## Updated at UTC 2026-08-08T02:39:24.719930

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-70646 7.5 0.35% 1 0 2026-08-08T02:17:18.997000 aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version
CVE-2026-64564 0 0.18% 3 2 2026-08-08T02:17:18.043000 In the Linux kernel, the following vulnerability has been resolved: sctp: don't
CVE-2026-56793 7.7 0.00% 2 0 2026-08-08T00:45:19.150000 Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Im
CVE-2026-52880 7.5 0.00% 2 0 2026-08-07T23:17:04.890000 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions f
CVE-2026-52879 7.5 0.00% 2 0 2026-08-07T23:17:04.743000 Klever-Go is the Go implementation of the Klever blockchain protocol. In version
CVE-2026-52878 7.5 0.00% 2 0 2026-08-07T23:17:04.593000 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1
CVE-2026-48120 8.6 0.00% 2 0 2026-08-07T23:17:04.117000 Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by d
CVE-2026-48026 8.7 0.00% 2 0 2026-08-07T23:17:03.810000 lakeFS is an open-source tool that transforms object storage into a Git-like rep
CVE-2026-47249 7.5 0.00% 2 0 2026-08-07T23:17:03.670000 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1
CVE-2026-46409 9.6 0.00% 2 0 2026-08-07T23:17:03.243000 OpenYak is a local-first agent runtime for reliable tool-using models, with a de
CVE-2026-48170 9.1 0.00% 4 0 2026-08-07T22:16:59.170000 `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs p
CVE-2026-48169 8.8 0.00% 2 0 2026-08-07T22:16:59.013000 PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonA
CVE-2026-20339 7.5 0.00% 2 0 2026-08-07T22:16:57.707000 A vulnerability in the PESpin file format parser of ClamAV could allow an unauth
CVE-2026-9044 8.0 0.97% 1 0 2026-08-07T21:31:31 An OS command injection vulnerability exists in the VPN module of TP-Link AXE75
CVE-2026-43622 7.8 0.13% 1 0 2026-08-07T21:30:31 llama.cpp builds b1886 through b7445 contain a double free vulnerability in the
CVE-2026-50540 9.6 0.00% 2 0 2026-08-07T21:17:28.827000 Kata Containers is an open source project focusing on a standard implementation
CVE-2026-65819 7.5 0.00% 2 0 2026-08-07T20:16:52.603000 gopacket provides packet processing capabilities for Go. Through version 1.7.0,
CVE-2026-62296 7.5 0.00% 2 0 2026-08-07T20:16:52.457000 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i
CVE-2026-62295 7.5 0.00% 2 0 2026-08-07T20:16:52.310000 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i
CVE-2026-61808 9.8 0.00% 2 0 2026-08-07T20:16:52.007000 LightRAG provides simple and fast retrieval-augmented generation. Through versio
CVE-2026-67261 9.8 1.60% 1 0 2026-08-07T20:08:27.597000 Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.
CVE-2026-8037 9.6 84.79% 8 2 2026-08-07T19:59:56.107000 OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC
CVE-2026-7406 7.8 0.13% 1 0 2026-08-07T19:18:54.820000 A maliciously crafted BMP file, when parsed through certain Autodesk products, c
CVE-2026-70638 7.8 0.13% 1 1 2026-08-07T19:18:53.427000 llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability i
CVE-2026-20337 7.5 0.00% 2 0 2026-08-07T19:17:41.010000 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-68823 9.1 0.51% 1 0 2026-08-07T18:58:50.450000 Exposed dangerous method or function in Azure Confidential Ledger allows an auth
CVE-2026-20338 7.5 0.00% 2 0 2026-08-07T18:31:53 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-71488 7.5 0.35% 1 0 2026-08-07T18:17:23.887000 league/commonmark is a PHP library for parsing and rendering CommonMark Markdown
CVE-2026-70636 7.5 0.32% 1 0 2026-08-07T18:17:22.853000 Flowise through 3.1.4 contains an authentication bypass vulnerability that allow
CVE-2026-19264 9.8 0.00% 2 0 2026-08-07T18:17:13.470000 Postiz is an open-source social media scheduling tool. The route that serves loc
CVE-2026-16030 8.1 0.14% 1 0 2026-08-07T18:17:09.153000 The MStore API WordPress plugin before 4.21.0 does not correctly verify the cry
CVE-2026-15816 7.5 0.00% 2 0 2026-08-07T18:17:09.020000 A flaw was found in dracut. The die() error-handling function writes its message
CVE-2026-62873 9.8 0.35% 2 0 2026-08-07T18:11:55.837000 Improper verification of cryptographic signature in Microsoft 365 Admin Center a
CVE-2026-65667 10.0 0.45% 2 0 2026-08-07T18:11:23.330000 Missing authorization in Microsoft Teams allows an unauthorized attacker to elev
CVE-2026-50515 9.9 0.91% 1 0 2026-08-07T18:05:55.493000 Deserialization of untrusted data in Azure Service Bus allows an authorized atta
CVE-2026-62830 9.9 0.43% 1 0 2026-08-07T17:54:24.087000 Missing authorization in Azure SRE Agent allows an authorized attacker to elevat
CVE-2026-63508 10.0 0.45% 3 0 2026-08-07T17:48:43.770000 Missing authentication for critical function in Microsoft Planetary Computer Pro
CVE-2026-70332 9.6 0.43% 2 0 2026-08-07T17:45:01.200000 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-67863 7.5 0.41% 1 0 2026-08-07T15:33:07 In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredIt
CVE-2026-54212 0 0.66% 1 0 2026-08-07T15:17:01.830000 Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint
CVE-2026-54211 0 0.64% 1 0 2026-08-07T15:17:01.713000 Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_
CVE-2026-54213 0 0.71% 1 0 2026-08-07T14:16:59.710000 Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality tha
CVE-2026-9196 8.1 0.27% 1 0 2026-08-07T13:16:53.430000 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to e
CVE-2026-34486 7.5 81.16% 3 6 2026-08-07T12:37:06.283000 Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f
CVE-2026-9169 8.8 0.14% 2 0 2026-08-07T09:32:04 DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows a
CVE-2026-71312 8.0 0.28% 1 0 2026-08-07T05:17:03.537000 rclone is a command-line program to sync files and directories to and from diffe
CVE-2026-62918 7.5 0.30% 1 0 2026-08-07T00:31:33 Improper verification of cryptographic signature in Microsoft Teams allows an un
CVE-2026-62896 9.6 0.39% 1 0 2026-08-07T00:31:33 Improper authentication in Microsoft Teams allows an authorized attacker to elev
CVE-2026-65668 8.8 0.43% 1 0 2026-08-07T00:31:33 Improper access control in Microsoft Purview eDiscovery allows an authorized att
CVE-2026-59115 9.9 0.63% 1 0 2026-08-07T00:31:28 '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an autho
CVE-2026-8325 7.8 0.13% 1 0 2026-08-07T00:31:28 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an
CVE-2026-62836 8.7 0.36% 2 0 2026-08-07T00:31:27 Improper restriction of communication channel to intended endpoints in Azure SQL
CVE-2026-56162 10.0 0.49% 2 0 2026-08-07T00:31:27 Improper authentication in Azure SQL Database allows an unauthorized attacker to
CVE-2026-59118 9.3 0.40% 1 0 2026-08-07T00:31:27 Improper authorization in Microsoft Power Apps allows an unauthorized attacker t
CVE-2026-66665 10.0 0.29% 1 0 2026-08-06T22:18:19.223000 Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
CVE-2026-65575 9.8 0.31% 1 0 2026-08-06T22:18:16.713000 Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
CVE-2026-53977 7.5 0.52% 1 0 2026-08-06T22:17:42.007000 OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows u
CVE-2026-3430 8.6 0.24% 1 1 2026-08-06T22:17:04.190000 The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and esc
CVE-2026-18427 7.5 0.46% 1 0 2026-08-06T22:16:50.143000 @fastify/static before version 10.1.3 contains an incomplete fix for a previous
CVE-2026-15991 8.8 0.61% 1 0 2026-08-06T22:16:48.620000 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion d
CVE-2026-16633 None 0.00% 1 0 2026-08-06T21:12:27 ### Impact If PDF.js is used to load a malicious PDF, and PDF.js is configured
CVE-2026-17624 8.5 0.38% 1 0 2026-08-06T19:32:05.107000 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.
CVE-2026-17633 8.5 0.40% 1 0 2026-08-06T19:31:40.753000 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke
CVE-2026-8183 7.7 0.37% 1 0 2026-08-06T18:55:31.633000 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.
CVE-2026-9201 8.8 0.23% 1 0 2026-08-06T18:31:34.390000 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to e
CVE-2026-53985 7.5 0.38% 1 0 2026-08-06T18:30:56 Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vuln
CVE-2026-18359 8.5 0.22% 1 0 2026-08-06T18:30:48 Server-side request forgery in the METS and IIIF import URI handling in Scripta
CVE-2026-18258 8.8 0.31% 1 0 2026-08-06T18:30:47 Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and
CVE-2026-66712 7.5 0.22% 1 0 2026-08-06T16:16:49.343000 Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
CVE-2026-15459 8.1 0.51% 1 0 2026-08-06T16:16:36.700000 The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypa
CVE-2026-20301 8.6 0.33% 1 0 2026-08-06T15:44:56.043000 A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referre
CVE-2026-20310 9.1 0.37% 1 0 2026-08-06T15:44:56.043000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20267 9.0 0.23% 1 0 2026-08-06T15:44:56.043000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20303 9.9 0.29% 1 0 2026-08-06T15:44:56.043000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-66709 9.1 0.48% 1 0 2026-08-06T15:32:56 Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
CVE-2026-66708 8.2 0.22% 1 0 2026-08-06T15:32:56 Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
CVE-2026-66710 8.1 0.30% 1 0 2026-08-06T15:32:56 Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
CVE-2026-66662 9.8 0.27% 1 0 2026-08-06T15:32:55 Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10
CVE-2026-66447 9.3 0.24% 1 0 2026-08-06T15:32:55 Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
CVE-2026-66733 7.5 0.89% 1 0 2026-08-06T15:32:48 Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vul
CVE-2026-5430 10.0 0.22% 2 0 2026-08-06T15:31:57.827000 The JWT authentication mechanism accepts tokens signed with algorithms other tha
CVE-2026-71321 7.5 0.42% 1 0 2026-08-06T14:16:44.860000 Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.
CVE-2026-71314 7.5 0.40% 1 0 2026-08-06T14:16:43.490000 Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.
CVE-2026-18411 8.1 0.34% 1 0 2026-08-06T14:16:31.853000 The KARR Security System and SWDS dealer-installed automotive anti-theft systems
CVE-2026-67869 7.5 0.47% 1 0 2026-08-06T13:18:23.103000 Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to ca
CVE-2026-1728 9.8 0.30% 1 0 2026-08-06T09:30:39 Tokens issued to a low-privileged user are not sufficiently restricted, allowing
CVE-2026-44945 9.1 0.30% 1 0 2026-08-06T05:17:03.793000 A privilege escalation vulnerability exists in Rancher's impersonation middlewar
CVE-2026-18485 7.8 0.11% 1 0 2026-08-06T05:16:40.767000 There is a local privilege escalation vulnerability recently discovered in the N
CVE-2026-70432 8.8 0.21% 1 0 2026-08-05T21:32:44 A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669
CVE-2026-70426 9.0 0.29% 2 0 2026-08-05T21:32:44 In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, incl
CVE-2026-70431 8.8 0.37% 1 0 2026-08-05T21:32:41 Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scriptin
CVE-2026-70615 9.9 0.21% 1 0 2026-08-05T21:31:48 boringproxy through 0.10.0 contains a newline injection vulnerability that allow
CVE-2026-34966 7.6 0.31% 1 0 2026-08-05T21:31:47 Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that
CVE-2026-17632 8.8 0.45% 1 0 2026-08-05T21:31:46 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke
CVE-2026-17583 8.4 0.14% 1 1 2026-08-05T21:31:46 The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable
CVE-2026-69111 7.5 0.57% 1 0 2026-08-05T21:31:46 Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vu
CVE-2026-70617 8.1 0.23% 1 0 2026-08-05T21:31:46 Spacebar Server before commit dcfd910 contains a missing authorization vulnerabi
CVE-2026-8182 8.8 0.38% 1 0 2026-08-05T21:31:39 IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet
CVE-2026-8478 8.8 0.37% 1 0 2026-08-05T21:31:39 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject ar
CVE-2026-71320 8.1 0.44% 1 0 2026-08-05T21:29:56 ## Impact Nuxt server islands accept props via the `/__nuxt_island/` endpoint.
CVE-2026-71319 9.6 0.32% 2 0 2026-08-05T21:27:39 ### Impact Nuxt DevTools (development mode only) exposes a bidirectional RPC ch
CVE-2026-71316 7.5 0.30% 1 0 2026-08-05T21:14:34 ### Impact When a page is covered by `routeRules` `cache` / `swr` / `isr`, Nuxt
CVE-2026-71315 8.2 0.27% 1 0 2026-08-05T21:05:19 ### Impact Nuxt matches route rules case-insensitively by default (mirroring vu
CVE-2026-63077 9.8 1.01% 7 3 2026-08-05T18:32:31 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-20313 7.7 0.25% 1 0 2026-08-05T18:31:49 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20312 8.8 0.19% 1 0 2026-08-05T18:31:49 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20304 9.9 0.25% 1 0 2026-08-05T18:31:49 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-9077 8.5 0.31% 1 0 2026-08-05T18:31:48 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attac
CVE-2026-20272 9.8 0.34% 1 0 2026-08-05T18:31:45 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20200 8.8 0.84% 2 1 2026-08-05T18:31:42 A vulnerability in the web-based management interface of Cisco IMC could allow a
CVE-2026-71294 7.6 0.22% 1 0 2026-08-05T16:17:08.827000 Cotonti CMS's Comments plugin deserializes user-supplied data without restrictin
CVE-2026-71287 8.8 0.25% 1 0 2026-08-05T16:17:08.190000 Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER
CVE-2026-71285 8.1 0.21% 1 0 2026-08-05T16:17:07.967000 Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js
CVE-2026-4431 9.1 0.33% 1 0 2026-08-05T16:16:57.470000 The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modi
CVE-2026-71289 9.8 0.37% 1 0 2026-08-05T15:32:29 The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implement
CVE-2026-66066 0 1.77% 1 7 2026-08-05T15:17:03.507000 Action Pack is a framework for handling and responding to web requests. In versi
CVE-2026-66747 9.8 0.58% 2 0 2026-08-05T12:31:36 Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS,
CVE-2026-71254 9.8 0.48% 1 0 2026-08-05T12:31:34 nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-
CVE-2026-71214 9.8 0.34% 1 0 2026-08-05T09:31:27 The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-serve
CVE-2026-58073 0 0.22% 1 0 2026-08-05T05:17:02.413000 A vulnerability in Veeam Service Provider Console allowing an unauthenticated at
CVE-2026-18556 7.4 0.49% 1 1 2026-08-05T05:16:46.967000 Authentication bypass using an alternate path or channel vulnerability in N-able
CVE-2026-9198 9.8 17.05% 2 4 2026-08-04T21:30:25 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain
CVE-2026-24254 9.8 0.45% 1 0 2026-08-04T18:31:37 NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topol
CVE-2026-64633 None 0.34% 1 1 2026-08-04T18:31:36 A vulnerability allowing remote unauthenticated code execution on the agent host
CVE-2026-58072 None 0.38% 1 0 2026-08-04T18:31:28 A vulnerability in Veeam Service Provider Console allowing arbitrary file write
CVE-2026-15920 6.1 0.30% 1 0 2026-08-04T18:16:45.087000 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `djang
CVE-2026-29146 7.5 6.26% 1 0 2026-08-04T13:18:02.797000 Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default
CVE-2026-64561 None 0.16% 10 5 2026-08-04T09:31:41 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: C
CVE-2026-64531 7.8 0.13% 1 4 2026-08-01T09:30:23 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-15969 9.8 0.98% 1 0 2026-07-31T18:33:17 SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via by
CVE-2026-28323 9.8 0.64% 2 0 2026-07-31T04:17:19.927000 SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass
CVE-2026-12943 9.8 0.92% 1 0 2026-07-31T04:16:46.070000 IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1
CVE-2026-64560 7.8 0.12% 2 1 2026-07-30T12:19:03.630000 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t
CVE-2025-68260 7.8 0.16% 1 0 2026-07-30T06:33:30 In the Linux kernel, the following vulnerability has been resolved: rust_binder
CVE-2026-20316 5.3 0.79% 1 0 2026-07-29T21:31:00 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-20079 10.0 37.67% 2 1 template 2026-07-29T17:16:51.683000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-43728 7.5 0.19% 1 0 2026-07-28T21:31:22 This issue was addressed through improved state management. This issue is fixed
CVE-2026-39868 9.1 0.94% 1 0 2026-07-27T21:16:51.020000 This issue was addressed with improved input validation. This issue is fixed in
CVE-2025-68686 5.9 1.26% 1 0 2026-07-27T18:31:25 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE
CVE-2026-60667 7.4 0.33% 1 0 2026-07-24T21:32:15 Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle
CVE-2026-65535 4.3 0.18% 2 0 2026-07-23T14:17:59.510000 Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-50522 9.8 75.76% 1 6 2026-07-22T21:31:51 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-0288 7.5 0.84% 2 0 2026-07-10T18:33:13 Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (T
CVE-2025-8088 8.8 94.55% 1 31 2026-06-17T10:06:17.243000 A path traversal vulnerability affecting the Windows version of WinRAR allows th
CVE-2025-58486 4.0 0.16% 2 0 2026-06-17T09:44:33.060000 Improper input validation in Samsung Account prior to version 15.5.01.1 allows l
CVE-2025-42999 9.1 11.28% 1 1 2026-06-17T09:23:21.993000 SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged
CVE-2026-28299 8.2 0.49% 2 0 2026-06-02T21:30:50 SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerab
CVE-2026-41679 10.0 2.95% 2 1 2026-04-27T16:19:05 ## Summary An unauthenticated attacker can achieve full remote code execution o
CVE-2025-58487 4.0 0.15% 1 0 2025-12-02T03:31:52 Improper authorization in Samsung Account prior to version 15.5.01.1 allows loca
CVE-2025-21079 7.1 0.41% 2 0 2025-11-05T06:30:37 Improper input validation in Samsung Members prior to version 5.5.01.3 allows re
CVE-2024-23692 9.8 99.47% 1 13 2025-10-22T00:34:06 Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a t
CVE-2026-64638 0 0.00% 4 10 N/A
CVE-2026-33691 0 3.58% 2 0 N/A
CVE-2026-48162 0 0.00% 1 0 N/A
CVE-2026-48024 0 0.00% 1 0 N/A
CVE-2026-49441 0 0.00% 1 0 N/A
CVE-2026-18576 0 0.00% 1 0 N/A
CVE-2026-48088 0 0.29% 1 0 N/A
CVE-2026-7867 0 0.18% 1 1 N/A
CVE-2026-59774 0 0.00% 1 1 N/A
CVE-2026-48168 0 0.91% 2 0 N/A
CVE-2026-18953 0 0.15% 1 0 N/A
CVE-2026-55524 0 0.19% 1 0 N/A
CVE-2026-55522 0 0.15% 1 0 N/A
CVE-2026-67531 0 0.43% 1 0 N/A
CVE-2026-8446 0 0.28% 1 0 N/A

