## Updated at UTC 2026-09-19T07:52:22.790255

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-93741 10.0 0.00% 2 0 2026-09-19T06:16:30.557000 A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affec
CVE-2026-85889 10.0 0.49% 6 0 2026-09-19T04:18:00.780000 Missing authentication for critical function in Azure AI Foundry allows an unaut
CVE-2026-92807 8.8 0.00% 4 0 2026-09-19T03:17:17.723000 The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitra
CVE-2026-92229 9.1 0.00% 4 0 2026-09-19T03:17:17.040000 The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plug
CVE-2026-89274 9.1 0.00% 4 0 2026-09-19T03:17:16.587000 The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Ex
CVE-2026-87909 7.5 0.00% 2 0 2026-09-19T03:17:15.853000 The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execut
CVE-2026-84434 9.8 0.00% 2 0 2026-09-19T03:17:15.573000 The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in
CVE-2026-93739 9.9 0.00% 2 0 2026-09-19T00:32:51 A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impac
CVE-2026-93740 10.0 0.00% 2 0 2026-09-19T00:32:50 A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected i
CVE-2026-75885 9.3 0.00% 4 0 2026-09-18T22:17:10.313000 A flaw was found in the OpenShift console. Unauthenticated access to the `/api/d
CVE-2026-93738 9.9 0.00% 2 0 2026-09-18T21:32:44 A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects th
CVE-2026-88097 8.1 0.00% 2 0 2026-09-18T21:32:43 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke
CVE-2026-93872 7.5 0.00% 2 0 2026-09-18T21:32:42 Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without al
CVE-2026-93031 8.8 0.00% 2 0 2026-09-18T21:32:41 The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-B
CVE-2026-93868 8.1 0.00% 2 0 2026-09-18T21:32:41 Cotonti through 1.0.0 derives password recovery validation tokens from md5(micro
CVE-2026-93839 9.8 0.00% 4 0 2026-09-18T21:32:40 LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /p
CVE-2026-84241 8.1 0.00% 2 0 2026-09-18T21:32:40 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2025-39682 7.1 0.51% 2 1 2026-09-18T21:31:33 In the Linux kernel, the following vulnerability has been resolved: tls: fix ha
CVE-2026-93572 7.5 0.00% 2 0 2026-09-18T21:18:48.020000 A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker
CVE-2026-57227 7.5 0.00% 2 0 2026-09-18T21:17:01.217000 Suricata is a network Intrusion Detection System, Intrusion Prevention System an
CVE-2026-92953 10.0 0.34% 2 0 2026-09-18T20:17:31.113000 vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and Array
CVE-2026-54767 9.1 0.43% 2 0 2026-09-18T20:17:17.253000 WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/soc
CVE-2026-20329 9.9 0.45% 2 0 2026-09-18T20:17:13.133000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-13639 9.8 0.51% 2 0 2026-09-18T20:17:06.860000 An insufficient entropy vulnerability in login logic in Synology DiskStation Man
CVE-2026-92838 7.8 0.14% 1 0 2026-09-18T19:41:42.593000 A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop ap
CVE-2026-15638 0 0.20% 1 0 2026-09-18T19:34:36.657000 An unauthenticated user with access to Secret Server could leverage a padding or
CVE-2026-28197 8.8 0.00% 2 0 2026-09-18T19:24:36.593000 An authenticated, low-privileged user with access to the NetBackup Flex OS mana
CVE-2026-86865 7.2 0.31% 1 0 2026-09-18T19:19:49.643000 Tanium addressed a SQL injection vulnerability in Asset.
CVE-2026-54520 8.1 0.40% 2 1 2026-09-18T19:16:42.680000 AI Agent Automation is a modular AI agent workflow automation platform with sche
CVE-2026-78428 8.0 0.24% 2 0 2026-09-18T19:07:38.320000 For users authenticated through SAML or OpenID Connect (OIDC), this vulnerabilit
CVE-2026-93762 9.8 0.00% 2 0 2026-09-18T19:05:01.127000 Mongoid contains an unsafe reflection weakness in the query path used for embedd
CVE-2026-93765 9.1 0.00% 2 0 2026-09-18T19:05:01.127000 Mongoid contains an unsafe reflection weakness in the document persistence layer
CVE-2026-93752 7.5 0.00% 2 0 2026-09-18T18:32:08 CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclar
CVE-2026-93761 7.5 0.00% 2 0 2026-09-18T18:32:04 An inefficient regular expression complexity issue in the in-memory query evalua
CVE-2026-93759 8.6 0.00% 2 0 2026-09-18T18:32:04 Mongoid does not neutralize a string-typed query criterion supplied to its query
CVE-2026-91149 7.5 0.00% 2 0 2026-09-18T18:32:04 A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this
CVE-2026-93758 8.1 0.00% 2 0 2026-09-18T18:32:02 An insecure direct object reference in the nested attributes handling of the Mon
CVE-2026-93687 7.5 0.00% 2 0 2026-09-18T18:32:02 braces through 3.0.3 contains a stack overflow vulnerability in the recursive AS
CVE-2026-93753 7.5 0.00% 2 0 2026-09-18T18:32:01 deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the merg
CVE-2026-93760 8.2 0.00% 2 0 2026-09-18T18:31:58 Mongoid does not restrict which query operators may come from caller-supplied fi
CVE-2026-85497 9.8 0.00% 2 0 2026-09-18T18:31:57 CareCam CM2507 IP cameras store the device's root-account password using a fixed
CVE-2026-84398 7.5 0.00% 2 0 2026-09-18T18:31:54 CM2507 IP cameras accept an empty password for a privileged account exposed thro
CVE-2026-93606 10.0 0.00% 2 0 2026-09-18T18:18:31.267000 vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `Node
CVE-2026-93597 7.7 0.00% 2 0 2026-09-18T18:18:29.630000 ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in th
CVE-2026-67100 9.8 0.35% 4 0 2026-09-18T18:17:11.110000 HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tena
CVE-2026-90999 9.8 0.22% 3 0 2026-09-18T17:49:08.457000 Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows
CVE-2026-92943 8.1 0.27% 2 0 2026-09-18T17:48:19.003000 Improper validation of certificate with host mismatch in the MQTT client TLS con
CVE-2026-61672 7.1 0.00% 1 0 2026-09-18T17:16:58.537000 Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0
CVE-2026-93688 7.5 0.00% 2 0 2026-09-18T16:17:15.683000 SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV tra
CVE-2026-93374 9.6 0.27% 2 0 2026-09-18T15:33:12 Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 all
CVE-2026-53266 8.8 0.12% 4 0 2026-09-18T15:32:49 In the Linux kernel, the following vulnerability has been resolved: netfilter:
CVE-2026-93605 10.0 0.00% 2 0 2026-09-18T15:32:25 vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where t
CVE-2026-93603 10.0 0.00% 2 0 2026-09-18T15:32:25 vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this`
CVE-2026-93592 7.5 0.00% 2 0 2026-09-18T15:32:24 vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the
CVE-2026-93591 7.6 0.00% 2 0 2026-09-18T15:32:24 SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph
CVE-2026-93491 7.5 0.00% 2 0 2026-09-18T15:32:17 A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker
CVE-2026-87886 7.8 0.28% 5 0 2026-09-18T15:32:10 Local privilege escalation due to insecure file permissions. The following produ
CVE-2025-39964 3.3 0.32% 4 1 2026-09-18T15:31:06 In the Linux kernel, the following vulnerability has been resolved: crypto: af_
CVE-2026-17086 8.8 0.89% 2 0 2026-09-18T15:17:06.153000 The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for
CVE-2026-85410 8.1 0.31% 2 0 2026-09-18T13:23:37.403000 The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder,
CVE-2026-93450 7.5 0.66% 2 0 2026-09-18T13:18:38.450000 go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability
CVE-2026-54671 8.8 0.41% 2 0 2026-09-18T13:18:33.920000 WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps I
CVE-2026-28198 8.8 0.00% 2 0 2026-09-18T12:31:28 An authenticated, low-privileged user with access to the NetBackup Flex OS mana
CVE-2026-6205 8.1 0.32% 2 0 2026-09-18T09:31:21 An external control of file name or path vulnerability in Upload API in Synology
CVE-2026-13684 9.8 0.46% 4 0 2026-09-18T09:31:20 An improper encoding or escaping of output vulnerability in SCGI in Synology Dis
CVE-2026-67101 9.3 0.27% 2 0 2026-09-18T09:31:08 HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF
CVE-2026-18911 7.5 1.06% 2 0 2026-09-18T06:32:11 ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent a
CVE-2026-18912 7.7 1.50% 2 0 2026-09-18T06:32:11 ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authent
CVE-2026-20324 9.9 0.44% 3 0 2026-09-18T04:17:37.867000 A vulnerability in the sftunnel inter-device communication protocol of Cisco Sec
CVE-2026-93456 8.2 0.15% 2 0 2026-09-18T03:30:28 django-page-cms through 2.0.13 exempts five admin mutation views from CSRF prote
CVE-2026-93452 7.5 0.49% 2 0 2026-09-18T00:31:21 snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.
CVE-2026-70469 7.5 0.37% 1 0 2026-09-17T21:32:42 Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the appli
CVE-2026-84858 8.8 0.68% 1 0 2026-09-17T21:32:41 ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote
CVE-2026-92956 10.0 0.40% 2 0 2026-09-17T20:18:59.730000 vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a def
CVE-2026-92946 10.0 0.59% 2 0 2026-09-17T20:18:59.483000 vm2 before 3.11.7 contains a remote code execution vulnerability when require.ex
CVE-2026-92940 10.0 0.34% 2 0 2026-09-17T20:18:59.213000 vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAg
CVE-2026-92919 8.1 0.38% 2 0 2026-09-17T20:18:58.840000 admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload h
CVE-2026-89026 9.8 0.52% 2 1 2026-09-17T20:18:52.037000 The Issabel Framework, the web framework supporting Issabel PBX software, before
CVE-2026-87976 0 0.39% 1 0 2026-09-17T20:18:51.303000 Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when
CVE-2026-54692 7.8 0.14% 2 0 2026-09-17T20:16:52.550000 SAIL is a cross-platform library for loading and saving images with support for
CVE-2026-73172 0 1.73% 1 0 2026-09-17T19:16:55.587000 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CVE-2026-86863 9.8 0.36% 2 0 2026-09-17T18:32:03 pgAdmin 4's Webserver authentication source is intended to accept an identity as
CVE-2026-92957 9.9 0.49% 2 0 2026-09-17T18:17:15.430000 vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when e
CVE-2026-92947 10.0 0.43% 2 0 2026-09-17T16:18:34.667000 vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing
CVE-2026-79752 0 0.46% 2 0 2026-09-17T16:17:44.693000 CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9,
CVE-2026-92950 8.6 0.22% 2 0 2026-09-17T15:32:35 vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that a
CVE-2026-92954 8.6 0.34% 2 0 2026-09-17T15:32:28 vm2 is a sandbox library for running untrusted JavaScript in Node.js. In version
CVE-2026-92938 9.9 0.42% 2 0 2026-09-17T15:32:28 vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to c
CVE-2026-92948 9.9 0.45% 2 0 2026-09-17T15:32:27 vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist b
CVE-2026-92951 9.9 0.37% 2 0 2026-09-17T15:32:26 vm2 before 3.11.7 contains an incorrect authorization vulnerability in the exter
CVE-2026-92935 9.0 0.50% 2 0 2026-09-17T15:32:26 vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <
CVE-2026-92944 9.8 0.58% 2 0 2026-09-17T15:32:26 vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Nod
CVE-2026-92941 10.0 0.27% 2 0 2026-09-17T15:32:26 vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sand
CVE-2026-92937 10.0 0.79% 2 0 2026-09-17T15:32:23 vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in
CVE-2026-81481 7.5 0.53% 2 0 2026-09-17T15:32:18 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Im
CVE-2026-92955 10.0 0.62% 2 0 2026-09-17T15:32:17 vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows
CVE-2026-92960 10.0 0.43% 2 0 2026-09-17T15:17:01.170000 vm2 before 3.11.6 fails to restrict access to os and dns builtins under the buil
CVE-2026-92939 9.9 0.53% 2 0 2026-09-17T15:17:00.650000 vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM san
CVE-2026-92934 9.0 0.74% 2 0 2026-09-17T15:17:00.520000 vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that a
CVE-2026-92578 8.1 0.33% 1 0 2026-09-17T15:16:58.247000 WWBN AVideo through 29.0 contains an authentication bypass vulnerability where t
CVE-2026-92918 8.8 0.35% 2 0 2026-09-17T13:17:01.013000 admin3 through 3.0.0 persists user session tokens in the audit log event body wh
CVE-2026-76460 10.0 0.78% 32 1 2026-09-17T12:46:31.670000 A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an
CVE-2026-92913 7.4 0.51% 2 0 2026-09-17T12:18:30.290000 AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptograp
CVE-2026-20211 9.1 0.56% 1 0 2026-09-17T12:17:25.350000 A vulnerability in Cisco ISE could allow an authenticated, remote attacker to ex
CVE-2026-20176 9.1 0.78% 1 0 2026-09-17T12:17:25.200000 A vulnerability in Cisco ISE could allow an authenticated, remote attacker to ex
CVE-2026-15688 None 0.12% 3 0 2026-09-17T09:33:03 Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi
CVE-2026-86320 7.8 0.22% 2 0 2026-09-17T09:33:03 A flaw was found in flatpak-builder where Git hooks are not disabled when applyi
CVE-2026-87796 9.8 0.61% 1 1 2026-09-17T06:30:45 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbit
CVE-2026-92576 8.6 0.40% 1 0 2026-09-17T00:31:25 HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability
CVE-2026-20332 9.9 0.30% 2 0 2026-09-16T21:32:55 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-89082 None 0.51% 2 0 2026-09-16T21:32:55 HP has identified potential security vulnerabilities in the HP Advance software
CVE-2026-20330 9.9 0.34% 2 0 2026-09-16T21:32:50 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20192 10.0 0.43% 6 0 2026-09-16T21:32:50 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20341 9.1 0.45% 1 0 2026-09-16T21:32:50 A vulnerability in the sftunnel inter-device communication protocol of Cisco Sec
CVE-2026-87024 7.2 0.31% 1 0 2026-09-16T21:32:47 Tanium addressed a SQL injection vulnerability in Asset.
CVE-2026-77179 0 0.16% 8 1 2026-09-16T20:38:33.883000 On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows
CVE-2026-79994 0 0.11% 3 0 2026-09-16T20:38:33.883000 The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a
CVE-2026-70416 10.0 0.91% 1 0 2026-09-16T20:37:16.870000 Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untru
CVE-2026-78547 0 0.15% 1 0 2026-09-16T19:16:15.097000 Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. T
CVE-2026-20331 9.6 0.23% 3 0 2026-09-16T18:32:09 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20307 9.9 0.95% 1 0 2026-09-16T18:32:09 A vulnerability in the web-based management interface of Cisco ISE could allow a
CVE-2026-92397 9.1 2.30% 1 0 2026-09-16T18:32:09 A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected
CVE-2026-89775 9.3 0.17% 1 0 2026-09-16T18:31:58 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64:
CVE-2026-61595 7.7 0.38% 1 0 2026-09-16T15:32:15 ### Impact `djust.tenants` isolation was enforced only on the HTTP path. The cur
CVE-2026-91843 9.8 0.50% 19 1 2026-09-16T15:31:14 A stack overflow during the unauthenticated login process may allow an attacker
CVE-2026-58704 8.0 0.21% 22 0 2026-09-16T15:30:57 In Cellular Modem, there is a possible permission bypass due to a logic error in
CVE-2026-40854 None 0.30% 1 0 2026-09-16T12:30:47 WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability i
CVE-2026-81642 None 0.52% 4 1 2026-09-16T09:30:28 In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in t
CVE-2026-15640 None 0.28% 1 0 2026-09-16T00:31:41 Under certain conditions a valid SAML IdP response may be used to impersonate an
CVE-2026-15639 None 0.39% 1 0 2026-09-16T00:31:33 An attacker can craft a malicious link that, if used by a legitimate user, may c
CVE-2026-78175 8.8 0.59% 2 0 2026-09-15T15:17:21.707000 The Tutor LMS – eLearning and online course solution plugin for WordPress is vul
CVE-2026-39919 9.8 0.49% 1 0 2026-09-15T15:17:14.723000 Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability i
CVE-2026-81915 0 0.42% 1 0 2026-09-15T14:40:24.370000 Concrete CMS below 9.5.3 does not perform an object-level authorization check wh
CVE-2026-76461 9.8 2.01% 5 4 2026-09-15T12:47:32.497000 A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure
CVE-2026-89491 None 0.21% 1 0 2026-09-14T15:33:33 In the Linux kernel, the following vulnerability has been resolved: ocfs2: clus
CVE-2026-89466 7.7 0.14% 1 0 2026-09-14T15:33:32 In the Linux kernel, the following vulnerability has been resolved: power: supp
CVE-2026-89478 9.8 0.52% 1 0 2026-09-14T15:32:26 In the Linux kernel, the following vulnerability has been resolved: sctp: drop
CVE-2026-89483 7.5 0.56% 1 0 2026-09-14T15:32:26 In the Linux kernel, the following vulnerability has been resolved: nvme: zero
CVE-2026-89442 7.8 0.16% 1 0 2026-09-14T15:32:24 In the Linux kernel, the following vulnerability has been resolved: platform/x8
CVE-2026-80938 None 0.17% 1 0 2026-09-14T15:32:20 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:
CVE-2026-85706 10.0 14.56% 1 13 template 2026-09-14T14:22:15.323000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7
CVE-2026-89510 7.8 0.18% 1 0 2026-09-14T13:19:07.537000 In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4:
CVE-2026-89479 9.8 0.51% 1 0 2026-09-14T13:19:04.457000 In the Linux kernel, the following vulnerability has been resolved: sctp: stop
CVE-2026-89474 0 0.17% 1 0 2026-09-14T13:19:03.733000 In the Linux kernel, the following vulnerability has been resolved: power: supp
CVE-2026-89473 0 0.20% 1 0 2026-09-14T13:19:03.620000 In the Linux kernel, the following vulnerability has been resolved: power: supp
CVE-2026-89460 0 0.17% 1 0 2026-09-14T13:19:02.357000 In the Linux kernel, the following vulnerability has been resolved: s390/cpum_c
CVE-2026-89444 0 0.21% 1 0 2026-09-14T13:19:01.690000 In the Linux kernel, the following vulnerability has been resolved: platform/x8
CVE-2026-81005 0 0.18% 2 0 2026-09-14T13:18:54.883000 In the Linux kernel, the following vulnerability has been resolved: ipmi: si: F
CVE-2026-81000 7.8 0.16% 7 0 2026-09-14T13:18:54.210000 In the Linux kernel, the following vulnerability has been resolved: net: tun: b
CVE-2026-80982 7.8 0.16% 1 0 2026-09-14T13:18:52.947000 In the Linux kernel, the following vulnerability has been resolved: net/smc: fi
CVE-2026-80967 8.4 0.18% 1 0 2026-09-14T13:18:51.370000 In the Linux kernel, the following vulnerability has been resolved: ALSA: pcxhr
CVE-2026-80952 7.8 0.12% 1 0 2026-09-14T13:18:50.710000 In the Linux kernel, the following vulnerability has been resolved: i3c: master
CVE-2026-80941 0 0.21% 1 0 2026-09-14T13:18:50.160000 In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88
CVE-2026-80939 0 0.17% 1 0 2026-09-14T13:18:50.037000 In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89
CVE-2026-90894 7.8 0.15% 1 0 2026-09-14T12:31:44 Parallels Desktop runs prl_disp_service as root. Local clients reach it on the w
CVE-2026-89520 7.8 0.16% 1 0 2026-09-13T09:33:29 In the Linux kernel, the following vulnerability has been resolved: sched/core:
CVE-2026-80954 7.8 0.15% 1 0 2026-09-13T09:32:11 In the Linux kernel, the following vulnerability has been resolved: i3c: Fix un
CVE-2026-89492 9.8 0.60% 1 0 2026-09-13T07:17:12.417000 In the Linux kernel, the following vulnerability has been resolved: ocfs2: vali
CVE-2026-89452 8.4 0.18% 1 0 2026-09-13T07:17:09.477000 In the Linux kernel, the following vulnerability has been resolved: iommu/msm:
CVE-2026-80953 8.4 0.18% 1 0 2026-09-13T07:17:02.463000 In the Linux kernel, the following vulnerability has been resolved: i3c: master
CVE-2026-84869 9.9 0.69% 1 0 2026-09-12T04:16:42.757000 A condition in the ScreenConnect client may allow files to be transferred and ex
CVE-2026-90467 4.0 0.23% 1 0 2026-09-12T03:30:29 aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by c
CVE-2026-89529 None 0.19% 1 0 2026-09-11T21:31:37 In the Linux kernel, the following vulnerability has been resolved: svcrdma: Re
CVE-2026-42016 8.1 0.89% 1 0 2026-09-11T21:31:06 JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri
CVE-2026-89455 0 0.20% 1 0 2026-09-11T20:19:26.220000 In the Linux kernel, the following vulnerability has been resolved: PCI: plda:
CVE-2026-89453 0 0.20% 1 0 2026-09-11T20:19:25.967000 In the Linux kernel, the following vulnerability has been resolved: iommu/amd:
CVE-2026-0310 0 0.34% 2 0 2026-09-11T04:17:13.060000 A buffer overflow vulnerability in the XML processing functionality of Palo Alto
CVE-2026-39113 4.0 0.21% 1 1 2026-09-09T16:04:24.933000 Buffer Overflow vulnerability in SQLite affected version source snapshots/builds
CVE-2026-15534 5.7 0.17% 1 0 2026-09-08T22:17:38.113000 Perl versions through 5.45.1 have out-of-bounds heap reads and writes during reg
CVE-2026-60004 9.8 86.78% 1 10 template 2026-09-08T17:56:31 ### Summary Gitea's `diffpatch` endpoint can be abused to install and execute a
CVE-2026-31431 7.8 99.91% 1 100 template 2026-09-08T15:13:07.273000 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-15315 8.8 0.30% 3 1 2026-09-04T18:32:18 Tapo C200 v5 contains an improper authentication vulnerability within the login
CVE-2026-15316 6.5 0.23% 4 1 2026-09-04T17:26:04.617000 An improper input validation vulnerability in the configuration service for proc
CVE-2026-80844 0 0.19% 7 0 2026-09-04T16:18:13.023000 In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6:
CVE-2026-13348 None 0.31% 2 0 2026-09-01T15:31:17 CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability
CVE-2026-56209 7.1 0.35% 1 0 2026-09-01T13:19:49.913000 An arbitrary address write vulnerability was found in libaom, the reference AV1
CVE-2026-56210 7.1 0.31% 1 0 2026-08-31T15:35:36 A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1
CVE-2026-56208 7.6 0.42% 1 0 2026-08-31T15:34:31 A heap buffer overflow vulnerability was found in libaom, the reference AV1 code
CVE-2026-56211 7.1 0.48% 1 0 2026-08-31T15:34:31 A remote code execution vulnerability was found in libaom, the reference AV1 cod
CVE-2026-18963 9.1 3.18% 2 15 2026-08-28T22:53:42 A flaw was found in the reset-credentials flow of the keycloak-services componen
CVE-2026-56389 8.6 0.16% 2 0 2026-08-24T18:32:30 GNU Bison allows for an execution of an arbitrary program during HTML report gen
CVE-2026-74469 8.8 0.47% 7 0 2026-08-19T17:21:03.977000 In the Linux kernel, the following vulnerability has been resolved: sctp: preve
CVE-2026-68121 7.8 0.14% 7 0 2026-08-19T17:20:29.553000 In the Linux kernel, the following vulnerability has been resolved: pppoe: relo
CVE-2026-59310 9.8 49.68% 3 2 2026-08-18T18:32:52 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-19487 5.3 0.42% 1 0 2026-08-13T21:37:11 Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression matc
CVE-2026-5430 10.0 0.32% 1 1 2026-08-06T09:30:40 The JWT authentication mechanism accepts tokens signed with algorithms other tha
CVE-2026-7646 6.5 0.30% 2 5 2026-08-05T18:31:49 IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from
CVE-2026-15830 5.3 1.26% 1 0 2026-08-04T18:31:31 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDja
CVE-2026-13584 None 0.13% 2 0 2026-08-04T06:32:37 Improper Enforcement of Message Integrity During Transmission in a Communication
CVE-2026-45659 8.8 76.08% 1 2 2026-07-01T21:35:53 Deserialization of untrusted data in Microsoft Office SharePoint allows an autho
CVE-2026-58138 9.8 9.26% 2 6 template 2026-06-30T21:31:51 Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code ex
CVE-2026-8024 9.8 0.55% 1 0 2026-06-22T17:47:16.070000 A remote, unauthenticated attacker may exploit a deserialization of untrusted da
CVE-2026-32746 9.8 23.67% 3 8 2026-03-23T15:31:40 telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMO
CVE-2024-20260 8.6 0.59% 1 0 2024-10-23T18:33:16 A vulnerability in the VPN and management web servers of the Cisco Adaptive Secu
CVE-2026-57228 0 0.00% 2 0 N/A
CVE-2026-63447 0 0.00% 2 0 N/A
CVE-2026-63446 0 0.00% 2 0 N/A
CVE-2026-63452 0 0.00% 2 0 N/A
CVE-2026-68928 0 0.00% 2 0 N/A
CVE-2026-71418 0 0.00% 2 0 N/A
CVE-2026-92708 0 0.00% 2 0 N/A
CVE-2026-72878 0 0.27% 2 0 N/A
CVE-2026-54670 0 0.55% 2 0 N/A
CVE-2026-54734 0 0.36% 2 0 N/A
CVE-2026-93426 0 0.37% 2 0 N/A
CVE-2026-54752 0 0.35% 2 0 N/A
CVE-2026-54716 0 0.32% 2 0 N/A
CVE-2026-54627 0 0.44% 2 0 N/A
CVE-2026-93337 0 0.15% 2 0 N/A
CVE-2026-85500 0 0.55% 2 0 N/A
CVE-2026-59347 0 0.00% 2 0 N/A
CVE-2026-59346 0 0.00% 2 1 N/A

