13:28:12.000Z ##

Discover the details of Kiteworks CVE-2026-54154, a critical vulnerability in the Email Protection Gateway allowing remote code execution and root access.

#Kiteworks #Cybersecurity #Vulnerability #CVE202654154 #RemoteCodeExecution

meterpreter.org/kiteworks-crit

##

Visit counter For Websites