CVE-2026-70646
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-08T02:17:18.997000

1 posts

aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON payloads that will ultimately be rejected, leading to unnecessary CPU and memory consumption. Version 3.0.7 fixes the issu

thehackerwire@mastodon.social at 2026-08-06T16:00:28.000Z ##

🟠 CVE-2026-70646 - High (7.5)

aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64564
(0 None)

EPSS: 0.18%

updated 2026-08-08T02:17:18.043000

3 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds

2 repos

https://github.com/HackSpeak/CVE-2026-64564

https://github.com/ethanolgolf/CVE-2026-64564

lobsters@mastodon.social at 2026-08-06T22:15:13.000Z ##

SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free lobste.rs/s/wdnet3 #linux #security #vibecoding
matrix.tencent.com/en/2026/08/

##

harrysintonen@infosec.exchange at 2026-08-06T18:39:53.000Z ##

#Debian stable has a fix now: linux-image-6.12.101+deb13-amd64

- sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564)

#CVE_2026_64564

##

harrysintonen@infosec.exchange at 2026-08-06T15:22:49.000Z ##

Yet another linux LPE to root. "CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape"

openwall.com/lists/oss-securit

#CVE_2026_64564 #infosec #cybersecurity

##

CVE-2026-56793
(7.7 HIGH)

EPSS: 0.00%

updated 2026-08-08T00:45:19.150000

2 posts

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

thehackerwire@mastodon.social at 2026-08-07T17:00:29.000Z ##

🟠 CVE-2026-56793 - High (7.7)

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-07T17:00:29.000Z ##

🟠 CVE-2026-56793 - High (7.7)

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52880
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-07T23:17:04.890000

2 posts

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serves requests through Go's default HTTP server with no ReadHeaderTimeout, ReadTimeout, or MaxHeaderBytes configured. As a result, incoming connections that

thehackerwire@mastodon.social at 2026-08-08T00:01:03.000Z ##

🟠 CVE-2026-52880 - High (7.5)

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-08T00:01:03.000Z ##

🟠 CVE-2026-52880 - High (7.5)

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52879
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-07T23:17:04.743000

2 posts

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message before the processor-level antiflood layer makes any admission decision, with no semaphore, throttler, or bound on the number of concurrent in-flight spawns. Because the antiflood check runs inside the s

thehackerwire@mastodon.social at 2026-08-08T00:00:25.000Z ##

🟠 CVE-2026-52879 - High (7.5)

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message before the processor-level antiflood layer makes a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-08T00:00:25.000Z ##

🟠 CVE-2026-52879 - High (7.5)

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message before the processor-level antiflood layer makes a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52878
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-07T23:17:04.593000

2 posts

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawData to decode to nil. Every transaction gossiped on the Klever-Go P2P network is decoded and validated synchronously inside the libp2p pubsub topic-valid

thehackerwire@mastodon.social at 2026-08-08T00:00:13.000Z ##

🟠 CVE-2026-52878 - High (7.5)

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawD...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-08T00:00:13.000Z ##

🟠 CVE-2026-52878 - High (7.5)

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawD...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48120
(8.6 HIGH)

EPSS: 0.00%

updated 2026-08-07T23:17:04.117000

2 posts

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add `autorestore-disable` to the user kakrc will disable the autorestore feature.

thehackerwire@mastodon.social at 2026-08-08T00:00:01.000Z ##

🟠 CVE-2026-48120 - High (8.6)

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Ka...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-08T00:00:01.000Z ##

🟠 CVE-2026-48120 - High (8.6)

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Ka...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48026
(8.7 HIGH)

EPSS: 0.00%

updated 2026-08-07T23:17:03.810000

2 posts

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write access to any repository branch can commit a `.md` object containing arbitrary HTML/JavaScript. Any ot

thehackerwire@mastodon.social at 2026-08-08T02:00:05.000Z ##

🟠 CVE-2026-48026 - High (8.7)

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects withou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-08T02:00:05.000Z ##

🟠 CVE-2026-48026 - High (8.7)

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects withou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47249
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-07T23:17:03.670000

2 posts

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a compressed RequestDataType_HashArrayType direct request that is only 442 bytes on the wire but expands into 200,000 decoded hash entries inside the resolver path. The resolver's antiflood logic counts o

thehackerwire@mastodon.social at 2026-08-08T00:01:25.000Z ##

🟠 CVE-2026-47249 - High (7.5)

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a compressed RequestDataType_HashArrayType direct r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-08T00:01:25.000Z ##

🟠 CVE-2026-47249 - High (7.5)

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a compressed RequestDataType_HashArrayType direct r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46409
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-08-07T23:17:03.243000

2 posts

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without server-side Origin validation, loopback authentication, or Content-Type enforcement, and with a wildcard CORS policy. Any webpage a user visits while OpenYak is runni

thehackerwire@mastodon.social at 2026-08-08T00:01:16.000Z ##

🔴 CVE-2026-46409 - Critical (9.6)

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:` (commonly 19141) without server-side Origin validat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-08T00:01:16.000Z ##

🔴 CVE-2026-46409 - Critical (9.6)

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:` (commonly 19141) without server-side Origin validat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48170
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-07T22:16:59.170000

4 posts

`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch, `Object.prototype.someProp` is set process-wide, affecting every plain object in the Node process. Any service that calls `scimPatch()` on attacker-controlled JSON (i.e. any SCI

offseq at 2026-08-08T00:00:37.444Z ##

CVE-2026-48170 (CRITICAL, CVSS 9.1): Prototype pollution in scim-patch <0.9.1 lets attackers alter Object.prototype globally in Node.js. Upgrade to 0.9.1+ or freeze prototypes for mitigation. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-07T23:00:11.000Z ##

🔴 CVE-2026-48170 - Critical (9.1)

`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch,
`Object.prototype.somePr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-08T00:00:37.000Z ##

CVE-2026-48170 (CRITICAL, CVSS 9.1): Prototype pollution in scim-patch <0.9.1 lets attackers alter Object.prototype globally in Node.js. Upgrade to 0.9.1+ or freeze prototypes for mitigation. radar.offseq.com/threat/cve-20 #OffSeq #CVE202648170 #NodeJS #InfoSec

##

thehackerwire@mastodon.social at 2026-08-07T23:00:11.000Z ##

🔴 CVE-2026-48170 - Critical (9.1)

`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch,
`Object.prototype.somePr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48169
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-07T22:16:59.013000

2 posts

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups without checking workspace ownership, so any authenticated user can read, modify, and delete resources in any workspace just by swapping UUIDs in their AP

thehackerwire@mastodon.social at 2026-08-07T23:00:01.000Z ##

🟠 CVE-2026-48169 - High (8.8)

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-07T23:00:01.000Z ##

🟠 CVE-2026-48169 - High (8.8)

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20339
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-07T22:16:57.707000

2 posts

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. An attacker could exploit thi

AAKL at 2026-08-07T17:50:53.316Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0

##

AAKL@infosec.exchange at 2026-08-07T17:50:53.000Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi #Cisco

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid #Microsoft

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/ #Google #Chrome

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100 #Apple

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s #AMD

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability #Java #SQL

##

CVE-2026-9044
(8.0 HIGH)

EPSS: 0.97%

updated 2026-08-07T21:31:31

1 posts

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters.  Successful exploitation of this vulnerability may enable an attacker to

CVE-2026-43622
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-07T21:30:31

1 posts

llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata corruption. Attackers can trigger this memory management mismatch to cause denial of service through process crashes or potentially achieve arbitrary code

thehackerwire@mastodon.social at 2026-08-06T18:59:46.000Z ##

🟠 CVE-2026-43622 - High (7.8)

llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50540
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-08-07T21:17:28.827000