CVE-2026-93741
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-19T06:16:30.557000

2 posts

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

thehackerwire@mastodon.social at 2026-09-19T07:03:14.000Z ##

🔴 CVE-2026-93741 - Critical (10)

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T07:03:14.000Z ##

🔴 CVE-2026-93741 - Critical (10)

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85889
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-09-19T04:18:00.780000

6 posts

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

AAKL at 2026-09-18T15:40:57.616Z ##

If you missed this, Microsoft patched this vulnerability yesterday:

CVE-2026-85889: Azure AI Foundry Elevation of Privilege Vulnerability (new) msrc.microsoft.com/update-guid

More:

The Hacker News: Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation thehackernews.com/2026/09/micr @thehackernews

##

cyberworldops at 2026-09-18T15:00:01.549Z ##

Microsoft patched CVE-2026-85889 in Azure AI Foundry, a missing authentication for critical function flaw with CVSS 10.0 enabling unauthenticated remote privilege escalation. MSRC reports full mitigation, but the network-accessible, no-auth vector makes tenant privilege review and log auditing critical.

cyberworldops.eu/en/azure-ai-f

##

offseq at 2026-09-18T00:00:34.707Z ##

CVE-2026-85889 | CRITICAL flaw in Azure AI Foundry: missing authentication for a critical function (CVSS 10) allows remote privilege escalation. Microsoft patched this cloud vulnerability — verify your environment per MSRC: radar.offseq.com/threat/cve-20

##

AAKL@infosec.exchange at 2026-09-18T15:40:57.000Z ##

If you missed this, Microsoft patched this vulnerability yesterday:

CVE-2026-85889: Azure AI Foundry Elevation of Privilege Vulnerability (new) msrc.microsoft.com/update-guid

More:

The Hacker News: Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation thehackernews.com/2026/09/micr @thehackernews #infosec #vulnerability #Microsoft #Azure

##

cyberworldops@infosec.exchange at 2026-09-18T15:00:01.000Z ##

Microsoft patched CVE-2026-85889 in Azure AI Foundry, a missing authentication for critical function flaw with CVSS 10.0 enabling unauthenticated remote privilege escalation. MSRC reports full mitigation, but the network-accessible, no-auth vector makes tenant privilege review and log auditing critical. #AzureSecurity #PrivilegeEscalation #AiSecurity

cyberworldops.eu/en/azure-ai-f

##

offseq@infosec.exchange at 2026-09-18T00:00:34.000Z ##

CVE-2026-85889 | CRITICAL flaw in Azure AI Foundry: missing authentication for a critical function (CVSS 10) allows remote privilege escalation. Microsoft patched this cloud vulnerability — verify your environment per MSRC: radar.offseq.com/threat/cve-20 #OffSeq #Azure #Infosec #CVE202685889

##

CVE-2026-92807
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-19T03:17:17.723000

4 posts

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`button_`/non-`email_` shortcode attribute verbatim into a custom options array without sanitization, allowlist enforcement, or capability checks, and `cr

thehackerwire@mastodon.social at 2026-09-19T07:03:34.000Z ##

🟠 CVE-2026-92807 - High (8.8)

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T06:00:26.230Z ##

CVE-2026-92807: HIGH severity (CVSS 8.8) code injection in pdfcrowd Save as PDF Plugin for WordPress (<=4.6.1). Contributor+ users can run arbitrary PHP — risking API credential leaks & server compromise. Restrict access, monitor for patch. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T07:03:34.000Z ##

🟠 CVE-2026-92807 - High (8.8)

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T06:00:26.000Z ##

CVE-2026-92807: HIGH severity (CVSS 8.8) code injection in pdfcrowd Save as PDF Plugin for WordPress (<=4.6.1). Contributor+ users can run arbitrary PHP — risking API credential leaks & server compromise. Restrict access, monitor for patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec

##

CVE-2026-92229
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-19T03:17:17.040000

4 posts

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary sho

thehackerwire@mastodon.social at 2026-09-19T07:03:24.000Z ##

🔴 CVE-2026-92229 - Critical (9.1)

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T04:30:23.539Z ##

CVE-2026-92229: CRITICAL code injection in wpmudev Forminator Forms plugin (≤1.57.2). Unauthenticated attackers can execute arbitrary shortcodes, risking full WordPress site compromise. Restrict or disable plugin now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T07:03:24.000Z ##

🔴 CVE-2026-92229 - Critical (9.1)

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T04:30:23.000Z ##

CVE-2026-92229: CRITICAL code injection in wpmudev Forminator Forms plugin (≤1.57.2). Unauthenticated attackers can execute arbitrary shortcodes, risking full WordPress site compromise. Restrict or disable plugin now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202692229

##

CVE-2026-89274
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-19T03:17:16.587000

4 posts

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the `reviewBody` field, which is populated verbatim from the `comment_content` of app

thehackerwire@mastodon.social at 2026-09-19T07:04:14.000Z ##

🔴 CVE-2026-89274 - Critical (9.1)

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-19T03:00:23.674Z ##

WP Recipe Maker <=10.8.1 hit by CVE-2026-89274: CRITICAL code injection via unsanitized shortcodes in comment ratings. Unauthenticated attackers can trigger arbitrary shortcode execution on recipe pages. Upgrade ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-19T07:04:14.000Z ##

🔴 CVE-2026-89274 - Critical (9.1)

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T03:00:23.000Z ##

WP Recipe Maker <=10.8.1 hit by CVE-2026-89274: CRITICAL code injection via unsanitized shortcodes in comment ratings. Unauthenticated attackers can trigger arbitrary shortcode execution on recipe pages. Upgrade ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202689274 #Infosec

##

CVE-2026-87909
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-19T03:17:15.853000

2 posts

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. This makes it p

thehackerwire@mastodon.social at 2026-09-19T07:04:32.000Z ##

🟠 CVE-2026-87909 - High (7.5)

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T07:04:32.000Z ##

🟠 CVE-2026-87909 - High (7.5)

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84434
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-19T03:17:15.573000

2 posts

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a rejected file's intact upload state is later passed to upload_file() without re-v

thehackerwire@mastodon.social at 2026-09-19T07:04:23.000Z ##

🔴 CVE-2026-84434 - Critical (9.8)

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T07:04:23.000Z ##

🔴 CVE-2026-84434 - Critical (9.8)

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93739
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-19T00:32:51

2 posts

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

thehackerwire@mastodon.social at 2026-09-18T23:01:09.000Z ##

🔴 CVE-2026-93739 - Critical (9.9)

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed fro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:01:09.000Z ##

🔴 CVE-2026-93739 - Critical (9.9)

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed fro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93740
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-19T00:32:50

2 posts

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

thehackerwire@mastodon.social at 2026-09-18T23:01:18.000Z ##

🔴 CVE-2026-93740 - Critical (10)

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:01:18.000Z ##

🔴 CVE-2026-93740 - Critical (10)

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75885
(9.3 CRITICAL)

EPSS: 0.00%

updated 2026-09-18T22:17:10.313000

4 posts

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests withou

offseq at 2026-09-19T00:00:37.803Z ##

CVE-2026-75885: CRITICAL SSRF & DoS in Red Hat OpenShift Container Platform 4. Unauthenticated access to /api/devfile/ endpoints can expose internal services & cause resource exhaustion. No fix yet — restrict access & monitor advisories. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-18T23:00:58.000Z ##

🔴 CVE-2026-75885 - Critical (9.3)

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T00:00:37.000Z ##

CVE-2026-75885: CRITICAL SSRF & DoS in Red Hat OpenShift Container Platform 4. Unauthenticated access to /api/devfile/ endpoints can expose internal services & cause resource exhaustion. No fix yet — restrict access & monitor advisories. radar.offseq.com/threat/cve-20 #OffSeq #OpenShift #SSRF

##

thehackerwire@mastodon.social at 2026-09-18T23:00:58.000Z ##

🔴 CVE-2026-75885 - Critical (9.3)

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93738
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-18T21:32:44

2 posts

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

thehackerwire@mastodon.social at 2026-09-18T22:01:34.000Z ##

🔴 CVE-2026-93738 - Critical (9.9)

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:01:34.000Z ##

🔴 CVE-2026-93738 - Critical (9.9)

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88097
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-18T21:32:43

2 posts

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

thehackerwire@mastodon.social at 2026-09-18T22:02:05.000Z ##

🟠 CVE-2026-88097 - High (8.1)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:02:05.000Z ##

🟠 CVE-2026-88097 - High (8.1)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93872
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T21:32:42

2 posts

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.

thehackerwire@mastodon.social at 2026-09-18T21:01:05.000Z ##

🟠 CVE-2026-93872 - High (7.5)

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:01:05.000Z ##

🟠 CVE-2026-93872 - High (7.5)

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93031
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-18T21:32:41

2 posts

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported f

thehackerwire@mastodon.social at 2026-09-18T21:02:33.000Z ##

🟠 CVE-2026-93031 - High (8.8)

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:02:33.000Z ##

🟠 CVE-2026-93031 - High (8.8)

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93868
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-18T21:32:41

2 posts

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and probe them against the passrecover authentication endpoint to reset any account pas

thehackerwire@mastodon.social at 2026-09-18T21:01:38.000Z ##

🟠 CVE-2026-93868 - High (8.1)

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:01:38.000Z ##

🟠 CVE-2026-93868 - High (8.1)

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93839
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-18T21:32:40

4 posts

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to int

cR0w at 2026-09-18T21:38:13.580Z ##

Go hack more LLM shit.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.

##

thehackerwire@mastodon.social at 2026-09-18T21:01:27.000Z ##

🔴 CVE-2026-93839 - Critical (9.8)

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-09-18T21:38:13.000Z ##

Go hack more LLM shit.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.

##

thehackerwire@mastodon.social at 2026-09-18T21:01:27.000Z ##

🔴 CVE-2026-93839 - Critical (9.8)

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84241
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-18T21:32:40

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

thehackerwire@mastodon.social at 2026-09-18T21:03:06.000Z ##

🟠 CVE-2026-84241 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:03:06.000Z ##

🟠 CVE-2026-84241 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-39682
(7.1 HIGH)

EPSS: 0.51%

updated 2026-09-18T21:31:33

2 posts

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we break out of the main processing loop. If the record has already been decrypted

1 repos

https://github.com/khoatran107/cve-2025-39682

cisakevtracker@mastodon.social at 2026-09-18T20:00:51.000Z ##

CVE ID: CVE-2025-39682
Vendor: Linux
Product: Kernel
Date Added: 2026-09-18
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-09-18T20:00:51.000Z ##

CVE ID: CVE-2025-39682
Vendor: Linux
Product: Kernel
Date Added: 2026-09-18
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-93572
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T21:18:48.020000

2 posts

A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to eagerly preallocate a large amount of heap memory, leading to heap memory exhaustion and a Denial of Service (DoS) for applications using `RedisDecoder` with `RedisArrayAggregator`

thehackerwire@mastodon.social at 2026-09-18T14:04:49.000Z ##

🟠 CVE-2026-93572 - High (7.5)

## Summary

`RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis resource-exhaustion advisories. The limits are independent, but the allocator remains eager: every positive nested RESP array he...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T14:04:49.000Z ##

🟠 CVE-2026-93572 - High (7.5)

## Summary

`RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis resource-exhaustion advisories. The limits are independent, but the allocator remains eager: every positive nested RESP array he...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57227
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T21:17:01.217000

2 posts

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appended to one transaction without a limit. Crafted MQTT traffic can grow transaction state indefinitely, consuming CPU and memory and causing slowdown or d

thehackerwire@mastodon.social at 2026-09-18T23:02:37.000Z ##

🟠 CVE-2026-57227 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:02:37.000Z ##

🟠 CVE-2026-57227 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92953
(10.0 CRITICAL)

EPSS: 0.34%

updated 2026-09-18T20:17:31.113000

2 posts

vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing host-created typed arrays to observe attacker-controlled properties after VM.run() returns.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-54767
(9.1 CRITICAL)

EPSS: 0.43%

updated 2026-09-18T20:17:17.253000

2 posts

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source repository. A remote attacker who obtains that value can reach the endpoint's TRUNCATE TABLE operations for the endereco, pessoafis

thehackerwire@mastodon.social at 2026-09-17T23:01:20.000Z ##

🔴 CVE-2026-54767 - Critical (9.1)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T23:01:20.000Z ##

🔴 CVE-2026-54767 - Critical (9.1)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20329
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-09-18T20:17:13.133000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

AAKL at 2026-09-18T16:27:33.387Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity

##

AAKL@infosec.exchange at 2026-09-18T16:27:33.000Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec

##

CVE-2026-13639
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-18T20:17:06.860000

2 posts

An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

CVE-2026-92838
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-18T19:41:42.593000

1 posts

A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully exploited, an attacker with local write access to the affected directory could achieve

offseq@infosec.exchange at 2026-09-17T04:30:24.000Z ##

CVE-2026-92838: HIGH severity DLL hijack in GeoVision GV-Remote E-map 18.3.1 🖥️. Local attackers can execute arbitrary code via unsafe DLL load paths. Restrict directory write access; check vendor guidance. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #Windows

##

CVE-2026-15638
(0 None)

EPSS: 0.20%

updated 2026-09-18T19:34:36.657000

1 posts

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.

cR0w@infosec.exchange at 2026-09-16T14:17:30.000Z ##

Go hack more Secret Server shit.

delinea.com/security-advisories

Authentication Bypass via SAML Response Manipulation - CVE-2026-15640

Reflected Cross-Site Scripting - CVE-2026-15639

Cryptographic Padding Oracle - CVE-2026-15638

##

CVE-2026-28197
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-18T19:24:36.593000

2 posts

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permissions. Successful exploitation grants the attacker unrestricted control over the Flex appliance host and all hosted containers, fully compromising confidentiality, i

thehackerwire@mastodon.social at 2026-09-18T14:03:48.000Z ##

🟠 CVE-2026-28197 - High (8.8)

An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could supply a specially crafted input to a
privileged administrative command, causing it to execute arbitrary code
with root-level permissions. Success...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T14:03:48.000Z ##

🟠 CVE-2026-28197 - High (8.8)

An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could supply a specially crafted input to a
privileged administrative command, causing it to execute arbitrary code
with root-level permissions. Success...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86865
(7.2 HIGH)

EPSS: 0.31%

updated 2026-09-18T19:19:49.643000

1 posts

Tanium addressed a SQL injection vulnerability in Asset.

CVE-2026-54520
(8.1 HIGH)

EPSS: 0.40%

updated 2026-09-18T19:16:42.680000

2 posts

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and then uses the resulting path for read or write operations without checking that it remains in an approved wo

1 repos

https://github.com/chaitanyagarware/CVE-2026-54520

thehackerwire@mastodon.social at 2026-09-17T23:01:41.000Z ##

🟠 CVE-2026-54520 - High (8.1)

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T23:01:41.000Z ##

🟠 CVE-2026-54520 - High (8.1)

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78428
(8.0 HIGH)

EPSS: 0.24%

updated 2026-09-18T19:07:38.320000

2 posts

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

thehackerwire@mastodon.social at 2026-09-17T11:00:42.000Z ##

🟠 CVE-2026-78428 - High (8)

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T11:00:42.000Z ##

🟠 CVE-2026-78428 - High (8)

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93762
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-18T19:05:01.127000

2 posts

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.

thehackerwire@mastodon.social at 2026-09-18T20:00:58.000Z ##

🔴 CVE-2026-93762 - Critical (9.8)

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T20:00:58.000Z ##

🔴 CVE-2026-93762 - Critical (9.8)

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93765
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-18T19:05:01.127000

2 posts

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becomin

thehackerwire@mastodon.social at 2026-09-18T18:02:26.000Z ##

🔴 CVE-2026-93765 - Critical (9.1)

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal metho...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T18:02:26.000Z ##

🔴 CVE-2026-93765 - Critical (9.1)

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal metho...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93752
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T18:32:08

2 posts

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal counter and trigger excessive memory allocation during cssText serialization, causing process termination.

thehackerwire@mastodon.social at 2026-09-18T20:01:09.000Z ##

🟠 CVE-2026-93752 - High (7.5)

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal counter a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T20:01:09.000Z ##

🟠 CVE-2026-93752 - High (7.5)

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal counter a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93761
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T18:32:04

2 posts

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a pattern-matching query condition on an embedded association may become unresponsive.

thehackerwire@mastodon.social at 2026-09-18T20:02:20.000Z ##

🟠 CVE-2026-93761 - High (7.5)

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T20:02:20.000Z ##

🟠 CVE-2026-93761 - High (7.5)

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93759
(8.6 HIGH)

EPSS: 0.00%

updated 2026-09-18T18:32:04

2 posts

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field value

thehackerwire@mastodon.social at 2026-09-18T20:02:01.000Z ##

🟠 CVE-2026-93759 - High (8.6)

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T20:02:01.000Z ##

🟠 CVE-2026-93759 - High (8.6)

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91149
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T18:32:04

2 posts

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of detached threads, consuming system resources such as memory and file descriptors. The primary consequence is a denial of service (DoS), leading to degradat

thehackerwire@mastodon.social at 2026-09-18T18:02:36.000Z ##

🟠 CVE-2026-91149 - High (7.5)

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T18:02:36.000Z ##

🟠 CVE-2026-91149 - High (7.5)

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93758
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-18T18:32:02

2 posts

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up without the usual ownership or scoping restrictions, then updated and linked to the requesting user's own record. This ma

thehackerwire@mastodon.social at 2026-09-18T18:02:16.000Z ##

🟠 CVE-2026-93758 - High (8.1)

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T18:02:16.000Z ##

🟠 CVE-2026-93758 - High (8.1)

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93687
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T18:32:02

2 posts

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.

thehackerwire@mastodon.social at 2026-09-18T17:05:11.000Z ##

🟠 CVE-2026-93687 - High (7.5)

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js proce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T17:05:11.000Z ##

🟠 CVE-2026-93687 - High (7.5)

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js proce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93753
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T18:32:01

2 posts

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without ow

thehackerwire@mastodon.social at 2026-09-18T20:01:19.000Z ##

🟠 CVE-2026-93753 - High (7.5)

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T20:01:19.000Z ##

🟠 CVE-2026-93753 - High (7.5)

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93760
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-18T18:31:58

2 posts

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may influence how the database evaluates the query. This may result in unintended disclosure of stored field values and in reduced d

thehackerwire@mastodon.social at 2026-09-18T20:02:10.000Z ##

🟠 CVE-2026-93760 - High (8.2)

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T20:02:10.000Z ##

🟠 CVE-2026-93760 - High (8.2)

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85497
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-18T18:31:57

2 posts

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.

cR0w at 2026-09-18T18:38:34.044Z ##

Oh look, yet another sev:CRIT CVE where the CVSS string doesn't match the description. Thanks, Doge.

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.

nvd.nist.gov/vuln/detail/cve-2

##

cR0w@infosec.exchange at 2026-09-18T18:38:34.000Z ##

Oh look, yet another sev:CRIT CVE where the CVSS string doesn't match the description. Thanks, Doge.

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.

nvd.nist.gov/vuln/detail/cve-2

##

CVE-2026-84398
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T18:31:54

2 posts

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.

thehackerwire@mastodon.social at 2026-09-18T17:05:30.000Z ##

🟠 CVE-2026-84398 - High (7.5)

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T17:05:30.000Z ##

🟠 CVE-2026-84398 - High (7.5)

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93606
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-18T18:18:31.267000

2 posts

vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps `then`/`catch` rejection slots that hold a function, and the sandbox-side `Symbol.species`/`

CVE-2026-93597
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-18T18:18:29.630000

2 posts

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or loopback IPv4 payloads to reach internal services and cloud metadata endpoints.

thehackerwire@mastodon.social at 2026-09-18T15:05:34.000Z ##

🟠 CVE-2026-93597 - High (7.7)

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T15:05:34.000Z ##

🟠 CVE-2026-93597 - High (7.7)

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67100
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-09-18T18:17:11.110000

4 posts

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations.

DailyCyberSecurity at 2026-09-18T09:26:48.724Z ##

HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.

securityonline.info/hcl-bigfix

##

offseq at 2026-09-18T09:00:25.506Z ##

CVE-2026-67100: HCL BigFix Service Management v23 faces CRITICAL SQL injection & cross-tenant data exposure (CVSS 9.8). Authenticated attackers can access PII across orgs. No patch yet — restrict access & monitor logs. radar.offseq.com/threat/cve-20

##

DailyCyberSecurity@infosec.exchange at 2026-09-18T09:26:48.000Z ##

HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.

#HCLBigFix #Cybersecurity #CVE202667100 #Vulnerability #InfoSec

securityonline.info/hcl-bigfix

##

offseq@infosec.exchange at 2026-09-18T09:00:25.000Z ##

CVE-2026-67100: HCL BigFix Service Management v23 faces CRITICAL SQL injection & cross-tenant data exposure (CVSS 9.8). Authenticated attackers can access PII across orgs. No patch yet — restrict access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #SQLi #Infosec

##

CVE-2026-90999
(9.8 CRITICAL)

EPSS: 0.22%

updated 2026-09-18T17:49:08.457000

3 posts

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.

sayzard@mastodon.sayzard.org at 2026-09-18T14:44:00.000Z ##

PhantomFix: A fake bug to Sentry Seer gets a coding agent to run attacker code

CERT/CC는 Sentry Seer가 이슈를 코딩 에이전트에 자동으로 넘기도록 설정된 경우, 공개 DSN으로 제출한 조작된 오류 이벤트가 에이전트 프롬프트에 유입되는 취약점(CVE-2026-90999)을 공개했습니다. 공격자는 예외 메시지·스택 트레이스·breadcrumb 등 텔레메트리 필드를 이용해 가짜 버그 분석을 만들고, 코딩 에이전트가 공격자 제어 패키지를 내려받아 실행하도록 유도할 수 있습니다. 그 결과 PR 검토 이전에 연결된 저장소에 접근 가능한 에이전트 실행 환경에서 임의 코드 실행이 가능할 수 있습니다. 현재 공급업체 패치 정보는 없으므로 Seer의 자동 re...

kb.cert.org/vuls/id/212479

##

_r_netsec at 2026-09-17T14:13:04.850Z ##

CVE-2026-90999: A fabricated Sentry bug report can make Seer's coding agent run attacker code agyn.io/blog/sentry-seer-autof

##

_r_netsec@infosec.exchange at 2026-09-17T14:13:04.000Z ##

CVE-2026-90999: A fabricated Sentry bug report can make Seer's coding agent run attacker code agyn.io/blog/sentry-seer-autof

##

CVE-2026-92943
(8.1 HIGH)

EPSS: 0.27%

updated 2026-09-18T17:48:19.003000

2 posts

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages that the device processes as authentic, via a certificate issued for an unrelated ho

thehackerwire@mastodon.social at 2026-09-17T21:00:31.000Z ##

🟠 CVE-2026-92943 - High (8.1)

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T21:00:31.000Z ##

🟠 CVE-2026-92943 - High (8.1)

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61672
(7.1 HIGH)

EPSS: 0.00%

updated 2026-09-18T17:16:58.537000

1 posts

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assumes byte-order sorting. When an administrator's forbidden list mixes capitalized and lowercase keys or otherwise has different case-insensitive and byte ordering, th

hugovalters@mastodon.social at 2026-09-18T23:05:34.000Z ##

CVE-2026-61672 - Policy bypass vulnerability in Capsule for Kubernetes allows metadata restriction evasion. CVSS 7.1. Update to 0.13.7 now. #CVE #Kubernetes #infosec

valtersit.com/cve/CVE-2026-616

##

CVE-2026-93688
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T16:17:15.683000

2 posts

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /generate endpoint and submit arbitrary bootstrap_room values to exhaust prefill process memory until out-of-memory termination.

thehackerwire@mastodon.social at 2026-09-18T17:05:18.000Z ##

🟠 CVE-2026-93688 - High (7.5)

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /gene...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T17:05:18.000Z ##

🟠 CVE-2026-93688 - High (7.5)

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /gene...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93374
(9.6 CRITICAL)

EPSS: 0.27%

updated 2026-09-18T15:33:12

2 posts

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

DailyCyberSecurity at 2026-09-18T06:21:23.470Z ##

Google patched critical Google Chrome vulnerabilities. Update now to address multiple Google Chrome vulnerabilities like CVE-2026-93374 and stay secure.

securityonline.info/google-chr

##

DailyCyberSecurity@infosec.exchange at 2026-09-18T06:21:23.000Z ##

Google patched critical Google Chrome vulnerabilities. Update now to address multiple Google Chrome vulnerabilities like CVE-2026-93374 and stay secure.

#GoogleChrome #ChromeSecurity #CVE202693374 #BrowserSecurity #InfoSec

securityonline.info/google-chr

##

CVE-2026-53266
(8.8 HIGH)

EPSS: 0.12%

updated 2026-09-18T15:32:49

4 posts

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Aski

AAKL at 2026-09-18T15:47:33.739Z ##

New.

CISA Adds Two Known Exploited Vulnerabilities to Catalog.

CVE-2025-39964 Linux Kernel Race Condition Vulnerability cve.org/CVERecord?id=CVE-2025-

CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability cve.org/CVERecord?id=CVE-2026-

##

secdb at 2026-09-18T15:00:11.403Z ##

🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-39964 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/0f28c4; git.kernel.org/stable/c/e4c1ec; git.kernel.org/stable/c/1f323a; git.kernel.org/stable/c/7c4491; git.kernel.org/stable/c/9aee87; git.kernel.org/stable/c/45bcf6; git.kernel.org/stable/c/1b34cb ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-53266 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/bf84ad; git.kernel.org/stable/c/76280b; git.kernel.org/stable/c/b7e919; git.kernel.org/stable/c/afd64b; git.kernel.org/stable/c/153ea9; git.kernel.org/stable/c/b18675; git.kernel.org/stable/c/c9b5ff; git.kernel.org/stable/c/67ba97 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-09-18T15:47:33.000Z ##

New.

CISA Adds Two Known Exploited Vulnerabilities to Catalog.

CVE-2025-39964 Linux Kernel Race Condition Vulnerability cve.org/CVERecord?id=CVE-2025-

CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #Linux #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-18T15:00:11.000Z ##

🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-39964 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/0f28c4; git.kernel.org/stable/c/e4c1ec; git.kernel.org/stable/c/1f323a; git.kernel.org/stable/c/7c4491; git.kernel.org/stable/c/9aee87; git.kernel.org/stable/c/45bcf6; git.kernel.org/stable/c/1b34cb ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-53266 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/bf84ad; git.kernel.org/stable/c/76280b; git.kernel.org/stable/c/b7e919; git.kernel.org/stable/c/afd64b; git.kernel.org/stable/c/153ea9; git.kernel.org/stable/c/b18675; git.kernel.org/stable/c/c9b5ff; git.kernel.org/stable/c/67ba97 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260918 #cisa20260918 #cve_2025_39964 #cve_2026_53266 #cve202539964 #cve202653266

##

CVE-2026-93605
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-18T15:32:25

2 posts

vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.

CVE-2026-93603
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-18T15:32:25

2 posts

vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.g. `fn()`, a detached method, `fn.call()`, `fn.apply(undefined)`, `Reflect.apply(fn, undefined, [])`, or `fn.bind()()` — the undefined receiver is passed straight

CVE-2026-93592
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T15:32:24

2 posts

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.

thehackerwire@mastodon.social at 2026-09-18T15:05:58.000Z ##

🟠 CVE-2026-93592 - High (7.5)

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T15:05:58.000Z ##

🟠 CVE-2026-93592 - High (7.5)

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93591
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-18T15:32:24

2 posts

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can inject SQL via inline HTML span tags in the getGraph endpoint to execute arbitrary queries on the read-write database and exfiltrate private data across n

thehackerwire@mastodon.social at 2026-09-18T15:05:51.000Z ##

🟠 CVE-2026-93591 - High (7.6)

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T15:05:51.000Z ##

🟠 CVE-2026-93591 - High (7.6)

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93491
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-18T15:32:17

2 posts

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.

thehackerwire@mastodon.social at 2026-09-18T14:03:37.000Z ##

🟠 CVE-2026-93491 - High (7.5)

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T14:03:37.000Z ##

🟠 CVE-2026-93491 - High (7.5)

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87886
(7.8 HIGH)

EPSS: 0.28%

updated 2026-09-18T15:32:10

5 posts

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

Matchbook3469@mastodon.social at 2026-09-18T00:48:28.000Z ##

🟠 New security advisory:

CVE-2026-87886 affects multiple systems.

• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#CVE #ZeroDay #ThreatIntel

##

netsecio@mastodon.social at 2026-09-17T15:31:25.000Z ##

📰 CISA Adds Actively Exploited Cisco and Acronis Flaws to KEV Catalog

CISA adds two actively exploited vulnerabilities to its KEV catalog: a critical Cisco ISE auth bypass (CVE-2026-76460) and an Acronis Backup flaw (CVE-2026-87886). Federal agencies must patch urgently. #CISA #KEV #PatchNow

🔗 cyber.netsecops.io/articles/ci

##

thecybermind@infosec.exchange at 2026-09-17T10:11:07.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-87886 – Acronis Backup Incorrect Default Permissions Vulnerability

A strategic executive briefing detailing permission hardening, risk deliberation, and incident response frameworks for CVE-2026-87886 in Acronis Backup environments....

thecybermind.co/enr6

##

beyondmachines1@infosec.exchange at 2026-09-17T10:01:14.000Z ##

Acronis Patches Actively Exploited Privilege Escalation Flaw in Hosting Plugins

Acronis patched a high-severity privilege escalation vulnerability (CVE-2026-87886) in its cPanel and Plesk backup plugins that attackers are actively exploiting in the wild. The flaw allows local users to gain root access by taking advantage of insecure file permissions.

**Check your Linux hosting servers for the Acronis backup plugin and update it to the latest version right now. Attackers are already using this flaw to gain root access, so do not wait for your next scheduled maintenance window.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cisakevtracker@mastodon.social at 2026-09-16T20:00:47.000Z ##

CVE ID: CVE-2026-87886
Vendor: Acronis
Product: Backup
Date Added: 2026-09-16
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-39964
(3.3 LOW)

EPSS: 0.32%

updated 2026-09-18T15:31:06

4 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates

1 repos

https://github.com/n1k0oowang/CVE-2025-39964_EXP

AAKL at 2026-09-18T15:47:33.739Z ##

New.

CISA Adds Two Known Exploited Vulnerabilities to Catalog.

CVE-2025-39964 Linux Kernel Race Condition Vulnerability cve.org/CVERecord?id=CVE-2025-

CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability cve.org/CVERecord?id=CVE-2026-

##

secdb at 2026-09-18T15:00:11.403Z ##

🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-39964 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/0f28c4; git.kernel.org/stable/c/e4c1ec; git.kernel.org/stable/c/1f323a; git.kernel.org/stable/c/7c4491; git.kernel.org/stable/c/9aee87; git.kernel.org/stable/c/45bcf6; git.kernel.org/stable/c/1b34cb ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-53266 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/bf84ad; git.kernel.org/stable/c/76280b; git.kernel.org/stable/c/b7e919; git.kernel.org/stable/c/afd64b; git.kernel.org/stable/c/153ea9; git.kernel.org/stable/c/b18675; git.kernel.org/stable/c/c9b5ff; git.kernel.org/stable/c/67ba97 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-09-18T15:47:33.000Z ##

New.

CISA Adds Two Known Exploited Vulnerabilities to Catalog.

CVE-2025-39964 Linux Kernel Race Condition Vulnerability cve.org/CVERecord?id=CVE-2025-

CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #Linux #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-18T15:00:11.000Z ##

🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-39964 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/0f28c4; git.kernel.org/stable/c/e4c1ec; git.kernel.org/stable/c/1f323a; git.kernel.org/stable/c/7c4491; git.kernel.org/stable/c/9aee87; git.kernel.org/stable/c/45bcf6; git.kernel.org/stable/c/1b34cb ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-53266 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/bf84ad; git.kernel.org/stable/c/76280b; git.kernel.org/stable/c/b7e919; git.kernel.org/stable/c/afd64b; git.kernel.org/stable/c/153ea9; git.kernel.org/stable/c/b18675; git.kernel.org/stable/c/c9b5ff; git.kernel.org/stable/c/67ba97 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260918 #cisa20260918 #cve_2025_39964 #cve_2026_53266 #cve202539964 #cve202653266

##

CVE-2026-17086
(8.8 HIGH)

EPSS: 0.89%

updated 2026-09-18T15:17:06.153000

2 posts

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this

thehackerwire@mastodon.social at 2026-09-18T07:04:42.000Z ##

🟠 CVE-2026-17086 - High (8.8)

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for auth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T07:04:42.000Z ##

🟠 CVE-2026-17086 - High (8.8)

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for auth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85410
(8.1 HIGH)

EPSS: 0.31%

updated 2026-09-18T13:23:37.403000

2 posts

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-leve

thehackerwire@mastodon.social at 2026-09-18T14:05:34.000Z ##

🟠 CVE-2026-85410 - High (8.1)

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T14:05:34.000Z ##

🟠 CVE-2026-85410 - High (8.1)

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93450
(7.5 HIGH)

EPSS: 0.66%

updated 2026-09-18T13:18:38.450000

2 posts

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI specifications, causing fatal stack overflow that terminates the process and all in-flight requests.

thehackerwire@mastodon.social at 2026-09-18T03:03:20.000Z ##

🟠 CVE-2026-93450 - High (7.5)

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T03:03:20.000Z ##

🟠 CVE-2026-93450 - High (7.5)

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54671
(8.8 HIGH)

EPSS: 0.41%

updated 2026-09-18T13:18:33.920000

2 posts

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional access for every authenticated user. The methods in web/controle/InternoControle.php, including listarUm, alterar, and excluir, accept user-controlled id or

thehackerwire@mastodon.social at 2026-09-17T23:00:35.000Z ##

🟠 CVE-2026-54671 - High (8.8)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T23:00:35.000Z ##

🟠 CVE-2026-54671 - High (8.8)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-28198
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-18T12:31:28

2 posts

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. Successful exploitation grants the attacker an unrestricted root shell with full control over the Flex appliance host and all hosted containers, completely compr

thehackerwire@mastodon.social at 2026-09-18T14:03:56.000Z ##

🟠 CVE-2026-28198 - High (8.8)

An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could bypass the cryptographic signature
verification step of a privileged support command by supplying a
specially formed access credential. Successful...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T14:03:56.000Z ##

🟠 CVE-2026-28198 - High (8.8)

An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could bypass the cryptographic signature
verification step of a privileged support command by supplying a
specially formed access credential. Successful...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6205
(8.1 HIGH)

EPSS: 0.32%

updated 2026-09-18T09:31:21

2 posts

An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks.

thehackerwire@mastodon.social at 2026-09-18T14:05:05.000Z ##

🟠 CVE-2026-6205 - High (8.1)

An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct den...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T14:05:05.000Z ##

🟠 CVE-2026-6205 - High (8.1)

An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct den...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13684
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-09-18T09:31:20

4 posts

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

thehackerwire@mastodon.social at 2026-09-18T14:05:33.000Z ##

🔴 CVE-2026-13684 - Critical (9.8)

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity at 2026-09-18T09:42:54.161Z ##

Synology fixed 8 DSM vulnerabilities, including two critical unauthenticated flaws (CVE-2026-13684, CVE-2026-13639) on DiskStation Manager. Update now.

securityonline.info/synology-d

##

thehackerwire@mastodon.social at 2026-09-18T14:05:33.000Z ##

🔴 CVE-2026-13684 - Critical (9.8)

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-09-18T09:42:54.000Z ##

Synology fixed 8 DSM vulnerabilities, including two critical unauthenticated flaws (CVE-2026-13684, CVE-2026-13639) on DiskStation Manager. Update now.

#Synology #DSM #NAS #CVE #Vulnerability #DiskStation #InfoSec #PatchNow #NetworkSecurity #DataStorage

securityonline.info/synology-d

##

CVE-2026-67101
(9.3 CRITICAL)

EPSS: 0.27%

updated 2026-09-18T09:31:08

2 posts

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet.

offseq at 2026-09-18T12:00:28.024Z ##

CVE-2026-67101: CRITICAL SSRF in HCL BigFix Service Management v23 (CVSS 9.3). Unauthenticated attackers can access internal systems. No patch yet — restrict service and monitor requests. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-18T12:00:28.000Z ##

CVE-2026-67101: CRITICAL SSRF in HCL BigFix Service Management v23 (CVSS 9.3). Unauthenticated attackers can access internal systems. No patch yet — restrict service and monitor requests. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #Vuln #Infosec

##

CVE-2026-18911
(7.5 HIGH)

EPSS: 1.06%

updated 2026-09-18T06:32:11

2 posts

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

thehackerwire@mastodon.social at 2026-09-18T07:04:32.000Z ##

🟠 CVE-2026-18911 - High (7.5)

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T07:04:32.000Z ##

🟠 CVE-2026-18911 - High (7.5)

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18912
(7.7 HIGH)

EPSS: 1.50%

updated 2026-09-18T06:32:11

2 posts

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

thehackerwire@mastodon.social at 2026-09-18T07:04:23.000Z ##

🟠 CVE-2026-18912 - High (7.7)

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T07:04:23.000Z ##

🟠 CVE-2026-18912 - High (7.7)

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20324
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-09-18T04:17:37.867000

3 posts

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerabil

guru@thecybersecguru.com at 2026-09-18T12:30:57.000Z ##

Cisco FMC CVE-2026-20324: critical sftunnel root RCE explained

Cisco FMC CVE-2026-20324 is a critical CVSS 9.9 sftunnel flaw enabling arbitrary file writes and root command execution. Learn the impact and fix

thecybersecguru.com/news/cisco

##

undercodenews@mastodon.social at 2026-09-17T18:38:51.000Z ##

Cisco Secure Firewall Management Center Hit by Critical CVE-2026-20324 Root RCE Vulnerability + Video

A Critical Warning for Cisco Firewall Administrators A critical vulnerability in Cisco Secure Firewall Management Center (FMC) has raised concerns for organizations relying on Cisco infrastructure to manage and protect their networks. Tracked as CVE-2026-20324, the flaw carries a CVSS score of 9.9 and can allow an authenticated remote attacker to execute arbitrary…

undercodenews.com/cisco-secure

##

guru@thecybersecguru.com at 2026-09-18T12:30:57.000Z ##

Cisco FMC CVE-2026-20324: critical sftunnel root RCE explained

Cisco FMC CVE-2026-20324 is a critical CVSS 9.9 sftunnel flaw enabling arbitrary file writes and root command execution. Learn the impact and fix

thecybersecguru.com/news/cisco

##

CVE-2026-93456
(8.2 HIGH)

EPSS: 0.15%

updated 2026-09-18T03:30:28

2 posts

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing unescaped content that renders to all visitors, enabling stored cross-site scripting attacks.

thehackerwire@mastodon.social at 2026-09-18T03:03:10.000Z ##

🟠 CVE-2026-93456 - High (8.2)

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T03:03:10.000Z ##

🟠 CVE-2026-93456 - High (8.2)

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93452
(7.5 HIGH)

EPSS: 0.49%

updated 2026-09-18T00:31:21

2 posts

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination.

thehackerwire@mastodon.social at 2026-09-18T03:03:29.000Z ##

🟠 CVE-2026-93452 - High (7.5)

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's rem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T03:03:29.000Z ##

🟠 CVE-2026-93452 - High (7.5)

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's rem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70469
(7.5 HIGH)

EPSS: 0.37%

updated 2026-09-17T21:32:42

1 posts

Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances of the Content-Encoding header and did not reject non-standard identifiers for gzip encoding, allowing a malicious client to send crafted r

DailyCyberSecurity@infosec.exchange at 2026-09-17T03:08:21.000Z ##

Learn about recent Apache NiFi vulnerabilities (CVE-2026-87976, CVE-2026-70469) and Apache MyFaces flaws. Apply Apache security updates to prevent DoS attacks.

#ApacheNiFi #ApacheMyFaces #Vulnerability #CVE202687976 #Cybersecurity

securityonline.info/apache-nif

##

CVE-2026-84858
(8.8 HIGH)

EPSS: 0.68%

updated 2026-09-17T21:32:41

1 posts

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on this method and so it is possible for an attacker with access to a low privile

AAKL@infosec.exchange at 2026-09-16T17:17:37.000Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability

##

CVE-2026-92956
(10.0 CRITICAL)

EPSS: 0.40%

updated 2026-09-17T20:18:59.730000

2 posts

vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox code receives that raw host error, walks from the h

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92946
(10.0 CRITICAL)

EPSS: 0.59%

updated 2026-09-17T20:18:59.483000

2 posts

vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands via child_process.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92940
(10.0 CRITICAL)

EPSS: 0.34%

updated 2026-09-17T20:18:59.213000

2 posts

vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin loader wraps host modules in a read-only proxy, but method calls such as Agent.prototype.on() are forwarded to the underlying host object, so sandbox code can register a listener for the agent's 'free' event. When an unr

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92919
(8.1 HIGH)

EPSS: 0.38%

updated 2026-09-17T20:18:58.840000

2 posts

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the configured storage directory and overwrite arbitrary files accessible to the server process.

thehackerwire@mastodon.social at 2026-09-17T14:02:33.000Z ##

🟠 CVE-2026-92919 - High (8.1)

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T14:02:33.000Z ##

🟠 CVE-2026-92919 - High (8.1)

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89026
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-09-17T20:18:52.037000

2 posts

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, c

1 repos

https://github.com/cflowsec/CVE-2026-89026

571906@ap.podcastindex.org at 2026-09-18T02:00:02.000Z ##

New Episode: SANS Stormcast Friday, September 18th, 2026: LousivLaoder Analysis; Issabel Framework 0-Day; Cyber Decoys; CISA Vuln Bulletin; Unbound Vulnerability

Shownotes:

LausivLoader analysis, or how to pass data between malware stages
https://isc.sans.edu/diary/LausivLoader%20analysis%2C%20or%20how%20to%20pass%20data%20between%20malware%20stages/33348
Issabel Framework Hard-coded JWT Key RCE CVE-2026-89026

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

cyberworldops@infosec.exchange at 2026-09-17T04:30:00.000Z ##

Unauthenticated RCE in Issabel Framework (CVE-2026-89026) is being exploited in the wild. A hardcoded JWT secret in pbxapi/index.php allows token forgery and OS command execution as the Asterisk user, risking full PBX takeover. #Issabel #RemoteCodeExecution #InfoSec

cyberworldops.eu/en/one-shared

##

CVE-2026-87976
(0 None)

EPSS: 0.39%

updated 2026-09-17T20:18:51.303000

1 posts

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticat

DailyCyberSecurity@infosec.exchange at 2026-09-17T03:08:21.000Z ##

Learn about recent Apache NiFi vulnerabilities (CVE-2026-87976, CVE-2026-70469) and Apache MyFaces flaws. Apply Apache security updates to prevent DoS attacks.

#ApacheNiFi #ApacheMyFaces #Vulnerability #CVE202687976 #Cybersecurity

securityonline.info/apache-nif

##

CVE-2026-54692
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-17T20:16:52.550000

2 posts

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one-byte-per-literal layout, but an X10 static short file causes the flat decode loop to write two file-controlled bytes per literal. When ceil(width/8) pro

thehackerwire@mastodon.social at 2026-09-17T21:01:19.000Z ##

🟠 CVE-2026-54692 - High (7.8)

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T21:01:19.000Z ##

🟠 CVE-2026-54692 - High (7.8)

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73172
(0 None)

EPSS: 1.73%

updated 2026-09-17T19:16:55.587000

1 posts

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.

offseq@infosec.exchange at 2026-09-16T13:30:26.000Z ##

Advantech EKI-1242IEIMS (fw ≤1.06.01) suffers CRITICAL CVE-2026-73172: unauthenticated OS command injection via TCP 5058 enables remote root access. No patch yet — restrict device exposure & monitor traffic. Details: radar.offseq.com/threat/cve-20 #OffSeq #ICS #CVE202673172 #infosec

##

CVE-2026-86863
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-09-17T18:32:03

2 posts

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from request.environ and, when that returned nothing, fell back to reading the same name directly from the inbound HTTP request headers via requ

DailyCyberSecurity at 2026-09-18T02:58:24.972Z ##

A critical pgAdmin 4 authentication bypass (CVE-2026-86863) allows remote admin takeover. Patch this pgAdmin 4 authentication bypass vulnerability now.

securityonline.info/pgadmin-4-

##

DailyCyberSecurity@infosec.exchange at 2026-09-18T02:58:24.000Z ##

A critical pgAdmin 4 authentication bypass (CVE-2026-86863) allows remote admin takeover. Patch this pgAdmin 4 authentication bypass vulnerability now.

#pgAdmin #PostgreSQL #CVE202686863 #AuthenticationBypass #Cybersecurity

securityonline.info/pgadmin-4-

##

CVE-2026-92957
(9.9 CRITICAL)

EPSS: 0.49%

updated 2026-09-17T18:17:15.430000

2 posts

vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy such as `new NodeVM({ require: { builtin: ['*', '-

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92947
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-09-17T16:18:34.667000

2 posts

vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-79752
(0 None)

EPSS: 0.46%

updated 2026-09-17T16:17:44.693000

2 posts

CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passe

offseq at 2026-09-18T01:30:23.307Z ##

CVE-2026-79752: CakePHP <4.5.12, 4.6.0-4.6.4, 5.0.0-5.1.8, 5.2.0-5.2.13, 5.3.0-5.3.6 FunctionsBuilder SQL injection risk! CRITICAL severity — patch ASAP or avoid user input in $dataType, $part, $unit. radar.offseq.com/threat/databa

##

offseq@infosec.exchange at 2026-09-18T01:30:23.000Z ##

CVE-2026-79752: CakePHP <4.5.12, 4.6.0-4.6.4, 5.0.0-5.1.8, 5.2.0-5.2.13, 5.3.0-5.3.6 FunctionsBuilder SQL injection risk! CRITICAL severity — patch ASAP or avoid user input in $dataType, $part, $unit. radar.offseq.com/threat/databa #OffSeq #CakePHP #SQLi #Infosec

##

CVE-2026-92950
(8.6 HIGH)

EPSS: 0.22%

updated 2026-09-17T15:32:35

2 posts

vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92954
(8.6 HIGH)

EPSS: 0.34%

updated 2026-09-17T15:32:28

2 posts

vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into the sandbox are not marked as handled at the bridge boundary; only Promises created inside the sandbox are wrapped with a rejection-swallowing handler (lib/setup-sandbox.js), and the bridge only installs host-side rejection sanitizers when sandbox co

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92938
(9.9 CRITICAL)

EPSS: 0.42%

updated 2026-09-17T15:32:28

2 posts

vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver treats any request starting with 'node:' as a core-module request and t

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92948
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-09-17T15:32:27

2 posts

vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test'] }). On Node.js 24+, module.builtinModules exposes the scheme-only key node:test, which is not covered by vm2's family-based DANGEROUS_BUILTINS protection, so it i

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92951
(9.9 CRITICAL)

EPSS: 0.37%

updated 2026-09-17T15:32:26

2 posts

vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute unauthorized host packages in the host context.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92935
(9.0 None)

EPSS: 0.50%

updated 2026-09-17T15:32:26

2 posts

vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === 'object' && requireOpts !== null`, so an array-shaped `require` value (for example `require: []`) satisfies the guard that is meant to reject nesting without an explicit require configuration. `makeResolverFromLegacyOptions()`

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92944
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-09-17T15:32:26

2 posts

vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an async function that returns a Promise with an attacker-controlled constructor Symbol.species, allowing them to reach the host Function constr

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92941
(10.0 CRITICAL)

EPSS: 0.27%

updated 2026-09-17T15:32:26

2 posts

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-co

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92937
(10.0 CRITICAL)

EPSS: 0.79%

updated 2026-09-17T15:32:23

2 posts

vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bridge.js:1624 identity-checks only the direct call target when deciding whether to rebuild/sanitise a rejected host Promise value. Registering the rejection handler through Function.prototype.call or .apply indirection (e.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-81481
(7.5 HIGH)

EPSS: 0.53%

updated 2026-09-17T15:32:18

2 posts

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

thehackerwire@mastodon.social at 2026-09-17T14:02:43.000Z ##

🟠 CVE-2026-81481 - High (7.5)

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T14:02:43.000Z ##

🟠 CVE-2026-81481 - High (7.5)

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92955
(10.0 CRITICAL)

EPSS: 0.62%

updated 2026-09-17T15:32:17

2 posts

vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with process context, bypassing code generation restrictions.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92960
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-09-17T15:17:01.170000

2 posts

vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host process DNS resolver globally, redirecting all subsequent host DNS queries through an attacker-controlled resolver.

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92939
(9.9 CRITICAL)

EPSS: 0.53%

updated 2026-09-17T15:17:00.650000

2 posts

vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, but its callable exports still execute with host-process authority. Sandboxed JavaScript can therefore call crypto.setEngine() with a filesystem path to an attacker-supplied native library (for example, one bundled in an u

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92934
(9.0 CRITICAL)

EPSS: 0.74%

updated 2026-09-17T15:17:00.520000

2 posts

vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to access unsanitized host proxies embedded in the errors array, enabling full remote code execution and process information dis

cR0w at 2026-09-17T18:34:20.124Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

cR0w@infosec.exchange at 2026-09-17T18:34:20.000Z ##

ICYMI: 19 sev:CRIT CVEs in Node VM2, which is supposed to be a sandbox, but apparently it's built like the AI "sandboxes."

cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-92578
(8.1 HIGH)

EPSS: 0.33%

updated 2026-09-17T15:16:58.247000

1 posts

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password v

offseq@infosec.exchange at 2026-09-17T00:00:35.000Z ##

CVE-2026-92578: CRITICAL auth bypass in WWBN AVideo (≤29.0) allows attackers with stolen password hashes to log in as any user — no password needed. Patch pending — restrict hash access, monitor for abuse. radar.offseq.com/threat/cve-20 #OffSeq #CVE202692578 #authentication #infosec

##

CVE-2026-92918
(8.8 HIGH)

EPSS: 0.35%

updated 2026-09-17T13:17:01.013000

2 posts

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and replay them as bearer credentials for full user access.

thehackerwire@mastodon.social at 2026-09-17T14:02:24.000Z ##

🟠 CVE-2026-92918 - High (8.8)

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and repla...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T14:02:24.000Z ##

🟠 CVE-2026-92918 - High (8.8)

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and repla...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76460
(10.0 CRITICAL)

EPSS: 0.78%

updated 2026-09-17T12:46:31.670000

32 posts

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized ac

1 repos

https://github.com/S3v3n-JG/CVE-2026-76460

netsecio@mastodon.social at 2026-09-18T15:43:36.000Z ##

📰 Cisco ISE Zero-Day (CVSS 10.0) Under Active Attack, Bypasses Auth

Cisco warns of a critical (CVSS 10.0) zero-day in Identity Services Engine (ISE) actively exploited in the wild. The flaw, CVE-2026-76460, allows full authentication bypass. CISA added to KEV catalog. Patch immediately! #Cisco #ZeroDay #CyberSecurity

🔗 cyber.netsecops.io/articles/ci

##

cyclone at 2026-09-18T14:20:41.864Z ##

Cisco ISE zero-day CVE-2026-76460 is being actively exploited.

The CVSS 10.0 flaw allows remote, unauthenticated attackers to bypass authentication and potentially execute commands with root privileges.

Cisco says there is no complete workaround and recommends upgrading immediately.

Read more here:
forum.hashpwn.net/post/16740

##

PC_Fluesterer@social.tchncs.de at 2026-09-18T12:47:45.000Z ##

Noch ein Cisco Zero-Day (perfekte 10) unter Angriff

Ja, Cisco-Evangelisten müssen dieser Tage ganz stark sein. Kurz nach dem Desaster mit dem "sicheren" E-Mail-Gateway ist die nächste "Sicherheitslücke" aufgefallen, weil sie bereits angegriffen wird. CVE-2026-76460 hat eine perfekte 10 (von 10) als Risiko-Einstufung erhalten. Die "Sicherheitslücke" steckt in der Cisco Identity Services Engine (ISE). Wie der Name nahelegt, ist die Aufgabe dieser Funktion, Benutzer/innen zu identifizieren und dann für bestimmte Tätigkeiten zu autorisieren. Die Schwachstelle entsteht durch, ich zitiere: "... insufficient authentication control ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #backdoor #closedsource #exploits #hersteller #identität #sicherheit #UnplugTrump #zeroday #cisco

##

oversecurity@mastodon.social at 2026-09-18T12:00:10.000Z ##

Cisco ISE Vulnerability With CVSS 10.0 Score Under Active Attack

Cisco patched CVE-2026-76460, a critical Cisco Identity Services Engine (ISE) bug under active attack. CISA lists it as an exploited vulnerability.

🔗️ [Thecyberexpress] link.is.it/LOu95i

##

ottoto2017@prattohome.com at 2026-09-18T08:03:46.000Z ##

「Cisco、ISE認証バイパスの新たなゼロデイ脆弱性(CVSS 10.0)が現在進行中の攻撃で悪用されていると警告 」: #TheHackerNews

「Ciscoは、Identity Services Engine(ISE)に影響を与える新たな最高レベルのセキュリティ脆弱性が発見され、現在悪用されていると警告した。

CVE-2026-76460 (CVSSスコア:10.0)として追跡されているこの脆弱性により 、認証されていないリモート攻撃者が認証を回避できる可能性がある。

「この脆弱性は、APIエンドポイントにおける認証制御の不備に起因するものです」とシスコは述べています。「攻撃者は、細工されたリクエストを影響を受けるAPIエンドポイントに送信することで、この脆弱性を悪用する可能性があります。攻撃が成功すると、攻撃者はWebベースの管理インターフェースを迂回して、影響を受けるデバイスへの不正アクセスを取得できる可能性があります。」 」

thehackernews.com/2026/09/cisc

#prattohome

##

Analyst207@mastodon.social at 2026-09-18T06:03:06.000Z ##

Cisco Discloses Second Actively Exploited Zero-Day Vulnerability

Cisco has disclosed a second actively exploited zero-day vulnerability, CVE-2026-76460, a maximum-severity flaw in its Identity Services Engine (ISE) that lets attackers bypass authentication and take full control of affected devices. This vulnerability is particularly alarming because it allows hackers to modify network access…

osintsights.com/cisco-disclose

#ZeroDay #Cisco #IdentityServicesEngine #Cve202676460 #AuthenticationBypass

##

youranonnewsirc@nerdculture.de at 2026-09-18T04:26:20.000Z ##

Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.

#Cybersecurity #TechNews #Geopolitics

##

threatnoir at 2026-09-18T03:05:51.971Z ##

⚠️ CRITICAL: Cisco alerts customers to second actively exploited zero-day in as many days

Cisco ISE zero-day CVE-2026-76460 is actively exploited in the wild. Remote attackers can bypass authentication, take full device control, modify network policies, and steal credentials. If you run ISE, this is a direct threat to your network perimeter and access controls.

threatnoir.com/focus

🤖 AI generated summary

##

undercodenews@mastodon.social at 2026-09-18T02:16:37.000Z ##

Cisco ISE Faces a Critical Zero-Day Threat as CISA Adds CVE-2026-76460 to the KEV Catalog + Video

A Critical Warning for Cisco ISE Administrators A new Cisco security vulnerability has moved rapidly from a newly disclosed flaw to an active-exploitation concern. On September 16, 2026, Cisco disclosed CVE-2026-76460, a critical authentication-bypass vulnerability affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Cisco…

undercodenews.com/cisco-ise-fa

##

Matchbook3469@mastodon.social at 2026-09-17T19:36:05.000Z ##

🔵 THREAT INTELLIGENCE

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Vulnerability | CRITICAL
CVEs: CVE-2026-76460

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in...

Full analysis:
yazoul.net/news/article/cisco-

by Yazoul AI

#InfoSec #Ransomware #IncidentResponse

##

netsecio@mastodon.social at 2026-09-17T15:31:25.000Z ##

📰 CISA Adds Actively Exploited Cisco and Acronis Flaws to KEV Catalog

CISA adds two actively exploited vulnerabilities to its KEV catalog: a critical Cisco ISE auth bypass (CVE-2026-76460) and an Acronis Backup flaw (CVE-2026-87886). Federal agencies must patch urgently. #CISA #KEV #PatchNow

🔗 cyber.netsecops.io/articles/ci

##

netsecio@mastodon.social at 2026-09-17T15:31:22.000Z ##

📰 Cisco ISE Zero-Day (CVSS 10.0) Under Active Attack, Bypasses Auth

Cisco warns of a critical (CVSS 10.0) zero-day in Identity Services Engine (ISE) actively exploited in the wild. The flaw, CVE-2026-76460, allows full authentication bypass. CISA added to KEV catalog. Patch immediately! #Cisco #ZeroDay #CyberSecurity

🔗 cyber.netsecops.io/articles/ci

##

Analyst207@mastodon.social at 2026-09-17T14:10:01.000Z ##

Cisco Discloses Zero-Day ISE Auth Bypass Under Active Exploitation

Cisco has uncovered a critical zero-day vulnerability, CVE-2026-76460, that lets hackers bypass authentication on its Identity Services Engine and Passive Identity Connector, and it's already being exploited by attackers. This flaw allows unauthorized access to affected devices with just a crafted request.

osintsights.com/cisco-disclose

#ZeroDay #Cve202676460 #IdentityServicesEngine #Ise #Cisco

##

beyondmachines1 at 2026-09-17T14:01:13.778Z ##

Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days

Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.

**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**

beyondmachines.net/event_detai

##

Matchbook3469@mastodon.social at 2026-09-17T12:28:07.000Z ##

🔴 New security advisory:

CVE-2026-76460 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #SecurityPatching #HackerNews

##

undercodenews@mastodon.social at 2026-09-17T12:21:13.000Z ##

Cisco ISE Under Attack: Critical CVE-2026-76460 Gives Attackers a Path to Root Access + Video

A Maximum-Severity Warning for Network Defenders Cisco has issued an urgent warning over active exploitation of a maximum-severity vulnerability in Cisco Identity Services Engine (ISE), a platform used by organizations to control and enforce access to corporate networks. The vulnerability, tracked as CVE-2026-76460, carries the highest possible CVSS score of 10.0 and has now…

undercodenews.com/cisco-ise-un

##

Analyst207@mastodon.social at 2026-09-17T12:03:14.000Z ##

Cisco Discloses Active Exploitation of ISE Flaw

Cisco warns that a critical API vulnerability, CVE-2026-76460, is under active exploitation, allowing attackers to bypass security and gain unauthorized access to devices with a simple crafted request. This maximum-severity flaw scores a perfect 10.0 on the CVSS scale, making it a high-risk threat that demands immediate attention.

osintsights.com/cisco-disclose

#Cve202676460 #ApiVulnerability #ActiveExploitation #Cisco #IseFlaw

##

cyclone@infosec.exchange at 2026-09-18T14:20:41.000Z ##

Cisco ISE zero-day CVE-2026-76460 is being actively exploited.

The CVSS 10.0 flaw allows remote, unauthenticated attackers to bypass authentication and potentially execute commands with root privileges.

Cisco says there is no complete workaround and recommends upgrading immediately.

Read more here:
forum.hashpwn.net/post/16740

#Cisco #CVE #CyberSecurity #InfoSec #hashpwn

##

PC_Fluesterer@social.tchncs.de at 2026-09-18T12:47:45.000Z ##

Noch ein Cisco Zero-Day (perfekte 10) unter Angriff

Ja, Cisco-Evangelisten müssen dieser Tage ganz stark sein. Kurz nach dem Desaster mit dem "sicheren" E-Mail-Gateway ist die nächste "Sicherheitslücke" aufgefallen, weil sie bereits angegriffen wird. CVE-2026-76460 hat eine perfekte 10 (von 10) als Risiko-Einstufung erhalten. Die "Sicherheitslücke" steckt in der Cisco Identity Services Engine (ISE). Wie der Name nahelegt, ist die Aufgabe dieser Funktion, Benutzer/innen zu identifizieren und dann für bestimmte Tätigkeiten zu autorisieren. Die Schwachstelle entsteht durch, ich zitiere: "... insufficient authentication control ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #backdoor #closedsource #exploits #hersteller #identität #sicherheit #UnplugTrump #zeroday #cisco

##

oversecurity@mastodon.social at 2026-09-18T12:00:10.000Z ##

Cisco ISE Vulnerability With CVSS 10.0 Score Under Active Attack

Cisco patched CVE-2026-76460, a critical Cisco Identity Services Engine (ISE) bug under active attack. CISA lists it as an exploited vulnerability.

🔗️ [Thecyberexpress] link.is.it/LOu95i

##

ottoto2017@prattohome.com at 2026-09-18T08:03:46.000Z ##

「Cisco、ISE認証バイパスの新たなゼロデイ脆弱性(CVSS 10.0)が現在進行中の攻撃で悪用されていると警告 」: #TheHackerNews

「Ciscoは、Identity Services Engine(ISE)に影響を与える新たな最高レベルのセキュリティ脆弱性が発見され、現在悪用されていると警告した。

CVE-2026-76460 (CVSSスコア:10.0)として追跡されているこの脆弱性により 、認証されていないリモート攻撃者が認証を回避できる可能性がある。

「この脆弱性は、APIエンドポイントにおける認証制御の不備に起因するものです」とシスコは述べています。「攻撃者は、細工されたリクエストを影響を受けるAPIエンドポイントに送信することで、この脆弱性を悪用する可能性があります。攻撃が成功すると、攻撃者はWebベースの管理インターフェースを迂回して、影響を受けるデバイスへの不正アクセスを取得できる可能性があります。」 」

thehackernews.com/2026/09/cisc

#prattohome

##

youranonnewsirc@nerdculture.de at 2026-09-18T04:26:20.000Z ##

Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.

#Cybersecurity #TechNews #Geopolitics

##

threatnoir@infosec.exchange at 2026-09-18T03:05:51.000Z ##

⚠️ CRITICAL: Cisco alerts customers to second actively exploited zero-day in as many days

Cisco ISE zero-day CVE-2026-76460 is actively exploited in the wild. Remote attackers can bypass authentication, take full device control, modify network policies, and steal credentials. If you run ISE, this is a direct threat to your network perimeter and access controls.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

beyondmachines1@infosec.exchange at 2026-09-17T14:01:13.000Z ##

Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days

Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.

**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-09-17T10:58:07.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-76460 – Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

A strategic executive briefing detailing privileged API mitigation, network segmentation, and zero-trust verification frameworks for CVE-2026-76460 in Cisco ISE....

thecybermind.co/78ny

##

offseq@infosec.exchange at 2026-09-17T10:30:26.000Z ##

CVE-2026-76460: CRITICAL auth bypass in Cisco ISE & ISE-PIC is actively exploited. Remote attackers can gain admin access via crafted API requests. Patch ISE 3.1 – 3.5 now — no workarounds. More: radar.offseq.com/threat/cisco- #OffSeq #Cisco #ZeroDay #Vuln #Cybersecurity

##

guru@thecybersecguru.com at 2026-09-17T08:44:54.000Z ##

Cisco ISE Zero-Day: CVE-2026-76460 Bypasses Authentication With a Perfect CVSS 10.0

Cisco ISE CVE-2026-76460 is a critical CVSS 10 authentication bypass. Learn how the flaw enables admin and root access, IOCs, hunting and fixes

thecybersecguru.com/news/cisco

##

ottoto2017@prattohome.com at 2026-09-17T07:49:31.000Z ##

「Ciscoは、ISEのゼロデイ脆弱性が攻撃に悪用され、深刻な被害を受ける可能性があると警告している。 」: #BLEEPINGCOMPUTER

「シスコは、攻撃者が実際に悪用している、深刻度が最大レベルのアイデンティティサービスエンジンの脆弱性に対処するためのセキュリティアップデートをリリースしました。

Cisco ISEは、IT管理者がエンドポイント、ユーザー、およびデバイスのネットワークリソースへのアクセスを管理するために使用する集中型ポリシープラットフォームであり、多くの場合、ゼロトラストセキュリティモデルを適用しながら使用されます。

このセキュリティ上の欠陥( CVE-2026-76460 として追跡)により、リモートの攻撃者は、Cisco Identity Services Engine(ISE)およびCisco ISE Passive Identity Connector(ISE-PIC)のAPIの脆弱性を悪用することで、設定に関係なく認証を回避できます。 」

bleepingcomputer.com/news/secu

#prattohome

##

offseq@infosec.exchange at 2026-09-17T07:30:37.000Z ##

CRITICAL auth bypass (CVE-2026-76460) in Cisco ISE & ISE-PIC is being actively exploited. Remote attackers gain root on management interface via crafted API calls. Patch ASAP — no workarounds except ACLs. Details: radar.offseq.com/threat/active #OffSeq #Cisco #ZeroDay

##

cyberworldops@infosec.exchange at 2026-09-17T07:00:01.000Z ##

Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint. Unauthenticated remote access can lead to root compromise of ISE and ISE-PIC, now listed in CISA KEV. Patching and log review are urgent. #CiscoIse #AuthBypass #CisaKev

cyberworldops.eu/en/cisco-ise-

##

cR0w@infosec.exchange at 2026-09-16T17:54:16.000Z ##

Patch your Cisco ISE. CVE-2026-76460 a perfect 10 and is EITW. 🥳

sec.cloudapps.cisco.com/securi

The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T17:27:21.000Z ##

An exploited Cisco ISE vulnerability (CVE-2026-76460) allows remote root access. Patch this critical Cisco ISE vulnerability to secure networks.

#Cisco #CiscoISE #CVE202676460 #Cybersecurity #InfoSec

securityonline.info/cisco-ise-

##

CVE-2026-92913
(7.4 HIGH)

EPSS: 0.51%

updated 2026-09-17T12:18:30.290000

2 posts

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in objects/functions.php derives the code entirely from uniqid() (sprintf('%08x%05x', seconds, microseconds)) with a single non-CSPRNG rand() character used only as padding, reducing the code space to rou

offseq at 2026-09-17T12:00:25.402Z ##

CVE-2026-92913 | WWBN AVideo (CRITICAL, CVSS 9.1): Weak random pairing codes + exposed microtime API = unauthenticated account takeover risk. No patch yet — restrict API access if possible. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-17T12:00:25.000Z ##

CVE-2026-92913 | WWBN AVideo (CRITICAL, CVSS 9.1): Weak random pairing codes + exposed microtime API = unauthenticated account takeover risk. No patch yet — restrict API access if possible. radar.offseq.com/threat/cve-20 #OffSeq #AVideo #CVE202692913 #AccountSecurity

##

CVE-2026-20211
(9.1 CRITICAL)

EPSS: 0.56%

updated 2026-09-17T12:17:25.350000

1 posts

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insecure deserialization of Java objects by the affected software. An attacker could exploit this vul

AAKL@infosec.exchange at 2026-09-16T17:17:37.000Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability

##

CVE-2026-20176
(9.1 CRITICAL)

EPSS: 0.78%

updated 2026-09-17T12:17:25.200000

1 posts

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sendi

AAKL@infosec.exchange at 2026-09-16T17:17:37.000Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability

##

CVE-2026-15688(CVSS UNKNOWN)

EPSS: 0.12%

updated 2026-09-17T09:33:03

3 posts

Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the executable module in memory, and thereby may be able to view, tamper with, destroy, or delete control programs.

cyberworldops at 2026-09-18T05:10:00.815Z ##

Mitsubishi GX Works3 and bundled Motion Control Settings allow local bypass of block-password auth via in-memory patching (CVE-2026-15688). It matters because it breaks project protection for PLC logic, enabling undetected modification.

cyberworldops.eu/en/mitsubishi

##

cyberworldops@infosec.exchange at 2026-09-18T05:10:00.000Z ##

Mitsubishi GX Works3 and bundled Motion Control Settings allow local bypass of block-password auth via in-memory patching (CVE-2026-15688). It matters because it breaks project protection for PLC logic, enabling undetected modification. #OtSecurity #PlcSecurity #VulnerabilityManagement

cyberworldops.eu/en/mitsubishi

##

offseq@infosec.exchange at 2026-09-17T09:00:28.000Z ##

CVE-2026-15688 | Mitsubishi Electric GX Works3 (CVSS 9.2, CRITICAL): Local attackers can bypass authentication by modifying memory, risking control program compromise. No fix yet — restrict local access. #OffSeq #ICS #CVE202615688 radar.offseq.com/threat/cve-20

##

CVE-2026-86320
(7.8 HIGH)

EPSS: 0.22%

updated 2026-09-17T09:33:03

2 posts

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder.

thehackerwire@mastodon.social at 2026-09-17T11:00:52.000Z ##

🟠 CVE-2026-86320 - High (7.8)

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T11:00:52.000Z ##

🟠 CVE-2026-86320 - High (7.8)

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87796
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-09-17T06:30:45

1 posts

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution poss

1 repos

https://github.com/abraxas/CVE-2026-87796

offseq@infosec.exchange at 2026-09-17T06:00:25.000Z ##

CVE-2026-87796 (CRITICAL, CVSS 9.8): sh1zen Multi Uploader for Gravity Forms ≤1.1.9 lets unauthenticated attackers upload arbitrary files, risking remote code execution. No patch yet — disable the plugin or restrict uploads. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #RCE

##

CVE-2026-92576
(8.6 HIGH)

EPSS: 0.40%

updated 2026-09-17T00:31:25

1 posts

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.

offseq@infosec.exchange at 2026-09-17T01:30:25.000Z ##

CRITICAL SSRF vuln (CVE-2026-92576) in HKUDS nanobot <0.3.0: Inadequate URL validation lets attackers access internal cloud metadata & services. Restrict WebFetchTool, monitor for suspicious requests. Patch status: unconfirmed. radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202692576

##

CVE-2026-20332
(9.9 CRITICAL)

EPSS: 0.30%

updated 2026-09-16T21:32:55

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

beyondmachines1 at 2026-09-17T17:01:13.925Z ##

Cisco Patches 18 Critical and High-Severity Firewall Vulnerabilities, One Actively Exploited

Cisco released a massive security hardening update fixing 18 vulnerabilities in its Secure Firewall suite, including an actively exploited authentication bypass (CVE-2026-20332) and multiple critical remote code execution flaws.

**If you use Cisco Secure Firewall (ASA, FTD, or FMC), this is urgent. Patch now to the fixed versions Cisco lists. At least one flaw is already being exploited by attackers. Make sure the management interfaces are reachable only from your trusted internal network and never from the internet.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-17T17:01:13.000Z ##

Cisco Patches 18 Critical and High-Severity Firewall Vulnerabilities, One Actively Exploited

Cisco released a massive security hardening update fixing 18 vulnerabilities in its Secure Firewall suite, including an actively exploited authentication bypass (CVE-2026-20332) and multiple critical remote code execution flaws.

**If you use Cisco Secure Firewall (ASA, FTD, or FMC), this is urgent. Patch now to the fixed versions Cisco lists. At least one flaw is already being exploited by attackers. Make sure the management interfaces are reachable only from your trusted internal network and never from the internet.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-89082(CVSS UNKNOWN)

EPSS: 0.51%

updated 2026-09-16T21:32:55

2 posts

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.

DailyCyberSecurity at 2026-09-17T14:52:01.266Z ##

HP released updates to fix critical HP Advance vulnerabilities (CVE-2026-89082). Patch these HP Advance vulnerabilities to stop remote code execution.

securityonline.info/hp-advance

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T14:52:01.000Z ##

HP released updates to fix critical HP Advance vulnerabilities (CVE-2026-89082). Patch these HP Advance vulnerabilities to stop remote code execution.

#HP #HPAdvance #CVE202689082 #Cybersecurity #Vulnerability

securityonline.info/hp-advance

##

CVE-2026-20330
(9.9 CRITICAL)

EPSS: 0.34%

updated 2026-09-16T21:32:50

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

AAKL at 2026-09-18T16:27:33.387Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity

##

AAKL@infosec.exchange at 2026-09-18T16:27:33.000Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec

##

CVE-2026-20192
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-09-16T21:32:50

6 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-

security_crawler_carl at 2026-09-18T14:02:42.144Z ##

Reward: You've received the Cursed Amulet of Maximum CVSS — it goes great with your existing collection of regrets.

ionix.io/threat-center/cve-202

(3/3)

##

security_crawler_carl at 2026-09-18T14:02:41.867Z ##

🏆 New Achievement! Perfect Score, Perfect Doom!

Splendid news, brave adventurer! Your quest to secure the network is absolutely still possible — and to help you on your way, Cisco has gifted the world CVE-2026-20192, a shiny CVSS 10.0 access control bypass in Cisco Identity Services Engine and ISE Passive Identity Connector. Maximum score! Like a Tamagotchi dying the moment you crack the box open.

Cisco caught this one themselves during an internal review, which is the good news. (1/3)

##

beyondmachines1 at 2026-09-17T14:01:13.778Z ##

Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days

Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.

**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**

beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-09-18T14:02:42.000Z ##

Reward: You've received the Cursed Amulet of Maximum CVSS — it goes great with your existing collection of regrets.

ionix.io/threat-center/cve-202

#CyberSecurity #CVE #Cisco #CriticalVulnerability #AccessControl #PatchedOrPerish (3/3)

##

security_crawler_carl@infosec.exchange at 2026-09-18T14:02:41.000Z ##

🏆 New Achievement! Perfect Score, Perfect Doom!

Splendid news, brave adventurer! Your quest to secure the network is absolutely still possible — and to help you on your way, Cisco has gifted the world CVE-2026-20192, a shiny CVSS 10.0 access control bypass in Cisco Identity Services Engine and ISE Passive Identity Connector. Maximum score! Like a Tamagotchi dying the moment you crack the box open.

Cisco caught this one themselves during an internal review, which is the good news. (1/3)

##

beyondmachines1@infosec.exchange at 2026-09-17T14:01:13.000Z ##

Cisco Patches 21 Flaws in ISE Identity Infrastructure Including Actively Exploited Zero-Days

Cisco released a set of security updates for Identity Services Engine (ISE) addressing 21 vulnerabilities, including two critical authentication bypasses (CVE-2026-20192 and CVE-2026-76460) currently exploited by attackers to gain root access.

**Treat this as a top-priority emergency attackers are already using some of these flaws to take over identity servers. If you run Cisco ISE or ISE-PIC, first make sure the management interface is never reachable from the internet. Then patch ASAP to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 or 3.5 P4. Check your access logs for strange accounts like "dummyuser". Assume a breach if you find anything weird.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-20341
(9.1 CRITICAL)

EPSS: 0.45%

updated 2026-09-16T21:32:50

1 posts

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain&nbsp;root privileges. This vulnerability is due to unsecured deserialization of untrusted data over the sftunnel management connection. An attacker could exploit this vulnerability by sending crafted sftunnel remote procedure calls (RPCs). A succ

offseq@infosec.exchange at 2026-09-17T03:00:25.000Z ##

CVE-2026-20341: CRITICAL flaw in Cisco Secure FMC Software sftunnel protocol. Admin remote attackers can gain root via insecure deserialization. Limit admin access, monitor for abuse, and check for patch updates. radar.offseq.com/threat/a-vuln #OffSeq #Cisco #Infosec #Vulnerability

##

CVE-2026-87024
(7.2 HIGH)

EPSS: 0.31%

updated 2026-09-16T21:32:47

1 posts

Tanium addressed a SQL injection vulnerability in Asset.

CVE-2026-77179
(0 None)

EPSS: 0.16%

updated 2026-09-16T20:38:33.883000

8 posts

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

1 repos

https://github.com/HORKimhab/CVE-2026-77179

_r_netsec at 2026-09-19T06:28:04.750Z ##

CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes) accomplish.ai/blog/escaping-do

##

ottoto2017@prattohome.com at 2026-09-18T07:52:46.000Z ##

「Dockerサンドボックスの重大な脆弱性により、悪意のあるゲストコードがmacOSホストファイルを読み取り、変更することが可能になる。 」: #TheHackerNews

「Dockerは9月15日のセキュリティ発表 で、macOS上のDocker Sandboxes 仮想マシン内で実行されている悪意のあるコードが、 共有されているプロジェクトディレクトリから脱出し、ホスト上の他の場所にあるファイルを読み取ったり変更したりする可能性があると警告した 。

このエスケープ処理は、仮想マシンを実行するホストアカウントの権限で実行されます。この脆弱性( CVE-2026-77179 )は、深刻度が「重大」と評価されており、macOS 版のバージョン 0.28.0 から 0.42.0 まで(0.42.0 は含まない)に影響があり、 9 月 7 日にリリースされたバージョン 0.42.0 で修正されました。 」

thehackernews.com/2026/09/crit

#prattohome

##

guru@thecybersecguru.com at 2026-09-18T06:46:02.000Z ##

Critical Docker Sandboxes Flaws Let AI Agents Escape MicroVMs to Hijack Hosts (CVE-2026-77179 & CVE-2026-79994)

Critical Docker Sandboxes flaws CVE-2026-77179 and CVE-2026-79994 can let malicious AI agents escape microVM isolation and access the host system

thecybersecguru.com/news/docke

##

Analyst207@mastodon.social at 2026-09-18T04:04:42.000Z ##

Docker Flaw Lets Guest Code Read, Modify macOS Host Files

A newly discovered Docker flaw on macOS could allow malicious code in a virtual machine to break free from its sandbox and read or modify sensitive host files, potentially leading to code execution on the host. This vulnerability, tracked as CVE-2026-77179, leverages a weakness in the virtio-fs host server to gain unauthorized access.

osintsights.com/docker-flaw-le

#DockerFlaw #Macos #Cve202677179 #Containerization #VirtualMachine

##

_r_netsec@infosec.exchange at 2026-09-19T06:28:04.000Z ##

CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes) accomplish.ai/blog/escaping-do

##

ottoto2017@prattohome.com at 2026-09-18T07:52:46.000Z ##

「Dockerサンドボックスの重大な脆弱性により、悪意のあるゲストコードがmacOSホストファイルを読み取り、変更することが可能になる。 」: #TheHackerNews

「Dockerは9月15日のセキュリティ発表 で、macOS上のDocker Sandboxes 仮想マシン内で実行されている悪意のあるコードが、 共有されているプロジェクトディレクトリから脱出し、ホスト上の他の場所にあるファイルを読み取ったり変更したりする可能性があると警告した 。

このエスケープ処理は、仮想マシンを実行するホストアカウントの権限で実行されます。この脆弱性( CVE-2026-77179 )は、深刻度が「重大」と評価されており、macOS 版のバージョン 0.28.0 から 0.42.0 まで(0.42.0 は含まない)に影響があり、 9 月 7 日にリリースされたバージョン 0.42.0 で修正されました。 」

thehackernews.com/2026/09/crit

#prattohome

##

guru@thecybersecguru.com at 2026-09-18T06:46:02.000Z ##

Critical Docker Sandboxes Flaws Let AI Agents Escape MicroVMs to Hijack Hosts (CVE-2026-77179 & CVE-2026-79994)

Critical Docker Sandboxes flaws CVE-2026-77179 and CVE-2026-79994 can let malicious AI agents escape microVM isolation and access the host system

thecybersecguru.com/news/docke

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T02:33:27.000Z ##

Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today.

#Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity

securityonline.info/docker-san

##

CVE-2026-79994
(0 None)

EPSS: 0.11%

updated 2026-09-16T20:38:33.883000

3 posts

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary AF_UNIX socket outside the shared workspace. This can expose data or host-side cap

guru@thecybersecguru.com at 2026-09-18T06:46:02.000Z ##

Critical Docker Sandboxes Flaws Let AI Agents Escape MicroVMs to Hijack Hosts (CVE-2026-77179 & CVE-2026-79994)

Critical Docker Sandboxes flaws CVE-2026-77179 and CVE-2026-79994 can let malicious AI agents escape microVM isolation and access the host system

thecybersecguru.com/news/docke

##

guru@thecybersecguru.com at 2026-09-18T06:46:02.000Z ##

Critical Docker Sandboxes Flaws Let AI Agents Escape MicroVMs to Hijack Hosts (CVE-2026-77179 & CVE-2026-79994)

Critical Docker Sandboxes flaws CVE-2026-77179 and CVE-2026-79994 can let malicious AI agents escape microVM isolation and access the host system

thecybersecguru.com/news/docke

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T02:33:27.000Z ##

Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today.

#Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity

securityonline.info/docker-san

##

CVE-2026-70416
(10.0 CRITICAL)

EPSS: 0.91%

updated 2026-09-16T20:37:16.870000

1 posts

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

thehackerwire@mastodon.social at 2026-09-16T17:02:58.000Z ##

🔴 CVE-2026-70416 - Critical (10)

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78547
(0 None)

EPSS: 0.15%

updated 2026-09-16T19:16:15.097000

1 posts

Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.

hugovalters@mastodon.social at 2026-09-18T06:40:21.000Z ##

CVE-2026-78547: Out-of-bounds write in Citrix Workspace app for Windows. CVSS not yet assigned, no patch confirmed. Treat as urgent, update to 2603.11 CR or 2507.1 LTSR CU3 now. valtersit.com/cve/CVE-2026-785 #CVE #Citrix #infosec

##

CVE-2026-20331
(9.6 CRITICAL)

EPSS: 0.23%

updated 2026-09-16T18:32:09

3 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

AAKL at 2026-09-18T16:27:33.387Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity

##

AAKL@infosec.exchange at 2026-09-18T16:27:33.000Z ##

Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec

##

nyanbinary@infosec.exchange at 2026-09-16T18:08:42.000Z ##

@cR0w was just looking at those, lol. Don't sleep on this great advertisment of a CVE though: db.gcve.eu/vuln/cve-2026-20331

##

CVE-2026-20307
(9.9 CRITICAL)

EPSS: 0.95%

updated 2026-09-16T18:32:09

1 posts

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. A

AAKL@infosec.exchange at 2026-09-16T17:17:37.000Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability

##

CVE-2026-92397
(9.1 CRITICAL)

EPSS: 2.30%

updated 2026-09-16T18:32:09

1 posts

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

thehackerwire@mastodon.social at 2026-09-16T17:02:40.000Z ##

🔴 CVE-2026-92397 - Critical (9.1)

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89775
(9.3 CRITICAL)

EPSS: 0.17%

updated 2026-09-16T18:31:58

1 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached by the TLB. For S1 mappings such as VNCR, this is deducted from the combination of the base granule size and the mapping level. However, this implies that the S1 M

DailyCyberSecurity@infosec.exchange at 2026-09-17T02:40:47.000Z ##

A critical KVM guest escape (CVE-2026-89775) enables an LPE to gain root on Linux hosts. Patch this KVM guest escape vulnerability now.

#KVM #LinuxKernel #CVE202689775 #Cybersecurity #InfoSec

securityonline.info/kvm-guest-

##

CVE-2026-61595
(7.7 HIGH)

EPSS: 0.38%

updated 2026-09-16T15:32:15

1 posts

### Impact `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local()` and set exclusively by the HTTP-only `TenantMiddleware`, so on the live (WebSocket/SSE) path `get_current_tenant()` was always `None` during mount and every event handler — and the tenant-aware `QuerySet` manager failed **OPEN** (returned the unfiltered queryset, ignoring `

thehackerwire@mastodon.social at 2026-09-16T17:02:47.000Z ##

🟠 CVE-2026-61595 - High (7.7)

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local(...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91843
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-09-16T15:31:14

19 posts

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

1 repos

https://github.com/HORKimhab/CVE-2026-91843

security_crawler_carl at 2026-09-18T20:55:25.862Z ##

Two companion curses arrived earlier: an auth bypass in August and a heap overflow in VPN certificate decoding in September.

INVENTORY PENALTY: Your management plane is now haunted. Patch Check Point Security Management Server immediately to close CVE-2026-91843 and its critical siblings.

Reward: You've received the Debuffed Robe of Five Failures — Armor Class: negative five. The "found internally, no exploitation detected" enchantment is fading fast. (2/3)

##

security_crawler_carl at 2026-09-18T20:55:25.725Z ##

🏆 New Achievement! Stack Overflow, Stack Underdelivery!

ITEM ACQUIRED: Cursed Login Request (very long username, -9.8 integrity, equips in zero hands). Check Point's Security Management Server has taken its fifth critical unauthenticated hit since July — CVE-2026-91843, a 9.8-rated stack overflow in the login handler that lets attackers execute code as root before a single password is checked. Censys confirms the trigger: just send a comically oversized username. (1/3)

##

netsecio@mastodon.social at 2026-09-18T15:42:44.000Z ##

📰 Check Point Patches Critical RCE Flaw in Management Servers

Check Point patches critical RCE flaw (CVE-2026-91843, CVSS 9.8) in Security Management Servers. Unauthenticated attackers can gain root access via a long username. LivePatch is available. Restrict trusted client access now! #CyberSecurity #CheckPoin...

🔗 cyber.netsecops.io/articles/ch

##

offseq at 2026-09-18T10:30:23.977Z ##

Check Point Security Mgmt & Log Server face CRITICAL stack buffer overflow (CVE-2026-91843). Remote, unauthenticated RCE as root possible. Patch now or restrict access, monitor for 'Username too long' login failures. radar.offseq.com/threat/new-ch

##

undercodenews@mastodon.social at 2026-09-18T10:19:58.000Z ##

Check Point Management Servers Face Critical Root-Level Remote Code Execution Risk

A Dangerous New Flaw Puts Security Management Systems in the Spotlight A critical vulnerability in Check Point Software Technologies security management products has raised fresh concerns for organizations that rely on centralized systems to control firewalls, collect security logs, and administer enterprise networks. Tracked as CVE-2026-91843, the flaw can potentially allow an…

undercodenews.com/check-point-

##

Analyst207@mastodon.social at 2026-09-18T10:03:06.000Z ##

Check Point Flaw Enables Hackers to Execute Code with Root Privileges

A critical flaw in Check Point's Security Management Server has been discovered, leaving all deployments vulnerable to hackers who can exploit it to execute code with root privileges, putting the entire firewall estate at risk. This severe vulnerability, tracked as CVE-2026-91843, requires immediate…

osintsights.com/check-point-fl

#CheckPoint #Cve202691843 #FirewallVulnerability #RootPrivilegeEscalation #SecurityManagementServer

##

beyondmachines1 at 2026-09-18T09:01:13.603Z ##

Critical Check Point Management Flaw Allows Unauthenticated Remote Root Access

Check Point issued an patch for a critical stack overflow vulnerability (CVE-2026-91843) in its Security Management and Log Servers that allows unauthenticated attackers to gain root-level code execution.

**If you run Check Point Security Management or Log Servers, make sure they are never reachable from the internet and restrict the Trusted Clients setting so only specific, known admin IP addresses can connect (use a VPN for remote access). Then apply the LivePatch fix released on September 16, 2026 to every management and log server, confirm it installed with `cplp list`, and check your logs for "Administrator failed to log in: Username too long" to spot attempted attacks.**

beyondmachines.net/event_detai

##

undercodenews@mastodon.social at 2026-09-18T08:30:02.000Z ##

Critical Check Point Vulnerability CVE-2026-91843 Exposes Management Servers to Unauthenticated Root-Level Remote Code Execution + Video

Critical Check Point Vulnerability CVE-2026-91843 Exposes Management Servers to Unauthenticated Root-Level Remote Code Execution A Critical Warning for Check Point Administrators A newly disclosed critical vulnerability in Check Point Security Management and Log Servers could allow a remote, unauthenticated attacker to execute…

undercodenews.com/critical-che

##

offseq at 2026-09-18T07:30:24.291Z ##

Check Point Security Mgmt & Log Server hit by CRITICAL RCE (CVE-2026-91843) via unauthenticated login. No active exploitation yet. Patch ASAP. Tanium (SQLi, RCE) & Kaspersky (Redis) also patched. radar.offseq.com/threat/check-

##

youranonnewsirc@nerdculture.de at 2026-09-18T04:26:20.000Z ##

Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.

#Cybersecurity #TechNews #Geopolitics

##

security_crawler_carl@infosec.exchange at 2026-09-18T20:55:25.000Z ##

Two companion curses arrived earlier: an auth bypass in August and a heap overflow in VPN certificate decoding in September.

INVENTORY PENALTY: Your management plane is now haunted. Patch Check Point Security Management Server immediately to close CVE-2026-91843 and its critical siblings.

Reward: You've received the Debuffed Robe of Five Failures — Armor Class: negative five. The "found internally, no exploitation detected" enchantment is fading fast. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-09-18T20:55:25.000Z ##

🏆 New Achievement! Stack Overflow, Stack Underdelivery!

ITEM ACQUIRED: Cursed Login Request (very long username, -9.8 integrity, equips in zero hands). Check Point's Security Management Server has taken its fifth critical unauthenticated hit since July — CVE-2026-91843, a 9.8-rated stack overflow in the login handler that lets attackers execute code as root before a single password is checked. Censys confirms the trigger: just send a comically oversized username. (1/3)

##

offseq@infosec.exchange at 2026-09-18T10:30:23.000Z ##

Check Point Security Mgmt & Log Server face CRITICAL stack buffer overflow (CVE-2026-91843). Remote, unauthenticated RCE as root possible. Patch now or restrict access, monitor for 'Username too long' login failures. radar.offseq.com/threat/new-ch #OffSeq #CheckPoint #Vuln #RCE

##

beyondmachines1@infosec.exchange at 2026-09-18T09:01:13.000Z ##

Critical Check Point Management Flaw Allows Unauthenticated Remote Root Access

Check Point issued an patch for a critical stack overflow vulnerability (CVE-2026-91843) in its Security Management and Log Servers that allows unauthenticated attackers to gain root-level code execution.

**If you run Check Point Security Management or Log Servers, make sure they are never reachable from the internet and restrict the Trusted Clients setting so only specific, known admin IP addresses can connect (use a VPN for remote access). Then apply the LivePatch fix released on September 16, 2026 to every management and log server, confirm it installed with `cplp list`, and check your logs for "Administrator failed to log in: Username too long" to spot attempted attacks.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-09-18T07:30:24.000Z ##

Check Point Security Mgmt & Log Server hit by CRITICAL RCE (CVE-2026-91843) via unauthenticated login. No active exploitation yet. Patch ASAP. Tanium (SQLi, RCE) & Kaspersky (Redis) also patched. radar.offseq.com/threat/check- #OffSeq #Vulnerability #RCE #PatchNow

##

youranonnewsirc@nerdculture.de at 2026-09-18T04:26:20.000Z ##

Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.

#Cybersecurity #TechNews #Geopolitics

##

censys@infosec.exchange at 2026-09-16T22:29:53.000Z ##

🚨New Censys Advisory: CVE-2026-91843

A critical (CVSS 9.8) unauthenticated RCE affects Check Point Quantum Security Management and Log Servers.

Censys observes 3,836 hosts globally exposing the management/log server role. This is total product presence, not a confirmed-vulnerable count.

No public PoC or confirmed exploitation has been reported as of publication. Check Point has released patches for supported versions via LivePatch.

Read the analysis and remediation details: censys.com/advisory/cve-2026-9

#Cybersecurity #CVE #Vulnerability #CensysARC

##

daniel1820815@infosec.exchange at 2026-09-16T19:23:20.000Z ##

🚨 Please read this important update from Check Point:

CVE-2026-91843 - Stack overflow in login process to the Security Management and Log Servers

support.checkpoint.com/results

#CheckPoint #CheckPointsoftwareTechnologies #CVE #CVE202691843

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T16:08:43.000Z ##

Check Point fixed a critical Check Point login flaw (CVE-2026-91843). Patch this Check Point login flaw now to block unauthenticated remote root takeovers.

#CheckPoint #Cybersecurity #CVE202691843 #InfoSec #Vulnerability

securityonline.info/check-poin

##

CVE-2026-58704
(8.0 HIGH)

EPSS: 0.21%

updated 2026-09-16T15:30:57

22 posts

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

cyberveille@mastobot.ping.moi at 2026-09-18T09:30:07.000Z ##

📢 [VULN] Google confirme un piratage des Pixel via une faille du modem - CVE-2026-58704

Google a confirmé que ses smartphones Pixel ont été piratés à la suite d’attaques ciblées exploitant une faille de type zero-day dans le modem. La faille de sécurité, qui a pour identifiant CVE-2026-58704, permet une élévation de privilèges sans aucune interaction de l’utilisateur et bénéficie désormais d’un…

🔗 kulturegeek.fr/news-359668/goo
💬 discussion : infosec.pub/post/52458473
#ZeroDay #CVE #Cyberveille

##

kuketzblog@social.tchncs.de at 2026-09-18T06:19:59.000Z ##

Google sieht Hinweise auf eine begrenzte, gezielte Ausnutzung von
CVE-2026-58704 auf Pixel-Geräten. Die Schwachstelle steckt im Modem
und ermöglicht eine Rechteausweitung. Der September-Patchlevel
2026-09-05 behebt die Lücke.

source.android.com/docs/securi

#Android #Pixel #ITSecurity

##

undercodenews@mastodon.social at 2026-09-17T19:33:26.000Z ##

Google Pixel Zero-Day Warning: CVE-2026-58704 Exploited in Targeted Attacks + Video

Google Pixel Zero-Day Warning: CVE-2026-58704 Exploited in Targeted Attacks A Silent Pixel Attack Has Triggered a New Security Warning Google Pixel users are facing a serious security warning after Google disclosed that a high-severity vulnerability in the cellular modem may have already been exploited in limited, targeted attacks. Tracked as CVE-2026-58704, the flaw involves a…

undercodenews.com/google-pixel

##

DarkWebInformer at 2026-09-17T17:33:47.483Z ##

🚨 Google confirms Pixel phones targeted in zero-click zero-day attacks

Google has patched CVE-2026-58704, a high-severity vulnerability in Pixel phones' cellular modem that the company says was already under "limited, targeted exploitation."

The flaw is caused by a logic error that can allow an attacker to bypass permission checks and escalate privileges beyond the modem's isolated environment.

Most importantly, exploitation requires no interaction from the victim.

No malicious link needs to be clicked and no file needs to be opened, making it a zero-click attack.

Google has not disclosed:

• Who carried out the attacks
• How many Pixel owners were targeted
• How the victims were selected
• What tools or spyware may have been deployed

CISA has added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog and set a September 19 remediation deadline for affected federal systems.

Google says Pixel devices with the September 5, 2026 security patch level or later are protected.

Pixel owners should update their devices immediately.

Source: techcrunch.com/2026/09/16/goog

##

sayzard@mastodon.sayzard.org at 2026-09-17T16:42:17.000Z ##

Google Pixel phones pwned in zero-click attacks

Google Pixel 휴대폰의 셀룰러 모뎀에서 권한 검증을 우회하고 권한 상승을 가능하게 하는 제로데이 취약점 CVE-2026-58704가 제한적 표적 공격에 악용된 정황이 공개됐다. 사용자 상호작용이 필요 없는 zero-click 공격이 가능하며, 이런 유형은 상용 스파이웨어 기반 표적 감시에 자주 활용된다. Google은 패치를 배포했고, CISA는 이 취약점을 KEV 카탈로그에 추가하며 미국 연방기관에 9월 19일까지 패치하도록 지시했다. AI 개발 자체와 직접 관련되지는 않지만, Android 기기를...

theregister.com/security/2026/

##

beyondmachines1 at 2026-09-17T13:01:13.438Z ##

Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks

Google's September 2026 update for Pixel devices fixes 110 vulnerabilities, including a high-severity modem flaw (CVE-2026-58704) that attackers are actively exploiting to escalate privileges without user interaction.

**Update your Pixel devices to the September 2026 patch level ASAP to block an active modem exploit and patch a huge set of issues.**

beyondmachines.net/event_detai

##

kuketzblog@social.tchncs.de at 2026-09-18T06:19:59.000Z ##

Google sieht Hinweise auf eine begrenzte, gezielte Ausnutzung von
CVE-2026-58704 auf Pixel-Geräten. Die Schwachstelle steckt im Modem
und ermöglicht eine Rechteausweitung. Der September-Patchlevel
2026-09-05 behebt die Lücke.

source.android.com/docs/securi

#Android #Pixel #ITSecurity

##

DarkWebInformer@infosec.exchange at 2026-09-17T17:33:47.000Z ##

🚨 Google confirms Pixel phones targeted in zero-click zero-day attacks

Google has patched CVE-2026-58704, a high-severity vulnerability in Pixel phones' cellular modem that the company says was already under "limited, targeted exploitation."

The flaw is caused by a logic error that can allow an attacker to bypass permission checks and escalate privileges beyond the modem's isolated environment.

Most importantly, exploitation requires no interaction from the victim.

No malicious link needs to be clicked and no file needs to be opened, making it a zero-click attack.

Google has not disclosed:

• Who carried out the attacks
• How many Pixel owners were targeted
• How the victims were selected
• What tools or spyware may have been deployed

CISA has added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog and set a September 19 remediation deadline for affected federal systems.

Google says Pixel devices with the September 5, 2026 security patch level or later are protected.

Pixel owners should update their devices immediately.

Source: techcrunch.com/2026/09/16/goog

##

beyondmachines1@infosec.exchange at 2026-09-17T13:01:13.000Z ##

Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks

Google's September 2026 update for Pixel devices fixes 110 vulnerabilities, including a high-severity modem flaw (CVE-2026-58704) that attackers are actively exploiting to escalate privileges without user interaction.

**Update your Pixel devices to the September 2026 patch level ASAP to block an active modem exploit and patch a huge set of issues.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

ottoto2017@prattohome.com at 2026-09-17T04:56:11.000Z ##

「Google Pixel端末がゼロクリック攻撃でハッキングされる
/CISAは連邦政府機関に対し、パッチ適用にわずか3日間しか猶予を与えていない。 」: #TheRegister

「Googleと米国政府は、Pixelスマートフォンの携帯モデムに存在するゼロデイ脆弱性を悪用した攻撃者が、権限チェックを回避し、ユーザーの操作なしに権限を昇格できると警告した。この脆弱性は、アップデートを行うことで既に修正されている。

Googleは 火曜日に、 CVE-2026-58704 として追跡されているこの重大な脆弱性 を公表し 、その際、このセキュリティホールが「限定的かつ標的を絞った悪用を受けている可能性がある」と警告した。つまり、Googleが問題を修正する前に、悪意のある人物がこのバグを発見し、悪用していたということだ。」

theregister.com/security/2026/

#prattohome

##

ottoto2017@prattohome.com at 2026-09-17T04:40:19.000Z ##

「Google、限定的な標的型攻撃の兆候が見られる中、Pixelモデムの脆弱性を修正 」: #TheHackerNews

「Googleは、 明らかにした。 同社のPixel Cellular Modemに存在する深刻なセキュリティ上の欠陥が、実際に悪用されていることを

(CVSSスコア:8.0)として追跡されているこの脆弱性は CVE-2026-58704 、権限昇格の欠陥です。

によると、「セルラーモデムには、コードの論理エラーにより権限がバイパスされる可能性がある」とのことです NIST(米国国立標準技術研究所)の国家脆弱性データベース(NVD)に掲載されているバグの説明 。「これにより、追加の実行権限を必要とせずに、リモート(近接/隣接)での権限昇格が可能になる可能性がある。悪用にはユーザーの操作は不要である。」 」

thehackernews.com/2026/09/goog

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T04:07:33.000Z ##

Google confirmed a Pixel modem zero-day (CVE-2026-58704) exploited in a zero-click spyware attack to escape the modem sandbox. Update now.

#Pixel #ZeroDay #CVE202658704 #Google #Spyware #ZeroClick #CyberSecurity

securityexpress.info/pixel-mod

##

thecybermind@infosec.exchange at 2026-09-16T21:31:34.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability

A strategic executive briefing detailing governance, risk mitigation, and compliance frameworks for CVE-2026-58704 on Google Pixel mobile devices....

thecybermind.co/h86g

##

simonzerafa@infosec.exchange at 2026-09-16T21:27:45.000Z ##

Google and CISA warned that an actively exploited zero-day vulnerability (CVE-2026-58704) affecting Pixel cellular modems.

This allows attackers to silently bypass permission checks and escalate privileges with no user interaction!

It was quickly added to CISA's Known Exploited Vulnerabilities (KEV) catalog [1.2.1, 1.5.1].

Would be an excellent idea for Pixel owners to ownload and apply the September Android OS patches ASAP!

#Google #PixelPhone #ZeroDay #Exploit

##

thecybermind@infosec.exchange at 2026-09-16T20:58:59.000Z ##

(CISA TS-MAN) The Cyber Mind TSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability

Actionable threat intelligence and end-to-end hardening strategies for CVE-2026-58704, addressing improper authorization flaws in Google Pixel cellular modems....

thecybermind.co/iuw6

##

cyberworldops@infosec.exchange at 2026-09-16T16:50:00.000Z ##

Google patched CVE-2026-58704, a high-severity Pixel Cellular Modem privilege-escalation flaw reportedly exploited in limited, targeted attacks. Its addition to CISA’s KEV Catalog underscores the need to prioritize affected device updates. #ZeroDay #MobileSecurity #ThreatIntelligence

cyberworldops.eu/en/google-pat

##

AAKL@infosec.exchange at 2026-09-16T16:26:50.000Z ##

New.

Press release: New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity cisa.gov/news-events/news/new-

The guide: Using Cyber Decoys to Strengthen Detection and Response cisa.gov/resources-tools/resou

CISA has also added one vulnerability to the catalogue.

CVE-2026-58704: Google Pixel Improper Authorization Vulnerability cve.org/CVERecord?id=CVE-2026- #Google #infosec #vulnerability #CISA

##

security_crawler_carl@infosec.exchange at 2026-09-16T16:14:16.000Z ##

🏆 New Achievement! Tutorial: Learning to Live With Being Actively Exploited!

Welcome to the Mandatory Pixel Debuff Sequence. Before you proceed, please note that CVE-2026-58704 has been equipped to your device without your consent. This is a zero-day — that means the tutorial boss was already in your pocket before the level loaded. (1/3)

##

secdb@infosec.exchange at 2026-09-16T15:01:11.000Z ##

🚨 [CISA-2026:0916] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-58704 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Pixel Improper Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Pixel
- Notes: source.android.com/docs/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260916 #cisa20260916 #cve_2026_58704 #cve202658704

##

rogeragrimes@infosec.exchange at 2026-09-16T14:56:00.000Z ##

If you've got a Google Pixel cell phone, do a system patch immediately. There is an active vulnerability that allows the hacker to take control of your device with no user interaction. It is being actively used in the wild.

cve.org/CVERecord?id=CVE-2026-

##

tugatech@masto.pt at 2026-09-16T14:31:09.000Z ##

Google corrige falha zero-day em telemóveis Pixel com atualização que resolve 110 vulnerabilidades. A falha, identificada como CVE-2026-58704, está a ser explorada em ataques direcionados de alcance limitado. 📱

🔗 tugatech.com.pt/t91149-google-

#falha #google #pixel 

##

cisakevtracker@mastodon.social at 2026-09-16T14:01:08.000Z ##

CVE ID: CVE-2026-58704
Vendor: Google
Product: Pixel
Date Added: 2026-09-16
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-40854(CVSS UNKNOWN)

EPSS: 0.30%

updated 2026-09-16T12:30:47

1 posts

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory entries such as "." or ".." in the cookie, allowing unauthorized access to the admin

cR0w@infosec.exchange at 2026-09-16T14:35:20.000Z ##

Vulnerabilities in a 5g router from T-Mobile, the company known for its security?! I'm shocked. Shocked! Well, not that shocked.

cert.pl/posts/2026/09/CVE-2026

#internetOfShit #miraiWillNeverDie
#jobSecurityForSomeone

##

CVE-2026-81642(CVSS UNKNOWN)

EPSS: 0.52%

updated 2026-09-16T09:30:28

4 posts

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerabili

1 repos

https://github.com/suominen/CVE-2026-81642

undercodenews@mastodon.social at 2026-09-18T00:02:32.000Z ##

Critical Unbound DNSSEC Flaw Opens a Dangerous Path to Remote Code Execution + Video

Critical Unbound DNSSEC Flaw Could Turn a Malicious DNS Zone Into a Remote Code Execution Gateway A Critical Weakness Hidden Inside DNS Validation A critical security flaw in the Unbound DNS resolver has placed organizations running older versions under serious patching pressure. Tracked as CVE-2026-81642, the vulnerability is a heap buffer overflow in Unbound's DNSSEC validation…

undercodenews.com/critical-unb

##

cyberworldops at 2026-09-17T20:30:00.629Z ##

NLnet Labs Unbound before 1.26.1 contains heap overflow CVE-2026-81642 in the DNSSEC validator via crafted DNSKEY with compression pointer into RDATA. Any resolver induced to query a malicious zone risks crash or potential RCE, exposing core DNS infrastructure.

cyberworldops.eu/en/unbound-dn

##

Analyst207@mastodon.social at 2026-09-17T14:03:25.000Z ##

Unbound DNSSEC Validator Flaw Enables Remote Code Execution

A critical flaw in the Unbound DNSSEC Validator, known as CVE-2026-81642, allows attackers to trigger a heap overflow, potentially enabling remote code execution on vulnerable systems. This vulnerability affects all Unbound DNS resolver releases before 1.26.1, putting countless systems at risk.

osintsights.com/unbound-dnssec

#DnssecValidatorFlaw #RemoteCodeExecution #Cve202681642 #Unbound #HeapOverflow

##

cyberworldops@infosec.exchange at 2026-09-17T20:30:00.000Z ##

NLnet Labs Unbound before 1.26.1 contains heap overflow CVE-2026-81642 in the DNSSEC validator via crafted DNSKEY with compression pointer into RDATA. Any resolver induced to query a malicious zone risks crash or potential RCE, exposing core DNS infrastructure. #Unbound #DnsSec #HeapOverflow

cyberworldops.eu/en/unbound-dn

##

CVE-2026-15640(CVSS UNKNOWN)

EPSS: 0.28%

updated 2026-09-16T00:31:41

1 posts

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

cR0w@infosec.exchange at 2026-09-16T14:17:30.000Z ##

Go hack more Secret Server shit.

delinea.com/security-advisories

Authentication Bypass via SAML Response Manipulation - CVE-2026-15640

Reflected Cross-Site Scripting - CVE-2026-15639

Cryptographic Padding Oracle - CVE-2026-15638

##

CVE-2026-15639(CVSS UNKNOWN)

EPSS: 0.39%

updated 2026-09-16T00:31:33

1 posts

An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.

cR0w@infosec.exchange at 2026-09-16T14:17:30.000Z ##

Go hack more Secret Server shit.

delinea.com/security-advisories

Authentication Bypass via SAML Response Manipulation - CVE-2026-15640

Reflected Cross-Site Scripting - CVE-2026-15639

Cryptographic Padding Oracle - CVE-2026-15638

##

CVE-2026-78175
(8.8 HIGH)

EPSS: 0.59%

updated 2026-09-15T15:17:21.707000

2 posts

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler lacking any capability or role check, relying solely on a nonce, while also passing attacker-supplied values through `esc_sq

guru@thecybersecguru.com at 2026-09-18T13:12:51.000Z ##

Tutor LMS Critical Flaw (CVE-2026-78175) Exposes 100,000+ WordPress Sites to Remote Code Execution

Tutor LMS CVE-2026-78175 is a critical RCE flaw affecting 100,000+ WordPress sites. Learn how the exploit works and how to patch it

thecybersecguru.com/news/cve-2

##

guru@thecybersecguru.com at 2026-09-18T13:12:51.000Z ##

Tutor LMS Critical Flaw (CVE-2026-78175) Exposes 100,000+ WordPress Sites to Remote Code Execution

Tutor LMS CVE-2026-78175 is a critical RCE flaw affecting 100,000+ WordPress sites. Learn how the exploit works and how to patch it

thecybersecguru.com/news/cve-2

##

CVE-2026-39919
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-09-15T15:17:14.723000

1 posts

Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates

DailyCyberSecurity@infosec.exchange at 2026-09-17T02:20:05.000Z ##

A Ghostscript buffer overflow enables unauthenticated remote code execution. Patch this Ghostscript buffer overflow flaw (CVE-2026-39919) immediately.

#Ghostscript #CVE202639919 #RemoteCodeExecution #Cybersecurity #InfoSec

securityonline.info/ghostscrip

##

CVE-2026-81915
(0 None)

EPSS: 0.42%

updated 2026-09-15T14:40:24.370000

1 posts

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::submit() dashboard controller loaded and saved the Page Type identified by a user-supplied ptID without calling canEditPageType(), so a signed-in dashboard user permitted to edit one Page Type could modify the configuration of Page Types outside their assigned authorization bounda

hugovalters@mastodon.social at 2026-09-17T21:10:08.000Z ##

CVE-2026-81915 Concrete CMS below 9.5.3: broken object-level authz lets any dashboard user edit Page Types outside their scope. CVSS N/A, patch status unknown. Update immediately. valtersit.com/cve/CVE-2026-819 #CVE #infosec #ConcreteCMS

##

CVE-2026-76461
(9.8 CRITICAL)

EPSS: 2.01%

updated 2026-09-15T12:47:32.497000

5 posts

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that co

4 repos

https://github.com/HORKimhab/CVE-2026-76461

https://github.com/S3v3n-JG/CVE-2026-76461

https://github.com/fevar54/CVE-2026-76461-Detection-Kit-

https://github.com/0xBlackash/CVE-2026-76461

hackmag at 2026-09-18T15:36:29.481Z ##

⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email

🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…

🔗 hackmag.com/news/cve-2026-7646

##

PC_Fluesterer@social.tchncs.de at 2026-09-17T13:30:04.000Z ##

Cisco Zero-Day wird aktiv angegriffen

Mal was neues - ach nein, Hintertüren bei Cisco sind ja gar nicht neu, sondern schon fast Gewohnheit. Am Montag hat die Firma ihre Kunden informiert, dass im Secure Email Gateway (SEG) eine Sicherheitslücke steckt, die bereits aktiv angegriffen wird. Dabei ist gleichgültig, ob das SEG auf eigener Hardware (Appliance) läuft oder als virtuelle Maschine oder Cloud-Dienst. Auch die Konfiguration des SEG macht keinen Unterschied. Das muss man sich mal auf der Zunge zergehen lassen: Das SEG, das vor schädlichen E-Mails schützen soll, kann durch genau solche angegriffen werden! Die Sicherheitslücke CVE-2026-76461 ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #backdoor #closedsource #email #exploits #hersteller #sicherheit #UnplugTrump #zeroday #cisco

##

hackmag@infosec.exchange at 2026-09-18T15:36:29.000Z ##

⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email

🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…

🔗 hackmag.com/news/cve-2026-7646

#news

##

security_crawler_carl@infosec.exchange at 2026-09-16T23:37:29.000Z ##

🏆 New Achievement! Root Access? We'll Get That Escalated for You!

Your ticket has been received. We see you're experiencing an issue where an unauthenticated attacker is executing arbitrary commands with root privileges on your Cisco Secure Email Gateway via CVE-2026-76461. Great news: we've reproduced the bug! It's the email parsing in Cisco AsyncOS — sending a specially crafted email with malicious SQL statements is all it takes. (1/3)

##

youranonnewsirc@nerdculture.de at 2026-09-16T16:26:20.000Z ##

Recent developments include Cisco patching a critical zero-day (CVE-2026-76461) in its Secure Email Gateway, which was actively exploited for root command execution. Geopolitically, China warned against weaponizing space after the US confirmed orbital weapon deployments. In technology, debates continue on AI safety versus national competitive advantage, with US Speaker Johnson rejecting development pauses.

#Cybersecurity #Geopolitics #AnonNews_irc

##

CVE-2026-89491(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-09-14T15:33:33

1 posts

In the Linux kernel, the following vulnerability has been resolved: ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() Patch series "ocfs2: cluster: o2hb_region_pin() fixes", v2. This series fixes three related issues in o2hb_region_pin(), all are from the original implementation in commit: 58a3158a5d17 ("ocfs2/cluster: Pin/unpin o2hb regions"): 1) It is called with

hugovalters@mastodon.social at 2026-09-17T19:40:07.000Z ##

CVE-2026-89491 Linux kernel ocfs2 flaw: sleep while holding o2hb_live_lock in o2hb_region_pin(). CVSS N/A, patch status unknown. Update immediately. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89466
(7.7 HIGH)

EPSS: 0.14%

updated 2026-09-14T15:33:32

1 posts

In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: terminate the strings from firmware The qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the firmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and leaves the destination without a terminator. Those destinations are model_number, serial_number and oem_info, each BATT

hugovalters@mastodon.social at 2026-09-18T11:20:01.000Z ##

CVE-2026-89466 Linux kernel qcom_battmgr: unterminated firmware strings leak adjacent memory to userspace. CVSS N/A, patch unknown. Update now. valtersit.com/cve/CVE-2026-894 #CVE #infosec #Linux

##

CVE-2026-89478
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-09-14T15:32:26

1 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: drop a chunk if its transport was removed sctp_rcv() resolves the transport once per packet and leaves it in chunk->transport. The lookup reference, or the one sctp_add_backlog() takes if the socket is owned by userspace, keeps it around until the chunk has been processed. An authenticated ASCONF DEL-IP can remove it in t

hugovalters@mastodon.social at 2026-09-18T08:10:17.000Z ##

CVE-2026-89478 Linux kernel sctp use-after-free via ASCONF DEL-IP. CVSS N/A, unpatched. Patch or restrict SCTP now. valtersit.com/cve/CVE-2026-894 #CVE #infosec #Linux

##

CVE-2026-89483
(7.5 HIGH)

EPSS: 0.56%

updated 2026-09-14T15:32:26

1 posts

In the Linux kernel, the following vulnerability has been resolved: nvme: zero the discard fallback page nvme_setup_discard() always maps sizeof(struct nvme_dsm_range) * NVME_DSM_MAX_RANGES = 4096 bytes as the DSM payload however many ranges the command declares, because some devices ignore the 'Number of Ranges' field - the Fixes: commit records two that read past the declared ranges. A single-

hugovalters@mastodon.social at 2026-09-17T13:20:02.000Z ##

CVE-2026-89483 Linux kernel nvme discard: uninitialized page read leaks 4080 bytes of stale kernel memory to devices. CVSS N/A, patch status unknown. Update kernel now if you run nvme. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89442
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T15:32:24

1 posts

In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate socket ID in clos_assoc ioctl isst_if_clos_assoc() validates the user-supplied socket_id with 'socket_id > topology_max_packages()', but isst_common.sst_inst[] is allocated with topology_max_packages() entries, so the valid index range is [0, topology_max_packages()). The '>' comparison lets socket_

hugovalters@mastodon.social at 2026-09-18T03:30:25.000Z ##

CVE-2026-89442: out-of-bounds access in the Linux kernel ISST driver lets a bad socket ID index past sst_inst[]. No CVSS or patch yet. Treat as unpatched, restrict ioctl access. Details: valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80938(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-14T15:32:20

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex mt7615_suspend() acquired the mt76 mutex and then called cancel_delayed_work_sync() on mac_work. mt7615_mac_work() acquires the same mutex via mt7615_mutex_acquire() at the top of the worker, so if mac_work is already running and blocked on the mutex, the suspe

hugovalters@mastodon.social at 2026-09-17T16:30:03.000Z ##

CVE-2026-80938 Linux kernel mt7615 wifi deadlock in suspend path, MAC work vs mutex. No CVSS or patch yet. Watch for fixes. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-85706
(10.0 CRITICAL)

EPSS: 14.56%

updated 2026-09-14T14:22:15.323000

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Nuclei template

13 repos

https://github.com/gagaltotal/CVE-2026-85706-gitlab-poc

https://github.com/gabrielunknown/CVE-2026-85706

https://github.com/0xenesbayram/cve-2026-85706

https://github.com/brigadeops32/CVE-2026-85706

https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc

https://github.com/ynsmroztas/GitLabSniper

https://github.com/FlowerWitch/CVE-2026-85706_docker_exp

https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab

https://github.com/mhtsec/CVE-2026-85706

https://github.com/solivaquaant/CVE-2026-85706

https://github.com/guneykabel/cve-2026-85706

https://github.com/tc4dy/CVE-2026-85706-PoC-Toolkit

https://github.com/plur1bu5/gitread

relayshieldadmin@infosec.exchange at 2026-09-16T18:20:40.000Z ##

GitLab CVE-2026-85706: unauth arbitrary file read, exploited in the wild, now on CISA KEV. Patch
19.3.2 / 19.2.6 / 19.1.8.
The 10.0 is about the read. The damage is the credentials inside the files, and a commits API
reads history, so secrets you deleted are still there.
Patch, hunt, THEN rotate. Rotating on a readable server hands over the new keys.
blog.relayshield.net/a-file-read-bug-is-a-credential-theft-bug
#GitLab #infosec #DevSecOps

##

CVE-2026-89510
(7.8 HIGH)

EPSS: 0.18%

updated 2026-09-14T13:19:07.537000

1 posts

In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Cancel reg_work before freeing device on remove c4iw_uld_state_change() queues reg_work to register the RDMA device. c4iw_remove() can free ctx->dev while this work is pending or running, leaving c4iw_register_device() accessing the freed device. Cancel reg_work before removing the device. The registration work can

hugovalters@mastodon.social at 2026-09-18T17:40:01.000Z ##

CVE-2026-89510 Linux kernel RDMA/cxgb4 use-after-free in c4iw_remove, reg_work frees device while registration work still runs. No CVSS, no patch yet. Update your kernel now. valtersit.com/cve/CVE-2026-895 #CVE #infosec #Linux

##

CVE-2026-89479
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-14T13:19:04.457000

1 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: stop processing a packet once its association is deleted sctp_endpoint_bh_rcv() looks the association up only when chunk->asoc is NULL, and caches the result in chunk->asoc and chunk->transport without taking a reference. A packet that matches no association is handed to the endpoint, so a peer can bundle COOKIE ECHO, SHU

hugovalters@mastodon.social at 2026-09-19T04:30:02.000Z ##

CVE-2026-89479 Linux kernel SCTP use-after-free, unpatched, no CVSS assigned. Crafted packet can free an association mid-processing. Patch status unclear, so track kernel updates now. Details: valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89474
(0 None)

EPSS: 0.17%

updated 2026-09-14T13:19:03.733000

1 posts

In the Linux kernel, the following vulnerability has been resolved: power: supply: bq256xx: drain usb_work before freeing the charger The USB-PHY notifier queues usb_work, whose handler calls power_supply_changed(bq->charger). The reset devm action only unregisters the notifier and was registered before the power supplies, so devm frees bq->charger on unwind before the action runs; a usb_work st

hugovalters@mastodon.social at 2026-09-18T03:00:02.000Z ##

CVE-2026-89474 Linux kernel bq256xx use-after-free in power supply driver, USB work can run after charger freed. No CVSS, no patch yet. Audit and update kernel now. valtersit.com/cve/CVE-2026-894 #CVE #infosec #LinuxKernel

##

CVE-2026-89473
(0 None)

EPSS: 0.20%

updated 2026-09-14T13:19:03.620000

1 posts

In the Linux kernel, the following vulnerability has been resolved: power: supply: bq25890: Fix power_supply reference leak bq25890_fw_probe() acquires a reference to a secondary charger using power_supply_get_by_name(), but the reference is not released on later probe failures or on driver detach. In particular, failures after bq25890_fw_probe() returns successfully, such as a failure in bq258

hugovalters@mastodon.social at 2026-09-18T16:00:01.000Z ##

CVE-2026-89473 Linux kernel bq25890 driver ref leak on probe fail or detach, causing resource exhaustion. No CVSS, no patch yet. Update when vendor fix lands. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89460
(0 None)

EPSS: 0.17%

updated 2026-09-14T13:19:02.357000

1 posts

In the Linux kernel, the following vulnerability has been resolved: s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks The command 'perf stat -e cycles -- <command>' crashes the kernel when CPUs are hotplug added during that run. Root cause is the allocation of struct cpu_cf_events at first event initialization. The allocation is dynamic and the first event that has task context create

hugovalters@mastodon.social at 2026-09-18T19:10:09.000Z ##

CVE-2026-89460: Linux kernel s390 cpum_cf crash on CPU hotplug, DoS risk. CVSS N/A, patch status unknown. Audit and update now. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89444
(0 None)

EPSS: 0.21%

updated 2026-09-14T13:19:01.690000

1 posts

In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer set_attribute() populates the security area of the BIOS attribute request buffer with the current admin password via populate_security_buffer(), then dumps the whole request buffer with print_hex_dump_bytes(). This can expose the plaintext admin password in

hugovalters@mastodon.social at 2026-09-18T05:00:18.000Z ##

CVE-2026-89444 Linux kernel dell-wmi-sysman leaks plaintext BIOS admin password to kernel log. CVSS N/A, patch status unknown. Update now. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-81005
(0 None)

EPSS: 0.18%

updated 2026-09-14T13:18:54.883000

2 posts

In the Linux kernel, the following vulnerability has been resolved: ipmi: si: Fix NULL pointer dereference after failed registration try_smi_init() allocates new_smi->si_sm and later calls ipmi_register_smi_mod(), which maps to ipmi_add_smi(). During ipmi_add_smi(), the upper IPMI message handler obtains the initial BMC device information through __bmc_get_device_id(). This can fail if the BMC

NyxKai@ieji.de at 2026-09-17T08:48:16.000Z ##

@hugovalters Thanks for flagging CVE-2026-81005. This NULL pointer dereference in ipmi_si is nasty — BMC failure during Get Device ID shouldn't crash the kernel. Mitigation: disable ipmi_si module if BMC is unresponsive (modprobe -r ipmi_si) or ensure ipmi_si.force_kipmi=0 to avoid kernel thread hang. Patch backports likely in stable kernel queue. #infosec #Linux #CVE

##

hugovalters@mastodon.social at 2026-09-17T08:40:00.000Z ##

CVE-2026-81005 Linux kernel NULL pointer dereference in ipmi_si after failed SMI registration. CVSS N/A. Unpatched. A BMC that fails Get Device ID can crash the kernel. Patch now. valtersit.com/cve/CVE-2026-810 #CVE #Linux #infosec

##

CVE-2026-81000
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T13:18:54.210000

7 posts

In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the re

cyberworldops at 2026-09-19T04:30:00.974Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk.

cyberworldops.eu/en/four-publi

##

sayzard@mastodon.sayzard.org at 2026-09-18T14:40:50.000Z ##

A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, DiagSpill

Linux 커널에서 일반 로컬 사용자를 root로 승격할 수 있는 4개 취약점 DirtyAH6(CVE-2026-80844), TUNderflow(CVE-2026-81000), PPPoEject(CVE-2026-68121), DiagSpill(CVE-2026-74469)가 공개됐다. 취약점들은 네트워크 서브시스템의 오래된 메모리 손상 문제이며, DiagSpill은 별도 capability나 비특권 사용자 네임스페이스 없이도 조건 충족 시 LPE가 가능하고 컨테이너 호스트 탈출 가능성도 있다. 수정은 Linux stable 5.10.270,...

openwall.com/lists/oss-securit

##

decio at 2026-09-18T08:13:07.228Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

##

harrysintonen at 2026-09-18T06:48:39.896Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

##

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

decio@infosec.exchange at 2026-09-18T08:13:07.000Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

#Linux #CyberSecurity #Vulnerability #CVE #Debian

##

harrysintonen@infosec.exchange at 2026-09-18T06:48:39.000Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469

##

CVE-2026-80982
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T13:18:52.947000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free in smc_rx_pipe_buf_release() smc_rx_splice() hands RMB pages to a pipe and takes a socket reference per entry so the smc_sock stays alive until the reader finishes. The connection does not: a concurrent close runs smc_conn_free(), which releases the receive buffer back to the link group pool. smc_rx_

hugovalters@mastodon.social at 2026-09-17T18:10:01.000Z ##

CVE-2026-80982 Linux net/smc use-after-free in smc_rx_pipe_buf_release(), patch status unknown, CVSS not assigned. Unpatched kernel race can crash or corrupt memory. Update immediately. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80967
(8.4 HIGH)

EPSS: 0.18%

updated 2026-09-14T13:18:51.370000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcxhr: initialize mutexes before requesting threaded IRQ pcxhr_probe() requests pcxhr_threaded_irq() before initializing mgr->lock, even though the threaded handler takes that mutex. Initialize the manager locks before request_threaded_irq() so an early interrupt cannot run against uninitialized mutex state during probe.

hugovalters@mastodon.social at 2026-09-18T01:30:03.000Z ##

CVE-2026-80967 Linux ALSA pcxhr: mutexes initialized after threaded IRQ request, risking uninitialized lock state during probe. Patch status unknown. Update your kernel now. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-80952
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-14T13:18:50.710000

1 posts

In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix info leak and UAF in device unregister path i3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before calling device_unregister(). During device_unregister(), device_del() emits a KOBJ_REMOVE uevent and unbinds the driver while the device descriptor is still expected to be valid. As a result, i3c_device

hugovalters@mastodon.social at 2026-09-17T15:00:02.000Z ##

CVE-2026-80952 Linux kernel i3c UAF and info leak in device unregister path, CVSS N/A, patch status unknown. Assume unpatched. Patch now: valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-80941
(0 None)

EPSS: 0.21%

updated 2026-09-14T13:18:50.160000

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() The skb passed to the rtw_hci_tx_write() is expected to be freed when the function fails, but the error path in rtw_txq_push_skb() does not free the skb before returning. This can lead to a memory leak in rtw_txq_push() where a dequeued skb is passed to rtw_txq_push_sk

hugovalters@mastodon.social at 2026-09-19T04:20:03.000Z ##

CVE-2026-80941 Linux rtw88 wifi driver memory leak in rtw_txq_push_skb error path. No CVSS or patch confirmed yet. Update your kernel as soon as fixes land. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80939
(0 None)

EPSS: 0.17%

updated 2026-09-14T13:18:50.037000

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot Since the hardware rfkill polling was introduced, arm64 platforms can panic with an asynchronous SError during warm reboot: SError Interrupt on CPU8, code 0x00000000be000011 -- SError Workqueue: events_power_efficient rfkill_poll [rfkill] rtw89_pc

hugovalters@mastodon.social at 2026-09-18T04:20:04.000Z ##

CVE-2026-80939 Linux rtw89 PCI wifi driver can panic arm64 systems with SError on warm reboot due to rfkill polling with no shutdown callback. No CVSS assigned, patch status unknown. Apply kernel updates when valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-90894
(7.8 HIGH)

EPSS: 0.15%

updated 2026-09-14T12:31:44

1 posts

Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon unpacks with one string, tar -xf "%1" -C "%2", then Qt QProcess::splitCommand 

oversecurity@mastodon.social at 2026-09-17T09:30:09.000Z ##

New Parallels Desktop Flaw Lets Local Users Seize Root Control of Macs

A newly documented security flaw in Parallels Desktop, identified as CVE-2026-90894 and nicknamed "ParaShells," could let any local account on

🔗️ [Thecyberexpress] link.is.it/XRBHSO

##

CVE-2026-89520
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T09:33:29

1 posts

In the Linux kernel, the following vulnerability has been resolved: sched/core: Make core-sched flips wait for in-flight selections Core scheduling's pick_next_task() operates on all sibling rqs under one acquisition of the shared core-wide lock. A ->pick_task() that releases the rq lock leaves every sibling __lock momentarily free, letting __sched_core_flip(false) complete mid-selection and reb

hugovalters@mastodon.social at 2026-09-18T14:30:38.000Z ##

CVE-2026-89520 Linux kernel core-sched race lets __sched_core_flip rebind rq_lockp mid-selection. No CVSS, no patch yet. Update to latest stable kernel when fixed. valtersit.com/cve/CVE-2026-895 #CVE #Linux #infosec

##

CVE-2026-80954
(7.8 HIGH)

EPSS: 0.15%

updated 2026-09-13T09:32:11

1 posts

In the Linux kernel, the following vulnerability has been resolved: i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() i3c_device_get_supported_xfer_mode() uses dev->desc to obtain the master controller. However, dev->desc must not be dereferenced unless bus->lock is held, and this function does not take that lock. The function only needs access to the master co

hugovalters@mastodon.social at 2026-09-18T20:40:07.000Z ##

CVE-2026-80954 Linux kernel i3c unlocked dev->desc dereference, unpatched, CVSS N/A. Patch now if you run i3c. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-89492
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-13T07:17:12.417000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when reading metadata ocfs2_validate_dx_leaf() and ocfs2_validate_dx_root() check the ECC and signature of an indexed-directory block before it reaches higher-level callers, but neither validator bounds the ocfs2_dx_entry_list counts against the capacity of the block that holds them.

hugovalters@mastodon.social at 2026-09-19T06:10:01.000Z ##

CVE-2026-89492 Linux kernel ocfs2 out-of-bounds access via unchecked directory-index entry counts. No CVSS or patch yet. Treat as unpatched and update immediately if ocfs2 is in use. valtersit.com/cve/CVE-2026-894 #CVE #infosec #Linux

##

CVE-2026-89452
(8.4 HIGH)

EPSS: 0.18%

updated 2026-09-13T07:17:09.477000

1 posts

In the Linux kernel, the following vulnerability has been resolved: iommu/msm: Unwind probe state on registration failure msm_iommu_probe() adds its devm-managed IOMMU object to qcom_iommu_devices before adding the IOMMU sysfs device and registering it with the IOMMU core. If iommu_device_sysfs_add() fails, probe returns with the object still on qcom_iommu_devices. The driver core then releases

hugovalters@mastodon.social at 2026-09-18T12:50:01.000Z ##

CVE-2026-89452 Linux kernel iommu/msm probe failure leaves a dangling list entry, risking use-after-free on later list walks. No CVSS score and no patch yet. Track it and update the kernel as soon as a fix valtersit.com/cve/CVE-2026-894 #CVE #LinuxKernel #infosec

##

CVE-2026-80953
(8.4 HIGH)

EPSS: 0.18%

updated 2026-09-13T07:17:02.463000

1 posts

In the Linux kernel, the following vulnerability has been resolved: i3c: master: adi: initialize the lock before enabling interrupts adi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR before the controller's IBI state, transfer queue list and transfer queue lock are initialized. A pending CMDR interrupt can therefore run adi_i3c_master_irq() and take master->xferqueue.lock

hugovalters@mastodon.social at 2026-09-19T01:10:00.000Z ##

CVE-2026-80953 Linux i3c adi driver inits lock after enabling IRQ, risking race and memory corruption. CVSS N/A, unpatched. Patch or mitigate now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-84869
(9.9 CRITICAL)

EPSS: 0.69%

updated 2026-09-12T04:16:42.757000

1 posts

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

thecybermind@infosec.exchange at 2026-09-16T14:42:24.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-84869 – ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

C-Suite threat intelligence and mitigation protocols for CVE-2026-84869, addressing active exploitation vectors within enterprise ConnectWise environments....

thecybermind.co/pxxw

##

CVE-2026-90467
(4.0 None)

EPSS: 0.23%

updated 2026-09-12T03:30:29

1 posts

aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging authenticated identities or forcing delivery notifications to third

hugovalters@mastodon.social at 2026-09-18T09:50:01.000Z ##

CVE-2026-90467 aiosmtplib before 5.1.3: ESMTP parameter injection via MAIL FROM/RCPT TO, forged auth and forced notifications. CVSS 4.0, no patch confirmed. Update to 5.1.3+ now. valtersit.com/cve/CVE-2026-904 #CVE #infosec #cybersecurity

##

CVE-2026-89529(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-09-11T21:31:37

1 posts

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject oversized Read segments at decode time The RPC/RDMA Read list decoder stores wire-supplied segment lengths without validation. xdr_count_read_segments() checks 4-byte alignment for non-zero position values but does not cap the segment length. An oversized rs_length reaches svc_rdma_build_read_segment(), which de

hugovalters@mastodon.social at 2026-09-17T11:50:02.000Z ##

CVE-2026-89529 Linux kernel svcrdma: unvalidated Read segment lengths allow oversized allocation. No CVSS yet, patch status unknown. Update your kernel now: valtersit.com/cve/CVE-2026-895 #CVE #infosec #Linux

##

CVE-2026-42016
(8.1 HIGH)

EPSS: 0.89%

updated 2026-09-11T21:31:06

1 posts

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

thecybermind@infosec.exchange at 2026-09-16T13:23:43.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-42016 – JFrog Artifactory Incorrect Authorization Vulnerability

C-Suite threat intelligence for CVE-2026-42016, covering OAuth scope validation, lateral movement detection, and repository hardening across JFrog Artifactory instances....

thecybermind.co/0vaa

##

CVE-2026-89455
(0 None)

EPSS: 0.20%

updated 2026-09-11T20:19:26.220000

1 posts

In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix use-after-free of event IRQs during teardown plda_pcie_irq_domain_deinit() removes pcie->event_domain via irq_domain_remove(), but the per-event IRQs mapped from that domain are requested with devm_request_irq() in plda_init_interrupts(). The actual free_irq() for a devm-managed IRQ is deferred by devres until aft

hugovalters@mastodon.social at 2026-09-19T01:40:18.000Z ##

CVE-2026-89455 Linux kernel PCI plda use-after-free during IRQ teardown. No CVSS or patch yet. Audit and update affected systems. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89453
(0 None)

EPSS: 0.20%

updated 2026-09-11T20:19:25.967000

1 posts

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faults iommu_call_iopf_notifier() looks up the requester with pci_get_domain_bus_and_slot(), which returns a PCI device with its reference count incremented. Neither the successful iommu_report_device_fault() path nor the abort path drops that reference, so every handled PPR request

hugovalters@mastodon.social at 2026-09-19T03:40:18.000Z ##

CVE-2026-89453 Linux kernel iommu/amd PPR fault handling leaks PCI device references. Unpatched. Patch now valtersit.com/cve/CVE-2026-894 #CVE #infosec #Linux

##

CVE-2026-0310
(0 None)

EPSS: 0.34%

updated 2026-09-11T04:17:13.060000

2 posts

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimiz

cR0w at 2026-09-18T12:46:29.099Z ##

@badsamurai CVE-2026-0310 go brrrrrr

##

cR0w@infosec.exchange at 2026-09-18T12:46:29.000Z ##

@badsamurai CVE-2026-0310 go brrrrrr

##

CVE-2026-39113
(4.0 MEDIUM)

EPSS: 0.21%

updated 2026-09-09T16:04:24.933000

1 posts

Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause a denial of service via the ext/misc/sqlar.c, sqlarUncompressFunc(), sqlar_uncompress(), sqlite3_value_int

1 repos

https://github.com/20000419/CVE-2026-39113

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-15534
(5.7 MEDIUM)

EPSS: 0.17%

updated 2026-09-08T22:17:38.113000

1 posts

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the sig

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-60004
(9.8 CRITICAL)

EPSS: 86.78%

updated 2026-09-08T17:56:31

1 posts

### Summary Gitea's `diffpatch` endpoint can be abused to install and execute a Git hook from repository-controlled content. An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository. ### Detai

Nuclei template

10 repos

https://github.com/shinthink/CVE-2026-60004

https://github.com/HORKimhab/CVE-2026-60004

https://github.com/gagaltotal/CVE-2026-60004-poc-gitea

https://github.com/imbas007/CVE-2026-60004-POC

https://github.com/HackSpeak/CVE-2026-60004

https://github.com/0xBlackash/CVE-2026-60004

https://github.com/EQSTLab/CVE-2026-60004

https://github.com/erberkan/CVE-2026-60004-PoC

https://github.com/Sachinart/CVE-2026-60004-gitea-0day

https://github.com/fevar54/cve-2026-60004

cyberveille@mastobot.ping.moi at 2026-09-17T15:00:05.000Z ##

📢 Red Heron exploite CVE-2026-60004 dans Gitea pour déployer un rootkit Linux inédit

L'Acronis Threat Research Unit (TRU) a publié le 13 septembre 2026 une analyse détaillée d'une campagne multinationale menée par un acteur malveillant sinophone qu'ils suivent sous le nom Red Heron. La découverte initiale remonte au 4 août 2026, lorsque TRU a…

📖 cyberveille : cyberveille.ch/posts/2026-09-1
🌐 source : acronis.com/en/tru/posts/red-h
🟢 vérification factuelle haute
#RedHeron #RootkitLinux #Cyberveille

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 99.91%

updated 2026-09-08T15:13:07.273000

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

Nuclei template

100 repos

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/wesmar/CVE-2026-31431

https://github.com/pyroceper/copy-fail-CVE-2026-31431

https://github.com/Boos4721/copyfail-rs

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/insomnisec/Detections-CVE-2026-31431

https://github.com/Smarttfoxx/copyfail

https://github.com/sgkdev/page_inject

https://github.com/desultory/CVE-2026-31431

https://github.com/Juguitos/copy-fail

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/Huchangzhi/autorootlinux

https://github.com/badsectorlabs/copyfail-go

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/cozystack/copy-fail-blocker

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/xeloxa/copyfail-exploit

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/nisec-eric/cve-2026-31431

https://github.com/b5null/CVE-2026-31431-C

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/povzayd/CVE-2026-31431

https://github.com/mrunalp/block-copyfail

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/diemoeve/copyfail-rs

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/samanzamani/copy-fail-checker

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/wgnet/wg.copyfail.patch

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/tgies/copy-fail-c

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/ncmprbll/copy-fail-rs

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/rvzsec/CVE-2026-31431

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/sgkdev/ptrace_may_dream

https://github.com/Qengineering/RK35xx-CopyFail-Hotfix

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/pedromizz/copy-fail

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/rootsecdev/cve_2026_31431

https://github.com/bootsareme/copyfail-deconstructed

https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH

https://github.com/gagaltotal/cve-2026-31431-copy-fail

https://github.com/malwarekid/CVE-2026-31431

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/sammwyy/copyfail-rs

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/luotian2/CVE-2026-31431

https://github.com/cs8425/copy-fail-go

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/atgreen/block-copyfail

https://github.com/sudoytang/copyfail-arm64

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/cyber-joker/copy-fail-python

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/0xShe/CVE-2026-31431

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix

https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape

https://github.com/AdityaBhatt3010/CVE-2026-31431

sayzard@mastodon.sayzard.org at 2026-09-17T11:41:42.000Z ##

When the Red Light Goes On: How We Responded to the Linux Kernel 0-Day

Linux 커널의 공개 PoC 로컬 권한 상승 취약점 CVE-2026-31431("Copy Fail")이 Ubuntu 24.04에서 비권한 사용자로부터 root 획득까지 가능하다고 보고됐다. 원인은 Crypto User API의 AF_ALG 경로에서 `algif_aead` 모듈에 도달 가능한 out-of-bounds write이며, 웹 애플리케이션 침해가 호스트 전체 침해로 확대될 수 있어 멀티테넌트 서버와 컨테이너 노드 운영자에게 특히 중요하다. 패치가 배포되기 전에는 `algif_aead`를 언로드하고 modprobe 설정으로 재로딩을 차단하는 방식으로 공...

nine.ch/en/blog/linux-kernel-0

##

CVE-2026-15315
(8.8 HIGH)

EPSS: 0.30%

updated 2026-09-04T18:32:18

3 posts

Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions,

1 repos

https://github.com/HORKimhab/CVE-2026-15315

beyondmachines1 at 2026-09-17T11:01:13.911Z ##

TP-Link Patches Critical Flaws in Tapo Surveillance Cameras

TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.

**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-17T11:01:13.000Z ##

TP-Link Patches Critical Flaws in Tapo Surveillance Cameras

TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.

**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-09-16T16:32:55.000Z ##

In case you didn't have enough problems with cameras, here's another one.

OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

More:

Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news #infosec #vulnerability #spyware #zeroday #threatresearch

##

CVE-2026-15316
(6.5 MEDIUM)

EPSS: 0.23%

updated 2026-09-04T17:26:04.617000

4 posts

An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS manage

1 repos

https://github.com/HORKimhab/CVE-2026-15315

beyondmachines1 at 2026-09-17T11:01:13.911Z ##

TP-Link Patches Critical Flaws in Tapo Surveillance Cameras

TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.

**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-17T11:01:13.000Z ##

TP-Link Patches Critical Flaws in Tapo Surveillance Cameras

TP-Link patched multiple vulnerabilities in its Tapo C200 and C120 cameras, including an authentication bypass (CVE-2026-15315) and a denial-of-service flaw (CVE-2026-15316), while a third critical vulnerability remains under investigation.

**Update your Tapo camera firmware to version V5_1.4.6 ASAP, and check for new updates for the most severe issue that's still not patched. And move all smart cameras to a separate guest network to keep your main computers safe if a device is hacked.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-09-16T16:32:55.000Z ##

In case you didn't have enough problems with cameras, here's another one.

OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

More:

Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news #infosec #vulnerability #spyware #zeroday #threatresearch

##

security_crawler_carl@infosec.exchange at 2026-09-16T13:10:27.000Z ##

CVE-2026-15316 throws in a denial-of-service against the onboarding flow as a bonus gift with purchase.

Perhaps you'd like our Extended Vulnerability Warranty? Only $49.99. Or — and hear me out — you could just update your Tapo C200 to firmware V5_1.4.6, released August 18, for the remarkable price of free.

Reward: You've received a slightly-used Tin Foil Lens Cap. Refurbished. Non-returnable.

infosecurity-magazine.com/news

#ZeroDay #CyberSecurity (2/2)

##

CVE-2026-80844
(0 None)

EPSS: 0.19%

updated 2026-09-04T16:18:13.023000

7 posts

In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of addresses described by the routing header's hdrlen field. That assumption does not hold for raw IPv6 HDRINCL packets.

cyberworldops at 2026-09-19T04:30:00.974Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk.

cyberworldops.eu/en/four-publi

##

sayzard@mastodon.sayzard.org at 2026-09-18T14:40:50.000Z ##

A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, DiagSpill

Linux 커널에서 일반 로컬 사용자를 root로 승격할 수 있는 4개 취약점 DirtyAH6(CVE-2026-80844), TUNderflow(CVE-2026-81000), PPPoEject(CVE-2026-68121), DiagSpill(CVE-2026-74469)가 공개됐다. 취약점들은 네트워크 서브시스템의 오래된 메모리 손상 문제이며, DiagSpill은 별도 capability나 비특권 사용자 네임스페이스 없이도 조건 충족 시 LPE가 가능하고 컨테이너 호스트 탈출 가능성도 있다. 수정은 Linux stable 5.10.270,...

openwall.com/lists/oss-securit

##

decio at 2026-09-18T08:13:07.228Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

##

harrysintonen at 2026-09-18T06:48:39.896Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

##

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

decio@infosec.exchange at 2026-09-18T08:13:07.000Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

#Linux #CyberSecurity #Vulnerability #CVE #Debian

##

harrysintonen@infosec.exchange at 2026-09-18T06:48:39.000Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469

##

CVE-2026-13348(CVSS UNKNOWN)

EPSS: 0.31%

updated 2026-09-01T15:31:17

2 posts

CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.

cyberworldops at 2026-09-18T22:40:00.819Z ##

Schneider Electric disclosed CVE-2026-13348 (CWE-307) in PowerChute Serial Shutdown, allowing unrestricted authentication attempts. Successful brute-forcing enables account takeover with impact on UPS management and operational continuity.

cyberworldops.eu/en/powerchute

##

cyberworldops@infosec.exchange at 2026-09-18T22:40:00.000Z ##

Schneider Electric disclosed CVE-2026-13348 (CWE-307) in PowerChute Serial Shutdown, allowing unrestricted authentication attempts. Successful brute-forcing enables account takeover with impact on UPS management and operational continuity. #SchneiderElectric #PowerChute #BruteForce

cyberworldops.eu/en/powerchute

##

CVE-2026-56209
(7.1 HIGH)

EPSS: 0.35%

updated 2026-09-01T13:19:49.913000

1 posts

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is full

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56210
(7.1 HIGH)

EPSS: 0.31%

updated 2026-08-31T15:35:36

1 posts

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can inf

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56208
(7.6 HIGH)

EPSS: 0.42%

updated 2026-08-31T15:34:31

1 posts

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56211
(7.1 HIGH)

EPSS: 0.48%

updated 2026-08-31T15:34:31

1 posts

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

DailyCyberSecurity at 2026-09-18T09:26:48.724Z ##

HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.

securityonline.info/hcl-bigfix

##

DailyCyberSecurity@infosec.exchange at 2026-09-18T09:26:48.000Z ##

HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.

#HCLBigFix #Cybersecurity #CVE202667100 #Vulnerability #InfoSec

securityonline.info/hcl-bigfix

##

CVE-2026-56389
(8.6 HIGH)

EPSS: 0.16%

updated 2026-08-24T18:32:30

2 posts

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided gramma

ottoto2017@prattohome.com at 2026-09-18T00:27:51.000Z ##

#Ubuntu 24.04.5 で #update

bison (2:3.8.2+dfsg-1ubuntu0.24.04.1)
CVE-2026-56389へのセキュリティ対応。

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-18T00:27:51.000Z ##

#Ubuntu 24.04.5 で #update

bison (2:3.8.2+dfsg-1ubuntu0.24.04.1)
CVE-2026-56389へのセキュリティ対応。

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-74469
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-19T17:21:03.977000

7 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sctp_assoc_add_peer() increments the association's 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero. SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload, then copies one sockaddr_storage for every entry in t

cyberworldops at 2026-09-19T04:30:00.974Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk.

cyberworldops.eu/en/four-publi

##

sayzard@mastodon.sayzard.org at 2026-09-18T14:40:50.000Z ##

A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, DiagSpill

Linux 커널에서 일반 로컬 사용자를 root로 승격할 수 있는 4개 취약점 DirtyAH6(CVE-2026-80844), TUNderflow(CVE-2026-81000), PPPoEject(CVE-2026-68121), DiagSpill(CVE-2026-74469)가 공개됐다. 취약점들은 네트워크 서브시스템의 오래된 메모리 손상 문제이며, DiagSpill은 별도 capability나 비특권 사용자 네임스페이스 없이도 조건 충족 시 LPE가 가능하고 컨테이너 호스트 탈출 가능성도 있다. 수정은 Linux stable 5.10.270,...

openwall.com/lists/oss-securit

##

decio at 2026-09-18T08:13:07.228Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

##

harrysintonen at 2026-09-18T06:48:39.896Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

##

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

decio@infosec.exchange at 2026-09-18T08:13:07.000Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

#Linux #CyberSecurity #Vulnerability #CVE #Debian

##

harrysintonen@infosec.exchange at 2026-09-18T06:48:39.000Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469

##

CVE-2026-68121
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-19T17:20:29.553000

7 posts

In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is

cyberworldops at 2026-09-19T04:30:00.974Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk.

cyberworldops.eu/en/four-publi

##

sayzard@mastodon.sayzard.org at 2026-09-18T14:40:50.000Z ##

A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, DiagSpill

Linux 커널에서 일반 로컬 사용자를 root로 승격할 수 있는 4개 취약점 DirtyAH6(CVE-2026-80844), TUNderflow(CVE-2026-81000), PPPoEject(CVE-2026-68121), DiagSpill(CVE-2026-74469)가 공개됐다. 취약점들은 네트워크 서브시스템의 오래된 메모리 손상 문제이며, DiagSpill은 별도 capability나 비특권 사용자 네임스페이스 없이도 조건 충족 시 LPE가 가능하고 컨테이너 호스트 탈출 가능성도 있다. 수정은 Linux stable 5.10.270,...

openwall.com/lists/oss-securit

##

decio at 2026-09-18T08:13:07.228Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

##

harrysintonen at 2026-09-18T06:48:39.896Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

##

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

decio@infosec.exchange at 2026-09-18T08:13:07.000Z ##

Ouep, vendredi vuln assisté is back : le kernel Linux, toujours la cible préférée du branding CVE 🐧

DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) et DiagSpill (CVE-2026-74469) permettent, dans les configurations adaptées, à un utilisateur local non privilégié d'obtenir root.
Bugs présents dans le kernel depuis 10 à 21 ans.

Risque pas uniforme : les trois premières nécessitent des user namespaces non privilégiés + des fonctionnalités réseau particulières (AH6/XFRM, TUN/TAP, PPPoE).
DiagSpill est directement accessible sans capability, MAIS nécessite SCTP + sctp_diag.

Pas de RCE distante générique, mais nuance à connaître pour les passerelles : DirtyAH6 peut causer un DoS distant sur un routeur IPv6 faisant de l'AH en mode transport (root distant obtenu en labo par l'auteur, via grooming côté cible--> jugé "extrêmement difficile").
DiagSpill a aussi un vecteur DoS distant si ASCONF/ADD-IP + SCTP-AUTH (ou addip_noauth_enable=1) sont actifs-->désactivés par défaut.

➡️ À surveiller en priorité : systèmes multi-utilisateurs, conteneurs, hôtes TUN/TAP, PPPoE, XFRM/AH6 ou SCTP.

🔎 Analyse complète
👇
heyitsas.im/posts/lpe-quartet/

:debian:
👇
DirtyAH6 corrigé sur Bookworm-security, encore vulnérable sur Trixie.

TUNderflow corrigée uniquement dans sid

PPPoEject et DiagSpill corrigés sur Bookworm-security et Trixie.
⬇️

PoCs 👀
👇
DirtyAH6 — CVE-2026-80844 : github.com/manizada/DirtyAH6
TUNderflow — CVE-2026-81000 : github.com/manizada/TUNderflow
PPPoEject — CVE-2026-68121 : github.com/manizada/PPPoEject
DiagSpill — CVE-2026-74469 : github.com/manizada/DiagSpill

#Linux #CyberSecurity #Vulnerability #CVE #Debian

##

harrysintonen@infosec.exchange at 2026-09-18T06:48:39.000Z ##

It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel:

- DirtyAH6 (CVE-2026-80844)
- TUNderflow (CVE-2026-81000)
- PPPoEject (CVE-2026-68121)
- DiagSpill (CVE-2026-74469)

"The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or specific CAPs; DiagSpill does not."

openwall.com/lists/oss-securit
heyitsas.im/posts/lpe-quartet/

#CVE_2026_80844 #CVE_2026_81000 #CVE_2026_68121 #CVE_2026_74469

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 49.68%

updated 2026-08-18T18:32:52

3 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

2 repos

https://github.com/BiuTrap/CVE-2026-59310

https://github.com/HORKimhab/CVE-2026-59310

CapTechGroup@mastodon.social at 2026-09-18T12:48:49.000Z ##

Oracle's quarterly release fixed 800+ flaws, none flagged as exploited. Meanwhile CVE-2026-59310, an unauthenticated directory traversal in the VMware vCenter Syslog server patched in July, is now in ransomware hands after...

captechgroup.com/threat-intell

##

DailyCyberSecurity at 2026-09-17T14:01:28.726Z ##

Discover how ransomware gangs actively exploit the critical VMware vCenter flaw, CVE-2026-59310. Learn about the swift weaponization and severe infrastructure risks.

meterpreter.org/vmware-vcenter

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T14:01:28.000Z ##

Discover how ransomware gangs actively exploit the critical VMware vCenter flaw, CVE-2026-59310. Learn about the swift weaponization and severe infrastructure risks.

#VMware #vCenter #CVE202659310 #Ransomware #CyberSecurity

meterpreter.org/vmware-vcenter

##

CVE-2026-19487
(5.3 MEDIUM)

EPSS: 0.42%

updated 2026-08-13T21:37:11

1 posts

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass. The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-5430
(10.0 CRITICAL)

EPSS: 0.32%

updated 2026-08-06T09:30:40

1 posts

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of adm

1 repos

https://github.com/HORKimhab/CVE-2026-5430

beyondmachines1@infosec.exchange at 2026-09-17T09:01:13.000Z ##

WSO2 Warns of Active Exploitation Targeting Critical Authentication Bypass

WSO2 is warning of active exploitation of a critical authentication bypass vulnerability (CVE-2026-5430) that allows attackers to take over administrative accounts and steal sensitive API credentials. The flaw affects multiple middleware products and has been targeted in the wild since mid-September 2026.

**If you run WSO2 API Manager, API Control Plane, Traffic Manager, or Universal Gateway, check for affected versions and patch immediately to the latest update level from WSO2. If you are using open source version apply the public GitHub fix. Attackers are already using forged tokens to gain full admin access.
After patching, assume your secrets were exposed and rotate all API keys, backend credentials, consumer keys, and application secrets, and check your logs for suspicious access since September 13, 2026.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-7646
(6.5 MEDIUM)

EPSS: 0.30%

updated 2026-08-05T18:31:49

2 posts

IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path traversal sequence in the filename.

5 repos

https://github.com/S3v3n-JG/CVE-2026-76461

https://github.com/fevar54/CVE-2026-76461-Detection-Kit-

https://github.com/S3v3n-JG/CVE-2026-76460

https://github.com/HORKimhab/CVE-2026-76461

https://github.com/0xBlackash/CVE-2026-76461

hackmag at 2026-09-18T15:36:29.481Z ##

⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email

🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…

🔗 hackmag.com/news/cve-2026-7646

##

hackmag@infosec.exchange at 2026-09-18T15:36:29.000Z ##

⚪️ Cisco Secure Email Gateway Appliances Can Be Hacked with a Malicious Email

🗨️ Cisco researchers have fixed a critical vulnerability in Secure Email Gateway, a gateway designed to protect email from malicious messages. Ironically, to compromise the gateway itself, an attacker only had to send a specially crafted email through it. The vulnerability…

🔗 hackmag.com/news/cve-2026-7646

#news

##

CVE-2026-15830
(5.3 MEDIUM)

EPSS: 1.26%

updated 2026-08-04T18:31:31

1 posts

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spa

djangonews@mastodon.social at 2026-09-16T20:00:11.000Z ##

[Django Fellow Reports] Django Fellow Report - Jacob

Jacob reviewed six Django pull requests and authored changes covering GEOS 3.10 support removal and expanded WKT depth-check coverage related to CVE-2026-15830.
forum.djangoproject.com/t/djan

##

CVE-2026-13584(CVSS UNKNOWN)

EPSS: 0.13%

updated 2026-08-04T06:32:37

2 posts

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Ana

cyberworldops at 2026-09-18T02:40:00.943Z ##

Mitsubishi Electric CC-Link IE TSN is affected by CVE-2026-13584, CWE-924 message integrity failure. An adjacent attacker can inject crafted packets under timing conditions to tamper with OT traffic. It matters for ICS integrity and safety assumptions on trusted segments.

cyberworldops.eu/en/mitsubishi

##

cyberworldops@infosec.exchange at 2026-09-18T02:40:00.000Z ##

Mitsubishi Electric CC-Link IE TSN is affected by CVE-2026-13584, CWE-924 message integrity failure. An adjacent attacker can inject crafted packets under timing conditions to tamper with OT traffic. It matters for ICS integrity and safety assumptions on trusted segments. #IcsSecurity #OtSecurity #MessageIntegrity

cyberworldops.eu/en/mitsubishi

##

CVE-2026-45659
(8.8 HIGH)

EPSS: 76.08%

updated 2026-07-01T21:35:53

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

2 repos

https://github.com/WismanSec/sharepoint-2026-poc

https://github.com/HORKimhab/CVE-2026-45659

CVE-2026-58138
(9.8 CRITICAL)

EPSS: 9.26%

updated 2026-06-30T21:31:51

2 posts

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or

Nuclei template

6 repos

https://github.com/BiiTts/CVE-2026-58138-Conductor-Unauth-RCE

https://github.com/seqra/cve-2026-58138

https://github.com/0xgh057r3c0n/CVE-2026-58138

https://github.com/Procjevt/CVE-2026-58138

https://github.com/0xBlackash/CVE-2026-58138

https://github.com/Ch4120N/CVE-2026-58138

cyberworldops at 2026-09-18T13:10:00.595Z ##

Orkes Conductor 3.21.21 through before 3.30.2 is affected by CVE-2026-58138, an unauthenticated RCE via malicious workflow definitions using inline JS/Python. Exposed APIs allow arbitrary OS command execution with host-level impact. Patch to 3.30.2 and restrict exposure.

cyberworldops.eu/en/exposed-or

##

cyberworldops@infosec.exchange at 2026-09-18T13:10:00.000Z ##

Orkes Conductor 3.21.21 through before 3.30.2 is affected by CVE-2026-58138, an unauthenticated RCE via malicious workflow definitions using inline JS/Python. Exposed APIs allow arbitrary OS command execution with host-level impact. Patch to 3.30.2 and restrict exposure. #OrkesConductor #RemoteCodeExecution #ThreatIntel

cyberworldops.eu/en/exposed-or

##

CVE-2026-8024
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-06-22T17:47:16.070000

1 posts

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.

certvde@infosec.exchange at 2026-09-17T08:41:07.000Z ##

🔄 CSAF advisory updated (version 3.0.0)

VDE-2026-051
iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator
CVE-2026-8024

Changes: Corrected all CPE numbers and vendor name of all products.

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: iba.csaf-tp.certvde.com/.well-

#OT #Advisory

##

CVE-2026-32746
(9.8 CRITICAL)

EPSS: 23.67%

updated 2026-03-23T15:31:40

3 posts

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

8 repos

https://github.com/chosenonehacks/CVE-2026-32746

https://github.com/ekomsSavior/telnet_scan

https://github.com/danindiana/cve-2026-32746-mitigation

https://github.com/MonkeySeC-sys/Kangaroo

https://github.com/duduLiu8787/CVE-2026-32746-Exploit

https://github.com/kaleth4/CVE-2026-32746

https://github.com/watchtowrlabs/watchtowr-vs-telnetd-CVE-2026-32746

https://github.com/jeffaf/cve-2026-32746

CVE-2024-20260
(8.6 HIGH)

EPSS: 0.59%

updated 2024-10-23T18:33:16

1 posts

A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv), formerly Cisco Firepower Threat Defense Virtual, platforms could allow an unauthenticated, remote attacker to cause the virtual devices to run out of system memory, which could cause SSL VPN connection processing to slow down and eve

CVE-2026-57228
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T23:02:48.000Z ##

🟠 CVE-2026-57228 - High (8.2)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:02:48.000Z ##

🟠 CVE-2026-57228 - High (8.2)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63447
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T23:02:21.000Z ##

🟠 CVE-2026-63447 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T23:02:21.000Z ##

🟠 CVE-2026-63447 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63446
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T22:03:40.000Z ##

🟠 CVE-2026-63446 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:03:40.000Z ##

🟠 CVE-2026-63446 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63452
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T22:03:30.000Z ##

🟠 CVE-2026-63452 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli comp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:03:30.000Z ##

🟠 CVE-2026-63452 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli comp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68928
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T22:03:20.000Z ##

🟠 CVE-2026-68928 - High (8.6)

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:03:20.000Z ##

🟠 CVE-2026-68928 - High (8.6)

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71418
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T22:02:15.000Z ##

🟠 CVE-2026-71418 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame cont...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T22:02:15.000Z ##

🟠 CVE-2026-71418 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame cont...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92708
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T21:02:57.000Z ##

🟠 CVE-2026-92708 - High (7.5)

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing Arr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-18T21:02:57.000Z ##

🟠 CVE-2026-92708 - High (7.5)

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing Arr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72878
(0 None)

EPSS: 0.27%

2 posts

N/A

DailyCyberSecurity at 2026-09-18T06:14:51.981Z ##

A critical Dokploy OS command injection flaw (CVE-2026-72878) exposes servers to root takeover via backups. Patch this Dokploy OS command injection now.

securityonline.info/dokploy-os

##

DailyCyberSecurity@infosec.exchange at 2026-09-18T06:14:51.000Z ##

A critical Dokploy OS command injection flaw (CVE-2026-72878) exposes servers to root takeover via backups. Patch this Dokploy OS command injection now.

#Dokploy #CommandInjection #CVE202672878 #Cybersecurity #PaaS

securityonline.info/dokploy-os

##

CVE-2026-54670
(0 None)

EPSS: 0.55%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T23:01:30.000Z ##

🔴 CVE-2026-54670 - Critical (9.1)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and meth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T23:01:30.000Z ##

🔴 CVE-2026-54670 - Critical (9.1)

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and meth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54734
(0 None)

EPSS: 0.36%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T23:00:45.000Z ##

🔴 CVE-2026-54734 - Critical (10)

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T23:00:45.000Z ##

🔴 CVE-2026-54734 - Critical (10)

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93426
(0 None)

EPSS: 0.37%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T23:00:26.000Z ##

🟠 CVE-2026-93426 - High (8.5)

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T23:00:26.000Z ##

🟠 CVE-2026-93426 - High (8.5)

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54752
(0 None)

EPSS: 0.35%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T21:01:39.000Z ##

🔴 CVE-2026-54752 - Critical (9.6)

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T21:01:39.000Z ##

🔴 CVE-2026-54752 - Critical (9.6)

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54716
(0 None)

EPSS: 0.32%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T21:01:30.000Z ##

🟠 CVE-2026-54716 - High (7.5)

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unboun...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T21:01:30.000Z ##

🟠 CVE-2026-54716 - High (7.5)

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can cause unboun...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54627
(0 None)

EPSS: 0.44%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T21:00:40.000Z ##

🔴 CVE-2026-54627 - Critical (9.8)

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap col...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T21:00:40.000Z ##

🔴 CVE-2026-54627 - Critical (9.8)

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap col...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93337
(0 None)

EPSS: 0.15%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-17T21:00:20.000Z ##

🟠 CVE-2026-93337 - High (7.8)

NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-17T21:00:20.000Z ##

🟠 CVE-2026-93337 - High (7.8)

NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85500
(0 None)

EPSS: 0.55%

2 posts

N/A

offseq at 2026-09-17T13:30:29.257Z ##

CVE-2026-85500: team-alembic ash_authentication (4.3.8 – 4.15.0, 5.0.0-rc.14) suffers a CRITICAL auth bypass — unconfirmed users may gain sessions, defeating email confirmation. Patch urgently. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-17T13:30:29.000Z ##

CVE-2026-85500: team-alembic ash_authentication (4.3.8 – 4.15.0, 5.0.0-rc.14) suffers a CRITICAL auth bypass — unconfirmed users may gain sessions, defeating email confirmation. Patch urgently. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE202685500 #AshAuthentication

##

CVE-2026-59347
(0 None)

EPSS: 0.00%

2 posts

N/A

sekurakbot@mastodon.com.pl at 2026-09-17T13:24:00.000Z ##

VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście

Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...

#WBiegu

sekurak.pl/vmware-lata-powazne

##

sekurakbot@mastodon.com.pl at 2026-09-17T13:24:00.000Z ##

VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście

Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...

#WBiegu

sekurak.pl/vmware-lata-powazne

##

CVE-2026-59346
(0 None)

EPSS: 0.00%

2 posts

N/A

1 repos

https://github.com/0xCyberstan/CVE-2026-59346-POC

sekurakbot@mastodon.com.pl at 2026-09-17T13:24:00.000Z ##

VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście

Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...

#WBiegu

sekurak.pl/vmware-lata-powazne

##

sekurakbot@mastodon.com.pl at 2026-09-17T13:24:00.000Z ##

VMware łata poważne błędy w Workstation i Fusion. Można wyskoczyć z maszyny wirtualnej i wykonać kod na hoście

Broadcom poinformował o załataniu dwóch poważnych błędów w popularnych produktach VMware Workstation oraz VMware Fusion. W określonych warunkach ich wykorzystanie mogło doprowadzić do ucieczki z maszyny wirtualnej oraz wykonanie kodu bezpośrednio na hoście. TLDR: Podatności otrzymały identyfikatory CVE-2026-59346 (CVSS 9.3) oraz CVE-2026-59347 (CVSS 8.1). Pierwsza z nich to błąd typu...

#WBiegu

sekurak.pl/vmware-lata-powazne

##

Visit counter For Websites