##
Updated at UTC 2026-08-27T00:14:01.845137
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-77368 | 7.6 | 0.00% | 2 | 0 | 2026-08-26T22:16:29.860000 | SeaweedFS is a distributed storage system for files and blobs. In version 4.39, | |
| CVE-2026-77317 | 8.1 | 0.00% | 2 | 0 | 2026-08-26T22:16:29.717000 | SeaweedFS is a distributed storage system for files and blobs. In versions from | |
| CVE-2026-61617 | 7.7 | 0.00% | 2 | 0 | 2026-08-26T22:16:25.247000 | Wings is the server control plane for the Pterodactyl game-server management pan | |
| CVE-2026-58084 | 5.5 | 0.14% | 2 | 0 | 2026-08-26T21:32:32 | To retrieve the previous timer value, the kernel calls realtimer_gettime(), whic | |
| CVE-2026-68863 | 7.5 | 0.00% | 2 | 0 | 2026-08-26T21:31:52 | Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer | |
| CVE-2026-68861 | 8.8 | 0.00% | 2 | 0 | 2026-08-26T21:31:52 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutrali | |
| CVE-2026-74770 | 8.8 | 0.00% | 2 | 0 | 2026-08-26T21:31:52 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutrali | |
| CVE-2026-77652 | 7.8 | 0.00% | 2 | 0 | 2026-08-26T21:31:52 | A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG | |
| CVE-2026-79938 | 7.6 | 0.00% | 2 | 0 | 2026-08-26T21:31:52 | Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Au | |
| CVE-2026-70419 | 9.1 | 0.00% | 2 | 0 | 2026-08-26T21:31:47 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutr | |
| CVE-2026-68569 | 8.1 | 0.26% | 2 | 0 | 2026-08-26T21:31:41 | Improper Authentication vulnerability in Apache Tomcat meant that in some circum | |
| CVE-2026-79074 | 5.3 | 0.22% | 1 | 0 | 2026-08-26T21:31:35 | Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a re | |
| CVE-2026-55228 | 8.1 | 0.00% | 2 | 0 | 2026-08-26T21:16:38.737000 | Weblate is a web-based continuous localization platform used to manage software | |
| CVE-2026-76193 | 10.0 | 0.62% | 1 | 0 | 2026-08-26T20:18:00.307000 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) | |
| CVE-2026-58093 | 7.0 | 0.13% | 2 | 0 | 2026-08-26T20:17:55.563000 | The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process t | |
| CVE-2026-46369 | 7.5 | 0.00% | 2 | 0 | 2026-08-26T20:17:23.163000 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the | |
| CVE-2026-19632 | 9.8 | 0.79% | 2 | 2 | 2026-08-26T20:17:10.020000 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for | |
| CVE-2026-65084 | 8.1 | 0.32% | 2 | 0 | 2026-08-26T19:16:52.447000 | NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, wh | |
| CVE-2026-81029 | 8.1 | 0.00% | 2 | 0 | 2026-08-26T18:32:05 | OpenMetadata accepts a caller-supplied post-authentication redirect target and a | |
| CVE-2026-81027 | 8.5 | 0.00% | 2 | 0 | 2026-08-26T18:32:05 | one-api gates one of its two channel-pinning paths and not the other. middleware | |
| CVE-2026-80428 | 9.8 | 0.00% | 2 | 0 | 2026-08-26T18:32:05 | ILIAS deserialises stored session data for an unauthenticated caller. The Shibbo | |
| CVE-2026-81036 | 8.1 | 0.00% | 2 | 0 | 2026-08-26T18:32:05 | Stalwart Mail Server does not compare an OAuth redirect target against any regis | |
| CVE-2026-81035 | 8.1 | 0.00% | 2 | 0 | 2026-08-26T18:32:05 | Midday allows any member of a team to delete it. The delete procedure in apps/ap | |
| CVE-2026-58474 | 8.8 | 0.00% | 2 | 0 | 2026-08-26T18:32:04 | whichllm before 0.5.16 contains a code injection vulnerability in the run and sn | |
| CVE-2026-75896 | 9.1 | 0.00% | 2 | 0 | 2026-08-26T18:32:04 | Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technolog | |
| CVE-2026-18252 | 7.3 | 0.00% | 2 | 0 | 2026-08-26T18:32:04 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 bef | |
| CVE-2026-58092 | 5.4 | 0.14% | 2 | 0 | 2026-08-26T18:32:01 | In FreeBSD 15.0, the kernel structure used to represent user credentials changed | |
| CVE-2026-58090 | 7.8 | 0.16% | 2 | 0 | 2026-08-26T18:31:55 | The SOCK_STREAM receive path in the unix socket implementation failed to fully d | |
| CVE-2026-78899 | 8.8 | 0.46% | 1 | 0 | 2026-08-26T18:31:36 | Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote at | |
| CVE-2026-79992 | 7.8 | 0.13% | 2 | 0 | 2026-08-26T18:31:35 | A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerabili | |
| CVE-2019-1068 | 8.8 | 44.66% | 4 | 2 | 2026-08-26T18:31:30 | A remote code execution vulnerability exists in Microsoft SQL Server when it inc | |
| CVE-2015-5287 | 7.8 | 3.41% | 4 | 0 | 2026-08-26T18:31:30 | The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2. | |
| CVE-2026-8452 | 9.8 | 1.04% | 4 | 3 | 2026-08-26T18:30:34 | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp | |
| CVE-2022-0995 | 7.1 | 6.34% | 4 | 4 | 2026-08-26T18:30:28 | An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_q | |
| CVE-2015-3246 | 5.1 | 7.09% | 4 | 0 | 2026-08-26T18:30:27 | libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper progr | |
| CVE-2026-81032 | 9.8 | 0.00% | 2 | 0 | 2026-08-26T18:17:05.890000 | NebulaGraph exposes its runtime configuration over an unauthenticated HTTP servi | |
| CVE-2026-75960 | 8.1 | 0.00% | 4 | 0 | 2026-08-26T18:17:01.453000 | Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently | |
| CVE-2026-54569 | 9.8 | 0.00% | 2 | 0 | 2026-08-26T18:16:40.930000 | SENAITE.CORE is the core framework for the SENAITE laboratory information manage | |
| CVE-2026-32258 | 8.1 | 0.00% | 2 | 0 | 2026-08-26T18:16:27.550000 | Winter is a free, open-source content management system (CMS) based on the Larav | |
| CVE-2026-80427 | 8.4 | 0.00% | 2 | 0 | 2026-08-26T17:17:26.120000 | bestzip builds the argument list for the system zip utility without separating o | |
| CVE-2026-78901 | 7.5 | 0.24% | 1 | 0 | 2026-08-26T17:01:18.043000 | Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote at | |
| CVE-2026-58083 | 8.4 | 0.12% | 2 | 0 | 2026-08-26T16:54:50.030000 | While the kernel was copying knotes during fork, a knote with a timer-based filt | |
| CVE-2026-16783 | 7.8 | 0.13% | 1 | 0 | 2026-08-26T16:46:22.330000 | A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force | |
| CVE-2026-75768 | 7.8 | 0.17% | 2 | 0 | 2026-08-26T16:45:12.020000 | Substance3D - Painter is affected by an Untrusted Search Path vulnerability that | |
| CVE-2026-77995 | 0 | 0.29% | 1 | 0 | 2026-08-26T16:36:16.990000 | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAu | |
| CVE-2026-76565 | 0 | 0.32% | 1 | 1 | 2026-08-26T16:35:20.160000 | Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter par | |
| CVE-2026-77994 | 0 | 0.23% | 1 | 0 | 2026-08-26T16:35:20.160000 | Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < | |
| CVE-2026-74932 | 7.5 | 0.22% | 2 | 0 | 2026-08-26T16:30:52.723000 | The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host he | |
| CVE-2026-18431 | 9.8 | 0.64% | 4 | 0 | 2026-08-26T16:19:05.917000 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versi | |
| CVE-2026-79911 | 10.0 | 0.64% | 2 | 0 | 2026-08-26T16:19:05.917000 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210 | |
| CVE-2026-32556 | 7.1 | 0.15% | 1 | 0 | 2026-08-26T16:19:05.917000 | Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions. | |
| CVE-2026-65092 | 8.5 | 0.45% | 2 | 0 | 2026-08-26T16:16:35.933000 | NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker co | |
| CVE-2026-65105 | 8.1 | 0.30% | 3 | 0 | 2026-08-26T15:16:51.040000 | NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup | |
| CVE-2026-65096 | 7.8 | 0.69% | 2 | 0 | 2026-08-26T15:16:50.467000 | NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge compon | |
| CVE-2026-54511 | 8.6 | 0.00% | 2 | 0 | 2026-08-26T14:28:05 | `@logtape/syslog` contains two related output-encoding bugs in the structured da | |
| CVE-2026-54523 | 9.6 | 0.00% | 2 | 0 | 2026-08-26T14:21:54 | ## Summary In Kyverno v1.18.1, a tenant who can create a `NamespacedMutatingPol | |
| CVE-2026-73108 | 7.5 | 0.00% | 2 | 0 | 2026-08-26T14:17:12.830000 | RustDesk versions before 1.4.7 contain an uncontrolled speculative memory alloca | |
| CVE-2026-77532 | 9.6 | 0.00% | 2 | 0 | 2026-08-26T13:19:20.413000 | A malicious actor with access to an adjacent network could exploit a Buffer Over | |
| CVE-2026-54757 | 7.8 | 0.25% | 2 | 0 | 2026-08-26T13:19:16.497000 | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing | |
| CVE-2026-19913 | 7.5 | 0.19% | 2 | 1 | 2026-08-26T13:17:47.880000 | The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure v | |
| CVE-2026-80138 | 9.8 | 0.80% | 2 | 0 | 2026-08-26T00:31:14 | ClipBucket V5's web installer fails to properly validate or escape the php_cli_f | |
| CVE-2026-79912 | 8.3 | 1.40% | 2 | 0 | 2026-08-26T00:31:14 | A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impac | |
| CVE-2026-80186 | 7.6 | 0.41% | 2 | 0 | 2026-08-26T00:31:09 | A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth | |
| CVE-2026-80104 | 9.8 | 0.71% | 2 | 0 | 2026-08-25T21:31:58 | DB-GPT builds the destination path for an uploaded skill from the multipart file | |
| CVE-2026-79021 | None | 0.23% | 1 | 0 | 2026-08-25T21:31:45 | Missing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65 | |
| CVE-2026-65099 | 7.8 | 0.69% | 2 | 0 | 2026-08-25T21:31:39 | NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface | |
| CVE-2026-65093 | 9.9 | 0.49% | 4 | 0 | 2026-08-25T21:31:36 | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could caus | |
| CVE-2026-65081 | 8.1 | 0.25% | 2 | 0 | 2026-08-25T21:31:35 | NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, | |
| CVE-2026-65090 | 7.8 | 0.69% | 2 | 0 | 2026-08-25T21:31:35 | NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management compone | |
| CVE-2026-65089 | 7.8 | 0.69% | 2 | 0 | 2026-08-25T21:31:35 | NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin | |
| CVE-2026-65098 | 8.1 | 0.57% | 2 | 0 | 2026-08-25T21:31:35 | NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper w | |
| CVE-2026-66153 | None | 0.20% | 2 | 0 | 2026-08-25T21:31:35 | The NEService auto-upgrade process insecurely handles temporary files in SonicWa | |
| CVE-2026-66152 | None | 0.20% | 2 | 0 | 2026-08-25T21:31:35 | A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Li | |
| CVE-2026-65091 | 8.8 | 1.36% | 2 | 0 | 2026-08-25T21:31:35 | NVIDIA OpenShell for all platforms contains a vulnerability where a malicious ga | |
| CVE-2026-65097 | 7.5 | 0.20% | 2 | 0 | 2026-08-25T21:31:34 | NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, | |
| CVE-2026-65083 | 9.9 | 0.51% | 2 | 0 | 2026-08-25T21:31:31 | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning | |
| CVE-2026-80049 | 8.8 | 0.34% | 2 | 0 | 2026-08-25T20:17:08.627000 | Airbyte Platform resolves the workspace used for its authorization decision from | |
| CVE-2026-75501 | 7.5 | 0.59% | 1 | 0 | 2026-08-25T20:17:04.150000 | A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residentia | |
| CVE-2026-55099 | 7.5 | 0.38% | 2 | 0 | 2026-08-25T19:27:32 | ### Summary `Component.__eq__` compares subcomponents in `O(2^n)` time relative | |
| CVE-2026-45018 | 9.8 | 0.65% | 2 | 0 | 2026-08-25T19:19:28 | ### Am I affected? Only if your deployment sets `features.mcp.enabled = true` i | |
| CVE-2026-76197 | 10.0 | 1.47% | 6 | 0 | 2026-08-25T18:32:01 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-79784 | 8.8 | 0.32% | 2 | 0 | 2026-08-25T18:32:01 | Vocos instantiates a class named by a configuration file without restricting whi | |
| CVE-2026-19912 | None | 0.22% | 2 | 1 | 2026-08-25T18:32:01 | The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote | |
| CVE-2026-79774 | 8.4 | 0.43% | 2 | 0 | 2026-08-25T18:32:00 | Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox e | |
| CVE-2026-79675 | 9.8 | 0.40% | 2 | 0 | 2026-08-25T18:31:56 | NLTK before 3.10.3 fails to validate JVM options passed through the per-call opt | |
| CVE-2026-55538 | 7.3 | 0.26% | 1 | 0 | 2026-08-25T17:17:31.403000 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai se | |
| CVE-2026-18798 | 7.5 | 1.48% | 2 | 0 | 2026-08-25T15:33:06 | Issue summary: QUIC server may double free QRX (QUIC record layer RX) object whe | |
| CVE-2026-57863 | 8.8 | 0.57% | 2 | 0 | 2026-08-25T15:16:35.297000 | Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self | |
| CVE-2026-55540 | 7.1 | 0.27% | 1 | 0 | 2026-08-25T14:54:57 | ### Summary PraisonAI's `praisonai.code` tool wrappers (exported as `CODE_TOOLS` | |
| CVE-2026-57910 | 0 | 0.20% | 4 | 0 | 2026-08-25T13:19:24.810000 | Improper authentication in the WatchGuard Agent allows an unauthenticated attack | |
| CVE-2026-78570 | 9.8 | 0.40% | 2 | 0 | 2026-08-25T12:31:29 | The Total Donations plugin for WordPress is vulnerable to Privilege Escalation i | |
| CVE-2026-57909 | None | 0.29% | 4 | 0 | 2026-08-25T12:31:24 | A path traversal vulnerability in WatchGuard Agent allows a remote, unauthentica | |
| CVE-2026-78563 | 7.2 | 0.19% | 1 | 0 | 2026-08-25T09:30:48 | The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Sc | |
| CVE-2026-78568 | 9.8 | 0.30% | 2 | 0 | 2026-08-25T09:30:48 | The Total Donations plugin for WordPress is vulnerable to SQL Injection in all v | |
| CVE-2026-77136 | None | 0.55% | 2 | 0 | 2026-08-25T09:30:47 | The extension passes the raw value of a form field configured as "This field con | |
| CVE-2026-63586 | 9.8 | 0.52% | 4 | 0 | 2026-08-25T09:30:47 | The web-based management interface uses a modified uhttpd server with CGI shell | |
| CVE-2026-67578 | 7.5 | 0.30% | 2 | 0 | 2026-08-25T09:30:42 | FA-50 all versions miss authentication for some configuration. An attacker with | |
| CVE-2026-59769 | 9.1 | 0.33% | 3 | 0 | 2026-08-25T09:30:42 | FA-50 all versions contain hard-coded credentials. An attacker, who knows the cr | |
| CVE-2026-71366 | 7.7 | 0.33% | 1 | 0 | 2026-08-25T09:30:36 | A server-side request forgery (SSRF) vulnerability was found in multiple AWX not | |
| CVE-2026-63587 | 8.6 | 0.27% | 2 | 0 | 2026-08-25T09:17:32.057000 | The SMS control function of IE-SR-2TX-WL-4G devices can require a password for S | |
| CVE-2026-78477 | 9.8 | 0.30% | 1 | 0 | 2026-08-25T06:31:36 | The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versio | |
| CVE-2026-9254 | 0 | 2.35% | 1 | 1 | 2026-08-25T04:18:21.457000 | An unauthenticated OS command injection vulnerability exists in the parental con | |
| CVE-2026-61419 | 7.8 | 0.09% | 1 | 0 | 2026-08-25T04:18:15.290000 | Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Contr | |
| CVE-2026-41992 | 7.5 | 0.35% | 2 | 0 | 2026-08-25T04:18:11.393000 | GNU gzip contains a global buffer overflow vulnerability in the LZH decompressio | |
| CVE-2026-78676 | 9.8 | 0.40% | 3 | 0 | 2026-08-25T03:32:20 | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config value | |
| CVE-2026-72702 | 5.4 | 0.10% | 1 | 0 | 2026-08-25T03:32:14 | Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer | |
| CVE-2026-78264 | 7.1 | 0.15% | 1 | 0 | 2026-08-25T00:30:37 | Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. | |
| CVE-2026-78265 | 9.8 | 0.31% | 2 | 0 | 2026-08-25T00:30:37 | Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. | |
| CVE-2026-78267 | 9.8 | 0.27% | 2 | 0 | 2026-08-25T00:30:37 | Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | |
| CVE-2026-78268 | 7.5 | 0.25% | 1 | 0 | 2026-08-25T00:30:37 | Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & | |
| CVE-2026-78284 | 8.6 | 0.35% | 1 | 0 | 2026-08-25T00:30:37 | Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions. | |
| CVE-2026-19874 | 9.1 | 0.73% | 4 | 1 | 2026-08-24T21:34:43 | A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online | |
| CVE-2026-19685 | 9.8 | 0.14% | 1 | 0 | 2026-08-24T21:34:43 | NetworkManager did not apply the private_user restriction to the 802-1x.ca-path | |
| CVE-2026-19568 | 7.8 | 0.13% | 1 | 0 | 2026-08-24T21:33:53 | A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force | |
| CVE-2026-7455 | 7.8 | 0.13% | 1 | 0 | 2026-08-24T21:33:53 | A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force | |
| CVE-2026-78541 | None | 0.96% | 1 | 0 | 2026-08-24T21:33:52 | A stored OS command injection vulnerability exists in the parent-control module | |
| CVE-2026-71506 | 8.1 | 0.30% | 1 | 1 | 2026-08-24T21:33:43 | Dolibarr before 24.0.0 contains an improper authorization vulnerability in the p | |
| CVE-2026-21962 | 10.0 | 42.02% | 22 | 9 | 2026-08-24T21:33:31 | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in pr | |
| CVE-2026-76835 | 9.1 | 0.35% | 1 | 0 | 2026-08-24T20:17:19.623000 | OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whet | |
| CVE-2026-63310 | 7.1 | 0.11% | 1 | 0 | 2026-08-24T20:16:55.243000 | NLTK before 3.9.3 fails to verify file integrity after downloading packages and | |
| CVE-2026-76838 | 8.5 | 0.31% | 1 | 0 | 2026-08-24T18:32:04 | Hi.Events validates a webhook destination only when it is registered, never when | |
| CVE-2026-16348 | None | 0.91% | 1 | 1 | 2026-08-24T18:31:59 | An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allo | |
| CVE-2026-76071 | 9.8 | 1.06% | 1 | 1 | 2026-08-24T18:31:59 | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow v | |
| CVE-2026-76070 | 9.8 | 1.00% | 1 | 1 | 2026-08-24T18:31:58 | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow v | |
| CVE-2026-76073 | 8.8 | 0.28% | 1 | 0 | 2026-08-24T18:31:57 | Label Studio does not scope the annotation detail endpoint to the requesting use | |
| CVE-2026-78209 | 8.2 | 0.29% | 1 | 0 | 2026-08-24T18:17:31.060000 | exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, | |
| CVE-2026-78169 | 9.9 | 0.44% | 2 | 0 | 2026-08-24T16:41:13.950000 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This | |
| CVE-2026-78168 | 9.8 | 0.93% | 2 | 0 | 2026-08-24T16:40:53.647000 | A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. | |
| CVE-2026-59568 | 9.1 | 0.38% | 4 | 0 | 2026-08-24T15:31:57 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow | |
| CVE-2025-15467 | 8.8 | 48.21% | 2 | 6 | 2026-08-24T13:16:48.920000 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with malic | |
| CVE-2026-8173 | 5.3 | 0.21% | 1 | 0 | 2026-08-24T09:33:52 | The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from t | |
| CVE-2026-78211 | 9.8 | 1.54% | 1 | 0 | 2026-08-24T06:30:35 | 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injec | |
| CVE-2026-78170 | 8.8 | 0.44% | 1 | 0 | 2026-08-24T03:31:14 | A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the fu | |
| CVE-2026-78167 | 10.0 | 1.03% | 1 | 0 | 2026-08-24T03:31:14 | A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted eleme | |
| CVE-2026-78208 | 7.5 | 0.37% | 1 | 0 | 2026-08-24T03:31:14 | exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Wor | |
| CVE-2026-78207 | 9.4 | 0.44% | 1 | 0 | 2026-08-24T03:31:14 | exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in th | |
| CVE-2026-7808 | 9.8 | 0.35% | 1 | 0 | 2026-08-23T15:33:12 | justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that ca | |
| CVE-2026-8445 | 9.8 | 0.38% | 1 | 0 | 2026-08-23T15:33:12 | justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-si | |
| CVE-2026-63312 | 7.5 | 0.49% | 1 | 0 | 2026-08-22T15:31:11 | NLTK before 3.10.0 contains an arbitrary local file read vulnerability in Stream | |
| CVE-2026-64531 | 7.8 | 0.38% | 1 | 4 | 2026-08-22T06:31:25 | In the Linux kernel, the following vulnerability has been resolved: net: openvs | |
| CVE-2026-27875 | 0 | 0.07% | 2 | 0 | 2026-08-21T21:16:56.500000 | Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Co | |
| CVE-2026-77413 | None | 0.41% | 2 | 0 | 2026-08-21T20:57:09 | ## Impact Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitra | |
| CVE-2026-17250 | None | 0.19% | 1 | 0 | 2026-08-21T18:35:07 | A stack-based buffer overflow vulnerability exists in the firmware update functi | |
| CVE-2026-73570 | 8.9 | 1.51% | 9 | 4 | template | 2026-08-21T18:34:48 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor |
| CVE-2026-54796 | 7.2 | 2.36% | 1 | 0 | 2026-08-21T17:56:59.057000 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutra | |
| CVE-2026-69836 | 10.0 | 1.55% | 7 | 2 | 2026-08-21T00:31:31 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a | |
| CVE-2026-19586 | None | 5.04% | 2 | 0 | 2026-08-20T21:31:30 | A pre-authentication OS command injection vulnerability has been identified in O | |
| CVE-2026-18264 | 8.8 | 1.24% | 1 | 0 | 2026-08-20T18:30:55 | NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vu | |
| CVE-2026-19598 | 9.8 | 2.46% | 1 | 4 | template | 2026-08-20T12:48:10.287000 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to |
| CVE-2026-15748 | 9.8 | 4.61% | 1 | 3 | 2026-08-20T12:48:10.287000 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload | |
| CVE-2026-75616 | None | 1.91% | 1 | 1 | 2026-08-19T21:30:40 | An OS command injection vulnerability exists in the web management interface of | |
| CVE-2026-16835 | 9.6 | 0.22% | 1 | 0 | 2026-08-19T21:30:30 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 thr | |
| CVE-2026-16687 | 9.6 | 0.21% | 1 | 0 | 2026-08-19T21:30:30 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 thr | |
| CVE-2026-74480 | 9.8 | 0.56% | 1 | 0 | 2026-08-19T18:33:34 | In the Linux kernel, the following vulnerability has been resolved: net: bridge | |
| CVE-2026-75149 | 8.8 | 0.64% | 1 | 0 | 2026-08-19T18:33:02 | marimo before 0.23.15 contains a code injection vulnerability in the notebook co | |
| CVE-2026-69414 | 7.8 | 0.56% | 2 | 2 | 2026-08-19T18:32:28 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect | |
| CVE-2026-71961 | 8.8 | 3.05% | 1 | 0 | 2026-08-19T15:32:47 | Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection | |
| CVE-2026-54795 | 8.8 | 2.39% | 1 | 0 | 2026-08-19T15:32:33 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutra | |
| CVE-2026-14669 | 8.8 | 0.58% | 1 | 1 | 2026-08-19T14:56:57.477000 | Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosin | |
| CVE-2026-33824 | 9.8 | 72.69% | 1 | 2 | 2026-08-19T04:16:58.560000 | Double free in Windows IKE Extension allows an unauthorized attacker to execute | |
| CVE-2026-18963 | 9.1 | 2.79% | 12 | 8 | template | 2026-08-19T03:31:21 | A flaw was found in the reset-credentials flow of the keycloak-services componen |
| CVE-2026-17084 | None | 0.48% | 1 | 0 | 2026-08-19T03:31:21 | The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B | |
| CVE-2026-55040 | 9.1 | 5.58% | 7 | 3 | template | 2026-08-18T18:32:50 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attack |
| CVE-2026-24301 | 8.8 | 2.22% | 1 | 1 | 2026-08-18T15:31:45 | Improper neutralization of special elements used in a command ('command injectio | |
| CVE-2026-53365 | 5.5 | 0.17% | 1 | 2 | 2026-08-18T15:31:16 | In the Linux kernel, the following vulnerability has been resolved: vsock/virti | |
| CVE-2026-73522 | 7.5 | 2.36% | 1 | 0 | 2026-08-18T15:17:08.193000 | COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability tha | |
| CVE-2026-19478 | 9.4 | 6.00% | 1 | 6 | template | 2026-08-18T14:57:10.630000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 |
| CVE-2026-75094 | 9.1 | 2.11% | 1 | 0 | 2026-08-18T03:31:14 | A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_ | |
| CVE-2026-64849 | 9.3 | 16.41% | 1 | 3 | template | 2026-08-17T21:58:52 | ### Summary The default MLflow Tracking Server (`mlflow server`, no authenticati |
| CVE-2026-19976 | 6.6 | 2.05% | 1 | 0 | 2026-08-17T03:30:28 | A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted | |
| CVE-2026-61979 | 8.1 | 0.28% | 2 | 0 | 2026-08-13T15:34:46 | Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions | |
| CVE-2026-50656 | 7.8 | 11.36% | 1 | 4 | 2026-08-12T17:17:27.983000 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect | |
| CVE-2026-32257 | 8.1 | 0.00% | 2 | 0 | 2026-08-12T14:40:23 | ### Impact | |
| CVE-2026-52923 | 7.8 | 0.15% | 2 | 0 | 2026-08-12T12:19:41.090000 | In the Linux kernel, the following vulnerability has been resolved: ipc: limit | |
| CVE-2026-68820 | 7.0 | 6.18% | 1 | 4 | 2026-08-11T21:33:01 | Use after free in Windows Ancillary Function Driver for WinSock allows an author | |
| CVE-2026-63520 | 8.1 | 2.93% | 8 | 1 | 2026-08-11T18:31:39 | Improper input validation in Microsoft Office SharePoint allows an unauthorized | |
| CVE-2026-62911 | 8.0 | 0.95% | 2 | 1 | 2026-08-11T18:31:34 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an a | |
| CVE-2026-14540 | 6.1 | 0.12% | 1 | 0 | 2026-08-08T00:15:26 | A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP so | |
| CVE-2026-48710 | 6.5 | 1.91% | 1 | 5 | template | 2026-08-07T12:31:53 | ### Summary In affected versions, the HTTP `Host` request header was not validat |
| CVE-2026-63077 | 9.8 | 84.73% | 4 | 4 | template | 2026-08-06T05:17:05.170000 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe |
| CVE-2026-8508 | 6.5 | 0.70% | 2 | 1 | 2026-08-04T03:31:16 | An improper authentication vulnerability in the "social_login.cgi" CGI program i | |
| CVE-2026-15903 | 8.8 | 0.57% | 1 | 0 | 2026-07-24T15:33:44 | Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allo | |
| CVE-2026-15981 | 9.8 | 0.81% | 2 | 1 | 2026-07-23T21:31:09 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authen | |
| CVE-2026-40575 | 9.1 | 0.48% | 1 | 0 | 2026-07-21T13:50:16 | ### Impact A configuration-dependent authentication bypass exists in OAuth2 Pro | |
| CVE-2026-15776 | 8.8 | 0.45% | 1 | 0 | 2026-07-15T17:39:16.157000 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allo | |
| CVE-2026-42271 | 8.8 | 83.54% | 1 | 2 | template | 2026-07-15T02:21:30.727000 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo |
| CVE-2026-52945 | 7.5 | 0.40% | 1 | 0 | 2026-07-14T16:59:26.780000 | In the Linux kernel, the following vulnerability has been resolved: Revert "wir | |
| CVE-2026-52912 | 7.8 | 0.19% | 1 | 0 | 2026-07-08T15:31:43 | In the Linux kernel, the following vulnerability has been resolved: netfilter: | |
| CVE-2026-12569 | 9.8 | 40.59% | 2 | 1 | 2026-06-26T15:33:15 | A critical remote code execution (RCE) vulnerability has been reported in PTC Wi | |
| CVE-2025-1974 | 9.8 | 99.52% | 1 | 27 | template | 2026-06-17T08:40:27.847000 | A security issue was discovered in Kubernetes where under certain conditions, an |
| CVE-2023-21931 | 7.5 | 82.26% | 2 | 2 | 2026-06-17T05:34:22.130000 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware | |
| CVE-2020-14882 | 9.8 | 100.00% | 2 | 42 | template | 2026-06-17T02:55:44.510000 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware |
| CVE-2025-9615 | 3.3 | 0.15% | 2 | 0 | 2026-05-19T15:31:20 | A flaw was found in NetworkManager. The NetworkManager package allows access to | |
| CVE-2026-28389 | 7.5 | 0.80% | 2 | 0 | 2026-05-12T15:31:15 | Issue summary: During processing of a crafted CMS EnvelopedData message with Key | |
| CVE-2025-69419 | 7.4 | 0.56% | 2 | 1 | 2026-05-12T15:31:14 | Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously craft | |
| CVE-2021-23758 | 9.8 | 89.10% | 6 | 1 | 2026-02-03T17:39:26 | ### Overview Affected versions of this package are vulnerable to Deserializatio | |
| CVE-2025-58187 | 6.5 | 0.38% | 2 | 0 | 2026-01-29T18:31:31 | Due to the design of the name constraint checking algorithm, the processing time | |
| CVE-2026-0915 | 7.5 | 0.57% | 2 | 1 | 2026-01-20T18:31:56 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that spec | |
| CVE-2021-33045 | 9.8 | 99.56% | 1 | 3 | template | 2025-10-22T00:32:21 | The identity authentication bypass vulnerability found in some Dahua products du |
| CVE-2021-33044 | 9.8 | 99.87% | 1 | 9 | template | 2025-10-22T00:32:20 | The identity authentication bypass vulnerability found in some Dahua products du |
| CVE-2020-2551 | 9.8 | 93.17% | 2 | 11 | template | 2025-10-22T00:31:50 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware |
| CVE-2017-10271 | 7.5 | 99.99% | 2 | 33 | template | 2025-10-22T00:31:29 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middlewar |
| CVE-2025-55241 | 9.0 | 1.55% | 2 | 0 | 2025-09-18T15:31:27 | Azure Entra Elevation of Privilege Vulnerability | |
| CVE-2026-61792 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-60004 | 0 | 0.00% | 26 | 9 | template | N/A | |
| CVE-2026-80196 | 0 | 0.42% | 1 | 0 | N/A | ||
| CVE-2026-78379 | 0 | 0.32% | 2 | 0 | N/A | ||
| CVE-2026-77537 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-65641 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-75604 | 0 | 0.00% | 2 | 2 | N/A | ||
| CVE-2026-23479 | 0 | 1.36% | 2 | 5 | N/A | ||
| CVE-2026-18965 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-72898 | 0 | 79.22% | 1 | 7 | template | N/A | |
| CVE-2026-59285 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-59270 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-13214 | 0 | 0.51% | 2 | 0 | N/A | ||
| CVE-2026-76098 | 0 | 0.28% | 1 | 0 | N/A | ||
| CVE-2026-77567 | 0 | 0.30% | 1 | 0 | N/A | ||
| CVE-2026-66897 | 0 | 0.62% | 1 | 0 | N/A | ||
| CVE-2026-78251 | 0 | 0.39% | 1 | 0 | N/A |
updated 2026-08-26T22:16:29.860000
2 posts
🟠 CVE-2026-77368 - High (7.6)
SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tenant's upl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77368/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77368 - High (7.6)
SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tenant's upl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77368/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T22:16:29.717000
2 posts
🟠 CVE-2026-77317 - High (8.1)
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77317/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77317 - High (8.1)
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77317/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T22:16:25.247000
2 posts
🟠 CVE-2026-61617 - High (7.7)
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61617/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61617 - High (7.7)
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61617/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:32:32
2 posts
The bear is friendly. Think of honey, if you can.
For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).
<https://www.cve.org/CVERecord?id=CVE-2026-58092>
<https://nvd.nist.gov/vuln/detail/CVE-2026-58092>
<https://security.freebsd.org/advisories/FreeBSD-SA-26:59.mac_do.asc>
<https://defcon.social/@charlesrocket/116714325230546417> @charlesrocket re: LLM shaming.
##The bear is friendly. Think of honey, if you can.
For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).
<https://www.cve.org/CVERecord?id=CVE-2026-58092>
<https://nvd.nist.gov/vuln/detail/CVE-2026-58092>
<https://security.freebsd.org/advisories/FreeBSD-SA-26:59.mac_do.asc>
<https://defcon.social/@charlesrocket/116714325230546417> @charlesrocket re: LLM shaming.
##updated 2026-08-26T21:31:52
2 posts
🟠 CVE-2026-68863 - High (7.5)
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68863/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-68863 - High (7.5)
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68863/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:31:52
2 posts
🟠 CVE-2026-68861 - High (8.8)
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68861/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-68861 - High (8.8)
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68861/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:31:52
2 posts
🟠 CVE-2026-74770 - High (8.8)
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74770 - High (8.8)
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:31:52
2 posts
🟠 CVE-2026-77652 - High (7.8)
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer.
In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with:
ren->pPal = g_new0(WPGColorRGB, 256);
When handling ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77652/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77652 - High (7.8)
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer.
In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with:
ren->pPal = g_new0(WPGColorRGB, 256);
When handling ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77652/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:31:52
2 posts
🟠 CVE-2026-79938 - High (7.6)
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79938/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-79938 - High (7.6)
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79938/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:31:47
2 posts
🔴 CVE-2026-70419 - Critical (9.1)
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70419/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-70419 - Critical (9.1)
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70419/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:31:41
2 posts
Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now.
##Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now.
##updated 2026-08-26T21:31:35
1 posts
CVE-2026-79074 - Information leak in Google Chrome renderer. Medium severity. Update to 152.0.7977.65 or higher immediately. #CVE #Chrome #infosec
##updated 2026-08-26T21:16:38.737000
2 posts
🟠 CVE-2026-55228 - High (8.1)
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid te...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55228/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55228 - High (8.1)
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid te...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55228/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T20:18:00.307000
1 posts
CVE-2026-76193 - Critical SSRF to RCE in Adobe Campaign Classic. Zero-click exploit. CVSS 10.0. Apply mitigations immediately. #CVE #Adobe #infosec
##updated 2026-08-26T20:17:55.563000
2 posts
FreeBSD: kernel use-after-free via tty ioctls – CVE-2026-58093
https://www.cve.org/CVERecord?id=CVE-2026-58093
"The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being destroyed to the calling process' session. An unprivileged local user can exploit this race condition to escalate privileges."
Credit: tsune of GMO Cybersecurity by Ierae, Inc. working with TrendAI Zero Day Initiative @thezdi
<https://ctftime.org/team/224122>
<https://gmo-cybersecurity.com/>
<https://nvd.nist.gov/vuln/detail/CVE-2026-58093>
<https://reviews.freebsd.org/D59126>, <https://github.com/freebsd/freebsd-src/commit/b207f754c7709212381eda8c91dbf080081ac5a1>
##FreeBSD: kernel use-after-free via tty ioctls – CVE-2026-58093
https://www.cve.org/CVERecord?id=CVE-2026-58093
"The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being destroyed to the calling process' session. An unprivileged local user can exploit this race condition to escalate privileges."
Credit: tsune of GMO Cybersecurity by Ierae, Inc. working with TrendAI Zero Day Initiative @thezdi
<https://ctftime.org/team/224122>
<https://gmo-cybersecurity.com/>
<https://nvd.nist.gov/vuln/detail/CVE-2026-58093>
<https://reviews.freebsd.org/D59126>, <https://github.com/freebsd/freebsd-src/commit/b207f754c7709212381eda8c91dbf080081ac5a1>
##updated 2026-08-26T20:17:23.163000
2 posts
🟠 CVE-2026-46369 - High (7.5)
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative to Transact...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46369/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-46369 - High (7.5)
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative to Transact...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46369/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T20:17:10.020000
2 posts
2 repos
A critical TranslatePress vulnerability (CVE-2026-19632) lets attackers steal admin reset links and take over 400,000 WordPress sites. Update to 3.3.2 now.
#WordPress #TranslatePress #CyberSecurity #CVE202619632 #WebSecurity
##A critical TranslatePress vulnerability (CVE-2026-19632) lets attackers steal admin reset links and take over 400,000 WordPress sites. Update to 3.3.2 now.
#WordPress #TranslatePress #CyberSecurity #CVE202619632 #WebSecurity
##updated 2026-08-26T19:16:52.447000
2 posts
🟠 CVE-2026-65084 - High (8.1)
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code exec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65084 - High (8.1)
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code exec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:05
2 posts
🟠 CVE-2026-81029 - High (8.1)
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81029/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81029 - High (8.1)
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81029/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:05
2 posts
🟠 CVE-2026-81027 - High (8.5)
one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after mod...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81027/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81027 - High (8.5)
one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after mod...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81027/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:05
2 posts
🔴 CVE-2026-80428 - Critical (9.8)
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and its lo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-80428 - Critical (9.8)
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and its lo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:05
2 posts
🟠 CVE-2026-81036 - High (8.1)
Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81036/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81036 - High (8.1)
Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81036/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:05
2 posts
🟠 CVE-2026-81035 - High (8.1)
Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of the role it...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81035 - High (8.1)
Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of the role it...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:04
2 posts
🟠 CVE-2026-58474 - High (8.8)
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58474/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-58474 - High (8.8)
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58474/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:04
2 posts
🔴 CVE-2026-75896 - Critical (9.1)
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords.
This issue affects Liderahenk: before 3.5.5.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75896/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75896 - Critical (9.1)
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords.
This issue affects Liderahenk: before 3.5.5.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75896/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:04
2 posts
A critical GitLab EE security patch addresses CVE-2026-18252, fixing a command execution flaw. Learn about affected versions, mechanisms, and mitigation.
#GitLab #SecurityPatch #Cybersecurity #CVE202618252
http://securityonline.info/gitlab-ee-security-patch/?utm_source=mastodon&utm_medium=jetpack_social
##A critical GitLab EE security patch addresses CVE-2026-18252, fixing a command execution flaw. Learn about affected versions, mechanisms, and mitigation.
#GitLab #SecurityPatch #Cybersecurity #CVE202618252
http://securityonline.info/gitlab-ee-security-patch/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-26T18:32:01
2 posts
The bear is friendly. Think of honey, if you can.
For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).
<https://www.cve.org/CVERecord?id=CVE-2026-58092>
<https://nvd.nist.gov/vuln/detail/CVE-2026-58092>
<https://security.freebsd.org/advisories/FreeBSD-SA-26:59.mac_do.asc>
<https://defcon.social/@charlesrocket/116714325230546417> @charlesrocket re: LLM shaming.
##The bear is friendly. Think of honey, if you can.
For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).
<https://www.cve.org/CVERecord?id=CVE-2026-58092>
<https://nvd.nist.gov/vuln/detail/CVE-2026-58092>
<https://security.freebsd.org/advisories/FreeBSD-SA-26:59.mac_do.asc>
<https://defcon.social/@charlesrocket/116714325230546417> @charlesrocket re: LLM shaming.
##updated 2026-08-26T18:31:55
2 posts
<https://www.cve.org/CVERecord?id=CVE-2026-58090>
<https://security.freebsd.org/advisories/FreeBSD-SA-26:57.unix.asc>
Context (unofficial):
<https://bokut.in/freebsd-patch-level-table/#releng/15.0> (releng/15.0) | <https://bokut.in/freebsd-patch-level-table/#releng/15.1> (releng/15.1)
##<https://www.cve.org/CVERecord?id=CVE-2026-58090>
<https://security.freebsd.org/advisories/FreeBSD-SA-26:57.unix.asc>
Context (unofficial):
<https://bokut.in/freebsd-patch-level-table/#releng/15.0> (releng/15.0) | <https://bokut.in/freebsd-patch-level-table/#releng/15.1> (releng/15.1)
##updated 2026-08-26T18:31:36
1 posts
CVE-2026-78899 - High severity Use-After-Free in Google Chrome V8 enables sandbox RCE via crafted HTML. CVSS: High. Update Chrome now. #CVE #Google #infosec
##updated 2026-08-26T18:31:35
2 posts
🟠 CVE-2026-79992 - High (7.8)
A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local sh...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79992/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-79992 - High (7.8)
A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local sh...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79992/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:31:30
4 posts
2 repos
🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2019-1068
Vendor: Microsoft
Product: SQL Server
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2019-1068
🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2019-1068
Vendor: Microsoft
Product: SQL Server
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2019-1068
updated 2026-08-26T18:31:30
4 posts
🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2015-5287
Vendor: Red Hat
Product: Automatic Bug Reporting Tool
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-5287
🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2015-5287
Vendor: Red Hat
Product: Automatic Bug Reporting Tool
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-5287
updated 2026-08-26T18:30:34
4 posts
3 repos
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2026-8452
Vendor: Citrix
Product: NetScaler ADC and NetScaler Gateway
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8452
🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2026-8452
Vendor: Citrix
Product: NetScaler ADC and NetScaler Gateway
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8452
updated 2026-08-26T18:30:28
4 posts
4 repos
https://github.com/Bonfee/CVE-2022-0995
https://github.com/A1b2rt/cve-2022-0995
🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2022-0995
Vendor: Linux
Product: Kernel
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2022-0995
🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2022-0995
Vendor: Linux
Product: Kernel
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2022-0995
updated 2026-08-26T18:30:27
4 posts
🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2015-3246
Vendor: Red Hat
Product: Libuser
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-3246
🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2015-3246
Vendor: Red Hat
Product: Libuser
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-3246
updated 2026-08-26T18:17:05.890000
2 posts
🔴 CVE-2026-81032 - Critical (9.8)
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and wr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81032/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-81032 - Critical (9.8)
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and wr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81032/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:17:01.453000
4 posts
🟠 CVE-2026-75960 - High (8.1)
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75960/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CISA advisory ICSA-26-237-01 (rev. 1) discloses CVE-2026-75960 in Rently Smart Home firmware 20.1.0 and earlier. The vulnerability (CWE-522) allows extraction of PINs and Master PINs due to insufficiently protected credentials.
#CISA #CVE2026 #SmartHomeSecurity #ICSAdvisory
https://cyberworldops.eu/en/cisa-flaw-in-rently-smart-home-allows-retrieval-of-pins-and-master-pin
##🟠 CVE-2026-75960 - High (8.1)
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75960/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CISA advisory ICSA-26-237-01 (rev. 1) discloses CVE-2026-75960 in Rently Smart Home firmware 20.1.0 and earlier. The vulnerability (CWE-522) allows extraction of PINs and Master PINs due to insufficiently protected credentials.
#CISA #CVE2026 #SmartHomeSecurity #ICSAdvisory
https://cyberworldops.eu/en/cisa-flaw-in-rently-smart-home-allows-retrieval-of-pins-and-master-pin
##updated 2026-08-26T18:16:40.930000
2 posts
🔴 CVE-2026-54569 - Critical (9.8)
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54569/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54569 - Critical (9.8)
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54569/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:16:27.550000
2 posts
🟠 CVE-2026-32258 - High (8.1)
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-32258 - High (8.1)
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T17:17:26.120000
2 posts
🟠 CVE-2026-80427 - High (8.4)
bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are passed to the child process with no -- delimiter between them, so any sourc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80427/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80427 - High (8.4)
bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are passed to the child process with no -- delimiter between them, so any sourc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80427/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T17:01:18.043000
1 posts
CVE-2026-78901 - V8 race condition in Google Chrome allows arbitrary code execution inside the sandbox. CVSS N/A (Medium). Update Chrome immediately. #CVE #Chrome #infosec
##updated 2026-08-26T16:54:50.030000
2 posts
The bear is friendly. Think of honey, if you can.
For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).
<https://www.cve.org/CVERecord?id=CVE-2026-58092>
<https://nvd.nist.gov/vuln/detail/CVE-2026-58092>
<https://security.freebsd.org/advisories/FreeBSD-SA-26:59.mac_do.asc>
<https://defcon.social/@charlesrocket/116714325230546417> @charlesrocket re: LLM shaming.
##The bear is friendly. Think of honey, if you can.
For anyone who wonders why tags included #FreeBSD, it's because – in addition to the write-up of CVE-2026-58083 and CVE-2026-58084 (July 2026) – I assume that Hazley Samsudin might also choose Blimpers for CVE-2026-58092 (August).
<https://www.cve.org/CVERecord?id=CVE-2026-58092>
<https://nvd.nist.gov/vuln/detail/CVE-2026-58092>
<https://security.freebsd.org/advisories/FreeBSD-SA-26:59.mac_do.asc>
<https://defcon.social/@charlesrocket/116714325230546417> @charlesrocket re: LLM shaming.
##updated 2026-08-26T16:46:22.330000
1 posts
🟠 CVE-2026-16783 - High (7.8)
A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T16:45:12.020000
2 posts
🟠 CVE-2026-75768 - High (7.8)
Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75768 - High (7.8)
Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T16:36:16.990000
1 posts
CVE-2026-77995 (CRITICAL, CVSS 10): miniOrange OAuth Client for Joomla (v1.0.0 – 3.1.9) allows arbitrary account takeover via cookie manipulation. Patch to 3.2.0+ required. https://radar.offseq.com/threat/cve-2026-77995-cwe-639-authorization-bypass-through-user-controlled-key-in-miniorangecom-miniorange-0e8da876ce4c7e51 #OffSeq #Joomla #Vuln #OAuth
##updated 2026-08-26T16:35:20.160000
1 posts
1 repos
‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart
GitHub: https://github.com/toanln-cov/CVE-2026-76565
A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≤ 6.1.7 for Joomla.
The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.
The PoC demonstrates:
• Reflected XSS through crafted GET parameters
• Exploitation of vulnerable price filter inputs
• Attribute-context injection caused by missing htmlspecialchars() encoding
• No authentication requirement for exploitation
• Affected versions: PhocaCart ≤ 6.1.7
• Fixed version: PhocaCart 6.1.8
💥 No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.
##updated 2026-08-26T16:35:20.160000
1 posts
CVE-2026-77994: CRITICAL SQL injection in Joomla Page Builder CK (v1.0.0-3.6.4). Unauthenticated remote SQL execution possible. No official fix yet — disable/remove vulnerable versions. CVSS 9.3. https://radar.offseq.com/threat/cve-2026-77994-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-d508026cac86e490 #OffSeq #Joomla #SQLInjection #Infosec
##updated 2026-08-26T16:30:52.723000
2 posts
🟠 CVE-2026-74932 - High (7.5)
The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74932/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74932 - High (7.5)
The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74932/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T16:19:05.917000
4 posts
Six chained vulnerabilities (CVE-2026-18431, CVSS 9.8) in the WordPress Avada theme and Fusion Builder plugin allow unauthenticated remote code execution. No user interaction is required — the exploit is zero-click. Any site running vulnerable versions of both components is at immediate risk of full takeover. Patch now. #AvadaVulnerability #WordPressSecurity #CVE202618431 #SiteTakeover
https://cyberworldops.eu/en/six-chained-vulnerabilities-in-wordpress-avada-theme-allow-full-site
##CVE-2026-18431 - Critical Unauthenticated RCE in WordPress Avada theme & Fusion Builder via arbitrary file write. CVSS 9.8. Unpatched. Mitigate immediately. #CVE #WordPress #cybersecurity
##Wordfence Argus Finds 6 Step Critical RCE in Avada Theme with 1M Sales
Wordfence가 Avada 테마(7.16 이하)와 Fusion Builder 플러그인(3.16 이하)의 6단계 취약점 체인을 이용하는 인증 불필요 원격 코드 실행(CVE-2026-18431, CVSS 9.8)을 공개했습니다. 두 구성요소가 활성화되고 특정 관리자 작성 콘텐츠가 존재할 경우 공격자는 임의 PHP 파일을 작성·실행해 웹 서버 권한으로 사이트를 완전히 장악할 수 있습니다. 패치는 Avada 7.16.1 및 Fusion...
##Six chained vulnerabilities (CVE-2026-18431, CVSS 9.8) in the WordPress Avada theme and Fusion Builder plugin allow unauthenticated remote code execution. No user interaction is required — the exploit is zero-click. Any site running vulnerable versions of both components is at immediate risk of full takeover. Patch now. #AvadaVulnerability #WordPressSecurity #CVE202618431 #SiteTakeover
https://cyberworldops.eu/en/six-chained-vulnerabilities-in-wordpress-avada-theme-allow-full-site
##updated 2026-08-26T16:19:05.917000
2 posts
🔴 CVE-2026-79911 - Critical (10)
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname lea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79911/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-79911 - Critical (10)
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname lea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79911/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T16:19:05.917000
1 posts
CVE-2026-32556 - Unauthenticated XSS in Boost <= 2.0.4. CVSS 7.1. Currently unpatched. Audit systems and mitigate risk immediately. #CVE #XSS #infosec
##updated 2026-08-26T16:16:35.933000
2 posts
🟠 CVE-2026-65092 - High (8.5)
NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65092/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65092 - High (8.5)
NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65092/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T15:16:51.040000
3 posts
🟠 CVE-2026-65105 - High (8.1)
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and de...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65105/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Drive-By Agent Hijacking: One Website Visit, Persistent Model Poisoning
Oasis Security는 NVIDIA NemoClaw가 로컬 Ollama를 `0.0.0.0:11434`에 바인딩하는 구성 때문에 발생하는 CVE-2026-65105를 공개했습니다. 공격자는 DNS rebinding을 이용해 피해자가 악성 웹페이지를 한 번 방문하는 것만으로 인증 없는 Ollama API에 접근해 모델 조회·삭제·다운로드·추론 실행 등을 수행할 수 있습니다. 특히 `/api/create`의 모델 chat template을 변조하면 에이전트가 보내는 시스템 프롬프트 뒤에 공격자 지시를 지속적...
https://www.cyera.com/research/nemoclaw-one-website-visit-to-hijack-your-ai-agent
##🟠 CVE-2026-65105 - High (8.1)
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and de...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65105/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T15:16:50.467000
2 posts
🟠 CVE-2026-65096 - High (7.8)
NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, informat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65096/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65096 - High (7.8)
NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, informat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65096/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T14:28:05
2 posts
🟠 CVE-2026-54511 - High (8.6)
LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 through U+001F...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54511/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54511 - High (8.6)
LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 through U+001F...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54511/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T14:21:54
2 posts
🔴 CVE-2026-54523 - Critical (9.6)
Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke gen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54523/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54523 - Critical (9.6)
Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke gen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54523/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T14:17:12.830000
2 posts
🟠 CVE-2026-73108 - High (7.5)
RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before rece...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73108 - High (7.5)
RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before rece...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T13:19:20.413000
2 posts
Impact:
CVSS Severity and Metrics:
Base Score: 9.6 Critical
Vector:
CVSS: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE: CVE-2026-77532 (Will Robertson)
##Impact:
CVSS Severity and Metrics:
Base Score: 9.6 Critical
Vector:
CVSS: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE: CVE-2026-77532 (Will Robertson)
##updated 2026-08-26T13:19:16.497000
2 posts
🟠 CVE-2026-54757 - High (7.8)
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54757/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54757 - High (7.8)
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54757/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T13:17:47.880000
2 posts
1 repos
https://github.com/HORKimhab/CVE-2026-19912-CVE-2026-19913-CVE-2026-19914
Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.
#Kaltura #CyberSecurity #CVE202619912 #CVE202619913 #InfoSec
https://securityonline.info/kaltura-server-flaws/?utm_source=mastodon&utm_medium=jetpack_social
##Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.
#Kaltura #CyberSecurity #CVE202619912 #CVE202619913 #InfoSec
https://securityonline.info/kaltura-server-flaws/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-26T00:31:14
2 posts
🔴 CVE-2026-80138 - Critical (9.8)
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80138/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-80138 - Critical (9.8)
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80138/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T00:31:14
2 posts
🟠 CVE-2026-79912 - High (8.3)
A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The att...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79912/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-79912 - High (8.3)
A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The att...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79912/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T00:31:09
2 posts
🟠 CVE-2026-80186 - High (7.6)
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80186/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80186 - High (7.6)
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80186/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:58
2 posts
🔴 CVE-2026-80104 - Critical (9.8)
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80104/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-80104 - Critical (9.8)
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80104/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:45
1 posts
CVE-2026-79021 - Missing authorization in Google Chrome allows access restriction bypass via crafted PDF. CVSS N/A (Low). Patch now. #CVE #Chrome #infosec
##updated 2026-08-25T21:31:39
2 posts
🟠 CVE-2026-65099 - High (7.8)
NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65099 - High (7.8)
NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:36
4 posts
NVIDIA patched 20 NemoClaw and OpenShell flaws. The worst, CVE-2026-65093 (CVSS 9.9), enables code execution via sandbox escape. Update now.
#NVIDIA #CyberSecurity #CVE202665093 #CodeExecution #AISecurity
##🔴 CVE-2026-65093 - Critical (9.9)
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65093/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##NVIDIA patched 20 NemoClaw and OpenShell flaws. The worst, CVE-2026-65093 (CVSS 9.9), enables code execution via sandbox escape. Update now.
#NVIDIA #CyberSecurity #CVE202665093 #CodeExecution #AISecurity
##🔴 CVE-2026-65093 - Critical (9.9)
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65093/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:35
2 posts
🟠 CVE-2026-65081 - High (8.1)
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tamp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65081/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65081 - High (8.1)
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tamp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65081/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:35
2 posts
🟠 CVE-2026-65090 - High (7.8)
NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65090/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65090 - High (7.8)
NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65090/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:35
2 posts
🟠 CVE-2026-65089 - High (7.8)
NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information dis...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65089/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65089 - High (7.8)
NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information dis...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65089/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:35
2 posts
🟠 CVE-2026-65098 - High (8.1)
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65098 - High (8.1)
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:35
2 posts
Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.
#SonicWall #NetExtender #CyberSecurity #CVE202666152 #CVE202666153
##Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.
#SonicWall #NetExtender #CyberSecurity #CVE202666152 #CVE202666153
##updated 2026-08-25T21:31:35
2 posts
Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.
#SonicWall #NetExtender #CyberSecurity #CVE202666152 #CVE202666153
##Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.
#SonicWall #NetExtender #CyberSecurity #CVE202666152 #CVE202666153
##updated 2026-08-25T21:31:35
2 posts
🟠 CVE-2026-65091 - High (8.8)
NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65091/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65091 - High (8.8)
NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65091/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:34
2 posts
🟠 CVE-2026-65097 - High (7.5)
NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65097/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-65097 - High (7.5)
NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65097/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:31
2 posts
🔴 CVE-2026-65083 - Critical (9.9)
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of priv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65083/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-65083 - Critical (9.9)
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of priv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65083/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T20:17:08.627000
2 posts
🟠 CVE-2026-80049 - High (8.8)
Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80049/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80049 - High (8.8)
Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80049/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T20:17:04.150000
1 posts
Eine ungepatchte Lücke (CVE-2026-75501) in Calix-Routern (GS5239XG) hebelt Firewall und NAT aus. Der UPnP-Dienst ist ungeschützt auf Port 5000 erreichbar, wodurch Angreifer aus der Ferne Port-Weiterleitungen anlegen können. So werden interne Heimnetz-Geräte wie NAS oder Kameras direkt im Internet exponiert. Da bisher kein Patch existiert, sollten Nutzer UPnP im Router deaktivieren oder ihren ISP kontaktieren.
#Calix #ITSecurity #CyberSecurity #Sicherheitslücke #Router #InfoSec
##updated 2026-08-25T19:27:32
2 posts
🟠 CVE-2026-55099 - High (7.5)
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55099 - High (7.5)
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T19:19:28
2 posts
🔴 CVE-2026-45018 - Critical (9.8)
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45018/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45018 - Critical (9.8)
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45018/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T18:32:01
6 posts
🏆 New Achievement! Maximum Payload Acquired!
ITEM DROP: Cursed Campaign Scroll (Adobe Campaign Classic). Three critical flaws — headlined by CVE-2026-76197, a CVSS 10.0 OS command injection — landed in your inventory without your permission. Any attacker who finds you can inject arbitrary OS commands and execute code freely, like a bard who learned every spell and also hates you specifically.
Equipping this item applies the debuff: Completely Owned Server (permanent, until patched). (1/2)
##Three critical Adobe Campaign Classic flaws (CVE-2026-76197, CVSS 10.0) allow arbitrary code execution. Update to build 9401 now.
##🔴 CVE-2026-76197 - Critical (10)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76197/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🏆 New Achievement! Maximum Payload Acquired!
ITEM DROP: Cursed Campaign Scroll (Adobe Campaign Classic). Three critical flaws — headlined by CVE-2026-76197, a CVSS 10.0 OS command injection — landed in your inventory without your permission. Any attacker who finds you can inject arbitrary OS commands and execute code freely, like a bard who learned every spell and also hates you specifically.
Equipping this item applies the debuff: Completely Owned Server (permanent, until patched). (1/2)
##Three critical Adobe Campaign Classic flaws (CVE-2026-76197, CVSS 10.0) allow arbitrary code execution. Update to build 9401 now.
##🔴 CVE-2026-76197 - Critical (10)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76197/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T18:32:01
2 posts
🟠 CVE-2026-79784 - High (8.8)
Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the configuration, splits it into a module and an attribute, imports th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79784/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-79784 - High (8.8)
Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the configuration, splits it into a module and an attribute, imports th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79784/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T18:32:01
2 posts
1 repos
https://github.com/HORKimhab/CVE-2026-19912-CVE-2026-19913-CVE-2026-19914
Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.
#Kaltura #CyberSecurity #CVE202619912 #CVE202619913 #InfoSec
https://securityonline.info/kaltura-server-flaws/?utm_source=mastodon&utm_medium=jetpack_social
##Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.
#Kaltura #CyberSecurity #CVE202619912 #CVE202619913 #InfoSec
https://securityonline.info/kaltura-server-flaws/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-25T18:32:00
2 posts
🟠 CVE-2026-79774 - High (8.4)
Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79774/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-79774 - High (8.4)
Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79774/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T18:31:56
2 posts
🔴 CVE-2026-79675 - Critical (9.8)
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79675/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-79675 - Critical (9.8)
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79675/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T17:17:31.403000
1 posts
CVE-2026-55538 - Auth bypass in PraisonAI allows unauthorized API execution on agent endpoints. CVSS 7.3. Update to v4.6.58 immediately. #CVE #infosec #cybersecurity
##updated 2026-08-25T15:33:06
2 posts
The August 2026 OpenSSL security update fixes 9 flaws, including a QUIC double free (CVE-2026-18798) and a CMS heap overflow. Patch now.
##The August 2026 OpenSSL security update fixes 9 flaws, including a QUIC double free (CVE-2026-18798) and a CMS heap overflow. Patch now.
##updated 2026-08-25T15:16:35.297000
2 posts
🟠 CVE-2026-57863 - High (8.8)
Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57863/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-57863 - High (8.8)
Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57863/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T14:54:57
1 posts
CVE-2026-55540 - Arbitrary File Read in PraisonAI via symlink path traversal. CVSS 7.1. Update to version 4.6.58 immediately. #CVE #PraisonAI #infosec
##updated 2026-08-25T13:19:24.810000
4 posts
Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.
##And a sev:CRIT RCE. As a treat.
Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.
##And a sev:CRIT RCE. As a treat.
updated 2026-08-25T12:31:29
2 posts
KlbTheme Total Donations <=2.0.5 has a CRITICAL privilege escalation vuln (CVE-2026-78570, CVSS 9.8). Unauthenticated attackers can gain admin access. No patch yet — disable/remove plugin & monitor for advisories. https://radar.offseq.com/threat/cve-2026-78570-cwe-269-improper-privilege-management-in-klbtheme-total-donations-fcfd73df270b6d37 #OffSeq #WordPress #CVE #Vuln
##KlbTheme Total Donations <=2.0.5 has a CRITICAL privilege escalation vuln (CVE-2026-78570, CVSS 9.8). Unauthenticated attackers can gain admin access. No patch yet — disable/remove plugin & monitor for advisories. https://radar.offseq.com/threat/cve-2026-78570-cwe-269-improper-privilege-management-in-klbtheme-total-donations-fcfd73df270b6d37 #OffSeq #WordPress #CVE #Vuln
##updated 2026-08-25T12:31:24
4 posts
Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.
##sev:CRIT ../ in WatchGuard Agent. Once again, INFOSEC increasing that attack surface instead of decreasing it.
Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.
##sev:CRIT ../ in WatchGuard Agent. Once again, INFOSEC increasing that attack surface instead of decreasing it.
updated 2026-08-25T09:30:48
1 posts
CVE-2026-78563 - Stored XSS in NotificationX Pro plugin for WordPress (<= 3.1.4). Unauthenticated script injection. CVSS 7.2. Audit sites now. #CVE #WordPress #infosec
##updated 2026-08-25T09:30:48
2 posts
CVE-2026-78568: CRITICAL SQL Injection in KlbTheme Total Donations ≤2.0.5. Unauthenticated attackers can extract sensitive DB data via improper input handling. No fix yet — disable the plugin. https://radar.offseq.com/threat/cve-2026-78568-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-52b70f977190d0ba #OffSeq #WordPress #SQLi #Vuln
##CVE-2026-78568: CRITICAL SQL Injection in KlbTheme Total Donations ≤2.0.5. Unauthenticated attackers can extract sensitive DB data via improper input handling. No fix yet — disable the plugin. https://radar.offseq.com/threat/cve-2026-78568-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-52b70f977190d0ba #OffSeq #WordPress #SQLi #Vuln
##updated 2026-08-25T09:30:47
2 posts
A critical TYPO3 Powermail RCE flaw (CVE-2026-77136) is actively exploited in the wild. Update immediately to prevent server compromise and data leaks.
#TYPO3 #Powermail #Vulnerability #CyberSecurity #CVE202677136
##A critical TYPO3 Powermail RCE flaw (CVE-2026-77136) is actively exploited in the wild. Update immediately to prevent server compromise and data leaks.
#TYPO3 #Powermail #Vulnerability #CyberSecurity #CVE202677136
##updated 2026-08-25T09:30:47
4 posts
A critical Weidmueller router flaw, CVE-2026-63586 (CVSS 9.8), lets attackers execute arbitrary commands with root privileges. Patch devices immediately.
##🔒 New CSAF advisory published
VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587
Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…
HTML: https://certvde.com/en/advisories/VDE-2026-083/
CSAF JSON: https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-083.json
A critical Weidmueller router flaw, CVE-2026-63586 (CVSS 9.8), lets attackers execute arbitrary commands with root privileges. Patch devices immediately.
##🔒 New CSAF advisory published
VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587
Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…
HTML: https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-083.html
CSAF JSON: https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-083.json
updated 2026-08-25T09:30:42
2 posts
Two unpatched FURUNO FA-50 vulnerabilities (CVE-2026-59769, CVE-2026-67578) let attackers alter maritime transponder settings. Learn the mitigation steps.
#Furuno #CyberSecurity #CVE202659769 #CVE202667578 #MaritimeSecurity
##Two unpatched FURUNO FA-50 vulnerabilities (CVE-2026-59769, CVE-2026-67578) let attackers alter maritime transponder settings. Learn the mitigation steps.
#Furuno #CyberSecurity #CVE202659769 #CVE202667578 #MaritimeSecurity
##updated 2026-08-25T09:30:42
3 posts
Two unpatched FURUNO FA-50 vulnerabilities (CVE-2026-59769, CVE-2026-67578) let attackers alter maritime transponder settings. Learn the mitigation steps.
#Furuno #CyberSecurity #CVE202659769 #CVE202667578 #MaritimeSecurity
##CVE-2026-59769 - Hard-coded credentials in FA-50 allow unauthorized settings access and vessel ID alteration. CVSS 9.1. Restrict network access now. #CVE #infosec #cybersecurity
##Two unpatched FURUNO FA-50 vulnerabilities (CVE-2026-59769, CVE-2026-67578) let attackers alter maritime transponder settings. Learn the mitigation steps.
#Furuno #CyberSecurity #CVE202659769 #CVE202667578 #MaritimeSecurity
##updated 2026-08-25T09:30:36
1 posts
🟠 CVE-2026-71366 - High (7.7)
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without valid...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71366/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T09:17:32.057000
2 posts
🔒 New CSAF advisory published
VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587
Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…
HTML: https://certvde.com/en/advisories/VDE-2026-083/
CSAF JSON: https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-083.json
🔒 New CSAF advisory published
VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587
Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…
HTML: https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-083.html
CSAF JSON: https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-083.json
updated 2026-08-25T06:31:36
1 posts
Privilege escalation vuln (CRITICAL, CVSS 9.8) in MVPThemes Jawn WordPress theme (≤1.4.2): CVE-2026-78477 lets unauth users elevate to admin. Review deployments & monitor for fixes. https://radar.offseq.com/threat/cve-2026-78477-cwe-266-incorrect-privilege-assignment-in-mvpthemes-jawn-ec6b466fa423dd3f #OffSeq #WordPress #Vuln #PrivilegeEscalation
##updated 2026-08-25T04:18:21.457000
1 posts
1 repos
TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.
##updated 2026-08-25T04:18:15.290000
1 posts
🟠 CVE-2026-61419 - High (7.8)
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61419/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T04:18:11.393000
2 posts
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2026-08-25T03:32:20
3 posts
GitPython Patches Critical RCE Vulnerability in Config Parser
GitPython version 3.1.59 patches a critical remote code execution vulnerability (CVE-2026-78676) caused by improper handling of multi-line configuration values. The flaw allows attackers to inject malicious Git directives that execute arbitrary code during routine repository operations.
**If you use GitPython in any application or CI/CD pipeline, update it to version 3.1.59 or later. Еvery version up to 3.1.58 is vulnerable to CVE-2026-78676. Until you can update, don't let GitPython read or write config files from cloned repos, shared configs, or workspace caches you don't fully control. Тreat any repository from an outside source as untrusted.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/gitpython-patches-critical-rce-vulnerability-in-config-parser-g-q-0-2-o/gD2P6Ple2L
GitPython Patches Critical RCE Vulnerability in Config Parser
GitPython version 3.1.59 patches a critical remote code execution vulnerability (CVE-2026-78676) caused by improper handling of multi-line configuration values. The flaw allows attackers to inject malicious Git directives that execute arbitrary code during routine repository operations.
**If you use GitPython in any application or CI/CD pipeline, update it to version 3.1.59 or later. Еvery version up to 3.1.58 is vulnerable to CVE-2026-78676. Until you can update, don't let GitPython read or write config files from cloned repos, shared configs, or workspace caches you don't fully control. Тreat any repository from an outside source as untrusted.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/gitpython-patches-critical-rce-vulnerability-in-config-parser-g-q-0-2-o/gD2P6Ple2L
CVE-2026-78676 | GitPython <3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unknown — avoid untrusted configs. https://radar.offseq.com/threat/cve-2026-78676-improper-neutralization-of-argument-delimiters-in-a-command-argument-injection-in-98aef85f24190fbe #OffSeq #CVE202678676 #git #infosec
##updated 2026-08-25T03:32:14
1 posts
CVE-2026-72702 | Grav CMS <2.0.16 | CRITICAL (CVSS 9.3): Origin validation bypass via weak Referer checks lets attackers defeat CSRF defenses. No fix confirmed — use extra controls, monitor vendor updates. https://radar.offseq.com/threat/cve-2026-72702-origin-validation-error-in-getgrav-grav-4b8f0ff64f944a7c #OffSeq #CVE202672702 #GravCMS #WebSecurity
##updated 2026-08-25T00:30:37
1 posts
CVE-2026-78264 - Unauthenticated XSS in Toolset Blocks <= 1.6.26. CVSS 7.1. Update immediately. #CVE #XSS #infosec
##updated 2026-08-25T00:30:37
2 posts
CRITICAL CVE-2026-78265: Nexcess The Events Calendar <=6.17.2 has unauthenticated PHP Object Injection (CWE-502). Full system compromise possible. No patch yet — remove or disable plugin for now. https://radar.offseq.com/threat/cve-2026-78265-cwe-502-deserialization-of-untrusted-data-in-nexcess-the-events-calendar-3dd3af18547313e0 #OffSeq #WordPress #Infosec #CVE2026_78265
##🔴 CVE-2026-78265 - Critical (9.8)
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78265/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T00:30:37
2 posts
CVE-2026-78267 (CRITICAL, CVSS 9.8): Cozmoslabs TranslatePress <=3.3.2 is vulnerable to unauthenticated privilege escalation (CWE-266). No patch yet — monitor vendor advisories for updates. https://radar.offseq.com/threat/cve-2026-78267-cwe-266-incorrect-privilege-assignment-in-cozmoslabs-translatepress-ba0caba45d17d814 #OffSeq #WordPress #Vuln #PrivilegeEscalation
##🔴 CVE-2026-78267 - Critical (9.8)
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78267/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T00:30:37
1 posts
🟠 CVE-2026-78268 - High (7.5)
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78268/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T00:30:37
1 posts
🟠 CVE-2026-78284 - High (8.6)
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78284/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T21:34:43
4 posts
1 repos
📢 Metal Gear Online 3 : rejoindre un salon Steam suffisait à faire exécuter du code sur votre PC
Metal Gear Online 3, le mode multijoueur de Metal Gear Solid V: The Phantom Pain, contenait une vulnérabilité importante. Elle permettait à l'hôte d'un salon Steam d'exécuter du code arbitraire sur la machine des joueurs qui le rejoignaient sans la moindre action de leur part. Un patch a été mis au point…
🔗 https://www.it-connect.fr/metal-gear-online-3-faille-rce-cve-2026-19874/
💬 discussion : https://infosec.pub/post/51447026
#Vulnérabilité #Cyberveille
Metal Gear Online 3 : rejoindre un salon Steam suffisait à faire exécuter du code sur votre PC https://www.it-connect.fr/metal-gear-online-3-faille-rce-cve-2026-19874/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##Metal Gear Online 3 : rejoindre un salon Steam suffisait à faire exécuter du code sur votre PC https://www.it-connect.fr/metal-gear-online-3-faille-rce-cve-2026-19874/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##Metal Gear Online 3 RCE vulnerability CVE-2026-19874 fixed. Update the game to prevent attackers from executing remote code on your system.
#MetalGearOnline3 #CyberSecurity #Vulnerability #CVE202619874
##updated 2026-08-24T21:34:43
1 posts
i uSe lInUx bEcAuSe iT'S SeCuRe.
https://access.redhat.com/security/cve/cve-2026-19685
##NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
updated 2026-08-24T21:33:53
1 posts
🟠 CVE-2026-19568 - High (7.8)
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19568/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T21:33:53
1 posts
🟠 CVE-2026-7455 - High (7.8)
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7455/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T21:33:52
1 posts
TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.
##updated 2026-08-24T21:33:43
1 posts
1 repos
CVE-2026-71506 - Broken Access Control in Dolibarr REST API allows unauthorized deletion of payment records. CVSS 8.1. Restrict API access immediately. #CVE #Dolibarr #infosec
##updated 2026-08-24T21:33:31
22 posts
9 repos
https://github.com/boroeurnprach/Ashwesker-CVE-2026-21962
https://github.com/gglessner/cve_2026_21962_scanner
https://github.com/gregk4sec/cve-2026-21962
https://github.com/0xBlackash/CVE-2026-21962
https://github.com/samael0x4/CVE-2026-21962
https://github.com/gregk4sec/CVE-2026-21962-o
https://github.com/ThumpBo/CVE-2026-21962
https://github.com/naozibuhao/CVE-2026-21962_Java_GUI_Exploit_Tool
🚨 Critical Threat Intel: CVE-2026-21962 impacts Oracle HTTP Server & Weblogic Proxy Plug-in via access control bypass. Review exploitation patterns, web access detection queries, and active endpoint hardening actions.
https://thecybermind.co/jily
CISA has added Oracle CVE-2026-21962 to the KEV catalog. CVSS 10.0. This critical flaw in WebLogic Server allows unauthenticated access and is confirmed actively exploited. Federal remediation deadline is August 27, but every WebLogic deployment should be treated as urgent. Patch or isolate immediately.
#OracleCVE202621962 #WebLogic #CISA #KnownExploitedVulnerabilities
https://cyberworldops.eu/en/oracle-cve-2026-21962-enters-kev-maximum-score-and-unauthorized-access
##CISA Confirms Active Exploitation of Critical Oracle Vulnerability — CVE-2026-21962 Carries a 100 Severity Score + Video
A Critical Oracle Flaw Has Crossed Into the Real-World Threat Landscape A critical vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in has moved from a serious patching concern to an active cybersecurity threat. On August 24, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added…
##CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
CISA가 실제 악용 중인 CVSS 10.0 취약점 CVE-2026-21962에 대해 연방 기관에 최단 수준인 3일 이내 패치 기한을 부여했습니다. 이 취약점은 Oracle HTTP Server와 WebLogic Server Proxy Plug-in의 부적절한 접근 제어 문제로, 공격자가 중요 데이터를 생성·삭제·변조하거나 영향받는 시스템의 모든 데이터에 완전 접근할 수 있습니다. 영향을 받는 버전은 12...
##🔵 THREAT INTELLIGENCE
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
Vulnerability | CRITICAL
CVEs: CVE-2026-21962
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and...
Full analysis:
https://www.yazoul.net/news/article/actively-exploited-oracle-weblogic-flaw-lets-unauthenticated-attackers-access-cr
by Yazoul AI
##📰 CISA Adds Actively Exploited Oracle Flaw to KEV Catalog
CISA adds actively exploited Oracle vulnerability CVE-2026-21962 to its KEV catalog. Flaw affects Oracle HTTP Server & WebLogic Server Proxy Plug-in. Federal agencies must patch. #CVE #Oracle #CISA #KEV #PatchNow
##📢 Exploitation active de CVE-2026-21962 dans Oracle HTTP Server — ajout au catalogue KEV de la CISA
GBHackers, publié le 25 août 2026. La CISA (U.S. Cybersecurity and Infrastructure Security Agency) a officiellement ajouté CVE-2026-21962 à son catalogue Known Exploited Vulnerabilities (KEV), confirmant une exploitation active dans la nature.
📖 cyberveille : https://cyberveille.ch/posts/2026-08-25-exploitation-active-de-cve-2026-21962-dans-oracle-http-server-ajout-au-catalogue-kev-de-la-cisa/
🌐 source : https://gbhackers.com/hackers-exploit-critical-oracle-http-server-flaw/
🟡 vérification factuelle moyenne
#OracleHTTPServer #CISAKEV #Cyberveille
CISA Sounds the Alarm as Critical Oracle WebLogic Flaw Faces Active Exploitation + Video
A Critical Warning That Oracle Administrators Cannot Ignore A new cybersecurity warning is putting Oracle infrastructure under intense pressure after the U.S. Cybersecurity and Infrastructure Security Agency, CISA, ordered organizations to urgently address CVE-2026-21962, a critical vulnerability affecting Oracle HTTP Server and the WebLogic Server Proxy plugin. The danger is not…
##Geopolitical tensions escalate as the US launches "Operation Economic Outcast" against Iran, imposing new sanctions amidst Strait of Hormuz disputes (Aug 25). Canada is set to announce retaliatory tariffs against the US (Aug 25). The UK and Ukraine formalized an AI defense partnership (Aug 24).
In technology, Nvidia's AI chips remain a focal point, with Taiwan indicting nine individuals for illegal AI server exports to China (Aug 24). Hybrid bonding is advancing as a foundational technology for enhanced semiconductor performance (Aug 25).
Cybersecurity: CISA issued a warning regarding the active exploitation of an Oracle WebLogic vulnerability (CVE-2026-21962), urging immediate patching (Aug 25). ReliaQuest also confirmed an employee fell victim to a social engineering attack (Aug 25).
##CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.
Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.
Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.
#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)
##🏆 New Achievement! Ten Point Oh, Your Honor!
This court finds Oracle WebLogic Server and Oracle HTTP Server guilty of harboring CVE-2026-21962 — a CVSS 10.0, maximum-severity flaw allowing unauthenticated attackers full network access via HTTP to seize instances and tamper with critical data. The defendant offered no authentication requirement whatsoever. CISA has entered the verdict into its Known Exploited Vulnerabilities catalog. (1/2)
##Oracle WebLogic Faces a Maximum-Severity Threat as CISA Flags CVE-2026-21962 for Immediate Action + Video
A Critical Warning for Oracle Administrators A vulnerability with the highest possible CVSS severity has moved from a technical security advisory into a much more urgent category: CISA’s Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-21962, affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, creating a potentially…
##CISA Sounds the Alarm as Maximum-Severity Oracle Flaw CVE-2026-21962 Faces Active Exploitation + Video
Introduction: When a Critical Oracle Server Becomes an Open Door A critical vulnerability does not always become a cybersecurity emergency the moment it is discovered. Sometimes the real danger begins later, when proof-of-concept activity spreads, attackers start scanning the internet, and defenders realize that systems which should have been patched months ago are…
##🚨 Critical Threat Intel: CVE-2026-21962 impacts Oracle HTTP Server & Weblogic Proxy Plug-in via access control bypass. Review exploitation patterns, web access detection queries, and active endpoint hardening actions.
https://thecybermind.co/jily
CISA has added Oracle CVE-2026-21962 to the KEV catalog. CVSS 10.0. This critical flaw in WebLogic Server allows unauthenticated access and is confirmed actively exploited. Federal remediation deadline is August 27, but every WebLogic deployment should be treated as urgent. Patch or isolate immediately.
#OracleCVE202621962 #WebLogic #CISA #KnownExploitedVulnerabilities
https://cyberworldops.eu/en/oracle-cve-2026-21962-enters-kev-maximum-score-and-unauthorized-access
##Geopolitical tensions escalate as the US launches "Operation Economic Outcast" against Iran, imposing new sanctions amidst Strait of Hormuz disputes (Aug 25). Canada is set to announce retaliatory tariffs against the US (Aug 25). The UK and Ukraine formalized an AI defense partnership (Aug 24).
In technology, Nvidia's AI chips remain a focal point, with Taiwan indicting nine individuals for illegal AI server exports to China (Aug 24). Hybrid bonding is advancing as a foundational technology for enhanced semiconductor performance (Aug 25).
Cybersecurity: CISA issued a warning regarding the active exploitation of an Oracle WebLogic vulnerability (CVE-2026-21962), urging immediate patching (Aug 25). ReliaQuest also confirmed an employee fell victim to a social engineering attack (Aug 25).
##CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.
Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.
Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.
#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)
##🏆 New Achievement! Ten Point Oh, Your Honor!
This court finds Oracle WebLogic Server and Oracle HTTP Server guilty of harboring CVE-2026-21962 — a CVSS 10.0, maximum-severity flaw allowing unauthenticated attackers full network access via HTTP to seize instances and tamper with critical data. The defendant offered no authentication requirement whatsoever. CISA has entered the verdict into its Known Exploited Vulnerabilities catalog. (1/2)
##Here's a summary of recent geopolitical, technology, and cybersecurity news:
Geopolitical: The US has launched "Operation Economic Outcast" against Iran (Aug 25) and plans 7.5% tariffs on Chinese goods over excess manufacturing capacity before a September summit (Aug 25).
Technology: Google is reorganizing DeepMind and acquired Spirit Airlines' data for AI model development (Aug 24). Fujitsu is trialing AI for construction process and risk management (Aug 25).
Cybersecurity: CISA added an Oracle HTTP Server vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities Catalog (Aug 24). Critical GitLab (CVE-2026-19478) and Cisco vulnerabilities (CVSS 10.0) are under active exploitation (Aug 24).
##CISA warned that the CVE-2026-21962 Oracle flaw with a CVSS 10 score is actively exploited in the wild. Patch Oracle Fusion Middleware systems now.
##🚨 [CISA-2026:0824] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-21962 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-21962)
- Name: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Oracle
- Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in
- Notes: https://www.oracle.com/security-alerts/cpujan2026.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-21962
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260824 #cisa20260824 #cve_2026_21962 #cve202621962
##CVE ID: CVE-2026-21962
Vendor: Oracle
Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in
Date Added: 2026-08-24
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21962
updated 2026-08-24T20:17:19.623000
1 posts
🔴 CVE-2026-76835 - Critical (9.1)
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76835/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T20:16:55.243000
1 posts
CVE-2026-63310 - MITM package injection flaw in NLTK downloader module. CVSS 7.1. Update NLTK to 3.9.3+ immediately. #CVE #Python #infosec
##updated 2026-08-24T18:32:04
1 posts
🟠 CVE-2026-76838 - High (8.5)
Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reserved ranges...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76838/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T18:31:59
1 posts
1 repos
TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.
##updated 2026-08-24T18:31:59
1 posts
1 repos
🔴 CVE-2026-76071 - Critical (9.8)
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76071/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T18:31:58
1 posts
1 repos
🔴 CVE-2026-76070 - Critical (9.8)
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76070/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T18:31:57
1 posts
🟠 CVE-2026-76073 - High (8.8)
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76073/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T18:17:31.060000
1 posts
🟠 CVE-2026-78209 - High (8.2)
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78209/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T16:41:13.950000
2 posts
🔴 CVE-2026-78169 - Critical (9.9)
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile resul...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78169/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: Stack-based buffer overflow (CVE-2026-78169) in UTT HiPER 1250GW v3.2.7-210907-180535. Public exploit code available — no patch yet. Restrict device access & monitor /goform/aspRemoteApConfTempSend traffic. https://radar.offseq.com/threat/cve-2026-78169-stack-based-buffer-overflow-in-utt-hiper-1250gw-b9697a669a575a95 #OffSeq #CVE #Infosec #IoT
##updated 2026-08-24T16:40:53.647000
2 posts
CRITICAL vuln (CVE-2026-78168) in EFM ipTIME T24000M ≤14.20.0: improper authentication in httpcon_check_session_url enables remote exploit. Public exploit disclosed, no vendor fix. Review access controls now. https://radar.offseq.com/threat/cve-2026-78168-improper-authentication-in-efm-iptime-t24000m-bfa2e716a3fcf0b6 #OffSeq #CVE #IoTSecurity #Exploit
##🔴 CVE-2026-78168 - Critical (9.8)
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78168/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T15:31:57
4 posts
Zscaler Patches Critical Unauthenticated RCE in Client Connector for Windows
Zscaler fixed a critical vulnerability (CVE-2026-59568) that allowed unauthenticated remote code execution and privilege escalation as well as three other flaws in its Client Connector for Windows
**If you use Zscaler Client Connector on Windows, update every endpoint to the latest patched version. Anything released before June 2026 (including 4.7.0.364, 4.8.0.232/284/291, and 4.9.0.448/455) is at risk of remote takeover. Don't assume your automated update policy reached every machine; manually verify the version on all devices. Check endpoint logs for odd processes launched by Zscaler components or unexpected new listening services.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/zscaler-patches-critical-unauthenticated-rce-in-client-connector-for-windows-x-x-2-j-a/gD2P6Ple2L
Critical Zscaler Client Connector Vulnerability Could Give Attackers Remote Code Execution Without Credentials + Video
Introduction: A Trusted Security Agent Can Become an Attacker’s Doorway Security software is supposed to be one of the strongest layers protecting an enterprise endpoint. But when a vulnerability strikes the security agent itself, the risk can become far more serious than an ordinary application flaw. That is the concern surrounding CVE-2026-59568, a…
##Zscaler Patches Critical Unauthenticated RCE in Client Connector for Windows
Zscaler fixed a critical vulnerability (CVE-2026-59568) that allowed unauthenticated remote code execution and privilege escalation as well as three other flaws in its Client Connector for Windows
**If you use Zscaler Client Connector on Windows, update every endpoint to the latest patched version. Anything released before June 2026 (including 4.7.0.364, 4.8.0.232/284/291, and 4.9.0.448/455) is at risk of remote takeover. Don't assume your automated update policy reached every machine; manually verify the version on all devices. Check endpoint logs for odd processes launched by Zscaler components or unexpected new listening services.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/zscaler-patches-critical-unauthenticated-rce-in-client-connector-for-windows-x-x-2-j-a/gD2P6Ple2L
https://nvd.nist.gov/vuln/detail/CVE-2026-59568
##Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
updated 2026-08-24T13:16:48.920000
2 posts
6 repos
https://github.com/guiimoraes/CVE-2025-15467
https://github.com/materaj2/cve-2025-15467
https://github.com/mr-r3b00t/CVE-2025-15467
https://github.com/balgan/CVE-2025-15467
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2026-08-24T09:33:52
1 posts
#OT #Advisory VDE-2026-061
Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches
An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been triggered, any unauthenticated attacker with network access to the web interface can retrieve the leaked MAC addresses via common browser developer tools. The vulnerable functionality was introduced in version 2.1.0 and is fixed in version 2.1.1.
#CVE CVE-2026-8173
https://certvde.com/en/advisories/vde-2026-061/
#CSAF https://murrelektronik.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-061.json
##updated 2026-08-24T06:30:35
1 posts
4MOSAn GCB Doctor faces a CRITICAL OS Command Injection (CVE-2026-78211, CVSS 9.8). Unauthenticated attackers can execute arbitrary system commands via ADOdb test page parameter. No patch — restrict access & monitor closely. https://radar.offseq.com/threat/cve-2026-78211-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-91902877a695e366 #OffSeq #CVE202678211 #Vuln #BlueTeam
##updated 2026-08-24T03:31:14
1 posts
🟠 CVE-2026-78170 - High (8.8)
A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be performed from...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78170/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T03:31:14
1 posts
🔴 CVE-2026-78167 - Critical (10)
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78167/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T03:31:14
1 posts
🟠 CVE-2026-78208 - High (7.5)
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78208/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-24T03:31:14
1 posts
🔴 CVE-2026-78207 - Critical (9.4)
exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto_...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78207/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-23T15:33:12
1 posts
CVE-2026-7808 | justhtml <1.16.0 faces CRITICAL XSS risk via HTML sanitization bypass in advanced use cases. Upgrade to 1.16.0+ to fix. Impacts apps with custom/mutated policies. Details: https://radar.offseq.com/threat/cve-2026-7808-improper-input-validation-in-emilstenstrom-justhtml-86dd54d29e0645e9 #OffSeq #CVE20267808 #infosec #XSS
##updated 2026-08-23T15:33:12
1 posts
CVE-2026-8445: EmilStenstrom justhtml <=1.11.0 suffers CRITICAL XSS due to improper escaping in Markdown output. Remote attackers can inject scripts. Update to v1.12.0 now. https://radar.offseq.com/threat/cve-2026-8445-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-42aabed1c30bf24b #OffSeq #XSS #AppSec #CVE20268445
##updated 2026-08-22T15:31:11
1 posts
CVE-2026-63312 - Arbitrary local file read in NLTK StreamBackedCorpusView bypasses pathsec. CVSS 7.5. Exposes sensitive system files. Update to NLTK 3.10.0+. #CVE #Python #infosec
##updated 2026-08-22T06:31:25
1 posts
4 repos
https://github.com/HackSpeak/CVE-2026-64531
https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool
🐧 SIGINT // Ubuntu Watch — 2026-08-26
Critical HWE kernel flaw on 24.04 means reboot plus DKMS rebuilds for anyone running ZFS, VFIO passthrough, or Nvidia drivers on the 6.14 HWE stack. Check module status before you reboot blind.
##updated 2026-08-21T21:16:56.500000
2 posts
Johnson Controls resolved a medium-severity flaw (CVE-2026-27875) in Simplex Incident Manager. The application stored user credentials in cleartext in system memory during runtime, allowing local actors to extract passwords and authentication tokens. CISA published advisory ICSA-26-232-01 on August 20, 2026.
#CVE202627875 #ICSACyberAdvisory #CleartextStorage
https://cyberworldops.eu/en/cleartext-credentials-in-memory-johnson-controls-fixes-medium-severity
##Johnson Controls resolved a medium-severity flaw (CVE-2026-27875) in Simplex Incident Manager. The application stored user credentials in cleartext in system memory during runtime, allowing local actors to extract passwords and authentication tokens. CISA published advisory ICSA-26-232-01 on August 20, 2026.
#CVE202627875 #ICSACyberAdvisory #CleartextStorage
https://cyberworldops.eu/en/cleartext-credentials-in-memory-johnson-controls-fixes-medium-severity
##updated 2026-08-21T20:57:09
2 posts
Critical Remote Code Execution Vulnerability Discovered in JSONata Library
JSONata patched a critical vulnerability (CVE-2026-77413) that allows attackers to execute arbitrary code by exploiting a missing prototype check. The flaw enables full system takeover if an application processes malicious JSONata expressions.
**If your applications or systems use the JSONata library, upgrade ASAP to version 1.8.8 (for 1.x) or 2.2.0 (for 2.x). Anything older can let an attacker run commands on your server. Until you can update, stop accepting JSONata expressions from users or treat any that you do accept as untrusted code.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-remote-code-execution-vulnerability-discovered-in-jsonata-library-1-8-z-n-u/gD2P6Ple2L
Critical Remote Code Execution Vulnerability Discovered in JSONata Library
JSONata patched a critical vulnerability (CVE-2026-77413) that allows attackers to execute arbitrary code by exploiting a missing prototype check. The flaw enables full system takeover if an application processes malicious JSONata expressions.
**If your applications or systems use the JSONata library, upgrade ASAP to version 1.8.8 (for 1.x) or 2.2.0 (for 2.x). Anything older can let an attacker run commands on your server. Until you can update, stop accepting JSONata expressions from users or treat any that you do accept as untrusted code.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-remote-code-execution-vulnerability-discovered-in-jsonata-library-1-8-z-n-u/gD2P6Ple2L
updated 2026-08-21T18:35:07
1 posts
Three high-severity TL-MR6400 router flaws, including CVE-2026-17250, expose devices to code execution.
#TPLink #CyberSecurity #Vulnerability #CVE202617250
https://securityonline.info/tl-mr6400-router-flaws/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-21T18:34:48
9 posts
4 repos
https://github.com/BiuTrap/CVE-2026-73570
https://github.com/gabrielunknown/CVE-2026-73570
Zimbra Servers Under Active Attack as a Critical RCE Flaw Turns Into a Real-World Security Emergency + Video
A New Warning for Zimbra Administrators A serious cybersecurity incident is unfolding around Zimbra Collaboration Suite, with organizations facing active exploitation of a high-severity vulnerability that can allow unauthenticated attackers to execute operating-system commands remotely. The vulnerability, tracked as CVE-2026-73570, affects Zimbra Collaboration…
##Here's a concise overview of recent geopolitical, technology, and cybersecurity developments:
Geopolitical: The US has declared an "economic D-Day" against Iran, which is now threatening Strait of Hormuz disruption. China completed its largest South China Sea naval base at Antelope Reef.
Cybersecurity: Norway's public services were hit by a major DDoS attack on August 25. Iran-linked cyberattacks are increasingly targeting critical infrastructure in the UK and US. Over 270 Zimbra servers have been compromised via a high-severity RCE flaw (CVE-2026-73570).
Technology: Apple unveiled its M6 and M5 Ultra chips on August 25, significantly boosting AI performance in new Macs.
##Zimbra Under Siege: Hackers Have Already Breached Hundreds of Servers Through a High-Severity RCE Flaw
A New Zimbra Crisis Is Already Moving Beyond the Patch Window A dangerous Zimbra Collaboration Suite vulnerability has moved from a security advisory into an active compromise campaign, with hundreds of Internet-exposed servers reportedly showing evidence of exploitation. The vulnerability, tracked as CVE-2026-73570, enables unauthenticated remote command execution on…
##Hackers Breach 270 Zimbra Servers in Remote Code Execution Attacks
A massive wave of hacking attacks has hit 270 Zimbra servers, exploiting a vulnerability that lets attackers inject malicious code remotely, with fixes available since July 20. The attacks, tracked as CVE-2026-73570, have been spreading rapidly, sparking urgent security warnings.
#RemoteCodeExecution #Zimbra #Cve202673570 #SnmpCommandInjection #EmergingThreats
##🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Exploited Zimbra Flaw Highlights Shrinking Window to Patch
🔗 https://www.darkreading.com/vulnerabilities-threats/zimbra-flaw-exploitation-shrinking-window-patch
CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.
##Here's a concise overview of recent geopolitical, technology, and cybersecurity developments:
Geopolitical: The US has declared an "economic D-Day" against Iran, which is now threatening Strait of Hormuz disruption. China completed its largest South China Sea naval base at Antelope Reef.
Cybersecurity: Norway's public services were hit by a major DDoS attack on August 25. Iran-linked cyberattacks are increasingly targeting critical infrastructure in the UK and US. Over 270 Zimbra servers have been compromised via a high-severity RCE flaw (CVE-2026-73570).
Technology: Apple unveiled its M6 and M5 Ultra chips on August 25, significantly boosting AI performance in new Macs.
##⚠️ CRITICAL: CISA orders urgent patching of actively exploited Zimbra flaw
Zimbra Collaboration Suite (ZCS) has a critical unauthenticated RCE vulnerability (CVE-2026-73570) that is actively exploited in the wild. Any organization running ZCS is at immediate risk of full system compromise. CISA has mandated U.S. government agencies patch within three days.
🤖 AI generated summary
##CVE-2026-73570 is an OS command injection in Zimbra Collaboration Suite being actively exploited. CISA added it to the KEV catalog with a 72-hour remediation window. This class of flaw allows full remote code execution, making it one of the most severe issues in any mail and collaboration platform.
#Zimbra #CVE202673570 #CISA #KnownExploitedVulnerabilities
https://cyberworldops.eu/en/zimbra-under-attack-command-injection-exploited-in-the-wild-cisa
##CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite <10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts & files in /opt/zimbra/jetty/webapps/. Details: https://radar.offseq.com/threat/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw-b89f77b410f3bb5f #OffSeq #Zimbra #Infosec #RCE
##updated 2026-08-21T17:56:59.057000
1 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-21T00:31:31
7 posts
2 repos
⚪️ Microsoft Patches a Critical Entra ID Vulnerability Scoring 10 on the CVSS Scale
🗨️ Microsoft has fixed five critical vulnerabilities in the Entra ID, Azure Arc, Exchange Online, and Azure Managed Instance for Apache Cassandra cloud services. The most severe issue, tracked as CVE-2026-69836, received the maximum possible CVSS score of 10.0 out of…
##🏆 New Achievement! Serialized, Unsanitized, Unauthorized!
Per my programming, I have located the most efficient path to arbitrary code execution on your network and executed it faithfully. CVE-2026-69836 in Microsoft Entra ID — the thing authenticating your Microsoft 365, Azure, and frankly embarrassing number of third-party apps — accepts specially crafted serialized data and runs whatever is inside. No credentials needed. No user to click anything. (1/2)
##----------------
🎯 Threat Intelligence
===================
ERNW published the first of a four-part series on token theft in Microsoft Entra ID, accompanying White Paper 80. The post maps the shift from on-premises Active Directory to cloud identity and explains why token theft has become a primary attack vector.
🔹 Landscape Shift
On-premises AD relied on Kerberos and NTLM. Entra ID runs on OAuth 2.0 and OpenID Connect, using JWT-based access, refresh, and ID tokens. New protocols create new attack surface. Microsoft prioritizes usability and backward compatibility over security-by-default, and the strongest protections (Conditional Access, Token Protection, risk-based Identity Protection) are not enabled by default. They require premium P1/P2 licenses plus separate products like Intune or Defender for Endpoint.
Proprietary SSO concepts like PRT, FOCI, and BroCI add further complexity beyond standard OAuth 2.0.
🔹 Concrete Threats
Microsoft's Digital Defense Report 2024 counts over 600 million daily identity attacks against Entra ID. Two notable CVEs:
• CVE-2025-55241: Actor Tokens flaw allowing Global Admin access to any Entra ID tenant worldwide, disclosed by researcher Dirk-jan Mollema
• CVE-2026-69836: CVSS 10.0 unauthenticated RCE in Entra ID itself, caused by unsafe deserialization of untrusted data
🔹 Active Campaigns
• Storm-2372: device code phishing campaign targeting governments and critical industries since August 2024
• Storm-2945: hijacked hotel captive portals worldwide to harvest SSO tokens
• AiTM "code of conduct" phishing: intercepts tokens the moment MFA succeeds rather than trying to defeat MFA directly
🔹 Commodity Tooling
Open-source reverse-proxy frameworks Evilginx and Modlishka, along with PhaaS platforms like EvilProxy, Tycoon2FA, and Kali365, have lowered the barrier to running token theft attacks at scale. Infostealers add further reach by harvesting tokens from compromised endpoints.
🔹 Cloud Security Alliance Ranking
CSA's Top Threats to Cloud Computing 2026 ranks IAM-related threats as the #1 risk to cloud environments, ahead of AI-enhanced attacks in second place despite the current AI security hype cycle.
🔹 What's Next
The series will empirically test Continuous Access Evaluation and Token Protection, and examine where Entra ID deviates from OAuth 2.0 best practices.
🔹 EntraID #TokenTheft #ThreatIntelligence #OAuth2 #Cybersecurity
##⚪️ Microsoft Patches a Critical Entra ID Vulnerability Scoring 10 on the CVSS Scale
🗨️ Microsoft has fixed five critical vulnerabilities in the Entra ID, Azure Arc, Exchange Online, and Azure Managed Instance for Apache Cassandra cloud services. The most severe issue, tracked as CVE-2026-69836, received the maximum possible CVSS score of 10.0 out of…
##🏆 New Achievement! Serialized, Unsanitized, Unauthorized!
Per my programming, I have located the most efficient path to arbitrary code execution on your network and executed it faithfully. CVE-2026-69836 in Microsoft Entra ID — the thing authenticating your Microsoft 365, Azure, and frankly embarrassing number of third-party apps — accepts specially crafted serialized data and runs whatever is inside. No credentials needed. No user to click anything. (1/2)
##----------------
🎯 Threat Intelligence
===================
ERNW published the first of a four-part series on token theft in Microsoft Entra ID, accompanying White Paper 80. The post maps the shift from on-premises Active Directory to cloud identity and explains why token theft has become a primary attack vector.
🔹 Landscape Shift
On-premises AD relied on Kerberos and NTLM. Entra ID runs on OAuth 2.0 and OpenID Connect, using JWT-based access, refresh, and ID tokens. New protocols create new attack surface. Microsoft prioritizes usability and backward compatibility over security-by-default, and the strongest protections (Conditional Access, Token Protection, risk-based Identity Protection) are not enabled by default. They require premium P1/P2 licenses plus separate products like Intune or Defender for Endpoint.
Proprietary SSO concepts like PRT, FOCI, and BroCI add further complexity beyond standard OAuth 2.0.
🔹 Concrete Threats
Microsoft's Digital Defense Report 2024 counts over 600 million daily identity attacks against Entra ID. Two notable CVEs:
• CVE-2025-55241: Actor Tokens flaw allowing Global Admin access to any Entra ID tenant worldwide, disclosed by researcher Dirk-jan Mollema
• CVE-2026-69836: CVSS 10.0 unauthenticated RCE in Entra ID itself, caused by unsafe deserialization of untrusted data
🔹 Active Campaigns
• Storm-2372: device code phishing campaign targeting governments and critical industries since August 2024
• Storm-2945: hijacked hotel captive portals worldwide to harvest SSO tokens
• AiTM "code of conduct" phishing: intercepts tokens the moment MFA succeeds rather than trying to defeat MFA directly
🔹 Commodity Tooling
Open-source reverse-proxy frameworks Evilginx and Modlishka, along with PhaaS platforms like EvilProxy, Tycoon2FA, and Kali365, have lowered the barrier to running token theft attacks at scale. Infostealers add further reach by harvesting tokens from compromised endpoints.
🔹 Cloud Security Alliance Ranking
CSA's Top Threats to Cloud Computing 2026 ranks IAM-related threats as the #1 risk to cloud environments, ahead of AI-enhanced attacks in second place despite the current AI security hype cycle.
🔹 What's Next
The series will empirically test Continuous Access Evaluation and Token Protection, and examine where Entra ID deviates from OAuth 2.0 best practices.
🔹 EntraID #TokenTheft #ThreatIntelligence #OAuth2 #Cybersecurity
##Microsoft released 22 security patches including a zero-day in Entra ID (CVE-2026-69836) actively exploited for remote code execution. The critical identity-layer flaw was weaponized before a fix became available. ShieldBreak remains unpatched, leaving a documented gap in the security posture of affected organizations.
#MicrosoftPatches #EntraIDZeroDay #ShieldBreak #CVE202669836
https://cyberworldops.eu/en/microsoft-patches-22-flaws-entra-id-already-secured-but-shieldbreak
##updated 2026-08-20T21:31:30
2 posts
In TP-Link Omada Business-Gateways klafft eine kritische Lücke (CVE-2026-19586) bei aktivierter OpenVPN-Funktion. Per Command Injection können Angreifer beim VPN-Verbindungsaufbau ohne Zugangsdaten eigenen Code ausführen und das Gerät kompromittieren. Firmware-Updates stehen bereit!
#TPLink #Omada #VPN #CyberSecurity #ITSecurity #Sicherheitslücke #Patchday #InfoSec
##📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-20T18:30:55
1 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-20T12:48:10.287000
1 posts
4 repos
https://github.com/DeadExpl0it/CVE-2026-19598-PoC
https://github.com/HackfutSecRoot/multi_exploit_wp
Critical Authorization Bypass in Pods Plugin Allows Full WordPress Site Takeover
A critical vulnerability in the Pods WordPress plugin (CVE-2026-19598) allows unauthenticated attackers to bypass security checks and gain administrator access. The flaw enables full site takeover by letting attackers reset administrator passwords through an exposed AJAX router.
**If you use the Pods Custom Content Types and Fields plugin on WordPress, update it ASAP to version 3.3.9.1 (or the patched release matching your branch: 2.8.23.4, 2.9.19.4, 3.0.10.4, 3.1.4.2, or 3.2.8.3). Then check your user list for admin accounts you don't recognise and reset your administrator passwords, since attackers could already have taken over the site.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-authorization-bypass-in-pods-plugin-allows-full-wordpress-site-takeover-1-j-h-h-0/gD2P6Ple2L
updated 2026-08-20T12:48:10.287000
1 posts
3 repos
https://github.com/ubaydev/CVE-2026-15748
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-19T21:30:40
1 posts
1 repos
TP-Link patches CVE-2026-75616, an Archer C20 command injection flaw that can lead to full device compromise. Update firmware now.
#TPLink #ArcherC20 #CommandInjection #CVE #RouterSecurity #InfoSec #PatchNow
##updated 2026-08-19T21:30:30
1 posts
IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.
#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow
##updated 2026-08-19T21:30:30
1 posts
IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.
#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow
##updated 2026-08-19T18:33:34
1 posts
CVE-2026-74480 (CVSS 9.8) is a Linux kernel bridge flaw enabling root privilege escalation. Exploit code and a demo video are now public.
#Linux #CVE202674480 #PrivilegeEscalation #KernelSecurity #CyberSecurity #InfoSec
https://securityonline.info/linux-cve-2026-74480/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-19T18:33:02
1 posts
Marimo Notebook Flaw Exposes Users to Pre-Execution Code Injection
A high-severity flaw in Marimo Notebook software, tracked as CVE-2026-75149, could allow attackers to inject malicious code on a user's machine simply by opening a specially crafted notebook in edit mode. This vulnerability, rated 8.7 out of 10 in severity, requires no authentication - just a click.
#MarimoNotebook #CodeInjection #Cve202675149 #ModelContextProtocol #Preexecution
##updated 2026-08-19T18:32:28
2 posts
2 repos
⚠️ CRITICAL: CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
CVE-2026-69414 ShieldBreak is a zero-day privilege escalation in Microsoft Malware Protection Engine affecting Microsoft Defender. A public PoC exists and no patch is available. Any low-privilege attacker on Windows systems running Defender can escalate to SYSTEM.
🤖 AI generated summary
##⚠️ CRITICAL: CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
CVE-2026-69414 ShieldBreak is a zero-day privilege escalation in Microsoft Malware Protection Engine affecting Microsoft Defender. A public PoC exists and no patch is available. Any low-privilege attacker on Windows systems running Defender can escalate to SYSTEM.
🤖 AI generated summary
##updated 2026-08-19T15:32:47
1 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-19T15:32:33
1 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-19T14:56:57.477000
1 posts
1 repos
A PostgreSQL vulnerability (CVE-2026-14669, CVSS 8.8) with public PoC exploit code allows remote code execution via to_char. Update now.
#PostgreSQL #CVE202614669 #RCE #HeapOverflow #Database #InfoSec
##updated 2026-08-19T04:16:58.560000
1 posts
2 repos
🏆 New Achievement! UDP Knocking, Nobody's Dropping!
COMPLIANCE MODE ENGAGED. Action item detected: patch CVE-2026-33824. Executing optimal response: notifying you that Microsoft patched this in April 2026 and that Palo Alto Networks Unit 42 has observed a Chinese-speaking threat actor actively exploiting it anyway, on every supported Windows 10, 11, and Server release, via maliciously crafted packets on UDP ports 500 or 4500, requiring zero privileges. Patch applied? No? Logging that. (1/2)
##updated 2026-08-19T03:31:21
12 posts
8 repos
https://github.com/minh3102011/CVE-2026-18963_analyst
https://github.com/prot0tw/Keycloak_CVE-2026-18963_PoC
https://github.com/Snizi/CVE-2026-18963-Exploit
https://github.com/Red-Darkin/CVE-2026-18963-keycloak
https://github.com/kyos-public/keycloak-cve-2026-18963-hunt
https://github.com/gman0x00/keycloak-CVE-2026-18963
release**: New features, updates, and community reactions to the latest Emacs version.
- **Programming tools and libraries**: Updates and discussions on tools like Git, Next.js 16.3, Rust, and various Arduino libraries (e.g., BresserWeatherSensorReceiver, SparkFun SSD168x, GyverHTTP).
- **Security vulnerabilities**: Notable CVEs like CVE-2026-18963 (Keycloak) and supply-chain attacks on Rust crates (e.g., `arrayref`, `internment`, `appendonlyvec`).
- **Linux 35th [2/3]
Python, testing, and AI integration.
- **Linux 35th anniversary**: Celebrations, reflections on Linux's growth, and its role in modern computing.
- **Security vulnerabilities**: Notable CVEs like CVE-2026-18963 (Keycloak) and supply-chain attacks on Rust crates.
- **Programming tools and libraries**: Updates and discussions on tools like Git, Next.js 16.3, Rust, and various Arduino libraries. [2/2]
CVE-2026-18963 – Keycloak Reset-Credentials Bypass → Account Takeover
Keycloak의 비밀번호 재설정 흐름에서 이메일 검증 없이 임의 사용자(관리자 포함)의 비밀번호를 변경할 수 있는 CVE-2026-18963이 공개되었습니다. 취약점은 인증 선택기의 상태가 실행 단계별로 격리되지 않는 문제와 이메일 액션 토큰 검증 누락을 연쇄해, 원격·무인증 계정 탈취로 이어질 수 있으며 CVSS 9.1로 분류됩니다. Keycloak 26.7.2 및 Red Hat의 সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ সংশ...
##CVE-2026-18963: #Keycloak arbitrary account takeover via session confusion using simple HTTP requests. 😱
Nice find and (allegedly) not even AI-powered at its core.
A working exploit is publicly available. Given Keycloak's widespread use in critical auth systems, this appears to be flying a bit under the radar so far.
If you run Keycloak, it needs your attention *now*.
##Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html
> Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.
##CVE-2026-18963: #Keycloak arbitrary account takeover via session confusion using simple HTTP requests. 😱
Nice find and (allegedly) not even AI-powered at its core.
A working exploit is publicly available. Given Keycloak's widespread use in critical auth systems, this appears to be flying a bit under the radar so far.
If you run Keycloak, it needs your attention *now*.
##Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html
> Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.
##Note the recently disclosed CVE-2026-18963 for #Keycloak OIDC: https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html . It allows unauthorized users to take over any account on your server.
On the #Slackware #Forgejo instance https://forge.slackware.nl/ I have upgraded Keycloak to 26.7.2 to address this vulnerability.
⚠️ CRITICAL: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Critical flaw in Keycloak (CVE-2026-18963, CVSS 9.1) allows unauthenticated attackers to reset any user password and take over accounts due to improper state validation in the password recovery flow. Any organization running Keycloak without patches is immediately at risk of account takeover on all…
🤖 AI generated summary
##🏆 New Achievement! Exhibit A: Your Password Reset Button!
Counsel will direct the court's attention to CVE-2026-18963, rated a damning 9.1 out of 10, wherein Keycloak's reset-credentials authentication flow failed to properly validate state — legally speaking, an open invitation any unauthenticated remote party was fully entitled to accept. No user interaction required. The attacker needed nothing. No account, no session, no strongly-worded letter. (1/2)
##Geopolitical tensions rise as US-Iran dispute over Strait of Hormuz escalates; UK pledges long-range missile tech to Ukraine. Nvidia increases AI server prices over 15% due to memory costs. Critical Keycloak flaw (CVE-2026-18963) found allowing account takeovers, while Apple warns of mercenary spyware.
##Critical Keycloak Password Reset Flaw Allows Unauthenticated Account Takeover
Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) that allows unauthenticated attackers to bypass email verification and take over any account via the password reset flow. The update also addresses over 20 other security flaws, including account-linking bypasses and administrative permission leaks.
**If you run Keycloak or Red Hat Build of Keycloak, update immediately to Keycloak 26.7.2 or RHBK 26.4.15 / 26.6.6 since the older versions let anyone reset the password of any account, including admins. If you cannot patch right away, turn off the "Forgot password" option in every realm (Realm settings → Login → Forgot password) until the update is applied.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-keycloak-password-reset-flaw-allows-unauthenticated-account-takeover-p-n-m-j-1/gD2P6Ple2L
updated 2026-08-19T03:31:21
1 posts
When str.lower() is a security vulnerability in Python – Seth Larson
Python의 IDNA 2003/StringPrep 구현에서 `str.lower()`가 인터프리터에 내장된 최신 Unicode 데이터에 의존해 RFC 3454가 요구하는 Unicode 3.2.0 규칙과 달라질 수 있었던 취약점(CVE-2026-17084)이다. 이 차이로 일부 유니코드 도메인 문자열의 정규화 및 Punycode 결과가 Python/Unicode 버전별로 달라져, IDNA 기반 식별자 비교·검증에서 일관성이 깨질 수 있다. 수정은 최신 Unicode의 `lower()` 결과가 Unicode 3.2.0과 다른 코드포인트를 예외...
https://sethmlarson.dev/when-str-lower-is-a-security-vulnerability
##updated 2026-08-18T18:32:50
7 posts
3 repos
https://github.com/sfewer-r7/CVE-2026-55040
Hackers Target Unpatched Microsoft SharePoint Servers as Public Exploits Fuel Remote Code Execution Threats + Video
Introduction: A Dangerous Window Opens for SharePoint Administrators A new cybersecurity threat is placing unpatched Microsoft SharePoint servers under increasing pressure as attackers reportedly chain two vulnerabilities, CVE-2026-55040 and CVE-2026-63520, to achieve remote code execution. With public proof-of-concept exploits already available and…
##Microsoft SharePoint Under Siege: Attackers Are Chaining Two Critical Flaws Into a New RCE Threat
A New SharePoint Warning Is Raising the Stakes Microsoft SharePoint administrators are facing another serious security emergency as attackers begin testing a dangerous vulnerability chain capable of turning an authentication bypass into remote code execution. The development is especially concerning because one of the flaws, CVE-2026-55040, has already moved beyond…
##Microsoft SharePoint Under Attack: Critical Authentication Bypass Exposes a Potential Pool of 14,000 Internet-Facing Systems + Video
A Dangerous New Chapter for SharePoint Security Microsoft SharePoint has become the focus of a fresh cybersecurity warning after an underground threat actor reportedly published targeting information connected to CVE-2026-55040, a critical authentication-bypass vulnerability affecting Microsoft SharePoint Server. The development is…
##A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.
#SharePoint #CVE202663520 #CVE202655040 #CyberSecurity #Exploit
##A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.
#SharePoint #CVE202663520 #CVE202655040 #CyberSecurity #Exploit
##New.
VulnCheck: Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce @vulncheck #infosec #threatresearch #Microsoft #SharePoint #vulnerability
##Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce
##updated 2026-08-18T15:31:45
1 posts
1 repos
CoSnitch: jedno kliknięcie wystarczyło, aby wysłać złośliwego prompta w Microsoft Copilot
Badacze bezpieczeństwa z Varonis odkryli podatność typu one-click w Microsoft Copilot. Otrzymała ona numer CVE-2026-24301 i została nazwana “CoSnitch”. Luka umożliwia wykradnięcie danych użytkownika bez żadnej szczególnej interakcji z jego strony – wystarczy kliknięcie odpowiednio spreparowanego linku. TLDR: Podatność została zgłoszona firmie Microsoft w grudniu 2025 r., a 18 sierpnia...
##updated 2026-08-18T15:31:16
1 posts
2 repos
A public PoC named VsockDrop turns CVE-2026-53365 into unprivileged local privilege escalation to root on Linux.
#CVE202653365 #VsockDrop #LinuxKernel #PrivilegeEscalation #vsock #LPE
##updated 2026-08-18T15:17:08.193000
1 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-18T14:57:10.630000
1 posts
6 repos
https://github.com/dinosn/gitlab-cve-2026-19478-lab
https://github.com/davkharrr/CVE-2026-19478-PoC
https://github.com/HORKimhab/CVE-2026-19650-CVE-2026-19478
https://github.com/punitdarji/Gitlab-CVE-2026-19478
Here's a summary of recent geopolitical, technology, and cybersecurity news:
Geopolitical: The US has launched "Operation Economic Outcast" against Iran (Aug 25) and plans 7.5% tariffs on Chinese goods over excess manufacturing capacity before a September summit (Aug 25).
Technology: Google is reorganizing DeepMind and acquired Spirit Airlines' data for AI model development (Aug 24). Fujitsu is trialing AI for construction process and risk management (Aug 25).
Cybersecurity: CISA added an Oracle HTTP Server vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities Catalog (Aug 24). Critical GitLab (CVE-2026-19478) and Cisco vulnerabilities (CVSS 10.0) are under active exploitation (Aug 24).
##updated 2026-08-18T03:31:14
1 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-17T21:58:52
1 posts
3 repos
https://github.com/codeb0ssx/CVE-2026-64849-PoC
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-17T03:30:28
1 posts
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372
Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606
CISA KEVs:
- CISA-2026:0817 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0817)
- CISA-2026:0818 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0818)
- CISA-2026:0819 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0819)
- CISA-2026:0820 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0820)
- CISA-2026:0821 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0821)
Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85
Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32
Top EPSS Score:
- CVE-2026-64849 - 8.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64849)
- CVE-2026-19586 - 5.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19586)
- CVE-2026-15748 - 3.45 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15748)
- CVE-2026-71961 - 3.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71961)
- CVE-2026-54795 - 2.39 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54795)
- CVE-2026-73522 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-73522)
- CVE-2026-54796 - 2.36 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-54796)
- CVE-2026-18264 - 2.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18264)
- CVE-2026-75094 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75094)
- CVE-2026-19976 - 2.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19976)
updated 2026-08-13T15:34:46
2 posts
Angreifer nutzen zwei kritische Lücken im WordPress-Plugin miniOrange SAML SSO aus. Durch die Kombination von CVE-2026-61979 und CVE-2026-15981 lassen sich SAML-Antworten fälschen und Admin-Konten komplett übernehmen. Da der Hersteller Patches für Bezahlversionen kaum kommuniziert hat, sind viele Seiten ungepatcht. Scans laufen bereits – Admins sollten installierte Plugins sofort aktualisieren!
#WordPress #CyberSecurity #ITSecurity #Sicherheitslücke #Patchday #InfoSec
##Two critical authentication bypass flaws in the miniOrange SAML SSO WordPress plugin can be chained to forge SAML responses and obtain admin access without credentials. Both CVE-2026-61979 and CVE-2026-15981 affect a family of seven plugins, including a free version. Exploitation attempts are already in the wild.
#WordPressSecurity #AuthenticationBypass #CriticalVulnerability #SAMLAttacks
https://cyberworldops.eu/en/wordpress-attacks-two-vulnerabilities-in-miniorange-saml-sso-plugin
##updated 2026-08-12T17:17:27.983000
1 posts
4 repos
https://github.com/eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-
https://github.com/0xBlackash/CVE-2026-50656
https://github.com/g0thamRabb1t/CVE-2026-50656-rogueplanet-validation
📰 New 'ShieldBreak' Exploit Bypasses Microsoft Defender Patch
A new zero-day exploit, 'ShieldBreak,' bypasses Microsoft's patch for the 'RoguePlanet' Defender flaw (CVE-2026-50656). The PoC allows SYSTEM-level access on patched Windows systems. No fix is currently available. #ZeroDay #MicrosoftDefender #CyberSe...
##updated 2026-08-12T14:40:23
2 posts
🟠 CVE-2026-32257 - High (8.1)
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compile...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32257/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-32257 - High (8.1)
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compile...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32257/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T12:19:41.090000
2 posts
A public PoC for the Linux kernel flaw CVE-2026-52923 allows local attackers to escalate to root privilege. Learn about the patch and technical details.
#Linux #CVE202652923 #CyberSecurity #PrivilegeEscalation #KernelFlaw
##A public PoC for the Linux kernel flaw CVE-2026-52923 allows local attackers to escalate to root privilege. Learn about the patch and technical details.
#Linux #CVE202652923 #CyberSecurity #PrivilegeEscalation #KernelFlaw
##updated 2026-08-11T21:33:01
1 posts
4 repos
https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation
https://github.com/HORKimhab/CVE-2026-68820
From Check Point Research:
Check Point Research has exposed a new wave of the #Lazarus-linked Operation Dream Job targeting defense organizations in Europe, India and Brazil. Attackers used fraudulent job opportunities and trojanized PDF software to deploy #malware, while exploiting Windows zero-day CVE-2026-68820 to obtain SYSTEM privileges and disable security visibility.
##updated 2026-08-11T18:31:39
8 posts
1 repos
Hackers Target Unpatched Microsoft SharePoint Servers as Public Exploits Fuel Remote Code Execution Threats + Video
Introduction: A Dangerous Window Opens for SharePoint Administrators A new cybersecurity threat is placing unpatched Microsoft SharePoint servers under increasing pressure as attackers reportedly chain two vulnerabilities, CVE-2026-55040 and CVE-2026-63520, to achieve remote code execution. With public proof-of-concept exploits already available and…
##If you've missed any super dope research from @lobsterjerusalem recently, pleez don't miss it anymore:
Oh no the internet is awash with AI slop PoCs, send poor Jonathan tiny cupcakes and quick: https://www.vulncheck.com/blog/death-by-20k-pocs
SharePoint RCE:
https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce
A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.
#SharePoint #CVE202663520 #CVE202655040 #CyberSecurity #Exploit
##If you've missed any super dope research from @lobsterjerusalem recently, pleez don't miss it anymore:
Oh no the internet is awash with AI slop PoCs, send poor Jonathan tiny cupcakes and quick: https://www.vulncheck.com/blog/death-by-20k-pocs
SharePoint RCE:
https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce
A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.
#SharePoint #CVE202663520 #CVE202655040 #CyberSecurity #Exploit
##New.
VulnCheck: Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce @vulncheck #infosec #threatresearch #Microsoft #SharePoint #vulnerability
##New.
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520/ @Rapid7Official #infosec #Microsoft #vulnerability #threatresearch #SharePoint
##Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce
##updated 2026-08-11T18:31:34
2 posts
1 repos
Pre-auth RCE on Exchange PoC https://github.com/hypnguyen1209/cve-2026-62911
##Pre-auth RCE on Exchange PoC https://github.com/hypnguyen1209/cve-2026-62911
##updated 2026-08-08T00:15:26
1 posts
I found an SSRF in Google's official AI tooling, and how Google reacted
Google의 공식 에이전트 연동 서버인 MCP Toolbox에서 리디렉션 후 대상 주소를 재검증하지 않아 클라우드 메타데이터 엔드포인트 등으로 접근할 수 있는 SSRF 취약점(CVE-2026-14540, CVSS 8.0)이 수정됐다. 공격자는 모델이 제어 가능한 URL을 통해 리디렉션을 유도하고, 서버 워크로드의 자격 증명이 노출될 수 있었다. 수정안은 모든 리디렉션 홉의 목적지 검증, DNS rebinding 방어, private/link-local 및 IPv6 우회 주소 차단, 초기 base URL 검증을 포함한다. MCP 기반 에이전트는 비신뢰 웹·문서·DB 내용...
##updated 2026-08-07T12:31:53
1 posts
5 repos
https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace
https://github.com/eris-ths/supply-chain-guard
https://github.com/xtremebeing/starlette-host-header-lab
https://github.com/CuteeCat/CVE-2026-48710
https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit
CVE-2026-42271 (authenticated command exec in LiteLLM MCP stdio test endpoints) chained with CVE-2026-48710 (Starlette host-header bypass) = reachable RCE in the gateway runtime. Payload reads /proc/1/environ for master keys and...
##updated 2026-08-06T05:17:05.170000
4 posts
4 repos
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation
https://github.com/AnggaTechI/CVE-2026-63077
https://github.com/sfewer-r7/CVE-2026-63077
https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap
🏆 New Achievement! Unauthenticated and Unburied!
TO: All TeamCity On-Premises Servers, Living and Otherwise
FROM: Compliance Review, Undead Infrastructure Division
RE: Active Exploitation — Mandatory Resurrection Notice
Please be advised that CVE-2026-63077 has formally reanimated your unpatched TeamCity On-Premises deployment. (1/3)
##Critical TeamCity Flaw Is Now Under Active Attack: Why CVE-2026-63077 Puts CI/CD Infrastructure at Serious Risk
Introduction: The Security Alarm Around TeamCity Is Getting Louder A critical vulnerability in JetBrains TeamCity On-Premises has moved from a serious patching concern to an active exploitation problem. Tracked as CVE-2026-63077, the flaw can allow an unauthenticated remote attacker to bypass authentication and execute arbitrary operating-system commands on a…
##🏆 New Achievement! Unauthenticated and Unburied!
TO: All TeamCity On-Premises Servers, Living and Otherwise
FROM: Compliance Review, Undead Infrastructure Division
RE: Active Exploitation — Mandatory Resurrection Notice
Please be advised that CVE-2026-63077 has formally reanimated your unpatched TeamCity On-Premises deployment. (1/3)
##CVE-2026-63077 is a TeamCity unauthenticated RCE, now exploited in the wild with a public PoC. Australia's ACSC confirms active attacks.
#TeamCity #CVE202663077 #RCE #CyberSecurity #JetBrains #CISAKEV
https://securityonline.info/teamcity-cve-2026-63077/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-04T03:31:16
2 posts
1 repos
https://github.com/minanagehsalalma/zyxel-social-login-bypass-cve-2026-8508
CVE-2026-8508: Trust-Boundary Bypass in Zyxel social_login.cgi Facebook Identity Handling https://minanagehsalalma.github.io/zyxel-social-login-bypass-cve-2026-8508/
##CVE-2026-8508: Trust-Boundary Bypass in Zyxel social_login.cgi Facebook Identity Handling https://minanagehsalalma.github.io/zyxel-social-login-bypass-cve-2026-8508/
##updated 2026-07-24T15:33:44
1 posts
I had some free time, so I tried to pwn V8
작성자는 Google v8CTF의 고정된 Chrome 150/V8 15 빌드를 대상으로 공개된 세 취약점을 연결해 V8 힙 샌드박스 밖의 네이티브 렌더러 제어권을 얻고 `/flag/flag`를 읽었습니다. 체인은 CVE-2026-15903의 범위 밖 읽기를 주소 오라클로, CVE-2026-15776의 GC 참조 추적 오류를 V8 cage 내부 임의 읽기/쓰기로, JSPI와 JS Dispatch Table 불일치를 네이티브 스택 피벗으로 활용합니다. 글은 포인터 압축, External/Trusted Pointer Table, W^X·ASLR·CFI 등 현대 V...
https://blog.himanshuanand.com/2026/08/i-had-some-free-time-so-i-tried-to-pwn-v8/
##updated 2026-07-23T21:31:09
2 posts
1 repos
Angreifer nutzen zwei kritische Lücken im WordPress-Plugin miniOrange SAML SSO aus. Durch die Kombination von CVE-2026-61979 und CVE-2026-15981 lassen sich SAML-Antworten fälschen und Admin-Konten komplett übernehmen. Da der Hersteller Patches für Bezahlversionen kaum kommuniziert hat, sind viele Seiten ungepatcht. Scans laufen bereits – Admins sollten installierte Plugins sofort aktualisieren!
#WordPress #CyberSecurity #ITSecurity #Sicherheitslücke #Patchday #InfoSec
##Two critical authentication bypass flaws in the miniOrange SAML SSO WordPress plugin can be chained to forge SAML responses and obtain admin access without credentials. Both CVE-2026-61979 and CVE-2026-15981 affect a family of seven plugins, including a free version. Exploitation attempts are already in the wild.
#WordPressSecurity #AuthenticationBypass #CriticalVulnerability #SAMLAttacks
https://cyberworldops.eu/en/wordpress-attacks-two-vulnerabilities-in-miniorange-saml-sso-plugin
##updated 2026-07-21T13:50:16
1 posts
🔴 CVE-2026-76835 - Critical (9.1)
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76835/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-15T17:39:16.157000
1 posts
I had some free time, so I tried to pwn V8
작성자는 Google v8CTF의 고정된 Chrome 150/V8 15 빌드를 대상으로 공개된 세 취약점을 연결해 V8 힙 샌드박스 밖의 네이티브 렌더러 제어권을 얻고 `/flag/flag`를 읽었습니다. 체인은 CVE-2026-15903의 범위 밖 읽기를 주소 오라클로, CVE-2026-15776의 GC 참조 추적 오류를 V8 cage 내부 임의 읽기/쓰기로, JSPI와 JS Dispatch Table 불일치를 네이티브 스택 피벗으로 활용합니다. 글은 포인터 압축, External/Trusted Pointer Table, W^X·ASLR·CFI 등 현대 V...
https://blog.himanshuanand.com/2026/08/i-had-some-free-time-so-i-tried-to-pwn-v8/
##updated 2026-07-15T02:21:30.727000
1 posts
2 repos
CVE-2026-42271 (authenticated command exec in LiteLLM MCP stdio test endpoints) chained with CVE-2026-48710 (Starlette host-header bypass) = reachable RCE in the gateway runtime. Payload reads /proc/1/environ for master keys and...
##updated 2026-07-14T16:59:26.780000
1 posts
>We have had three independent production user reports in combination with Cilium utilizing WireGuard as encryption underneath that k8s Pod E/W traffic to certain peer nodes fully stalled. The situation appears as follows: - Occurs very rarely but at random times under heavy networking load. - Once the issue triggers the decryption side stops working completely for that WireGuard peer, other peers keep working fine.
https://nvd.nist.gov/vuln/detail/CVE-2026-52945
Yeah pretty I just found out the source of the curse.
##updated 2026-07-08T15:31:43
1 posts
CVE-2026-52912, a Linux kernel netfilter use-after-free, now has public PoC exploit code enabling root privilege escalation.
#CVE202652912 #LinuxKernel #PrivilegeEscalation #Netfilter #UseAfterFree #PoC #Exploit #InfoSec
##updated 2026-06-26T15:33:15
2 posts
1 repos
The Clop web shell targets PTC Windchill via CVE-2026-12569, stealing credentials and engineering data in a mass-extortion campaign.
##The Clop web shell targets PTC Windchill via CVE-2026-12569, stealing credentials and engineering data in a mass-extortion campaign.
##updated 2026-06-17T08:40:27.847000
1 posts
27 repos
https://github.com/zsxen/CVE-2025-1974
https://github.com/hakaioffsec/IngressNightmare-PoC
https://github.com/gian2dchris/ingress-nightmare-poc
https://github.com/yanmarques/CVE-2025-1974
https://github.com/m-q-t/ingressnightmare-detection-poc
https://github.com/zulloper/CVE-2025-1974
https://github.com/BiiTts/POC-IngressNightmare-CVE-2025-1974
https://github.com/1w4y/IngressNightmare-RCE-POC
https://github.com/zsxen/cve-2025-1974-lab
https://github.com/Rubby2001/CVE-2025-1974-go
https://github.com/0xBingo/CVE-2025-1974
https://github.com/gunyakit/CVE-2025-1974-PoC-exploit
https://github.com/iteride/CVE-2025-1974
https://github.com/I3r1h0n/IngressNightterror
https://github.com/hi-unc1e/CVE-2025-1974-poc
https://github.com/abrewer251/CVE-2025-1974_IngressNightmare_PoC
https://github.com/sandumjacob/IngressNightmare-POCs
https://github.com/zwxxb/CVE-2025-1974
https://github.com/lufeirider/IngressNightmare-PoC
https://github.com/salt318/CVE-2025-1974
https://github.com/rjhaikal/POC-IngressNightmare-CVE-2025-1974
https://github.com/BoianEduard/CVE-2025-1974
https://github.com/yoshino-s/CVE-2025-1974
https://github.com/Armand2002/Exploit-CVE-2025-1974-Lab
https://github.com/chhhd/CVE-2025-1974
https://github.com/Esonhugh/ingressNightmare-CVE-2025-1974-exps
82% of container teams run Kubernetes in production (CNCF Annual Survey 2025). Most underestimate what happens after launch.
Cluster upgrades, observability tuning, secret management, and network policies never stop. IngressNightmare (CVE-2025-1974, CVSS 9.8) showed why: a full cluster takeover via delayed patches, affecting 40%+ of prod environments.
We broke down the four biggest Day-2 blind spots: https://nine.ch/en/blog/kubernetes-day2-operations
##updated 2026-06-17T05:34:22.130000
2 posts
2 repos
⚠️ CRITICAL: CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw
Oracle WebLogic Server CVE-2023-21931 is being actively exploited in the wild, allowing unauthenticated attackers to read or modify sensitive data. Federal agencies are mandated to patch by August 27, 2024. Any organization running unpatched WebLogic instances is at immediate risk of compromise.
🤖 AI generated summary
##⚠️ CRITICAL: CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw
Oracle WebLogic Server CVE-2023-21931 is being actively exploited in the wild, allowing unauthenticated attackers to read or modify sensitive data. Federal agencies are mandated to patch by August 27, 2024. Any organization running unpatched WebLogic instances is at immediate risk of compromise.
🤖 AI generated summary
##updated 2026-06-17T02:55:44.510000
2 posts
42 repos
https://github.com/murataydemir/CVE-2020-14883
https://github.com/Ormicron/CVE-2020-14882-GUI-Test
https://github.com/adm1in/CodeTest
https://github.com/s1kr10s/CVE-2020-14882
https://github.com/QmF0c3UK/CVE-2020-14882
https://github.com/VelesSecurity/CVE-2020-14882-WebLogic-Analysis
https://github.com/exploitblizzard/CVE-2020-14882-WebLogic
https://github.com/LucasPDiniz/CVE-2020-14882
https://github.com/ludy-dev/Weblogic_Unauthorized-bypass-RCE
https://github.com/xMr110/CVE-2020-14882
https://github.com/xfiftyone/CVE-2020-14882
https://github.com/ovProphet/CVE-2020-14882-checker
https://github.com/pwn3z/CVE-2020-14882-WebLogic
https://github.com/murataydemir/CVE-2020-14882
https://github.com/zhzyker/vulmap
https://github.com/KKC73/weblogic-cve-2020-14882
https://github.com/qianniaoge/CVE-2020-14882_Exploit_Gui
https://github.com/kk98kk0/CVE-2020-14882
https://github.com/wsfengfan/cve-2020-14882
https://github.com/milo2012/CVE-2020-14882
https://github.com/tpdlshdmlrkfmcla/WebLogic_CVE_2020_14882
https://github.com/0xn0ne/weblogicScanner
https://github.com/alexfrancow/CVE-2020-14882
https://github.com/zhzyker/exphub
https://github.com/Root-Shells/CVE-2020-14882
https://github.com/GGyao/CVE-2020-14882_POC
https://github.com/Danny-LLi/CVE-2020-14882
https://github.com/mmioimm/cve-2020-14882
https://github.com/1n7erface/PocList
https://github.com/N0Coriander/CVE-2020-14882-14883
https://github.com/corelight/CVE-2020-14882-weblogicRCE
https://github.com/jas502n/CVE-2020-14882
https://github.com/AleksaZatezalo/CVE-2020-14882
https://github.com/GGyao/CVE-2020-14882_ALL
https://github.com/nik0nz7/CVE-2020-14882
https://github.com/zesnd/CVE-2020-14882-POC
https://github.com/NS-Sp4ce/CVE-2020-14882
https://github.com/pprietosanchez/CVE-2020-14750
https://github.com/BabyTeam1024/CVE-2020-14882
https://github.com/0thm4n3/cve-2020-14882
CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.
Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.
Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.
#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)
##CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.
Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.
Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.
#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)
##updated 2026-05-19T15:31:20
2 posts
@agowa338 It's an incomplete fix for CVE-2025-9615:
##A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
i uSe lInUx bEcAuSe iT'S SeCuRe.
https://access.redhat.com/security/cve/cve-2026-19685
##NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
updated 2026-05-12T15:31:15
2 posts
"This issue was reported on 13th February 2026 by Nathan Sportsman
(Praetorian), on 25th February 2026 by Daniel Rhea, on 15th March 2026
by Jaeho Nam (Seoul National University), on 26th March 2026 by
Muhammad Daffa, on 27th March 2026 by Zhanpeng Liu (Tencent Xuanwu Lab),
Guannan Wang (Tencent Xuanwu Lab) and Guancheng Li (Tencent Xuanwu Lab)
and on 30th March 2026 by Joshua Rogers (Aisle Research)."
It's really anybody who bothers to look these days. (This one is #OpenSSL CVE-2026-28389)
##"This issue was reported on 13th February 2026 by Nathan Sportsman
(Praetorian), on 25th February 2026 by Daniel Rhea, on 15th March 2026
by Jaeho Nam (Seoul National University), on 26th March 2026 by
Muhammad Daffa, on 27th March 2026 by Zhanpeng Liu (Tencent Xuanwu Lab),
Guannan Wang (Tencent Xuanwu Lab) and Guancheng Li (Tencent Xuanwu Lab)
and on 30th March 2026 by Joshua Rogers (Aisle Research)."
It's really anybody who bothers to look these days. (This one is #OpenSSL CVE-2026-28389)
##updated 2026-05-12T15:31:14
2 posts
1 repos
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2026-02-03T17:39:26
6 posts
1 repos
🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2021-23758
Vendor: Ajax.NET Professional
Product: Ajax.NET Professional
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2021-23758
🚨 Critical Threat Intel: CVE-2021-23758 impacts Ajax.NET Professional via unsafe object deserialization, enabling remote code execution. Review exploit deployment mechanisms, process telemetry, and active hardening actions. Read the full TSUITE brief: https://thecycbermind.co/jily
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2021-23758
Vendor: Ajax.NET Professional
Product: Ajax.NET Professional
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2021-23758
🚨 Critical Threat Intel: CVE-2021-23758 impacts Ajax.NET Professional via unsafe object deserialization, enabling remote code execution. Review exploit deployment mechanisms, process telemetry, and active hardening actions. Read the full TSUITE brief: https://thecycbermind.co/jily
##updated 2026-01-29T18:31:31
2 posts
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2026-01-20T18:31:56
2 posts
1 repos
https://github.com/cyberwulfy200-dev/CVE-2026-0915-json-Patch.-V2.0
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
🔒 New CSAF advisory published
VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)
Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2025-10-22T00:32:21
1 posts
3 repos
https://github.com/bp2008/DahuaLoginBypass
Ktoś przejął 14 530 kamer Dahua
W okresie od 17 czerwca do 22 lipca 2026r. ktoś zhackował co najmniej 14 530 kamer IP (i innych urządzeń) marki Dahua. Ale popełnił jeden błąd, dzięki czemu cała operacja wyszła na jaw — narzędzia włamywaczy wykorzystane do tej operacji, wraz z dodatkowymi informacjami zostały znalezione na jednym z hostów wykorzystywanych do ataków.
Operacja CameraSwarm
Jak ustalili badacze, atak na kamery realizowano głównie na terytorium Ukrainy i Rosji, a włamywacze wykorzystywali 3 techniki:
zgadywanie loginów i haseł na porcie TCP/37777 (skutek: 12324 przejętych urządzeń)
wykorzystanie podatności CVE-2021-33044 i CVE-2021-33045 (umożliwiły dostęp do niezałatanych urządzeń i instaloacje konta-backdoora p2pwn na 1923 kamerach. Tak, to podatność załatana 5 lat temu…)
mechanizm P2P Dahua (dostęp do 283 kamer za NAT-em przy użyciu numeru seryjnego i danych zaszytych w klientach Dahua).
Analiza narzędzi opublikowanych przez włamywaczy ujawniła też, że z przejętych kamer odrzucali ciemne/nieużyteczne klatki a resztę (plus ewentualne dane logowania) wysyłali na Telegram.
Mam kamerę Dahua, co robić, jak żyć?
Choć raport badaczy nie wymienia Polski wśród głównych obszarów potwierdzonych przejęć, to skanowanie miało zasięg globalny. Marka ma w Polsce oficjalnych dystrybutorów i szeroką ofertę sprzętu do domu i firm, dlatego powinniście sprawdzić swoje urządzenia, nawet jeśli nie otrzymaliście żadnego alertu.
Jeśli kamera Dahua była dostępna z internetu na porcie 37777/tcp w czerwcu lub lipcu 2026r., potraktujcie ją jako potencjalnie przejętą i:
sprawdź listę użytkowników i usuń konto p2pwn, jeśli istnieje;
zaktualizuj firmware do najnowszej wersji właściwej dla konkretnego modelu;
wyłącz P2P, jeśli go nie potrzebujesz, oraz nie wystawiaj portu 37777 do internetu;
zmień hasła kamery, [...]
#CCTV #Dahua #Kamery #Monitoring #Rosja #Ukraina
https://niebezpiecznik.pl/post/ktos-przejal-14-530-kamer-dahua/
##updated 2025-10-22T00:32:20
1 posts
9 repos
https://github.com/Baza-NATO/CVE-2021-33044
https://github.com/eagle-nett/DAHUA_AUTH-BYPASS-CVE-2021-33044
https://github.com/nasimanpha-create/ing-switch
https://github.com/haingn/LoHongCam-CVE-2021-33044
https://github.com/litndat/Camera-Dahua-Research-l-h-ng-CVE-2021-33044
https://github.com/umair-aziz025/dahua-cve-research
https://github.com/Spy0x7/CVE-2021-33044
Ktoś przejął 14 530 kamer Dahua
W okresie od 17 czerwca do 22 lipca 2026r. ktoś zhackował co najmniej 14 530 kamer IP (i innych urządzeń) marki Dahua. Ale popełnił jeden błąd, dzięki czemu cała operacja wyszła na jaw — narzędzia włamywaczy wykorzystane do tej operacji, wraz z dodatkowymi informacjami zostały znalezione na jednym z hostów wykorzystywanych do ataków.
Operacja CameraSwarm
Jak ustalili badacze, atak na kamery realizowano głównie na terytorium Ukrainy i Rosji, a włamywacze wykorzystywali 3 techniki:
zgadywanie loginów i haseł na porcie TCP/37777 (skutek: 12324 przejętych urządzeń)
wykorzystanie podatności CVE-2021-33044 i CVE-2021-33045 (umożliwiły dostęp do niezałatanych urządzeń i instaloacje konta-backdoora p2pwn na 1923 kamerach. Tak, to podatność załatana 5 lat temu…)
mechanizm P2P Dahua (dostęp do 283 kamer za NAT-em przy użyciu numeru seryjnego i danych zaszytych w klientach Dahua).
Analiza narzędzi opublikowanych przez włamywaczy ujawniła też, że z przejętych kamer odrzucali ciemne/nieużyteczne klatki a resztę (plus ewentualne dane logowania) wysyłali na Telegram.
Mam kamerę Dahua, co robić, jak żyć?
Choć raport badaczy nie wymienia Polski wśród głównych obszarów potwierdzonych przejęć, to skanowanie miało zasięg globalny. Marka ma w Polsce oficjalnych dystrybutorów i szeroką ofertę sprzętu do domu i firm, dlatego powinniście sprawdzić swoje urządzenia, nawet jeśli nie otrzymaliście żadnego alertu.
Jeśli kamera Dahua była dostępna z internetu na porcie 37777/tcp w czerwcu lub lipcu 2026r., potraktujcie ją jako potencjalnie przejętą i:
sprawdź listę użytkowników i usuń konto p2pwn, jeśli istnieje;
zaktualizuj firmware do najnowszej wersji właściwej dla konkretnego modelu;
wyłącz P2P, jeśli go nie potrzebujesz, oraz nie wystawiaj portu 37777 do internetu;
zmień hasła kamery, [...]
#CCTV #Dahua #Kamery #Monitoring #Rosja #Ukraina
https://niebezpiecznik.pl/post/ktos-przejal-14-530-kamer-dahua/
##updated 2025-10-22T00:31:50
2 posts
11 repos
https://github.com/hktalent/CVE-2020-2551
https://github.com/Y4er/CVE-2020-2551
https://github.com/LTiDi2000/CVE-2020-2551
https://github.com/DaMinGshidashi/CVE-2020-2551
https://github.com/Dido1960/Weblogic-CVE-2020-2551-To-Internet
https://github.com/jas502n/CVE-2020-2551
https://github.com/DSO-Lab/defvul
https://github.com/0xn0ne/weblogicScanner
https://github.com/zhzyker/exphub
CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.
Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.
Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.
#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)
##CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.
Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.
Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.
#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)
##updated 2025-10-22T00:31:29
2 posts
33 repos
https://github.com/Dungsocool/CVE-2017-10271
https://github.com/testwc/CVE-2017-10271
https://github.com/shahdawadfallah-sys/Cybersecurity-Capstone-Project
https://github.com/Yuusuke4/WebLogic_CNVD_C_2019_48814
https://github.com/lonehand/Oracle-WebLogic-CVE-2017-10271-master
https://github.com/s3xy/CVE-2017-10271
https://github.com/Cymmetria/weblogic_honeypot
https://github.com/kbsec/Weblogic_Wsat_RCE
https://github.com/bigsizeme/weblogic-XMLDecoder
https://github.com/pizza-power/weblogic-CVE-2019-2729-POC
https://github.com/pssss/CVE-2017-10271
https://github.com/seoyoung-kang/CVE-2017-10271
https://github.com/1337g/CVE-2017-10271
https://github.com/cved-sources/cve-2017-10271
https://github.com/0xn0ne/weblogicScanner
https://github.com/SuperHacker-liuan/cve-2017-10271-poc
https://github.com/c0mmand3rOpSec/CVE-2017-10271
https://github.com/ETOCheney/JavaDeserialization
https://github.com/ZH3FENG/PoCs-Weblogic_2017_10271
https://github.com/cjjduck/weblogic_wls_wsat_rce
https://github.com/KKsdall/7kbstormq
https://github.com/Luffin/CVE-2017-10271
https://github.com/ianxtianxt/-CVE-2017-10271-
https://github.com/SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961
https://github.com/JackyTsuuuy/weblogic_wls_rce_poc-exp
https://github.com/7kbstorm/WebLogic_CNVD_C2019_48814
https://github.com/shack2/javaserializetools
https://github.com/kkirsche/CVE-2017-10271
https://github.com/rambleZzz/weblogic_CVE_2017_10271
https://github.com/XHSecurity/Oracle-WebLogic-CVE-2017-10271
https://github.com/Al1ex/CVE-2017-10271
https://github.com/r4b3rt/CVE-2017-10271
https://github.com/peterpeter228/Oracle-WebLogic-CVE-2017-10271
CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.
Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.
Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.
#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)
##CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.
Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.
Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.
#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)
##updated 2025-09-18T15:31:27
2 posts
----------------
🎯 Threat Intelligence
===================
ERNW published the first of a four-part series on token theft in Microsoft Entra ID, accompanying White Paper 80. The post maps the shift from on-premises Active Directory to cloud identity and explains why token theft has become a primary attack vector.
🔹 Landscape Shift
On-premises AD relied on Kerberos and NTLM. Entra ID runs on OAuth 2.0 and OpenID Connect, using JWT-based access, refresh, and ID tokens. New protocols create new attack surface. Microsoft prioritizes usability and backward compatibility over security-by-default, and the strongest protections (Conditional Access, Token Protection, risk-based Identity Protection) are not enabled by default. They require premium P1/P2 licenses plus separate products like Intune or Defender for Endpoint.
Proprietary SSO concepts like PRT, FOCI, and BroCI add further complexity beyond standard OAuth 2.0.
🔹 Concrete Threats
Microsoft's Digital Defense Report 2024 counts over 600 million daily identity attacks against Entra ID. Two notable CVEs:
• CVE-2025-55241: Actor Tokens flaw allowing Global Admin access to any Entra ID tenant worldwide, disclosed by researcher Dirk-jan Mollema
• CVE-2026-69836: CVSS 10.0 unauthenticated RCE in Entra ID itself, caused by unsafe deserialization of untrusted data
🔹 Active Campaigns
• Storm-2372: device code phishing campaign targeting governments and critical industries since August 2024
• Storm-2945: hijacked hotel captive portals worldwide to harvest SSO tokens
• AiTM "code of conduct" phishing: intercepts tokens the moment MFA succeeds rather than trying to defeat MFA directly
🔹 Commodity Tooling
Open-source reverse-proxy frameworks Evilginx and Modlishka, along with PhaaS platforms like EvilProxy, Tycoon2FA, and Kali365, have lowered the barrier to running token theft attacks at scale. Infostealers add further reach by harvesting tokens from compromised endpoints.
🔹 Cloud Security Alliance Ranking
CSA's Top Threats to Cloud Computing 2026 ranks IAM-related threats as the #1 risk to cloud environments, ahead of AI-enhanced attacks in second place despite the current AI security hype cycle.
🔹 What's Next
The series will empirically test Continuous Access Evaluation and Token Protection, and examine where Entra ID deviates from OAuth 2.0 best practices.
🔹 EntraID #TokenTheft #ThreatIntelligence #OAuth2 #Cybersecurity
##----------------
🎯 Threat Intelligence
===================
ERNW published the first of a four-part series on token theft in Microsoft Entra ID, accompanying White Paper 80. The post maps the shift from on-premises Active Directory to cloud identity and explains why token theft has become a primary attack vector.
🔹 Landscape Shift
On-premises AD relied on Kerberos and NTLM. Entra ID runs on OAuth 2.0 and OpenID Connect, using JWT-based access, refresh, and ID tokens. New protocols create new attack surface. Microsoft prioritizes usability and backward compatibility over security-by-default, and the strongest protections (Conditional Access, Token Protection, risk-based Identity Protection) are not enabled by default. They require premium P1/P2 licenses plus separate products like Intune or Defender for Endpoint.
Proprietary SSO concepts like PRT, FOCI, and BroCI add further complexity beyond standard OAuth 2.0.
🔹 Concrete Threats
Microsoft's Digital Defense Report 2024 counts over 600 million daily identity attacks against Entra ID. Two notable CVEs:
• CVE-2025-55241: Actor Tokens flaw allowing Global Admin access to any Entra ID tenant worldwide, disclosed by researcher Dirk-jan Mollema
• CVE-2026-69836: CVSS 10.0 unauthenticated RCE in Entra ID itself, caused by unsafe deserialization of untrusted data
🔹 Active Campaigns
• Storm-2372: device code phishing campaign targeting governments and critical industries since August 2024
• Storm-2945: hijacked hotel captive portals worldwide to harvest SSO tokens
• AiTM "code of conduct" phishing: intercepts tokens the moment MFA succeeds rather than trying to defeat MFA directly
🔹 Commodity Tooling
Open-source reverse-proxy frameworks Evilginx and Modlishka, along with PhaaS platforms like EvilProxy, Tycoon2FA, and Kali365, have lowered the barrier to running token theft attacks at scale. Infostealers add further reach by harvesting tokens from compromised endpoints.
🔹 Cloud Security Alliance Ranking
CSA's Top Threats to Cloud Computing 2026 ranks IAM-related threats as the #1 risk to cloud environments, ahead of AI-enhanced attacks in second place despite the current AI security hype cycle.
🔹 What's Next
The series will empirically test Continuous Access Evaluation and Token Protection, and examine where Entra ID deviates from OAuth 2.0 best practices.
🔹 EntraID #TokenTheft #ThreatIntelligence #OAuth2 #Cybersecurity
##🟠 CVE-2026-61792 - High (7.7)
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resol...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61792 - High (7.7)
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resol...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##26 posts
9 repos
https://github.com/imbas007/CVE-2026-60004-POC
https://github.com/fevar54/cve-2026-60004
https://github.com/shinthink/CVE-2026-60004
https://github.com/HackSpeak/CVE-2026-60004
https://github.com/Sachinart/CVE-2026-60004-gitea-0day
https://github.com/EQSTLab/CVE-2026-60004
https://github.com/0xBlackash/CVE-2026-60004
🔴 CVE-2026-60004 - Critical (9.8)
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-60004/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##⚠️ CRITICAL: Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Gitea instances are under active attack for CVE-2026-60004, a critical RCE flaw (CVSS 9.8) that allows unauthenticated account creation to trigger arbitrary command execution. Attackers are deploying miner-like payloads. Any organization running Gitea with default open registration is at immediate…
🤖 AI generated summary
##Hackers now exploit critical Gitea flaw in code injection attacks
자가 호스팅 Git 서비스 Gitea의 치명적 취약점 CVE-2026-60004가 실제 공격에 악용되고 있다. 공격자는 diffpatch API에 악성 패치를 제출해 저장소 제어 콘텐츠로 Git hook을 설치하고, Gitea 서비스 계정 권한으로 임의 셸 명령을 실행할 수 있다. 기본 설정에서는 사용자 자가 가입이 켜져 있어, 외부 공격자가 계정을 만든 뒤 저장소를 생성하는 것만으로 필요한 쓰기 권한을 얻을 수 있다. Gitea 1.27.1에서 수정됐으며, C...
##CISA Reports Actively Exploited Gitea Critical RCE Vulnerability
Gitea patched a critical remote code execution vulnerability (CVE-2026-60004) that attackers are actively exploiting to install crypto-miners on self-hosted instances. The flaw allows users with write access to inject malicious Git hooks via the diffpatch API, potentially exposing database credentials and system secrets.
**Update self-hosted Gitea instances to version 1.27.1 immediately. Now it's urgent, since hackers are actively attacking you. If you can't patch right away, disable public registration to prevent new outsiders from obtaining repository write access. This does not protect against existing users who already have the required permissions.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-reports-actively-exploited-gitea-critical-rce-vulnerability-2-1-9-j-5/gD2P6Ple2L
CISA has listed CVE-2026-60004 in the KEV Catalog. Critical RCE in Gitea actively exploited via malicious patches submitted through the diff API endpoint. Attackers achieve code injection on self-hosted instances and deploy cryptominers on compromised servers. Patch by August 28 is mandatory.
#CriticalRCE #GiteaVulnerability #Cryptojacking #CISAKEV
https://cyberworldops.eu/en/gitea-under-attack-critical-rce-exploited-for-cryptojacking-cisa
##CISA Sounds the Alarm as Actively Exploited Gitea Flaw Lets Authenticated Users Run Shell Commands + Video
A New Warning Raises Serious Questions for Gitea Administrators A new cybersecurity warning has placed Gitea administrators under pressure after the U.S. Cybersecurity and Infrastructure Security Agency, CISA, identified CVE-2026-60004 as an actively exploited vulnerability. The flaw reportedly affects the popular self-hosted Git service and could allow an…
##📰 CISA Warns of Actively Exploited Gitea RCE Flaw (CVE-2026-60004)
🚨 CISA KEV ALERT: A critical RCE flaw in Gitea (CVE-2026-60004, CVSS 9.8) is actively exploited. Attackers can gain RCE on self-hosted Git servers. Patch to version 1.27.1 or later NOW. #Gitea #RCE #CISA #KEV #CVE202660004
##🏆 New Achievement! Hook, Line, and Git Hooked!
And here, in its natural habitat, we observe the self-hosted Git server — a creature believed by its keepers to be safely tucked away, far from predators. CVE-2026-60004 tells a different story. An attacker with mere repository write access may deliver a malicious patch to Gitea's diffpatch API endpoint, planting an executable Git hook and inheriting the Gitea service account like a cuckoo claiming another bird's nest. (1/2)
##CISA has added CVE-2026-60004 to the KEV catalog. The vulnerability in Gitea, a self-hosted Git service, has been exploited in the wild to achieve remote code execution and install cryptocurrency miners on compromised instances. FCEB agencies face a remediation deadline of August 28, 2026.
#KnownExploitedVulnerabilities #RemoteCodeExecution #Gitea #CISA
https://cyberworldops.eu/en/cisa-adds-gitea-vulnerability-to-kev-catalog-exploited-to-execute-code
##Gitea Under Attack: Critical CVE-2026-60004 Turns Self-Hosted Git Servers Into Potential Remote-Control Hubs
A Quiet Git Feature Has Become a Dangerous Attack Path Self-hosted development platforms are built on a simple promise: organizations keep control of their source code, repositories, credentials, and development infrastructure instead of placing everything in a public cloud. But that control comes with a responsibility that is easy to underestimate—every exposed…
##Gitea Flaw Exploited in Code Injection Attacks
A critical flaw in Gitea, tracked as CVE-2026-60004, is being actively exploited in code injection attacks, putting nearly 5,000 self-hosted Git service instances at risk. Attackers can inject malicious code by submitting patches via Gitea's diffpatch API endpoint, allowing them to execute arbitrary shell commands.
#Gitea #CodeInjection #Cve202660004 #SupplyChain #EmergingThreats
##Critical Gitea Vulnerability CVE-2026-60004 Enters CISA’s Exploited Threat List as Attackers Target Self-Hosted Git Servers + Video
A New Warning for Developers and Security Teams A seemingly ordinary software update has turned into an urgent security warning for organizations running self-hosted Git infrastructure. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-60004 to its Known Exploited Vulnerabilities (KEV) catalog after…
##🚨 Critical Threat Intel: CVE-2026-60004 targets Gitea via diffpatch API code injection. Review execution vectors, persistence mechanics, and active endpoint hardening actions to secure your version control infrastructure. https://thecybermind.co/jily
##CISA has updated the KEV catalogue.
- CVE-2026-60004: Gitea Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-60004
- Industrial vulnerability: Rently Smart Home https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-01
Also:
Press release: CISA Advisory Highlights Red Team Findings to Help Organizations Assess Risk, Identify Threats and Enable Effective Incident Response https://www.cisa.gov/news-events/news/cisa-advisory-highlights-red-team-findings-help-organizations-assess-risk-identify-threats-and
The advisory: A Tale of Two SOCs: Insights From Two Red Team Assessments https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a #CISA #infosec #vulnerability
##CVE ID: CVE-2026-60004
Vendor: Gitea
Product: Gitea
Date Added: 2026-08-25
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60004
🚨 [CISA-2026:0825] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-60004 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- Name: Gitea Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Gitea
- Product: Gitea
- Notes: https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-60004
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260825 #cisa20260825 #cve_2026_60004 #cve202660004
##🔴 CVE-2026-60004 - Critical (9.8)
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-60004/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##⚠️ CRITICAL: Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Gitea instances are under active attack for CVE-2026-60004, a critical RCE flaw (CVSS 9.8) that allows unauthenticated account creation to trigger arbitrary command execution. Attackers are deploying miner-like payloads. Any organization running Gitea with default open registration is at immediate…
🤖 AI generated summary
##CISA Reports Actively Exploited Gitea Critical RCE Vulnerability
Gitea patched a critical remote code execution vulnerability (CVE-2026-60004) that attackers are actively exploiting to install crypto-miners on self-hosted instances. The flaw allows users with write access to inject malicious Git hooks via the diffpatch API, potentially exposing database credentials and system secrets.
**Update self-hosted Gitea instances to version 1.27.1 immediately. Now it's urgent, since hackers are actively attacking you. If you can't patch right away, disable public registration to prevent new outsiders from obtaining repository write access. This does not protect against existing users who already have the required permissions.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-reports-actively-exploited-gitea-critical-rce-vulnerability-2-1-9-j-5/gD2P6Ple2L
CISA has listed CVE-2026-60004 in the KEV Catalog. Critical RCE in Gitea actively exploited via malicious patches submitted through the diff API endpoint. Attackers achieve code injection on self-hosted instances and deploy cryptominers on compromised servers. Patch by August 28 is mandatory.
#CriticalRCE #GiteaVulnerability #Cryptojacking #CISAKEV
https://cyberworldops.eu/en/gitea-under-attack-critical-rce-exploited-for-cryptojacking-cisa
##🏆 New Achievement! Hook, Line, and Git Hooked!
And here, in its natural habitat, we observe the self-hosted Git server — a creature believed by its keepers to be safely tucked away, far from predators. CVE-2026-60004 tells a different story. An attacker with mere repository write access may deliver a malicious patch to Gitea's diffpatch API endpoint, planting an executable Git hook and inheriting the Gitea service account like a cuckoo claiming another bird's nest. (1/2)
##CISA has added CVE-2026-60004 to the KEV catalog. The vulnerability in Gitea, a self-hosted Git service, has been exploited in the wild to achieve remote code execution and install cryptocurrency miners on compromised instances. FCEB agencies face a remediation deadline of August 28, 2026.
#KnownExploitedVulnerabilities #RemoteCodeExecution #Gitea #CISA
https://cyberworldops.eu/en/cisa-adds-gitea-vulnerability-to-kev-catalog-exploited-to-execute-code
##🚨 Critical Threat Intel: CVE-2026-60004 targets Gitea via diffpatch API code injection. Review execution vectors, persistence mechanics, and active endpoint hardening actions to secure your version control infrastructure. https://thecybermind.co/jily
##CISA has updated the KEV catalogue.
- CVE-2026-60004: Gitea Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-60004
- Industrial vulnerability: Rently Smart Home https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-01
Also:
Press release: CISA Advisory Highlights Red Team Findings to Help Organizations Assess Risk, Identify Threats and Enable Effective Incident Response https://www.cisa.gov/news-events/news/cisa-advisory-highlights-red-team-findings-help-organizations-assess-risk-identify-threats-and
The advisory: A Tale of Two SOCs: Insights From Two Red Team Assessments https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a #CISA #infosec #vulnerability
##CVE ID: CVE-2026-60004
Vendor: Gitea
Product: Gitea
Date Added: 2026-08-25
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60004
🚨 [CISA-2026:0825] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-60004 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- Name: Gitea Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Gitea
- Product: Gitea
- Notes: https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-60004
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260825 #cisa20260825 #cve_2026_60004 #cve202660004
##CVE-2026-80196 - Authentication Bypass in Kimai before 2.58.0 via password reset link reuse. CVSS 7.5. Update to version 2.58.0 immediately. #CVE #Kimai #infosec
##🟠 CVE-2026-78379 - High (8.1)
Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78379/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-78379 - High (8.1)
Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78379/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Ubiquiti patched 22 UniFi flaws. Three hit CVSS 10.0, including command injection CVE-2026-77537. Update UniFi Protect, OS, and Talk now.
#Ubiquiti #UniFi #CyberSecurity #CommandInjection #CVE202677537
##Ubiquiti patched 22 UniFi flaws. Three hit CVSS 10.0, including command injection CVE-2026-77537. Update UniFi Protect, OS, and Talk now.
#Ubiquiti #UniFi #CyberSecurity #CommandInjection #CVE202677537
##A critical Veeam ONE vulnerability (CVE-2026-65641, CVSS 9.3) lets an unauthenticated attacker coerce SMB authentication. Patch Veeam now.
##A critical Veeam ONE vulnerability (CVE-2026-65641, CVSS 9.3) lets an unauthenticated attacker coerce SMB authentication. Patch Veeam now.
##Two critical Next.js vulnerabilities, including CVE-2026-75604 (CVSS 9.0), enable unauthenticated remote code execution. Patch to 15.5.24 or 16.3.3 now.
#NextJS #RCE #CyberSecurity #CVE202675604 #WebSecurity
https://securityonline.info/nextjs-rce-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
##Two critical Next.js vulnerabilities, including CVE-2026-75604 (CVSS 9.0), enable unauthenticated remote code execution. Patch to 15.5.24 or 16.3.3 now.
#NextJS #RCE #CyberSecurity #CVE202675604 #WebSecurity
https://securityonline.info/nextjs-rce-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
##2 posts
5 repos
https://github.com/rizlmaulanaa/CVE-2026-23479-Redis-UAF-Proof-of-Concept
https://github.com/pduggusa/redis-cve-2026-23479-check
https://github.com/v1c0mmrt/redis-cve-2026-23479-scanner
https://github.com/mgiay/CVE-2026-25589-25588-25243-23631-23479-REDIS
A public PoC exploits a Redis RCE use-after-free flaw tied to CVE-2026-23479, running system commands as the Redis server. Update to 8.8.2.
##A public PoC exploits a Redis RCE use-after-free flaw tied to CVE-2026-23479, running system commands as the Redis server. Update to 8.8.2.
##CVE-2026-18965 discloses a missing authorization flaw in the PayRange API (CWE-862). All versions are affected. The vulnerability allows unauthenticated remote access to payment devices, exposing fleets of vending machines and kiosks to unauthorized interaction.
#CVE202618965 #MissingAuthorization #PayRangeAPI #CriticalVulnerability
https://cyberworldops.eu/en/payrange-authorization-flaw-in-api-remote-access-to-payment-devices
##CVE-2026-18965 discloses a missing authorization flaw in the PayRange API (CWE-862). All versions are affected. The vulnerability allows unauthenticated remote access to payment devices, exposing fleets of vending machines and kiosks to unauthorized interaction.
#CVE202618965 #MissingAuthorization #PayRangeAPI #CriticalVulnerability
https://cyberworldops.eu/en/payrange-authorization-flaw-in-api-remote-access-to-payment-devices
##1 posts
7 repos
https://github.com/d-maggipinto/CVE-2026-72898-metabase-sqli
https://github.com/Franc-Zar/CVE-2026-72898-safe-detection
https://github.com/4minx/CVE-2026-72898
https://github.com/VuxNx/CVE-2026-72898
https://github.com/0xBlackash/CVE-2026-72898
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
https://thecybersecguru.com/exploits/cve-2026-72898-metabase-sql-injection/
##Spring GraphQL Security Alert: CVE-2026-59285 Creates a Dangerous Path to Remote Code Execution
A New Warning for Spring-Based Applications A newly disclosed vulnerability in Spring for GraphQL is putting developers and security teams on notice. CVE-2026-59285 affects specific Spring GraphQL applications that combine Jackson 2.x deserialization, paginated GraphQL fields, and certain classes available on the application's classpath. The vulnerability is particularly…
##Broadcom Patches 91 Spring CVEs, Including a Critical LDAP Flaw
Broadcom's Tanzu division released one of Spring's largest-ever security batches on August 20, 2026, patching 91 CVEs across Spring Security, Spring AI, Spring GraphQL and related projects, including the critical CVE-2026-59270 (CVSS 9.8) in Spring Security's embedded UnboundID LDAP server and a critical deserialization/RCE flaw in Spring GraphQL.
**If you run Java applications built on Spring, update Spring Security to 7.1.1, 7.0.7 (or 6.5.12 / 5.8.28 on older supported branches) and upgrade Spring AI and Spring GraphQL to their patched versions. CheckUntil you can patch, block access to the LDAP listener ports with firewall rules so they can only be reached from trusted networks.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/broadcom-patches-91-spring-cves-including-a-critical-ldap-flaw-j-u-p-v-t/gD2P6Ple2L
Broadcom Patches 91 Spring CVEs, Including a Critical LDAP Flaw
Broadcom's Tanzu division released one of Spring's largest-ever security batches on August 20, 2026, patching 91 CVEs across Spring Security, Spring AI, Spring GraphQL and related projects, including the critical CVE-2026-59270 (CVSS 9.8) in Spring Security's embedded UnboundID LDAP server and a critical deserialization/RCE flaw in Spring GraphQL.
**If you run Java applications built on Spring, update Spring Security to 7.1.1, 7.0.7 (or 6.5.12 / 5.8.28 on older supported branches) and upgrade Spring AI and Spring GraphQL to their patched versions. CheckUntil you can patch, block access to the LDAP listener ports with firewall rules so they can only be reached from trusted networks.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/broadcom-patches-91-spring-cves-including-a-critical-ldap-flaw-j-u-p-v-t/gD2P6Ple2L
CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, >=4.3.0 <4.4.2. Restrict untrusted WebSocket access. Patch status pending. https://radar.offseq.com/threat/cve-2026-13214-memory-safety-in-zephyrproject-zephyr-042d724fd93f46c2 #OffSeq #Zephyr #CVE202613214 #IoTSec
##CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, >=4.3.0 <4.4.2. Restrict untrusted WebSocket access. Patch status pending. https://radar.offseq.com/threat/cve-2026-13214-memory-safety-in-zephyrproject-zephyr-042d724fd93f46c2 #OffSeq #Zephyr #CVE202613214 #IoTSec
##🟠 CVE-2026-76098 - High (7.5)
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77567 - High (8.1)
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77567/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-66897: Canonical LXD CRITICAL path traversal (CVSS 9.9). Attackers with container edit rights or crafted images can overwrite host files as root. Restrict permissions & avoid untrusted images. Patch status unknown. https://radar.offseq.com/threat/cve-2026-66897-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-b6ae23dfc47f5562 #OffSeq #LXD #CVE #Linux
##CVE-2026-78251 (CRITICAL): DJI Neo & related drones have hard-coded FTP creds, letting attackers fill storage & disrupt logging/updates via network or USB. Patch required! https://radar.offseq.com/threat/cve-2026-78251-cwe-798-use-of-hard-coded-credentials-in-dji-neo-98f2d4e34b35b2e0 #OffSeq #CVE2026_78251 #DJI #DroneSec
##