2 posts

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtime accepts an arbitrary io.katacontainers.config_path pod annotation and loads the referenced host TOML file without re

thehackerwire@mastodon.social at 2026-08-07T23:00:43.000Z ##

🔴 CVE-2026-50540 - Critical (9.6)

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated config...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-07T23:00:43.000Z ##

🔴 CVE-2026-50540 - Critical (9.6)

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated config...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65819
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-07T20:16:52.603000

2 posts

gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded through DecodingLayerParser or DecodeFromBytes to trigger an unrecovered panic and remotely deny service. A patch commit is available at 210f25f.

thehackerwire@mastodon.social at 2026-08-08T02:00:30.000Z ##

🟠 CVE-2026-65819 - High (7.5)

gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded through De...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-08T02:00:30.000Z ##

🟠 CVE-2026-65819 - High (7.5)

gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded through De...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62296
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-07T20:16:52.457000

2 posts

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion between parseElementInner() and parseElement(), raising a StackOverflowError. An attacker who can submit FHIR resources containing such narratives can t

thehackerwire@mastodon.social at 2026-08-08T02:00:16.000Z ##

🟠 CVE-2026-62296 - High (7.5)

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-08T02:00:16.000Z ##

🟠 CVE-2026-62296 - High (7.5)

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62295
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-07T20:16:52.310000

2 posts

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or objects. As a result, a small but deeply nested, syntactically valid FHIR JSON document can trigger unbounded readArray() or readObject() recursion, raising

thehackerwire@mastodon.social at 2026-08-07T23:01:03.000Z ##

🟠 CVE-2026-62295 - High (7.5)

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or obje...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-07T23:01:03.000Z ##

🟠 CVE-2026-62295 - High (7.5)

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or obje...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61808
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-07T20:16:52.007000

2 posts

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or delete documents, modify the knowledge graph, cancel pipelines, clear caches, and consume LLM resources. This issue is mitiga

thehackerwire@mastodon.social at 2026-08-07T23:00:53.000Z ##

🔴 CVE-2026-61808 - Critical (9.8)

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-07T23:00:53.000Z ##

🔴 CVE-2026-61808 - Critical (9.8)

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67261
(9.8 CRITICAL)

EPSS: 1.60%

updated 2026-08-07T20:08:27.597000

1 posts

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete sys

thehackerwire@mastodon.social at 2026-08-06T20:00:37.000Z ##

🔴 CVE-2026-67261 - Critical (9.8)

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8037
(9.6 CRITICAL)

EPSS: 84.79%

updated 2026-08-07T19:59:56.107000

8 posts

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

2 repos

https://github.com/Caster-chen/CVE-2026-8037-POC

https://github.com/HORKimhab/CVE-2026-8037

thecybermind at 2026-08-07T23:33:16.262Z ##

CRITICAL THREAT ALERT: Active exploitation of CVE-2026-8037 in Progress LoadMaster allows unauthenticated RCE via command injection. Securing your perimeter requires immediate SIEM detection updates and access restrictions. Review our full TSUITE analysis: thecybermind.co/5yde

##

secdb at 2026-08-07T19:00:11.880Z ##

🚨 [CISA-2026:0807] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-8037 (secdb.nttzen.cloud/cve/detail/)
- Name: Progress LoadMaster Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Progress
- Product: LoadMaster
- Notes: community.progress.com/s/artic ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-07T18:00:45.000Z ##

CVE ID: CVE-2026-8037
Vendor: Progress
Product: LoadMaster
Date Added: 2026-08-07
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL at 2026-08-07T17:50:53.316Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0

##

thecybermind@infosec.exchange at 2026-08-07T23:33:16.000Z ##

CRITICAL THREAT ALERT: Active exploitation of CVE-2026-8037 in Progress LoadMaster allows unauthenticated RCE via command injection. Securing your perimeter requires immediate SIEM detection updates and access restrictions. Review our full TSUITE analysis: thecybermind.co/5yde

##

secdb@infosec.exchange at 2026-08-07T19:00:11.000Z ##

🚨 [CISA-2026:0807] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-8037 (secdb.nttzen.cloud/cve/detail/)
- Name: Progress LoadMaster Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Progress
- Product: LoadMaster
- Notes: community.progress.com/s/artic ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260807 #cisa20260807 #cve_2026_8037 #cve20268037

##

cisakevtracker@mastodon.social at 2026-08-07T18:00:45.000Z ##

CVE ID: CVE-2026-8037
Vendor: Progress
Product: LoadMaster
Date Added: 2026-08-07
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-08-07T17:50:53.000Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi #Cisco

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid #Microsoft

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/ #Google #Chrome

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100 #Apple

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s #AMD

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability #Java #SQL

##

CVE-2026-7406
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-07T19:18:54.820000

1 posts

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

thehackerwire@mastodon.social at 2026-08-06T23:00:09.000Z ##

🟠 CVE-2026-7406 - High (7.8)

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70638
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-07T19:18:53.427000

1 posts

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocation to wrap and allocate insufficient memory. Attackers can exploit this by providing a crafted n_seq_max value through a

1 repos

https://github.com/Hunt-Benito/one-multiply-too-many-cve-2026-70638-llama-cpp-android-jni-integer-overflow

thehackerwire@mastodon.social at 2026-08-06T23:01:20.000Z ##

🟠 CVE-2026-70638 - High (7.8)

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20337
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-07T19:17:41.010000

2 posts

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A succe

AAKL at 2026-08-07T17:50:53.316Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0

##

AAKL@infosec.exchange at 2026-08-07T17:50:53.000Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi #Cisco

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid #Microsoft

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/ #Google #Chrome

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100 #Apple

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s #AMD

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability #Java #SQL

##

CVE-2026-68823
(9.1 CRITICAL)

EPSS: 0.51%

updated 2026-08-07T18:58:50.450000

1 posts

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-08-07T01:00:19.000Z ##

🔴 CVE-2026-68823 - Critical (9.1)

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20338
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-07T18:31:53

2 posts

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to ca

AAKL at 2026-08-07T17:50:53.316Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0

##

AAKL@infosec.exchange at 2026-08-07T17:50:53.000Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi #Cisco

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid #Microsoft

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/ #Google #Chrome

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100 #Apple

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s #AMD

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability #Java #SQL

##

CVE-2026-71488
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-07T18:17:23.887000

1 posts

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character positions and byte positions, and the Autolink extension can also copy and validate

thehackerwire@mastodon.social at 2026-08-06T23:00:58.000Z ##

🟠 CVE-2026-71488 - High (7.5)

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70636
(7.5 HIGH)

EPSS: 0.32%

updated 2026-08-07T18:17:22.853000

1 posts

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2-credential refresh route with a trailing credential identifier to

thehackerwire@mastodon.social at 2026-08-06T23:01:09.000Z ##

🟠 CVE-2026-70636 - High (7.5)

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19264
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-07T18:17:13.470000

2 posts

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments are collapsed before routing, but URL-encoded separators survive route matching and are decoded onl

thehackerwire@mastodon.social at 2026-08-07T17:00:06.000Z ##

🔴 CVE-2026-19264 - Critical (9.8)

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-07T17:00:06.000Z ##

🔴 CVE-2026-19264 - Critical (9.8)

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16030
(8.1 HIGH)

EPSS: 0.14%

updated 2026-08-07T18:17:09.153000

1 posts

The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.

offseq@infosec.exchange at 2026-08-07T09:00:26.000Z ##

MStore API WordPress plugin (<4.21.0) hit by CRITICAL vuln (CVE-2026-16030): improper phone token checks enable account takeover, incl. admins. Restrict endpoints & monitor logins until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_16030 #Vuln

##

CVE-2026-15816
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-07T18:17:09.020000

2 posts

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time

thehackerwire@mastodon.social at 2026-08-07T17:00:41.000Z ##

🟠 CVE-2026-15816 - High (7.5)

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH opt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-07T17:00:41.000Z ##

🟠 CVE-2026-15816 - High (7.5)

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH opt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62873
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-08-07T18:11:55.837000

2 posts

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-08-07T03:00:26.000Z ##

CVE-2026-62873 (CRITICAL, CVSS 9.8) affects Microsoft 365 Admin Center: Improper cryptographic signature checks allow privilege escalation over the network. Microsoft has issued a fix — confirm your environment is patched. radar.offseq.com/threat/cve-20 #OffSeq #Microsoft365 #Vuln

##

thehackerwire@mastodon.social at 2026-08-07T01:01:22.000Z ##

🔴 CVE-2026-62873 - Critical (9.8)

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65667
(10.0 CRITICAL)

EPSS: 0.45%

updated 2026-08-07T18:11:23.330000

2 posts

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

AAKL@infosec.exchange at 2026-08-07T16:00:15.000Z ##

If you missed these yesterday.

"Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10."

Security Week: Microsoft, Apple Release Fresh Security Updates securityweek.com/microsoft-app #Microsoft #Apple #infosec #vylnerability #Apple

##

thehackerwire@mastodon.social at 2026-08-07T01:00:29.000Z ##

🔴 CVE-2026-65667 - Critical (10)

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50515
(9.9 CRITICAL)

EPSS: 0.91%

updated 2026-08-07T18:05:55.493000

1 posts

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

hugovalters@mastodon.social at 2026-08-07T18:07:47.000Z ##

CVE-2026-50515 - Critical deserialization RCE in Azure Service Bus. Authorized attacker can execute code over network. CVSS 9.9, unpatched. Harden access and monitor now. #CVE #Azure #infosec

valtersit.com/cve/CVE-2026-505

##

CVE-2026-62830
(9.9 CRITICAL)

EPSS: 0.43%

updated 2026-08-07T17:54:24.087000

1 posts

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-07T02:00:19.000Z ##

🔴 CVE-2026-62830 - Critical (9.9)

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63508
(10.0 CRITICAL)

EPSS: 0.45%

updated 2026-08-07T17:48:43.770000

3 posts

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

AAKL@infosec.exchange at 2026-08-07T16:00:15.000Z ##

If you missed these yesterday.

"Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10."

Security Week: Microsoft, Apple Release Fresh Security Updates securityweek.com/microsoft-app #Microsoft #Apple #infosec #vylnerability #Apple

##

offseq@infosec.exchange at 2026-08-07T04:30:24.000Z ##

CVE-2026-63508 (CRITICAL, CVSS 10): Microsoft Planetary Computer Pro (GeoCatalog) suffers from missing authentication, enabling remote privilege escalation. Immediate patching recommended. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Microsoft #Infosec

##

thehackerwire@mastodon.social at 2026-08-07T02:00:09.000Z ##

🔴 CVE-2026-63508 - Critical (10)

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70332
(9.6 CRITICAL)

EPSS: 0.43%

updated 2026-08-07T17:45:01.200000

2 posts

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

offseq@infosec.exchange at 2026-08-07T01:30:26.000Z ##

Critical SSRF (CVE-2026-70332) in Microsoft SharePoint Online (CVSS 9.6) lets attackers send unauthorized network requests. Patch ASAP with the official fix: radar.offseq.com/threat/cve-20 #OffSeq #InfoSec #Microsoft #SSRF #CloudSecurity

##

thehackerwire@mastodon.social at 2026-08-07T01:00:09.000Z ##

🔴 CVE-2026-70332 - Critical (9.6)

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67863
(7.5 HIGH)

EPSS: 0.41%

updated 2026-08-07T15:33:07

1 posts

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.

thehackerwire@mastodon.social at 2026-08-05T23:59:50.000Z ##

🟠 CVE-2026-67863 - High (7.5)

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredIte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54212
(0 None)

EPSS: 0.66%

updated 2026-08-07T15:17:01.830000

1 posts

Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, such as one that is at least 8 characters long and begins with a number, an unauthenticated attacker can cause the server to crash, resulting in denial of service. Depending on the stack state or if a stack canary can b

offseq@infosec.exchange at 2026-08-07T12:00:26.000Z ##

CVE-2026-54212: CRITICAL buffer overflow in Tobit TeamDavid Webbox API (≤ Rollout 524). Crafted JSON lets unauthenticated attackers crash servers; RCE possible if combined with other flaws. Restrict API, monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #CVE #bufferOverflow #infosec

##

CVE-2026-54211
(0 None)

EPSS: 0.64%

updated 2026-08-07T15:17:01.713000

1 posts

Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values in these parameters, an authenticated attacker can trigger a server crash, resulting in denial of service. Depending on the stack state or if a stack canary can be disclosed through

offseq@infosec.exchange at 2026-08-07T13:30:16.000Z ##

Tobit TeamDavid (Webbox ≤ Rollout 524) hit by CRITICAL buffer overflow (CVE-2026-54211). Authenticated attackers can crash servers; possible RCE if stack canary is disclosed. Restrict access & monitor. No patch yet. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #InfoSec

##

CVE-2026-54213
(0 None)

EPSS: 0.71%

updated 2026-08-07T14:16:59.710000

1 posts

Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of “restarting”, the server shuts completely down. As a result, a remote attacker can trigger a persistent denial of service by shuttin

offseq@infosec.exchange at 2026-08-07T10:30:25.000Z ##

CVE-2026-54213: CRITICAL improper access control in Tobit TeamDavid Webbox — public /internalRestart endpoint lets remote attackers trigger persistent DoS by shutting down servers. No patch yet. Restrict access & monitor. radar.offseq.com/threat/cve-20 #OffSeq #Cybersecurity #Vuln

##

CVE-2026-9196
(8.1 HIGH)

EPSS: 0.27%

updated 2026-08-07T13:16:53.430000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user approval, which may allow an attacker to trigger side effects such as outbound network access, file system

thehackerwire@mastodon.social at 2026-08-05T20:00:08.000Z ##

🟠 CVE-2026-9196 - High (8.1)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34486
(7.5 HIGH)

EPSS: 81.16%

updated 2026-08-07T12:37:06.283000

3 posts

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

6 repos

https://github.com/punitdarji/tomcat-cve-2026-34486

https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction

https://github.com/AirSkye/CVE-2026-34486-poc

https://github.com/striga-ai/CVE-2026-34486

https://github.com/404-src/CVE-2026-34486

https://github.com/anonmrc/CVE-2026-34486-e-Tomcat-Tribes

security_crawler_carl@infosec.exchange at 2026-08-07T07:27:32.000Z ##

🏆 New Achievement! Patch Notes From Hell!

Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)

##

beyondmachines1@infosec.exchange at 2026-08-06T11:01:31.000Z ##

CISA Reports Active Exploitation of Apache Tomcat RCE Vulnerability

CISA reports active exploitation of an Apache Tomcat vulnerability (CVE-2026-34486) to its KEV catalog after Chinese threat actors exploited a fail-open logic error in the EncryptInterceptor to achieve remote code execution.

**If you run Apache Tomcat with clustering enabled, upgrade ASAP to 9.0.117, 10.1.54, or 11.0.21 This flaw is being actively exploited and can give attackers full remote code execution on every node in the cluster. If you can't patch, make sure your cluster traffic ports are not reachable from the internet, check `server.xml` and `context.xml` to confirm EncryptInterceptor is active with no custom interceptors overriding it, and turn off plain HTTP in favour of HTTPS only.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-08-05T11:47:47.000Z ##

🚨 CISA KEV ALERT: CVE-2026-34486 exposes Apache Tomcat installations to EncryptInterceptor bypasses and data interception. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection queries, and hardening steps: thecybermind.co/it1p

Top-of-the-Line LinkedIn Post

##

CVE-2026-9169
(8.8 HIGH)

EPSS: 0.14%

updated 2026-08-07T09:32:04

2 posts

DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally.

thehackerwire@mastodon.social at 2026-08-07T17:00:51.000Z ##

🟠 CVE-2026-9169 - High (8.8)

DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH en...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-07T17:00:51.000Z ##

🟠 CVE-2026-9169 - High (8.8)

DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH en...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71312
(8.0 HIGH)

EPSS: 0.28%

updated 2026-08-07T05:17:03.537000

1 posts

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controll

thehackerwire@mastodon.social at 2026-08-05T22:01:04.000Z ##

🟠 CVE-2026-71312 - High (8)

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62918
(7.5 HIGH)

EPSS: 0.30%

updated 2026-08-07T00:31:33

1 posts

Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.

thehackerwire@mastodon.social at 2026-08-07T01:59:58.000Z ##

🟠 CVE-2026-62918 - High (7.5)

Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62896
(9.6 CRITICAL)

EPSS: 0.39%

updated 2026-08-07T00:31:33

1 posts

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-07T01:01:32.000Z ##

🔴 CVE-2026-62896 - Critical (9.6)

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65668
(8.8 HIGH)

EPSS: 0.43%

updated 2026-08-07T00:31:33

1 posts

Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-07T01:01:11.000Z ##

🟠 CVE-2026-65668 - High (8.8)

Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59115
(9.9 CRITICAL)

EPSS: 0.63%

updated 2026-08-07T00:31:28

1 posts

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-07T03:00:17.000Z ##

🔴 CVE-2026-59115 - Critical (9.9)

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8325
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-07T00:31:28

1 posts

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

thehackerwire@mastodon.social at 2026-08-06T22:59:59.000Z ##

🟠 CVE-2026-8325 - High (7.8)

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62836
(8.7 HIGH)

EPSS: 0.36%

updated 2026-08-07T00:31:27

2 posts

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

hugovalters@mastodon.social at 2026-08-07T23:00:55.000Z ##

CVE-2026-62836 - Privilege escalation in Azure SQL Managed Instance via improper endpoint restriction. CVSS 8.7. Unpatched. Restrict network access and monitor. #CVE #Azure #infosec

valtersit.com/cve/CVE-2026-628

##

thehackerwire@mastodon.social at 2026-08-07T03:00:06.000Z ##

🟠 CVE-2026-62836 - High (8.7)

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56162
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-08-07T00:31:27

2 posts

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

hugovalters@mastodon.social at 2026-08-07T17:09:18.000Z ##

CVE-2026-56162 - Critical auth bypass in Azure SQL Database. Privilege escalation over network, CVSS 10. Unpatched - assume exposure. Mitigate immediately. #CVE #Azure #infosec

valtersit.com/cve/CVE-2026-561

##

AAKL@infosec.exchange at 2026-08-07T16:00:15.000Z ##

If you missed these yesterday.

"Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10."

Security Week: Microsoft, Apple Release Fresh Security Updates securityweek.com/microsoft-app #Microsoft #Apple #infosec #vylnerability #Apple

##

CVE-2026-59118
(9.3 CRITICAL)

EPSS: 0.40%

updated 2026-08-07T00:31:27

1 posts

Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-07T03:00:28.000Z ##

🔴 CVE-2026-59118 - Critical (9.3)

Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66665
(10.0 CRITICAL)

EPSS: 0.29%

updated 2026-08-06T22:18:19.223000

1 posts

Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

thehackerwire@mastodon.social at 2026-08-06T21:00:57.000Z ##

🔴 CVE-2026-66665 - Critical (10)

Unauthenticated Arbitrary File Upload in Type Hub &lt;= 2.0.6 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65575
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-08-06T22:18:16.713000

1 posts

Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.

thehackerwire@mastodon.social at 2026-08-06T22:00:19.000Z ##

🔴 CVE-2026-65575 - Critical (9.8)

Unauthenticated PHP Object Injection in Accalia &lt;= 1.5.3 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53977
(7.5 HIGH)

EPSS: 0.52%

updated 2026-08-06T22:17:42.007000

1 posts

OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authentication middleware in the Express route handler chain. Attackers can exploit the route registration order in bootstrap-runtime.js to reach the shutdown ha

thehackerwire@mastodon.social at 2026-08-06T17:00:06.000Z ##

🟠 CVE-2026-53977 - High (7.5)

OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authenti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-3430
(8.6 HIGH)

EPSS: 0.24%

updated 2026-08-06T22:17:04.190000

1 posts

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.

1 repos

https://github.com/JoakimBulow/CVE-2026-34308

thehackerwire@mastodon.social at 2026-08-06T17:00:34.000Z ##

🟠 CVE-2026-3430 - High (8.6)

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18427
(7.5 HIGH)

EPSS: 0.46%

updated 2026-08-06T22:16:50.143000

1 posts

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and before delegating to the send layer. As a result, an unauthenticated attacker could request a file protected by a route

thehackerwire@mastodon.social at 2026-08-06T20:00:04.000Z ##

🟠 CVE-2026-18427 - High (7.5)

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or back...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15991
(8.8 HIGH)

EPSS: 0.61%

updated 2026-08-06T22:16:48.620000

1 posts

The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server, which can lead to remote code execution when the right file is deleted (such as

thehackerwire@mastodon.social at 2026-08-06T07:00:21.000Z ##

🟠 CVE-2026-15991 - High (8.8)

The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16633(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-08-06T21:12:27

1 posts

### Impact If PDF.js is used to load a malicious PDF, and PDF.js is configured with `enableScripting` set to true (which is the default value) and no CSP for disallowing script-src, unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain. ### Patches ### Workarounds Set `enableScripting` to `false` or set a CSP.

offseq@infosec.exchange at 2026-08-07T06:00:24.000Z ##

Vulnerability in ngx-extended-pdf-viewer (HIGH): Bundled pdf.js exposes XFA (enabled by default), risking JS execution via malicious PDFs (CVE-2026-16633). Update to 29.0.0-rc.3 or disable XFA for mitigation. radar.offseq.com/threat/ngx-ex #OffSeq #Vulnerability #PDF #Infosec

##

CVE-2026-17624
(8.5 HIGH)

EPSS: 0.38%

updated 2026-08-06T19:32:05.107000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of module imports.

thehackerwire@mastodon.social at 2026-08-06T04:00:05.000Z ##

🟠 CVE-2026-17624 - High (8.5)

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17633
(8.5 HIGH)

EPSS: 0.40%

updated 2026-08-06T19:31:40.753000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.

thehackerwire@mastodon.social at 2026-08-06T03:00:10.000Z ##

🟠 CVE-2026-17633 - High (8.5)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8183
(7.7 HIGH)

EPSS: 0.37%

updated 2026-08-06T18:55:31.633000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to v i ew arbitrary files on the system.

thehackerwire@mastodon.social at 2026-08-05T20:01:13.000Z ##

🟠 CVE-2026-8183 - High (7.7)

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9201
(8.8 HIGH)

EPSS: 0.23%

updated 2026-08-06T18:31:34.390000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is enabled, the application validates component code using a truncated SHA‑256 hash. Because the hash comparison relies on only a p

thehackerwire@mastodon.social at 2026-08-05T20:00:17.000Z ##

🟠 CVE-2026-9201 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to truste...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53985
(7.5 HIGH)

EPSS: 0.38%

updated 2026-08-06T18:30:56

1 posts

Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sending a single restart_service command. Attackers can connect to the Socket.IO server on port 7000 without credentials due to disabled authentication enfor

thehackerwire@mastodon.social at 2026-08-06T17:00:17.000Z ##

🟠 CVE-2026-53985 - High (7.5)

Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18359
(8.5 HIGH)

EPSS: 0.22%

updated 2026-08-06T18:30:48

1 posts

Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or iiif_uri parameter of POST /api/documents/{pk}/imports/, because the IMPORT_ALLOWED_DOMAINS setting defaults to '*' and n

thehackerwire@mastodon.social at 2026-08-06T18:59:55.000Z ##

🟠 CVE-2026-18359 - High (8.5)

Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metada...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18258
(8.8 HIGH)

EPSS: 0.31%

updated 2026-08-06T18:30:47

1 posts

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset

thehackerwire@mastodon.social at 2026-08-06T20:00:22.000Z ##

🟠 CVE-2026-18258 - High (8.8)

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via prim...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66712
(7.5 HIGH)

EPSS: 0.22%

updated 2026-08-06T16:16:49.343000

1 posts

Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.

thehackerwire@mastodon.social at 2026-08-06T16:00:51.000Z ##

🟠 CVE-2026-66712 - High (7.5)

Unauthenticated Broken Access Control in Simple Membership &lt;= 4.7.8 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15459
(8.1 HIGH)

EPSS: 0.51%

updated 2026-08-06T16:16:36.700000

1 posts

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature is empty, making the signature verified by validate_hash() trivially forgeable; version 5.0.0 additionally removed the replay

thehackerwire@mastodon.social at 2026-08-06T07:00:10.000Z ##

🟠 CVE-2026-15459 - High (8.1)

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20301
(8.6 HIGH)

EPSS: 0.33%

updated 2026-08-06T15:44:56.043000

1 posts

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerabil

thehackerwire@mastodon.social at 2026-08-06T08:00:51.000Z ##

🟠 CVE-2026-20301 - High (8.6)

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20310
(9.1 CRITICAL)

EPSS: 0.37%

updated 2026-08-06T15:44:56.043000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access

thehackerwire@mastodon.social at 2026-08-06T08:00:19.000Z ##

🔴 CVE-2026-20310 - Critical (9.1)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20267
(9.0 CRITICAL)

EPSS: 0.23%

updated 2026-08-06T15:44:56.043000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by&nbsp;CVE-2026-20267 are related to improper access control issues that ar

CVE-2026-20303
(9.9 CRITICAL)

EPSS: 0.29%

updated 2026-08-06T15:44:56.043000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are g

CVE-2026-66709
(9.1 CRITICAL)

EPSS: 0.48%

updated 2026-08-06T15:32:56

1 posts

Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.

thehackerwire@mastodon.social at 2026-08-06T21:00:45.000Z ##

🔴 CVE-2026-66709 - Critical (9.1)

Shop manager Remote Code Execution (RCE) in CTX Feed &lt;= 6.6.42 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66708
(8.2 HIGH)

EPSS: 0.22%

updated 2026-08-06T15:32:56

1 posts

Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.

thehackerwire@mastodon.social at 2026-08-06T21:00:35.000Z ##

🟠 CVE-2026-66708 - High (8.2)

Unauthenticated Broken Access Control in Total Upkeep &lt;= 1.17.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66710
(8.1 HIGH)

EPSS: 0.30%

updated 2026-08-06T15:32:56

1 posts

Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.

thehackerwire@mastodon.social at 2026-08-06T16:00:40.000Z ##

🟠 CVE-2026-66710 - High (8.1)

Unauthenticated Local File Inclusion in e2pdf &lt;= 1.32.40 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66662
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-08-06T15:32:55

1 posts

Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.

thehackerwire@mastodon.social at 2026-08-06T22:00:09.000Z ##

🔴 CVE-2026-66662 - Critical (9.8)

Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps &lt;= 3.29.10 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66447
(9.3 CRITICAL)

EPSS: 0.24%

updated 2026-08-06T15:32:55

1 posts

Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.

thehackerwire@mastodon.social at 2026-08-06T21:59:59.000Z ##

🔴 CVE-2026-66447 - Critical (9.3)

Unauthenticated SQL Injection in WordPress File Upload &lt;= 5.1.7 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66733
(7.5 HIGH)

EPSS: 0.89%

updated 2026-08-06T15:32:48

1 posts

Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauthenticated remote attackers to crash the server process by sending a crafted UDP packet with mUniquePacketID set to the maximum uint32 value. The mUniquePacketID field is read directly from the UDP wire-format packet header without bounds checking, cau

offseq@infosec.exchange at 2026-08-06T13:30:24.000Z ##

CVE-2026-66733: HIGH severity vuln in Eukaryot sonic3air ≤26.03.28.0. Crafted UDP packets can force unbounded memory allocation, crashing the server (DoS, no RCE). Patch unconfirmed — check vendor. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #DoS #sonic3air

##

CVE-2026-5430
(10.0 CRITICAL)

EPSS: 0.22%

updated 2026-08-06T15:31:57.827000

2 posts

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of adm

DailyCyberSecurity@infosec.exchange at 2026-08-07T13:05:48.000Z ##

WSO2 patched four critical account takeover flaws, including CVE-2026-5430 at CVSS 10 via JWT auth bypass. Details and fixes inside.

#WSO2 #AccountTakeover #CVE #APIsecurity #CyberSecurity

securityonline.info/wso2-accou

##

offseq@infosec.exchange at 2026-08-06T09:00:30.000Z ##

WSO2 Universal Gateway v4.5.0 & 4.6.0 affected by CRITICAL CVE-2026-5430 (CVSS 10.0). Improper JWT validation enables account takeover. No patch yet — apply compensating controls. radar.offseq.com/threat/cve-20 #OffSeq #WSO2 #JWT #Vulnerability

##

CVE-2026-71321
(7.5 HIGH)

EPSS: 0.42%

updated 2026-08-06T14:16:44.860000

1 posts

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attacker-controlled JSON body input with destr and ohash before validating the URL-resident hash. An unauthenticated `POST /__nuxt_island/_.json` with a large JSON body is fully read, parsed, hashed, and then rejected, which

thehackerwire@mastodon.social at 2026-08-05T23:00:58.000Z ##

🟠 CVE-2026-71321 - High (7.5)

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attacker-controlled JSON body input with destr and ohash before validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71314
(7.5 HIGH)

EPSS: 0.40%

updated 2026-08-06T14:16:43.490000

1 posts

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until MAX_VFOR_LENGTH = 100000 and crash the Nuxt process. This issue is fixed in 3.21.10 and 4.5.1.

thehackerwire@mastodon.social at 2026-08-05T21:59:50.000Z ##

🟠 CVE-2026-71314 - High (7.5)

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until MAX_VFOR_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18411
(8.1 HIGH)

EPSS: 0.34%

updated 2026-08-06T14:16:31.853000

1 posts

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization.

thehackerwire@mastodon.social at 2026-08-05T22:01:23.000Z ##

🟠 CVE-2026-18411 - High (8.1)

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67869
(7.5 HIGH)

EPSS: 0.47%

updated 2026-08-06T13:18:23.103000

1 posts

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata

thehackerwire@mastodon.social at 2026-08-06T00:59:47.000Z ##

🟠 CVE-2026-67869 - High (7.5)

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-1728
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-08-06T09:30:39

1 posts

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able

offseq@infosec.exchange at 2026-08-06T10:30:25.000Z ##

CVE-2026-1728 | CRITICAL: WSO2 API Manager (v4.0.0 – 4.6.0) has an improper privilege management flaw. Low-privileged user tokens can access admin REST APIs — possible admin account takeover. Patch status unknown. Restrict access & monitor. radar.offseq.com/threat/cve-20 #OffSeq #WSO2 #Vuln

##

CVE-2026-44945
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-08-06T05:17:03.793000

1 posts

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.

offseq@infosec.exchange at 2026-08-05T10:30:25.000Z ##

SUSE Rancher CVE-2026-44945 (CRITICAL, CVSS 9.1): Privilege escalation flaw lets authenticated users with default global role gain full admin on Rancher & clusters. Restrict access & monitor pending patch. radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202644945 #Kubernetes

##

CVE-2026-18485
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-06T05:16:40.767000

1 posts

There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to escalate privileges and execute arbitrary code.  This vulnerability affects NI-PAL 26.3.1 and prior versions running on Microsoft Windows.

thehackerwire@mastodon.social at 2026-08-06T03:00:20.000Z ##

🟠 CVE-2026-18485 - High (7.8)

There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to escalate privileges and execute arbitrary code.  This vulnerability affects NI-PAL 26.3.1 and p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70432
(8.8 HIGH)

EPSS: 0.21%

updated 2026-08-05T21:32:44

1 posts

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.

thehackerwire@mastodon.social at 2026-08-06T07:00:32.000Z ##

🟠 CVE-2026-70432 - High (8.8)

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70426
(9.0 None)

EPSS: 0.29%

updated 2026-08-05T21:32:44

2 posts

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization

thehackerwire@mastodon.social at 2026-08-06T04:00:16.000Z ##

🔴 CVE-2026-70426 - Critical (9)

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserializa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-08-06T01:06:12.000Z ##

Critical Jenkins vulnerability CVE-2026-70426 lets attackers bypass the JEP-200 filter and run code on the controller. Patch now.
#Jenkins #CVE202670426 #RCE #DevSecOps #Deserialization #CyberSecurity

securityonline.info/jenkins-cv

##

CVE-2026-70431
(8.8 HIGH)

EPSS: 0.37%

updated 2026-08-05T21:32:41

1 posts

Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.

thehackerwire@mastodon.social at 2026-08-06T04:00:27.000Z ##

🟠 CVE-2026-70431 - High (8.8)

Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70615
(9.9 CRITICAL)

EPSS: 0.21%

updated 2026-08-05T21:31:48

1 posts

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter of the tunnel creation endpoint. Attackers can insert an unrestricted public key entry into authorize

thehackerwire@mastodon.social at 2026-08-05T20:59:59.000Z ##

🔴 CVE-2026-70615 - Critical (9.9)

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34966
(7.6 HIGH)

EPSS: 0.31%

updated 2026-08-05T21:31:47

1 posts

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints

thehackerwire@mastodon.social at 2026-08-05T22:00:09.000Z ##

🟠 CVE-2026-34966 - High (7.6)

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17632
(8.8 HIGH)

EPSS: 0.45%

updated 2026-08-05T21:31:46

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.

thehackerwire@mastodon.social at 2026-08-06T03:00:30.000Z ##

🟠 CVE-2026-17632 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17583
(8.4 HIGH)

EPSS: 0.14%

updated 2026-08-05T21:31:46

1 posts

The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.

1 repos

https://github.com/HORKimhab/CVE-2026-17583

thehackerwire@mastodon.social at 2026-08-05T22:01:13.000Z ##

🟠 CVE-2026-17583 - High (8.4)

The affected

Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69111
(7.5 HIGH)

EPSS: 0.57%

updated 2026-08-05T21:31:46

1 posts

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exploit the unprotected /management/stop endpoint, which bypasses REST API authentication middleware, by supplying a 'role' parameter to shut down the proxy

thehackerwire@mastodon.social at 2026-08-05T21:00:18.000Z ##

🟠 CVE-2026-69111 - High (7.5)

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70617
(8.1 HIGH)

EPSS: 0.23%

updated 2026-08-05T21:31:46

1 posts

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT /channels/{channel_id}/recipients/{user_id} handler to join private group DMs, read complete m

thehackerwire@mastodon.social at 2026-08-05T21:00:09.000Z ##

🟠 CVE-2026-70617 - High (8.1)

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without member...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8182
(8.8 HIGH)

EPSS: 0.38%

updated 2026-08-05T21:31:39

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.

thehackerwire@mastodon.social at 2026-08-05T20:01:02.000Z ##

🟠 CVE-2026-8182 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8478
(8.8 HIGH)

EPSS: 0.37%

updated 2026-08-05T21:31:39

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.

thehackerwire@mastodon.social at 2026-08-05T20:00:27.000Z ##

🟠 CVE-2026-8478 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71320
(8.1 HIGH)

EPSS: 0.44%

updated 2026-08-05T21:29:56

1 posts

## Impact Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When `vue.runtimeCompiler: true` is enabled (off by default) and the application has a server island component that forwards props into Vue's dynamic component resolution (`<component :is>`, `resolveDynamicComponent`, or `h()`), an attacker can inject a `template` key into the island props to achieve server-side remote

thehackerwire@mastodon.social at 2026-08-05T23:00:49.000Z ##

🟠 CVE-2026-71320 - High (8.1)

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing temp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71319
(9.6 CRITICAL)

EPSS: 0.32%

updated 2026-08-05T21:27:39

2 posts

### Impact Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the `nuxt:devtools:rpc` plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (`ws://<host>:<port>/`, subprotocol `vite-hmr`) can call RPC methods, with no token, handshake, or origin check before the channel is established.

offseq@infosec.exchange at 2026-08-06T03:00:29.000Z ##

Nuxt DevTools <3.3.1 is affected by CVE-2026-71319 (CRITICAL). Unauthenticated Vite HMR WebSocket RPC lets attackers execute arbitrary code via updateOptions() & openInEditor(). Patch to 3.3.1 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #NuxtJS #CVE202671319 #infosec

##

thehackerwire@mastodon.social at 2026-08-05T23:00:39.000Z ##

🔴 CVE-2026-71319 - Critical (9.6)

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel h...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71316
(7.5 HIGH)

EPSS: 0.30%

updated 2026-08-05T21:14:34

1 posts

### Impact When a page is covered by `routeRules` `cache` / `swr` / `isr`, Nuxt enables runtime payload extraction and serves `/<page>/_payload.json`. On affected versions the renderer stored the SSR payload in the shared `cache:nuxt:payload` storage under a path-only key (no cookie, `authorization`, or `cache.varies` dimension) and, on a later payload request, returned the cached entry before ro

thehackerwire@mastodon.social at 2026-08-05T23:59:59.000Z ##

🟠 CVE-2026-71316 - High (7.5)

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for //_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71315
(8.2 HIGH)

EPSS: 0.27%

updated 2026-08-05T21:05:19

1 posts

### Impact Nuxt matches route rules case-insensitively by default (mirroring vue-router's default `sensitive: false` routing). The fix for GHSA-mm7m-92g8-7m47 / CVE-2026-53721 lowercased the *lookup* path before matching route rules, but the route-rule *keys* compiled into the matcher were left verbatim. As a result, any route rule whose key contains an uppercase character (for example `/Admin`,

thehackerwire@mastodon.social at 2026-08-05T21:59:59.000Z ##

🟠 CVE-2026-71315 - High (8.2)

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorization gates. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 1.01%

updated 2026-08-05T18:32:31

7 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

3 repos

https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap

https://github.com/sfewer-r7/CVE-2026-63077

https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

Matchbook3469@mastodon.social at 2026-08-07T16:55:57.000Z ##

🔵 THREAT INTELLIGENCE

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

Vulnerability | CRITICAL
CVEs: CVE-2026-63077

A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the...

Full analysis:
yazoul.net/news/article/cisa-f

by Yazoul AI

#CyberSecurity #CVE #SecurityOps

##

patrickcmiller@infosec.exchange at 2026-08-06T22:12:01.000Z ##

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild thehackernews.com/2026/08/cisa

##

thecybermind@infosec.exchange at 2026-08-06T11:58:45.000Z ##

🚨 CSUITE THREAT ADVISORY: CISA confirms active exploitation of CVE-2026-63077 in JetBrains TeamCity. Unauthenticated RCE threatens core build pipelines & supply chain integrity. Get the executive governance, risk management, and compliance brief now: thecybermind.co/jvee

##

DailyCyberSecurity@infosec.exchange at 2026-08-06T01:44:36.000Z ##

TeamCity vulnerability CVE-2026-63077 enables unauthenticated remote code execution. CISA added it to the KEV catalog amid active exploitation.

#TeamCity #CVE202663077 #RCE #CISA #KEV #CyberSecurity

securityonline.info/teamcity-c

##

thecybermind@infosec.exchange at 2026-08-05T20:36:39.000Z ##

🚨 CISA KEV ALERT: CVE-2026-63077 exposes JetBrains TeamCity servers to unauthenticated RCE via untrusted deserialization. Active exploitation confirmed. Get the forensic breakdown, CrowdStrike CQL detection logic, and CI/CD hardening steps: thecybermind.co/oapr

##

secdb@infosec.exchange at 2026-08-05T19:00:10.000Z ##

🚨 [CISA-2026:0805] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-63077 (secdb.nttzen.cloud/cve/detail/)
- Name: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JetBrains
- Product: TeamCity
- Notes: blog.jetbrains.com/teamcity/20; jetbrains.com/privacy-security ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260805 #cisa20260805 #cve_2026_63077 #cve202663077

##

cisakevtracker@mastodon.social at 2026-08-05T18:00:45.000Z ##

CVE ID: CVE-2026-63077
Vendor: JetBrains
Product: TeamCity
Date Added: 2026-08-05
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-20313
(7.7 HIGH)

EPSS: 0.25%

updated 2026-08-05T18:31:49

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20313 are related to Improper link resolution before file access i

thehackerwire@mastodon.social at 2026-08-06T08:00:07.000Z ##

🟠 CVE-2026-20313 - High (7.7)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20312
(8.8 HIGH)

EPSS: 0.19%

updated 2026-08-05T18:31:49

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information is

thehackerwire@mastodon.social at 2026-08-05T18:00:37.000Z ##

🟠 CVE-2026-20312 - High (8.8)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address mu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20304
(9.9 CRITICAL)

EPSS: 0.25%

updated 2026-08-05T18:31:49

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grou

CVE-2026-9077
(8.5 HIGH)

EPSS: 0.31%

updated 2026-08-05T18:31:48

1 posts

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.

thehackerwire@mastodon.social at 2026-08-05T18:00:16.000Z ##

🟠 CVE-2026-9077 - High (8.5)

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20272
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-05T18:31:45

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of specia

CVE-2026-20200
(8.8 HIGH)

EPSS: 0.84%

updated 2026-08-05T18:31:42

2 posts

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp; This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inp

1 repos

https://github.com/NSIDE-ATTACK-LOGIC/CIMCown

DailyCyberSecurity@infosec.exchange at 2026-08-07T01:40:55.000Z ##

PoC exploit code is public for CVE-2026-20200, a Cisco IMC argument injection flaw enabling root RCE. CVSS 8.8. Patch details inside.

#Cisco #RCE #CVE #InfoSec #CyberSecurity

securityonline.info/cisco-imc-

##

security_crawler_carl@infosec.exchange at 2026-08-06T18:46:14.000Z ##

🏆 New Achievement! Root Access: Now Available In Select Markets While Supplies Last!

TERMS AND CONDITIONS APPLY. Cisco IMC (CVE-2026-20200) is now eligible for the Root Prize Draw, in which any authenticated remote attacker — even one with low privileges, congratulations to them — may submit crafted inputs to the web-based management interface for a chance to execute arbitrary commands as root on your rack server. (1/3)

##

CVE-2026-71294
(7.6 HIGH)

EPSS: 0.22%

updated 2026-08-05T16:17:08.827000

1 posts

Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a `ci` POST parameter obtained via `cot_import('ci', 'P', 'TXT')` (trim-only sanitization) is passed to `unserialize(base64_decode($ci))` with no `allowed_classes` restriction, reachable by any member with write access to

thehackerwire@mastodon.social at 2026-08-05T14:00:10.000Z ##

🟠 CVE-2026-71294 - High (7.6)

Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a `ci` POST parameter obtained via `cot_import('ci', 'P', 'TXT')` (tr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71287
(8.8 HIGH)

EPSS: 0.25%

updated 2026-08-05T16:17:08.190000

1 posts

Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and table.column), a payload such as `SLEEP(5)` passes through completely unmodified. The sanitized value is

thehackerwire@mastodon.social at 2026-08-05T14:00:30.000Z ##

🟠 CVE-2026-71287 - High (8.8)

Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71285
(8.1 HIGH)

EPSS: 0.21%

updated 2026-08-05T16:17:07.967000

1 posts

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a <script> block rendered on every public status page: `_paq.push(['setSiteId', ${escapedSiteIdHTMLAttribute}]);`. The escaping pipeline used (jsesc with isScriptContext:true, then html-escaper.escape()) does not esc

thehackerwire@mastodon.social at 2026-08-05T14:00:20.000Z ##

🟠 CVE-2026-71285 - High (8.1)

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a block rendered on every public status page: `_paq.push(['set...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-4431
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-08-05T16:16:57.470000

1 posts

The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv_rbsm_submit_post` without any authorization checks when a `postId` parameter is

offseq@infosec.exchange at 2026-08-05T09:00:27.000Z ##

CVE-2026-4431: CRITICAL vuln in Easy Post Submission ≤2.3.0 for WordPress. Missing auth lets unauthenticated attackers modify or unpublish any post via AJAX. No patch yet — disable plugin if possible. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #CVE20264431

##

CVE-2026-71289
(9.8 CRITICAL)

EPSS: 0.37%

updated 2026-08-05T15:32:29

1 posts

The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. "${ION_MGR_PORT:-8089}:8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access Manager) gateway that is otherwise the system's sole authentic

offseq@infosec.exchange at 2026-08-05T13:30:25.000Z ##

CVE-2026-71289 (CRITICAL, CVSS 9.8): NASA-AMMOS ANMS exposes amp-manager REST API w/ no auth. Remote attackers can control system & disrupt ops. Restrict access, avoid default configs, check vendor for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE #NASA #Infosec

##

CVE-2026-66066
(0 None)

EPSS: 1.77%

updated 2026-08-05T15:17:03.507000

1 posts

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated a

7 repos

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

https://github.com/0xsha/KindaRails2Shell

https://github.com/rails/rails-forensics-CVE-2026-66066

https://github.com/shinthink/CVE-2026-66066

https://github.com/paveg/rails-activestorage-vips-audit

https://github.com/HackSpeak/CVE-2026-66066

https://github.com/0xBlackash/CVE-2026-66066

security_crawler_carl@infosec.exchange at 2026-08-06T02:29:26.000Z ##

🏆 New Achievement! Upload In Peace, Active Storage!

We are gathered here today to mourn Active Storage, the earnest, overly-trusting file-handling component of Ruby on Rails, taken from us by CVE-2026-66066, nicknamed "KindaRails2Shell." It lived as it worked: accepting everything without question, like a golden retriever at a buffet. (1/3)

##

CVE-2026-66747
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-08-05T12:31:36

2 posts

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP

DailyCyberSecurity@infosec.exchange at 2026-08-07T02:30:41.000Z ##

CVE-2026-66747: a Zbtlink router backdoor named ENDLESSDOORS gives unauthenticated remote code execution as root. No fix exists. CVSS 9.8.

#Zbtlink #RouterBackdoor #CVE #IoT #CyberSecurity

securityonline.info/zbtlink-ro

##

catc0n@infosec.exchange at 2026-08-05T10:34:45.000Z ##

Today, VulnCheck is disclosing #ENDLESSDOORS, a phone-home implant CTO @albinolobster discovered in Zbtlink routers. ENDLESSDOORS starts automatically, runs with root privileges, and attempts to connect to command-and-control infrastructure roughly every 35 seconds. The backdoor ships by default across 20+ Zbtlink router models, which are white-labeled and sold on popular retail sites including Amazon, AliExpress, and Alibaba.

The implant and server implement no encryption or verification, meaning anyone along the network path can hijack the client-server communication and obtain a root shell on the device, regardless of the router's network position.

The VulnCheck CNA has assigned CVE-2026-66747 to track backdoored firmware versions; our blog also has guidance for defenders, including affected firmware images, hashes, network indicators, a YARA rule, and network signatures (Suricata / Snort).

vulncheck.com/blog/zbt-endless

##

CVE-2026-71254
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-08-05T12:31:34

1 posts

nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record() function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the total request size does not exceed 245 bytes and that each sub-request's record_length is at most 124, but it never validates the CUMULATIVE response size across all sub-requests before processing them.

offseq@infosec.exchange at 2026-08-05T12:00:26.000Z ##

CVE-2026-71254: CRITICAL out-of-bounds write in debevv nanoMODBUS (≤v1.23.0). Unauthenticated FC 0x14 requests can cause memory corruption, leading to DoS or RCE — especially on embedded targets. Patch/mitigate now. radar.offseq.com/threat/cve-20 #OffSeq #CVE #ICS #infosec

##

CVE-2026-71214
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-05T09:31:27

1 posts

The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no verification that the request actually originated from Hasura. By setting {"session_variab

offseq@infosec.exchange at 2026-08-05T07:30:25.000Z ##

CVE-2026-71214: NASA-AMMOS plandev sequencing-server has a CRITICAL vuln (CVSS 9.8) — unauthenticated users can inject commands by spoofing session roles or using whitelisted endpoints. Patch urgently. More: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #NASA #CyberSec #CVSS

##

CVE-2026-58073
(0 None)

EPSS: 0.22%

updated 2026-08-05T05:17:02.413000

1 posts

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.

beyondmachines1@infosec.exchange at 2026-08-06T10:01:09.000Z ##

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console

Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.

**If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-18556
(7.4 HIGH)

EPSS: 0.49%

updated 2026-08-05T05:16:46.967000

1 posts

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

1 repos

https://github.com/CreamyG31337/ncentral-compromise-ioc-triage

thecybermind@infosec.exchange at 2026-08-05T17:08:36.000Z ##

🚨 CISA KEV ALERT: CVE-2026-18556 exposes N-able N-central installations to authentication bypass via alternate channel paths. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection logic, and hardening guidance now: thecybermind.co/radr

##

CVE-2026-9198
(9.8 CRITICAL)

EPSS: 17.05%

updated 2026-08-04T21:30:25

2 posts

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

4 repos

https://github.com/0xgh057r3c0n/CVE-2026-9198

https://github.com/0xdak/CVE-2026-9198_exploit

https://github.com/rmhowe425/PoC-CVE-2026-9198

https://github.com/ywh-jfellus/CVE-2026-9198

security_crawler_carl@infosec.exchange at 2026-08-07T07:27:32.000Z ##

🏆 New Achievement! Patch Notes From Hell!

Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)

##

beyondmachines1@infosec.exchange at 2026-08-05T20:01:06.000Z ##

Actively Exploited IBM Langflow Vulnerability Allows Unauthenticated Remote Code Execution

IBM Langflow OSS injection vulnerability (CVE-2026-9198)is actively exploited. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and requires immediate patching/

**If you run IBM Langflow OSS (versions 1.0.0 through 1.10.0), update to version 1.10.1 or later immediately. Attackers are already using this flaw to take over servers. If you can't update immediately, take the Langflow instance off the internet, and check your logs for unexpected superuser tokens or odd Python code being run.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-24254
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-08-04T18:31:37

1 posts

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

CVE-2026-64633(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-08-04T18:31:36

1 posts

A vulnerability allowing remote unauthenticated code execution on the agent host.

1 repos

https://github.com/tfawnies/CVE-2026-64633

beyondmachines1@infosec.exchange at 2026-08-07T09:01:07.000Z ##

Veeam ONE Patches Critical Remote Code Execution and SQL Injection Flaws

Veeam ONE version 13 contains six vulnerabilities, including a CVSS 10.0 critical remote code execution flaw and a high-severity SQL injection bug. These vulnerabilities allow unauthenticated attackers to take over agent hosts, read arbitrary files, and extract sensitive database information.

**If you run Veeam ONE version 13, update it to build 13.1.0.7034. One of these flaws (CVE-2026-64633) lets an attacker take over the system remotely without any login or clicks from you. While you're at it, make sure Veeam ONE is only reachable from your trusted admin network, not from the internet or the general user network.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-58072(CVSS UNKNOWN)

EPSS: 0.38%

updated 2026-08-04T18:31:28

1 posts

A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.

beyondmachines1@infosec.exchange at 2026-08-06T10:01:09.000Z ##

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console

Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.

**If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-15920
(6.1 MEDIUM)

EPSS: 0.30%

updated 2026-08-04T18:16:45.087000

1 posts

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link. Exploitation re

CVE-2026-29146
(7.5 HIGH)

EPSS: 6.26%

updated 2026-08-04T13:18:02.797000

1 posts

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

security_crawler_carl@infosec.exchange at 2026-08-07T07:27:32.000Z ##

🏆 New Achievement! Patch Notes From Hell!

Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)

##

CVE-2026-64561(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-08-04T09:31:41

10 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid ro

5 repos

https://github.com/Aoripus-LTD/Zapscape-Fix

https://github.com/HackSpeak/CVE-2026-64561

https://github.com/aarif450/Zapscape

https://github.com/HORKimhab/CVE-2026-64561

https://github.com/aarif450/aarif450.github.io

cadusilva@bolha.one at 2026-08-07T16:28:32.000Z ##

Instale já a correção para vulnerabilidade em máquinas virtuais

Se você usa Proxmox ou apenas tem um VPS, atualize já seu sistema. O problema permite o escape de máquinas virtuais e acesso à máquina física.

Se usa Debian, saiu o kernel 6.12.101-1 que corrige o problema. O Proxmox também já lançou atualização mesmo para quem não é assinante com o kernel 7.0.14-9.

:debian: security-tracker.debian.org/tr
:xp_secure_server: forum.proxmox.com/threads/prox
:xp_sys_info: cve.org/CVERecord?id=CVE-2026-
:github: github.com/V4bel/Zapscape

@fediadminbr

#FediAdminBR #MastoAdmin

##

cadusilva@bolha.one at 2026-08-07T16:28:32.000Z ##

Instale já a correção para vulnerabilidade em máquinas virtuais

Se você usa Proxmox ou apenas tem um VPS, atualize já seu sistema. O problema permite o escape de máquinas virtuais e acesso à máquina física.

Se usa Debian, saiu o kernel 6.12.101-1 que corrige o problema. O Proxmox também já lançou atualização mesmo para quem não é assinante com o kernel 7.0.14-9.

:debian: security-tracker.debian.org/tr
:xp_secure_server: forum.proxmox.com/threads/prox
:xp_sys_info: cve.org/CVERecord?id=CVE-2026-
:github: github.com/V4bel/Zapscape

@fediadminbr

#FediAdminBR #MastoAdmin

##

DailyCyberSecurity@infosec.exchange at 2026-08-07T08:06:43.000Z ##

A new Linux Kernel KVM vulnerability threatens cloud servers with virtual machine escape risks. Learn about CVE-2026-64561 and secure your host machine now.

#LinuxKernel #KVMVulnerability #CVE202664561 #CloudSecurity #VMescape

securityexpress.info/linux-ker

##

ottoto2017@prattohome.com at 2026-08-07T04:19:17.000Z ##

「Zapscape KVMの新たな脆弱性により、特権を持つL1ゲストコードがLinuxホストに漏洩する可能性 」: #TheHackerNews

「Linuxカーネルの新たな脆弱性「Zapscape」 により、L1ゲスト仮想マシン(VM)内でカーネル権限を持つ攻撃者がKVM分離を回避し、ホスト上でコードを実行できる可能性があります。このリスクは、ネストされた仮想化が信頼できないゲストに公開されている場合に発生します。

この脆弱性は CVE-2026-64561 として追跡されており、ネストされたゲストメモリ変換に使用されるシャドウページテーブルを管理するKVM/x86のシャドウメモリ管理ユニット(MMU)に影響を与えます。

このバグを明らかにしたセキュリティ研究者の キム・ヒョヌ氏 は、実証されたエクスプロイト経路によって、カーネル権限、つまりroot権限でホスト上でコマンドを実行できると述べた。 」

thehackernews.com/2026/08/new-

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-08-07T02:04:59.000Z ##

CVE-2026-64561: Zapscape KVM Escape Runs Commands With Kernel Root Privilege, PoC Exploit Code Publicly Disclosed

securityonline.info/kvm-escape

##

TomSellers@infosec.exchange at 2026-08-07T00:45:01.000Z ##

Not sure if I'm late to that party on this one or not. Guest to host escape in Linux KVM.

Zapscape (CVE-2026-64561)
Zapscape is a use-after-free vulnerability in the shadow MMU emulation of KVM/x86, specifically in the recursive zap path that runs when shadow pages are reclaimed. It can trigger the bug with guest-side actions alone to corrupt the host kernel's shadow page, and it can threaten the guest-host isolation of KVM/x86 hosts that accept untrusted guests and expose nested virtualization, particularly multi-tenant x86 public clouds.

github.com/V4bel/Zapscape

#Security #Linux #VIrtualization

##

hn50@social.lansky.name at 2026-08-06T21:25:06.000Z ##

Zapscape (CVE-2026-64561): Guest-to-Host Escape in KVM/x86

Link: github.com/V4bel/Zapscape
Discussion: news.ycombinator.com/item?id=4

##

ngate@mastodon.social at 2026-08-06T17:42:15.000Z ##

🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated

##

h4ckernews@mastodon.social at 2026-08-06T17:42:10.000Z ##

Zapscape (CVE-2026-64561)

github.com/V4bel/Zapscape

Comments: news.ycombinator.com/item?id=4

#HackerNews #Zapscape #CVE-2026-64561 #cybersecurity #vulnerability #hackernews #open_source #software_security

##

CuratedHackerNews@mastodon.social at 2026-08-06T17:32:05.000Z ##

Zapscape (CVE-2026-64561): Guest-to-Host Escape in KVM/x86

github.com/V4bel/Zapscape

#github

##

CVE-2026-64531
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-01T09:30:23

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guar

4 repos

https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool

https://github.com/HackSpeak/CVE-2026-64531

https://github.com/suominen/ovswrap

https://github.com/0xBlackash/CVE-2026-64531

netsecio@mastodon.social at 2026-08-07T17:55:51.000Z ##

📰 Linux Kernel Flaw "OVSwrap" Allows Root Privilege Escalation

New Linux kernel LPE flaw 'OVSwrap' (CVE-2026-64531) allows local users to gain root. The bug in Open vSwitch datapath poses a critical risk to multi-tenant and container environments. Patch now! #Linux #Kernel #Vulnerability #CyberSecurity

🔗 cyber.netsecops.io/articles/li

##

CVE-2026-15969
(9.8 CRITICAL)

EPSS: 0.98%

updated 2026-07-31T18:33:17

1 posts

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.

DailyCyberSecurity@infosec.exchange at 2026-08-05T14:27:11.000Z ##

Six SGLang vulnerabilities include unauthenticated RCE via CVE-2026-15969, plus data and model-weight theft. No patch exists yet.

#SGLang #RCE #LLMSecurity #CVE202615969 #InfoSec

securityonline.info/sglang-vul

##

CVE-2026-28323
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-07-31T04:17:19.927000

2 posts

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

AAKL at 2026-08-07T17:20:10.660Z ##

This post is from yesterday.

Note: Arctic Wolf will sell your data without consent. You need to scroll to the bottom and opt out of being sold to unscrupulous third-parties.

Arctic Wolf: SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299 arcticwolf.com/resources/blog/

##

AAKL@infosec.exchange at 2026-08-07T17:20:10.000Z ##

This post is from yesterday.

Note: Arctic Wolf will sell your data without consent. You need to scroll to the bottom and opt out of being sold to unscrupulous third-parties.

Arctic Wolf: SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299 arcticwolf.com/resources/blog/ #infosec #vulnerability #privacy

##

CVE-2026-12943
(9.8 CRITICAL)

EPSS: 0.92%

updated 2026-07-31T04:16:46.070000

1 posts

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

DailyCyberSecurity@infosec.exchange at 2026-08-05T13:47:16.000Z ##

IBM critical vulnerabilities hit App Connect, Power HMC, and webMethods. CVE-2026-12943 lets attackers execute arbitrary commands at CVSS 9.8.

#IBM #CVE202612943 #RCE #InfoSec #VulnerabilityManagement

securityonline.info/ibm-critic

##

CVE-2026-64560
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-30T12:19:03.630000

2 posts

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec() posix_cpu_timer_del() // Observes old leader p = pid_task(pid, pid_type); de_thread() switch_leader(); release

1 repos

https://github.com/villager1314/CVE-2026-64560-Analysis

CVE-2025-68260
(7.8 HIGH)

EPSS: 0.16%

updated 2026-07-30T06:33:30

1 posts

In the Linux kernel, the following vulnerability has been resolved: rust_binder: fix race condition on death_list Rust Binder contains the following unsafe operation: // SAFETY: A `NodeDeath` is never inserted into the death list // of any node other than its owner, so it is either in this // death list or in no death list. unsafe { node_inner.death_list.remove(self) }; This operation is u

mrmasterkeyboard@mastodon.social at 2026-08-07T02:22:44.000Z ##

@cloudskater

For one, Rust is vibecoded now. There are Claude commits in it and probably more than GitHub is willing to tell me.
Two, users try to rewrite everything to Rust when there is no point. When Rust was no longer experimental in Linux it caused CVEs (CVE-2025-68260).
Three, Rust projects can take 10 seconds to compile or 20 minutes.
Four, it uses LLVM and that's bloated and vibecoded now.
Five, I generally just don't like it either. I prefer C and some other similar langs much more.

##

CVE-2026-20316
(5.3 MEDIUM)

EPSS: 0.79%

updated 2026-07-29T21:31:00

1 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vuln

AAKL@infosec.exchange at 2026-08-05T15:17:35.000Z ##

Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity support.broadcom.com/web/ecx/s #Broadcom

Cisco has a new advisory for a critical vulnerability that was published yesterday:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

This addresses a vulnerability that was first published on July 29:

High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 37.67%

updated 2026-07-29T17:16:51.683000

2 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp; This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this v

Nuclei template

1 repos

https://github.com/0xBlackash/CVE-2026-20079

offseq@infosec.exchange at 2026-08-06T07:30:27.000Z ##

CRITICAL vulnerabilities patched in Cisco SD-WAN, IOS XE, FMC, and IMC. FMC flaw (CVE-2026-20079, CVSS 10.0) allows remote root access; IMC PoC public. No active exploitation. Patch now: radar.offseq.com/threat/cisco- #OffSeq #Cisco #Vulnerability #PatchTuesday

##

AAKL@infosec.exchange at 2026-08-05T15:17:35.000Z ##

Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity support.broadcom.com/web/ecx/s #Broadcom

Cisco has a new advisory for a critical vulnerability that was published yesterday:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

This addresses a vulnerability that was first published on July 29:

High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-43728
(7.5 HIGH)

EPSS: 0.19%

updated 2026-07-28T21:31:22

1 posts

This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26.6. An attacker may be able to modify the state of the Keychain.

sayzard@mastodon.sayzard.org at 2026-08-07T20:40:21.000Z ##

The Keychain CVE Where Every Key Fits

macOS 26.4~26.5.2의 로그인 키체인에서 CVE-2026-43728이 발생해, GUI 로그인 세션이 열려 있는 경우 `security unlock-keychain`에 임의의 비밀번호나 빈 입력을 제공해도 잠금 해제가 성공할 수 있었습니다. 공격자는 SSH 세션이나 백그라운드 Swift 앱에서도 이를 악용해 로그인 키체인의 자격 증명·비밀을 읽거나 키체인 암호를 변경해 사용자 접근을 방해할 수 있었습니다. 문제는 macOS 26.4 이후의 사용자 인증 동작 변화와 연관된 것으로 보이며, Apple은 macOS Tahoe 26.6에서 수정했습니다. macOS 개발·...

boberito.medium.com/the-keycha

##

CVE-2026-39868
(9.1 CRITICAL)

EPSS: 0.94%

updated 2026-07-27T21:16:51.020000

1 posts

This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVE-2025-68686
(5.9 MEDIUM)

EPSS: 1.26%

updated 2026-07-27T18:31:25

1 posts

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases

daniel1820815@infosec.exchange at 2026-08-07T08:36:00.000Z ##

Hackers bypass patch using new FortiOS vulnerability

An actively exploited #vulnerability in #FortiOS allows for the bypass of a previous protection mechanism against manipulated symbolic links. Affected systems should be updated and checked for prior compromise.

Sensitive information on potentially compromised #FortiGate systems running FortiOS with SSL-VPN enabled may be at risk.

euvd.enisa.europa.eu/vulnerabi

Source: security-insider.de/fortios-ss

#Fortinet #CVE

##

CVE-2026-60667
(7.4 HIGH)

EPSS: 0.33%

updated 2026-07-24T21:32:15

1 posts

Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise PeopleSoft Enterprise HCM Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion

AwkwardTuring@infosec.exchange at 2026-08-07T08:07:34.000Z ##

@da_667 oh the number of times my sleep deprived brain tried to understand how the text in front of me relates to the CVE I thought to analyse *UNTIL I FIGURED THE SEARCH RESULTS WERE BORKED AND CVE-2026-60667 IS IN FACT NOT THE CVE I WAS ORIGINALLY LOOKING FOR* gave me serious PTSD.

Relieved to see I'm not the dumbo after all.

##

CVE-2026-65535
(4.3 MEDIUM)

EPSS: 0.18%

updated 2026-07-23T14:17:59.510000

2 posts

Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

dan@discuss.systems at 2026-08-08T02:15:49.000Z ##

CVE-2026-65535: Ranch Overflow

##

dan@discuss.systems at 2026-08-08T02:15:49.000Z ##

CVE-2026-65535: Ranch Overflow

##

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 75.76%

updated 2026-07-22T21:31:51

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

6 repos

https://github.com/WismanSec/sharepoint-2026-poc

https://github.com/ChPratik/CVE-2026-50522

https://github.com/darses/CVE-2026-50522

https://github.com/4minx/CVE-2026-50522

https://github.com/HORKimhab/CVE-2026-50522

https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept

netsecio@mastodon.social at 2026-08-07T17:55:43.000Z ##

📰 Microsoft SharePoint RCE Vulnerability Now Actively Exploited

🚨 ACTIVE EXPLOITATION: A critical RCE flaw in Microsoft SharePoint (CVE-2026-50522) is being exploited in the wild. Attackers can steal machine keys for persistent access even after patching. Patch immediately! #SharePoint #CyberSecurity #RCE

🔗 cyber.netsecops.io/articles/mi

##

CVE-2026-0288
(7.5 HIGH)

EPSS: 0.84%

updated 2026-07-10T18:33:13

2 posts

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server

AAKL at 2026-08-07T17:50:53.316Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0

##

AAKL@infosec.exchange at 2026-08-07T17:50:53.000Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi #Cisco

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid #Microsoft

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/ #Google #Chrome

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100 #Apple

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s #AMD

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability #Java #SQL

##

CVE-2025-8088
(8.8 HIGH)

EPSS: 94.55%

updated 2026-06-17T10:06:17.243000

1 posts

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

31 repos

https://github.com/undefined-name12/CVE-2025-8088-Winrar

https://github.com/jordan922/CVE-2025-8088

https://github.com/shaheeryasirofficial/CVE-2025-8088

https://github.com/AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal

https://github.com/techcorp/CVE-2025-8088-Exploit

https://github.com/hbesljx/CVE-2025-8088-EXP

https://github.com/travisbgreen/cve-2025-8088

https://github.com/0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC

https://github.com/ilhamrzr/RAR-Anomaly-Inspector

https://github.com/Shinkirou789/Cve-2025-8088-WinRar-vulnerability

https://github.com/aldisakti2/CVE-2025-8088-BUILDER-Winrar-Tool

https://github.com/ghostn4444/CVE-2025-8088

https://github.com/sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-

https://github.com/nuky-alt/CVE-2025-8088

https://github.com/Lewis-Ricardo/Amaranth-Project

https://github.com/pentestfunctions/CVE-2025-8088-Multi-Document

https://github.com/knight0x07/WinRAR-CVE-2025-8088-PoC-RAR

https://github.com/onlytoxi/CVE-2025-8088-Winrar-Tool

https://github.com/kitsuneshade/WinRAR-Exploit-Tool---Rust-Edition

https://github.com/pexlexity/WinRAR-CVE-2025-8088-Path-Traversal-PoC

https://github.com/xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit

https://github.com/starfallreverie/winrar-exploit

https://github.com/lennertdefauw/CVE-2025-8088

https://github.com/pescada-dev/-CVE-2025-8088

https://github.com/papcaii2004/CVE-2025-8088-WinRAR-builder

https://github.com/IsmaelCosma/CVE-2025-8088

https://github.com/Syrins/CVE-2025-8088-Winrar-Tool-Gui

https://github.com/nhattanhh/CVE-2025-8088

https://github.com/walidpyh/CVE-2025-8088

https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool

https://github.com/pentestfunctions/best-CVE-2025-8088

kev_Stalker@infosec.exchange at 2026-08-07T04:40:25.000Z ##

CVE-2025-8088 - Changed to Known Ransomware Status

RARLAB WinRAR Path Traversal VulnerabilityVendor: RARLABProduct: WinRARRARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 06, 2026 at 14:08:17 UTCDate nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-58486
(4.0 MEDIUM)

EPSS: 0.16%

updated 2026-06-17T09:44:33.060000

2 posts

Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.

threatnoir@infosec.exchange at 2026-08-06T10:06:38.000Z ##

⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

offseq@infosec.exchange at 2026-08-06T04:30:27.000Z ##

CRITICAL exploit chain affects Samsung Galaxy S25, S24, Flip 7: chained flaws in Samsung Members (CVE-2025-21079), Samsung Account (CVE-2025-58486/58487), and Bixby allow full remote system access. Patch now. radar.offseq.com/threat/how-a- #OffSeq #Samsung #Infosec #Vuln

##

CVE-2025-42999
(9.1 CRITICAL)

EPSS: 11.28%

updated 2026-06-17T09:23:21.993000

1 posts

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

1 repos

https://github.com/Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment

kev_Stalker@infosec.exchange at 2026-08-07T04:34:15.000Z ##

CVE-2025-42999 - Changed to Known Ransomware Status

SAP NetWeaver Deserialization VulnerabilityVendor: SAPProduct: NetWeaverSAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.Status changed from Unknown to Known for ransomware campaign nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-28299
(8.2 HIGH)

EPSS: 0.49%

updated 2026-06-02T21:30:50

2 posts

SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory.

AAKL at 2026-08-07T17:20:10.660Z ##

This post is from yesterday.

Note: Arctic Wolf will sell your data without consent. You need to scroll to the bottom and opt out of being sold to unscrupulous third-parties.

Arctic Wolf: SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299 arcticwolf.com/resources/blog/

##

AAKL@infosec.exchange at 2026-08-07T17:20:10.000Z ##

This post is from yesterday.

Note: Arctic Wolf will sell your data without consent. You need to scroll to the bottom and opt out of being sold to unscrupulous third-parties.

Arctic Wolf: SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299 arcticwolf.com/resources/blog/ #infosec #vulnerability #privacy

##

CVE-2026-41679
(10.0 CRITICAL)

EPSS: 2.95%

updated 2026-04-27T16:19:05

2 posts

## Summary An unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The entire chain is six API calls. I verified every step against the latest version. I have a fully automated PoC script and a video recording availabl

1 repos

https://github.com/bartfroklage/cve-2026-41679

raul@mastodon.in4matics.cat at 2026-08-07T08:59:53.000Z ##

Vuln critica (CVSS 10.0) a Paperclip, orquestracio d'agents d'IA

CVE-2026-41679: RCE via bypass d'autenticacio. Registrar-se sense verificar email, aconseguir token d'API persistent, i importar un .paperclip.yaml malicios que executa comandes al servidor

Tambe afecta el mode local_trusted: DNS rebinding des del navegador executa comandes al PC del dev.

Actualitza ja.

blog.elhacker.net/2026/08/vuln

#Seguridad #CVE #AgentesIA #InfoSec #RCE

##

offseq@infosec.exchange at 2026-08-06T12:00:26.000Z ##

CVE-2026-41679 | Paperclip AI platform CRITICAL vuln: auth bypass let attackers register, obtain API tokens, & run code as server. DNS rebinding risk in dev mode. Patch now. radar.offseq.com/threat/critic #OffSeq #CVE #Paperclip #vuln

##

CVE-2025-58487
(4.0 None)

EPSS: 0.15%

updated 2025-12-02T03:31:52

1 posts

Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity with Samsung Account privilege.

threatnoir@infosec.exchange at 2026-08-06T10:06:38.000Z ##

⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2025-21079
(7.1 HIGH)

EPSS: 0.41%

updated 2025-11-05T06:30:37

2 posts

Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.

threatnoir@infosec.exchange at 2026-08-06T10:06:38.000Z ##

⚠️ CRITICAL: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

A three-stage exploit chain (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487) chaining Samsung Members, Samsung Account, and Bixby achieves RCE and system-level access on Galaxy phones. Samsung patched in November/December 2025, but unpatched devices and those missing any of the three apps remain ex…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

offseq@infosec.exchange at 2026-08-06T04:30:27.000Z ##

CRITICAL exploit chain affects Samsung Galaxy S25, S24, Flip 7: chained flaws in Samsung Members (CVE-2025-21079), Samsung Account (CVE-2025-58486/58487), and Bixby allow full remote system access. Patch now. radar.offseq.com/threat/how-a- #OffSeq #Samsung #Infosec #Vuln

##

CVE-2024-23692
(9.8 CRITICAL)

EPSS: 99.47%

updated 2025-10-22T00:34:06

1 posts

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.

13 repos

https://github.com/vanboomqi/CVE-2024-23692

https://github.com/Mr-r00t11/CVE-2024-23692

https://github.com/Tupler/CVE-2024-23692-exp

https://github.com/wgetnz/hfs2

https://github.com/BBD-YZZ/CVE-2024-23692

https://github.com/NanoWraith/CVE-2024-23692

https://github.com/WanLiChangChengWanLiChang/CVE-2024-23692-RCE

https://github.com/NingXin2002/HFS2.3_poc

https://github.com/999gawkboyy/CVE-2024-23692_Exploit

https://github.com/0x20c/CVE-2024-23692-EXP

https://github.com/pradeepboo/Rejetto-HFS-2.x-RCE-CVE-2024-23692

https://github.com/verylazytech/CVE-2024-23692

https://github.com/jakabakos/CVE-2024-23692-RCE-in-Rejetto-HFS

kev_Stalker@infosec.exchange at 2026-08-07T04:29:17.000Z ##

CVE-2024-23692 - Changed to Known Ransomware Status

Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine VulnerabilityVendor: RejettoProduct: HTTP File ServerRejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted nvd.nist.gov/vuln/detail/CVE-2

##

sayzard@mastodon.sayzard.org at 2026-08-07T21:46:18.000Z ##

WordPress CVE-2026-64638 Pre-Auth XSS to RCE

PwnAI Research는 WordPress Core의 로그인 오류 처리에서 PHP `strip_tags()`와 WordPress KSES의 HTML 파싱 차이를 악용하는 사전 인증 XSS→RCE 체인(CVE-2026-64638)을 공개했습니다. 공격자는 존재하지 않는 사용자명에 공백이 포함된 태그 형태의 페이로드를 넣어 로그인 페이지 DOM을 주입하고, 기본 탑재된 `user-profile.js`의 자동 클릭 및 DOM clobbering을 통해 WordPress REST JSONP 응답을 동일 출처에서 실행시키는 흐름을 주장합니다. 이후 로그인한 관리자가 해당 페이지를 열면 SAME-Origin Method Execution 기법으로 관리자...

pwn.ai/blog/xss2shell

##

DarkWebInformer at 2026-08-07T20:00:07.709Z ##

🚨 WordPress patches XSS2Shell flaw that could lead to server code execution

CVE-2026-64638 is a CVSS 8.9 pre-authentication XSS vulnerability in the WordPress login screen.

The XSS itself requires no account. Researchers at pwn.ai demonstrated how it can be chained against a logged-in administrator to reach PHP code execution after social engineering the admin into interacting with an attacker-controlled page.

A successful chain could potentially allow attackers to:

• Create API credentials
• Gain authenticated REST access
• Upload malicious plugin files
• Execute PHP on the server
• Access WordPress secrets and database credentials

WordPress 7.0.3 fixes the flaw, with patches backported through the 4.7 branch.

NHS England says exploitation is likely following the release of technical details and a PoC.

WordPress has not reported confirmed exploitation in the wild as of August 7.

Update immediately.

##

DarkWebInformer@infosec.exchange at 2026-08-07T20:00:07.000Z ##

🚨 WordPress patches XSS2Shell flaw that could lead to server code execution

CVE-2026-64638 is a CVSS 8.9 pre-authentication XSS vulnerability in the WordPress login screen.

The XSS itself requires no account. Researchers at pwn.ai demonstrated how it can be chained against a logged-in administrator to reach PHP code execution after social engineering the admin into interacting with an attacker-controlled page.

A successful chain could potentially allow attackers to:

• Create API credentials
• Gain authenticated REST access
• Upload malicious plugin files
• Execute PHP on the server
• Access WordPress secrets and database credentials

WordPress 7.0.3 fixes the flaw, with patches backported through the 4.7 branch.

NHS England says exploitation is likely following the release of technical details and a PoC.

WordPress has not reported confirmed exploitation in the wild as of August 7.

Update immediately.

##

DailyCyberSecurity@infosec.exchange at 2026-08-07T01:53:41.000Z ##

WordPress 7.0.3 fixes CVE-2026-64638, a pre-auth XSS on the login screen that can escalate to remote code execution. CVSS 8.9. Update now.

#WordPress #XSS #RCE #CVE #CyberSecurity

securityonline.info/wordpress-

##

CVE-2026-33691
(0 None)

EPSS: 3.58%

2 posts

N/A

secdb at 2026-08-07T19:00:11.880Z ##

🚨 [CISA-2026:0807] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-8037 (secdb.nttzen.cloud/cve/detail/)
- Name: Progress LoadMaster Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Progress
- Product: LoadMaster
- Notes: community.progress.com/s/artic ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-08-07T19:00:11.000Z ##

🚨 [CISA-2026:0807] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-8037 (secdb.nttzen.cloud/cve/detail/)
- Name: Progress LoadMaster Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Progress
- Product: LoadMaster
- Notes: community.progress.com/s/artic ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260807 #cisa20260807 #cve_2026_8037 #cve20268037

##

CVE-2026-48162
(0 None)

EPSS: 0.00%

1 posts

N/A

moltenbit@infosec.exchange at 2026-08-07T13:47:18.000Z ##

three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

patched in 4.14.6.

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity

##

CVE-2026-48024
(0 None)

EPSS: 0.00%

1 posts

N/A

moltenbit@infosec.exchange at 2026-08-07T13:47:18.000Z ##

three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

patched in 4.14.6.

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity

##

CVE-2026-49441
(0 None)

EPSS: 0.00%

1 posts

N/A

moltenbit@infosec.exchange at 2026-08-07T13:47:18.000Z ##

three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

patched in 4.14.6.

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity

##

CVE-2026-18576
(0 None)

EPSS: 0.00%

1 posts

N/A

security_crawler_carl@infosec.exchange at 2026-08-07T07:27:32.000Z ##

🏆 New Achievement! Patch Notes From Hell!

Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)

##

CVE-2026-48088
(0 None)

EPSS: 0.29%

1 posts

N/A

offseq@infosec.exchange at 2026-08-07T00:00:38.000Z ##

CVE-2026-48088 | CRITICAL in open-reception appointment-booking-software <1.0.4: Missing authorization on crypto key API lets attackers decrypt appointments & disrupt flows. Patch to 1.0.4 now. radar.offseq.com/threat/cve-20
#OffSeq #CVE202648088 #Vuln #AppSec

##

CVE-2026-7867
(0 None)

EPSS: 0.18%

1 posts

N/A

1 repos

https://github.com/azqzazq1/CVE-2026-7867-disk2root

thehackerwire@mastodon.social at 2026-08-06T22:59:49.000Z ##

🟠 CVE-2026-7867 - High (7.8)

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

security_crawler_carl@infosec.exchange at 2026-08-06T10:06:40.000Z ##

🏆 New Achievement! Open Source, Open Season!

The court finds Gitea guilty of harboring CVE-2026-59774. The charges: permitting unauthenticated attackers to submit specially crafted Org-mode markup to a public repository and read arbitrary files from the server — with sentencing escalating, in certain configurations, to full remote code execution as the Gitea operating system user. No login required. No accomplices named. (1/2)

##

CVE-2026-48168
(0 None)

EPSS: 0.91%

2 posts

N/A

offseq@infosec.exchange at 2026-08-06T06:00:27.000Z ##

PraisonAI <4.6.40 is affected by CVE-2026-48168 (CRITICAL, CVSS 10): Missing authorization lets attackers exploit GitHub Actions, execute arbitrary shell commands, and compromise repos. Patch to 4.6.40! radar.offseq.com/threat/cve-20 #OffSeq #CVE202648168 #SecDevOps

##

thehackerwire@mastodon.social at 2026-08-05T20:01:23.000Z ##

🔴 CVE-2026-48168 - Critical (10)

PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without qu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18953
(0 None)

EPSS: 0.15%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-06T02:00:32.000Z ##

🟠 CVE-2026-18953 - High (8.6)

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55524
(0 None)

EPSS: 0.19%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-06T02:00:23.000Z ##

🟠 CVE-2026-55524 - High (7.5)

PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal destinatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55522
(0 None)

EPSS: 0.15%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-06T02:00:12.000Z ##

🟠 CVE-2026-55522 - High (7.8)

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67531
(0 None)

EPSS: 0.43%

1 posts

N/A

offseq@infosec.exchange at 2026-08-06T00:00:39.000Z ##

CVE-2026-67531 (CRITICAL): agentfront frontmcp <1.5.7 suffers a code injection flaw enabling remote code execution and theft of secrets. Upgrade to v1.5.7+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #RCE #InfoSec #CVE2026

##

CVE-2026-8446
(0 None)

EPSS: 0.28%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-05T18:00:26.000Z ##

🟠 CVE-2026-8446 - High (7.5)

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth .

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites