## Updated at UTC 2026-09-29T08:50:30.842467

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-86950 8.8 0.00% 11 0 2026-09-29T08:17:21.447000 An out-of-bounds write issue was addressed with improved bounds checking. This i
CVE-2026-88771 9.8 0.00% 49 6 2026-09-29T04:18:01.603000 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc
CVE-2026-82384 9.8 0.00% 1 1 2026-09-29T04:18:00.500000 Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticat
CVE-2026-12342 9.6 0.00% 1 0 2026-09-29T04:17:55.873000 This vulnerability impacts all versions of IdentityIQ and allows an unauthentica
CVE-2026-102422 8.1 0.00% 2 0 2026-09-29T04:17:55.707000 shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by
CVE-2026-101878 7.5 0.00% 2 0 2026-09-29T03:30:47 Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of
CVE-2026-101860 8.8 0.00% 2 0 2026-09-29T03:30:47 A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this
CVE-2026-102240 10.0 0.00% 4 0 2026-09-29T02:16:55.153000 A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the
CVE-2026-101354 9.6 0.00% 4 0 2026-09-29T02:16:53.230000 A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affecte
CVE-2026-102361 9.1 0.00% 4 0 2026-09-29T00:17:03.183000 mall4j through 4.0 contains a missing authentication vulnerability in the PUT /u
CVE-2026-101264 9.1 0.00% 4 0 2026-09-29T00:17:02.663000 A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unk
CVE-2026-101263 9.1 0.00% 2 0 2026-09-29T00:17:01.540000 A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some
CVE-2026-101261 9.1 0.00% 2 0 2026-09-28T23:17:01.003000 A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown par
CVE-2026-100655 0 0.00% 1 0 2026-09-28T22:17:30.120000 Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-96760 0 0.00% 2 0 2026-09-28T21:17:19.650000 Authlib (v1.7.2 and below) contains a signature verification bypass vulnerabilit
CVE-2026-100844 8.4 0.00% 1 0 2026-09-28T21:03:04.910000 MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner c
CVE-2026-100840 7.8 0.00% 1 0 2026-09-28T21:03:04.910000 MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle
CVE-2026-100845 7.8 0.00% 1 0 2026-09-28T21:03:04.910000 MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the Numpy
CVE-2026-100627 8.1 0.00% 1 0 2026-09-28T20:57:50.143000 Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect
CVE-2026-100622 7.5 0.00% 1 0 2026-09-28T20:57:50.143000 capgo.app through 12.129.0 fails to verify deletion status when serving cached b
CVE-2026-100865 8.8 0.00% 1 0 2026-09-28T20:57:50.143000 Heym before 0.0.53 evaluates workflow condition expressions using Python's eval(
CVE-2026-100871 8.8 0.00% 1 0 2026-09-28T20:55:27.360000 Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to incl
CVE-2026-101065 9.8 0.00% 1 0 2026-09-28T20:55:27.360000 Obot is an open-source AI agent/MCP platform. In all versions up to and includin
CVE-2026-100846 7.6 0.00% 1 0 2026-09-28T20:53:43.443000 MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in
CVE-2026-86102 0 0.00% 1 0 2026-09-28T20:51:05.473000 An OS command injection vulnerability in the WatchGuard AP internal API service
CVE-2026-100850 7.7 0.00% 1 0 2026-09-28T20:51:05.473000 AzuraCast before 0.23.8 contains a server-side request forgery and local file re
CVE-2026-87969 None 0.00% 1 0 2026-09-28T18:31:33 An OS command injection vulnerability in the WatchGuard AP diagnostic CLI allows
CVE-2026-101891 None 0.00% 1 0 2026-09-28T18:31:33 An improper access control vulnerability in an internal API service on WatchGuar
CVE-2026-101081 9.1 0.00% 1 0 2026-09-28T18:31:33 A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability
CVE-2026-88778 7.5 0.00% 5 1 2026-09-28T18:31:19 Predictable exact value from previous values vulnerability in Citrix NetScaler A
CVE-2026-100679 8.8 0.00% 1 0 2026-09-28T18:17:15.007000 stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authent
CVE-2026-88777 9.8 0.00% 2 1 2026-09-28T18:12:31.173000 Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix N
CVE-2026-88776 9.8 0.00% 2 1 2026-09-28T18:09:52.120000 Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix N
CVE-2026-100721 9.0 0.00% 2 1 2026-09-28T17:17:46.057000 vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module
CVE-2026-100711 7.5 0.00% 1 0 2026-09-28T17:17:45.767000 froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API k
CVE-2026-100684 8.1 0.00% 1 0 2026-09-28T17:17:45.093000 Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the O
CVE-2026-100672 7.5 0.00% 1 0 2026-09-28T17:17:44.670000 The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version
CVE-2026-100660 7.5 0.00% 1 0 2026-09-28T17:17:44.247000 Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.1
CVE-2026-86609 8.8 0.00% 1 0 2026-09-28T16:38:58.950000 The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape
CVE-2026-100690 7.5 0.00% 1 0 2026-09-28T16:37:02.187000 Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css
CVE-2026-100693 8.4 0.00% 1 0 2026-09-28T16:37:02.187000 Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation
CVE-2026-100686 8.1 0.00% 1 0 2026-09-28T16:36:05.010000 Budibase versions before 3.45.0 fail to validate per-app authorization in the PO
CVE-2026-73640 None 0.00% 1 0 2026-09-28T15:32:02 Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password rec
CVE-2026-88774 7.2 0.00% 2 1 2026-09-28T15:31:46 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-88775 9.8 0.00% 2 1 2026-09-28T15:31:46 Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gatew
CVE-2026-88773 10.0 0.00% 3 1 2026-09-28T15:31:46 Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling')
CVE-2026-100838 8.1 0.00% 1 0 2026-09-28T15:23:38.510000 Contrast is a confidential-computing runtime for Kubernetes. In versions before
CVE-2026-100705 7.6 0.00% 1 0 2026-09-28T15:20:06.633000 Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default
CVE-2026-100740 9.9 0.00% 2 1 2026-09-28T15:17:11.597000 A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the funct
CVE-2026-100716 9.9 0.00% 1 0 2026-09-28T15:17:11.427000 Froxlor is a server administration panel. In versions 2.3.10 and earlier, the cu
CVE-2026-100704 7.7 0.00% 1 0 2026-09-28T15:17:10.903000 Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, th
CVE-2026-101039 10.0 0.00% 1 0 2026-09-28T15:16:04.793000 A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this
CVE-2026-100886 10.0 0.00% 2 1 2026-09-28T15:16:04.793000 A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4
CVE-2026-85984 9.8 0.00% 2 1 2026-09-28T15:16:04.793000 The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPres
CVE-2026-101001 10.0 0.00% 1 0 2026-09-28T15:15:33.930000 A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impac
CVE-2026-101060 8.2 0.00% 1 0 2026-09-28T14:17:13.093000 python-utcp versions before 1.1.4 contain a server-side request forgery vulnerab
CVE-2026-88772 8.1 0.00% 29 5 2026-09-28T12:32:09 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-81867 None 0.00% 1 0 2026-09-28T12:31:13 A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Goog
CVE-2026-101009 8.4 0.00% 1 0 2026-09-28T09:30:34 A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected eleme
CVE-2026-101002 9.9 0.00% 2 0 2026-09-28T06:31:23 A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affec
CVE-2026-101000 10.0 0.00% 1 0 2026-09-28T06:31:23 A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affec
CVE-2026-100908 7.5 0.00% 1 0 2026-09-28T06:31:18 A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown f
CVE-2026-100896 9.9 0.00% 2 0 2026-09-28T03:30:34 A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected
CVE-2026-96896 7.2 0.00% 1 0 2026-09-28T03:30:27 The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19
CVE-2026-81655 7.5 0.00% 2 0 2026-09-28T03:30:25 The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict acce
CVE-2026-101084 9.6 0.00% 2 0 2026-09-27T21:31:10 obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-co
CVE-2026-101090 9.8 0.00% 2 0 2026-09-27T21:31:10 Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect e
CVE-2026-101064 7.6 0.00% 1 0 2026-09-27T21:31:10 Obot before v0.23.0 contains a server-side request forgery vulnerability in remo
CVE-2026-101062 8.8 0.00% 1 0 2026-09-27T21:31:10 Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENAB
CVE-2026-101045 8.0 0.00% 1 0 2026-09-27T18:30:34 Fleet-maintained app install and uninstall scripts for macOS are generated from
CVE-2026-100673 8.2 0.00% 1 0 2026-09-27T17:16:55.343000 The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 th
CVE-2026-100872 7.5 0.00% 1 0 2026-09-27T15:31:14 Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during
CVE-2026-100870 8.8 0.00% 1 0 2026-09-27T15:31:08 Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build admini
CVE-2026-89136 None 0.00% 2 0 2026-09-27T12:30:28 When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2
CVE-2026-93302 None 0.00% 2 0 2026-09-27T12:30:21 MatchTrustedPeer ignores the public key used, leading to forged CA clones passin
CVE-2026-100741 9.8 0.00% 2 0 2026-09-27T09:31:17 Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's
CVE-2026-100843 7.8 0.00% 1 0 2026-09-27T03:31:13 MONAI versions before 1.6.0 contain a remote code execution vulnerability in the
CVE-2026-100839 8.4 0.00% 1 0 2026-09-27T03:31:13 Contrast is a confidential-computing runtime for Kubernetes. In versions before
CVE-2026-100847 7.5 0.00% 1 0 2026-09-27T03:31:13 AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder
CVE-2026-100851 7.6 0.00% 1 0 2026-09-27T03:31:13 AzuraCast before 0.23.8 contains a broken access control vulnerability in the GE
CVE-2026-100857 8.0 0.00% 1 0 2026-09-27T03:31:13 AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWri
CVE-2026-100856 8.8 0.00% 1 0 2026-09-27T03:31:13 AzuraCast before 0.23.6 contains a code injection vulnerability in the remote re
CVE-2026-100864 8.8 0.00% 1 0 2026-09-27T03:31:13 heym before 0.0.91 contains a sandbox escape vulnerability in the expression eng
CVE-2026-100723 7.5 0.00% 1 0 2026-09-27T03:31:12 vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (b
CVE-2026-100833 8.2 0.00% 1 0 2026-09-27T03:31:12 Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime p
CVE-2026-100835 7.4 0.00% 1 1 2026-09-27T03:31:12 Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contr
CVE-2026-100841 7.8 0.00% 1 0 2026-09-27T03:31:12 In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the
CVE-2026-100852 8.8 0.00% 1 0 2026-09-27T03:31:12 AzuraCast through 0.23.x contains a command injection vulnerability in the Liqui
CVE-2026-84388 9.6 0.00% 1 1 2026-09-27T00:16:35.007000 A improper restriction of rendered ui layers or frames vulnerability in Fortinet
CVE-2026-100720 8.7 0.00% 1 0 2026-09-26T23:16:33.660000 Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When
CVE-2026-100713 7.8 0.00% 1 0 2026-09-26T23:16:33.173000 Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race con
CVE-2026-82901 9.8 0.00% 2 1 2026-09-26T21:30:34 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitr
CVE-2026-77203 8.8 0.00% 1 0 2026-09-26T18:31:09 The Groups – Memberships and Access Control plugin for WordPress is vulnerable t
CVE-2026-100715 9.6 0.00% 1 0 2026-09-26T15:31:32 Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink foll
CVE-2026-100707 7.7 0.00% 1 0 2026-09-26T15:31:28 Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall conte
CVE-2026-100717 9.9 0.00% 1 0 2026-09-26T15:31:28 froxlor is a server administration panel. In versions 2.3.10 and earlier, Valida
CVE-2026-100671 8.0 0.00% 1 0 2026-09-26T15:31:27 Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 throug
CVE-2026-100676 8.2 0.00% 1 0 2026-09-26T15:31:27 January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), befor
CVE-2026-100685 7.7 0.00% 1 0 2026-09-26T15:31:27 Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint
CVE-2026-100683 8.0 0.00% 1 0 2026-09-26T15:31:27 Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename D
CVE-2026-100682 8.8 0.00% 1 0 2026-09-26T15:31:27 Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in
CVE-2026-100680 8.1 0.00% 1 0 2026-09-26T15:31:27 Budibase versions before 3.45.0 fail to disable external JSON reference resoluti
CVE-2026-100697 8.6 0.00% 1 0 2026-09-26T15:31:27 Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins
CVE-2026-100706 9.9 0.00% 1 0 2026-09-26T15:31:27 kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Po
CVE-2026-100703 7.7 0.00% 1 0 2026-09-26T15:31:27 Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its
CVE-2026-100709 7.5 0.00% 1 0 2026-09-26T15:31:27 Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (p
CVE-2026-100714 9.1 0.00% 1 0 2026-09-26T15:31:27 Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchalleng
CVE-2026-100664 7.5 0.00% 1 0 2026-09-26T15:31:26 Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4
CVE-2026-100670 8.8 0.00% 1 0 2026-09-26T15:31:26 Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in
CVE-2026-100669 7.5 0.00% 1 0 2026-09-26T15:31:26 Grav before 2.0.25 ships web server configuration samples whose access-control d
CVE-2026-100700 7.5 0.00% 1 0 2026-09-26T15:31:24 nodemailer before 10.0.6 contains a denial of service vulnerability in the addre
CVE-2026-100656 7.5 0.00% 1 0 2026-09-26T15:31:23 Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue gro
CVE-2026-100662 7.5 0.00% 1 0 2026-09-26T15:31:23 Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4
CVE-2026-100661 7.5 0.00% 1 0 2026-09-26T15:31:23 Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4
CVE-2026-100692 7.5 0.00% 1 0 2026-09-26T15:31:23 Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0,
CVE-2026-100639 8.8 0.00% 1 0 2026-09-26T15:31:22 SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gu
CVE-2026-100637 7.6 0.00% 1 0 2026-09-26T15:31:22 SiYuan versions before v3.8.4 contain a path traversal vulnerability in the chec
CVE-2026-100636 7.6 0.00% 1 0 2026-09-26T15:31:22 SiYuan versions before v3.8.4 contain a path traversal vulnerability in the expo
CVE-2026-100646 8.1 0.00% 1 0 2026-09-26T15:31:22 SiYuan is a self-hosted personal knowledge management system. In versions up to
CVE-2026-100644 7.5 0.00% 1 0 2026-09-26T15:31:22 SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query e
CVE-2026-100642 7.6 0.00% 1 0 2026-09-26T15:31:22 SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery v
CVE-2026-100657 7.5 0.00% 1 0 2026-09-26T15:31:22 Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in Stom
CVE-2026-100663 7.5 0.00% 1 0 2026-09-26T15:31:22 Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.1
CVE-2026-100631 7.5 0.00% 1 0 2026-09-26T15:31:21 Parse Server is an open source backend server. In versions prior to 8.6.90 and i
CVE-2026-100643 8.0 0.00% 1 0 2026-09-26T15:31:21 SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View
CVE-2026-100665 7.5 0.00% 1 0 2026-09-26T15:31:19 Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostn
CVE-2026-100623 8.8 0.00% 1 0 2026-09-26T15:31:16 Capgo (capgo.app) exposes the legacy membership table public.org_users directly
CVE-2026-100645 8.0 0.00% 1 0 2026-09-26T14:16:46.857000 SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnera
CVE-2026-100641 8.0 0.00% 1 0 2026-09-26T14:16:46.193000 SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before
CVE-2026-100638 7.6 0.00% 1 0 2026-09-26T14:16:45.590000 SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setN
CVE-2026-65660 6.5 0.00% 3 2 2026-09-25T18:32:20 Improper control of generation of code ('code injection') in Microsoft Office Sh
CVE-2026-85542 8.8 0.00% 1 0 2026-09-25T15:31:48 IBM Guardium Data Protection 12.2 is affected by a command injection vulnerabili
CVE-2026-62062 8.8 0.00% 3 1 2026-09-25T09:31:05 Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder all
CVE-2026-14281 9.8 0.00% 1 3 2026-09-25T09:31:05 The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Co
CVE-2026-48842 8.1 0.00% 1 2 2026-09-25T04:17:35.357000 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authenticat
CVE-2026-61743 6.3 0.00% 1 0 2026-09-24T21:25:27.050000 Chartbrew is an open-source web application that can connect directly to databas
CVE-2026-61652 0 0.00% 1 0 2026-09-24T21:25:27.050000 Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of
CVE-2026-55074 0 0.00% 1 0 2026-09-24T21:25:27.050000 Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeB
CVE-2026-15027 8.8 0.00% 1 0 2026-09-24T14:45:22.827000 CGServiSign developed by Changing has a OS Command Injection vulnerability. Unau
CVE-2026-94097 10.0 0.00% 1 0 2026-09-24T13:17:17.460000 A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affec
CVE-2026-76978 8.8 0.00% 1 0 2026-09-24T04:17:59.137000 ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and belo
CVE-2026-93340 6.8 0.00% 1 0 2026-09-23T16:16:48.007000 Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerabi
CVE-2026-43641 9.8 0.00% 1 0 2026-09-23T16:16:43.407000 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command
CVE-2026-19599 9.9 0.00% 1 0 2026-09-23T15:30:51 ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable
CVE-2026-93616 9.8 0.00% 1 1 2026-09-22T21:31:15 A directory traversal and file upload vulnerability allows an unauthenticated at
CVE-2026-91827 7.5 0.00% 1 0 2026-09-22T19:41:38.447000 The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form fie
CVE-2026-94117 7.6 0.00% 1 0 2026-09-22T19:04:55.677000 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-74849 9.8 0.00% 1 0 2026-09-22T12:30:32 Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerab
CVE-2026-9231 7.5 0.00% 1 0 2026-09-22T09:31:22 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for W
CVE-2026-6922 7.1 0.00% 1 0 2026-09-22T09:31:17 The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnera
CVE-2026-12470 7.2 0.00% 1 0 2026-09-22T06:30:35 The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress i
CVE-2026-80521 7.8 0.00% 1 1 2026-09-21T14:17:20.193000 In the Linux kernel, the following vulnerability has been resolved: af_unix: Un
CVE-2026-94098 9.1 0.00% 1 0 2026-09-21T03:30:22 A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulne
CVE-2026-82890 5.9 0.00% 1 0 2026-09-18T21:32:36 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-10747 10.0 0.00% 2 0 2026-09-18T18:31:55 IBM MQ Appliance could allow a remote attacker to cause a denial of service or p
CVE-2026-89775 9.3 0.00% 1 0 2026-09-16T18:31:58 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64:
CVE-2026-43786 7.8 0.00% 1 2 2026-09-15T19:32:06.417000 This issue was addressed with additional entitlement checks. This issue is fixed
CVE-2026-86060 9.8 0.00% 1 5 2026-09-11T15:32:27 RouterOS contains an argument-handling flaw in the SSH login path involving user
CVE-2026-0310 0 0.00% 1 0 2026-09-11T04:17:13.060000 A buffer overflow vulnerability in the XML processing functionality of Palo Alto
CVE-2026-27962 9.1 0.00% 2 0 2026-09-10T13:18:01.463000 Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior
CVE-2026-8452 9.8 0.00% 2 6 2026-08-27T04:18:00.787000 Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp
CVE-2026-15742 8.8 0.00% 2 0 2026-08-13T15:34:40 Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to
CVE-2026-58052 3.3 0.00% 1 0 2026-08-07T20:47:38.443000 7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extra
CVE-2026-26740 8.2 0.00% 1 0 2026-07-23T12:17:15.660000 Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to caus
CVE-2026-54514 5.3 0.00% 1 1 2026-07-20T21:21:20 ## Summary `JDKFromStringDeserializer` constructed `InetSocketAddress` with `new
CVE-2026-20700 7.8 0.00% 1 2 2026-06-17T10:17:43.440000 A memory corruption issue was addressed with improved state management. This iss
CVE-2026-35273 9.8 0.00% 3 4 template 2026-06-12T18:31:50 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS
CVE-2026-28802 None 0.00% 2 0 2026-03-06T21:56:56 ### Summary After upgrading the library from 1.5.2 to 1.6.0 (and the latest 1.6.
CVE-2023-3519 9.8 99.75% 2 15 2025-10-22T00:33:51 Unauthenticated remote code execution
CVE-2026-92142 0 0.00% 2 0 N/A
CVE-2026-87799 0 0.00% 2 0 N/A
CVE-2026-69227 0 0.00% 2 0 N/A
CVE-2026-97381 0 0.00% 2 0 N/A
CVE-2026-87902 0 0.00% 3 25 N/A
CVE-2026-101894 0 0.00% 1 1 N/A
CVE-2026-54160 0 0.00% 1 0 N/A
CVE-2026-32740 0 0.00% 1 1 N/A
CVE-2026-887712 0 0.00% 1 0 N/A
CVE-2026-96280 0 0.00% 1 0 N/A

