##
Updated at UTC 2026-08-21T15:19:13.566285
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-77683 | 9.9 | 0.00% | 2 | 0 | 2026-08-21T14:16:53.637000 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this | |
| CVE-2026-77651 | 9.8 | 0.43% | 1 | 0 | 2026-08-21T14:16:53.510000 | The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when | |
| CVE-2026-73570 | 8.9 | 0.54% | 7 | 1 | 2026-08-21T14:05:53.253000 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor | |
| CVE-2026-73938 | 7.5 | 0.38% | 1 | 0 | 2026-08-21T13:38:20.260000 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73935 | 7.5 | 0.30% | 1 | 0 | 2026-08-21T13:38:06.317000 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73934 | 7.5 | 0.30% | 1 | 0 | 2026-08-21T13:38:01.810000 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73931 | 8.3 | 0.23% | 1 | 0 | 2026-08-21T13:37:15.280000 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73930 | 9.9 | 0.36% | 1 | 0 | 2026-08-21T13:37:11.433000 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73925 | 8.2 | 0.23% | 1 | 0 | 2026-08-21T13:36:32.327000 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-76158 | 0 | 0.41% | 1 | 0 | 2026-08-21T13:18:19.727000 | External Control of File Name or Path in the upload API endpoint of Datiphy Data | |
| CVE-2026-69836 | 10.0 | 1.37% | 10 | 1 | 2026-08-21T12:28:35.090000 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a | |
| CVE-2026-77776 | 9.1 | 0.00% | 4 | 0 | 2026-08-21T12:16:36.967000 | Headroom's LLM proxy derives the memory owner from the x-headroom-user-id reques | |
| CVE-2026-77775 | 8.6 | 0.00% | 2 | 0 | 2026-08-21T12:16:36.813000 | Headroom's LLM proxy lets a client choose the upstream destination with the x-he | |
| CVE-2026-59279 | 7.5 | 0.00% | 2 | 0 | 2026-08-21T12:16:30.013000 | The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not | |
| CVE-2026-18781 | None | 0.21% | 2 | 0 | 2026-08-21T09:32:04 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin befor | |
| CVE-2026-76310 | 9.4 | 0.37% | 1 | 0 | 2026-08-21T04:18:20.733000 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut | |
| CVE-2026-75144 | 7.8 | 0.14% | 1 | 0 | 2026-08-21T04:18:19.900000 | FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in th | |
| CVE-2026-75143 | 9.8 | 0.40% | 1 | 0 | 2026-08-21T04:18:19.753000 | FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protoco | |
| CVE-2026-72530 | 9.0 | 0.97% | 5 | 0 | 2026-08-21T04:18:15.903000 | A remote unauthorized attacker with network access via port 4307/TCP to the True | |
| CVE-2026-72529 | 9.8 | 0.78% | 4 | 0 | 2026-08-21T04:18:15.753000 | A remote unauthorized attacker with network access via port 4307/TCP to the True | |
| CVE-2026-19586 | 0 | 5.04% | 1 | 0 | 2026-08-21T04:18:02.220000 | A pre-authentication OS command injection vulnerability has been identified in O | |
| CVE-2026-76155 | None | 0.29% | 1 | 0 | 2026-08-21T03:31:29 | Use of default credentials in Datiphy Data Management Center from v8.3.0 through | |
| CVE-2026-76156 | None | 0.83% | 1 | 0 | 2026-08-21T03:31:29 | OS command injection in the api endpoint of Datiphy Data Management Center from | |
| CVE-2026-77647 | 9.8 | 0.81% | 2 | 0 | 2026-08-21T00:31:31 | SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary | |
| CVE-2026-77645 | None | 0.47% | 1 | 0 | 2026-08-21T00:31:31 | A critical remote code execution (RCE) vulnerability has been reported in PTC Wi | |
| CVE-2026-69855 | 7.7 | 0.48% | 1 | 0 | 2026-08-21T00:31:31 | Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an autho | |
| CVE-2026-72860 | 8.5 | 0.22% | 1 | 0 | 2026-08-21T00:31:31 | The POST /api/provider-nodes/validate route in 9router takes a caller-supplied b | |
| CVE-2026-72848 | 8.6 | 0.48% | 1 | 0 | 2026-08-21T00:31:31 | SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py a | |
| CVE-2026-72818 | 7.5 | 0.51% | 1 | 0 | 2026-08-21T00:31:31 | The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetToken | |
| CVE-2026-77642 | 7.5 | 0.19% | 1 | 0 | 2026-08-21T00:31:31 | tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus | |
| CVE-2026-72843 | 9.8 | 0.57% | 1 | 0 | 2026-08-21T00:31:24 | The customer update route in EverShop is declared with "access": "public" in pac | |
| CVE-2026-66792 | 9.9 | 0.30% | 1 | 0 | 2026-08-20T23:16:28.200000 | A flaw was found in the multicloud-operators-subscription component. This vulner | |
| CVE-2026-73040 | 8.8 | 0.67% | 1 | 0 | 2026-08-20T21:31:37 | Dockge validates a stack name only on the write path. In backend/stack.ts the al | |
| CVE-2026-67567 | 9.9 | 0.32% | 3 | 0 | 2026-08-20T21:31:36 | A flaw was found in the multicloud-operators-subscription component. This vulner | |
| CVE-2026-18420 | 8.8 | 0.96% | 1 | 0 | 2026-08-20T21:31:36 | Improper input validation in the Time Series Visual Builder (TSVB) plugin in Ope | |
| CVE-2026-72852 | 7.8 | 0.14% | 1 | 0 | 2026-08-20T21:31:36 | hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by | |
| CVE-2026-77148 | 9.9 | 0.47% | 1 | 0 | 2026-08-20T21:31:36 | A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function | |
| CVE-2026-73137 | 7.7 | 0.29% | 1 | 0 | 2026-08-20T21:31:30 | A flaw was found in the multicloud-operators-subscription component of Red Hat A | |
| CVE-2026-77638 | 8.9 | 0.17% | 1 | 0 | 2026-08-20T21:31:30 | Tor before 0.4.9.11 is prone to a race condition where in just the right circums | |
| CVE-2026-76017 | 0 | 0.36% | 1 | 0 | 2026-08-20T21:17:09.800000 | Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a | |
| CVE-2026-73257 | 9.1 | 0.38% | 1 | 0 | 2026-08-20T20:17:46.470000 | Mongoose is an embedded web server and network library. Priro to version 7.22, a | |
| CVE-2026-76641 | 7.5 | 0.34% | 1 | 0 | 2026-08-20T19:17:04.430000 | Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows att | |
| CVE-2026-66785 | 9.9 | 0.29% | 2 | 0 | 2026-08-20T19:16:58.463000 | A flaw was found in Submariner. This vulnerability allows a malicious cluster (s | |
| CVE-2026-16885 | 9.8 | 0.80% | 1 | 0 | 2026-08-20T19:16:50.880000 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e | |
| CVE-2026-77022 | 9.9 | 0.46% | 1 | 0 | 2026-08-20T18:31:06 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this | |
| CVE-2026-75140 | 7.5 | 0.53% | 1 | 0 | 2026-08-20T18:30:58 | jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource | |
| CVE-2026-73256 | 9.1 | 0.40% | 1 | 0 | 2026-08-20T18:16:46.523000 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote | |
| CVE-2026-76928 | 7.5 | 0.28% | 1 | 0 | 2026-08-20T17:19:48.260000 | X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows de | |
| CVE-2026-66582 | 7.1 | 0.18% | 1 | 0 | 2026-08-20T17:19:24.533000 | Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. | |
| CVE-2026-63038 | 0 | 0.21% | 1 | 0 | 2026-08-20T17:19:14.390000 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti | |
| CVE-2026-18290 | 7.8 | 0.26% | 1 | 0 | 2026-08-20T17:17:25.647000 | OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution V | |
| CVE-2026-76880 | 7.5 | 0.28% | 1 | 0 | 2026-08-20T16:18:22.187000 | RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial | |
| CVE-2026-76879 | 7.5 | 0.28% | 1 | 0 | 2026-08-20T16:18:21.780000 | C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows den | |
| CVE-2026-76633 | 8.1 | 0.24% | 1 | 0 | 2026-08-20T16:18:19.223000 | WeGIA before 3.9.2 contains an authorization bypass vulnerability in the passwor | |
| CVE-2026-76397 | 8.1 | 0.25% | 1 | 0 | 2026-08-20T16:18:13.520000 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk r | |
| CVE-2026-71961 | 8.8 | 3.34% | 1 | 0 | 2026-08-20T16:17:52.367000 | Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection | |
| CVE-2026-19942 | 8.1 | 0.69% | 1 | 0 | 2026-08-20T16:17:19.950000 | The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO | |
| CVE-2026-14953 | 4.3 | 0.20% | 1 | 0 | 2026-08-20T16:17:07.463000 | A low-privileged remote attacker can enumerate all configured users and identify | |
| CVE-2026-14950 | 9.8 | 0.55% | 3 | 0 | 2026-08-20T16:17:07.210000 | An unauthenticated remote attacker in possession of a valid session identifier i | |
| CVE-2026-14948 | 8.8 | 0.39% | 1 | 0 | 2026-08-20T16:17:07.080000 | A low privileged remote attacker can hijack an active administrative session wit | |
| CVE-2026-76833 | 7.8 | 0.15% | 1 | 0 | 2026-08-20T15:34:26 | @cgauge/yaml npm package contains an arbitrary code execution vulnerability that | |
| CVE-2026-76886 | 8.1 | 0.32% | 1 | 0 | 2026-08-20T15:34:14 | C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows den | |
| CVE-2026-75146 | 8.1 | 0.26% | 1 | 0 | 2026-08-20T15:18:38.097000 | FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer | |
| CVE-2026-61897 | 7.8 | 0.10% | 1 | 0 | 2026-08-20T15:17:38.740000 | An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partial | |
| CVE-2026-28164 | 9.6 | 0.15% | 1 | 0 | 2026-08-20T15:17:29.713000 | Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Add | |
| CVE-2026-75569 | 7.7 | 0.29% | 1 | 0 | 2026-08-20T14:17:58.883000 | A flaw was found in mce-operator-bundle. The build process fetches and executes | |
| CVE-2026-19490 | 0 | 0.33% | 4 | 0 | 2026-08-20T14:17:10.673000 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f | |
| CVE-2026-18963 | 9.1 | 0.39% | 5 | 1 | 2026-08-20T14:17:10.413000 | A flaw was found in the reset-credentials flow of the keycloak-services componen | |
| CVE-2026-66780 | 9.9 | 0.24% | 1 | 0 | 2026-08-20T13:08:53.900000 | A flaw was found in the submariner-operator component. The `submariner-k8s-broke | |
| CVE-2026-13097 | 9.1 | 0.34% | 1 | 0 | 2026-08-20T13:08:53.900000 | A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enfo | |
| CVE-2026-73197 | 7.5 | 0.35% | 1 | 0 | 2026-08-20T13:08:53.900000 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this | |
| CVE-2026-20030 | 10.0 | 0.45% | 1 | 0 | 2026-08-20T13:01:19.947000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-75935 | 7.5 | 0.44% | 1 | 0 | 2026-08-20T13:01:19.947000 | Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-jav | |
| CVE-2026-32475 | 9.0 | 0.42% | 10 | 0 | 2026-08-20T12:48:31.843000 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Eleme | |
| CVE-2026-15748 | 9.8 | 3.45% | 2 | 3 | 2026-08-20T12:48:10.287000 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload | |
| CVE-2026-76008 | 10.0 | 0.57% | 2 | 0 | 2026-08-20T12:48:10.287000 | A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_ | |
| CVE-2026-73198 | 7.5 | 0.35% | 1 | 0 | 2026-08-20T12:31:29 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vu | |
| CVE-2026-75860 | 9.8 | 0.34% | 1 | 0 | 2026-08-20T12:31:22 | The JSON Options WordPress plugin through 0.0.4 does not have any capability che | |
| CVE-2026-14952 | 7.5 | 0.49% | 1 | 0 | 2026-08-20T09:31:23 | An unauthenticated remote attacker can retrieve sensible files from the FDS Web | |
| CVE-2026-14949 | 6.5 | 0.26% | 1 | 0 | 2026-08-20T09:31:23 | A low privileged remote attacker with a valid session can submit a request to th | |
| CVE-2026-14951 | 8.0 | 0.16% | 1 | 0 | 2026-08-20T09:31:23 | An low privileged remote attacker can cause authenticated users to perform unint | |
| CVE-2026-14947 | 7.2 | 0.94% | 1 | 0 | 2026-08-20T09:31:23 | A high-privileged remote attacker can upload malicious ZIP archive containing di | |
| CVE-2026-14946 | 7.2 | 0.52% | 1 | 0 | 2026-08-20T09:16:45.813000 | A high privileged remote attacker can upload a .php file and then request it dir | |
| CVE-2026-76589 | 9.9 | 0.61% | 2 | 0 | 2026-08-20T00:35:17 | A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the | |
| CVE-2026-76850 | 9.8 | 0.98% | 2 | 0 | 2026-08-20T00:35:17 | LMDeploy deserializes disaggregated-serving peer messages with pickle. The handl | |
| CVE-2026-76590 | 9.9 | 0.61% | 2 | 0 | 2026-08-20T00:35:16 | A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by | |
| CVE-2026-76832 | 8.8 | 0.84% | 1 | 0 | 2026-08-20T00:35:16 | Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal v | |
| CVE-2026-76399 | 8.1 | 0.25% | 1 | 0 | 2026-08-20T00:35:11 | In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk r | |
| CVE-2026-76396 | 7.5 | 0.24% | 1 | 0 | 2026-08-20T00:35:11 | In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the sch | |
| CVE-2026-76395 | 8.8 | 0.47% | 1 | 0 | 2026-08-20T00:35:11 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk r | |
| CVE-2026-76404 | 9.1 | 0.56% | 3 | 0 | 2026-08-20T00:35:08 | In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splu | |
| CVE-2026-20231 | 9.9 | 0.41% | 1 | 0 | 2026-08-19T21:31:33 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76139 | 8.0 | 0.33% | 1 | 0 | 2026-08-19T21:30:46 | A flaw was found in acm-operator-bundle. The build process for this component do | |
| CVE-2026-76584 | 9.9 | 0.49% | 1 | 0 | 2026-08-19T21:30:40 | A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected b | |
| CVE-2026-70496 | 9.9 | 0.26% | 2 | 0 | 2026-08-19T21:30:39 | A flaw was found in search-v2-operator. The operator's ClusterRole has permissio | |
| CVE-2026-18848 | 8.3 | 0.10% | 1 | 0 | 2026-08-19T21:30:32 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 thr | |
| CVE-2026-20315 | 10.0 | 0.32% | 4 | 0 | 2026-08-19T21:30:29 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20317 | 10.0 | 0.34% | 2 | 0 | 2026-08-19T21:30:29 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-68899 | 8.7 | 0.40% | 1 | 0 | 2026-08-19T20:17:21.567000 | Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in m | |
| CVE-2026-68561 | 8.8 | 0.38% | 1 | 0 | 2026-08-19T20:17:21.400000 | Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards. | |
| CVE-2026-52876 | 8.8 | 0.15% | 1 | 0 | 2026-08-19T19:17:19.073000 | Streambert is a cross-platform Electron Desktop App to stream and download video | |
| CVE-2026-50142 | 7.5 | 0.56% | 1 | 1 | 2026-08-19T19:17:18.057000 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1. | |
| CVE-2026-61518 | 8.8 | 0.31% | 1 | 0 | 2026-08-19T18:32:57 | ISPConfig contains an authenticated SQL injection vulnerability in the Remote AP | |
| CVE-2026-66794 | 9.3 | 0.32% | 1 | 0 | 2026-08-19T18:32:57 | A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine f | |
| CVE-2026-75142 | 7.8 | 0.14% | 1 | 0 | 2026-08-19T18:32:57 | FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS mux | |
| CVE-2026-75141 | 7.8 | 0.14% | 1 | 0 | 2026-08-19T18:32:57 | FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box wri | |
| CVE-2026-20320 | 7.5 | 0.35% | 1 | 0 | 2026-08-19T18:32:51 | A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWork | |
| CVE-2026-18051 | 10.0 | 0.43% | 1 | 0 | 2026-08-19T18:32:44 | The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the | |
| CVE-2026-60702 | 9.9 | 0.42% | 1 | 0 | 2026-08-19T18:32:34 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware | |
| CVE-2026-75149 | 8.8 | 0.64% | 1 | 0 | 2026-08-19T18:17:26.080000 | marimo before 0.23.15 contains a code injection vulnerability in the notebook co | |
| CVE-2026-73924 | 9.1 | 0.29% | 1 | 0 | 2026-08-19T15:33:23 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73921 | 9.8 | 0.33% | 1 | 0 | 2026-08-19T15:33:23 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-71176 | 8.8 | 0.30% | 1 | 0 | 2026-08-19T15:32:47 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutra | |
| CVE-2026-76234 | 7.5 | 0.22% | 1 | 0 | 2026-08-19T15:32:36 | libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, con | |
| CVE-2026-67364 | None | 0.29% | 1 | 0 | 2026-08-19T15:32:24 | Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < | |
| CVE-2026-73937 | 8.2 | 0.38% | 1 | 0 | 2026-08-19T15:32:20 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73939 | 8.6 | 0.32% | 1 | 0 | 2026-08-19T15:32:20 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73922 | 9.1 | 0.29% | 1 | 0 | 2026-08-19T15:32:19 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-73936 | 7.5 | 0.41% | 1 | 0 | 2026-08-19T15:32:19 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp | |
| CVE-2026-70408 | 8.8 | 0.33% | 1 | 0 | 2026-08-19T06:31:24 | An incorrect authorization vulnerability exists in acmailer, which may allow a u | |
| CVE-2026-76004 | 9.9 | 0.44% | 2 | 0 | 2026-08-19T03:31:30 | A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-21090 | |
| CVE-2026-76003 | 9.9 | 0.44% | 2 | 0 | 2026-08-19T03:31:23 | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected | |
| CVE-2026-75976 | 9.9 | 0.63% | 2 | 0 | 2026-08-19T00:31:19 | A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the | |
| CVE-2026-21580 | None | 0.36% | 1 | 0 | 2026-08-19T00:31:18 | This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security | |
| CVE-2026-66602 | 8.8 | 0.15% | 1 | 0 | 2026-08-19T00:31:18 | Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress | |
| CVE-2026-75877 | 9.9 | 0.61% | 1 | 0 | 2026-08-18T21:31:59 | A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affec | |
| CVE-2026-47627 | 9.8 | 0.43% | 1 | 0 | 2026-08-18T21:31:53 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attac | |
| CVE-2026-67271 | 9.8 | 0.46% | 1 | 0 | 2026-08-18T18:32:05 | Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/ | |
| CVE-2026-65400 | 7.1 | 0.75% | 2 | 1 | 2026-08-18T18:31:47 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-33824 | 9.8 | 77.90% | 3 | 2 | 2026-08-18T18:31:46 | Double free in Windows IKE Extension allows an unauthorized attacker to execute | |
| CVE-2026-24301 | 8.8 | 1.63% | 2 | 1 | 2026-08-18T15:31:45 | Improper neutralization of special elements used in a command ('command injectio | |
| CVE-2026-40145 | 0 | 0.11% | 1 | 0 | 2026-08-18T15:04:46.610000 | A vulnerability exists in the interaction between a Endpoint Privilege Managemen | |
| CVE-2026-19478 | 9.4 | 1.51% | 9 | 4 | template | 2026-08-18T14:57:10.630000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 |
| CVE-2025-62593 | 8.8 | 1.01% | 2 | 1 | 2026-08-18T04:16:40.860000 | Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ra | |
| CVE-2026-64849 | 9.3 | 8.15% | 5 | 3 | 2026-08-17T21:58:52 | ### Summary The default MLflow Tracking Server (`mlflow server`, no authenticati | |
| CVE-2026-17482 | 9.8 | 0.55% | 1 | 0 | 2026-08-17T19:16:28.953000 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to e | |
| CVE-2026-40144 | None | 0.11% | 1 | 0 | 2026-08-17T18:31:22 | A memory-corruption vulnerability exists in a kernel-mode component of BeyondTru | |
| CVE-2026-47686 | 9.9 | 0.32% | 1 | 0 | 2026-08-17T17:32:35 | **Affected:** vm2 <= 3.11.3 **CVSS 3.1:** 9.9 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N | |
| CVE-2026-68820 | 7.0 | 0.33% | 1 | 2 | 2026-08-16T19:17:24.183000 | Use after free in Windows Ancillary Function Driver for WinSock allows an author | |
| CVE-2026-17186 | 9.9 | 0.47% | 1 | 0 | 2026-08-14T21:31:35 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute | |
| CVE-2026-8715 | 9.6 | 0.32% | 1 | 0 | 2026-08-13T21:36:21 | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read | |
| CVE-2026-13738 | 0 | 0.53% | 1 | 0 | 2026-08-11T17:17:47.660000 | CommServe contained an authorization bypass vulnerability affecting a limited se | |
| CVE-2026-13737 | 0 | 0.43% | 1 | 0 | 2026-08-11T17:17:47.540000 | CommServe contained an allowlist bypass vulnerability affecting command executio | |
| CVE-2026-6540 | 7.5 | 0.37% | 1 | 1 | 2026-08-08T03:32:15 | Calico's Application Layer Policy (disabled by default), which enforces HTTP rul | |
| CVE-2026-66066 | 0 | 1.77% | 2 | 7 | 2026-08-05T15:17:03.507000 | Action Pack is a framework for handling and responding to web requests. In versi | |
| CVE-2026-11622 | 7.5 | 0.51% | 1 | 0 | 2026-07-22T20:33:11.590000 | A DNSSEC validating resolver that is under a random subdomain attack against a D | |
| CVE-2026-47301 | 8.8 | 0.68% | 1 | 1 | 2026-07-14T21:32:21 | Improper access control in Microsoft Configuration Manager allows an authorized | |
| CVE-2026-52929 | 7.5 | 0.39% | 1 | 0 | 2026-07-08T15:28:40.107000 | In the Linux kernel, the following vulnerability has been resolved: sctp: strea | |
| CVE-2026-58472 | 5.9 | 0.22% | 1 | 0 | 2026-07-07T21:31:43 | GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflo | |
| CVE-2026-8452 | 9.8 | 1.04% | 2 | 2 | 2026-07-01T15:52:28.390000 | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp | |
| CVE-2026-12569 | 9.8 | 30.20% | 7 | 1 | 2026-06-26T15:33:15 | A critical remote code execution (RCE) vulnerability has been reported in PTC Wi | |
| CVE-2026-20266 | 9.1 | 0.63% | 1 | 0 | 2026-06-17T18:35:58 | In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk r | |
| CVE-2010-3854 | 0 | 5.92% | 1 | 0 | 2026-06-16T23:23:40.850000 | Multiple cross-site scripting (XSS) vulnerabilities in the web administration in | |
| CVE-2008-5161 | 3.7 | 15.39% | 1 | 1 | 2026-06-16T22:59:22.107000 | Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Conne | |
| CVE-2026-0075 | 5.9 | 0.09% | 2 | 1 | 2026-06-02T15:33:09 | In multiple functions, there is a possible way to access the contacts database d | |
| CVE-2026-1947 | 7.5 | 0.27% | 1 | 4 | 2026-03-16T15:30:54 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vuln | |
| CVE-2026-59270 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-77176 | 0 | 0.41% | 2 | 0 | N/A | ||
| CVE-2026-71485 | 0 | 0.42% | 1 | 0 | N/A | ||
| CVE-2026-71428 | 0 | 0.25% | 1 | 0 | N/A | ||
| CVE-2026-59324 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-59307 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-63490 | 0 | 0.47% | 1 | 0 | N/A | ||
| CVE-2026-54330 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-68900 | 0 | 0.25% | 1 | 0 | N/A | ||
| CVE-2026-50191 | 0 | 0.33% | 1 | 0 | N/A | ||
| CVE-2026-50186 | 0 | 0.43% | 1 | 0 | N/A | ||
| CVE-2026-52872 | 0 | 0.14% | 1 | 0 | N/A | ||
| CVE-2026-53958 | 0 | 0.28% | 1 | 0 | N/A | ||
| CVE-2026-52877 | 0 | 0.30% | 1 | 0 | N/A | ||
| CVE-2026-75936 | 0 | 0.44% | 1 | 0 | N/A |
updated 2026-08-21T14:16:53.637000
2 posts
CVE-2026-77683: CRITICAL command injection in Comfast CF-N1-S (2.6.0.1) via /cgi-bin/mbox-config timestr parameter. Public exploit available, remote exploitation possible. Patch unavailable. https://radar.offseq.com/threat/cve-2026-77683-command-injection-in-comfast-cf-n1-s-c0a0594c5aac367d #OffSeq #CVE202677683 #IoTSecurity #CommandInjection
##CVE-2026-77683: CRITICAL command injection in Comfast CF-N1-S (2.6.0.1) via /cgi-bin/mbox-config timestr parameter. Public exploit available, remote exploitation possible. Patch unavailable. https://radar.offseq.com/threat/cve-2026-77683-command-injection-in-comfast-cf-n1-s-c0a0594c5aac367d #OffSeq #CVE202677683 #IoTSecurity #CommandInjection
##updated 2026-08-21T14:16:53.510000
1 posts
CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: https://radar.offseq.com/threat/cve-2026-77651-cwe-506-embedded-malicious-code-in-droundy-arrayref-c761153d40c2552d #OffSeq #RustLang #CVE2026 #Infosec
##updated 2026-08-21T14:05:53.253000
7 posts
1 repos
Zimbra Under Attack: Critical CVE-2026-73570 Turns Internet-Facing Mail Servers Into High-Value Targets + Video
A Warning That Arrived Just 28 Days After the Patch A newly confirmed exploitation campaign against Zimbra Collaboration Suite is raising the pressure on organizations that operate their own email infrastructure. Poland’s national computer emergency response team, CERT Polska, has confirmed that attackers are actively exploiting CVE-2026-73570, a critical…
##Critical Zimbra RCE Vulnerability Exploited in Global Attacks
Zimbra patched nine vulnerabilities in its Collaboration Suite, including a critical RCE flaw (CVE-2026-73570) that attackers are currently exploiting to take control of mail servers. Organizations should update to version 10.1.20 and check logs for signs of compromise.
**If you run Zimbra Collaboration Suite, update to version 10.1.20 ASAP. Attackers are already exploiting this to take over mail servers, and everything older is vulnerable. Because this flaw is being actively exploited, also check for signs of breach: look for unexpected files in `/opt/zimbra/jetty/webapps/` and `/tmp/`, and review `/var/log/zimbra.log` for services restarting on their own.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/critical-zimbra-rce-vulnerability-exploited-in-global-attacks-p-1-4-k-y/gD2P6Ple2L
Critical Zimbra RCE Vulnerability Exploited in Global Attacks
Zimbra patched nine vulnerabilities in its Collaboration Suite, including a critical RCE flaw (CVE-2026-73570) that attackers are currently exploiting to take control of mail servers. Organizations should update to version 10.1.20 and check logs for signs of compromise.
**If you run Zimbra Collaboration Suite, update to version 10.1.20 ASAP. Attackers are already exploiting this to take over mail servers, and everything older is vulnerable. Because this flaw is being actively exploited, also check for signs of breach: look for unexpected files in `/opt/zimbra/jetty/webapps/` and `/tmp/`, and review `/var/log/zimbra.log` for services restarting on their own.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/critical-zimbra-rce-vulnerability-exploited-in-global-attacks-p-1-4-k-y/gD2P6Ple2L
CVE-2026-73570 in Zimbra Collaboration Suite is under active exploitation. CERT Polska flagged real-world attacks this week. The flaw grants unauthenticated remote OS command execution when zimbra-snmp is installed with SNMP enabled. Attacker identity and campaign goals remain unknown — patch priority is critical for affected deployments.
#Zimbra #CVE202673570 #ThreatIntelligence #PatchNow
https://cyberworldops.eu/en/zimbra-cve-2026-73570-exploited-in-the-wild-who-needs-to-patch
##Active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite is underway. The command injection flaw enables unauthenticated RCE on ZCS versions prior to 10.1.20 when zimbra-snmp is installed with SNMP notifications active. Attackers exploit this via crafted SMTP requests for full server compromise. Patch or disable SNMP immediately.
#ZimbraRCE #CVE202673570 #PatchNow
https://cyberworldops.eu/en/zimbra-vulnerability-exploited-to-enable-unauthenticated-remote
##CRITICAL: CVE-2026-73570 in Zimbra Collaboration Suite is under active exploit. RCE via SNMP notifications lets unauth attackers run OS commands as Zimbra user. Patch to 10.1.20 now & monitor for abnormal files/restarts. Details: https://radar.offseq.com/threat/critical-zimbra-rce-flaw-now-actively-exploited-in-attacks-7db25eca9fa27ac1 #OffSeq #Zimbra #Vuln
##CVE-2026-73570 is exploited in the wild. This unauthenticated RCE hits Zimbra Collaboration via SNMP notifications. Patch to 10.1.20 now.
#Zimbra #CVE #RCE #RemoteCodeExecution #ExploitedInTheWild #InfoSec #PatchNow
https://securityonline.info/zimbra-cve-2026-73570/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-21T13:38:20.260000
1 posts
🟠 CVE-2026-73938 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73938/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T13:38:06.317000
1 posts
🟠 CVE-2026-73935 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T13:38:01.810000
1 posts
🟠 CVE-2026-73934 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73934/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T13:37:15.280000
1 posts
🟠 CVE-2026-73931 - High (8.3)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73931/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T13:37:11.433000
1 posts
🔴 CVE-2026-73930 - Critical (9.9)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73930/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T13:36:32.327000
1 posts
🟠 CVE-2026-73925 - High (8.2)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73925/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T13:18:19.727000
1 posts
CVE-2026-76158: Datiphy Data Management Center 8.3.0 faces CRITICAL vuln (CVSS 9.3) — upload API allows unauthenticated file writes anywhere via path traversal 🗂️. Restrict access & monitor uploads until patch. https://radar.offseq.com/threat/cve-2026-76158-cwe-73-external-control-of-file-name-or-path-in-datiphy-inc-data-management-center-6c6f4960c6201d48 #OffSeq #Vuln #Datiphy #CVE202676158
##updated 2026-08-21T12:28:35.090000
10 posts
1 repos
A maximum-severity CVSS 10.0 flaw in Microsoft Entra ID is under active exploitation, allowing remote code execution. Two CVEs are in play, CVE-2026-68820 and CVE-2026-69836, with activity attributed to the Lazarus Group.
##A critical deserialization vulnerability (CVE-2026-69836) has been actively exploited in Microsoft Entra ID. The flaw could allow unauthorized access to identity and access management functions across Azure, M365, and Dynamics CRM Online.
#CriticalVulnerability #MicrosoftEntra #IdentitySecurity #Deserialization
https://cyberworldops.eu/en/cve-2026-69836-critical-vulnerability-exploited-in-microsoft-entra-id
##Microsoft corrige falha crítica no Entra ID, uma vulnerabilidade que permitia a execução de código malicioso sem privilégios. A falha, classificada como CVE-2026-69836, já foi explorada em ataques informáticos. 🛡️
##Microsoft patches exploited Entra ID flaw amid rising attacks
Microsoft has patched a critical vulnerability in its Entra ID platform, known as CVE-2026-69836, which allowed attackers to execute code remotely with ease, and has already been exploited in recent attacks. This flaw enabled unauthorized threat actors to gain control and wreak havoc, making swift action crucial to prevent…
#MicrosoftEntraId #IdentityManagement #Cve202669836 #ZeroDay #EmergingThreats
##🔴 New security advisory:
CVE-2026-69836 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-69836-entra-id-unauthenticated-rce
by Yazoul AI
##Microsoft Entra ID Faces a Critical CVSS 100 Exploit Claim — Why This Cloud Identity Warning Is So Serious + Video
A Cloud Identity Warning That Deserves Attention Microsoft has warned of a maximum-severity security vulnerability allegedly affecting Microsoft Entra ID, the cloud identity and access management platform formerly known as Azure Active Directory. According to the information provided in the original report, the flaw is tracked as CVE-2026-69836 and carries…
##A critical deserialization vulnerability (CVE-2026-69836) has been actively exploited in Microsoft Entra ID. The flaw could allow unauthorized access to identity and access management functions across Azure, M365, and Dynamics CRM Online.
#CriticalVulnerability #MicrosoftEntra #IdentitySecurity #Deserialization
https://cyberworldops.eu/en/cve-2026-69836-critical-vulnerability-exploited-in-microsoft-entra-id
##Microsoft corrige falha crítica no Entra ID, uma vulnerabilidade que permitia a execução de código malicioso sem privilégios. A falha, classificada como CVE-2026-69836, já foi explorada em ataques informáticos. 🛡️
##「Microsoft Entra IDの脆弱性(CVSS 10.0)が実際に悪用され、リモートコード実行が可能になる 」: #TheHackerNews
「マイクロソフトは木曜日、Entra IDに重大なセキュリティ上の欠陥があり、既に悪用されていると警告したが、顧客による対応は不要であると述べた。
CVE-2026-69836 (CVSSスコア:10.0)として追跡されているこの脆弱性は、 リモートコード実行によって、このテクノロジー大手企業のクラウドベースのIDおよびアクセス管理サービスに影響を与える事例です。このサービスは以前はAzure Active DirectoryまたはAzure ADと呼ばれていました。
マイクロソフトは木曜日に発表した警告の中で、 「Microsoft Entra IDにおける信頼できないデータの逆シリアル化により、権限のない攻撃者がネットワーク上でコードを実行できる可能性がある」 と述べた。 」
https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html
##CVE-2026-69836, a CVSS 10 Entra ID remote code execution flaw, was exploited in the wild. Microsoft has fully mitigated it server-side.
#CVE202669836 #EntraID #RemoteCodeExecution #Microsoft #CloudSecurity #RCE
##updated 2026-08-21T12:16:36.967000
4 posts
🔴 CVE-2026-77776 - Critical (9.1)
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77776/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: CVE-2026-77776 in Headroom Labs Headroom (<0.36.1) allows unauth'd attackers to spoof x-headroom-user-id and access/modify any user's LLM memory. Default configs expose this via 0.0.0.0 binding. Restrict access & use auth tokens. https://radar.offseq.com/threat/cve-2026-77776-authorization-bypass-through-user-controlled-key-in-headroom-labs-headroom-0c2eff15c1a3dc1f #OffSeq #CVE #infosec #LLM
##🔴 CVE-2026-77776 - Critical (9.1)
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77776/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: CVE-2026-77776 in Headroom Labs Headroom (<0.36.1) allows unauth'd attackers to spoof x-headroom-user-id and access/modify any user's LLM memory. Default configs expose this via 0.0.0.0 binding. Restrict access & use auth tokens. https://radar.offseq.com/threat/cve-2026-77776-authorization-bypass-through-user-controlled-key-in-headroom-labs-headroom-0c2eff15c1a3dc1f #OffSeq #CVE #infosec #LLM
##updated 2026-08-21T12:16:36.813000
2 posts
🟠 CVE-2026-77775 - High (8.6)
Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77775/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77775 - High (8.6)
Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77775/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T12:16:30.013000
2 posts
🟠 CVE-2026-59279 - High (7.5)
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59279/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-59279 - High (7.5)
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59279/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T09:32:04
2 posts
CVE-2026-18781: CRITICAL code injection in Drag and Drop Multiple File Upload for Contact Form 7 <1.3.9.9. Unauthenticated users can run code on affected WordPress servers. No patch yet — restrict or disable plugin. https://radar.offseq.com/threat/cve-2026-18781-cwe-94-improper-control-of-generation-of-code-code-injection-in-drag-and-drop-multiple-23e69d42b3732263 #OffSeq #WordPress #Infosec #CVE202618781
##CVE-2026-18781: CRITICAL code injection in Drag and Drop Multiple File Upload for Contact Form 7 <1.3.9.9. Unauthenticated users can run code on affected WordPress servers. No patch yet — restrict or disable plugin. https://radar.offseq.com/threat/cve-2026-18781-cwe-94-improper-control-of-generation-of-code-code-injection-in-drag-and-drop-multiple-23e69d42b3732263 #OffSeq #WordPress #Infosec #CVE202618781
##updated 2026-08-21T04:18:20.733000
1 posts
Splunk patches three critical embedded report flaws (CVE-2026-76310, CVSS 9.4) that let unauthenticated users affect system integrity.
#Splunk #CVE #AccessControl #SplunkEnterprise #Vulnerability #InfoSec #PatchNow
##updated 2026-08-21T04:18:19.900000
1 posts
🟠 CVE-2026-75144 - High (7.8)
FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75144/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T04:18:19.753000
1 posts
🔴 CVE-2026-75143 - Critical (9.8)
FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, ove...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75143/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T04:18:15.903000
5 posts
CISA confirms two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, are exploited in the wild to deliver PhantomCore malware. Patch now.
#TrueConf #CVE #ExploitedInTheWild #PhantomCore #HeadMare #InfoSec #PatchNow
##CISA has added two known vulnerabilities to the KEV catalogue.
- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72529
- CVE-2026-72530: TrueConf Server Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72530 #CISA
Yesterday:
Cisco:
CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP @TalosSecurity #Cisco #infosec #vulnerability
##🚨 [CISA-2026:0820] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-72529 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72529)
- Name: TrueConf Server Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TrueConf
- Product: Server
- Notes: https://trueconf.com/blog/news/security-fixes-updates-and-advisories ; https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-72529
⚠️ CVE-2026-72530 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72530)
- Name: TrueConf Server Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TrueConf
- Product: Server
- Notes: https://trueconf.com/blog/news/security-fixes-updates-and-advisories ; https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-breakout-from-isolated-environment/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-72530
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260820 #cisa20260820 #cve_2026_72529 #cve_2026_72530 #cve202672529 #cve202672530
##CVE ID: CVE-2026-72530
Vendor: TrueConf
Product: Server
Date Added: 2026-08-20
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72530
🔴 CVE-2026-72530 - Critical (9)
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and exec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72530/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T04:18:15.753000
4 posts
CISA confirms two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, are exploited in the wild to deliver PhantomCore malware. Patch now.
#TrueConf #CVE #ExploitedInTheWild #PhantomCore #HeadMare #InfoSec #PatchNow
##CISA has added two known vulnerabilities to the KEV catalogue.
- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72529
- CVE-2026-72530: TrueConf Server Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72530 #CISA
Yesterday:
Cisco:
CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP @TalosSecurity #Cisco #infosec #vulnerability
##🚨 [CISA-2026:0820] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-72529 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72529)
- Name: TrueConf Server Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TrueConf
- Product: Server
- Notes: https://trueconf.com/blog/news/security-fixes-updates-and-advisories ; https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-72529
⚠️ CVE-2026-72530 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-72530)
- Name: TrueConf Server Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TrueConf
- Product: Server
- Notes: https://trueconf.com/blog/news/security-fixes-updates-and-advisories ; https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-breakout-from-isolated-environment/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-72530
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260820 #cisa20260820 #cve_2026_72529 #cve_2026_72530 #cve202672529 #cve202672530
##CVE ID: CVE-2026-72529
Vendor: TrueConf
Product: Server
Date Added: 2026-08-20
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72529
updated 2026-08-21T04:18:02.220000
1 posts
CVE-2026-19586 (CVSS 9.3) is a pre-authentication OS command injection flaw in Omada gateways. TP-Link has released fixed firmware.
#Omada #TPLink #CVE202619586 #CommandInjection #OpenVPN #NetworkSecurity
##updated 2026-08-21T03:31:29
1 posts
Datiphy Data Management Center 8.3.0 hit by CRITICAL vuln (CVE-2026-76155) due to default admin creds. Remote attackers can gain full access. No patch yet — change credentials & limit access ASAP. https://radar.offseq.com/threat/cve-2026-76155-cwe-1392-use-of-default-credentials-in-datiphy-inc-data-management-center-6739f6ae6f5ecf78 #OffSeq #CVE #Vuln #Datiphy
##updated 2026-08-21T03:31:29
1 posts
CVE-2026-76156: CRITICAL OS command injection in Datiphy Data Management Center (8.3.0 – 8.5.1). Authenticated admins can run root OS commands via API. No patch yet — restrict admin access, monitor activity. https://radar.offseq.com/threat/cve-2026-76156-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-af474791202edb0c #OffSeq #CVE202676156 #Vuln #Infosec
##updated 2026-08-21T00:31:31
2 posts
CVE-2026-77647, a CVSS 9.8 unauthenticated RCE in SPIP before 4.4.20, is exploited in the wild. Update now.
#SPIP #CVE202677647 #RCE #ExploitedInTheWild #CMS #WebSecurity
https://securityonline.info/cve-2026-77647-spip-rce/?utm_source=mastodon&utm_medium=jetpack_social
##🔴 CVE-2026-77647 - Critical (9.8)
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77647/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T00:31:31
1 posts
CRITICAL RCE flaw (CVE-2026-77645) in PTC Windchill PDMLink (multiple versions). Unauthenticated attackers can execute remote code via insecure deserialization. No patch yet — restrict access & monitor closely. https://radar.offseq.com/threat/cve-2026-77645-cwe-20-improper-input-validation-in-ptc-windchill-pdmlink-d801e9b56795a3c8 #OffSeq #Vulnerability #PTC #Infosec
##updated 2026-08-21T00:31:31
1 posts
🟠 CVE-2026-69855 - High (7.7)
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T00:31:31
1 posts
🟠 CVE-2026-72860 - High (8.5)
The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares hostname strin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72860/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T00:31:31
1 posts
🟠 CVE-2026-72848 - High (8.6)
SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72848/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T00:31:31
1 posts
🟠 CVE-2026-72818 - High (7.5)
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisti...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72818/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T00:31:31
1 posts
🟠 CVE-2026-77642 - High (7.5)
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-20...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77642/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-21T00:31:24
1 posts
🔴 CVE-2026-72843 - Critical (9.8)
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72843/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T23:16:28.200000
1 posts
Three critical Red Hat ACM/MCE flaws, led by CVE-2026-66792 (CVSS 9.9), allow full compromise of the managed cluster.
#CVE202666792 #RedHat #Kubernetes #PrivilegeEscalation #ACM #ClusterAdmin
##updated 2026-08-20T21:31:37
1 posts
🟠 CVE-2026-73040 - High (8.8)
Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.server.stacksD...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73040/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T21:31:36
3 posts
Three Red Hat flaws enable privilege escalation, led by CVE-2026-67567 (CVSS 9.9) in ACM. Two FreeIPA bugs can reach full domain compromise.
#RedHat #CVE202667567 #PrivilegeEscalation #FreeIPA #Kubernetes #ACM
##Three Red Hat flaws enable privilege escalation, led by CVE-2026-67567 (CVSS 9.9) in ACM. Two FreeIPA bugs can reach full domain compromise.
#RedHat #CVE202667567 #PrivilegeEscalation #FreeIPA #Kubernetes #ACM
##🔴 CVE-2026-67567 - Critical (9.9)
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller pr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67567/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T21:31:36
1 posts
🟠 CVE-2026-18420 - High (8.8)
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. Th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18420/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T21:31:36
1 posts
🟠 CVE-2026-72852 - High (7.8)
hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In src-lib/convolutional_layer.cpp, l.nweights is computed as (c / groups) ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72852/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T21:31:36
1 posts
🔴 CVE-2026-77148 - Critical (9.9)
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77148/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T21:31:30
1 posts
🟠 CVE-2026-73137 - High (7.7)
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73137/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T21:31:30
1 posts
🟠 CVE-2026-77638 - High (8.9)
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77638/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T21:17:09.800000
1 posts
Google patches CVE-2026-76017, a critical use-after-free in Chrome, among 7 security fixes. Update to 151.0.7922.173 or later now.
#Chrome #CVE #UseAfterFree #Google #BrowserSecurity #InfoSec #PatchNow
https://securityonline.info/chrome-cve-2026-76017/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-20T20:17:46.470000
1 posts
🔴 CVE-2026-73257 - Critical (9.1)
Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_htt...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73257/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T19:17:04.430000
1 posts
🟠 CVE-2026-76641 - High (7.5)
Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76641/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T19:16:58.463000
2 posts
CVE-2026-66785 - Critical network redirection flaw in Submariner. Malicious clusters can hijack peer traffic via crafted endpoints. CVSS 9.9. No patch yet - isolate clusters, monitor traffic. #CVE #Submariner #infosec
##🔴 CVE-2026-66785 - Critical (9.9)
A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly valida...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66785/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T19:16:50.880000
1 posts
Stack-based buffer overflow (CVE-2026-16885) in IBM AIX 7.2, 7.3 & PowerVM VIOS 4.1 (CRITICAL, CVSS 9.8). Remote, unauthenticated code execution possible. No patch yet — monitor IBM advisories. https://radar.offseq.com/threat/cve-2026-16885-cwe-121-stack-based-buffer-overflow-in-ibm-aix-4d84d05fa38f4cbc #OffSeq #IBM #AIX #Vuln
##updated 2026-08-20T18:31:06
1 posts
🔴 CVE-2026-77022 - Critical (9.9)
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component SSID Configuration. The manipulation of the argument ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77022/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T18:30:58
1 posts
🟠 CVE-2026-75140 - High (7.5)
jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75140/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T18:16:46.523000
1 posts
🔴 CVE-2026-73256 - Critical (9.1)
Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73256/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T17:19:48.260000
1 posts
🟠 CVE-2026-76928 - High (7.5)
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76928/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T17:19:24.533000
1 posts
CVE-2026-66582 - Unauthenticated XSS in TranslatePress ≤3.3.2. CVSS 7.1. No patch yet. Disable or restrict access now. #CVE #WordPress #infosec
##updated 2026-08-20T17:19:14.390000
1 posts
An Apache InLong SQL injection flaw, CVE-2026-63038, lets attackers inject SQL via multiple parameters. Two more bugs join it. Upgrade to 2.4.0.
##updated 2026-08-20T17:17:25.647000
1 posts
CVE-2026-18290 - RCE in OriginLab OriginPro via OGG parsing. Out-of-bounds write leads to arbitrary code execution. CVSS 7.8. No patch yet; avoid opening untrusted OGG files. #CVE #OriginPro #infosec
##updated 2026-08-20T16:18:22.187000
1 posts
🟠 CVE-2026-76880 - High (7.5)
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76880/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T16:18:21.780000
1 posts
🟠 CVE-2026-76879 - High (7.5)
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76879/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T16:18:19.223000
1 posts
🟠 CVE-2026-76633 - High (8.1)
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76633/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T16:18:13.520000
1 posts
🟠 CVE-2026-76397 - High (8.1)
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolki...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76397/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T16:17:52.367000
1 posts
🟠 CVE-2026-71961 - High (8.8)
Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command inte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71961/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T16:17:19.950000
1 posts
🟠 CVE-2026-19942 - High (8.1)
The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the AVCF_Abilities_Media::register (repla...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19942/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T16:17:07.463000
1 posts
#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities
Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953
https://certvde.com/en/advisories/vde-2026-078/
#CSAF https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-078.json
##updated 2026-08-20T16:17:07.210000
3 posts
Frauscher FDS102 vulnerabilities include CVE-2026-14950 (CVSS 9.8), a session flaw enabling unauthorized continued access. Update to v2.14.0.
##Frauscher FDS 102 v2.1.0 hit by CRITICAL vuln (CVE-2026-14950): insufficient session expiration lets remote attackers keep using stolen session tokens. No patch yet — monitor sessions, restrict access. https://radar.offseq.com/threat/cve-2026-14950-cwe-613-insufficient-session-expiration-in-frauscher-sensortechnik-fds-102-0a0f578bbcdd7c33 #OffSeq #ICS #CVE202614950 #Security
###OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities
Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953
https://certvde.com/en/advisories/vde-2026-078/
#CSAF https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-078.json
##updated 2026-08-20T16:17:07.080000
1 posts
#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities
Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953
https://certvde.com/en/advisories/vde-2026-078/
#CSAF https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-078.json
##updated 2026-08-20T15:34:26
1 posts
🟠 CVE-2026-76833 - High (7.8)
@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76833/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T15:34:14
1 posts
🟠 CVE-2026-76886 - High (8.1)
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76886/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T15:18:38.097000
1 posts
🟠 CVE-2026-75146 - High (8.1)
FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negativ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75146/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T15:17:38.740000
1 posts
🟠 CVE-2026-61897 - High (7.8)
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61897/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T15:17:29.713000
1 posts
CVE-2026-28164: CRITICAL CSRF in HashThemes Easy Elementor Addons ≤2.3.7. Remote attackers can exploit this for full user compromise. No patch yet — track vendor advisories. CVSS 9.6. https://radar.offseq.com/threat/cve-2026-28164-cwe-352-cross-site-request-forgery-csrf-in-hashthemes-easy-elementor-addons-7bfb9b1be22a1e31 #OffSeq #WordPress #CSRF #CVE2026_28164
##updated 2026-08-20T14:17:58.883000
1 posts
🟠 CVE-2026-75569 - High (7.7)
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75569/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T14:17:10.673000
4 posts
「Citrixは、NetScalerの新たな脆弱性をできるだけ早く修正するよう管理者に強く求めている。」: #BLEEPINGCOMPUTER
「Citrixは、NetScaler GatewayセキュアリモートアクセスソリューションとNetScaler ADCネットワークアプライアンスに影響を与える2つの脆弱性からシステムを保護するため、顧客に対し直ちにセキュリティ対策を講じるよう警告した。
2つのうちより深刻な脆弱性( CVE-2026-19490 として追跡)では、NetScalerのファームウェアバージョンとSAMLアクションが構成されているかどうかに応じて、アプライアンスがAAA仮想サーバーまたはゲートウェイ(SSL VPN、ICAプロキシ、CVPN、RDPプロキシ)として構成されている場合に、権限を持たないリモート攻撃者が認証をバイパスできる可能性があります。 」
##「Citrixは、NetScalerの新たな脆弱性をできるだけ早く修正するよう管理者に強く求めている。」: #BLEEPINGCOMPUTER
「Citrixは、NetScaler GatewayセキュアリモートアクセスソリューションとNetScaler ADCネットワークアプライアンスに影響を与える2つの脆弱性からシステムを保護するため、顧客に対し直ちにセキュリティ対策を講じるよう警告した。
2つのうちより深刻な脆弱性( CVE-2026-19490 として追跡)では、NetScalerのファームウェアバージョンとSAMLアクションが構成されているかどうかに応じて、アプライアンスがAAA仮想サーバーまたはゲートウェイ(SSL VPN、ICAプロキシ、CVPN、RDPプロキシ)として構成されている場合に、権限を持たないリモート攻撃者が認証をバイパスできる可能性があります。 」
##Citrix has released patches for CVE-2026-19490, a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway. An unauthenticated remote attacker can exploit the flaw via an alternative path to bypass authentication on appliances configured as SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA servers.
#CitrixBleb #NetScalerVuln #CVSS9 #RemoteAccessSecurity
https://cyberworldops.eu/en/netscaler-critical-authentication-bypass-citrix-urges-immediate
##CVE-2026-19490 (CVSS 9.3) is a critical NetScaler authentication bypass in NetScaler Gateway and ADC. Patch now to block unauthenticated access.
##updated 2026-08-20T14:17:10.413000
5 posts
1 repos
Keycloak Unauthenticated Account Takeover
벨기에 사이버보안센터(CCB)는 Red Hat build of Keycloak 26.4 및 26.6의 자격 증명 재설정 흐름에서 원격 비인증 계정 탈취가 가능한 CVE-2026-18963을 경고했다. CVSS 9.1의 CWE-640 취약점으로, 공격자는 비밀번호 재설정 이메일의 검증 링크를 클릭하지 않고도 임의 사용자의 재설정을 강제하고 새 자격 증명을 설정할 수 있다. Keycloak이 SSO·인증·권한 부여의 중심에 배치되는 경우 영향 범위가 해당 계정에 연결된 다수의 AI 서비스, 에이전트,...
##A Keycloak account takeover flaw, CVE-2026-18963, lets attackers reset any user's password with no email verification. Update to 26.7.2 now.
##A Keycloak account takeover flaw, CVE-2026-18963, lets attackers reset any user's password with no email verification. Update to 26.7.2 now.
##Guten Morgen an @univention Kund*innen, die unsere #Keycloak App einsetzen! Wir werden demnächst Version 26.7.2 herausbringen. Von dem Account-Takeover-CVE ist unsere App nicht betroffen.
Details findet Ihr hier: https://help.univention.com/t/keycloak-26-7-2-and-cve-2026-18963-potential-account-takeover-nubus-not-affected/25494
##PSA: Critical unauthenticated account takeover vulnerability in #Keycloak - allows resetting arbitrary users‘ passwords. Update to 26.7.2 immediately or disable password reset. Tracked as CVE-2026-18963. https://github.com/keycloak/keycloak/issues/51833
##updated 2026-08-20T13:08:53.900000
1 posts
A critical Red Hat vulnerability, CVE-2026-66780 (CVSS 9.9), enables a MITM attack across a cluster mesh. Two more critical flaws also disclosed.
##updated 2026-08-20T13:08:53.900000
1 posts
🔴 CVE-2026-13097 - Critical (9.1)
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13097/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T13:08:53.900000
1 posts
🟠 CVE-2026-73197 - High (7.5)
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73197/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T13:01:19.947000
1 posts
Cisco patches a Crosswork SQL injection flaw, CVE-2026-20030, rated CVSS 10.0. A BroadWorks XXE bug (CVE-2026-20320) also gets a fix.
#Cisco #CVE #SQLInjection #Crosswork #BroadWorks #XXE #Vulnerability #InfoSec
##updated 2026-08-20T13:01:19.947000
1 posts
🟠 CVE-2026-75935 - High (7.5)
Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T12:48:31.843000
10 posts
📢 [VULN] WordPress : cette faille Elementor Pro ouvre votre site aux pirates CVE-2026-32475
Nouvelle alerte à destination de tous les administrateurs de sites WordPress : la faille CVE-2026-32475, corrigée le 19 août 2026 dans Elementor Pro, permet à un visiteur anonyme de déposer un fichier PHP sur un site WordPress, puis de l'exécuter. Aucun compte, aucune interaction avec un administrateur.
🔗 https://www.it-connect.fr/elementor-pro-cve-2026-32475-rce-non-authentifiee/
💬 discussion : https://infosec.pub/post/51237084
#CVE #Cyberveille
Elementor Pro : une faille critique permet de prendre le contrôle d’un site WordPress https://www.it-connect.fr/elementor-pro-cve-2026-32475-rce-non-authentifiee/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Wordpress
##CVE-2026-32475 (CVSS 9.8) is an unauthenticated file upload flaw in Elementor Pro. It threatens complete site compromise across 6 million sites.
#ElementorPro #CVE202632475 #WordPress #RCE #FileUpload #WebSecurity
##「Elementor Proの重大なバグにより、WordPressサイトがリモートコード実行攻撃に晒される 」: #BLEEPINGCOMPUTER
「WordPressプラグイン「Elementor Pro」に存在する重大な脆弱性により、攻撃者が実行可能ファイルをアップロードして、サーバー上でリモートコードを実行できる可能性がある。
CVE-2026-32475として識別されたこの脆弱性は、Elementor Proのバージョン4.2.2より前のバージョンに影響し、ファイル検証と処理に別々のループを使用するファイルアップロードモジュールに起因しており、ファイル名が空のアップロードの処理方法が異なっています。」
##📢 [VULN] WordPress : cette faille Elementor Pro ouvre votre site aux pirates CVE-2026-32475
Nouvelle alerte à destination de tous les administrateurs de sites WordPress : la faille CVE-2026-32475, corrigée le 19 août 2026 dans Elementor Pro, permet à un visiteur anonyme de déposer un fichier PHP sur un site WordPress, puis de l'exécuter. Aucun compte, aucune interaction avec un administrateur.
🔗 https://www.it-connect.fr/elementor-pro-cve-2026-32475-rce-non-authentifiee/
💬 discussion : https://infosec.pub/post/51237084
#CVE #Cyberveille
Elementor Pro : une faille critique permet de prendre le contrôle d’un site WordPress https://www.it-connect.fr/elementor-pro-cve-2026-32475-rce-non-authentifiee/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Wordpress
##CVE-2026-32475 (CVSS 9.8) is an unauthenticated file upload flaw in Elementor Pro. It threatens complete site compromise across 6 million sites.
#ElementorPro #CVE202632475 #WordPress #RCE #FileUpload #WebSecurity
##「Elementor Proの重大なバグにより、WordPressサイトがリモートコード実行攻撃に晒される 」: #BLEEPINGCOMPUTER
「WordPressプラグイン「Elementor Pro」に存在する重大な脆弱性により、攻撃者が実行可能ファイルをアップロードして、サーバー上でリモートコードを実行できる可能性がある。
CVE-2026-32475として識別されたこの脆弱性は、Elementor Proのバージョン4.2.2より前のバージョンに影響し、ファイル検証と処理に別々のループを使用するファイルアップロードモジュールに起因しており、ファイル名が空のアップロードの処理方法が異なっています。」
##A critical flaw in Elementor Pro (CVE-2026-32475) enables unauthenticated remote code execution via the File Upload module. Two desynchronized processing loops mishandle empty filenames, bypassing validation entirely. All versions below 4.2.2 are affected. Patch immediately and audit server logs for indicators of exploitation.
#ElementorPro #WordPress #RemoteCodeExecution #CVE202632475
https://cyberworldops.eu/en/elementor-pro-critical-vulnerability-in-forms-file-upload-could-lead
##WordPress admins running Elementor Pro:
CVSS 9.8 - CVE-2026-32475
WordPress Elementor Pro Plugin <= 4.2.1 is vulnerable to a high priority Arbitrary File Upload
https://patchstack.com/articles/critical-unauthenticated-file-upload-to-rce-in-elementor-pro-plugin/
##updated 2026-08-20T12:48:10.287000
2 posts
3 repos
https://github.com/yora1928/cve-2026-15748
Unauthenticated RCE Vulnerability Patched in Forminator Forms Plugin
WPMU DEV patched a critical vulnerability (CVE-2026-15748) in the Forminator Forms plugin that allowed unauthenticated attackers to upload and execute PHP files. The flaw can lead to full remote code execution and site compromise.
**If you use the Forminator Forms plugin on your WordPress site, update it to version 1.56.2 or later ASAP away: attackers can take over the whole site without logging in. After updating, check your upload folders for any unfamiliar PHP files. If you can't update yet, delete any forms that use both File Upload and Select fields.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/unauthenticated-rce-vulnerability-patched-in-forminator-forms-plugin-q-r-9-h-5/gD2P6Ple2L
CVE-2026-15748, scored 9.8 out of 10, allows unauthenticated attackers to manipulate Select field configurations and bypass the plugin's blocklist entirely, uploading executable files through handle_file_upload. Defiant confirms this is several weaknesses working together in a kind of tragic team-building exercise.
Remote code execution is not a learning objective we endorse. Please update Forminator Forms to version 1.56.2 or later immediately. (2/3)
##updated 2026-08-20T12:48:10.287000
2 posts
🔴 CVE-2026-76008 - Critical (10)
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76008/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Comfast CF-N1-S v2.6.0.1 hit by CRITICAL CVE-2026-76008: stack-based buffer overflow in /cgi-bin/mbox-config (get_para_from_uri). Remote exploitation risk; mitigation unavailable. Monitor for patches. #OffSeq #CVE202676008 #IoTSecurity https://radar.offseq.com/threat/cve-2026-76008-stack-based-buffer-overflow-in-comfast-cf-n1-s-3ceda49f6d8d37d6
##updated 2026-08-20T12:31:29
1 posts
🟠 CVE-2026-73198 - High (7.5)
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memor...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73198/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T12:31:22
1 posts
CVE-2026-75860: CRITICAL privilege escalation in JSON Options ≤0.0.4. Unauthenticated attackers can update WordPress options & gain admin access. Remove or disable plugin until fix is available. Full site takeover risk. https://radar.offseq.com/threat/cve-2026-75860-cwe-269-improper-privilege-management-in-json-options-5e170a19118b89b1 #OffSeq #WordPress #CVE202675860
##updated 2026-08-20T09:31:23
1 posts
#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities
Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953
https://certvde.com/en/advisories/vde-2026-078/
#CSAF https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-078.json
##updated 2026-08-20T09:31:23
1 posts
#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities
Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953
https://certvde.com/en/advisories/vde-2026-078/
#CSAF https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-078.json
##updated 2026-08-20T09:31:23
1 posts
#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities
Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953
https://certvde.com/en/advisories/vde-2026-078/
#CSAF https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-078.json
##updated 2026-08-20T09:31:23
1 posts
#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities
Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953
https://certvde.com/en/advisories/vde-2026-078/
#CSAF https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-078.json
##updated 2026-08-20T09:16:45.813000
1 posts
#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities
Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953
https://certvde.com/en/advisories/vde-2026-078/
#CSAF https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-078.json
##updated 2026-08-20T00:35:17
2 posts
TRENDnet TEW-755AP is affected by CVE-2026-76589 (CRITICAL, CVSS 9.4): stack-based buffer overflow in /sbin/mycli, exploitable remotely. Public exploit; no patch yet. Restrict device access and monitor. https://radar.offseq.com/threat/cve-2026-76589-stack-based-buffer-overflow-in-trendnet-tew-755ap-b22775c9ba4ec937 #OffSeq #CVE202676589 #IoTSecurity
##🔴 CVE-2026-76589 - Critical (9.9)
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76589/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T00:35:17
2 posts
CVE-2026-76850 (CRITICAL): InternLM lmdeploy <0.16.0 vulnerable to remote code execution via untrusted pickle deserialization on ZeroMQ endpoints. Enable API keys or disable disaggregated serving to mitigate. https://radar.offseq.com/threat/cve-2026-76850-deserialization-of-untrusted-data-in-internlm-lmdeploy-657fdd1d6177df51 #OffSeq #Infosec #Vuln #CVE202676850
##🔴 CVE-2026-76850 - Critical (9.8)
LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes wit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76850/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T00:35:16
2 posts
CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. https://radar.offseq.com/threat/cve-2026-76590-stack-based-buffer-overflow-in-trendnet-tew-755ap-37978d53e46251c0 #OffSeq #Vuln #IoTSec #CVE2026
##🔴 CVE-2026-76590 - Critical (9.9)
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76590/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T00:35:16
1 posts
🟠 CVE-2026-76832 - High (8.8)
Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to rea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76832/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T00:35:11
1 posts
🟠 CVE-2026-76399 - High (8.1)
In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76399/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T00:35:11
1 posts
🟠 CVE-2026-76396 - High (7.5)
In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76396/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T00:35:11
1 posts
🟠 CVE-2026-76395 - High (8.8)
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76395/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-20T00:35:08
3 posts
Splunk patches CVE-2026-76404, a critical remote code execution flaw in the MCP Server app, plus 16 more bugs across its apps and add-ons.
#Splunk #CVE #RemoteCodeExecution #RCE #MCPServer #Deserialization #InfoSec #PatchNow
##Splunk MCP Server app v1.2 is impacted by CVE-2026-76404 (CRITICAL, CVSS 9.1) — insecure deserialization lets admin users run arbitrary OS commands. Limit admin access & monitor for misuse until a patch is released. https://radar.offseq.com/threat/cve-2026-76404-the-application-deserializes-untrusted-data-without-sufficiently-verifying-that-the-a0d42d963a9e6a80 #OffSeq #Splunk #Infosec #CVE202676404
##🔴 CVE-2026-76404 - Critical (9.1)
In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76404/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T21:31:33
1 posts
CISA has added two known vulnerabilities to the KEV catalogue.
- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72529
- CVE-2026-72530: TrueConf Server Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72530 #CISA
Yesterday:
Cisco:
CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-08-19T21:30:46
1 posts
🟠 CVE-2026-76139 - High (8)
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub acces...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76139/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T21:30:40
1 posts
🔴 CVE-2026-76584 - Critical (9.9)
A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation of the argument Currenttime results in st...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76584/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T21:30:39
2 posts
Red Hat ACM privilege escalation flaws (CVE-2026-70496, CVSS 9.9) let attackers seize full cluster control. See the three Kubernetes bugs.
#RedHat #Kubernetes #PrivilegeEscalation #CVE #ACM #CloudSecurity #InfoSec
##🔴 CVE-2026-70496 - Critical (9.9)
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70496/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T21:30:32
1 posts
🟠 CVE-2026-18848 - High (8.3)
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18848/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T21:30:29
4 posts
「Ciscoのバグの深刻度警告は、オリンピック体操競技の得点のように、10、10、9.9、9.6、7.5と表示されます。
/Secure Workload Softwareには5つの重大な欠陥があり、SaaSユーザーでさえアップデートをインストールする必要がある。 」: #TheRegister
「シスコは、ネットワーク内での攻撃者の横方向への移動を阻止することを目的としたマイクロセグメンテーションツールであるセキュアワークロードソフトウェア(旧称Tetration)に、4つの重大な欠陥と、さらに1つの深刻なバグが存在することを明らかにした。
CVE-2026-20315とCVE-2026-20317は、最高評価の10点満点バグです。どちらも不適切なアクセス制御に関連しています。 」
##「Ciscoのバグの深刻度警告は、オリンピック体操競技の得点のように、10、10、9.9、9.6、7.5と表示されます。
/Secure Workload Softwareには5つの重大な欠陥があり、SaaSユーザーでさえアップデートをインストールする必要がある。 」: #TheRegister
「シスコは、ネットワーク内での攻撃者の横方向への移動を阻止することを目的としたマイクロセグメンテーションツールであるセキュアワークロードソフトウェア(旧称Tetration)に、4つの重大な欠陥と、さらに1つの深刻なバグが存在することを明らかにした。
CVE-2026-20315とCVE-2026-20317は、最高評価の10点満点バグです。どちらも不適切なアクセス制御に関連しています。 」
##CISA has added two known vulnerabilities to the KEV catalogue.
- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72529
- CVE-2026-72530: TrueConf Server Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72530 #CISA
Yesterday:
Cisco:
CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP @TalosSecurity #Cisco #infosec #vulnerability
##Cisco patches Secure Workload flaws CVE-2026-20315 and CVE-2026-20317, an authentication bypass and privilege escalation pair scoring CVSS 10. Upgrade now.
#Cisco #CVE #AuthenticationBypass #PrivilegeEscalation #Vulnerability #InfoSec #PatchNow
##updated 2026-08-19T21:30:29
2 posts
CISA has added two known vulnerabilities to the KEV catalogue.
- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72529
- CVE-2026-72530: TrueConf Server Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-72530 #CISA
Yesterday:
Cisco:
CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP @TalosSecurity #Cisco #infosec #vulnerability
##Cisco patches Secure Workload flaws CVE-2026-20315 and CVE-2026-20317, an authentication bypass and privilege escalation pair scoring CVSS 10. Upgrade now.
#Cisco #CVE #AuthenticationBypass #PrivilegeEscalation #Vulnerability #InfoSec #PatchNow
##updated 2026-08-19T20:17:21.567000
1 posts
🟠 CVE-2026-68899 - High (8.7)
Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based MIME detection, but detectMimeFromFile() silently returned undefined when that binary was unavaila...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68899/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T20:17:21.400000
1 posts
🟠 CVE-2026-68561 - High (8.8)
Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in server/lib/utils.js, which authorized any board member whenever fieldNames included...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68561/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T19:17:19.073000
1 posts
🟠 CVE-2026-52876 - High (8.8)
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52876/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T19:17:18.057000
1 posts
1 repos
🟠 CVE-2026-50142 - High (7.5)
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequences/seq_bo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50142/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T18:32:57
1 posts
🟠 CVE-2026-61518 - High (8.8)
ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query bind...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61518/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T18:32:57
1 posts
🔴 CVE-2026-66794 - Critical (9.3)
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manip...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66794/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T18:32:57
1 posts
🟠 CVE-2026-75142 - High (7.8)
FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75142/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T18:32:57
1 posts
🟠 CVE-2026-75141 - High (7.8)
FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap bu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75141/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T18:32:51
1 posts
Cisco patches a Crosswork SQL injection flaw, CVE-2026-20030, rated CVSS 10.0. A BroadWorks XXE bug (CVE-2026-20320) also gets a fix.
#Cisco #CVE #SQLInjection #Crosswork #BroadWorks #XXE #Vulnerability #InfoSec
##updated 2026-08-19T18:32:44
1 posts
CVE-2026-18051 (CVSS 10) is an unauthenticated arbitrary file write in W3 Total Cache, exposing 900k+ WordPress sites. Update to 2.10.5 now.
#W3TotalCache #WordPress #CVE202618051 #PathTraversal #InfoSec
##updated 2026-08-19T18:32:34
1 posts
An Oracle WebLogic vulnerability, CVE-2026-60702 (CVSS 9.9), allows full server takeover. Oracle patched nine flaws, five rated critical. Update now.
#OracleWebLogic #CVE202660702 #RCE #FusionMiddleware #ServerTakeover #InfoSec
##updated 2026-08-19T18:17:26.080000
1 posts
🟠 CVE-2026-75149 - High (8.8)
marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75149/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T15:33:23
1 posts
🔴 CVE-2026-73924 - Critical (9.1)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73924/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T15:33:23
1 posts
🔴 CVE-2026-73921 - Critical (9.8)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73921/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T15:32:47
1 posts
🟠 CVE-2026-71176 - High (8.8)
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulner...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71176/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T15:32:36
1 posts
🟠 CVE-2026-76234 - High (7.5)
libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs. libcrux-ecdh did not properly check length and clamping during X25519 secret validation (and had a broken clamping check for im...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76234/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T15:32:24
1 posts
CVE-2026-67364 (CVSS 10): CRITICAL pre-auth PHP code injection in Balbooa Forms for Joomla (v1.0.0 – 2.4.3.1). Exploitable via unescaped query param in custom-PHP handler. Update to 2.4.3.2+ now. https://radar.offseq.com/threat/cve-2026-67364-cwe-94-improper-control-of-generation-of-code-code-injection-in-balbooacom-balbooa-36f88c0efc17ca75 #OffSeq #Joomla #CVE202667364 #WebSecurity
##updated 2026-08-19T15:32:20
1 posts
🟠 CVE-2026-73937 - High (8.2)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73937/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T15:32:20
1 posts
🟠 CVE-2026-73939 - High (8.6)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73939/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T15:32:19
1 posts
🔴 CVE-2026-73922 - Critical (9.1)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73922/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T15:32:19
1 posts
🟠 CVE-2026-73936 - High (7.5)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73936/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T06:31:24
1 posts
🟠 CVE-2026-70408 - High (8.8)
An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70408/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T03:31:30
2 posts
UTT HiPER 1250GW v3.2.7-210907-180535 hit by CRITICAL stack-based buffer overflow (CVE-2026-76004) in HTTP handler. Exploitable via 'pvid' arg. No patch yet — restrict remote access & monitor traffic. https://radar.offseq.com/threat/cve-2026-76004-stack-based-buffer-overflow-in-utt-hiper-1250gw-976b1783bc5dbe2e #OffSeq #CVE202676004 #Vuln #Infosec
##🔴 CVE-2026-76004 - Critical (9.9)
A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The manipulation of the argumen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76004/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T03:31:23
2 posts
CVE-2026-76003 (CRITICAL): Stack-based buffer overflow in UTT HiPER 1200GW (2.5.3-170306). Remote code execution possible via timestart argument; public exploit exists. No patch yet. Restrict access & monitor. https://radar.offseq.com/threat/cve-2026-76003-stack-based-buffer-overflow-in-utt-hiper-1200gw-f42b168f89ef1ec7 #OffSeq #CVE202676003 #infosec #vuln
##🔴 CVE-2026-76003 - Critical (9.9)
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based buffer overflow. The attack may ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76003/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-19T00:31:19
2 posts
🔴 CVE-2026-75976 - Critical (9.9)
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based buffer overflow. The attac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75976/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Stack-based buffer overflow (CVE-2026-75976, CVSS 9.4) in TRENDnet TEW-823DRU 1.1.02b01: remote exploitation possible via /cgi-bin/wan.cgi. Public exploit exists. Assess exposure & monitor for patches: https://radar.offseq.com/threat/cve-2026-75976-stack-based-buffer-overflow-in-trendnet-tew-823dru-3e76dd1e5f15fcab #OffSeq #Vulnerability #Infosec #IoTSecurity
##updated 2026-08-19T00:31:18
1 posts
A Confluence vulnerability, CVE-2026-21580, is a stored XSS flaw (CVSS 8.6) allowing unauthenticated attacks. A Jira flaw also patched. Update now.
#Atlassian #Confluence #CVE202621580 #StoredXSS #Jira #InfoSec
##updated 2026-08-19T00:31:18
1 posts
🟠 CVE-2026-66602 - High (8.8)
Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery.
This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66602/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T21:31:59
1 posts
🔴 CVE-2026-75877 - Critical (9.9)
A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/FUN_0043372C of the component alphapd. Executing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75877/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-18T21:31:53
1 posts
NVIDIA Triton vulnerability CVE-2026-47627 scores CVSS 9.8. Learn how the denial of service flaw works and why you must update to version 26.06 now.
#NVIDIA #TritonInferenceServer #CVE202647627 #DenialOfService #AIsecurity #CVSS
##updated 2026-08-18T18:32:05
1 posts
A critical Dell PowerStore vulnerability, CVE-2026-67271 (CVSS 9.8), allows unauthenticated remote code execution via SMB. Two more flaws patched.
##updated 2026-08-18T18:31:47
2 posts
1 repos
Attackers are exploiting CVE-2026-65400, a critical macOS Screen Sharing auth bypass, to gain root access and deploy Monero miners on Macs with exposed port 5900.
##⚪️ Hackers Exploit macOS Screen Sharing Vulnerability to Install Crypto Miners
🗨️ The Netherlands’ National Cyber Security Centre (NCSC) has warned that attackers have begun exploiting the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. The flaw allows authentication to be bypassed, granting access to a Mac without a password, and is already…
##updated 2026-08-18T18:31:46
3 posts
2 repos
CISA confirmed active exploitation of CVE-2026-33824, an unauthenticated Windows IKE double-free flaw patched in April, ordering federal agencies to remediate within three days.
##CISA Warns of Active Exploitation of Critical Microsoft IKE Remote Code Execution Flaw
CISA reports active exploitation of a Windows IKE service critical remote code execution vulnerability (CVE-2026-33824). The flaw allows unauthenticated attackers to take full control of affected systems by sending malicious network packets.
**If you run Windows systems with IKEv2 enabled (VPN gateways, RRAS servers, IPsec endpoints), apply Microsoft's patch for CVE-2026-33824 immediately. Attackers are actively taking over these machines with no login or user action needed. If you can't patch right away, block inbound UDP ports 500 and 4500 at your firewall and only allow those ports from trusted, known IP addresses.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-of-critical-microsoft-ike-remote-code-execution-flaw-l-d-l-z-t/gD2P6Ple2L
CVE-2026-33824: CRITICAL RCE in Windows IKE Extension is being actively exploited. All supported Windows 10, 11 & Server are impacted. Patch immediately or block UDP 500/4500 if IKE not used. More at https://radar.offseq.com/threat/critical-rce-flaw-in-windows-ike-extension-now-actively-exploited-e49a0ac6b3ada788 #OffSeq #RCE #Windows #BlueTeam
##updated 2026-08-18T15:31:45
2 posts
1 repos
CoSnitch : Copilot a lui-même livré la faille qui permet de voler vos données https://www.it-connect.fr/cosnitch-cve-2026-24301-copilot-personal-faille-un-clic/ #ActuCybersécurité #Cybersécurité #Microsoft #Copilot #IA
##Von wegen KI: MS Copilot ist strunzdumm
Das Sicherheitsunternehmen Varonis hat eine Sicherheitslücke in Microsoft (MS) Copilot gefunden. Die hat inzwischen auch einen Namen bekommen und eine CVE-Nummer: CVE-2026-24301 oder CoSnitch. Sie ist mit 8,8 von 10 als kritisch eingestuft. Anscheinend gibt es noch keinen Flicken dagegen. Wer diese Lücke ausnutzt, kann Copilot von Ferne heimlich (ohne Interaktion des Opfers) dazu veranlassen, sensible geheime Daten zu senden. Zwar hat Copilot Schutzvorkehrungen gegen solchen Missbrauch, aber die sind unvollständig. Der Trick der Forscher/innen bestand darin, Copilot sich selbst hacken zu lassen! Immer wenn die KI einen ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/08/19/von-wegen-ki-ms-copilot-ist-strunzdumm/
#cybercrime #datenleck #KI #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump
##updated 2026-08-18T15:04:46.610000
1 posts
BeyondTrust patched two high-severity EPM flaws (CVE-2026-40144, CVE-2026-40145) that allow local privilege escalation on Windows. Update to 26.1.2.
#BeyondTrust #CVE202640144 #PrivilegeEscalation #Windows #EndpointSecurity #InfoSec
##updated 2026-08-18T14:57:10.630000
9 posts
4 repos
https://github.com/davkharrr/CVE-2026-19478-PoC
https://github.com/renzi25031469/CVE-2026-19478
Critical GitLab Flaw CVE-2026-19478 Is Under Active Attack: Why Organizations Need to Patch Now + Video
A Dangerous Warning for GitLab Administrators A critical vulnerability in self-managed GitLab installations has moved from a serious security concern to an immediate incident-response priority. Security researchers are warning that attackers are actively exploiting CVE-2026-19478, a flaw rated CVSS 9.4, that can allow completely unauthenticated attackers to remotely…
##watchTowr reports active exploitation of CVE-2026-19478 in GitLab within days of public disclosure. The flaw is a code injection via GraphQL directives, exploitable by unauthenticated remote attackers. Reproduction was possible within minutes of the advisory going live. Patch immediately.
#GitLab #CVE202619478 #CodeInjection #PatchNow
https://cyberworldops.eu/en/gitlab-cve-2026-19478-actively-exploited-days-after-disclosure
##GitLab : la faille critique CVE-2026-19478 est déjà exploitée, deux jours après le correctif https://www.it-connect.fr/gitlab-cve-2026-19478-faille-critique-exploitee/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##watchTowr reports active exploitation of CVE-2026-19478 in GitLab within days of public disclosure. The flaw is a code injection via GraphQL directives, exploitable by unauthenticated remote attackers. Reproduction was possible within minutes of the advisory going live. Patch immediately.
#GitLab #CVE202619478 #CodeInjection #PatchNow
https://cyberworldops.eu/en/gitlab-cve-2026-19478-actively-exploited-days-after-disclosure
##GitLab : la faille critique CVE-2026-19478 est déjà exploitée, deux jours après le correctif https://www.it-connect.fr/gitlab-cve-2026-19478-faille-critique-exploitee/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##A GitLab CVE-2026-19478 sebezhetőséget napokkal a nyilvánosságra hozatal után már aktívan kihasználják
##⚪️ Critical GitLab Vulnerability Allowed Deletion of Public Projects
🗨️ GitLab developers have released emergency patches for Community Edition (CE) and Enterprise Edition (EE) that address the critical vulnerability CVE-2026-19478 (CVSS score: 9.4). Under certain conditions, the flaw allowed an unauthenticated attacker to remotely modify or delete public projects and…
##Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive
#GitLab #CVE_2026_19478 #CVE_2026_19650
https://www.ox.security/blog/gitlab-graphql-cve-2026-19478-19650/
Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects
GitLab has patched two security flaws, including CVE-2026-19478, a critical code injection vulnerability that could allow unauthenticated attackers...
🔗️ [Thecyberexpress] https://link.is.it/otTWyh
##updated 2026-08-18T04:16:40.860000
2 posts
1 repos
Ray Framework Remote Code Execution Vulnerability Under Active Exploitation
CISA warned that attackers are exploiting a remote code execution vulnerability in the Ray framework to target machine learning developers. The flaw allows attackers to bypass browser security checks and run arbitrary commands on developer machines and internal networks.
**If you use the Ray framework, update it to version 2.52.0 or later ASAP. Attackers are actively exploiting CVE-2025-62593 to run commands on developer machines. Also make sure Ray is never reachable from the internet and only accessible from trusted networks, and watch for unusual traffic between developer laptops and your internal compute clusters.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/ray-framework-remote-code-execution-vulnerability-under-active-exploitation-y-u-w-h-s/gD2P6Ple2L
Recent alerts include CISA adding a critical RCE flaw in Ray-Project Ray (CVE-2025-62593) to its KEV catalog (Aug 18). Heights Finance also reported a data breach impacting over 1.2 million customers. Globally, ransomware incidents remain high, with AI increasingly used in attacks. Geopolitically, US-Iran talks have stalled, intensifying Middle East tensions and affecting global shipping.
##updated 2026-08-17T21:58:52
5 posts
3 repos
https://github.com/codeb0ssx/CVE-2026-64849-PoC
CVE-2026-64849 exposes unauthenticated MLflow tracking servers to critical server-side request forgery (SSRF) threats via redirect bypasses. Discover immediate mitigation strategies, CISA KEV compliance guidelines, and SOC detection playbooks to secure your AI infrastructure. https://thecybermind.co/jily
##CISA has detected active exploitation of CVE-2026-64849, a critical SSRF in MLflow. Exposed tracking servers without authentication can be abused to query cloud metadata, internal services, and loopback addresses, leading to credential theft and internal reconnaissance.
#CloudSecurity #SSRF #Vulnerability #ThreatIntel
https://cyberworldops.eu/en/mlflow-under-attack-critical-ssrf-exposes-cloud-credentials-and
##🚨 [CISA-2026:0819] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-64849 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- Name: MLflow Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MLflow
- Product: MLflow
- Notes: https://github.com/mlflow/mlflow/pull/24258 ; https://github.com/mlflow/mlflow/issues/24179 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-64849
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260819 #cisa20260819 #cve_2026_64849 #cve202664849
##CVE ID: CVE-2026-64849
Vendor: MLflow
Product: MLflow
Date Added: 2026-08-19
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64849
Attackers Exploit a Critical MLflow Vulnerability
Attackers are actively exploiting a critical flaw in MLflow (CVE-2026-64849) to steal cloud credentials and gain remote code execution.
**If you run MLflow, update it to version 3.15.0 or later ASAP, and make sure the server is not reachable from the internet. Then check your audit logs for any odd requests to cloud metadata services. If you see any (or aren't sure), rotate your cloud credentials and keys as a precaution.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/attackers-exploit-a-critical-mlflow-vulnerability-3-u-3-k-6/gD2P6Ple2L
updated 2026-08-17T19:16:28.953000
1 posts
A critical IBM remote code execution flaw (CVE-2026-17482, CVSS 9.8) allows attackers to compromise workstations. Discover how to apply the software patch.
#IBM #CyberSecurity #CVE202617482 #RCE #VulnerabilityManagement
##updated 2026-08-17T18:31:22
1 posts
BeyondTrust patched two high-severity EPM flaws (CVE-2026-40144, CVE-2026-40145) that allow local privilege escalation on Windows. Update to 26.1.2.
#BeyondTrust #CVE202640144 #PrivilegeEscalation #Windows #EndpointSecurity #InfoSec
##updated 2026-08-17T17:32:35
1 posts
A vm2 sandbox escape (CVE-2026-47686, CVSS 9.9) with public PoC lets attackers hijack the host. Two more critical flaws also patched. Update to 3.11.6.
##updated 2026-08-16T19:17:24.183000
1 posts
2 repos
A maximum-severity CVSS 10.0 flaw in Microsoft Entra ID is under active exploitation, allowing remote code execution. Two CVEs are in play, CVE-2026-68820 and CVE-2026-69836, with activity attributed to the Lazarus Group.
##updated 2026-08-14T21:31:35
1 posts
IBM patches an IBM Db2 Mirror RCE flaw, CVE-2026-17186, rated CVSS 9.9, plus 17 more bugs in Db2 Mirror for i. Patch now.
#IBM #Db2Mirror #IBMi #RCE #CVE #CyberSecurity #Vulnerability #InfoSec
##updated 2026-08-13T21:36:21
1 posts
A Vault Secrets Operator vulnerability, CVE-2026-8715, lets tenants read pod files and gain privilege escalation. Patch to 1.5.0 now.
#HashiCorp #Vault #Kubernetes #CVE #PrivilegeEscalation #CyberSecurity #InfoSec #Vulnerability
##updated 2026-08-11T17:17:47.660000
1 posts
Protect your network from CVE-2026-13737 and CVE-2026-13738. These critical Commvault command execution flaws allow hackers to bypass authorization checks.
#Commvault #CVE202613737 #CVE202613738 #Cybersecurity #Vulnerability
##updated 2026-08-11T17:17:47.540000
1 posts
Protect your network from CVE-2026-13737 and CVE-2026-13738. These critical Commvault command execution flaws allow hackers to bypass authorization checks.
#Commvault #CVE202613737 #CVE202613738 #Cybersecurity #Vulnerability
##updated 2026-08-08T03:32:15
1 posts
1 repos
⚪️ Hackers Exploit macOS Screen Sharing Vulnerability to Install Crypto Miners
🗨️ The Netherlands’ National Cyber Security Centre (NCSC) has warned that attackers have begun exploiting the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. The flaw allows authentication to be bypassed, granting access to a Mac without a password, and is already…
##updated 2026-08-05T15:17:03.507000
2 posts
7 repos
https://github.com/HackSpeak/CVE-2026-66066
https://github.com/rails/rails-forensics-CVE-2026-66066
https://github.com/0xsha/KindaRails2Shell
https://github.com/Zer0SumGam3/CVE-2026-66066-POC
https://github.com/0xBlackash/CVE-2026-66066
Mastodon v4.7 へのupgrade をRails v8.1.3 の脆弱性解消とは、関係ないことを学習。
Google AI:
「今回の「KindaRails2Shell (CVE-2026-66066)」という脆弱性の攻撃ルートを、Mastodon自体が完全に通らない構造になっているためです。
Active Storage(問題の部品)を完全排除している
ダイレクトアップロード機能も使っていない」
以上の回答を得ました。
Mastodon v4.7 が Rails v8.1.3 の対策で出されたと言う以前の私の投稿を訂正いたします。
##Mastodon v4.7 へのupgrade をRails v8.1.3 の脆弱性解消とは、関係ないことを学習。
Google AI:
「今回の「KindaRails2Shell (CVE-2026-66066)」という脆弱性の攻撃ルートを、Mastodon自体が完全に通らない構造になっているためです。
Active Storage(問題の部品)を完全排除している
ダイレクトアップロード機能も使っていない」
以上の回答を得ました。
Mastodon v4.7 が Rails v8.1.3 の対策で出されたと言う以前の私の投稿を訂正いたします。
##updated 2026-07-22T20:33:11.590000
1 posts
WTF?
> The fix for CVE-2026-11622 was reverted in commit d76328bfc7 on the development branch, reintroducing this vulnerability in the current stable release (9.20.27).
The branch was never merged and it was prepared just as an experiment. And this little ...person… tried to report this as CVSS 7.5.
##updated 2026-07-14T21:32:21
1 posts
1 repos
https://github.com/OmriBaso/SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit
CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM
##updated 2026-07-08T15:28:40.107000
1 posts
PoC exploit code for CVE-2026-52929, a Linux kernel SCTP flaw, is public. A video shows root privilege escalation on Ubuntu 26.04.
#CVE202652929 #LinuxKernel #SCTP #PrivilegeEscalation #PoC #infosec
##updated 2026-07-07T21:31:43
1 posts
console-setup (1.226ubuntu1.1)
セキュリティ対応ではない。
console-setup-linux
keyboard-configuration
open-vm-tools (2:13.0.10-0ubuntu0.24.04.1)
セキュリティ対応ではない。
snapd (2.76.3+ubuntu24.04)
セキュリティ対応ではない。
wget (1.21.4-1ubuntu4.5)
CVE-2026-58472へのセキュリティ対応。
updated 2026-07-01T15:52:28.390000
2 posts
2 repos
https://github.com/derekpreston81/CVE_ADC_IOC_2026
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
Citrix NetScaler Flaws Under Active Attack Following Exploit Release
Citrix NetScaler ADC and Gateway appliances are being exploited via a critical SAML memory overflow vulnerability (CVE-2026-8452) that allows pre-authentication remote code execution. Attackers are targeting perimeter devices to gain unauthorized access to internal corporate networks following the release of public proof-of-concept code.
**If you run Citrix NetScaler ADC or Gateway, patch immediately to version 14.1-72.61 or 13.1-63.18 (or the matching FIPS builds). Attackers are already exploiting these appliances and a public exploit PoC is available. If you can't patch right away, restrict the management interface to trusted internal networks only, review your SAML configuration, and check logs for unexpected admin logins or config changes.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/citrix-netscaler-flaws-under-active-attack-following-exploit-release-e-x-8-8-4/gD2P6Ple2L
Citrix NetScaler Flaws Under Active Attack Following Exploit Release
Citrix NetScaler ADC and Gateway appliances are being exploited via a critical SAML memory overflow vulnerability (CVE-2026-8452) that allows pre-authentication remote code execution. Attackers are targeting perimeter devices to gain unauthorized access to internal corporate networks following the release of public proof-of-concept code.
**If you run Citrix NetScaler ADC or Gateway, patch immediately to version 14.1-72.61 or 13.1-63.18 (or the matching FIPS builds). Attackers are already exploiting these appliances and a public exploit PoC is available. If you can't patch right away, restrict the management interface to trusted internal networks only, review your SAML configuration, and check logs for unexpected admin logins or config changes.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/citrix-netscaler-flaws-under-active-attack-following-exploit-release-e-x-8-8-4/gD2P6Ple2L
updated 2026-06-26T15:33:15
7 posts
1 repos
⚠️ CRITICAL: Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
Clop ransomware operators deployed a custom JSP web shell targeting PTC Windchill and FlexPLM servers, exploiting CVE-2026-12569 to decrypt stored credentials and exfiltrate engineering data. Any organization running vulnerable Windchill instances is at immediate risk of credential compromise, late…
🤖 AI generated summary
##ReliaQuest found Clop deploying a purpose-built JSP web shell that abuses Windchill's internal APIs to decrypt secrets and steal files after exploiting CVE-2026-12569.
##Cl0p published full names of over 40 organizations allegedly breached through CVE-2026-12569 in PTC Windchill and FlexPLM. The flaw was added to CISA KEV in June, yet dozens of instances remained unpatched into August.
#Cl0p #Windchill #SupplyChainSecurity #CVE202612569
https://cyberworldops.eu/en/cl0p-targets-windchill-more-than-40-organizations-exposed-to-a
##You built your product lifecycle management empire on unpatched servers. Magnificent. Truly. Patch CVE-2026-12569 on all PTC Windchill and FlexPLM instances immediately, and hunt for unauthorized web shells before Clop finishes admiring your data.
Reward: You've unlocked the Hollow Trophy — a shiny gold cup with absolutely nothing inside it, just like your patch management schedule.
#Ransomware #CyberSecurity #ClopRansomware #PtcWindchill #WebShell #PatchedOrPerish (2/2)
##🏆 New Achievement! Shell We Dance, PTC?
Ahem. Allow me to explain my genius. Clop — yes, the ransomware operation, the one you've heard about in hushed tones — identified CVE-2026-12569 in PTC Windchill and FlexPLM servers and deployed a custom web shell so elegantly minimal it needs no additional tooling whatsoever. Credentials? Siphoned. Sensitive engineering data? Exfiltrated. It's almost beautiful, like a Bond villain who remembered to actually press the button. (1/2)
##ReliaQuest has documented a custom JSP web shell deployed by Clop after exploitation of CVE-2026-12569 on PTC Windchill and FlexPLM servers. The implant maps design vaults, decrypts keystore credentials, and queries databases via the application's own identity.
#Clop #PTCWindchill #WebShell #ThreatIntelligence
https://cyberworldops.eu/en/clop-exploits-windchill-jsp-web-shell-steals-credentials-and
##PTC Windchill/FlexPLM (CVE-2026-12569) exploited by Cl0p ransomware: CRITICAL severity, remote code execution, 40+ orgs hit. Patch ASAP to block active data theft & extortion. Full details: https://radar.offseq.com/threat/cl0p-ransomware-group-names-over-40-victims-of-ptc-windchill-campaign-1b708410d1eaf87f #OffSeq #Ransomware #CVE202612569 #Infosec
##updated 2026-06-17T18:35:58
1 posts
Critical OS command injection in Splunk AI Toolkit (CVE-2026-20266, CVSS 9.1) lets admins run arbitrary host commands. Patch to 5.7.4 now.
#Splunk #CVE #OSCommandInjection #Vulnerability #InfoSec #PatchNow #AISecurity
##updated 2026-06-16T23:23:40.850000
1 posts
@janl Oh no, I doxed myself. The reporter of CVE-2010-3854 wanted to stay anonymous, heh.
##updated 2026-06-16T22:59:22.107000
1 posts
1 repos
https://github.com/talha3117/OpenSSH-4.7p1-CVE-2008-5161-Exploit
updated 2026-06-02T15:33:09
2 posts
1 repos
🚨 Public PoC available for high-severity Android ContactsProvider flaw
https://github.com/qm4rs/cve-2026-0075
CVE-2026-0075 affects Android 14, 15, 16, and 16 QPR2 and can allow access to information from the contacts database through a SQL-related side channel without user interaction.
Researcher QM4RS has now released a controlled Android PoC that intentionally requests neither READ_CONTACTS nor WRITE_CONTACTS.
The issue involves ContactsProvider2 returning detailed SQLite errors to callers that lack contacts permission. Those errors could potentially be abused as an information side channel.
Google's fix strips sensitive JSON-related SQLite exception details from unauthorized callers.
The researcher cautions that the PoC is build-specific and does not demonstrate a universal exploitation path across every Android device.
Devices with the June 5, 2026 Android security patch level or later address the issue.
##A public PoC for CVE-2026-0075 shows an Android elevation of privilege in ContactsProvider2 that needs no user interaction.
#CVE20260075 #Android #ElevationOfPrivilege #ContactsProvider #SQLInjection #AndroidSecurity
https://securityonline.info/cve-2026-0075-android-eop/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-03-16T15:30:54
1 posts
4 repos
https://github.com/davkharrr/CVE-2026-19478-PoC
https://github.com/renzi25031469/CVE-2026-19478
⚪️ Critical GitLab Vulnerability Allowed Deletion of Public Projects
🗨️ GitLab developers have released emergency patches for Community Edition (CE) and Enterprise Edition (EE) that address the critical vulnerability CVE-2026-19478 (CVSS score: 9.4). Under certain conditions, the flaw allowed an unauthenticated attacker to remotely modify or delete public projects and…
##Spring Security Vulnerability CVE-2026-59270 Exposes Embedded LDAP Servers to Remote Attackers
A Quiet Configuration Flaw With Serious Security Consequences A vulnerability hiding inside an embedded LDAP component can be easy to overlook—until an attacker discovers that the directory server is listening on a network interface it was never supposed to expose. That is the danger behind CVE-2026-59270, a newly disclosed Spring Security vulnerability affecting applications…
##Four Spring Security vulnerabilities were disclosed, led by CVE-2026-59270 (CVSS 9.4). Attackers can read or modify entries in the in-memory directory.
##CVE-2026-77176 lets a malicious operator mount arbitrary guest rootfs paths in Kata Containers Confidential Containers setups. Update to Kata 4.1.0.
#CVE202677176 #KataContainers #ConfidentialContainers #CloudSecurity #genpolicy #infosec
##🟠 CVE-2026-77176 - High (8.1)
A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77176/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71485 - Critical (9.1)
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEm...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71485/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-71428 - Critical (9.3)
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partitio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Two critical Spring Integration vulnerabilities, CVE-2026-59307 and CVE-2026-59324, expose systems to remote code execution and data leakage. Update now.
#SpringIntegration #CyberSecurity #CVE202659307 #CVE202659324 #Vulnerability
##Two critical Spring Integration vulnerabilities, CVE-2026-59307 and CVE-2026-59324, expose systems to remote code execution and data leakage. Update now.
#SpringIntegration #CyberSecurity #CVE202659307 #CVE202659324 #Vulnerability
##🟠 CVE-2026-63490 - High (7.5)
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63490/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##https://docs.ceph.com/en/latest/security/CVE-2026-54330/
https://github.com/ceph/ceph/commit/89df1b55f12f4bb07878cc0e8f5152307166b7f4
>RGW: This release contains a fix for CVE-2026-54330. We now reject Sigv4 requests with `host` and `x-amz-` headers not included in the signed subset. Unfortunately, the REST client used in multisite was generating such improperly signed requests.
can't make this shit up
> If you are running multisite, you must set the ``rgw_sigv4_insecure`` option to true before you begin to upgrade. After all clusters are upgraded, set the option to ``false`` again.
??! D:
they want me to backdoor the cluster in order to fix a security vuln in the cluster lmfao
##🟠 CVE-2026-68900 - High (7.6)
Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded entity-encoded markup, and then interpolated titleText and allText ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68900/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-50191 - High (8.8)
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50191/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-50186 - High (8.8)
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports/:id/:filename. In server/api/controllers/boards...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50186/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-52872 - High (8.8)
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied subtitle ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52872/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-53958 - High (7.6)
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcI...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-52877 - High (8.3)
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal withou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52877/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75936 - High (7.5)
Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75936/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##