##
Updated at UTC 2026-07-24T21:26:04.358297
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-17107 | 8.5 | 0.00% | 2 | 0 | 2026-07-24T20:49:03.140000 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Ad | |
| CVE-2026-62835 | 9.3 | 0.00% | 2 | 0 | 2026-07-24T20:48:18.380000 | Improper authorization in Azure Portal allows an unauthorized attacker to disclo | |
| CVE-2026-58630 | 10.0 | 0.00% | 4 | 0 | 2026-07-24T20:48:18.380000 | Improper access control in Azure App Service allows an unauthorized attacker to | |
| CVE-2026-60217 | 10.0 | 0.45% | 1 | 0 | 2026-07-24T20:41:08.940000 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo | |
| CVE-2026-66035 | 7.5 | 0.00% | 2 | 0 | 2026-07-24T19:17:10.700000 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication h | |
| CVE-2026-65709 | 8.3 | 0.00% | 2 | 0 | 2026-07-24T19:17:10.580000 | sysPass through version 3.2.11 contains a missing object-level authorization vul | |
| CVE-2026-54342 | 8.1 | 0.00% | 2 | 0 | 2026-07-24T19:16:59.200000 | In epa4all, prior to version 2026-05-20, an attacker on the network path between | |
| CVE-2026-48021 | 9.1 | 0.00% | 2 | 0 | 2026-07-24T19:16:58.033000 | In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS c | |
| CVE-2026-66027 | 8.3 | 0.00% | 2 | 0 | 2026-07-24T18:31:37 | Suna before 0.9.102 contains a broken access control vulnerability in the messag | |
| CVE-2026-66034 | 7.5 | 0.00% | 2 | 0 | 2026-07-24T18:18:09.050000 | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check | |
| CVE-2026-66032 | 8.8 | 0.00% | 2 | 0 | 2026-07-24T18:18:08.923000 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerab | |
| CVE-2026-65708 | 8.1 | 0.00% | 2 | 0 | 2026-07-24T18:18:08.653000 | sysPass through version 3.2.11 contains an insecure direct object reference vuln | |
| CVE-2026-66033 | 7.5 | 0.00% | 2 | 0 | 2026-07-24T17:17:35.263000 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication i | |
| CVE-2026-8789 | 8.1 | 0.00% | 2 | 0 | 2026-07-24T15:33:10 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modific | |
| CVE-2026-57106 | 10.0 | 0.00% | 2 | 0 | 2026-07-24T15:33:03 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attack | |
| CVE-2026-64600 | 0 | 0.64% | 1 | 2 | 2026-07-24T15:19:06.087000 | In the Linux kernel, the following vulnerability has been resolved: xfs: resamp | |
| CVE-2026-16730 | 5.5 | 0.00% | 1 | 0 | 2026-07-24T12:31:03 | A flaw was found in dbus-broker. When the process file-descriptor limit is reach | |
| CVE-2026-14172 | 7.8 | 0.11% | 1 | 0 | 2026-07-24T09:32:22 | Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables | |
| CVE-2026-15704 | 9.8 | 0.35% | 1 | 0 | 2026-07-24T09:32:16 | In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled | |
| CVE-2026-24727 | None | 0.67% | 1 | 0 | 2026-07-24T09:32:16 | An unrestricted upload of file with dangerous type vulnerability in the e-paper | |
| CVE-2026-16870 | 8.8 | 0.36% | 1 | 0 | 2026-07-24T06:34:17 | Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior | |
| CVE-2026-54120 | 9.9 | 0.71% | 1 | 0 | 2026-07-24T03:31:56 | Improper input validation in Microsoft Surface allows an authorized attacker to | |
| CVE-2026-56160 | 9.1 | 0.65% | 1 | 0 | 2026-07-24T03:31:56 | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized att | |
| CVE-2026-47056 | 10.0 | 0.33% | 1 | 0 | 2026-07-23T18:31:02 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware | |
| CVE-2026-16232 | 9.1 | 12.68% | 4 | 1 | 2026-07-23T15:44:54.743000 | An authentication bypass vulnerability in the Check Point SmartConsole login pro | |
| CVE-2026-50522 | 9.8 | 57.10% | 1 | 1 | 2026-07-22T21:31:51 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut | |
| CVE-2026-54121 | 8.8 | 0.80% | 5 | 1 | 2026-07-21T19:54:33.623000 | Improper authorization in Active Directory Certificate Services (AD CS) allows a | |
| CVE-2026-16242 | 9.4 | 0.37% | 1 | 0 | 2026-07-20T09:31:15 | A flaw was found in the Konnectivity proxy-server configuration for hosted contr | |
| CVE-2026-42533 | 8.1 | 2.79% | 1 | 6 | 2026-07-15T15:33:14 | A vulnerability exists in NGINX Plus and NGINX Open Source when a mapย directive | |
| CVE-2026-50454 | 7.8 | 0.44% | 1 | 0 | 2026-07-14T18:32:32 | Relative path traversal in Windows User Interface Core allows an authorized atta | |
| CVE-2025-66376 | 7.2 | 21.62% | 2 | 0 | 2026-06-17T09:56:44.753000 | Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas | |
| CVE-2025-0679 | 4.3 | 0.29% | 1 | 0 | 2026-06-17T08:26:57.313000 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 be | |
| CVE-2026-0770 | None | 53.46% | 1 | 7 | template | 2026-02-19T22:09:33 | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere R |
| CVE-2026-61884 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-63030 | 0 | 97.92% | 2 | 67 | template | N/A | |
| CVE-2026-60137 | 0 | 77.97% | 1 | 42 | N/A |
updated 2026-07-24T20:49:03.140000
2 posts
๐ CVE-2026-17107 - High (8.5)
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-17107/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##๐ CVE-2026-17107 - High (8.5)
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-17107/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T20:48:18.380000
2 posts
๐จ CVE-2026-62835: Microsoft Azure Portal Information Disclosure Vulnerability
CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.
CVSS: 9.3
More information: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62835
##๐จ CVE-2026-62835: Microsoft Azure Portal Information Disclosure Vulnerability
CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.
CVSS: 9.3
More information: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62835
##updated 2026-07-24T20:48:18.380000
4 posts
โผ๏ธ CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVSS: 10
Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58630
##๐ด CVE-2026-58630 - Critical (10)
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-58630/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##โผ๏ธ CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVSS: 10
Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58630
##๐ด CVE-2026-58630 - Critical (10)
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-58630/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T20:41:08.940000
1 posts
Oracle drops 1,449 security patches like it's the new normal
Oracle๊ฐ ๋ถ๊ธฐ ๋ณด์ ์ ๋ฐ์ดํธ์์ 1,449๊ฑด์ ํจ์น๋ฅผ ๋ฐฐํฌํ์ผ๋ฉฐ, ์ด ์ค Oracle Fusion Middleware ๊ด๋ จ ์ทจ์ฝ์ 10๊ฑด์ CVSS 10.0์ด๋ค. ํนํ ์ธ์ฆ ์์ด HTTP๋ก Oracle Data Integrator๋ฅผ ์ฅ์ ํ ์ ์๋ CVE-2026-47056๊ณผ TCP๋ฅผ ํตํด Oracle Coherence๋ฅผ ์ฅ์ ํ ์ ์๋ CVE-2026-60217์ ์ฆ์ ํจ์น ์ฐ์ ์์๊ฐ ๋๋ค. Oracle Database Server์๋ ์ ๊ถํ ์๊ฒฉ ์ฝ๋ ์คํ ๊ฐ...
##updated 2026-07-24T19:17:10.700000
2 posts
๐ CVE-2026-66035 - High (7.5)
libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-66035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##๐ CVE-2026-66035 - High (7.5)
libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-66035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T19:17:10.580000
2 posts
๐ CVE-2026-65709 - High (8.3)
sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without pe...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-65709/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##๐ CVE-2026-65709 - High (8.3)
sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without pe...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-65709/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T19:16:59.200000
2 posts
๐ CVE-2026-54342 - High (8.1)
In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnek...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-54342/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##๐ CVE-2026-54342 - High (8.1)
In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnek...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-54342/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T19:16:58.033000
2 posts
๐ด CVE-2026-48021 - Critical (9.1)
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traff...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-48021/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##๐ด CVE-2026-48021 - Critical (9.1)
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traff...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-48021/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T18:31:37
2 posts
๐ CVE-2026-66027 - High (8.3)
Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-66027/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##๐ CVE-2026-66027 - High (8.3)
Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-66027/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T18:18:09.050000
2 posts
๐ CVE-2026-66034 - High (7.5)
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsy...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-66034/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##๐ CVE-2026-66034 - High (7.5)
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsy...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-66034/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T18:18:08.923000
2 posts
๐ CVE-2026-66032 - High (8.8)
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a serv...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-66032/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##๐ CVE-2026-66032 - High (8.8)
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a serv...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-66032/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T18:18:08.653000
2 posts
๐ CVE-2026-65708 - High (8.1)
sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing au...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-65708/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##๐ CVE-2026-65708 - High (8.1)
sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing au...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-65708/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T17:17:35.263000
2 posts
๐ CVE-2026-66033 - High (7.5)
libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AE...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-66033/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##๐ CVE-2026-66033 - High (7.5)
libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AE...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-66033/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T15:33:10
2 posts
๐ CVE-2026-8789 - High (8.1)
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-8789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##๐ CVE-2026-8789 - High (8.1)
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-8789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T15:33:03
2 posts
๐ด CVE-2026-57106 - Critical (10)
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-57106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##๐ด CVE-2026-57106 - Critical (10)
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-57106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T15:19:06.087000
1 posts
2 repos
Discover the RefluXFS Linux vulnerability (CVE-2026-64600) in XFS that allows local users to overwrite protected files and gain root privileges.
#RefluXFS #CVE202664600 #LinuxKernel #Cybersecurity #XFS
https://meterpreter.org/refluxfs-linux-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-24T12:31:03
1 posts
got a red hat cve for the bug i found trying out superluminal on linux. this means that i'm a SECURITY RESEARCHER now! https://access.redhat.com/security/cve/cve-2026-16730
##updated 2026-07-24T09:32:22
1 posts
๐ CVE-2026-14172 - High (7.8)
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYS...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-14172/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T09:32:16
1 posts
๐ด CVE-2026-15704 - Critical (9.8)
In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router.
The shared rou...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-15704/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T09:32:16
1 posts
CVE-2026-24727 (CRITICAL, CVSS 9.3): SUNNET Corporate Training Mgmt System v10.3 allows admins to upload ZIP files with executable code, enabling server command execution. No patch yet โ restrict admin access & monitor uploads. https://radar.offseq.com/threat/cve-2026-24727-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-sunnet-technology-co-ltd-fe23deeb060f5b6d #OffSeq #CVE202624727 #infosec ๐ก๏ธ
##updated 2026-07-24T06:34:17
1 posts
๐ CVE-2026-16870 - High (8.8)
Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-16870/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T03:31:56
1 posts
CVE-2026-54120 (CRITICAL, CVSS 9.9): Improper input validation in Microsoft Surface Management Services lets authorized attackers run code remotely. Patch now: https://radar.offseq.com/threat/cve-2026-54120-cwe-20-improper-input-validation-in-microsoft-surface-management-services-203a5e59f513d748 ๐ฅ๏ธ #OffSeq #infosec #Microsoft #CVE202654120
##updated 2026-07-24T03:31:56
1 posts
CRITICAL improper authorization vuln (CVE-2026-56160) in Azure Red Hat OpenShift (ARO): privilege escalation risk for authorized users. No active exploits. Microsoft has released a fix โ ensure your ARO instances are updated. Details: https://radar.offseq.com/threat/cve-2026-56160-cwe-285-improper-authorization-in-microsoft-azure-red-hat-openshift-aro-9a561de9f992bb49 #OffSeq #Azure #CVE202656160
##updated 2026-07-23T18:31:02
1 posts
Oracle drops 1,449 security patches like it's the new normal
Oracle๊ฐ ๋ถ๊ธฐ ๋ณด์ ์ ๋ฐ์ดํธ์์ 1,449๊ฑด์ ํจ์น๋ฅผ ๋ฐฐํฌํ์ผ๋ฉฐ, ์ด ์ค Oracle Fusion Middleware ๊ด๋ จ ์ทจ์ฝ์ 10๊ฑด์ CVSS 10.0์ด๋ค. ํนํ ์ธ์ฆ ์์ด HTTP๋ก Oracle Data Integrator๋ฅผ ์ฅ์ ํ ์ ์๋ CVE-2026-47056๊ณผ TCP๋ฅผ ํตํด Oracle Coherence๋ฅผ ์ฅ์ ํ ์ ์๋ CVE-2026-60217์ ์ฆ์ ํจ์น ์ฐ์ ์์๊ฐ ๋๋ค. Oracle Database Server์๋ ์ ๊ถํ ์๊ฒฉ ์ฝ๋ ์คํ ๊ฐ...
##updated 2026-07-23T15:44:54.743000
4 posts
1 repos
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
โผ๏ธ CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
CVSS: 9.1
Scanner: https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
Details and Mitigation: https://support.checkpoint.com/results/sk/sk185169/
##๐ฐ Check Point Patches Actively Exploited SmartConsole Auth Bypass Flaw
๐จ CRITICAL PATCH: Check Point fixes an actively exploited auth bypass zero-day (CVE-2026-16232, CVSS 9.3) in SmartConsole. Flaw allows full admin access. CISA added to KEV. Patch NOW. #CyberSecurity #ZeroDay #CheckPoint #Infosec
๐ cyber[.]netsecops[.]io
##โผ๏ธ CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
CVSS: 9.1
Scanner: https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
Details and Mitigation: https://support.checkpoint.com/results/sk/sk185169/
##Geopolitical tensions escalated as US strikes on Iran continued and Houthi attacks on Saudi tankers raised oil prices. In cybersecurity, a critical Check Point zero-day (CVE-2026-16232) is actively exploited. US agencies warned of Iranian cyber campaigns targeting critical infrastructure PLCs and Russian state-backed phishing on Zimbra Collaboration Suite. AI agents are now a primary attack surface.
##updated 2026-07-22T21:31:51
1 posts
1 repos
(CISA TS-SOC) CVE-2026-50522 โ Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data....
##updated 2026-07-21T19:54:33.623000
5 posts
1 repos
Certighost AD CS Vulnerability Exposes a Dangerous Path to Domain Controller Control, Microsoft Fixes Critical Identity Security Flaw + Video
Introduction: A New Warning for Active Directory Defenders A newly disclosed Active Directory security vulnerability is raising concerns among enterprise defenders because it demonstrates how a seemingly limited user account could become a stepping stone toward full domain compromise. The flaw, tracked as CVE-2026-54121 and knownโฆ
##โผ๏ธ PoC released for CVE-2026-54121 codenamed Certighost
CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.
##๐ฐ PoC Exploit 'Certighost' for Critical AD CS Flaw Now Public
PoC exploit 'Certighost' released for critical AD CS flaw CVE-2026-54121 (CVSS 8.8). Exploit allows low-privilege users to impersonate a Domain Controller, leading to full domain compromise. Patching is urgent. #ActiveDirectory #CyberSecurity #BlueTeam
๐ cyber[.]netsecops[.]io
##โผ๏ธ PoC released for CVE-2026-54121 codenamed Certighost
CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.
##New.
GitHub/H0j3n: Certighost (CVE-2026-54121) https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26
More:
The Hacker News: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html @thehackernews #infosec #vulnerability #Microsoft #Windows
##updated 2026-07-20T09:31:15
1 posts
A Konnectivity vulnerability (CVE-2026-16242, CVSS 9.4) lets unauthenticated attackers proxy and modify control-plane traffic. See the fix and mitigation.
#Konnectivity #Kubernetes #CVE202616242 #CloudSecurity #ControlPlane #AuthBypass #InfoSec #PatchNow
##updated 2026-07-15T15:33:14
1 posts
6 repos
https://github.com/gagaltotal/CVE-2026-42533-nginx
https://github.com/seguridadentrerios/CVE-2026-42533
https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner
https://github.com/srkyn/nginx-map-risk-audit
15-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533 โ cyberstan #devopsish https://cyberstan.co.uk/nginx-rce/
##updated 2026-07-14T18:32:32
1 posts
A public proof-of-concept details the Windows AppResolver LPE (CVE-2026-50454), a UAC bypass that chains an admin token to a SYSTEM shell.
#Windows #CVE202650454 #PrivilegeEscalation #UACBypass #InfoSec
##updated 2026-06-17T09:56:44.753000
2 posts
๐ฐ Russian APT 'Laundry Bear' Targets West with Zero-Click Zimbra Exploit
International advisory warns of Russian APT 'Laundry Bear' using a zero-click Zimbra exploit (CVE-2025-66376) in a widespread espionage campaign against Western targets. Actors steal emails & credentials. #ThreatIntel #Zimbra #CyberSecurity
๐ cyber[.]netsecops[.]io
##๐ฐ Russian Hackers Use Zero-Click Zimbra Exploit in Global Spy Campaign
Russian state actors (Void Blizzard) are exploiting a zero-click Zimbra vulnerability (CVE-2025-66376) to steal credentials and emails. The campaign uses JavaScript injection via phishing emails. Patching is critical. #CyberEspionage #Zimbra #ThreatI...
๐ cyber[.]netsecops[.]io
##updated 2026-06-17T08:26:57.313000
1 posts
CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.
Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.
Reward: You've received a hollow Authenticator Token โ pre-drained.
#ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)
##updated 2026-02-19T22:09:33
1 posts
7 repos
https://github.com/Yetazyyy/CVE-2026-0770
https://github.com/razureink/cve-2026-0770-langflow_rce_reproduction
https://github.com/0xBlackash/CVE-2026-0770
https://github.com/0xgh057r3c0n/CVE-2026-0770
https://github.com/affix/CVE-2026-0770-PoC
(CISA TS-SOC) CVE-2026-0770 โ Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Severity: UNKNOWN Impact Summary: Remote attackers can execute arbitrary code on affected installations. Timestamp: 2026-07-24T01:31:37.336Z ATT&CK Mappingโฆ...
##Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8
##2 posts
67 repos
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/Lutfifakee-Project/wp2shell
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/ekomsSavior/wp2shell
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/kulichr/wp2shell
https://github.com/Crypto-Cat/wp2shell
https://github.com/CybersecSpirit/CVE-2026-63030
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/TomorrowX6/CVE-2026-63030-poc
https://github.com/shinthink/CVE-2026-63030
https://github.com/c0gnit00/Wp2Shell
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/InstaWP/wp2shell-scan
https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause
https://github.com/4B3R4M4-607D/CVE-2026-63030-POC
https://github.com/Iqbalx7/wp2shell
https://github.com/NULL200OK/WP2Shell
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/yoerivegt/wp2shell-poc
https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030
https://github.com/0xjessie21/wp2shell-checker
https://github.com/0xWhoknows/wp2shell
https://github.com/Ch4120N/CVE-2026-63030
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/securelayer7/WordPresShell
https://github.com/4minx/CVE-2026-63030
https://github.com/mhtsec/CVE-2026-63030
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/ZenithGenius/wordpress-batch-rce-lab
https://github.com/vulnquest58/PressVector
https://github.com/bahartanir/wp2shell-scanner
https://github.com/ikow/wp2shell
https://github.com/0xBlackash/CVE-2026-63030
https://github.com/ananay/wp2shell-lab
https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t
https://github.com/zeroc00I/CVE-2026-63030
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030
https://github.com/0xh7ml/CVE-2026-63030
https://github.com/mrx-arafat/CVE-2026-63030-POC
https://github.com/47Cid/wp2shell-lab
https://github.com/mverschu/CVE-2026-63030
https://github.com/administrator-01001/CVE-2026-63030
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/fullhunt/wp2shell-scan
https://github.com/dinosn/wp2shell-lab
https://github.com/ebrasha/abdal-cve-2026-63030
https://github.com/Icex0/wp2shell-poc
https://github.com/ChiefYoru/CVE-2026-63030_PoC
https://github.com/raphy76/wp2shell-poc-fulljs
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/gbrsh/CVE-2026-63030
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/h4cd0c/wp2shell
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/zi3lak/wp2shell_scanner
https://github.com/mcipekci/wp2shell
(CISA TS-SOC) CVE-2026-60137 โ WordPress Core SQL Injection Vulnerability
Severity: MEDIUM Impact Summary: Allows unauthenticated attackers to perform SQL injection, which can be chained with CVE-2026-63030 to achieve remote code execution on default WordPress installations....
##(CISA TS-SOC) CVE-2026-63030 โ WordPress Core Interpretation Conflict Vulnerability
Severity: CRITICAL Impact Summary: An attacker can exploit an interpretation conflict in WordPress Core to perform SQL Injection, which may be chained to achieve Remote Code Execution....
##1 posts
42 repos
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/ebrasha/abdal-cve-2026-60137
https://github.com/ekomsSavior/wp2shell
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/kulichr/wp2shell
https://github.com/Crypto-Cat/wp2shell
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/shinthink/CVE-2026-63030
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/Iqbalx7/wp2shell
https://github.com/NULL200OK/WP2Shell
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/yoerivegt/wp2shell-poc
https://github.com/0xjessie21/wp2shell-checker
https://github.com/0xWhoknows/wp2shell
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/securelayer7/WordPresShell
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/vulnquest58/PressVector
https://github.com/bahartanir/wp2shell-scanner
https://github.com/ikow/wp2shell
https://github.com/ananay/wp2shell-lab
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/47Cid/wp2shell-lab
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/dinosn/wp2shell-lab
https://github.com/Icex0/wp2shell-poc
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/h4cd0c/wp2shell
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/zi3lak/wp2shell_scanner
(CISA TS-SOC) CVE-2026-60137 โ WordPress Core SQL Injection Vulnerability
Severity: MEDIUM Impact Summary: Allows unauthenticated attackers to perform SQL injection, which can be chained with CVE-2026-63030 to achieve remote code execution on default WordPress installations....
##