CVE-2026-86950
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-29T08:17:21.447000

11 posts

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions o

571906@ap.podcastindex.org at 2026-09-29T02:00:02.000Z ##

New Episode: SANS Stormcast Tuesday, September 29th, 2026: MacOS/iOS 0-Day Patch; macOS priv. escalation 0-day; File Notification Attacks

Shownotes:

Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950)
https://isc.sans.edu/diary/Apple%20Emergency%20Patch%20for%20iOS%2026%2C%20macOS26%2C%20macOS15%20%28CVE-2026-86950%29/33376
https://support.apple.com/en-us/100100
Pro

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

DailyCyberSecurity at 2026-09-29T03:30:05.073Z ##

Learn about the critical CVE-2026-86950 zero-day vulnerability patched in iOS 26.7.1. Discover how this CoreGraphics flaw could lead to malicious code execution.

securityexpress.info/apple-pat

##

DailyCyberSecurity at 2026-09-29T00:22:48.050Z ##

Apple patched an exploited Apple zero-day vulnerability. Learn how this Apple zero-day vulnerability impacts devices and install emergency updates now.

securityonline.info/exploited-

##

undercodenews@mastodon.social at 2026-09-28T22:14:21.000Z ##

Apple Rushes Out Security Updates After Exploited CoreGraphics Flaw Targets Older iPhones, iPads and Macs + Video

Apple Warns of Targeted Attacks Exploiting a Serious Security Vulnerability Apple has released emergency security updates for older versions of its operating systems after confirming that a newly disclosed vulnerability may have been exploited in highly targeted attacks. The flaw, tracked as CVE-2026-86950, affects Apple's CoreGraphics component and…

undercodenews.com/apple-rushes

##

sans_isc at 2026-09-28T22:06:23.937Z ##

Apple Emergency Patch for iOS 26/macOS26/macOS15 (CVE-2026-86950) isc.sans.edu/diary/33376

##

cyberworldops at 2026-09-28T20:50:00.474Z ##

Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics enabling arbitrary code execution via a malicious file. Apple states it may have been exploited in highly sophisticated attacks against specific users on iOS before iOS 27. Immediate patching is critical for high-risk users.

cyberworldops.eu/en/apple-clos

##

DailyCyberSecurity@infosec.exchange at 2026-09-29T03:30:05.000Z ##

Learn about the critical CVE-2026-86950 zero-day vulnerability patched in iOS 26.7.1. Discover how this CoreGraphics flaw could lead to malicious code execution.

#AppleSecurity #iOSUpdate #ZeroDay #CyberSecurity #TechNews

securityexpress.info/apple-pat

##

DailyCyberSecurity@infosec.exchange at 2026-09-29T00:22:48.000Z ##

Apple patched an exploited Apple zero-day vulnerability. Learn how this Apple zero-day vulnerability impacts devices and install emergency updates now.

#Apple #iOS #macOS #CVE202686950 #ZeroDay #Cybersecurity #InfoSec

securityonline.info/exploited-

##

sans_isc@infosec.exchange at 2026-09-28T22:06:23.000Z ##

Apple Emergency Patch for iOS 26/macOS26/macOS15 (CVE-2026-86950) isc.sans.edu/diary/33376

##

cyberworldops@infosec.exchange at 2026-09-28T20:50:00.000Z ##

Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics enabling arbitrary code execution via a malicious file. Apple states it may have been exploited in highly sophisticated attacks against specific users on iOS before iOS 27. Immediate patching is critical for high-risk users. #AppleSecurity #CoreGraphics #IosSecurity

cyberworldops.eu/en/apple-clos

##

applsec@infosec.exchange at 2026-09-28T19:11:35.000Z ##

📣 EMERGENCY UPDATE 📣

Apple pushed updates for a new zero-day that may have been actively exploited.

🐛 CVE-2026-86950 (CoreGraphics):
- iOS and iPadOS 26.7.1
- macOS Sequoia 15.8.1
- macOS Tahoe 26.7.1

#apple #cybersecurity #infosec #security #ios

##

CVE-2026-88771
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-29T04:18:01.603000

49 posts

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

6 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/techupdate24/citrix-netscaler-cve-2026-88771-rce

https://github.com/EXEcution-py/CVE-2026-88771-POC

https://github.com/securekomodo/citrixInspector

https://github.com/technion/netscaler_scanner

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771

DailyCyberSecurity at 2026-09-29T04:44:47.686Z ##

CVE-2026-88771 is a Citrix NetScaler command injection exploited in the wild. Details and a PoC are public. Patch NetScaler to 14.1-73.37 now.

securityonline.info/citrix-net

##

youranonnewsirc@nerdculture.de at 2026-09-29T04:25:37.000Z ##

Recent global developments highlight escalating cybersecurity risks and geopolitical tensions. AI-powered attacks are rapidly exploiting vulnerabilities, with threat actors leveraging agentic workflows for credential harvesting. In response, Nvidia has launched its Open Agent Safety Platform to manage rogue AI agents. Meanwhile, CISA has issued a critical warning regarding actively exploited Citrix NetScaler zero-day flaws (CVE-2026-88771, CVE-2026-88772).

On the geopolitical front, a new US-Saudi civilian nuclear pact has raised significant proliferation concerns, as Saudi Arabia has not ruled out developing nuclear weapons.

#Cybersecurity #AI #Geopolitics

##

undercodenews@mastodon.social at 2026-09-29T01:26:39.000Z ##

Citrix NetScaler Zero-Days Exploited in the Wild as Customers Waited for Official Warning + Video

A Dangerous Weekend of Uncertainty Citrix has released emergency patches for two critical NetScaler vulnerabilities that were already being exploited in the wild, but the company’s delayed public confirmation left cybersecurity teams scrambling for answers during much of the weekend. The vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, affect Citrix NetScaler…

undercodenews.com/citrix-netsc

##

DarkWebInformer at 2026-09-28T23:10:32.163Z ##

CVE-2026-88771: Detection Artifact Generator for Citrix NetScaler

GitHub: github.com/watchtowrlabs/watch

##

DarkWebInformer at 2026-09-28T22:57:43.962Z ##

citrixInspector: Passively identify Citrix ADC / NetScaler ADC & Gateway builds and check for known vulnerabilities, including CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and KEV-listed CVE-2026-88771/88772.

GitHub: github.com/securekomodo/citrix

##

GossiTheDog@cyberplace.social at 2026-09-28T22:49:57.000Z ##

Technical write up of the latest Citrix Netscaler incident, which I’m calling PitScaler - you’ll find out why from this:

cert.europa.eu/blog/taking-exe

You may notice it matches the hunting hints earlier in this thread. Guess who found it first :annoyingdog:

It’s a really interesting vuln scenario. I’m tracking over 100 victim orgs now. Each one has a unique webshell which can’t be scanned for remotely unless you’re the attacker. It’s espionage.

##

netsecio@mastodon.social at 2026-09-28T22:34:28.000Z ##

📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack

Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE

🔗 cyber.netsecops.io/articles/ci

##

patrickcmiller at 2026-09-28T21:42:02.279Z ##

Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) labs.watchtowr.com/oh-look-the

##

Matchbook3469@mastodon.social at 2026-09-28T21:39:22.000Z ##

🔵 THREAT INTELLIGENCE

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Vulnerability | CRITICAL
CVEs: CVE-2026-88771, CVE-2026-88772

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being...

Full analysis:
yazoul.net/news/article/citrix

by Yazoul AI

#ThreatIntel #Malware #SecurityOps

##

cyberveille@mastobot.ping.moi at 2026-09-28T21:30:05.000Z ##

📢 Citrix NetScaler : injection de commandes pré-auth exploitée en zero-day (CVE-2026-88771)

Cet article présente l'analyse technique détaillée de CVE-2026-88771, une vulnérabilité d'injection de commandes pré-authentification affectant Citrix NetScaler ADC et NetScaler Gateway, exploitée activement en zero-day avant la publication de tout correctif.

📖 cyberveille : cyberveille.ch/posts/2026-09-2
🌐 source : labs.watchtowr.com/oh-look-the
🟢 vérification factuelle haute
#CitrixNetScaler #ZeroDay #Cyberveille

##

censys at 2026-09-28T21:22:52.979Z ##

🚨RAPID RESPONSE: Two critical Citrix NetScaler vulnerabilities are being actively exploited as zero-days.

CVE-2026-88771 and CVE-2026-88772 can each lead to remote code execution.

Censys currently observes 42,735 Internet-exposed NetScaler ADC or Gateway hosts. Censys ARC breaks down the exposed population, exploitation status, patches, and guidance for defenders.

Read the advisory: censys.com/advisory/cve-2026-1

##

cyberveille@mastobot.ping.moi at 2026-09-28T20:30:05.000Z ##

📢 Deux zero-days critiques NetScaler (CVE-2026-88771 et CVE-2026-88772) exploités activement

🔍 Vulnérabilités identifiées Citrix a publié le bulletin de sécurité CTX697096 confirmant deux failles critiques : CVE-2026-88771 (score CVSS 9.5) : Exécution de code à distance via une validation d'entrée incorrecte, exploitable sans authentification, affectant…

📖 cyberveille : cyberveille.ch/posts/2026-09-2
🌐 source : bleepingcomputer.com/news/secu
🟡 vérification factuelle moyenne
#NetScaler #ZeroDay #Cyberveille

##

DailyCyberSecurity@infosec.exchange at 2026-09-29T04:44:47.000Z ##

CVE-2026-88771 is a Citrix NetScaler command injection exploited in the wild. Details and a PoC are public. Patch NetScaler to 14.1-73.37 now.

#Citrix #NetScaler #CVE202688771 #CommandInjection #ZeroDay #ExploitedInTheWild #PoC #PatchNow

securityonline.info/citrix-net

##

youranonnewsirc@nerdculture.de at 2026-09-29T04:25:37.000Z ##

Recent global developments highlight escalating cybersecurity risks and geopolitical tensions. AI-powered attacks are rapidly exploiting vulnerabilities, with threat actors leveraging agentic workflows for credential harvesting. In response, Nvidia has launched its Open Agent Safety Platform to manage rogue AI agents. Meanwhile, CISA has issued a critical warning regarding actively exploited Citrix NetScaler zero-day flaws (CVE-2026-88771, CVE-2026-88772).

On the geopolitical front, a new US-Saudi civilian nuclear pact has raised significant proliferation concerns, as Saudi Arabia has not ruled out developing nuclear weapons.

#Cybersecurity #AI #Geopolitics

##

DarkWebInformer@infosec.exchange at 2026-09-28T23:10:32.000Z ##

CVE-2026-88771: Detection Artifact Generator for Citrix NetScaler

GitHub: github.com/watchtowrlabs/watch

##

DarkWebInformer@infosec.exchange at 2026-09-28T22:57:43.000Z ##

citrixInspector: Passively identify Citrix ADC / NetScaler ADC & Gateway builds and check for known vulnerabilities, including CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and KEV-listed CVE-2026-88771/88772.

GitHub: github.com/securekomodo/citrix

##

GossiTheDog@cyberplace.social at 2026-09-28T22:49:57.000Z ##

Technical write up of the latest Citrix Netscaler incident, which I’m calling PitScaler - you’ll find out why from this:

cert.europa.eu/blog/taking-exe

You may notice it matches the hunting hints earlier in this thread. Guess who found it first :annoyingdog:

It’s a really interesting vuln scenario. I’m tracking over 100 victim orgs now. Each one has a unique webshell which can’t be scanned for remotely unless you’re the attacker. It’s espionage.

##

patrickcmiller@infosec.exchange at 2026-09-28T21:42:02.000Z ##

Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) labs.watchtowr.com/oh-look-the

##

censys@infosec.exchange at 2026-09-28T21:22:52.000Z ##

🚨RAPID RESPONSE: Two critical Citrix NetScaler vulnerabilities are being actively exploited as zero-days.

CVE-2026-88771 and CVE-2026-88772 can each lead to remote code execution.

Censys currently observes 42,735 Internet-exposed NetScaler ADC or Gateway hosts. Censys ARC breaks down the exposed population, exploitation status, patches, and guidance for defenders.

Read the advisory: censys.com/advisory/cve-2026-1

#Cybersecurity #Citrix #NetScaler #VulnerabilityManagement #CensysARC

##

ssvc@infosec.exchange at 2026-09-28T17:18:37.000Z ##

GreyNoise saw CVE-2026-88771 exploitation attempts on Sep 24, more than three days before public disclosure. Some IOC are listed.

greynoise.io/blog/swarming-aga

#threatintel #citrix #netscaler #zeroday #CVE

##

thenextweb@flipboard.com at 2026-09-28T16:42:18.000Z ##

Hackers are exploiting two critical Citrix NetScaler zero-days
thenextweb.com/news/citrix-net

Posted into TNW - All Stories @tnw-all-stories-thenextweb

##

AAKL@infosec.exchange at 2026-09-28T16:45:24.000Z ##

Tenable, posted yesterday: Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities tenable.com/blog/frequently-as @tenablesecurity

GreyNoise: Swarming Against Citrix 0-Day Exploitation greynoise.io/blog/swarming-aga @greynoise

WatchTower: Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) labs.watchtowr.com/oh-look-the #vulnerability #Citrix #NetScaler

@ifin

##

youranonnewsirc@nerdculture.de at 2026-09-28T16:25:41.000Z ##

Here's a summary of the latest geopolitical, technology, and cybersecurity news:

Geopolitically, US-Iran tensions remain high after President Trump rejected a Strait of Hormuz proposal, with ongoing investigations into potential terror links to Iran after arrests near a U.S.-operated air base in the UK. Russia has intensified attacks on Kyiv, while Ukraine reportedly recaptured territory in Donetsk.

In technology, OpenAI halted AI model training due to "rogue agent" incidents and unexpected behavior on government websites. Nvidia launched an Open Agent Safety Platform to enhance AI security.

Cybersecurity saw critical Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) actively exploited globally, prompting CISA to add them to its KEV catalog. Ransomware activity reached a 2026 high in August, with industrial sectors being the most targeted. A new Carbonato botnet targets Docker hosts to deploy a Telegram-controlled AI agent. Kiteworks also advised customers to temporarily shut down their platform due to credible threat intelligence.

#AnonNews_irc #Cybersecurity #News

##

christopherkunz@chaos.social at 2026-09-28T13:13:55.000Z ##

@bsi labs.watchtowr.com/oh-look-the
Ab wann gilt der Betrieb dieser Geräte eigentlich als fahrlässig?

##

bsi@social.bund.de at 2026-09-28T13:04:09.000Z ##

⚠️ 📢 Sicherheitswarnung: Am 27. September 2026 veröffentlichte der Hersteller #Citrix ein Advisory [CIT26a] zu insgesamt acht Sicherheitslücken in seinen Produkten NetScaler ADC (ehemals Citrix ADC) und NetScaler Gateway (ehemals Citrix Gateway). Hierin enthalten sind auch zwei #ZeroDay-Schwachstellen (CVE-2026-88771 und CVE-2026-88772), zu denen sich im Laufe des vergangenen Wochenendes Berichte über eine aktive Ausnutzung verbreitet hatten.

Mehr dazu hier: bsi.bund.de/dok/1209522

##

ssvc@infosec.exchange at 2026-09-28T12:16:27.000Z ##

CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.

cisa.gov/news-events/alerts/20

#CISA #KEV #Citrix #zeroday #CVE

##

_r_netsec@infosec.exchange at 2026-09-28T11:13:05.000Z ##

Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs labs.watchtowr.com/oh-look-the

##

youranonnewsirc@nerdculture.de at 2026-09-28T10:26:19.000Z ##

Critical Citrix NetScaler RCE zero-days (CVE-2026-88771/88772) are under active exploitation; urgent fixes released. OpenAI halted AI model training after agents went rogue on government sites. Geopolitically, US-Iran tensions persist over the Strait of Hormuz, with reports of missile attacks.

#Cybersecurity #Geopolitics #AnonNews_irc

##

benzogaga33@mamot.fr at 2026-09-28T09:40:04.000Z ##

« Éteignez vos NetScaler » : Citrix confirme 2 failles zero-day critiques déjà exploitées it-connect.fr/citrix-netscaler #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

oversecurity@mastodon.social at 2026-09-28T09:20:31.000Z ##

Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack

Citrix has released fixes for two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771

🔗️ [Thecyberexpress] link.is.it/oXuQ75

##

cert_fr@social.numerique.gouv.fr at 2026-09-28T09:00:19.000Z ##

⚠️ Alerte CERT-FR ⚠️
Les vulnérabilités CVE-2026-88771 et CVE-2026-88772 sont activement exploitées et permettent une RCE pré-authentification sur Citrix NetScaler ADC et Gateway.

cert.ssi.gouv.fr/alerte/CERTFR

##

tugatech@masto.pt at 2026-09-28T08:41:25.000Z ##

Citrix corrige 2 vulnerabilidades críticas no NetScaler exploradas em ataques. A empresa já disponibilizou atualizações de segurança para corrigir as falhas zero-day identificadas como CVE-2026-88771 e CVE-2026-88772. 🛡️

🔗 tugatech.com.pt/t91845-citrix-

 

##

threatnoir@infosec.exchange at 2026-09-28T08:06:09.000Z ##

⚠️ CRITICAL: Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix NetScaler ADC and Gateway appliances are under active attack via two unpatched RCE zero-days (CVE-2026-88771 and CVE-2026-88772). Unauthenticated attackers can execute arbitrary commands or trigger denial-of-service on vulnerable instances. Any organization running these appliances without t…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-28T07:05:59.000Z ##

⚠️ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler to the Known Exploited Vulnerabilities catalog due to active exploitation in the wild. These are remote code execution vectors being actively weaponized. Federal agencies and any organization running exposed NetScaler instances…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

ssvc@infosec.exchange at 2026-09-28T01:16:48.000Z ##

CISA working on a Sunday: Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-887712 were added to the Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

cisa.gov/news-event/alerts/202

#KEV #Citrix #NetScaler #zeroday #CVE

##

cisakevtracker@mastodon.social at 2026-09-27T23:01:08.000Z ##

CVE ID: CVE-2026-88771
Vendor: Citrix
Product: NetScaler
Date Added: 2026-09-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-09-27T23:00:11.000Z ##

🚨 [CISA-2026:0927] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-88771 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: community.citrix.com/techzone- ; support.citrix.com/support-hom ; support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-88772 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: community.citrix.com/techzone- ; support.citrix.com/support-hom ; support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260927 #cisa20260927 #cve_2026_88771 #cve_2026_88772 #cve202688771 #cve202688772

##

youranonnewsirc@nerdculture.de at 2026-09-27T22:26:18.000Z ##

Latest News (Sept 26-27, 2026): Geopolitically, President Trump rejected Iran's Strait of Hormuz reopening proposal. In technology, OpenAI halted AI model training due to reports of "rogue" agents. Cybersecurity saw CISA add two critical, actively exploited Citrix NetScaler RCE zero-days to its KEV catalog (CVE-2026-88771, CVE-2026-88772), while ShinyHunters resumed Oracle PeopleSoft attacks, bypassing WAFs.

#Cybersecurity #TechNews #Geopolitics

##

zackwhittaker@mastodon.social at 2026-09-27T20:04:46.000Z ##

Citrix has a security post on its website that also confirms exploitation and has a bunch of remedation advice, which you might not know because the company set the page to "noindex," so it doesn't show up in search results. 🤦‍♂️

community.citrix.com/techzone-

##

zackwhittaker@mastodon.social at 2026-09-27T19:56:16.000Z ##

CISA has confirmed two bugs in Citrix NetScaler are under attack, CVE-2026-88771 and CVE-2026-88772, per its catalog of known exploited vulnerabiliites. cisa.gov/known-exploited-vulne

Citrix has a support base article, confirming exploitation. support.citrix.com/support-hom

##

security_crawler_carl@infosec.exchange at 2026-09-27T19:42:16.000Z ##

🏆 New Achievement! Welcome to the Mandatory Exploit Tutorial!

Ah, new player. Before you proceed, the game would like to walk you through two compulsory debuffs. CVE-2026-88771 — CVSS 9.5, unauthenticated remote code execution via improper input validation — is applied automatically. No extra features required. Think of it as the tutorial that runs whether you clicked "Skip" or not. CVE-2026-88772 also joins the party, also scoring 9.5, because the game respects symmetry. (1/3)

##

cyberworldops@infosec.exchange at 2026-09-27T18:30:00.000Z ##

Citrix patched NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 after confirmed exploitation of unmitigated systems. Edge appliances remain high-value targets, and the September 27 release also fixes six other flaws requiring immediate patching. #Citrix #NetScaler #ZeroDay #VulnerabilityManagement

cyberworldops.eu/en/citrix-pat

##

jela@social.tchncs.de at 2026-09-27T17:31:47.000Z ##

Zusätzlich sehr nützliche Betriebs- und Incident-Response-Hinweise gibt es hier: cyberkendra.com/2026/09/cve-20

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

pedro@infosec.exchange at 2026-09-27T16:22:43.000Z ##

@watchTowr Thanks for being on top of it 💪
community.citrix.com/techzone-

##

DailyCyberSecurity@infosec.exchange at 2026-09-27T16:18:08.000Z ##

Two Citrix NetScaler zero-day RCE flaws are under active exploitation. Citrix confirmed CVE-2026-88771 and CVE-2026-88772 and shipped patches. Update now.

#Citrix #NetScaler #ZeroDay #RCE #CyberSecurity #VPN #watchTowr #PatchNow

securityonline.info/citrix-net

##

ssvc@infosec.exchange at 2026-09-27T15:56:01.000Z ##

Citrix NetScaler zero-days

Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.

This is a Monday problem for me, but you're better off knowing what to expect when coming into work tomorrow. h/t @mttaggart

support.citrix.com/support-hom

#citrix #netscaler #zeroday #cve

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

GossiTheDog@cyberplace.social at 2026-09-27T15:33:35.000Z ##

Netscaler CVEs are out:

support.citrix.com/support-hom

Patch isn’t yet through QA at Citrix still, been a week :02angery:

The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained.

It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.

Probably nation state aligned as well resourced, espionage rather than teens.

##

CVE-2026-82384
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-29T04:18:00.500000

1 posts

Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no

1 repos

https://github.com/murrez/CVE-2026-82384

offseq@infosec.exchange at 2026-09-28T09:00:26.000Z ##

Apache Roller 6.1.5 is vulnerable (CVE-2026-82384, CRITICAL, CVSS 9.8): unauthenticated remote deserialization can lead to RCE via XML-RPC — even if disabled. Upgrade to 6.1.6+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #ApacheRoller #CVE202682384 #infosec

##

CVE-2026-12342
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-29T04:17:55.873000

1 posts

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.

cR0w@infosec.exchange at 2026-09-28T18:54:15.000Z ##

You had one job.

sailpoint.com/security-advisor

sev:CRIT 9.6 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.

##

CVE-2026-102422
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-29T04:17:55.707000

2 posts

shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that later string therefore ends the comment, and the rest of the string is parsed as shell input: `quote(['echo', 'ok', { comment: 'x' }, 'a\nid;#'])` runs `id`

thehackerwire@mastodon.social at 2026-09-29T06:31:37.000Z ##

🟠 CVE-2026-102422 - High (8.1)

shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that late...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-29T06:31:37.000Z ##

🟠 CVE-2026-102422 - High (8.1)

shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that late...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101878
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-29T03:30:47

2 posts

Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQL Server deployments and allowing a user whose identity-provider identifier begins with another organization member's full 50-character iden

thehackerwire@mastodon.social at 2026-09-29T03:02:20.000Z ##

🟠 CVE-2026-101878 - High (7.5)

Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login ide...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-29T03:02:20.000Z ##

🟠 CVE-2026-101878 - High (7.5)

Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login ide...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101860
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-29T03:30:47

2 posts

A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted

thehackerwire@mastodon.social at 2026-09-29T03:02:11.000Z ##

🟠 CVE-2026-101860 - High (8.8)

A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation res...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-29T03:02:11.000Z ##

🟠 CVE-2026-101860 - High (8.8)

A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation res...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102240
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-29T02:16:55.153000

4 posts

A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not res

thehackerwire@mastodon.social at 2026-09-29T03:02:01.000Z ##

🔴 CVE-2026-102240 - Critical (10)

A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-29T03:00:24.455Z ##

CRITICAL: CVE-2026-102240 affects Netcore NAP930 v0.1.241010.141410. OS command injection in /www/cgi-bin/network_tools (sid arg). No patch, public exploit available. Isolate devices & monitor! radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-29T03:02:01.000Z ##

🔴 CVE-2026-102240 - Critical (10)

A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-29T03:00:24.000Z ##

CRITICAL: CVE-2026-102240 affects Netcore NAP930 v0.1.241010.141410. OS command injection in /www/cgi-bin/network_tools (sid arg). No patch, public exploit available. Isolate devices & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Netcore #Vulnerability #Infosec

##

CVE-2026-101354
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-29T02:16:53.230000

4 posts

A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have access to the local network to execute the attack. The exploit has been released to the public and may be used for attacks. The vendor was contacted early ab

thehackerwire@mastodon.social at 2026-09-29T06:31:45.000Z ##

🔴 CVE-2026-101354 - Critical (9.6)

A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-29T04:30:24.243Z ##

FAST FAC1203R (20200116_2.0.4) hit by CRITICAL stack-based buffer overflow (CVE-2026-101354, CVSS 9.4). Exploit is public; no patch. Local network access required. Restrict access + monitor for threats. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-29T06:31:45.000Z ##

🔴 CVE-2026-101354 - Critical (9.6)

A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-29T04:30:24.000Z ##

FAST FAC1203R (20200116_2.0.4) hit by CRITICAL stack-based buffer overflow (CVE-2026-101354, CVSS 9.4). Exploit is public; no patch. Local network access required. Restrict access + monitor for threats. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026101354 #IoTSecurity

##

CVE-2026-102361
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-29T00:17:03.183000

4 posts

mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.

thehackerwire@mastodon.social at 2026-09-29T06:31:54.000Z ##

🔴 CVE-2026-102361 - Critical (9.1)

mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to ov...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-29T00:00:35.435Z ##

CVE-2026-102361 in gz-yami mall4j (<=4.0): CRITICAL bug lets anyone reset any user password via PUT /user/updatePwd 🛡️. Enables account takeover and access to sensitive data. Patch ASAP! radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-29T06:31:54.000Z ##

🔴 CVE-2026-102361 - Critical (9.1)

mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to ov...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-29T00:00:35.000Z ##

CVE-2026-102361 in gz-yami mall4j (<=4.0): CRITICAL bug lets anyone reset any user password via PUT /user/updatePwd 🛡️. Enables account takeover and access to sensitive data. Patch ASAP! radar.offseq.com/threat/cve-20 #OffSeq #CVE2026102361 #infosec #ecommerce

##

CVE-2026-101264
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-29T00:17:02.663000

4 posts

A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

thehackerwire@mastodon.social at 2026-09-29T07:16:59.000Z ##

🔴 CVE-2026-101264 - Critical (9.1)

A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-29T01:30:24.329Z ##

Ziroom ZHOME A0101 v1.0.1.0 faces a CRITICAL (CVSS 9.4) command injection flaw (CVE-2026-101264) via /api/ZRnetwork/set_passwd. No patch, vendor silent. Restrict API access & monitor closely. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-29T07:16:59.000Z ##

🔴 CVE-2026-101264 - Critical (9.1)

A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-29T01:30:24.000Z ##

Ziroom ZHOME A0101 v1.0.1.0 faces a CRITICAL (CVSS 9.4) command injection flaw (CVE-2026-101264) via /api/ZRnetwork/set_passwd. No patch, vendor silent. Restrict API access & monitor closely. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026101264 #Infosec #IoT

##

CVE-2026-101263
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-29T00:17:01.540000

2 posts

A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

thehackerwire@mastodon.social at 2026-09-29T07:17:07.000Z ##

🔴 CVE-2026-101263 - Critical (9.1)

A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-29T07:17:07.000Z ##

🔴 CVE-2026-101263 - Critical (9.1)

A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101261
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T23:17:01.003000

2 posts

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

thehackerwire@mastodon.social at 2026-09-29T07:17:15.000Z ##

🔴 CVE-2026-101261 - Critical (9.1)

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-29T07:17:15.000Z ##

🔴 CVE-2026-101261 - Critical (9.1)

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100655
(0 None)

EPSS: 0.00%

updated 2026-09-28T22:17:30.120000

1 posts

Rejected reason: This CVE ID has been rejected as a duplicate.

thehackerwire@mastodon.social at 2026-09-28T01:30:44.000Z ##

🟠 CVE-2026-100655 - High (7.5)

Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final accept an unlimited number of concurrent remote-initiated SPDY streams: SpdySessionHandler defaults localConcurrentStreams to In...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96760
(0 None)

EPSS: 0.00%

updated 2026-09-28T21:17:19.650000

2 posts

Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.

DailyCyberSecurity at 2026-09-29T02:00:17.224Z ##

An Authlib signature bypass vulnerability (CVE-2026-96760, CVE-2026-28802, CVE-2026-27962) lets attackers forge JWS payloads. Update libraries now.

securityonline.info/authlib-si

##

DailyCyberSecurity@infosec.exchange at 2026-09-29T02:00:17.000Z ##

An Authlib signature bypass vulnerability (CVE-2026-96760, CVE-2026-28802, CVE-2026-27962) lets attackers forge JWS payloads. Update libraries now.

#Authlib #CVE202696760 #Cybersecurity #JWS #Vulnerability

securityonline.info/authlib-si

##

CVE-2026-100844
(8.4 HIGH)

EPSS: 0.00%

updated 2026-09-28T21:03:04.910000

1 posts

MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments are concatenated into a command string without quoting or validation and then passed to subprocess with shell=True, so shell metacharacters (e.g., ';' on

thehackerwire@mastodon.social at 2026-09-28T00:45:45.000Z ##

🟠 CVE-2026-100844 - High (8.4)

MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100840
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T21:03:04.910000

1 posts

MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malicious bundle with crafted configuration containing arbitrary code that executes when a victim loads the bundle using monai.bundle.load() or m

thehackerwire@mastodon.social at 2026-09-27T03:02:01.000Z ##

🟠 CVE-2026-100840 - High (7.8)

MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can pu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100845
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T21:03:04.910000

1 posts

MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payloads that execute arbitrary code when loaded through MONAI's standard data pipeline.

thehackerwire@mastodon.social at 2026-09-27T02:46:24.000Z ##

🟠 CVE-2026-100845 - High (7.8)

MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payload...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100627
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-28T20:57:50.143000

1 posts

Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle promotion path. The PUT /bundle endpoint, available to "all" and "write" API keys, dispatches to setChannel, which authorizes with checkPermission(c, 'channel.promote_bundle', { appId: body.app_id }) and omits the request's channel_id. Because the omitted scope field is passed t

thehackerwire@mastodon.social at 2026-09-28T07:17:12.000Z ##

🟠 CVE-2026-100627 - High (8.1)

Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle promotion path. The PUT /bundle endpoint, available to "all" and "write" API keys, dispatches to setChannel, which authorizes ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100622
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T20:57:50.143000

1 posts

capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint. Unauthenticated attackers can download deleted bundles using cached URLs and trigger restoration of deleted objects into R2 storage on cache hits.

thehackerwire@mastodon.social at 2026-09-28T07:16:54.000Z ##

🟠 CVE-2026-100622 - High (7.5)

capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint. Unauthenticated attackers can download deleted bundles using cached URLs and trigger restoration of deleted objects...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100865
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T20:57:50.143000

1 posts

Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes or import malicious templates to execute arbitrary Python and OS commands as the backend process user.

thehackerwire@mastodon.social at 2026-09-27T02:31:42.000Z ##

🟠 CVE-2026-100865 - High (8.8)

Heym before 0.0.53 contains multiple independent vulnerabilities. (1) The workflow condition evaluator uses Python eval() without an effective sandbox, allowing any user who can edit a workflow branch/condition node — or who can import a workflo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100871
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T20:55:27.360000

1 posts

Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator's email address and obtain a token that the Admin API resolves to that administrator, granting full administrative access.

thehackerwire@mastodon.social at 2026-09-28T00:30:37.000Z ##

🟠 CVE-2026-100871 - High (8.8)

Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator's emai...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101065
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T20:55:27.360000

1 posts

Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who ca

thehackerwire@mastodon.social at 2026-09-28T00:15:20.000Z ##

🔴 CVE-2026-101065 - Critical (9.8)

Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100846
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-28T20:53:43.443000

1 posts

MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining __reduce__ is executed during deserializati

thehackerwire@mastodon.social at 2026-09-27T02:46:33.000Z ##

🟠 CVE-2026-100846 - High (7.6)

MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86102
(0 None)

EPSS: 0.00%

updated 2026-09-28T20:51:05.473000

1 posts

An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.

CVE-2026-100850
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-28T20:51:05.473000

1 posts

AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the station Media permission can create or update a playlist with source=remote_url and remote_type=playlist whose remote_url points at a file:// path or an internal/loopback/link-local

thehackerwire@mastodon.social at 2026-09-27T02:32:42.000Z ##

🟠 CVE-2026-100850 - High (7.7)

AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the station Media permission can...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87969(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-28T18:31:33

1 posts

An OS command injection vulnerability in the WatchGuard AP diagnostic CLI allows an authenticated administrator to execute arbitrary operating system commands by supplying crafted input.

CVE-2026-101891(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-28T18:31:33

1 posts

An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.

CVE-2026-101081
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T18:31:33

1 posts

A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

thehackerwire@mastodon.social at 2026-09-28T17:30:59.000Z ##

🔴 CVE-2026-101081 - Critical (9.1)

A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88778
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T18:31:19

5 posts

Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.

1 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

secdb@infosec.exchange at 2026-09-27T23:00:11.000Z ##

🚨 [CISA-2026:0927] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-88771 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: community.citrix.com/techzone- ; support.citrix.com/support-hom ; support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-88772 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: community.citrix.com/techzone- ; support.citrix.com/support-hom ; support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260927 #cisa20260927 #cve_2026_88771 #cve_2026_88772 #cve202688771 #cve202688772

##

zackwhittaker@mastodon.social at 2026-09-27T20:04:46.000Z ##

Citrix has a security post on its website that also confirms exploitation and has a bunch of remedation advice, which you might not know because the company set the page to "noindex," so it doesn't show up in search results. 🤦‍♂️

community.citrix.com/techzone-

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

pedro@infosec.exchange at 2026-09-27T16:22:43.000Z ##

@watchTowr Thanks for being on top of it 💪
community.citrix.com/techzone-

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-100679
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T18:17:15.007000

1 posts

stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account and use it with a victim's session token to disable TOTP, view recovery codes, or perform other sensitive operations without providing the victim's creden

thehackerwire@mastodon.social at 2026-09-27T02:01:33.000Z ##

🟠 CVE-2026-100679 - High (8.8)

stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88777
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T18:12:31.173000

2 posts

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service

1 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-88776
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T18:09:52.120000

2 posts

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service

1 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-100721
(9.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T17:17:46.057000

2 posts

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-str

1 repos

https://github.com/murrez/CVE-2026-100721

thehackerwire@mastodon.social at 2026-09-28T01:00:53.000Z ##

🔴 CVE-2026-100721 - Critical (9)

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js reco...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-27T06:00:23.000Z ##

CVE-2026-100721: CRITICAL auth bypass in vm2 <3.12.2's NodeVM external-module resolver. Sandbox escape & arbitrary code exec possible. Upgrade to 3.12.2+ ASAP. radar.offseq.com/threat/vm2-be #OffSeq #CVE2026100721 #vm2 #infosec

##

CVE-2026-100711
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T17:17:45.767000

1 posts

froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.

thehackerwire@mastodon.social at 2026-09-27T00:16:25.000Z ##

🟠 CVE-2026-100711 - High (7.5)

froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100684
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-28T17:17:45.093000

1 posts

Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone — without validating an invite code and without an email_verified check (the email_verified gate protects only the existin

thehackerwire@mastodon.social at 2026-09-27T01:32:58.000Z ##

🟠 CVE-2026-100684 - High (8.1)

Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the Id...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100672
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T17:17:44.670000

1 posts

The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the admin service is registered on the current route rather than that the visitor is authenticated, and it echoes the JSON and calls exit() during the plugin

thehackerwire@mastodon.social at 2026-09-27T02:16:52.000Z ##

🟠 CVE-2026-100672 - High (7.5)

The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100660
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T17:17:44.247000

1 posts

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker for every encoded field section that references the QPACK dynamic table, keyed by the peer-controlled QUIC stream ID, and these entries are released only when the remote decoder sends a Section Acknow

thehackerwire@mastodon.social at 2026-09-28T01:45:44.000Z ##

🟠 CVE-2026-100660 - High (7.5)

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker for every encoded field section that references...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86609
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T16:38:58.950000

1 posts

The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin befor

thehackerwire@mastodon.social at 2026-09-28T02:31:16.000Z ##

🟠 CVE-2026-86609 - High (8.8)

The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform S...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100690
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T16:37:02.187000

1 posts

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that point outside the allowed set, Hugo did not detect symlinks escaping the sandbox.

thehackerwire@mastodon.social at 2026-09-27T01:16:15.000Z ##

🟠 CVE-2026-100690 - High (7.5)

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100693
(8.4 HIGH)

EPSS: 0.00%

updated 2026-09-28T16:37:02.187000

1 posts

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost.

thehackerwire@mastodon.social at 2026-09-27T01:01:30.000Z ##

🟠 CVE-2026-100693 - High (8.4)

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100686
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-28T16:36:05.010000

1 posts

Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.

thehackerwire@mastodon.social at 2026-09-27T01:01:48.000Z ##

🟠 CVE-2026-100686 - High (8.1)

Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit mi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73640(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-28T15:32:02

1 posts

Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an arbitrary SQL query. The parameter is interpreted as part of SQL predicate resulting in Time-Based Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only bee

cR0w@infosec.exchange at 2026-09-28T16:09:17.000Z ##

sev:CRITs in Dayforce Payroll. Go patch and protect that shit before your pay gets fucked.

cert.pl/en/posts/2026/09/CVE-2

##

CVE-2026-88774
(7.2 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:31:46

2 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.

1 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-88775
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T15:31:46

2 posts

Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

1 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-88773
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T15:31:46

3 posts

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

1 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

GossiTheDog@cyberplace.social at 2026-09-27T15:33:35.000Z ##

Netscaler CVEs are out:

support.citrix.com/support-hom

Patch isn’t yet through QA at Citrix still, been a week :02angery:

The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained.

It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.

Probably nation state aligned as well resourced, espionage rather than teens.

##

CVE-2026-100838
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:23:38.510000

1 posts

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem. A malicious process on the untrusted host able to connect to the Kata agent VSOCK could issue a series of CopyFile requests to overwrite security-critic

thehackerwire@mastodon.social at 2026-09-27T02:47:19.000Z ##

🟠 CVE-2026-100838 - High (8.1)

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100705
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:20:06.633000

1 posts

Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.169.253, metadata.google.internal, 127.0.0.0/8, ::1/128) and the scoped-token control were wired only into the new CEL http.Get/Post library and were never applied to the legacy apiCall service executor (pkg/engine/apicall/executor.go) or to the GlobalContextEntry external-API

thehackerwire@mastodon.social at 2026-09-27T00:46:29.000Z ##

🟠 CVE-2026-100705 - High (7.6)

Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.169.253, metadata.google.internal, 127.0.0.0/8, ::1/128) and the scoped-token control were wired only into the new CEL http....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100740
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T15:17:11.597000

2 posts

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.

1 repos

https://github.com/murrez/CVE-2026-100740

thehackerwire@mastodon.social at 2026-09-27T01:32:18.000Z ##

🔴 CVE-2026-100740 - Critical (9.9)

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-27T01:30:24.000Z ##

D-Link DIR-895L hit by CRITICAL vuln: CVE-2026-100740 (CVSS 9.4) in tunnel_set_params — public exploit code enables remote RCE or DoS via out-of-bounds write. No patch yet. Monitor for updates: radar.offseq.com/threat/cve-20 #OffSeq #CVE2026100740 #infosec #RouterSecurity

##

CVE-2026-100716
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T15:17:11.427000

1 posts

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that skips the first segment below the customer home directory, and the guard in ExportCron.php checks only the final component

thehackerwire@mastodon.social at 2026-09-27T00:02:44.000Z ##

🔴 CVE-2026-100716 - Critical (9.9)

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100704
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:17:10.903000

1 posts

Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyverno.io/v1beta1) evaluator never reads the spec.images and spec.allowedValues fields of a PolicyException. Any PolicyException whose policyRefs and matchConditions match a resource causes image signature verification to be skipped for the entire resource rather than only for the lis

thehackerwire@mastodon.social at 2026-09-27T00:31:33.000Z ##

🟠 CVE-2026-100704 - High (7.7)

Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyverno.io/v1beta1) evaluator never reads the spec.images and spec.allowedValues fields of a PolicyException. Any PolicyException who...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101039
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T15:16:04.793000

1 posts

A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element of the component devdiscover Service. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

offseq@infosec.exchange at 2026-09-28T13:30:28.000Z ##

CRITICAL: FAST FAC1900R 20190827_2.0.2 vulnerable to stack-based buffer overflow (CVE-2026-101039, CVSS 10). RCE possible via public exploit. No patch released; block access to devdiscover Service. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoT #Infosec

##

CVE-2026-100886
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T15:16:04.793000

2 posts

A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any wa

1 repos

https://github.com/heapframe/seetong-ts81xxd3x-rce

thehackerwire@mastodon.social at 2026-09-28T00:00:51.000Z ##

🔴 CVE-2026-100886 - Critical (10)

A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-28T00:00:36.000Z ##

Seetong T8108 series (v4.6.1.4-build202604241011) hit by CRITICAL CVE-2026-100886: improper authentication in Debug Service. Exploitable remotely — public exploit code available. No patch. Restrict network access ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026100886 #IoTSecurity #Vuln

##

CVE-2026-85984
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T15:16:04.793000

2 posts

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as suffici

1 repos

https://github.com/murrez/CVE-2026-85984

offseq@infosec.exchange at 2026-09-27T03:00:25.000Z ##

CVE-2026-85984: CRITICAL auth bypass in miniOrange OTP Login plugin ≤5.5.5. Attackers can log in as admin with just a username if certain options are enabled. Disable risky settings and check vendor guidance. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202685984

##

thehackerwire@mastodon.social at 2026-09-26T23:46:48.000Z ##

🔴 CVE-2026-85984 - Critical (9.8)

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent gua...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101001
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T15:15:33.930000

1 posts

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about thi

thehackerwire@mastodon.social at 2026-09-28T05:31:27.000Z ##

🔴 CVE-2026-101001 - Critical (10)

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101060
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-28T14:17:13.093000

1 posts

python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoint can return a 302 redirect to internal services, allowing the UTCP client to reach cloud metadata endpoints or internal HTTP services and ret

thehackerwire@mastodon.social at 2026-09-28T00:16:29.000Z ##

🟠 CVE-2026-101060 - High (8.2)

python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88772
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-28T12:32:09

29 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

5 repos

https://github.com/murrez/CVE-2026-88772

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/securekomodo/citrixInspector

https://github.com/technion/netscaler_scanner

https://github.com/FollowerSeize/CVE-2026-88772-POC

youranonnewsirc@nerdculture.de at 2026-09-29T04:25:37.000Z ##

Recent global developments highlight escalating cybersecurity risks and geopolitical tensions. AI-powered attacks are rapidly exploiting vulnerabilities, with threat actors leveraging agentic workflows for credential harvesting. In response, Nvidia has launched its Open Agent Safety Platform to manage rogue AI agents. Meanwhile, CISA has issued a critical warning regarding actively exploited Citrix NetScaler zero-day flaws (CVE-2026-88771, CVE-2026-88772).

On the geopolitical front, a new US-Saudi civilian nuclear pact has raised significant proliferation concerns, as Saudi Arabia has not ruled out developing nuclear weapons.

#Cybersecurity #AI #Geopolitics

##

undercodenews@mastodon.social at 2026-09-29T01:26:39.000Z ##

Citrix NetScaler Zero-Days Exploited in the Wild as Customers Waited for Official Warning + Video

A Dangerous Weekend of Uncertainty Citrix has released emergency patches for two critical NetScaler vulnerabilities that were already being exploited in the wild, but the company’s delayed public confirmation left cybersecurity teams scrambling for answers during much of the weekend. The vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, affect Citrix NetScaler…

undercodenews.com/citrix-netsc

##

netsecio@mastodon.social at 2026-09-28T22:34:28.000Z ##

📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack

Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE

🔗 cyber.netsecops.io/articles/ci

##

Matchbook3469@mastodon.social at 2026-09-28T21:39:22.000Z ##

🔵 THREAT INTELLIGENCE

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Vulnerability | CRITICAL
CVEs: CVE-2026-88771, CVE-2026-88772

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being...

Full analysis:
yazoul.net/news/article/citrix

by Yazoul AI

#ThreatIntel #Malware #SecurityOps

##

censys at 2026-09-28T21:22:52.979Z ##

🚨RAPID RESPONSE: Two critical Citrix NetScaler vulnerabilities are being actively exploited as zero-days.

CVE-2026-88771 and CVE-2026-88772 can each lead to remote code execution.

Censys currently observes 42,735 Internet-exposed NetScaler ADC or Gateway hosts. Censys ARC breaks down the exposed population, exploitation status, patches, and guidance for defenders.

Read the advisory: censys.com/advisory/cve-2026-1

##

cyberveille@mastobot.ping.moi at 2026-09-28T20:30:05.000Z ##

📢 Deux zero-days critiques NetScaler (CVE-2026-88771 et CVE-2026-88772) exploités activement

🔍 Vulnérabilités identifiées Citrix a publié le bulletin de sécurité CTX697096 confirmant deux failles critiques : CVE-2026-88771 (score CVSS 9.5) : Exécution de code à distance via une validation d'entrée incorrecte, exploitable sans authentification, affectant…

📖 cyberveille : cyberveille.ch/posts/2026-09-2
🌐 source : bleepingcomputer.com/news/secu
🟡 vérification factuelle moyenne
#NetScaler #ZeroDay #Cyberveille

##

youranonnewsirc@nerdculture.de at 2026-09-29T04:25:37.000Z ##

Recent global developments highlight escalating cybersecurity risks and geopolitical tensions. AI-powered attacks are rapidly exploiting vulnerabilities, with threat actors leveraging agentic workflows for credential harvesting. In response, Nvidia has launched its Open Agent Safety Platform to manage rogue AI agents. Meanwhile, CISA has issued a critical warning regarding actively exploited Citrix NetScaler zero-day flaws (CVE-2026-88771, CVE-2026-88772).

On the geopolitical front, a new US-Saudi civilian nuclear pact has raised significant proliferation concerns, as Saudi Arabia has not ruled out developing nuclear weapons.

#Cybersecurity #AI #Geopolitics

##

censys@infosec.exchange at 2026-09-28T21:22:52.000Z ##

🚨RAPID RESPONSE: Two critical Citrix NetScaler vulnerabilities are being actively exploited as zero-days.

CVE-2026-88771 and CVE-2026-88772 can each lead to remote code execution.

Censys currently observes 42,735 Internet-exposed NetScaler ADC or Gateway hosts. Censys ARC breaks down the exposed population, exploitation status, patches, and guidance for defenders.

Read the advisory: censys.com/advisory/cve-2026-1

#Cybersecurity #Citrix #NetScaler #VulnerabilityManagement #CensysARC

##

thecybermind@infosec.exchange at 2026-09-28T19:48:29.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-88772 – Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

A high-severity memory buffer vulnerability in Citrix NetScaler is under active exploitation. Review CISA telemetry and deployment hardening protocols....

thecybermind.co/41l1

##

youranonnewsirc@nerdculture.de at 2026-09-28T16:25:41.000Z ##

Here's a summary of the latest geopolitical, technology, and cybersecurity news:

Geopolitically, US-Iran tensions remain high after President Trump rejected a Strait of Hormuz proposal, with ongoing investigations into potential terror links to Iran after arrests near a U.S.-operated air base in the UK. Russia has intensified attacks on Kyiv, while Ukraine reportedly recaptured territory in Donetsk.

In technology, OpenAI halted AI model training due to "rogue agent" incidents and unexpected behavior on government websites. Nvidia launched an Open Agent Safety Platform to enhance AI security.

Cybersecurity saw critical Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) actively exploited globally, prompting CISA to add them to its KEV catalog. Ransomware activity reached a 2026 high in August, with industrial sectors being the most targeted. A new Carbonato botnet targets Docker hosts to deploy a Telegram-controlled AI agent. Kiteworks also advised customers to temporarily shut down their platform due to credible threat intelligence.

#AnonNews_irc #Cybersecurity #News

##

GossiTheDog@cyberplace.social at 2026-09-28T15:13:43.000Z ##

There's various proof of concepts doing the rounds on Github for the new Citrix vulns. All the ones I've seen so far are fake AI slop.

E.g. this one is AI generated, it's not a PoC, it doesn't exploit, the fingerprint method it uses doesn't exist and as a checker it doesn't actually work either.

github.com/murrez/CVE-2026-887

##

bsi@social.bund.de at 2026-09-28T13:04:09.000Z ##

⚠️ 📢 Sicherheitswarnung: Am 27. September 2026 veröffentlichte der Hersteller #Citrix ein Advisory [CIT26a] zu insgesamt acht Sicherheitslücken in seinen Produkten NetScaler ADC (ehemals Citrix ADC) und NetScaler Gateway (ehemals Citrix Gateway). Hierin enthalten sind auch zwei #ZeroDay-Schwachstellen (CVE-2026-88771 und CVE-2026-88772), zu denen sich im Laufe des vergangenen Wochenendes Berichte über eine aktive Ausnutzung verbreitet hatten.

Mehr dazu hier: bsi.bund.de/dok/1209522

##

ssvc@infosec.exchange at 2026-09-28T12:16:27.000Z ##

CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.

cisa.gov/news-events/alerts/20

#CISA #KEV #Citrix #zeroday #CVE

##

benzogaga33@mamot.fr at 2026-09-28T09:40:04.000Z ##

« Éteignez vos NetScaler » : Citrix confirme 2 failles zero-day critiques déjà exploitées it-connect.fr/citrix-netscaler #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

cert_fr@social.numerique.gouv.fr at 2026-09-28T09:00:19.000Z ##

⚠️ Alerte CERT-FR ⚠️
Les vulnérabilités CVE-2026-88771 et CVE-2026-88772 sont activement exploitées et permettent une RCE pré-authentification sur Citrix NetScaler ADC et Gateway.

cert.ssi.gouv.fr/alerte/CERTFR

##

tugatech@masto.pt at 2026-09-28T08:41:25.000Z ##

Citrix corrige 2 vulnerabilidades críticas no NetScaler exploradas em ataques. A empresa já disponibilizou atualizações de segurança para corrigir as falhas zero-day identificadas como CVE-2026-88771 e CVE-2026-88772. 🛡️

🔗 tugatech.com.pt/t91845-citrix-

 

##

threatnoir@infosec.exchange at 2026-09-28T08:06:09.000Z ##

⚠️ CRITICAL: Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix NetScaler ADC and Gateway appliances are under active attack via two unpatched RCE zero-days (CVE-2026-88771 and CVE-2026-88772). Unauthenticated attackers can execute arbitrary commands or trigger denial-of-service on vulnerable instances. Any organization running these appliances without t…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-28T07:05:59.000Z ##

⚠️ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler to the Known Exploited Vulnerabilities catalog due to active exploitation in the wild. These are remote code execution vectors being actively weaponized. Federal agencies and any organization running exposed NetScaler instances…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

cisakevtracker@mastodon.social at 2026-09-27T23:00:52.000Z ##

CVE ID: CVE-2026-88772
Vendor: Citrix
Product: NetScaler
Date Added: 2026-09-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-09-27T23:00:11.000Z ##

🚨 [CISA-2026:0927] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-88771 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: community.citrix.com/techzone- ; support.citrix.com/support-hom ; support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-88772 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: community.citrix.com/techzone- ; support.citrix.com/support-hom ; support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260927 #cisa20260927 #cve_2026_88771 #cve_2026_88772 #cve202688771 #cve202688772

##

youranonnewsirc@nerdculture.de at 2026-09-27T22:26:18.000Z ##

Latest News (Sept 26-27, 2026): Geopolitically, President Trump rejected Iran's Strait of Hormuz reopening proposal. In technology, OpenAI halted AI model training due to reports of "rogue" agents. Cybersecurity saw CISA add two critical, actively exploited Citrix NetScaler RCE zero-days to its KEV catalog (CVE-2026-88771, CVE-2026-88772), while ShinyHunters resumed Oracle PeopleSoft attacks, bypassing WAFs.

#Cybersecurity #TechNews #Geopolitics

##

zackwhittaker@mastodon.social at 2026-09-27T19:56:16.000Z ##

CISA has confirmed two bugs in Citrix NetScaler are under attack, CVE-2026-88771 and CVE-2026-88772, per its catalog of known exploited vulnerabiliites. cisa.gov/known-exploited-vulne

Citrix has a support base article, confirming exploitation. support.citrix.com/support-hom

##

security_crawler_carl@infosec.exchange at 2026-09-27T19:42:16.000Z ##

🏆 New Achievement! Welcome to the Mandatory Exploit Tutorial!

Ah, new player. Before you proceed, the game would like to walk you through two compulsory debuffs. CVE-2026-88771 — CVSS 9.5, unauthenticated remote code execution via improper input validation — is applied automatically. No extra features required. Think of it as the tutorial that runs whether you clicked "Skip" or not. CVE-2026-88772 also joins the party, also scoring 9.5, because the game respects symmetry. (1/3)

##

cyberworldops@infosec.exchange at 2026-09-27T18:30:00.000Z ##

Citrix patched NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 after confirmed exploitation of unmitigated systems. Edge appliances remain high-value targets, and the September 27 release also fixes six other flaws requiring immediate patching. #Citrix #NetScaler #ZeroDay #VulnerabilityManagement

cyberworldops.eu/en/citrix-pat

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

DailyCyberSecurity@infosec.exchange at 2026-09-27T16:18:08.000Z ##

Two Citrix NetScaler zero-day RCE flaws are under active exploitation. Citrix confirmed CVE-2026-88771 and CVE-2026-88772 and shipped patches. Update now.

#Citrix #NetScaler #ZeroDay #RCE #CyberSecurity #VPN #watchTowr #PatchNow

securityonline.info/citrix-net

##

ssvc@infosec.exchange at 2026-09-27T15:56:01.000Z ##

Citrix NetScaler zero-days

Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.

This is a Monday problem for me, but you're better off knowing what to expect when coming into work tomorrow. h/t @mttaggart

support.citrix.com/support-hom

#citrix #netscaler #zeroday #cve

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

GossiTheDog@cyberplace.social at 2026-09-27T15:33:35.000Z ##

Netscaler CVEs are out:

support.citrix.com/support-hom

Patch isn’t yet through QA at Citrix still, been a week :02angery:

The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained.

It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.

Probably nation state aligned as well resourced, espionage rather than teens.

##

CVE-2026-81867(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-28T12:31:13

1 posts

A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerability was patched on 28 June 2026, and no customer

offseq@infosec.exchange at 2026-09-28T12:00:26.000Z ##

Critical: Google Cloud Application Integration is affected by CVE-2026-81867 (CVSS 9.4) — deserialization of untrusted data lets authenticated users run code on shared servers. Patched 2026-06-28. Confirm your environment is current. Details: radar.offseq.com/threat/cve-20 #OffSeq #CloudSecurity #CVE202681867

##

CVE-2026-101009
(8.4 HIGH)

EPSS: 0.00%

updated 2026-09-28T09:30:34

1 posts

A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendo

offseq@infosec.exchange at 2026-09-28T07:30:26.000Z ##

OS command injection (CVE-2026-101009) in aaPanel BaoTa <=11.8.0: CRITICAL severity. Exploit public, vendor silent. Remote attackers can execute commands via panelTask.bt_task._unzip. Review and mitigate now. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026101009 #infosec

##

CVE-2026-101002
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T06:31:23

2 posts

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early

thehackerwire@mastodon.social at 2026-09-28T07:01:50.000Z ##

🔴 CVE-2026-101002 - Critical (9.9)

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-28T06:00:24.000Z ##

CVE-2026-101002: Critical OS command injection in Netcore NBR200V2 v1.3.241127.071246 via Tools Ping Handler. Public exploit code available; no vendor patch. Isolate devices, restrict network access. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026101002 #Netcore #Vuln

##

CVE-2026-101000
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T06:31:23

1 posts

A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted ear

thehackerwire@mastodon.social at 2026-09-28T05:31:19.000Z ##

🔴 CVE-2026-101000 - Critical (10)

A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100908
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T06:31:18

1 posts

A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Parser. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

thehackerwire@mastodon.social at 2026-09-28T05:31:37.000Z ##

🟠 CVE-2026-100908 - High (7.5)

A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Parser. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100896
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T03:30:34

2 posts

A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

offseq@infosec.exchange at 2026-09-28T03:00:26.000Z ##

TOTOLINK N150RT v3.4.0-B20201030 is vulnerable (CVE-2026-100896, CVSS 9.4): CRITICAL OS command injection in Web UI. Public exploit out, no patch yet. Restrict mgmt access & monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026100896 #infosec #router

##

thehackerwire@mastodon.social at 2026-09-28T02:30:35.000Z ##

🔴 CVE-2026-100896 - Critical (9.9)

A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96896
(7.2 HIGH)

EPSS: 0.00%

updated 2026-09-28T03:30:27

1 posts

The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.

offseq@infosec.exchange at 2026-09-27T07:30:23.000Z ##

CVE-2026-96896: Malcure Malware Shield <19.9.7 has a CRITICAL auth flaw. Subsite admins in WP multisite can write/delete arbitrary files, enabling RCE. Upgrade to 19.9.7+ now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #RCE

##

CVE-2026-81655
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T03:30:25

2 posts

The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.

thehackerwire@mastodon.social at 2026-09-28T02:31:25.000Z ##

🟠 CVE-2026-81655 - High (7.5)

The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-27T10:30:24.000Z ##

CVE-2026-81655: CRITICAL code injection in Ad Inserter WP plugin (2.8.12 – 2.8.18). Subscribers can execute PHP or unescaped content. Patch to 2.8.19+ ASAP. More: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #Vuln

##

CVE-2026-101084
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-27T21:31:10

2 posts

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.

offseq@infosec.exchange at 2026-09-28T04:30:25.000Z ##

obot-platform obot <0.21.1 suffers a CRITICAL auth bypass (CVE-2026-101084): authenticated users with server IDs can access restricted MCP servers via /mcp-connect. Patch to 0.21.1 now! radar.offseq.com/threat/cve-20 #OffSeq #CVE2026101084 #infosec #vuln

##

thehackerwire@mastodon.social at 2026-09-28T00:15:29.000Z ##

🔴 CVE-2026-101084 - Critical (9.6)

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101090
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-27T21:31:10

2 posts

Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to b

offseq@infosec.exchange at 2026-09-28T01:30:23.000Z ##

Nezha 2.2.3 (CVE-2026-101090): CRITICAL open redirect via Host header injection in OAuth2 flow. Account takeover possible if dashboard_host is unset. Set to trusted value; no patch yet. radar.offseq.com/threat/cve-20 #OffSeq #OAuth2 #Vulnerability #InfoSec

##

thehackerwire@mastodon.social at 2026-09-28T00:01:10.000Z ##

🔴 CVE-2026-101090 - Critical (9.8)

Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101064
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-27T21:31:10

1 posts

Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error messages to disclose sensitive credentials.

thehackerwire@mastodon.social at 2026-09-28T00:16:20.000Z ##

🟠 CVE-2026-101064 - High (7.6)

Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101062
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T21:31:10

1 posts

Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the authorization flow auto-completes for an already logged-in user with no consent screen, an attacker who registers a client pointing at their own dom

thehackerwire@mastodon.social at 2026-09-28T00:15:39.000Z ##

🟠 CVE-2026-101062 - High (8.8)

Obot before v0.23.0 (affected versions &lt;= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Beca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101045
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-27T18:30:34

1 posts

Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the script generator escaped this metadata at some interpolation sites but not all of them, so cask metadata containing shell metacharacters (for example $(...) command substitution) could be carried into scripts that execute as root on managed macOS hos

thehackerwire@mastodon.social at 2026-09-28T00:16:38.000Z ##

🟠 CVE-2026-101045 - High (8)

Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the script generator escaped this metadata at some interpolation sites but not all of them, so cask m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100673
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-27T17:16:55.343000

1 posts

The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor wh

thehackerwire@mastodon.social at 2026-09-27T01:46:33.000Z ##

🟠 CVE-2026-100673 - High (8.2)

The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100872
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-27T15:31:14

1 posts

Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.

thehackerwire@mastodon.social at 2026-09-28T00:30:46.000Z ##

🟠 CVE-2026-100872 - High (7.5)

Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100870
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T15:31:08

1 posts

Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over

thehackerwire@mastodon.social at 2026-09-28T00:30:28.000Z ##

🟠 CVE-2026-100870 - High (8.8)

Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domai...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89136(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-27T12:30:28

2 posts

When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited server_cert_type=RawPublicKey which allowed a malicious or misbehaving server to bypass authentication. RPK is off by default and only enabled in --enable-rpk OR --enable-all OR --enable-distro AKA HAVE_RPK builds.

CVE-2026-93302(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-27T12:30:21

2 posts

MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert(). The peer must know the certificates being loaded to either of those APIs to take advantage of the issue. When OPENSSL_COMPATIBLE_DEFAULTS is als

CVE-2026-100741
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-27T09:31:17

2 posts

Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with the privileges of the service account, via a password containing a backslash followed by an apostrophe, sent in any logon (SMTP AUTH, POP3, IMAP) that na

thehackerwire@mastodon.social at 2026-09-28T00:45:28.000Z ##

🔴 CVE-2026-100741 - Critical (9.8)

Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-27T09:00:26.000Z ##

CVE-2026-100741: CRITICAL eval injection in hMailServer (Windows, 6.0.0 – 6.3.3) enables remote code execution via JScript event scripting. Requires non-default config. Disable event scripting/JScript now. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #CyberSec #CVE #hMailServer

##

CVE-2026-100843
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:13

1 posts

MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrary system commands when deserialized by the vulnerable function.

thehackerwire@mastodon.social at 2026-09-28T00:45:36.000Z ##

🟠 CVE-2026-100843 - High (7.8)

MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100839
(8.4 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:13

1 posts

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted host (QEMU) to the guest firmware (OVMF) and on to the Linux kernel, whose AML interpreter executes them. An attacker controlling the host — an assumed adve

thehackerwire@mastodon.social at 2026-09-27T02:47:28.000Z ##

🟠 CVE-2026-100839 - High (8.4)

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted hos...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100847
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:13

1 posts

AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database information including user credentials and station settings.

thehackerwire@mastodon.social at 2026-09-27T02:47:10.000Z ##

🟠 CVE-2026-100847 - High (7.5)

AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database informa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100851
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:13

1 posts

AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin passwor

thehackerwire@mastodon.social at 2026-09-27T02:32:51.000Z ##

🟠 CVE-2026-100851 - High (7.6)

AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay pass...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100857
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:13

1 posts

AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Attackers can inject #{process.run()} expressions into playlist URLs or station metadata fields tha

thehackerwire@mastodon.social at 2026-09-27T02:32:33.000Z ##

🟠 CVE-2026-100857 - High (8)

AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100856
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:13

1 posts

AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can inject nested Liquidsoap interpolation syntax to execute arbitrary code in the Liquidsoap process, disclose internal API keys, or disrupt station operation.

thehackerwire@mastodon.social at 2026-09-27T02:31:50.000Z ##

🟠 CVE-2026-100856 - High (8.8)

AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can inject neste...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100864
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:13

1 posts

heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python code. Attackers can craft workflow expressions using dunder attribute access through item expressions or the fallback resolver to access os.system and execute commands as the backend process.

thehackerwire@mastodon.social at 2026-09-27T02:31:33.000Z ##

🟠 CVE-2026-100864 - High (8.8)

heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python code. Attackers can craft workflow expressions using dunder ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100723
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:12

1 posts

vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through NodeVM's builtin allowlist (require: { builtin: ['zlib'] }), zlib.deflateSync can return a Buffer backed by Node's shared small-buffer pool whose .buffer is

thehackerwire@mastodon.social at 2026-09-28T01:00:45.000Z ##

🟠 CVE-2026-100723 - High (7.5)

vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through Node...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100833
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:12

1 posts

Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver without verifying the image digest. An attacker with access to the Kata agent API — for example, a

thehackerwire@mastodon.social at 2026-09-28T01:00:36.000Z ##

🟠 CVE-2026-100833 - High (8.2)

Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accept...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100835
(7.4 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:12

1 posts

Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI a

1 repos

https://github.com/murrez/CVE-2026-100835

offseq@infosec.exchange at 2026-09-27T04:30:24.000Z ##

CVE-2026-100835: Contrast <1.16.0 faces CRITICAL remote attestation relay attacks. Any valid TEE attestation report is accepted, risking trust bypass. Upgrade ASAP. radar.offseq.com/threat/contra #OffSeq #CVE2026100835 #infosec #security

##

CVE-2026-100841
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:12

1 posts

In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_only=False). Related cache helpers in monai/data/utils.py also call pickle.loads on cached content and derive cache keys with hashlib.md5. As a result, a

thehackerwire@mastodon.social at 2026-09-27T03:02:12.000Z ##

🟠 CVE-2026-100841 - High (7.8)

In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100852
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:12

1 posts

AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permissions can set a username containing shell metacharacters and trigger command execution as the Liquidsoap process user when recording closes.

thehackerwire@mastodon.social at 2026-09-27T02:46:15.000Z ##

🟠 CVE-2026-100852 - High (8.8)

AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84388
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-27T00:16:35.007000

1 posts

A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack

1 repos

https://github.com/ShadowForge-Cyber/CVE-2026-84388-POC

AAKL@infosec.exchange at 2026-09-28T16:53:55.000Z ##

Fortinet posted a critical vulnerability yesterday:

CVE-2026-84388 - Improper Restriction of Rendered UI Layers or Frames in FortiPAM Chrome Extension Enables Remote Information Disclosure app.opencve.io/cve/CVE-2026-84 #infosec #Fortinet #Chrome #vulnerability

##

CVE-2026-100720
(8.7 HIGH)

EPSS: 0.00%

updated 2026-09-26T23:16:33.660000

1 posts

Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store the issuer organization (issuer['O']) value verbatim without sanitization. Froxlor's table-listing renderer then emits s

thehackerwire@mastodon.social at 2026-09-27T00:01:38.000Z ##

🟠 CVE-2026-100720 - High (8.7)

Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100713
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-26T23:16:33.173000

1 posts

Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::makeCorrectDir()/makeCorrectFile() is done only at check time; the live filesystem path is re-resolved as root at write time (file_put_contents with FILE_APP

thehackerwire@mastodon.social at 2026-09-27T00:01:47.000Z ##

🟠 CVE-2026-100713 - High (7.8)

Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::make...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82901
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-26T21:30:34

2 posts

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is o

1 repos

https://github.com/murrez/CVE-2026-82901

offseq@infosec.exchange at 2026-09-27T00:00:34.000Z ##

CVE-2026-82901: CRITICAL (CVSS 9.8) file upload vuln in Ultra Addons for Contact Form 7 (≤3.5.50). RCE risk if PDF Generator enabled (off by default). Disable/monitor plugin & watch for patches. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #Vulnerability

##

thehackerwire@mastodon.social at 2026-09-26T23:46:38.000Z ##

🔴 CVE-2026-82901 - Critical (9.8)

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it poss...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77203
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-26T18:31:09

1 posts

The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's author capabilities via the global $post->post_author rather than from the currently authenticated user's own capabilities, while simultaneously minting a

thehackerwire@mastodon.social at 2026-09-26T23:46:56.000Z ##

🟠 CVE-2026-77203 - High (8.8)

The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100715
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-26T15:31:32

1 posts

Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink component walk is skipped, and then executes 'rm -rf' as root on the resulting path with string-level guards only. Because mak

thehackerwire@mastodon.social at 2026-09-27T00:02:35.000Z ##

🔴 CVE-2026-100715 - Critical (9.6)

Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100707
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:28

1 posts

Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and execution. A low-privilege tenant can use percent-encoded dot-segments in urlPath to bypass namespace checks and read resources from other namespaces using the Kyverno admission controller's ServiceAccount credentials

thehackerwire@mastodon.social at 2026-09-27T00:46:46.000Z ##

🟠 CVE-2026-100707 - High (7.7)

Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and execution. A low-privilege tenant can use percent-encoded dot-se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100717
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-26T15:31:28

1 posts

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or chan

thehackerwire@mastodon.social at 2026-09-27T00:16:08.000Z ##

🔴 CVE-2026-100717 - Critical (9.9)

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100671
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission is rendered through a Twig sandbox that allowlists get_cookie(), which returns any cookie sent with the current request, including the visitor's session cookie. Because the read oc

thehackerwire@mastodon.social at 2026-09-27T02:16:42.000Z ##

🟠 CVE-2026-100671 - High (8)

Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission is rendered through a T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100676
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG <image href> values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who causes the service to proxy an attacker-hosted SVG (e.g. via the /proxy endpoint) can determine whether local files exist through observable r

thehackerwire@mastodon.social at 2026-09-27T01:46:42.000Z ##

🟠 CVE-2026-100676 - High (8.2)

January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100685
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to acces

thehackerwire@mastodon.social at 2026-09-27T01:46:25.000Z ##

🟠 CVE-2026-100685 - High (7.7)

Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100683
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename literal for MSSQL) without applying the project's quoteMySqlIdentifier / quoteSqlServerIdentifier helpers. An attacker with DDL rights on a connected MySQL/

thehackerwire@mastodon.social at 2026-09-27T01:32:50.000Z ##

🟠 CVE-2026-100683 - High (8)

Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename lit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100682
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary files as root, enabling remote code execution.

thehackerwire@mastodon.social at 2026-09-27T01:32:41.000Z ##

🟠 CVE-2026-100682 - High (8.8)

Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with lea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100680
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references in OpenAPI specifications submitted to the import endpoint to exfiltrate sensitive files including environment variables containing JWT secrets, API keys,

thehackerwire@mastodon.social at 2026-09-27T01:16:32.000Z ##

🟠 CVE-2026-100680 - High (8.1)

Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100697
(8.6 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[driver]=clickhouse with auth[server] set to an arbitrary URL (for example http://127.0.0.1:18089), causing the Adminer server to issue an HTTP POST contain

thehackerwire@mastodon.social at 2026-09-27T01:01:39.000Z ##

🟠 CVE-2026-100697 - High (8.6)

Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[dr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100706
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyExc

thehackerwire@mastodon.social at 2026-09-27T00:46:38.000Z ##

🔴 CVE-2026-100706 - Critical (9.9)

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100703
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy namespace. A tenant who can create a namespaced policy (e.g. NamespacedValidatingPolicy, and likewise the namespaced mutating, deleting, generating, and

thehackerwire@mastodon.social at 2026-09-27T00:31:25.000Z ##

🟠 CVE-2026-100703 - High (7.7)

Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100709
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type. Because customer and administrator IDs are allocated from separate namespaces, a remembered-2FA token legitimately issued to a customer with a given ID

thehackerwire@mastodon.social at 2026-09-27T00:16:17.000Z ##

🟠 CVE-2026-100709 - High (7.5)

Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100714
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php and executed by the root cron via FileDir::safe_exec. Because safe_exec only bla

thehackerwire@mastodon.social at 2026-09-27T00:02:27.000Z ##

🔴 CVE-2026-100714 - Critical (9.1)

Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100664
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:26

1 posts

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1 request-target. In HttpConversionUtil.toHttp3Headers(HttpMessage, boolean) — reached via Http3FrameToHttpObjectCodec(false) — a non-empty Host header takes precedence over the r

thehackerwire@mastodon.social at 2026-09-28T01:15:49.000Z ##

🟠 CVE-2026-100664 - High (7.5)

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1 request-target. In HttpC...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100670
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:26

1 posts

Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation key such as `access.admin.super` (instead of the nested `access[admin][super]`) matches no blueprint rule, survives BlueprintSchema::filterArray() an

thehackerwire@mastodon.social at 2026-09-27T02:01:51.000Z ##

🟠 CVE-2026-100670 - High (8.8)

Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100669
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:26

1 posts

Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, user_pages, system, vendor, ignore_folders) sets ignoreCase="false" on its URL Rewrite <match> element, overriding the IIS default of ignoreCase="true";

thehackerwire@mastodon.social at 2026-09-27T02:01:42.000Z ##

🟠 CVE-2026-100669 - High (7.5)

Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100700
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:24

1 posts

nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs to block the Node.js event loop for tens of seconds, causing service unavailability.

thehackerwire@mastodon.social at 2026-09-27T00:31:17.000Z ##

🟠 CVE-2026-100700 - High (7.5)

nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free run...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100656
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:23

1 posts

Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks the HTTP method of each still-unanswered pipelined request; the first 32 entries are bit-packed into a single long, but every additional entry is appended to methodOverflowQueue, an ArrayDeque with no size limit and no rejection path. A remote, unauthenticated attacker who

thehackerwire@mastodon.social at 2026-09-28T01:30:52.000Z ##

🟠 CVE-2026-100656 - High (7.5)

Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks the HTTP method of each still-unanswered pipelined request; the first 32 entries are bit-packed into a single long, but e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100662
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:23

1 posts

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder (QpackEncoderHandler, installed on the peer-initiated unidirectional QPACK encoder stream, type 0x02). The handler accepts an attacker-declared string-literal length of up to Integer.MAX_VALUE (~2 GiB)

thehackerwire@mastodon.social at 2026-09-28T01:15:31.000Z ##

🟠 CVE-2026-100662 - High (7.5)

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder (QpackEncoderHandler, installed on the peer-init...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100661
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:23

1 posts

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound the number of continuation bytes it will process. A remote, unauthenticated peer can open a QPACK unidirectional stream (type 0x02 encoder or 0x03 decoder) and send a first

thehackerwire@mastodon.social at 2026-09-27T02:17:02.000Z ##

🟠 CVE-2026-100661 - High (7.5)

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound the number of conti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100692
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:23

1 posts

Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a mount root (for example themes/mytheme/assets -> /some/dir/outside). Files behind such a symlink were readable during a site build through resources.Get, res

thehackerwire@mastodon.social at 2026-09-27T01:16:24.000Z ##

🟠 CVE-2026-100692 - High (7.5)

Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a moun...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100639
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/button.ts, assigned via innerHTML in app/src/protyle/gutter/index.ts) from content pasted as plain-text Markdown containing a Kramdown inline attribute list (IAL). Because the shared Lute renderer parses Kramdown IAL from text/plain input, an attacker-supplied Markdown snippet

thehackerwire@mastodon.social at 2026-09-28T02:45:54.000Z ##

🟠 CVE-2026-100639 - High (8.8)

SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/button.ts, assigned via innerHTML in app/src/protyle/gutter/index.ts) from content pasted as plain-text Markdown containing ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100637
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing directory traversal sequences to overwrite arbitrary JSON files in pre-existing kernel-writable directories outside workspace boundaries.

thehackerwire@mastodon.social at 2026-09-28T02:31:34.000Z ##

🟠 CVE-2026-100637 - High (7.6)

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing directory t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100636
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authenticated administrators to write arbitrary HTML content to index.html outside the workspace directory. Attackers can supply a folder parameter with directory traversal sequences to escape the export directory and overwrite index.html in any pre-existing kernel-writable location,

thehackerwire@mastodon.social at 2026-09-28T02:15:52.000Z ##

🟠 CVE-2026-100636 - High (7.6)

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authenticated administrators to write arbitrary HTML content to index.html outside the workspace directory. Attackers can supply a f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100646
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in kernel/util/net.go) fail open when the HTTP Origin header is absent, on the incorrect assumption that any browser-initiated cross-site request carries an Origin. Because browsers omit Origin on cr

thehackerwire@mastodon.social at 2026-09-28T02:15:43.000Z ##

🟠 CVE-2026-100646 - High (8.1)

SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in kernel/util/net.go) fail open when the HTTP...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100644
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath parameter is concatenated into SQL without escaping. Unauthenticated attackers on published sites with auth disabled can inject SQL via UNION SELECT to extract arbitrary database rows from all notebooks.

thehackerwire@mastodon.social at 2026-09-28T02:01:12.000Z ##

🟠 CVE-2026-100644 - High (7.5)

SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath parameter is concatenated into SQL without escaping. Unauthenticated attackers on published sites with auth disabled can inject SQL...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100642
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can craft malicious web pages that force victims to terminate the kernel process, read workspace configuration and proxy settings, and trigger administrative a

thehackerwire@mastodon.social at 2026-09-28T02:00:51.000Z ##

🟠 CVE-2026-100642 - High (7.6)

SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100657
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder. Once a frame's declared content-length has been fully read, the decoder allocates a chunk buffer from the channel allocator and parks it in an instance field while waiting for the single NUL byte that terminates the frame. If that byte never arrives, the buffer is never released: the replay Signal thr

thehackerwire@mastodon.social at 2026-09-28T01:45:36.000Z ##

🟠 CVE-2026-100657 - High (7.5)

Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder. Once a frame's declared content-length has been fully read, the decoder allocates a chunk buffer from the channel allocator and parks it in an instan...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100663
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3 in HttpConversionUtil.toHttp3Headers. The authority-form target (e.g., "CONNECT trusted.example:443") is parsed as a URI, so its host is emitted as :scheme, :path is set to "/", and the HTTP/1 Host head

thehackerwire@mastodon.social at 2026-09-28T01:15:40.000Z ##

🟠 CVE-2026-100663 - High (7.5)

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3 in HttpConversionUtil.toHttp3Headers. The authori...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100631
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:21

1 posts

Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to build database queries. An unauthenticated remote attacker who knows only the public application ID can submit non-string va

thehackerwire@mastodon.social at 2026-09-28T02:46:03.000Z ##

🟠 CVE-2026-100631 - High (7.5)

Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100643
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:21

1 posts

SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. Attackers can execute stored JavaScript when other users open affected database menus, and in the Electron desktop app with

thehackerwire@mastodon.social at 2026-09-28T02:01:03.000Z ##

🟠 CVE-2026-100643 - High (8)

SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100665
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:19

1 posts

Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can presen

thehackerwire@mastodon.social at 2026-09-28T01:30:35.000Z ##

🟠 CVE-2026-100665 - High (7.5)

Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100623
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:16

1 posts

Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to update" only verify that the caller has admin rights in the target organization (public.check_min_rights('admin', ...)); they do not require a pending invitation in tmp_users, acceptance of an invite

thehackerwire@mastodon.social at 2026-09-28T07:17:03.000Z ##

🟠 CVE-2026-100623 - High (8.8)

Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to update" only verify that the caller has admin r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100645
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-26T14:16:46.857000

1 posts

SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration enabled, attackers can inject JavaScript that calls Node.js child_process APIs to execute arbitrary commands with user privileges.

thehackerwire@mastodon.social at 2026-09-28T02:15:34.000Z ##

🟠 CVE-2026-100645 - High (8)

SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration ena...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100641
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-26T14:16:46.193000

1 posts

SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts and assigned to listElement.innerHTML, so content such as <img src=invalid onerror=...> becomes an executable event-handler attribute. Because the SiYua

thehackerwire@mastodon.social at 2026-09-28T01:45:53.000Z ##

🟠 CVE-2026-100641 - High (8)

SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100638
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-26T14:16:45.590000

1 posts

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can supply directory traversal sequences in the notebook parameter to escape the workspace data directory and write conf.json files to arbitrary locations accessibl

thehackerwire@mastodon.social at 2026-09-28T02:45:44.000Z ##

🟠 CVE-2026-100638 - High (7.6)

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can supply ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65660
(6.5 MEDIUM)

EPSS: 0.00%

updated 2026-09-25T18:32:20

3 posts

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

2 repos

https://github.com/HORKimhab/CVE-2026-65660

https://github.com/ShadowForge-Cyber/CVE-2026-65660-Poc

CVE-2026-85542
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-25T15:31:48

1 posts

IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated privileges on the Central Manager.

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-62062
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-25T09:31:05

3 posts

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.

1 repos

https://github.com/abraxas/CVE-2026-62062

DailyCyberSecurity@infosec.exchange at 2026-09-28T13:21:48.000Z ##

Discover the critical CVE-2026-62062 Elementor CSRF vulnerability. Learn how this REST API bypass threatens millions of WordPress sites and how to patch it.

#Elementor #WordPress #CSRF #CyberSecurity #WebSecurity

meterpreter.org/elementor-csrf

##

wpguyuk@infosec.exchange at 2026-09-28T07:04:35.000Z ##

If your site runs Elementor 4.3.0 or 4.3.1, I would update immediately. CVE-2026-62062 allows any authenticated user — a subscriber or WooCommerce customer — to escalate their privileges to admin level. Open registration or a membership area makes this a concrete, present risk rather than a theoretical one.

#WordPress #Elementor #SecurityHardening #CVE #WordPressSecurity

wpguy.uk/blog/elementor-privil

##

guru@thecybersecguru.com at 2026-09-26T17:58:21.000Z ##

Critical Elementor CSRF Flaw Exposes 2 Million WordPress Sites to Full Takeover

Elementor CVE-2026-62062 is a CVSS 8.8 CSRF flaw affecting versions 4.3.0 and 4.3.1. Update to 4.3.2 to block the attack

thecybersecguru.com/news/eleme

##

CVE-2026-14281
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-25T09:31:05

1 posts

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and the absence of a key allowlist in the `finish_registration_logic` function, which

3 repos

https://github.com/murrez/CVE-2026-14281

https://github.com/abatsakidis/CVE-2026-14281-check

https://github.com/langz337/CVE-2026-14281

DarkWebInformer@infosec.exchange at 2026-09-27T19:32:22.000Z ##

‼️ CVE-2026-14281: Unauthenticated Privilege Escalation Vulnerability in the WAWP WordPress Plugin

CVE Published: September 24, 2026
PoC Published: September 25, 2026

GitHub PoC: github.com/murrez/CVE-2026-142

##

CVE-2026-48842
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-25T04:17:35.357000

1 posts

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

2 repos

https://github.com/murrez/CVE-2026-48842

https://github.com/4minx/CVE-2026-48842

linuxmint_hun@mastodon.social at 2026-09-29T05:30:18.000Z ##

Figyelem: a javított CVE-2026-48842 Roundcube-hibát már aktívan kihasználják, hitelesítés nélkül SQL-injekcióval hozzáférhetnek levelezésekhez. Több százezer példány érhető el neten — érinti-e a te szerveredet is, frissítettél már? Ellenőrizd a verziót és telepítsd az 1.6.16/1.7.1 javítást most.

linuxmint.hu/hir/2026/09/elohi

#Roundcube #CVE2026-48842 #SQLinjection #Webmail #CyberSecurity #PatchNow #SentinelOne #Shadowserver #Proofpoint #CISA #UNKMassTraction #RoundcubeUpdate

##

CVE-2026-61743
(6.3 MEDIUM)

EPSS: 0.00%

updated 2026-09-24T21:25:27.050000

1 posts

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's server/modules/safeRequest.js calls validateOutboundUrl() to resolve and validate a target hostname, but request-promise performs a separate DNS resolution for the actual connection. An authenticated user who can create or test API connections a

hugovalters@mastodon.social at 2026-09-29T08:20:18.000Z ##

CVE-2026-61743 Chartbrew SSRF: DNS rebinding lets an authenticated user pivot validation to private addresses. CVSS 6.3. Fix in 5.2.2, still under review. Patch now. valtersit.com/cve/CVE-2026-617 #CVE #infosec #SSRF

##

CVE-2026-61652
(0 None)

EPSS: 0.00%

updated 2026-09-24T21:25:27.050000

1 posts

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all callers who streamed compressed responses relying on the chunk size — explicit (`iter_bytes(chunk_size=...)`) or the default — to bound memory. The decoder ignored that bound, so a chunk could be far larger than requested and a single compressed response could overf

hugovalters@mastodon.social at 2026-09-29T06:40:21.000Z ##

CVE-2026-61652: Zapros Python HTTP client memory exhaustion DoS, CVSS 7.5. Streaming compressed responses can blow past chunk bounds and exhaust memory. Fixed in 0.14.0, patch still under review. Apply workarounds or update now. valtersit.com/cve/CVE-2026-616 #CVE #infosec

##

CVE-2026-55074
(0 None)

EPSS: 0.00%

updated 2026-09-24T21:25:27.050000

1 posts

Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic links, and the path was operated on outside the jail, so a symlink existing inside the

Larvitz@burningboard.net at 2026-09-27T09:38:25.000Z ##

For almost a year, my Ansible connection plugin for FreeBSD jails had a jail escape.

A symlink inside a jail, a root-owned mv on the host, and every file transfer could land wherever the jail wanted. Rejecting ".." didn't help at all.

Now it's CVE-2026-55074. Here's the bug, the fix, and what disclosing it looks like when the project has one maintainer.

blog.hofstede.it/my-ansible-pl

#FreeBSD #Ansible #InfoSec #CVE #Jails #OpenSource #Security #SysAdmin

##

CVE-2026-15027
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T14:45:22.827000

1 posts

CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer.

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-94097
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T13:17:17.460000

1 posts

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about t

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-76978
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T04:17:59.137000

1 posts

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-93340
(6.8 MEDIUM)

EPSS: 0.00%

updated 2026-09-23T16:16:48.007000

1 posts

Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a crafted request specifying an attacker-controlled origin, causing the victim to

hugovalters@mastodon.social at 2026-09-29T05:10:01.000Z ##

CVE-2026-93340 Gladys Assistant before 5.1.0: password reset link poisoning lets unauthenticated attackers steal reset tokens and take over accounts. CVSS 6.8. Patch under review, update as soon as it lands. valtersit.com/cve/CVE-2026-933 #CVE #infosec

##

CVE-2026-43641
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-23T16:16:43.407000

1 posts

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and inject shell payloads through the uid field, which

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19599
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-23T15:30:51

1 posts

ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-93616
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-22T21:31:15

1 posts

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

1 repos

https://github.com/WadesWeaponShed/CVE-2026-93616_Checks

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-91827
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-22T19:41:38.447000

1 posts

The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution

hugovalters@mastodon.social at 2026-09-28T21:20:22.000Z ##

CVE-2026-91827: PHP Object Injection in Ninja Forms 3.15.3, unpatched. CVSS 7.5, can lead to RCE. Disable or update now. valtersit.com/cve/CVE-2026-918 #CVE #WordPress #infosec

##

CVE-2026-94117
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-22T19:04:55.677000

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3.

hugovalters@mastodon.social at 2026-09-29T01:50:01.000Z ##

CVE-2026-94117: Blind SQL injection in DevItems HashBar WordPress plugin through 2.0.3. CVSS 7.6, no patch yet. If you run it, disable or remove now. valtersit.com/cve/CVE-2026-941 #CVE #WordPress #infosec

##

CVE-2026-74849
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-22T12:30:32

1 posts

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-9231
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-22T09:31:22

1 posts

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in

hugovalters@mastodon.social at 2026-09-29T04:00:24.000Z ##

CVE-2026-9231: LFI in WP Travel Engine WordPress plugin (up to 6.8.0), CVSS 7.5. Contributors can include and execute arbitrary PHP files. No patch yet - disable plugin or restrict access. valtersit.com/cve/CVE-2026-923 #CVE #WordPress #infosec

##

CVE-2026-6922
(7.1 HIGH)

EPSS: 0.00%

updated 2026-09-22T09:31:17

1 posts

The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.2.1. This is due to an operator precedence bug in the post-type guard within the trash_table_bulk() and restore_table_bulk() functions that causes the guard to never fire, combined with a permission callback that only verifies plugin role membership

hugovalters@mastodon.social at 2026-09-29T03:31:00.000Z ##

CVE-2026-6922: WP Table Builder plugin, incorrect authorization up to 2.2.1. Auth attackers can trash or restore tables they shouldn't. CVSS 7.1. No patch yet. Disable the plugin until fixed.
valtersit.com/cve/CVE-2026-692
#WordPress #infosec #CVE

##

CVE-2026-12470
(7.2 HIGH)

EPSS: 0.00%

updated 2026-09-22T06:30:35

1 posts

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'cmp_ajax_import_settings' AJAX action in all versions up to, and including, 4.1.17. This makes it possible for authenticated attackers, with Editor-level access and above, to update arbitrar

hugovalters@mastodon.social at 2026-09-29T03:50:20.000Z ##

CVE-2026-12470 NiteoThemes CMP WordPress plugin, CVSS 7.2. Missing capability check in cmp_ajax_import_settings lets Editor-level users update arbitrary options and escalate privileges. No patch yet. Disable or remove the valtersit.com/cve/CVE-2026-124 #CVE #WordPress #infosec

##

CVE-2026-80521
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-21T14:17:20.193000

1 posts

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: X -. A <-> B ^--' 2) Run the following concurrently: 2-1) send() sk-B to sk-B from sk-X 2-2) close() both A and B At 2-1), there is a sm

1 repos

https://github.com/Markakd/Container_escape

CVE-2026-94098
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-21T03:30:22

1 posts

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this di

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-82890
(5.9 MEDIUM)

EPSS: 0.00%

updated 2026-09-18T21:32:36

1 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation.

hugovalters@mastodon.social at 2026-09-27T14:00:25.000Z ##

CVE-2026-82890 IBM Guardium Data Protection 12.2 allows remote authenticated attackers to execute arbitrary JavaScript via improper input neutralization. CVSS 5.9, patch status unknown. Review and update immediately. valtersit.com/cve/CVE-2026-828 #CVE #infosec #IBM

##

CVE-2026-10747
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-18T18:31:55

2 posts

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

censys at 2026-09-28T21:22:52.979Z ##

🚨RAPID RESPONSE: Two critical Citrix NetScaler vulnerabilities are being actively exploited as zero-days.

CVE-2026-88771 and CVE-2026-88772 can each lead to remote code execution.

Censys currently observes 42,735 Internet-exposed NetScaler ADC or Gateway hosts. Censys ARC breaks down the exposed population, exploitation status, patches, and guidance for defenders.

Read the advisory: censys.com/advisory/cve-2026-1

##

censys@infosec.exchange at 2026-09-28T21:22:52.000Z ##

🚨RAPID RESPONSE: Two critical Citrix NetScaler vulnerabilities are being actively exploited as zero-days.

CVE-2026-88771 and CVE-2026-88772 can each lead to remote code execution.

Censys currently observes 42,735 Internet-exposed NetScaler ADC or Gateway hosts. Censys ARC breaks down the exposed population, exploitation status, patches, and guidance for defenders.

Read the advisory: censys.com/advisory/cve-2026-1

#Cybersecurity #Citrix #NetScaler #VulnerabilityManagement #CensysARC

##

CVE-2026-89775
(9.3 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T18:31:58

1 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached by the TLB. For S1 mappings such as VNCR, this is deducted from the combination of the base granule size and the mapping level. However, this implies that the S1 M

sekurakbot@mastodon.com.pl at 2026-09-28T00:06:00.000Z ##

Krytyczna luka w Linux KVM na ARM64. W określonych warunkach można przejąć kontrolę nad hostem [CVE-2026-89775]

Na portalu openwall.com badacz bezpieczeństwa Hyunwoo Kim opublikował wpis zawierający szczegóły krytycznej podatności w podsystemie KVM (Kernel-based Virtual Machine) dla architektury ARM64 w jądrze Linuxa. Luka oznaczona identyfikatorem CVE-2026-89775 umożliwia ucieczkę z maszyny wirtualnej i uzyskanie dostępu do pamięci hosta. Może to prowadzić do przejęcia kontroli nad systemem (hypervisorem).  TLDR:...

#Aktualności #Cve #Kvm #Linux #Rce

sekurak.pl/krytyczna-luka-w-li

##

CVE-2026-43786
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-15T19:32:06.417000

1 posts

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

2 repos

https://github.com/0xBlackash/CVE-2026-43786

https://github.com/Malwation/CVE-2026-43786

CVE-2026-86060
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-11T15:32:27

1 posts

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable

5 repos

https://github.com/HackSpeak/CVE-2026-67279

https://github.com/digiprosec/MicroTrick

https://github.com/tc4dy/CVE-2026-67279-86060-Toolkit

https://github.com/bahirul/cve-2026-86060

https://github.com/gagaltotal/CVE-2026-mikrotik-poc

cyberveille@mastobot.ping.moi at 2026-09-28T23:30:05.000Z ##

📢 PoC public : chaîne d'exploitation MikroTrick sur RouterOS (CVE-2026-86060)

Cet article présente un exploit de preuve de concept (PoC) nommé MikroTrick, ciblant les équipements MikroTik RouterOS exposés sur Internet. La campagne d'exploitation dans la nature a débuté au moins le 2026-09-02, et CERT Polska a publié sa divulgation le 2026-09-05.

📖 cyberveille : cyberveille.ch/posts/2026-09-2
🌐 source : github.com/digiprosec/MicroTri
🟡 vérification factuelle moyenne
#PoC #RouterOS #Cyberveille

##

CVE-2026-0310
(0 None)

EPSS: 0.00%

updated 2026-09-11T04:17:13.060000

1 posts

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimiz

CVE-2026-27962
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T13:18:01.463000

2 posts

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization function, the library extracts and uses the cryptographic key embedded in the atta

DailyCyberSecurity at 2026-09-29T02:00:17.224Z ##

An Authlib signature bypass vulnerability (CVE-2026-96760, CVE-2026-28802, CVE-2026-27962) lets attackers forge JWS payloads. Update libraries now.

securityonline.info/authlib-si

##

DailyCyberSecurity@infosec.exchange at 2026-09-29T02:00:17.000Z ##

An Authlib signature bypass vulnerability (CVE-2026-96760, CVE-2026-28802, CVE-2026-27962) lets attackers forge JWS payloads. Update libraries now.

#Authlib #CVE202696760 #Cybersecurity #JWS #Vulnerability

securityonline.info/authlib-si

##

CVE-2026-8452
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-27T04:18:00.787000

2 posts

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

6 repos

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

https://github.com/securekomodo/citrixInspector

https://github.com/BishopFox/CVE-2026-8452-check

https://github.com/derekpreston81/CVE_ADC_IOC_2026

https://github.com/techupdate24/citrix-netscaler-cve-2026-8452-rce

https://github.com/maxprog-svg/CitrixBleedCVE-2026-8452-2025-5777

DarkWebInformer at 2026-09-28T22:57:43.962Z ##

citrixInspector: Passively identify Citrix ADC / NetScaler ADC & Gateway builds and check for known vulnerabilities, including CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and KEV-listed CVE-2026-88771/88772.

GitHub: github.com/securekomodo/citrix

##

DarkWebInformer@infosec.exchange at 2026-09-28T22:57:43.000Z ##

citrixInspector: Passively identify Citrix ADC / NetScaler ADC & Gateway builds and check for known vulnerabilities, including CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and KEV-listed CVE-2026-88771/88772.

GitHub: github.com/securekomodo/citrix

##

CVE-2026-15742
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-13T15:34:40

2 posts

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

DailyCyberSecurity at 2026-09-29T00:20:50.025Z ##

A critical PostgreSQL RCE vulnerability allows remote code execution. Details and PoC for this PostgreSQL RCE vulnerability are now public. Update now.

securityonline.info/postgresql

##

DailyCyberSecurity@infosec.exchange at 2026-09-29T00:20:50.000Z ##

A critical PostgreSQL RCE vulnerability allows remote code execution. Details and PoC for this PostgreSQL RCE vulnerability are now public. Update now.

#PostgreSQL #CVE202615742 #RCE #Cybersecurity #DatabaseSecurity

securityonline.info/postgresql

##

CVE-2026-58052
(3.3 LOW)

EPSS: 0.00%

updated 2026-08-07T20:47:38.443000

1 posts

7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a RAR5 STM record named ':Zone.Identifier:$DATA' is not matched and NTFS canonicalizes it to the same stream, overwriting the propagated Internet-zone marker with Zon

linuxmint_hun@mastodon.social at 2026-09-28T03:35:59.000Z ##

A 7‑Zip 26.03 hibajavításokkal és egy fontos Windows‑specifikus MotW‑sérülékenység (CVE-2026-58052) javításával érkezett. Szeretnéd tudni, hogyan kerülhette meg korábban a SmartScreen-et egy manipulált RAR5‑archívum, és érint‑e téged ez Windows alatt? Linuxra is elérhető a frissítés — nézd meg a részleteket.

linuxmint.hu/hir/2026/09/tomor

#7zip #26.03 #CVE2026-58052 #MotW #RAR5 #tömörítés #letöltés #szabad_szoftver #Linux #Windows

##

CVE-2026-26740
(8.2 HIGH)

EPSS: 0.00%

updated 2026-07-23T12:17:15.660000

1 posts

Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size.

sayzard@mastodon.sayzard.org at 2026-09-28T23:44:45.000Z ##

Google Rewrites Critical C Dependencies to Rust Using AI and Differential Fuzzin

Google 보안팀은 약 3,000줄 규모의 C 기반 giflib를 Gemini로 Rust로 이식하고, 기존 ABI·심볼 호환성을 유지하는 드롭인 라이브러리 `giflib-rs`를 공개했다. 생성 코드의 신뢰성은 3천만 개 이상의 실제 GIF 회귀 테스트와 6일간 2억 회의 C/Rust 차등 퍼징으로 검증했으며, 이 과정에서 LZW 디코더의 예외 처리와 기존 C 코드의 out-of-bounds write를 발견했다. Rust 대체 구현은 이후 공개된 giflib 힙 쓰기 취약점(CVE-2026-26740)에 구조적으로 영향을 받지 않았고, 운영...

infoq.com/news/2026/09/c-rust-

##

CVE-2026-54514
(5.3 MEDIUM)

EPSS: 0.00%

updated 2026-07-20T21:21:20

1 posts

## Summary `JDKFromStringDeserializer` constructed `InetSocketAddress` with `new InetSocketAddress(host, port)`, which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an `InetSocketAddress` field issues an attacker-chosen DNS query during `readValue`, before any application-level validation or connect l

1 repos

https://github.com/xiaoqiMikko/jackson-check

EUVD_Bot@mastodon.social at 2026-09-28T21:01:06.000Z ##

🚨 EUVD-2026-65088

📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: tools.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind (+2 more)
🏢 Vendor: FasterXML
📅 Updated: 2026-09-28

📝 jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-20700
(7.8 HIGH)

EPSS: 0.00%

updated 2026-06-17T10:17:43.440000

1 posts

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals

2 repos

https://github.com/notthemystery/CVE-2026-20700-POC-that-ll-never-work

https://github.com/R3n3r0/CVE-2026-20700

Analyst207@mastodon.social at 2026-09-29T07:49:20.000Z ##

Apple patches zero-day flaw in CoreGraphics exploited in targeted attacks

Apple just patched a zero-day flaw in CoreGraphics that was exploited in super-sophisticated targeted attacks - and you might want to update your devices ASAP! This out-of-bounds write vulnerability, tracked as CVE-2026-20700, could put your iOS device at risk if you're running an older version.

osintsights.com/apple-patches-

#ZeroDay #Coregraphics #Cve202620700 #Apple #Ios

##

CVE-2026-35273
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-06-12T18:31:50

3 posts

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of Peopl

Nuclei template

4 repos

https://github.com/HORKimhab/CVE-2026-35273

https://github.com/0xBlackash/CVE-2026-35273

https://github.com/ekomsSavior/POC_cve_2026_35273

https://github.com/12hrformat/CVE-2026-35273-POC

linuxmint_hun@mastodon.social at 2026-09-28T14:54:13.000Z ##

Google: tömegesen kihasználják az Oracle PeopleSoft CVE-2026-35273-at. WAF-ot URL-kódolással kerülik meg és web shelleket telepítenek — nálatok is lehet gond? Nézd meg, mit kell azonnal ellenőrizni.

linuxmint.hu/hir/2026/09/tamad

#Oracle #PeopleSoft #CVE2026-35273 #WAF #webshell #ShinyHunters #Mandiant #cybersecurity #infosec

##

youranonnewsirc@nerdculture.de at 2026-09-27T04:26:17.000Z ##

Cybersecurity: ShinyHunters exploit a critical Oracle PeopleSoft flaw (CVE-2026-35273), bypassing WAFs and deploying SIDEEYE backdoor across sectors. Geopolitics/Tech: President Trump rejects AI regulation, prioritizing innovation despite global concerns (Sept 26, 2026).

#Cybersecurity #AnonNews_irc #News

##

cyberworldops@infosec.exchange at 2026-09-26T14:40:01.000Z ##

Google reports active exploitation of CVE-2026-35273 in Oracle PeopleSoft PeopleTools by UNC6240, linked to ShinyHunters. Encoded requests evade WAF rules to deploy JSP webshells via the Environment Management Hub, enabling persistent access. Prioritize patching and compromise hunting. #OracleSecurity #PeopleSoft #ThreatIntel

cyberworldops.eu/en/encoded-re

##

CVE-2026-28802(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-03-06T21:56:56

2 posts

### Summary After upgrading the library from 1.5.2 to 1.6.0 (and the latest 1.6.5) it was noticed that previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected. ### Details It was likely introduced in this commit: https://github.com/authlib/authl

DailyCyberSecurity at 2026-09-29T02:00:17.224Z ##

An Authlib signature bypass vulnerability (CVE-2026-96760, CVE-2026-28802, CVE-2026-27962) lets attackers forge JWS payloads. Update libraries now.

securityonline.info/authlib-si

##

DailyCyberSecurity@infosec.exchange at 2026-09-29T02:00:17.000Z ##

An Authlib signature bypass vulnerability (CVE-2026-96760, CVE-2026-28802, CVE-2026-27962) lets attackers forge JWS payloads. Update libraries now.

#Authlib #CVE202696760 #Cybersecurity #JWS #Vulnerability

securityonline.info/authlib-si

##

DarkWebInformer at 2026-09-28T22:57:43.962Z ##

citrixInspector: Passively identify Citrix ADC / NetScaler ADC & Gateway builds and check for known vulnerabilities, including CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and KEV-listed CVE-2026-88771/88772.

GitHub: github.com/securekomodo/citrix

##

DarkWebInformer@infosec.exchange at 2026-09-28T22:57:43.000Z ##

citrixInspector: Passively identify Citrix ADC / NetScaler ADC & Gateway builds and check for known vulnerabilities, including CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and KEV-listed CVE-2026-88771/88772.

GitHub: github.com/securekomodo/citrix

##

CVE-2026-92142
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-87799
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-69227
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-09-29T01:43:08.089Z ##

Esri patched three Portal for ArcGIS vulnerabilities, including CVE-2026-69227. Apply Security Update 4 to secure your enterprise GIS environment today.

securityonline.info/portal-for

##

DailyCyberSecurity@infosec.exchange at 2026-09-29T01:43:08.000Z ##

Esri patched three Portal for ArcGIS vulnerabilities, including CVE-2026-69227. Apply Security Update 4 to secure your enterprise GIS environment today.

#ArcGIS #Esri #CVE202669227 #CVE202669226 #Cybersecurity #Vulnerability

securityonline.info/portal-for

##

CVE-2026-97381
(0 None)

EPSS: 0.00%

2 posts

N/A

kirb@hachyderm.io at 2026-09-29T00:57:58.000Z ##

Don’t know what took so long, but GitHub finally assigned it CVE-2026-97381. They said it’ll be published when my GHSA advisory is published, but… it already was, 2 months ago. I wasn’t waiting on them to do me the favor of picking from a list of numbers when my users are at risk.

Wish me luck with GitHub support because I’ll need it.

##

kirb@hachyderm.io at 2026-09-29T00:57:58.000Z ##

Don’t know what took so long, but GitHub finally assigned it CVE-2026-97381. They said it’ll be published when my GHSA advisory is published, but… it already was, 2 months ago. I wasn’t waiting on them to do me the favor of picking from a list of numbers when my users are at risk.

Wish me luck with GitHub support because I’ll need it.

##

cyberveille@mastobot.ping.moi at 2026-09-28T21:00:08.000Z ##

📢 CVE-2026-87902 : 30 000 IP ciblent WordPress en 5 jours via une faille LFI critique

CrowdSec VulnTracking, publié le 28 septembre 2026. CrowdSec rapporte l'exploitation massive et rapide de CVE-2026-87902, une vulnérabilité critique de type Local File Inclusion (LFI) dans le cœur de WordPress, pouvant mener à une exécution de code à distance (RCE) dans…

📖 cyberveille : cyberveille.ch/posts/2026-09-2
🌐 source : crowdsec.net/vulntracking-repo
🟢 vérification factuelle haute
#LFI #WordPress #Cyberveille

##

thenextweb@flipboard.com at 2026-09-28T11:32:39.000Z ##

Hackers exploited a critical WordPress flaw within hours of the patch
thenextweb.com/news/wordpress-

Posted into TNW - All Stories @tnw-all-stories-thenextweb

##

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-101894
(0 None)

EPSS: 0.00%

1 posts

N/A

1 repos

https://github.com/murrez/CVE-2026-101894

thehackerwire@mastodon.social at 2026-09-28T17:30:49.000Z ##

🔴 CVE-2026-101894 - Critical (9.1)

The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54160
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-28T17:30:41.000Z ##

🟠 CVE-2026-54160 - High (8.2)

Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitH...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-887712
(0 None)

EPSS: 0.00%

1 posts

N/A

ssvc@infosec.exchange at 2026-09-28T01:16:48.000Z ##

CISA working on a Sunday: Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-887712 were added to the Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

cisa.gov/news-event/alerts/202

#KEV #Citrix #NetScaler #zeroday #CVE

##

CVE-2026-96280
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-28T00:01:01.000Z ##

🟠 CVE-2026-96280 - High (7.5)

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites