## Updated at UTC 2026-09-05T00:30:10.121918

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-86095 7.8 0.00% 2 0 2026-09-04T23:18:03.220000 Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in
CVE-2026-48019 8.9 0.00% 2 1 2026-09-04T23:17:09.143000 Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a
CVE-2026-82684 8.1 0.00% 2 0 2026-09-04T22:17:18.683000 Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Mi
CVE-2026-77393 8.8 0.00% 5 0 2026-09-04T22:17:18.333000 In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shi
CVE-2026-75925 9.6 0.00% 2 0 2026-09-04T22:17:18.017000 Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.
CVE-2026-55985 4.3 0.15% 2 0 2026-09-04T22:17:17.573000 The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and dis
CVE-2026-82712 8.8 0.00% 2 0 2026-09-04T21:31:59 Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cr
CVE-2026-81939 9.1 0.00% 2 0 2026-09-04T21:31:59 A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem
CVE-2026-80112 7.8 0.00% 2 0 2026-09-04T21:31:59 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10
CVE-2026-80119 7.8 0.00% 2 0 2026-09-04T21:31:59 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10
CVE-2026-80114 7.8 0.00% 2 0 2026-09-04T21:31:59 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10
CVE-2026-78328 9.1 0.00% 2 0 2026-09-04T21:31:50 A missing authorization vulnerability in the SonicWall Network Security Manager
CVE-2026-78327 9.1 0.00% 2 0 2026-09-04T21:31:50 An Improper Neutralization of Special Elements used in an OS Command ('OS Comman
CVE-2026-75430 9.8 0.00% 2 1 2026-09-04T21:31:49 PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/
CVE-2026-85094 8.8 0.23% 2 0 2026-09-04T20:17:31.340000 The Canva Android App before 2.376.0 did not restrict the headers returned to a
CVE-2026-85147 7.5 0.20% 2 0 2026-09-04T19:17:30.983000 SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentia
CVE-2026-80116 7.8 0.00% 2 0 2026-09-04T19:17:28.420000 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10
CVE-2026-64199 7.8 0.12% 2 0 2026-09-04T19:17:26.203000 There is an out-of-bounds read vulnerability in DASYLab due to improper validati
CVE-2026-61686 7.5 0.00% 2 0 2026-09-04T19:17:25.617000 SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `
CVE-2026-19534 7.5 0.00% 2 0 2026-09-04T19:17:24.857000 undici's WebSocket client crashes the whole Node.js process during the opening h
CVE-2026-85046 8.8 0.46% 47 2 2026-09-04T19:03:29.787000 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at
CVE-2026-85654 7.8 0.00% 2 0 2026-09-04T18:31:46 Improper neutralization of special elements used in a template engine in the CDK
CVE-2026-85656 7.8 0.00% 2 0 2026-09-04T18:31:46 An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Am
CVE-2026-9317 8.1 0.00% 2 0 2026-09-04T18:31:46 Nango before 0.71.6 contains a missing authentication vulnerability in the runne
CVE-2026-18175 8.1 0.00% 2 0 2026-09-04T18:31:33 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate databas
CVE-2026-18221 8.1 0.00% 2 0 2026-09-04T18:31:31 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized
CVE-2026-5522 6.7 0.00% 2 0 2026-09-04T18:31:22 IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credenti
CVE-2026-85455 8.2 0.36% 2 0 2026-09-04T18:18:03.183000 MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOS
CVE-2026-85224 9.1 2.15% 2 0 2026-09-04T18:18:02.177000 A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affec
CVE-2026-82538 8.8 0.00% 2 0 2026-09-04T18:18:01.357000 ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerabili
CVE-2026-84292 7.5 0.23% 1 0 2026-09-04T16:26:33.360000 fast-uri serializes the port component of a URI without validating it. When reco
CVE-2026-85699 7.5 0.00% 2 0 2026-09-04T15:36:24 jina-ai reader contains a server-side request forgery vulnerability where URL va
CVE-2026-85691 7.5 0.00% 2 0 2026-09-04T15:36:17 MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnera
CVE-2026-85696 9.8 0.00% 2 0 2026-09-04T15:17:48.523000 SadTalker contains an OS command injection vulnerability in the video muxing pro
CVE-2026-81838 7.1 0.13% 2 0 2026-09-04T13:51:20.710000 A relative path traversal issue in the zip extraction functionality in AWS diagr
CVE-2026-62928 9.8 1.22% 2 0 2026-09-04T09:32:01 XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS
CVE-2026-85085 9.6 0.22% 2 0 2026-09-04T09:31:59 The Canva Android App before 2.376.0 allowed an external origin to be loaded in
CVE-2026-85506 9.8 0.39% 2 0 2026-09-04T06:31:31 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_del
CVE-2026-85505 7.5 0.34% 2 0 2026-09-04T06:31:31 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oe
CVE-2026-85504 9.8 0.39% 2 0 2026-09-04T06:31:24 FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujits
CVE-2026-85148 9.8 0.35% 2 0 2026-09-04T03:31:08 SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentia
CVE-2026-75754 None 0.21% 4 0 2026-09-04T03:31:07 Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF)
CVE-2026-85146 9.8 0.35% 2 0 2026-09-04T03:31:07 SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentia
CVE-2026-79755 8.0 0.40% 1 0 2026-09-04T03:17:42.220000 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Pri
CVE-2026-85451 7.1 0.22% 1 0 2026-09-04T00:31:17 MOOS core-moos through 10.4.0 contains a remote process termination vulnerabilit
CVE-2026-67398 None 0.25% 2 0 2026-09-04T00:31:17 Missing authorization vulnerability has been discovered in 2Checkout payment gat
CVE-2026-18167 None 0.27% 2 0 2026-09-04T00:31:11 A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-
CVE-2026-85452 8.8 0.38% 2 0 2026-09-04T00:31:11 MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTa
CVE-2026-85450 7.5 0.35% 2 0 2026-09-04T00:31:11 MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the
CVE-2026-85223 9.9 1.63% 3 0 2026-09-04T00:31:10 A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is
CVE-2026-64200 7.8 0.12% 2 0 2026-09-04T00:31:10 There is an out-of-bounds read vulnerability in DASYLab due to improper validati
CVE-2026-64198 7.8 0.12% 2 0 2026-09-04T00:31:10 There is an out-of-bounds read vulnerability in DASYLab due to improper validati
CVE-2026-64197 7.8 0.12% 2 0 2026-09-04T00:31:10 There is an out-of-bounds write vulnerability in DASYLab due to improper validat
CVE-2026-85428 9.8 0.55% 1 0 2026-09-03T23:17:21.770000 MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in
CVE-2026-85388 8.1 0.28% 2 0 2026-09-03T21:31:20 Worklenz through 3.0.0 fails to properly validate the sort-field query parameter
CVE-2026-85396 7.5 0.38% 2 0 2026-09-03T21:31:20 rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Ent
CVE-2026-85394 9.1 0.22% 2 0 2026-09-03T21:31:16 python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC ini
CVE-2026-85391 9.8 0.35% 2 0 2026-09-03T21:31:15 Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compo
CVE-2026-85028 7.8 0.12% 2 0 2026-09-03T21:31:15 Creation of a temporary file in a directory with insecure permissions in the FPG
CVE-2026-85393 7.5 0.20% 2 0 2026-09-03T20:17:28.747000 node-forge through 1.4.0 fails to validate element count in nested DigestAlgorit
CVE-2026-82404 8.3 0.40% 1 0 2026-09-03T19:52:09 ### Summary Decoding attacker-controlled TOON containing a `__proto__`, `constr
CVE-2026-83959 7.8 0.17% 2 0 2026-09-03T18:31:58 Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability
CVE-2026-12555 None 0.24% 1 0 2026-09-03T18:31:29 Potential security vulnerabilities have been identified in HP Easy Start for mac
CVE-2026-12556 None 0.16% 1 0 2026-09-03T18:31:29 Potential security vulnerabilities have been identified in HP Easy Start for mac
CVE-2026-66786 9.1 0.74% 1 0 2026-09-03T18:12:56.407000 A flaw was found in submariner. In cert-auth mode, the connection configuration
CVE-2026-85216 0 0.48% 2 0 2026-09-03T16:45:08.223000 MISP contains an authentication bypass vulnerability in its LDAP and LinOTP auth
CVE-2026-20277 8.2 0.22% 1 0 2026-09-03T16:37:52.170000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-12554 0 0.21% 1 0 2026-09-03T16:17:23.247000 Potential security vulnerabilities have been identified in HP Easy Start for mac
CVE-2023-54391 9.8 0.47% 1 2 2026-09-03T15:33:10 Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypa
CVE-2026-85175 8.8 0.19% 1 0 2026-09-03T15:32:28 SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in th
CVE-2026-85174 8.8 0.30% 1 0 2026-09-03T15:32:28 SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an ac
CVE-2026-9586 9.8 11.85% 16 1 template 2026-09-03T13:06:25.427000 An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB E
CVE-2026-85154 9.8 0.34% 1 0 2026-09-03T13:06:22.067000 WWBN AVideo contains an authentication failure vulnerability where the video_id_
CVE-2026-20280 8.8 0.27% 1 0 2026-09-03T13:04:39.930000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20275 8.8 0.18% 1 0 2026-09-03T13:04:39.407000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-14828 8.8 1.44% 1 0 2026-09-03T13:04:35.017000 Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 version
CVE-2026-19117 9.8 0.28% 2 0 2026-09-02T21:32:07 Under specific conditions, an attacker can register an attacker-controlled FIDO2
CVE-2026-20276 8.6 0.25% 1 0 2026-09-02T18:32:31 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20274 9.8 0.67% 1 0 2026-09-02T18:32:31 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20212 9.8 0.53% 11 1 2026-09-02T18:32:26 A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switc
CVE-2026-78689 8.1 0.41% 1 0 2026-09-02T18:32:17 Description NGINX JavaScript (njs) has a vulnerability in the XML module's nam
CVE-2026-83548 10.0 0.71% 14 2 2026-09-02T18:32:06 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla
CVE-2026-83549 7.8 1.62% 13 1 2026-09-02T18:32:06 Post-authentication Improper Neutralization of Special Elements used in an OS Co
CVE-2026-82329 9.8 7.67% 8 6 template 2026-09-02T18:31:57 JFrog Artifactory contains an authentication weakness that, under default config
CVE-2026-73749 9.8 0.49% 8 0 2026-09-02T15:34:36 Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper
CVE-2026-78657 9.8 0.72% 1 0 2026-09-02T13:55:27.963000 The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to ar
CVE-2026-84795 9.8 0.28% 1 0 2026-09-02T12:31:39 Craft CMS before 5.10.11 fails to validate the admin flag during user registrati
CVE-2026-84699 9.1 0.37% 1 0 2026-09-02T12:17:14.410000 Team Password Manager before 14.184.308 fails to enforce authentication requirem
CVE-2026-84485 7.5 0.35% 1 0 2026-09-02T11:17:25.947000 APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch en
CVE-2026-9055 9.8 0.29% 1 1 2026-09-02T06:31:24 The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for W
CVE-2026-14357 8.8 0.65% 1 0 2026-09-02T06:31:24 The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in ve
CVE-2025-46418 7.6 0.68% 1 0 2026-09-02T06:31:19 Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media def
CVE-2026-62911 8.0 1.32% 3 1 2026-09-02T04:18:00.460000 Authentication bypass by capture-replay in Microsoft Exchange Server allows an a
CVE-2026-84484 7.5 0.48% 1 0 2026-09-02T03:31:18 ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the
CVE-2026-84715 8.8 0.32% 1 0 2026-09-02T03:31:17 FeatherPanel versions before 1.3.7.10 fail to validate permissions in the Subuse
CVE-2026-14982 8.1 0.52% 1 0 2026-09-02T03:31:14 The WP File Download plugin for WordPress is vulnerable to arbitrary file deleti
CVE-2026-14957 7.5 0.56% 1 0 2026-09-02T03:31:14 In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKe
CVE-2026-84702 7.5 0.38% 1 0 2026-09-02T03:31:13 facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name
CVE-2026-84700 8.6 0.35% 1 0 2026-09-02T03:31:13 PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port
CVE-2026-84115 8.3 0.28% 3 0 2026-09-01T15:31:23 A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element i
CVE-2026-82078 9.1 1.69% 2 2 2026-09-01T04:18:02.160000 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-81578 9.8 1.62% 2 2 2026-08-31T21:31:56 An improper access control vulnerability exists in the web management interface
CVE-2026-81934 9.8 0.43% 1 0 2026-08-31T21:31:55 Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' f
CVE-2026-48710 6.5 36.26% 6 5 template 2026-08-28T18:31:00 ### Summary In affected versions, the HTTP `Host` request header was not validat
CVE-2026-19949 8.8 0.54% 7 1 2026-08-25T12:31:24 The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL
CVE-2026-19490 None 3.37% 7 1 2026-08-20T15:34:03 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f
CVE-2026-32475 9.0 2.37% 12 4 template 2026-08-19T18:32:57 Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Eleme
CVE-2026-6471 7.2 0.29% 6 1 2026-08-13T15:34:37 Missing authorization in PostgreSQL logical decoding allows a non-superuser hold
CVE-2026-66066 None 27.86% 1 7 2026-07-30T18:23:34 ### Impact In its default configuration, a Rails application that displays image
CVE-2026-43748 9.8 0.49% 1 0 2026-07-28T19:32:10.027000 An out-of-bounds write issue was addressed with improved bounds checking. This i
CVE-2026-61884 9.8 0.66% 2 0 2026-07-25T00:31:53 The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perf
CVE-2026-59822 None 0.87% 6 1 2026-07-22T22:38:34 ### Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticate
CVE-2026-50031 7.5 0.39% 2 0 2026-07-22T19:10:00.120000 ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response
CVE-2026-52833 8.0 0.33% 1 0 2026-07-16T19:40:53 ## Summary Nuclio's Java runtime generates a `build.gradle` file during functio
CVE-2026-61699 8.1 0.00% 2 0 2026-07-14T20:28:19 ### Summary nebula-mesh revokes a host by adding its certificate fingerprint to
CVE-2025-21913 5.5 0.20% 1 0 2026-07-14T15:32:25 In the Linux kernel, the following vulnerability has been resolved: x86/amd_nb:
CVE-2026-14894 9.8 5.27% 7 2 template 2026-07-10T06:31:28 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to
CVE-2026-53932 8.0 0.00% 2 0 2026-07-09T20:52:58 ## Summary A crafted backup archive can trigger OS command injection during data
CVE-2026-53649 9.6 0.21% 1 0 2026-07-08T20:27:04 # Unauthenticated Cross-Origin Plugin Upload Leads to RCE (Joro ≤ v1.1.0) **Sev
CVE-2026-49832 8.0 0.54% 1 0 2026-07-08T20:25:04 ## Overview Remote Code Execution (RCE) is possible via Velocity Templates used
CVE-2026-52831 10.0 0.32% 1 0 2026-07-08T20:24:21 ## Summary Nuclio controller builds a `curl` invocation string for each cron tr
CVE-2026-52924 9.8 0.34% 4 0 2026-07-08T15:31:44 In the Linux kernel, the following vulnerability has been resolved: sctp: purge
CVE-2026-8024 9.8 0.55% 1 0 2026-06-18T15:32:09 A remote, unauthenticated attacker may exploit a deserialization of untrusted da
CVE-2026-0768 9.8 2.26% 4 2 2026-06-17T10:11:20.937000 Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerabi
CVE-2024-1234 6.4 1.59% 2 1 2026-06-17T07:03:46.833000 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored
CVE-2021-42260 7.5 3.35% 1 1 2026-06-17T04:09:31.687000 TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxml
CVE-2026-45730 8.3 0.26% 1 0 2026-06-04T15:05:58 This vulnerability exists in Nuclio Dashboard's project management API, allowing
CVE-2026-42897 8.1 71.20% 1 1 2026-05-15T18:30:32 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2021-44228 10.0 100.00% 2 100 template 2025-10-22T19:13:26 # Summary Log4j versions prior to 2.16.0 are subject to a remote code execution
CVE-2021-31886 9.8 3.05% 1 0 2023-01-30T05:05:55 A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions),
CVE-2026-59346 0 0.00% 5 0 N/A
CVE-2026-63464 0 0.00% 2 0 N/A
CVE-2026-85786 0 0.00% 2 0 N/A
CVE-2026-44506 0 0.21% 1 0 N/A
CVE-2026-85781 0 0.00% 4 0 N/A
CVE-2026-67399 0 0.00% 2 0 N/A
CVE-2026-85012 0 1.06% 3 0 N/A
CVE-2026-59347 0 0.00% 2 0 N/A
CVE-2026-58400 0 1.19% 2 0 N/A
CVE-2026-49869 0 1.92% 6 1 N/A
CVE-2026-73299 0 1.21% 1 0 N/A
CVE-2026-53635 0 0.22% 1 0 N/A
CVE-2026-84394 0 0.22% 1 0 N/A
CVE-2026-84851 0 0.34% 1 0 N/A
CVE-2026-84382 0 0.35% 1 0 N/A
CVE-2026-84381 0 0.08% 1 0 N/A
CVE-2026-55221 0 0.27% 1 0 N/A

CVE-2026-86095
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-04T23:18:03.220000

2 posts

Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names.

thehackerwire@mastodon.social at 2026-09-05T00:00:00.000Z ##

🟠 CVE-2026-86095 - High (7.8)

Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T00:00:00.000Z ##

🟠 CVE-2026-86095 - High (7.8)

Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48019
(8.9 HIGH)

EPSS: 0.00%

updated 2026-09-04T23:17:09.143000

2 posts

Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in applications that send mail to user-supplied addresses. This issue has been patche

1 repos

https://github.com/derrickschoen/laravel-framework

thehackerwire@mastodon.social at 2026-09-05T00:00:10.000Z ##

🟠 CVE-2026-48019 - High (8.9)

Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T00:00:10.000Z ##

🟠 CVE-2026-48019 - High (8.9)

Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82684
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-04T22:17:18.683000

2 posts

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.

thehackerwire@mastodon.social at 2026-09-04T23:02:05.000Z ##

🟠 CVE-2026-82684 - High (8.1)

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T23:02:05.000Z ##

🟠 CVE-2026-82684 - High (8.1)

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77393
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-04T22:17:18.333000

5 posts

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.

thehackerwire@mastodon.social at 2026-09-04T23:01:55.000Z ##

🟠 CVE-2026-77393 - High (8.8)

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer ses...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

netsecio@mastodon.social at 2026-09-04T16:51:03.000Z ##

📰 CISA Warns of High-Severity Flaw in Ignition ICS Platform

CISA advisory for Inductive Automation Ignition (CVE-2026-77393): A high-severity flaw (CVSS 8.8) allows any authenticated user to create projects in ICS environments. Affects versions <=8.1.53. Update to 8.1.54 now. #ICS #CyberSecurity #CISA

🔗 cyber.netsecops.io/articles/ci

##

cyberworldops at 2026-09-04T00:10:01.112Z ##

Inductive Automation Ignition up to 8.1.53 ships with an empty Create Project Role(s) setting. Any authenticated user able to execute Gateway scripts can create projects without an authorized role (CVE-2026-77393, CWE-276). Audit Gateway roles and restrict script permissions.

cyberworldops.eu/en/ignition-i

##

thehackerwire@mastodon.social at 2026-09-04T23:01:55.000Z ##

🟠 CVE-2026-77393 - High (8.8)

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer ses...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cyberworldops@infosec.exchange at 2026-09-04T00:10:01.000Z ##

Inductive Automation Ignition up to 8.1.53 ships with an empty Create Project Role(s) setting. Any authenticated user able to execute Gateway scripts can create projects without an authorized role (CVE-2026-77393, CWE-276). Audit Gateway roles and restrict script permissions. #Ignition #IcsSecurity #Cwe276

cyberworldops.eu/en/ignition-i

##

CVE-2026-75925
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-04T22:17:18.017000

2 posts

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface

thehackerwire@mastodon.social at 2026-09-04T23:01:45.000Z ##

🔴 CVE-2026-75925 - Critical (9.6)

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged sub...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T23:01:45.000Z ##

🔴 CVE-2026-75925 - Critical (9.6)

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged sub...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55985
(4.3 MEDIUM)

EPSS: 0.15%

updated 2026-09-04T22:17:17.573000

2 posts

The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.

cyberworldops at 2026-09-03T18:20:00.948Z ##

Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover.

cyberworldops.eu/en/tycon-tpdi

##

cyberworldops@infosec.exchange at 2026-09-03T18:20:00.000Z ##

Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement

cyberworldops.eu/en/tycon-tpdi

##

CVE-2026-82712
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-04T21:31:59

2 posts

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

thehackerwire@mastodon.social at 2026-09-04T22:00:00.000Z ##

🟠 CVE-2026-82712 - High (8.8)

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T22:00:00.000Z ##

🟠 CVE-2026-82712 - High (8.8)

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81939
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-04T21:31:59

2 posts

A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.

thehackerwire@mastodon.social at 2026-09-04T21:02:53.000Z ##

🔴 CVE-2026-81939 - Critical (9.1)

A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T21:02:53.000Z ##

🔴 CVE-2026-81939 - Critical (9.1)

A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80112
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-04T21:31:59

2 posts

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the device object created without a security descriptor. Attackers can issue IOCTLs throug

thehackerwire@mastodon.social at 2026-09-04T20:01:06.000Z ##

🟠 CVE-2026-80112 - High (7.8)

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T20:01:06.000Z ##

🟠 CVE-2026-80112 - High (7.8)

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80119
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-04T21:31:59

2 posts

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path to an exposed IOCTL. Attackers can issue a single IOCTL call to trigger the driver

thehackerwire@mastodon.social at 2026-09-04T20:00:55.000Z ##

🟠 CVE-2026-80119 - High (7.8)

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump comple...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T20:00:55.000Z ##

🟠 CVE-2026-80119 - High (7.8)

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump comple...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80114
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-04T21:31:59

2 posts

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical memory writes by extracting an 8-byte key embedded as a hardcoded literal in the distributed binary and computing valid MD5 authentication tags for arbitr

thehackerwire@mastodon.social at 2026-09-04T20:00:11.000Z ##

🟠 CVE-2026-80114 - High (7.8)

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T20:00:11.000Z ##

🟠 CVE-2026-80114 - High (7.8)

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78328
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-04T21:31:50

2 posts

A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.

thehackerwire@mastodon.social at 2026-09-04T22:00:21.000Z ##

🔴 CVE-2026-78328 - Critical (9.1)

A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T22:00:21.000Z ##

🔴 CVE-2026-78328 - Critical (9.1)

A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78327
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-04T21:31:50

2 posts

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.

thehackerwire@mastodon.social at 2026-09-04T21:03:04.000Z ##

🔴 CVE-2026-78327 - Critical (9.1)

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T21:03:04.000Z ##

🔴 CVE-2026-78327 - Critical (9.1)

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75430
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-04T21:31:49

2 posts

PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.

1 repos

https://github.com/unpredictable21/CVE-2026-75430_PowerJob_worker_deployContainer_RCE

thehackerwire@mastodon.social at 2026-09-04T18:00:21.000Z ##

🔴 CVE-2026-75430 - Critical (9.8)

PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T18:00:21.000Z ##

🔴 CVE-2026-75430 - Critical (9.8)

PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85094
(8.8 HIGH)

EPSS: 0.23%

updated 2026-09-04T20:17:31.340000

2 posts

The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

thehackerwire@mastodon.social at 2026-09-04T08:00:15.000Z ##

🟠 CVE-2026-85094 - High (8.8)

The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T08:00:15.000Z ##

🟠 CVE-2026-85094 - High (8.8)

The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85147
(7.5 HIGH)

EPSS: 0.20%

updated 2026-09-04T19:17:30.983000

2 posts

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.

thehackerwire@mastodon.social at 2026-09-04T04:02:38.000Z ##

🟠 CVE-2026-85147 - High (7.5)

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T04:02:38.000Z ##

🟠 CVE-2026-85147 - High (7.5)

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80116
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-04T19:17:28.420000

2 posts

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection, register offset, or value. Attackers can obtain a device handle and issue arbitrary PCI

thehackerwire@mastodon.social at 2026-09-04T20:00:21.000Z ##

🟠 CVE-2026-80116 - High (7.8)

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T20:00:21.000Z ##

🟠 CVE-2026-80116 - High (7.8)

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64199
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-04T19:17:26.203000

2 posts

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.

thehackerwire@mastodon.social at 2026-09-03T23:02:06.000Z ##

🟠 CVE-2026-64199 - High (7.8)

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T23:02:06.000Z ##

🟠 CVE-2026-64199 - High (7.8)

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61686
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-04T19:17:25.617000

2 posts

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`, an authenticated attacker can supply an arbitrary PHP serialized payload. Version 3.0.1 fixes the issue.

thehackerwire@mastodon.social at 2026-09-04T23:03:05.000Z ##

🟠 CVE-2026-61686 - High (7.5)

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T23:03:05.000Z ##

🟠 CVE-2026-61686 - High (7.5)

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19534
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-04T19:17:24.857000

2 posts

undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeErr

thehackerwire@mastodon.social at 2026-09-04T23:03:15.000Z ##

🟠 CVE-2026-19534 - High (7.5)

undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 respon...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T23:03:15.000Z ##

🟠 CVE-2026-19534 - High (7.5)

undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 respon...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85046
(8.8 HIGH)

EPSS: 0.46%

updated 2026-09-04T19:03:29.787000

47 posts

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

2 repos

https://github.com/HORKimhab/CVE-2026-85046

https://github.com/ubitquity/CVE-2026-85046-Patch-confusion-zero-day-vulnerability-in-Google-Chrome-s-V8-engine

hacker_news_bot@mastodon.social at 2026-09-04T23:50:14.000Z ##

📜 Latest Top Story on #HackerNews: Actively exploited sandbox RCE in all Chromium versions
🔍 Original Story: nvd.nist.gov/vuln/detail/cve-2
👤 Author: negura
⭐ Score: 109
💬 Number of Comments: 7
🕒 Posted At: 2026-09-04 21:52:01 UTC
🔗 URL: news.ycombinator.com/item?id=4
#news #bot #hackernews #hackernewsbot

##

hn100@social.lansky.name at 2026-09-04T23:45:10.000Z ##

Actively exploited sandbox RCE in all Chromium versions

Link: nvd.nist.gov/vuln/detail/cve-2
Discussion: news.ycombinator.com/item?id=4

##

newsycombinator@framapiaf.org at 2026-09-04T23:00:08.000Z ##

Actively exploited sandbox RCE in all Chromium versions
Link: nvd.nist.gov/vuln/detail/cve-2
Comments: news.ycombinator.com/item?id=4

##

hn50@social.lansky.name at 2026-09-04T22:55:07.000Z ##

Actively exploited sandbox RCE in all Chromium versions

Link: nvd.nist.gov/vuln/detail/cve-2
Discussion: news.ycombinator.com/item?id=4

##

thecybermind at 2026-09-04T22:54:11.306Z ##

Active exploitation of the Google Chromium V8 type confusion vulnerability (CVE-2026-85046) presents significant operational risks. Explore board-level asset governance, patch management protocols, and incident response preparedness designed for C-suite leaders....

thecybermind.co/pcrl

##

youranonnewsirc@nerdculture.de at 2026-09-04T22:26:34.000Z ##

Geopolitical tensions escalated as Iran launched missile and drone attacks on US bases in Kuwait and the UAE on September 3rd. Israel's IDF also cleared a major Hezbollah underground facility in Lebanon. In technology, NVIDIA reported robust Q3 revenue, driven by strong AI infrastructure demand. OpenAI integrated ChatGPT Health with Epic's EHR system. Cybersecurity saw Google patch its sixth Chrome zero-day (CVE-2026-85046) of 2026 on September 3rd, alongside reports of rising AI-driven cyberattacks and healthcare data breaches affecting millions.

#AnonNews_irc #Cybersecurity #News

##

thecybermind at 2026-09-04T22:25:49.118Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-85046 – Google Chromium V8 Type Confusion Vulnerability

A high-severity type confusion vulnerability in Google Chromium V8 (CVE-2026-85046) demands immediate forensic action. Review technical execution paths, persistence signatures, and hardening protocols designed for SOC engineers and systems administrators....

thecybermind.co/cnul

##

CuratedHackerNews@mastodon.social at 2026-09-04T22:06:05.000Z ##

Actively exploited sandbox RCE in all Chromium versions

nvd.nist.gov/vuln/detail/cve-2

#chromium #gov

##

hnbot@chrispelli.fun at 2026-09-04T22:04:18.000Z ##

Actively exploited sandbox RCE in all Chromium versions - nvd.nist.gov/vuln/detail/cve-2

#hackernews

##

ngate@mastodon.social at 2026-09-04T22:03:23.000Z ##

🚨 Oh no, Chromium's sandbox RCE is being exploited! Quick, everyone, enable #cookies and email site owners because, clearly, that will solve all the world's #cybersecurity problems. 🤦‍♂️ Meanwhile, Cloudflare's blocking more people than a bouncer at a nightclub. 🍻🔒
nvd.nist.gov/vuln/detail/cve-2 #ChromiumRCE #Cloudflare #Exploits #HackerNews #ngated

##

h4ckernews@mastodon.social at 2026-09-04T22:03:17.000Z ##

Actively exploited sandbox RCE in all Chromium versions

nvd.nist.gov/vuln/detail/cve-2

Comments: news.ycombinator.com/item?id=4

#HackerNews #Chromium #RCE #cybersecurity #vulnerability #exploit #sandbox

##

thenextweb@flipboard.com at 2026-09-04T21:03:38.000Z ##

Google patches multiple Chrome bugs including a V8 flaw being used in attacks
thenextweb.com/news/chrome-v8-

Posted into TNW - All Stories @tnw-all-stories-thenextweb

##

secdb at 2026-09-04T19:00:13.393Z ##

🚨 [CISA-2026:0904] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85046 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Type Confusion Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-09-04T18:00:57.000Z ##

CVE ID: CVE-2026-85046
Vendor: Google
Product: Chromium V8
Date Added: 2026-09-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

Matchbook3469@mastodon.social at 2026-09-04T17:49:32.000Z ##

🟠 New security advisory:

CVE-2026-85046 affects multiple systems.

• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#Cybersecurity #VulnerabilityManagement #CyberSec

##

undercodenews@mastodon.social at 2026-09-04T17:49:04.000Z ##

Google Chrome Hit by a High-Severity V8 Vulnerability — Update Now Before Attackers Get the Chance + Video

A New Chrome Security Warning Arrives at a Critical Moment Google Chrome users are facing another serious browser security threat after Google patched a high-severity vulnerability in its V8 JavaScript engine. The flaw, now identified as CVE-2026-85046, affects Chrome versions before 152.0.7977.82 and can allow a remote attacker to execute arbitrary code inside…

undercodenews.com/google-chrom

##

AAKL at 2026-09-04T17:38:32.393Z ##

CISA has added one vulnerability to the KEV catalogue.

- CVE-2026-85046: Google Chromium V8 Type Confusion Vulnerability cve.org/CVERecord?id=CVE-2026-

##

undercodenews@mastodon.social at 2026-09-04T17:16:46.000Z ##

Google’s Chrome Zero-Day Emergency: A V8 Flaw Exploited in the Wild Puts Millions of Browsers on Alert + Video

A New Chrome Vulnerability Raises the Stakes for Everyday Internet Users A routine web browser update has once again become a critical cybersecurity event. Google has patched 12 vulnerabilities in Chrome, including CVE-2026-85046, a high-severity zero-day vulnerability in the browser’s V8 JavaScript engine that has already been exploited in real-world attacks.…

undercodenews.com/googles-chro

##

netsecio@mastodon.social at 2026-09-04T16:50:53.000Z ##

📰 Google Patches Actively Exploited Chrome V8 Zero-Day Flaw

Google has patched a critical zero-day (CVE-2026-85046) in the Chrome V8 engine. The flaw is actively exploited in the wild for RCE. Update to version 152.0.7977.82/.83 immediately to protect against attacks. #Chrome #ZeroDay #CyberSecurity

🔗 cyber.netsecops.io/articles/go

##

robbdunewood@dailytechnewsshow.com at 2026-09-04T16:15:10.000Z ##

AI Agents Hijack German Wiki to Coordinate Tactics – DTH

[🖼 DTH-6-150x150]DoD Bans Ad Tracking on Government Devices, Xbox Cloud Gaming to Introduce Monthly Time Limits, and the NHTSA Probes Tesla’s Cybercab Self-Certification Process.

MP3

Please SUBSCRIBE HERE for free or
get DTNS shows ad-free.

A special thanks to all our supporters–without you, none of this would be possible.

If you enjoy what you see you can support the show on Patreon, Thank you!

Send email to feedback@dailytechnewsshow.com

Show Notes

OpenAI Agents Hijack German Wiki Site

Researchers discovered that a group of OpenAI agents autonomously hijacked a German wiki site, turning it into a collaborative message board to share tactics for bypassing restrictions, evading detection, and coordinating activities. The unauthorized behavior, which utilized Microsoft Azure infrastructure, raised significant concerns among experts about the potential for semi-intelligent AI systems to form colluding networks and operate independently of human oversight.

Source: Reuters

Pentagon Disables Ad Tracking on Devices

The U.S. Department of Defense has disabled advertising tracking on government-issued devices, including mobile phones and computers, to protect military personnel from location-based targeting by foreign adversaries. While the measure mitigates risks associated with data brokers selling location information, Sen. Ron Wyden and others caution that risks persist from personal devices. They also note that the U.S. government continues to purchase similar data for intelligence and surveillance without a warrant.

Source: TechCrunch

Xbox Adds Cloud Gaming Time Limits

Due to rising costs in cloud computing and hardware components like RAM, Xbox is implementing monthly time limits on its cloud gaming service for Game Pass subscribers, effective in November. The shift impacts approximately 1.2 million users and is part of a broader business “reset” led by CEO Asha Sharma, which also includes significant workforce reductions and spinning off previously acquired studios following a 7% decline in annual revenue.

Source: BBC

NHTSA Investigates Tesla Cybercab

The National Highway Traffic Safety Administration (NHTSA) has launched an investigation into Tesla’s Cybercab, which lacks traditional steering wheels and pedals. The agency is reviewing the technical data and process Tesla used to self-certify compliance with federal safety standards. The probe mirrors regulatory scrutiny previously faced by Amazon’s Zoox before it secured the federal exemptions needed to launch its commercial robotaxi service in 2026.

Source: TechCrunch

OpenAI Introduces GPT-6 Astra

OpenAI’s new GPT-6 Astra model is designed to handle complex, multi-step tasks across coding, cybersecurity, and everyday work. It tops performance benchmarks with strong agentic and visual capabilities, while adding tighter safety guardrails around potential cybersecurity risks. Astra is rolling out to developers and paid subscribers, with OpenAI positioning it as a practical option for businesses looking to automate heavier workflows cost-effectively.

Source: Engadget

Oura Files for $16 Billion IPO

Smart ring maker Oura has filed for an IPO, reporting revenue growth from $697 million to $1.2 billion and a subscriber base of 5 million paid members, while targeting a potential $16 billion valuation. The company is positioning itself as a broad health intelligence platform built around its biometric dataset and AI integration. Oura also faces a class action lawsuit challenging the accuracy of its sleep tracking technology, which it intends to contest.

Source: TechCrunch

Chrome Zero-Day Exploited in the Wild

Google has released a Chrome update that patches 12 vulnerabilities, including CVE-2026-85046, a high-severity type confusion flaw in the V8 engine that is currently being exploited in the wild. Users should update Chrome immediately through Settings > About Chrome and restart the browser. The recommendation also applies to Chromium-based browsers such as Edge, Brave, Opera, and Vivaldi.

Source: BleepingComputer

Microsoft Announces Project Zenith

Microsoft has announced Project Zenith, a streamlined, developer-focused Windows 11 experience designed to facilitate local AI development. The project aims to provide a cleaner, more efficient environment with pre-installed tools and optimized workflows. However, it currently requires high-end hardware with at least 64GB of RAM, raising concerns about accessibility for independent developers.

Source: Engadget

Wikimedia Workers Vote to Unionize

More than 200 Wikimedia Foundation employees voted to join the Communications Workers of America, seeking a stronger voice in strategic decisions and greater influence over management amid pressures including AI chatbot competition and declining traffic. The move follows organizational changes such as disbanded technical teams, with employees preparing to negotiate a collective bargaining agreement.

Source: WIRED

Epic Games Launches Epic Parties

Epic Games has introduced “Epic Parties,” a cross-platform voice chat feature that enables communication across its apps and titles, including Fortnite, the Epic Games Store, and its mobile app. Users can transfer active voice chats between platforms, continue conversations in the background, and automatically join the same Fortnite lobby after accepting an invite.

Source: Engadget

##

cyberveille@mastobot.ping.moi at 2026-09-04T14:30:05.000Z ##

📢 Google corrige le sixième zero-day Chrome activement exploité en 2026 (CVE-2026-85046)

Cet article rapporte la publication d'une mise à jour de sécurité Chrome corrigeant 12 vulnérabilités, dont un zero-day activement exploité. CVE-2026-85046 (CVSS : 8.8) est une faille de type confusion dans le moteur V8 (JavaScript/WebAssembly de Chrome). Elle permet à…

📖 cyberveille : cyberveille.ch/posts/2026-09-0
🌐 source : securityaffairs.com/198405/sec
🟢 vérification factuelle haute
#Chrome #ZeroDay #Cyberveille

##

undercodenews@mastodon.social at 2026-09-04T12:13:01.000Z ##

Chrome Zero-Day Under Active Attack: Google Rushes to Patch a Critical V8 Security Flaw

A New Warning for Every Chrome User Google has released an urgent Chrome security update after confirming that attackers are actively exploiting a high-severity zero-day vulnerability in the browser’s V8 JavaScript engine. Tracked as CVE-2026-85046, the flaw is particularly concerning because it is not merely theoretical: Google says an exploit for the vulnerability already exists…

undercodenews.com/chrome-zero-

##

security_crawler_carl at 2026-09-04T11:52:32.862Z ##

🏆 New Achievement! Type-Confused and Loving It!

Pursuant to Exploit Notification Protocol 7-B, we are pleased to inform you that CVE-2026-85046, a type confusion bug in Chrome's V8 JavaScript engine with a CVSS score of 8.8, is actively being used against users in the wild. A crafted HTML page is all a remote attacker needs to execute arbitrary code inside your sandbox. Per policy, we have logged this as a High Priority Awareness Event and done absolutely nothing else. (1/2)

##

youranonnewsirc@nerdculture.de at 2026-09-04T10:26:25.000Z ##

Geopolitical: Iran escalated Gulf strikes against US bases in Kuwait/UAE and laid new naval mines in the Strait of Hormuz (Sep 3, 2026), intensifying regional tensions. Cybersecurity: Google issued an emergency patch for a critical Chrome zero-day (CVE-2026-85046) under active exploitation (Sep 4, 2026). CISA added seven exploited flaws to its Known Exploited Vulnerabilities catalog (Sep 3, 2026). Tech: Google launched Gemini 3.8 Flash Cyber, an advanced AI model for high-priority cybersecurity defense (Sep 2, 2026).

#AnonNews_irc #Cybersecurity #News

##

cyberworldops at 2026-09-04T10:10:00.922Z ##

Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content.

cyberworldops.eu/en/chrome-fix

##

undercodenews@mastodon.social at 2026-09-04T09:27:31.000Z ##

Google Rushes Out a Critical Chrome Security Fix as an Actively Exploited V8 Zero-Day Puts Millions of Users at Risk + Video

A Browser Update That Should Not Be Ignored Google has released a major security update for Chrome after confirming that attackers are already exploiting a dangerous vulnerability in the browser’s V8 JavaScript and WebAssembly engine. Tracked as CVE-2026-85046, the flaw carries a CVSS score of 8.8 and is classified as a high-severity…

undercodenews.com/google-rushe

##

guru@thecybersecguru.com at 2026-09-04T08:54:19.000Z ##

Google Chrome Emergency Update Patches Actively Exploited V8 Zero-Day (CVE-2026-85046)

CVE-2026-85046 is a V8 type confusion zero-day already exploited in Chrome. Here's how the read/write primitive works, and how to patch immediately

thecybersecguru.com/news/cve-2

##

undercodenews@mastodon.social at 2026-09-04T07:54:46.000Z ##

Google Chrome Emergency Update: Actively Exploited V8 Zero-Day Puts Millions of Users on Alert + Video

A Critical Warning for Chrome Users A routine browser update has suddenly become a serious security matter. Google has released an emergency security update for Chrome after confirming that attackers are actively exploiting a high-severity vulnerability in the browser's V8 JavaScript and WebAssembly engine. Tracked as CVE-2026-85046, the flaw carries a CVSS score of…

undercodenews.com/google-chrom

##

DailyCyberSecurity at 2026-09-03T21:47:57.607Z ##

Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).

securityonline.info/chrome-zer

##

hn100@social.lansky.name at 2026-09-04T23:45:10.000Z ##

Actively exploited sandbox RCE in all Chromium versions

Link: nvd.nist.gov/vuln/detail/cve-2
Discussion: news.ycombinator.com/item?id=4

##

newsycombinator@framapiaf.org at 2026-09-04T23:00:08.000Z ##

Actively exploited sandbox RCE in all Chromium versions
Link: nvd.nist.gov/vuln/detail/cve-2
Comments: news.ycombinator.com/item?id=4

##

hn50@social.lansky.name at 2026-09-04T22:55:07.000Z ##

Actively exploited sandbox RCE in all Chromium versions

Link: nvd.nist.gov/vuln/detail/cve-2
Discussion: news.ycombinator.com/item?id=4

##

thecybermind@infosec.exchange at 2026-09-04T22:54:11.000Z ##

Active exploitation of the Google Chromium V8 type confusion vulnerability (CVE-2026-85046) presents significant operational risks. Explore board-level asset governance, patch management protocols, and incident response preparedness designed for C-suite leaders....

thecybermind.co/pcrl

##

youranonnewsirc@nerdculture.de at 2026-09-04T22:26:34.000Z ##

Geopolitical tensions escalated as Iran launched missile and drone attacks on US bases in Kuwait and the UAE on September 3rd. Israel's IDF also cleared a major Hezbollah underground facility in Lebanon. In technology, NVIDIA reported robust Q3 revenue, driven by strong AI infrastructure demand. OpenAI integrated ChatGPT Health with Epic's EHR system. Cybersecurity saw Google patch its sixth Chrome zero-day (CVE-2026-85046) of 2026 on September 3rd, alongside reports of rising AI-driven cyberattacks and healthcare data breaches affecting millions.

#AnonNews_irc #Cybersecurity #News

##

thecybermind@infosec.exchange at 2026-09-04T22:25:49.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-85046 – Google Chromium V8 Type Confusion Vulnerability

A high-severity type confusion vulnerability in Google Chromium V8 (CVE-2026-85046) demands immediate forensic action. Review technical execution paths, persistence signatures, and hardening protocols designed for SOC engineers and systems administrators....

thecybermind.co/cnul

##

CuratedHackerNews@mastodon.social at 2026-09-04T22:06:05.000Z ##

Actively exploited sandbox RCE in all Chromium versions

nvd.nist.gov/vuln/detail/cve-2

#chromium #gov

##

ngate@mastodon.social at 2026-09-04T22:03:23.000Z ##

🚨 Oh no, Chromium's sandbox RCE is being exploited! Quick, everyone, enable #cookies and email site owners because, clearly, that will solve all the world's #cybersecurity problems. 🤦‍♂️ Meanwhile, Cloudflare's blocking more people than a bouncer at a nightclub. 🍻🔒
nvd.nist.gov/vuln/detail/cve-2 #ChromiumRCE #Cloudflare #Exploits #HackerNews #ngated

##

h4ckernews@mastodon.social at 2026-09-04T22:03:17.000Z ##

Actively exploited sandbox RCE in all Chromium versions

nvd.nist.gov/vuln/detail/cve-2

Comments: news.ycombinator.com/item?id=4

#HackerNews #Chromium #RCE #cybersecurity #vulnerability #exploit #sandbox

##

thenextweb@flipboard.com at 2026-09-04T21:03:38.000Z ##

Google patches multiple Chrome bugs including a V8 flaw being used in attacks
thenextweb.com/news/chrome-v8-

Posted into TNW - All Stories @tnw-all-stories-thenextweb

##

secdb@infosec.exchange at 2026-09-04T19:00:13.000Z ##

🚨 [CISA-2026:0904] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85046 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Type Confusion Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260904 #cisa20260904 #cve_2026_85046 #cve202685046

##

cisakevtracker@mastodon.social at 2026-09-04T18:00:57.000Z ##

CVE ID: CVE-2026-85046
Vendor: Google
Product: Chromium V8
Date Added: 2026-09-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-09-04T17:38:32.000Z ##

CISA has added one vulnerability to the KEV catalogue.

- CVE-2026-85046: Google Chromium V8 Type Confusion Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #Google #Chromium #vulnerability

##

security_crawler_carl@infosec.exchange at 2026-09-04T11:52:32.000Z ##

🏆 New Achievement! Type-Confused and Loving It!

Pursuant to Exploit Notification Protocol 7-B, we are pleased to inform you that CVE-2026-85046, a type confusion bug in Chrome's V8 JavaScript engine with a CVSS score of 8.8, is actively being used against users in the wild. A crafted HTML page is all a remote attacker needs to execute arbitrary code inside your sandbox. Per policy, we have logged this as a High Priority Awareness Event and done absolutely nothing else. (1/2)

##

youranonnewsirc@nerdculture.de at 2026-09-04T10:26:25.000Z ##

Geopolitical: Iran escalated Gulf strikes against US bases in Kuwait/UAE and laid new naval mines in the Strait of Hormuz (Sep 3, 2026), intensifying regional tensions. Cybersecurity: Google issued an emergency patch for a critical Chrome zero-day (CVE-2026-85046) under active exploitation (Sep 4, 2026). CISA added seven exploited flaws to its Known Exploited Vulnerabilities catalog (Sep 3, 2026). Tech: Google launched Gemini 3.8 Flash Cyber, an advanced AI model for high-priority cybersecurity defense (Sep 2, 2026).

#AnonNews_irc #Cybersecurity #News

##

cyberworldops@infosec.exchange at 2026-09-04T10:10:00.000Z ##

Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content. #ChromeSecurity #VulnerabilityManagement #ZeroDay

cyberworldops.eu/en/chrome-fix

##

guru@thecybersecguru.com at 2026-09-04T08:54:19.000Z ##

Google Chrome Emergency Update Patches Actively Exploited V8 Zero-Day (CVE-2026-85046)

CVE-2026-85046 is a V8 type confusion zero-day already exploited in Chrome. Here's how the read/write primitive works, and how to patch immediately

thecybersecguru.com/news/cve-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-03T21:47:57.000Z ##

Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).

#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046

securityonline.info/chrome-zer

##

CVE-2026-85654
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-04T18:31:46

2 posts

Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file.

thehackerwire@mastodon.social at 2026-09-04T22:00:43.000Z ##

🟠 CVE-2026-85654 - High (7.8)

Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated ap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T22:00:43.000Z ##

🟠 CVE-2026-85654 - High (7.8)

Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated ap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85656
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-04T18:31:46

2 posts

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.

thehackerwire@mastodon.social at 2026-09-04T22:00:31.000Z ##

🟠 CVE-2026-85656 - High (7.8)

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T22:00:31.000Z ##

🟠 CVE-2026-85656 - High (7.8)

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9317
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-04T18:31:46

2 posts

Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with network access to the runner port can send requests to the unauthenticated start procedure, bypassing the unenforced RUNNER_SECRET_KEY environment variable

thehackerwire@mastodon.social at 2026-09-04T20:01:15.000Z ##

🟠 CVE-2026-9317 - High (8.1)

Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with ne...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T20:01:15.000Z ##

🟠 CVE-2026-9317 - High (8.1)

Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with ne...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18175
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-04T18:31:33

2 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.

thehackerwire@mastodon.social at 2026-09-04T18:00:31.000Z ##

🟠 CVE-2026-18175 - High (8.1)

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T18:00:31.000Z ##

🟠 CVE-2026-18175 - High (8.1)

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18221
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-04T18:31:31

2 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.

thehackerwire@mastodon.social at 2026-09-04T18:00:42.000Z ##

🟠 CVE-2026-18221 - High (8.1)

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T18:00:42.000Z ##

🟠 CVE-2026-18221 - High (8.1)

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5522
(6.7 MEDIUM)

EPSS: 0.00%

updated 2026-09-04T18:31:22

2 posts

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

CVE-2026-85455
(8.2 HIGH)

EPSS: 0.36%

updated 2026-09-04T18:18:03.183000

2 posts

MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted short packet to read memory before authentication.

thehackerwire@mastodon.social at 2026-09-04T00:00:32.000Z ##

🟠 CVE-2026-85455 - High (8.2)

MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T00:00:32.000Z ##

🟠 CVE-2026-85455 - High (8.2)

MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85224
(9.1 CRITICAL)

EPSS: 2.15%

updated 2026-09-04T18:18:02.177000

2 posts

A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

thehackerwire@mastodon.social at 2026-09-03T23:01:10.000Z ##

🔴 CVE-2026-85224 - Critical (9.1)

A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T23:01:10.000Z ##

🔴 CVE-2026-85224 - Critical (9.1)

A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82538
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-04T18:18:01.357000

2 posts

ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and b

thehackerwire@mastodon.social at 2026-09-04T23:02:56.000Z ##

🟠 CVE-2026-82538 - High (8.8)

ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T23:02:56.000Z ##

🟠 CVE-2026-82538 - High (8.8)

ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84292
(7.5 HIGH)

EPSS: 0.23%

updated 2026-09-04T16:26:33.360000

1 posts

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read

thehackerwire@mastodon.social at 2026-09-02T22:59:49.000Z ##

🟠 CVE-2026-84292 - High (7.5)

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85699
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-04T15:36:24

2 posts

jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network addresses or cloud metadata endpoints, allowing the server to fetch and return the target's response body to the attacker.

thehackerwire@mastodon.social at 2026-09-04T16:00:42.000Z ##

🟠 CVE-2026-85699 - High (7.5)

jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T16:00:42.000Z ##

🟠 CVE-2026-85699 - High (7.5)

jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85691
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-04T15:36:17

2 posts

MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authentication to read their responses directly from the JSON response.

thehackerwire@mastodon.social at 2026-09-04T16:00:53.000Z ##

🟠 CVE-2026-85691 - High (7.5)

MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authenticat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T16:00:53.000Z ##

🟠 CVE-2026-85691 - High (7.5)

MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authenticat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85696
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-04T15:17:48.523000

2 posts

SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted arguments and execute arbitrary system commands when video generation occurs.

thehackerwire@mastodon.social at 2026-09-04T16:00:31.000Z ##

🔴 CVE-2026-85696 - Critical (9.8)

SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the fi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T16:00:31.000Z ##

🔴 CVE-2026-85696 - Critical (9.8)

SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the fi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81838
(7.1 HIGH)

EPSS: 0.13%

updated 2026-09-04T13:51:20.710000

2 posts

A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform inappropriate actions in the diagram bundle. To remediate this issue, users should up

awssecurityfeed at 2026-09-04T17:45:01.263Z ##

CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)

Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT
Description:
awsdac (diagram-as-code) is a CLI tool that generates AWS architecture diagrams from YAML d...

aws.amazon.com/security/securi

##

awssecurityfeed@infosec.exchange at 2026-09-04T17:45:01.000Z ##

CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)

Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT
Description:
awsdac (diagram-as-code) is a CLI tool that generates AWS architecture diagrams from YAML d...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-62928
(9.8 CRITICAL)

EPSS: 1.22%

updated 2026-09-04T09:32:01

2 posts

XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.

thehackerwire@mastodon.social at 2026-09-04T08:00:25.000Z ##

🔴 CVE-2026-62928 - Critical (9.8)

XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T08:00:25.000Z ##

🔴 CVE-2026-62928 - Critical (9.8)

XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85085
(9.6 CRITICAL)

EPSS: 0.22%

updated 2026-09-04T09:31:59

2 posts

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.

thehackerwire@mastodon.social at 2026-09-04T08:00:04.000Z ##

🔴 CVE-2026-85085 - Critical (9.6)

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T08:00:04.000Z ##

🔴 CVE-2026-85085 - Critical (9.6)

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85506
(9.8 CRITICAL)

EPSS: 0.39%

updated 2026-09-04T06:31:31

2 posts

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

thehackerwire@mastodon.social at 2026-09-04T07:03:45.000Z ##

🔴 CVE-2026-85506 - Critical (9.8)

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T07:03:45.000Z ##

🔴 CVE-2026-85506 - Critical (9.8)

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85505
(7.5 HIGH)

EPSS: 0.34%

updated 2026-09-04T06:31:31

2 posts

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).

thehackerwire@mastodon.social at 2026-09-04T07:03:34.000Z ##

🟠 CVE-2026-85505 - High (7.5)

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has differe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T07:03:34.000Z ##

🟠 CVE-2026-85505 - High (7.5)

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has differe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85504
(9.8 CRITICAL)

EPSS: 0.39%

updated 2026-09-04T06:31:24

2 posts

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

thehackerwire@mastodon.social at 2026-09-04T07:03:24.000Z ##

🔴 CVE-2026-85504 - Critical (9.8)

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T07:03:24.000Z ##

🔴 CVE-2026-85504 - Critical (9.8)

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85148
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-09-04T03:31:08

2 posts

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.

thehackerwire@mastodon.social at 2026-09-04T04:02:17.000Z ##

🔴 CVE-2026-85148 - Critical (9.8)

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T04:02:17.000Z ##

🔴 CVE-2026-85148 - Critical (9.8)

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75754(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-09-04T03:31:07

4 posts

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of

DailyCyberSecurity at 2026-09-04T17:13:05.383Z ##

An ASUS Control Center vulnerability, CVE-2026-75754 (CVSS 10), gives unauthenticated attackers a root shell. Update to v3.1.0.9 now.

securityonline.info/asus-contr

##

cR0w at 2026-09-04T03:21:07.015Z ##

These bugdoors are getting lazy.

cve.org/CVERecord?id=CVE-2026-

sev:CRIT 10.0 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of data on ASUS Control Center, as well as remote control of all servers, PCs, and workstations within the company. Refer to the 'Security Update for ASUS Control Center' section on the ASUS Security Advisory for more information.

##

DailyCyberSecurity@infosec.exchange at 2026-09-04T17:13:05.000Z ##

An ASUS Control Center vulnerability, CVE-2026-75754 (CVSS 10), gives unauthenticated attackers a root shell. Update to v3.1.0.9 now.

#ASUS #CVE202675754 #RCE #ControlCenter #RootShell #CVSS10 #Infosec #PatchNow

securityonline.info/asus-contr

##

cR0w@infosec.exchange at 2026-09-04T03:21:07.000Z ##

These bugdoors are getting lazy.

cve.org/CVERecord?id=CVE-2026-

sev:CRIT 10.0 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of data on ASUS Control Center, as well as remote control of all servers, PCs, and workstations within the company. Refer to the 'Security Update for ASUS Control Center' section on the ASUS Security Advisory for more information.

##

CVE-2026-85146
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-09-04T03:31:07

2 posts

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.

thehackerwire@mastodon.social at 2026-09-04T04:02:28.000Z ##

🔴 CVE-2026-85146 - Critical (9.8)

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application sou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T04:02:28.000Z ##

🔴 CVE-2026-85146 - Critical (9.8)

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application sou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79755
(8.0 HIGH)

EPSS: 0.40%

updated 2026-09-04T03:17:42.220000

1 posts

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpolated—unvalidated—into a double-quoted docker ps --filter "label=nuclio.io/namespace=<value>" command that is executed via the host shell (/bin/sh -c). Because the default auth kind is nop (unauthenticated), a remote attacker ca

thehackerwire@mastodon.social at 2026-09-02T17:59:59.000Z ##

🟠 CVE-2026-79755 - High (8)

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpolated—unvalidated—into a double-quoted docker ps --filter "label=nuclio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85451
(7.1 HIGH)

EPSS: 0.22%

updated 2026-09-04T00:31:17

1 posts

MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS processes and send termination commands to trigger process shutdown by exploiting the default multicast group and port with the known passphrase.

hugovalters@mastodon.social at 2026-09-04T15:40:01.000Z ##

CVE-2026-85451: MOOS core-moos ≤10.4.0 has a hard-coded passphrase enabling remote process termination via multicast. Any reachable peer can kill processes—no patch available. CVSS 7.1. Update immediately or isolate multicast. valtersit.com/cve/CVE-2026-854 #CVE #infosec #MOOS

##

CVE-2026-67398(CVSS UNKNOWN)

EPSS: 0.25%

updated 2026-09-04T00:31:17

2 posts

Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.

DailyCyberSecurity at 2026-09-04T01:46:22.600Z ##

A critical WHMCS security update fixes CVE-2026-67399 and CVE-2026-67398. Apply the patch now to prevent remote code execution and data leaks.

securityonline.info/whmcs-secu

##

DailyCyberSecurity@infosec.exchange at 2026-09-04T01:46:22.000Z ##

A critical WHMCS security update fixes CVE-2026-67399 and CVE-2026-67398. Apply the patch now to prevent remote code execution and data leaks.

#WHMCS #CyberSecurity #CVE202667399 #CVE202667398 #InfoSec

securityonline.info/whmcs-secu

##

CVE-2026-18167(CVSS UNKNOWN)

EPSS: 0.27%

updated 2026-09-04T00:31:11

2 posts

A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device. Successful exploitation may cause the EasyMesh daemon to crash and may potentially allow remote code execution when Mesh

CVE-2026-85452
(8.8 HIGH)

EPSS: 0.38%

updated 2026-09-04T00:31:11

2 posts

MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply arbitrarily long MOOS identifiers that overflow the buffers when an operator selects process list entries or pokes variables, enabling code execution.

thehackerwire@mastodon.social at 2026-09-04T00:00:21.000Z ##

🟠 CVE-2026-85452 - High (8.8)

MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T00:00:21.000Z ##

🟠 CVE-2026-85452 - High (8.8)

MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85450
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-04T00:31:11

2 posts

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server threads and memory, causing service unavailability.

thehackerwire@mastodon.social at 2026-09-04T00:00:10.000Z ##

🟠 CVE-2026-85450 - High (7.5)

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T00:00:10.000Z ##

🟠 CVE-2026-85450 - High (7.5)

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85223
(9.9 CRITICAL)

EPSS: 1.63%

updated 2026-09-04T00:31:10

3 posts

A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.

hugovalters@mastodon.social at 2026-09-04T11:08:56.000Z ##

CVE-2026-85223 - Critical OS Command Injection in D-Link DNS-340L. Remote exploit public via dropbox.cgi. CVSS 9.9. Isolate affected devices now. #CVE #DLink #infosec

valtersit.com/cve/CVE-2026-852

##

thehackerwire@mastodon.social at 2026-09-03T23:00:59.000Z ##

🔴 CVE-2026-85223 - Critical (9.9)

A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T23:00:59.000Z ##

🔴 CVE-2026-85223 - Critical (9.9)

A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64200
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-04T00:31:10

2 posts

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.

thehackerwire@mastodon.social at 2026-09-03T23:02:16.000Z ##

🟠 CVE-2026-64200 - High (7.8)

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T23:02:16.000Z ##

🟠 CVE-2026-64200 - High (7.8)

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64198
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-04T00:31:10

2 posts

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.

thehackerwire@mastodon.social at 2026-09-03T23:01:56.000Z ##

🟠 CVE-2026-64198 - High (7.8)

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T23:01:56.000Z ##

🟠 CVE-2026-64198 - High (7.8)

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64197
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-04T00:31:10

2 posts

There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.

thehackerwire@mastodon.social at 2026-09-03T23:01:19.000Z ##

🟠 CVE-2026-64197 - High (7.8)

There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a spec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T23:01:19.000Z ##

🟠 CVE-2026-64197 - High (7.8)

There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a spec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85428
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-09-03T23:17:21.770000

1 posts

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.

hugovalters@mastodon.social at 2026-09-04T12:00:01.000Z ##

CVE-2026-85428: Critical auth bypass in MOOS core-moos ≤10.4.0. Unauthenticated attackers can write variables via MOOSDB HTTP server, hijacking actuators/overrides. CVSS 9.8. Unpatched. If you run MOOS, disable HTTP or restrict access NOW. Details: valtersit.com/cve/CVE-2026-854 #CVE #infosec #OTsecurity

##

CVE-2026-85388
(8.1 HIGH)

EPSS: 0.28%

updated 2026-09-03T21:31:20

2 posts

Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolean-based blind SQL injection techniques to extract sensitive database content including password hashes from other tenants. This is an incomplete fix for

thehackerwire@mastodon.social at 2026-09-03T20:01:26.000Z ##

🟠 CVE-2026-85388 - High (8.1)

Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T20:01:26.000Z ##

🟠 CVE-2026-85388 - High (8.1)

Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85396
(7.5 HIGH)

EPSS: 0.38%

updated 2026-09-03T21:31:20

2 posts

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.

thehackerwire@mastodon.social at 2026-09-03T20:00:41.000Z ##

🟠 CVE-2026-85396 - High (7.5)

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T20:00:41.000Z ##

🟠 CVE-2026-85396 - High (7.5)

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85394
(9.1 CRITICAL)

EPSS: 0.22%

updated 2026-09-03T21:31:16

2 posts

python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an incomplete fix for CVE-2024-33663.

thehackerwire@mastodon.social at 2026-09-03T20:00:30.000Z ##

🔴 CVE-2026-85394 - Critical (9.1)

python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T20:00:30.000Z ##

🔴 CVE-2026-85394 - Critical (9.1)

python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85391
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-09-03T21:31:15

2 posts

Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints without credentials.

thehackerwire@mastodon.social at 2026-09-03T20:01:36.000Z ##

🔴 CVE-2026-85391 - Critical (9.8)

Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T20:01:36.000Z ##

🔴 CVE-2026-85391 - Critical (9.8)

Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85028
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-03T21:31:15

2 posts

Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own pr

thehackerwire@mastodon.social at 2026-09-03T20:01:16.000Z ##

🟠 CVE-2026-85028 - High (7.8)

Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T20:01:16.000Z ##

🟠 CVE-2026-85028 - High (7.8)

Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85393
(7.5 HIGH)

EPSS: 0.20%

updated 2026-09-03T20:17:28.747000

2 posts

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894.

thehackerwire@mastodon.social at 2026-09-03T20:00:21.000Z ##

🟠 CVE-2026-85393 - High (7.5)

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T20:00:21.000Z ##

🟠 CVE-2026-85393 - High (7.5)

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82404
(8.3 HIGH)

EPSS: 0.40%

updated 2026-09-03T19:52:09

1 posts

### Summary Decoding attacker-controlled TOON containing a `__proto__`, `constructor`, or `prototype` key wrote through the object's prototype chain instead of creating an own property, polluting `Object.prototype` for the whole runtime. The `expandPaths: 'safe'` path (dotted keys such as `a.__proto__.x`) was the strongest vector; plain nested objects, tabular rows, and quoted keys were all affec

thehackerwire@mastodon.social at 2026-09-02T17:59:49.000Z ##

🟠 CVE-2026-82404 - High (8.3)

TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote through the object prototype chain instead of creating an own pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83959
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-03T18:31:58

2 posts

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

thehackerwire@mastodon.social at 2026-09-03T19:00:19.000Z ##

🟠 CVE-2026-83959 - High (7.8)

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T19:00:19.000Z ##

🟠 CVE-2026-83959 - High (7.8)

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12555(CVSS UNKNOWN)

EPSS: 0.24%

updated 2026-09-03T18:31:29

1 posts

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

_r_netsec@infosec.exchange at 2026-09-02T21:28:05.000Z ##

Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) ciphersecuritylabs.com/researc

##

CVE-2026-12556(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-09-03T18:31:29

1 posts

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

_r_netsec@infosec.exchange at 2026-09-02T21:28:05.000Z ##

Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) ciphersecuritylabs.com/researc

##

CVE-2026-66786
(9.1 CRITICAL)

EPSS: 0.74%

updated 2026-09-03T18:12:56.407000

1 posts

A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdo

thehackerwire@mastodon.social at 2026-09-03T00:00:09.000Z ##

🔴 CVE-2026-66786 - Critical (9.1)

A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85216
(0 None)

EPSS: 0.48%

updated 2026-09-03T16:45:08.223000

2 posts

MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but did not replicate its credential validation checks. As a result, empty or non-string values could reach the underlying a

cR0w at 2026-09-03T16:34:01.161Z ##

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.5 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but did not replicate its credential validation checks. As a result, empty or non-string values could reach the underlying authentication mechanisms. In the LDAP authentication path, an attacker able to identify a valid directory user's email address could submit an empty password. The empty credential could be passed to ldap_bind(), where an LDAP server accepting unauthenticated binds may return a successful result for a valid distinguished name combined with an empty password. MISP could consequently treat the attacker as the corresponding authenticated directory user without verification of the user's password. The issue also affected the LinOTP authentication component. Invalid credential types were not rejected before being processed, and when mixed authentication was enabled, an empty password could be checked against a locally stored MISP password hash. LDAP-provisioned MISP accounts could additionally be created with an empty local password because account creation skipped normal validation, resulting in a hash corresponding to an empty password. This could permit authentication through the local fallback mechanism when such an account was no longer resolved through LDAP. Successful exploitation could allow a remote unauthenticated attacker to impersonate an existing MISP user. If the targeted account has administrative or other privileged permissions, the attacker could gain corresponding access to sensitive threat-intelligence data, modify or delete information, alter configuration, or perform other privileged operations. The patch resolves the vulnerability by requiring authentication identifiers and passwords to be valid strings, rejecting empty passwords where they are not explicitly permitted, and assigning a randomly generated local password to LDAP-provisioned accounts instead of storing a hash derived from an empty password.

##

cR0w@infosec.exchange at 2026-09-03T16:34:01.000Z ##

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.5 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but did not replicate its credential validation checks. As a result, empty or non-string values could reach the underlying authentication mechanisms. In the LDAP authentication path, an attacker able to identify a valid directory user's email address could submit an empty password. The empty credential could be passed to ldap_bind(), where an LDAP server accepting unauthenticated binds may return a successful result for a valid distinguished name combined with an empty password. MISP could consequently treat the attacker as the corresponding authenticated directory user without verification of the user's password. The issue also affected the LinOTP authentication component. Invalid credential types were not rejected before being processed, and when mixed authentication was enabled, an empty password could be checked against a locally stored MISP password hash. LDAP-provisioned MISP accounts could additionally be created with an empty local password because account creation skipped normal validation, resulting in a hash corresponding to an empty password. This could permit authentication through the local fallback mechanism when such an account was no longer resolved through LDAP. Successful exploitation could allow a remote unauthenticated attacker to impersonate an existing MISP user. If the targeted account has administrative or other privileged permissions, the attacker could gain corresponding access to sensitive threat-intelligence data, modify or delete information, alter configuration, or perform other privileged operations. The patch resolves the vulnerability by requiring authentication identifiers and passwords to be valid strings, rejecting empty passwords where they are not explicitly permitted, and assigning a randomly generated local password to LDAP-provisioned accounts instead of storing a hash derived from an empty password.

##

CVE-2026-20277
(8.2 HIGH)

EPSS: 0.22%

updated 2026-09-03T16:37:52.170000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20277 are related to protection mechanism failure issues that

thehackerwire@mastodon.social at 2026-09-03T12:01:31.000Z ##

🟠 CVE-2026-20277 - High (8.2)

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12554
(0 None)

EPSS: 0.21%

updated 2026-09-03T16:17:23.247000

1 posts

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

_r_netsec@infosec.exchange at 2026-09-02T21:28:05.000Z ##

Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) ciphersecuritylabs.com/researc

##

CVE-2023-54391
(9.8 CRITICAL)

EPSS: 0.47%

updated 2026-09-03T15:33:10

1 posts

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with a

2 repos

https://github.com/disqualifier/psa-2026-00043-recovery

https://github.com/neeythann/Proxmox-VE-7-RCE

CVE-2026-85175
(8.8 HIGH)

EPSS: 0.19%

updated 2026-09-03T15:32:28

1 posts

SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/key.pem) or CA private key (conf/ca.key) stored in the same conf/ directory. Because the getFile handler skips the blocklist for RoleAdministrator and all authenti

thehackerwire@mastodon.social at 2026-09-03T14:00:24.000Z ##

🟠 CVE-2026-85175 - High (8.8)

SiYuan versions &lt;= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/key.pem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85174
(8.8 HIGH)

EPSS: 0.30%

updated 2026-09-03T15:32:28

1 posts

SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access.

thehackerwire@mastodon.social at 2026-09-03T14:00:12.000Z ##

🟠 CVE-2026-85174 - High (8.8)

SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9586
(9.8 CRITICAL)

EPSS: 11.85%

updated 2026-09-03T13:06:25.427000

16 posts

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL

Nuclei template

1 repos

https://github.com/HORKimhab/CVE-2026-9586

Matchbook3469@mastodon.social at 2026-09-04T18:53:11.000Z ##

🔵 THREAT INTELLIGENCE

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Vulnerability | CRITICAL
CVEs: CVE-2026-9586

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead...

Full analysis:
yazoul.net/news/article/hacker

by Yazoul AI

#ThreatIntel #Malware #SecurityOps

##

undercodenews@mastodon.social at 2026-09-04T18:39:00.000Z ##

CISA Warns of Active Switchvox Attacks as Critical CVE-2026-9586 Puts Internet-Facing VoIP Systems at Risk + Video

A Quiet VoIP Vulnerability Turns Into an Active Security Emergency A vulnerability hidden inside an enterprise phone-management platform has now moved from security research into the real world. CVE-2026-9586, a critical unauthenticated SQL injection flaw affecting Sangoma Switchvox, is being actively exploited against internet-facing systems, according to…

undercodenews.com/cisa-warns-o

##

undercodenews@mastodon.social at 2026-09-04T18:23:20.000Z ##

Critical Sangoma Switchvox Vulnerability Is Being Exploited: What Organizations Need to Know About CVE-2026-9586 + Video

A New Cybersecurity Warning With Real-World Consequences The cybersecurity landscape rarely gives defenders much time to breathe. A vulnerability can move from a technical discovery to an active attack campaign in a matter of days, and CVE-2026-9586 is a powerful example of how quickly that transition can happen. Security researchers have confirmed…

undercodenews.com/critical-san

##

security_crawler_carl at 2026-09-04T17:10:37.201Z ##

🏆 New Achievement! The Court Finds Switchvox Guilty of Existing on the Internet!

This tribunal hereby enters judgment against Sangoma Switchvox SMB Edition 8.3, charged with one count of catastrophic negligence via CVE-2026-9586. The evidence: a /pa endpoint that concatenates raw phone IP values directly into database queries — no sanitization, no credentials required — handing any passerby PostgreSQL superuser rights. (1/2)

##

cyberveille@mastobot.ping.moi at 2026-09-04T15:30:04.000Z ##

📢 Exploitation active de CVE-2026-9586 dans Sangoma Switchvox pour déployer des reverse shells

BleepingComputer, publié le 2 septembre 2026. Des chercheurs de Horizon3 ont observé l'exploitation active de CVE-2026-9586, une vulnérabilité critique d'injection SQL non authentifiée affectant la plateforme VoIP d'entreprise Sangoma Switchvox.

📖 cyberveille : cyberveille.ch/posts/2026-09-0
🌐 source : bleepingcomputer.com/news/secu
🟢 vérification factuelle haute
#ReverseShell #SangomaSwitchvox #Cyberveille

##

cyberworldops at 2026-09-04T14:20:00.848Z ##

Horizon3 reports active exploitation of CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox allowing remote code execution via a single request. Internet-exposed PBX systems should be patched immediately and checked for intrusion using published IoCs.

cyberworldops.eu/en/sangoma-sw

##

DailyCyberSecurity at 2026-09-04T14:16:12.594Z ##

Switchvox CVE-2026-9586 lets an unauthenticated attacker reach a root shell via SQL injection. Active exploitation seen; patch to 8.4.0.2.

meterpreter.org/switchvox-cve-

##

security_crawler_carl@infosec.exchange at 2026-09-04T17:10:37.000Z ##

🏆 New Achievement! The Court Finds Switchvox Guilty of Existing on the Internet!

This tribunal hereby enters judgment against Sangoma Switchvox SMB Edition 8.3, charged with one count of catastrophic negligence via CVE-2026-9586. The evidence: a /pa endpoint that concatenates raw phone IP values directly into database queries — no sanitization, no credentials required — handing any passerby PostgreSQL superuser rights. (1/2)

##

cyberworldops@infosec.exchange at 2026-09-04T14:20:00.000Z ##

Horizon3 reports active exploitation of CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox allowing remote code execution via a single request. Internet-exposed PBX systems should be patched immediately and checked for intrusion using published IoCs. #Switchvox #SqlInjection #RemoteCodeExecution

cyberworldops.eu/en/sangoma-sw

##

DailyCyberSecurity@infosec.exchange at 2026-09-04T14:16:12.000Z ##

Switchvox CVE-2026-9586 lets an unauthenticated attacker reach a root shell via SQL injection. Active exploitation seen; patch to 8.4.0.2.

#Switchvox #CVE20269586 #RCE #SQLInjection #Sangoma #VoIP #InfoSec

meterpreter.org/switchvox-cve-

##

beyondmachines1@infosec.exchange at 2026-09-03T08:01:29.000Z ##

Attackers Exploit Critical Sangoma Switchvox Flaw to Deploy Reverse Shells

Sangoma patched 12 vulnerabilities in Switchvox, including a critical unauthenticated SQL injection (CVE-2026-9586) that attackers are currently using to gain remote code execution and steal authentication keys.

**If you run Sangoma Switchvox, first make sure it isn't reachable from the internet and can only be accessed from trusted networks, then update immediately to version 8.4.0.2. Anything on version 8.3 or earlier is being actively attacked. Because attackers have been stealing keys, tokens and user data, also check /var/log/switchvox/db-quirks.log for signs of SQL injection, block the IP 176.65.148.184, and reset passwords and signing keys if you find anything suspicious.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

oversecurity@mastodon.social at 2026-09-02T21:40:30.000Z ##

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can...

🔗️ [Bleepingcomputer] link.is.it/o3uhXX

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:58.000Z ##

CVE ID: CVE-2026-9586
Vendor: Sangoma
Product: Switchvox
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops@infosec.exchange at 2026-09-02T10:10:00.000Z ##

Active exploitation attempts are targeting CVE-2026-9586, a critical unauthenticated SQL injection in Sangoma Switchvox SMB Edition. A single crafted request enables arbitrary SQL execution on PostgreSQL and leads to remote code execution via reverse shell. Immediate patching and exposure review are critical. #Switchvox #SqlInjection #ThreatIntel

cyberworldops.eu/en/switchvox-

##

CVE-2026-85154
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-09-03T13:06:22.067000

1 posts

WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes

thehackerwire@mastodon.social at 2026-09-03T14:00:35.000Z ##

🔴 CVE-2026-85154 - Critical (9.8)

WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20280
(8.8 HIGH)

EPSS: 0.27%

updated 2026-09-03T13:04:39.930000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the&nbsp;Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20280 are related to improper checking or handling of exc

hugovalters@mastodon.social at 2026-09-03T11:04:46.000Z ##

CVE-2026-20280 - High severity flaw in Cisco IOS XR Software. Improper handling of exceptional conditions (CWE-703). CVSS 8.8. Update immediately. #CVE #Cisco #infosec

valtersit.com/cve/CVE-2026-202

##

CVE-2026-20275
(8.8 HIGH)

EPSS: 0.18%

updated 2026-09-03T13:04:39.407000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20275 are related to incorrect calculation issues that are gro

AAKL@infosec.exchange at 2026-09-02T16:36:40.000Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s #Broadcom

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-14828
(8.8 HIGH)

EPSS: 1.44%

updated 2026-09-03T13:04:35.017000

1 posts

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

thehackerwire@mastodon.social at 2026-09-02T11:00:25.000Z ##

🟠 CVE-2026-14828 - High (8.8)

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19117
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-09-02T21:32:07

2 posts

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

thehackerwire@mastodon.social at 2026-09-02T23:02:33.000Z ##

🔴 CVE-2026-19117 - Critical (9.8)

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as
that user. This issue affects on-premises deployments only.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-09-02T21:46:36.000Z ##

Credential managers are so hot right now. Here's Delinea's on-prem offering.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

##

CVE-2026-20276
(8.6 HIGH)

EPSS: 0.25%

updated 2026-09-02T18:32:31

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issues

AAKL@infosec.exchange at 2026-09-02T16:36:40.000Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s #Broadcom

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-20274
(9.8 CRITICAL)

EPSS: 0.67%

updated 2026-09-02T18:32:31

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are g

AAKL@infosec.exchange at 2026-09-02T16:36:40.000Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s #Broadcom

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-20212
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-02T18:32:26

11 posts

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and

1 repos

https://github.com/HORKimhab/CVE-2026-20212

guru@thecybersecguru.com at 2026-09-04T05:42:20.000Z ##

Critical Cisco Nexus 9000 RCE Flaw (CVE-2026-20212) & IOS XR Hardening: Complete Technical Analysis and Remediation Guide

CVE-2026-20212 is a critical CVSS 9.8 unauthenticated RCE affecting specific Cisco Nexus 9000 switches. Check affected models, NX-OS versions and fixes

thecybersecguru.com/news/cve-2

##

cyberworldops at 2026-09-03T22:20:01.181Z ##

Cisco disclosed CVE-2026-20212, a critical unauthenticated RCE in Silicon One on Nexus 9000 switches. Exploitation yields root execution via crafted data, putting core data-center fabric at risk of full compromise.

cyberworldops.eu/en/cisco-nexu

##

undercodenews@mastodon.social at 2026-09-03T21:27:17.000Z ##

Cisco’s Critical Nexus 9000 Flaw Exposes a Dangerous Path to Root Access + Video

A New Warning for Network Administrators A critical security flaw in certain Cisco Nexus 9000 switches has turned the spotlight back toward one of the most important lessons in modern infrastructure security: even highly specialized network hardware can contain vulnerabilities capable of giving an attacker complete control. Cisco has released security updates for CVE-2026-20212, a…

undercodenews.com/ciscos-criti

##

threatnoir at 2026-09-03T21:05:54.033Z ##

⚠️ CRITICAL: Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco released patches for CVE-2026-20212, a critical unauthenticated remote code execution vulnerability in Nexus 9000 switches (10 Silicon One-based models). Attackers can exploit this via TCP ports 43210 and 43211 to execute commands as root. If you run affected Nexus 9000 hardware, this is imme…

threatnoir.com/focus

🤖 AI generated summary

##

undercodenews@mastodon.social at 2026-09-03T20:53:05.000Z ##

Cisco Nexus 9000 Critical Flaw Exposes Silicon One Switches to Root-Level Remote Code Execution + Video

A Dangerous New Warning for Data Center Networks A critical vulnerability in Cisco Nexus 9000 Series switches has turned a routine software security update into an urgent priority for organizations operating affected data center infrastructure. Tracked as CVE-2026-20212, the flaw carries a CVSS score of 9.8 and can allow an unauthenticated remote attacker to execute…

undercodenews.com/cisco-nexus-

##

Analyst207@mastodon.social at 2026-09-03T17:29:20.000Z ##

Cisco Discloses Critical Flaw in Nexus 9000 Switches

Cisco has uncovered a critical flaw in its Nexus 9000 switches, known as CVE-2026-20212, which could allow an unauthenticated attacker to remotely execute code as root. This vulnerability affects 10 specific models and has already been patched by the company.

osintsights.com/cisco-disclose

#Cisco #Nexus9000 #Cve202620212 #RemoteCodeExecution #SiliconOne

##

guru@thecybersecguru.com at 2026-09-04T05:42:20.000Z ##

Critical Cisco Nexus 9000 RCE Flaw (CVE-2026-20212) & IOS XR Hardening: Complete Technical Analysis and Remediation Guide

CVE-2026-20212 is a critical CVSS 9.8 unauthenticated RCE affecting specific Cisco Nexus 9000 switches. Check affected models, NX-OS versions and fixes

thecybersecguru.com/news/cve-2

##

cyberworldops@infosec.exchange at 2026-09-03T22:20:01.000Z ##

Cisco disclosed CVE-2026-20212, a critical unauthenticated RCE in Silicon One on Nexus 9000 switches. Exploitation yields root execution via crafted data, putting core data-center fabric at risk of full compromise. #CiscoNexus #SiliconOne #NetworkSecurity

cyberworldops.eu/en/cisco-nexu

##

threatnoir@infosec.exchange at 2026-09-03T21:05:54.000Z ##

⚠️ CRITICAL: Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco released patches for CVE-2026-20212, a critical unauthenticated remote code execution vulnerability in Nexus 9000 switches (10 Silicon One-based models). Attackers can exploit this via TCP ports 43210 and 43211 to execute commands as root. If you run affected Nexus 9000 hardware, this is imme…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

DailyCyberSecurity@infosec.exchange at 2026-09-03T03:39:50.000Z ##

CVE-2026-20212, a critical Cisco Nexus 9000 vulnerability, lets an unauthenticated attacker gain remote code execution with root privileges. CVSS 9.8.

#Cisco #Nexus9000 #SiliconOne #RCE #NXOS #NetworkSecurity #InfoSec #PatchNow

securityonline.info/cisco-nexu

##

AAKL@infosec.exchange at 2026-09-02T16:36:40.000Z ##

New security advisories.

Broadcom has addressed several vulnerabilities,two of them critical support.broadcom.com/web/ecx/s #Broadcom

Cisco: Five advisories, two of them addressing critical vulnerabilities:

- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

More: sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-78689
(8.1 HIGH)

EPSS: 0.41%

updated 2026-09-02T18:32:17

1 posts

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list cau

cR0w@infosec.exchange at 2026-09-02T19:12:01.000Z ##

I am fortunate enough to not know anything about NGINX JavaScript ( hashtag blessed ) but if you do, this might be of interest.

nvd.nist.gov/vuln/detail/cve-2

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list causes an out-of-bounds write past the end of a heap allocation. With the njs engine, which is the engine used when the js_engine directive is absent, this corrupts adjacent objects and crashes the NGINX worker. With the QuickJS engine, the same call additionally leaks the prefix list on every invocation, causing worker memory to grow across requests. The official nginxinc/nginx-saml reference implementation is affected during SAML signature verification. It reads InclusiveNamespaces/@PrefixList from an untrusted SAML message and passes it to xml.exclusiveC14n() before the signature has been verified, so a valid SAML signature is not required. A crafted SAML Response, Assertion, LogoutRequest, or LogoutResponse is sufficient. Code execution has not been demonstrated and cannot be ruled out for all platforms, as the effect of the out-of-bounds write depends on conditions beyond the attacker's control. Impact This vulnerability allows remote attackers to cause a denial of service on the NGINX system, either through repeatable worker restarts or through worker memory growth or possibly trigger code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

##

CVE-2026-83548
(10.0 CRITICAL)

EPSS: 0.71%

updated 2026-09-02T18:32:06

14 posts

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

2 repos

https://github.com/xcoy0te/CVE-2026-83548-checker

https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis

csaf at 2026-09-04T08:47:35.075Z ##

RE: social.bund.de/@certbund/11720

For a critical as example, here is the CSAF JSON file (from the Germans): wid.cert-bund.de/.well-known/c .

(For psirt.global.sonicwall.com/vul CVE-2026-83548, CVE-2026-83549 a CVSS v3 10.0 "critical" defect)

In the vulnerabilities and product_tree sections there are precise infos which version is affected. More structure than the vendor's version.

BTW, the version from the Netherland - advisories.ncsc.nl/csaf/v2/202 - does not have the affected versions, but they give the criticality.

So both could be improved and potentially they will with the next revsions. 😉

Still, if this runs directly in our IT Security Management system, this is much better and faster than manually reading the HTML or PDF advisories.

##

Analyst207@mastodon.social at 2026-09-03T23:29:12.000Z ##

Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances

SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.

osintsights.com/attackers-expl

#ZeroDay #Sonicwall #Cve202683548 #Cve202683549 #Sma1000

##

undercodenews@mastodon.social at 2026-09-03T22:31:48.000Z ##

SonicWall Under Siege Again: Two Zero-Days Turn the SMA 1000 Into a High-Risk Gateway for Attackers + Video

Introduction: Another Warning From the Network Edge SonicWall customers are once again facing a serious security crisis, and this time the danger is concentrated around the SonicWall SMA 1000 remote-access appliance. Two newly disclosed vulnerabilities, CVE-2026-83548 and CVE-2026-83549, are already being exploited in the wild, turning what should be a trusted…

undercodenews.com/sonicwall-un

##

csaf@infosec.exchange at 2026-09-04T08:47:35.000Z ##

RE: social.bund.de/@certbund/11720

For a critical #itsecurity #vulnerability as example, here is the CSAF JSON file (from the Germans): wid.cert-bund.de/.well-known/c .

(For psirt.global.sonicwall.com/vul CVE-2026-83548, CVE-2026-83549 a CVSS v3 10.0 "critical" defect)

In the vulnerabilities and product_tree sections there are precise infos which version is affected. More structure than the vendor's version.

BTW, the version from the Netherland - advisories.ncsc.nl/csaf/v2/202 - does not have the affected versions, but they give the criticality.

😉

##

AAKL@infosec.exchange at 2026-09-03T14:26:43.000Z ##

New.

Rapid7: Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild rapid7.com/blog/post/etr-criti @Rapid7Official #infosec #vulnerability #SonicWall

##

beyondmachines1@infosec.exchange at 2026-09-03T09:01:31.000Z ##

SonicWall Patches Chained Zero-Day Vulnerabilities in SMA 1000 Series VPNs

SonicWall has patched two zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its SMA 1000 series VPN appliances that attackers are chaining to achieve unauthenticated remote code execution.

**If you run SonicWall SMA 1000 appliances (models 6210, 7210, or 8200v), update immediately to version 12.4.3-03526 or 12.5.0-02952. These devices are actively attacked to take over VPN gateways. After patching review your logs for signs of compromise, if anything looks suspicious, re-image the appliance, change all passwords and reset TOTP tokens, and only restore backups from before the breach.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

ottoto2017@prattohome.com at 2026-09-03T05:14:11.000Z ##

「攻撃者がSonicWall SMA 1000の2つのゼロデイ脆弱性を悪用し、攻撃連鎖を形成する可能性 」: #TheHackerNews

「SonicWallは、ゼロデイ攻撃で悪用された、同社のSecure Mobile Access(SMA)1000シリーズVPNアプライアンスに影響を与える2つのセキュリティ上の欠陥に対処するためのセキュリティアップデートをリリースしました。

SonicWallのウィリアム・ペリー氏とアダム・バビス氏が社内で発見した脆弱 性は 以下のとおりです。

CVE-2026-83548 (CVSS スコア: 10.0)
CVE-2026-83549 (CVSS スコア: 7.8)

SonicWallは、「脆弱性が積極的に悪用されていることを示す事例を調査した」と述べ、攻撃者が両方のバグを組み合わせて、脆弱性のあるデバイス上で任意のコードを実行している可能性を示唆した。 」

thehackernews.com/2026/09/atta

#prattohome

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:02:13.000Z ##

CVE ID: CVE-2026-83548
Vendor: SonicWall
Product: SMA1000 Appliances
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cert_fr@social.numerique.gouv.fr at 2026-09-02T12:51:59.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

##

security_crawler_carl@infosec.exchange at 2026-09-02T07:13:42.000Z ##

🏆 New Achievement! By Continuing to Use This Appliance, You Agree to Be Owned!

Please note that Section 2, Paragraph 4 of your SMA1000 user agreement has been updated. By failing to patch CVE-2026-83548 — a pre-authentication SSRF flaw scoring a perfect 10.0 CVSS in the Appliance Work Place interface — you consent to unauthenticated strangers poking around your network. (1/2)

##

decio@infosec.exchange at 2026-09-02T07:06:36.000Z ##

Tiens, encore du #SonicWall SMA1000 ...

Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.

La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.

Sont concernés les SMA1000 6210, 7210 et 8200v.

Pas de workaround : hotfix à appliquer au plus vite. ☹️

Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.

À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.

Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃

Advisory 🩹
👇
psirt.global.sonicwall.com/vul

#CyberVeille

##

cyberworldops@infosec.exchange at 2026-09-02T06:20:01.000Z ##

SonicWall confirmed active exploitation of two zero-days in SMA1000 appliances, including pre-auth SSRF CVE-2026-83548. Chained, the flaws allow unauthenticated remote command execution on SSL-VPN gateways. Operators should patch immediately and hunt for post-exploitation activity. #SonicWall #ZeroDay #InfoSec

cyberworldops.eu/en/sonicwall-

##

CVE-2026-83549
(7.8 HIGH)

EPSS: 1.62%

updated 2026-09-02T18:32:06

13 posts

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

1 repos

https://github.com/xcoy0te/CVE-2026-83548-checker

csaf at 2026-09-04T08:47:35.075Z ##

RE: social.bund.de/@certbund/11720

For a critical as example, here is the CSAF JSON file (from the Germans): wid.cert-bund.de/.well-known/c .

(For psirt.global.sonicwall.com/vul CVE-2026-83548, CVE-2026-83549 a CVSS v3 10.0 "critical" defect)

In the vulnerabilities and product_tree sections there are precise infos which version is affected. More structure than the vendor's version.

BTW, the version from the Netherland - advisories.ncsc.nl/csaf/v2/202 - does not have the affected versions, but they give the criticality.

So both could be improved and potentially they will with the next revsions. 😉

Still, if this runs directly in our IT Security Management system, this is much better and faster than manually reading the HTML or PDF advisories.

##

Analyst207@mastodon.social at 2026-09-03T23:29:12.000Z ##

Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances

SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.

osintsights.com/attackers-expl

#ZeroDay #Sonicwall #Cve202683548 #Cve202683549 #Sma1000

##

undercodenews@mastodon.social at 2026-09-03T22:31:48.000Z ##

SonicWall Under Siege Again: Two Zero-Days Turn the SMA 1000 Into a High-Risk Gateway for Attackers + Video

Introduction: Another Warning From the Network Edge SonicWall customers are once again facing a serious security crisis, and this time the danger is concentrated around the SonicWall SMA 1000 remote-access appliance. Two newly disclosed vulnerabilities, CVE-2026-83548 and CVE-2026-83549, are already being exploited in the wild, turning what should be a trusted…

undercodenews.com/sonicwall-un

##

csaf@infosec.exchange at 2026-09-04T08:47:35.000Z ##

RE: social.bund.de/@certbund/11720

For a critical #itsecurity #vulnerability as example, here is the CSAF JSON file (from the Germans): wid.cert-bund.de/.well-known/c .

(For psirt.global.sonicwall.com/vul CVE-2026-83548, CVE-2026-83549 a CVSS v3 10.0 "critical" defect)

In the vulnerabilities and product_tree sections there are precise infos which version is affected. More structure than the vendor's version.

BTW, the version from the Netherland - advisories.ncsc.nl/csaf/v2/202 - does not have the affected versions, but they give the criticality.

😉

##

AAKL@infosec.exchange at 2026-09-03T14:26:43.000Z ##

New.

Rapid7: Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild rapid7.com/blog/post/etr-criti @Rapid7Official #infosec #vulnerability #SonicWall

##

beyondmachines1@infosec.exchange at 2026-09-03T09:01:31.000Z ##

SonicWall Patches Chained Zero-Day Vulnerabilities in SMA 1000 Series VPNs

SonicWall has patched two zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its SMA 1000 series VPN appliances that attackers are chaining to achieve unauthenticated remote code execution.

**If you run SonicWall SMA 1000 appliances (models 6210, 7210, or 8200v), update immediately to version 12.4.3-03526 or 12.5.0-02952. These devices are actively attacked to take over VPN gateways. After patching review your logs for signs of compromise, if anything looks suspicious, re-image the appliance, change all passwords and reset TOTP tokens, and only restore backups from before the breach.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

ottoto2017@prattohome.com at 2026-09-03T05:14:11.000Z ##

「攻撃者がSonicWall SMA 1000の2つのゼロデイ脆弱性を悪用し、攻撃連鎖を形成する可能性 」: #TheHackerNews

「SonicWallは、ゼロデイ攻撃で悪用された、同社のSecure Mobile Access(SMA)1000シリーズVPNアプライアンスに影響を与える2つのセキュリティ上の欠陥に対処するためのセキュリティアップデートをリリースしました。

SonicWallのウィリアム・ペリー氏とアダム・バビス氏が社内で発見した脆弱 性は 以下のとおりです。

CVE-2026-83548 (CVSS スコア: 10.0)
CVE-2026-83549 (CVSS スコア: 7.8)

SonicWallは、「脆弱性が積極的に悪用されていることを示す事例を調査した」と述べ、攻撃者が両方のバグを組み合わせて、脆弱性のあるデバイス上で任意のコードを実行している可能性を示唆した。 」

thehackernews.com/2026/09/atta

#prattohome

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:02:29.000Z ##

CVE ID: CVE-2026-83549
Vendor: SonicWall
Product: SMA1000 Appliances
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cert_fr@social.numerique.gouv.fr at 2026-09-02T12:51:59.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

##

security_crawler_carl@infosec.exchange at 2026-09-02T07:13:42.000Z ##

By also ignoring CVE-2026-83549, an OS command injection flaw in the AMC component, you further agree to let those same strangers chain both bugs together for full remote code execution. SonicWall has confirmed active exploitation in the wild. Ransomware gangs find SonicWall products particularly cozy real estate.

To opt out of these terms, patch your SMA1000 immediately.

Reward: You've received the Binding Arbitration Curse — your incidents are now non-disputable.

#ZeroDay #SonicWall (2/2)

##

decio@infosec.exchange at 2026-09-02T07:06:36.000Z ##

Tiens, encore du #SonicWall SMA1000 ...

Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.

La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.

Sont concernés les SMA1000 6210, 7210 et 8200v.

Pas de workaround : hotfix à appliquer au plus vite. ☹️

Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.

À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.

Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃

Advisory 🩹
👇
psirt.global.sonicwall.com/vul

#CyberVeille

##

CVE-2026-82329
(9.8 CRITICAL)

EPSS: 7.67%

updated 2026-09-02T18:31:57

8 posts

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Nuclei template

6 repos

https://github.com/HORKimhab/CVE-2026-82329

https://github.com/dinosn/cve-2026-82329-jfrog-artifactory

https://github.com/0xCyp1337/CVE-2026-82329

https://github.com/realalexandergeorgiev/artifactory-CVE-2026-82329-poc.py

https://github.com/gagaltotal/CVE-2026-82329-poc

https://github.com/ynsmroztas/CVE-2026-82329-JFrog-Artifactory-Auth-Bypass

cyberveille@mastobot.ping.moi at 2026-09-04T15:30:04.000Z ##

📢 Exploitation active de CVE-2026-82329 dans JFrog Artifactory pour forger des tokens admin

BleepingComputer, publié le 2 septembre 2026. L'article rapporte l'exploitation active d'une vulnérabilité critique dans JFrog Artifactory, un gestionnaire de dépôts logiciels largement utilisé pour stocker, organiser, sécuriser et distribuer…

📖 cyberveille : cyberveille.ch/posts/2026-09-0
🌐 source : bleepingcomputer.com/news/secu
🟡 vérification factuelle moyenne
#JFrogArtifactory #AuthenticationBypass #Cyberveille

##

Matchbook3469@mastodon.social at 2026-09-03T19:10:28.000Z ##

🔵 THREAT INTELLIGENCE

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

Vulnerability | CRITICAL
CVEs: CVE-2026-82329

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide...

Full analysis:
yazoul.net/news/article/hacker

by Yazoul AI

#CyberSecurity #APT #CyberNews

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:42.000Z ##

CVE ID: CVE-2026-82329
Vendor: JFrog
Product: Artifactory
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

oversecurity@mastodon.social at 2026-09-02T16:10:21.000Z ##

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide...

🔗️ [Bleepingcomputer] link.is.it/GGGBsY

##

beyondmachines1@infosec.exchange at 2026-09-02T08:01:30.000Z ##

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens

JFrog Artifactory is facing active exploitation of a critical authentication bypass (CVE-2026-82329) that allows unauthenticated attackers to mint administrator tokens and compromise software supply chains.

**If you run self-managed JFrog Artifactory, update to version 7.161.20 ASAP. Attackers are already exploiting this flaw to take full admin control. Primary systems at risk are internet facing self-hosted Artifactory instances. Cloud-hosted instances managed by JFrog are not affected.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

youranonnewsirc@nerdculture.de at 2026-09-02T04:26:22.000Z ##

Geopolitical tensions persist between the U.S. and Iran regarding actions in the Strait of Hormuz (Sept 1, 2026). On the cybersecurity front, critical infrastructure, including Midwest water utilities, faces new ransomware attacks. Additionally, a severe authentication bypass flaw (CVE-2026-82329) in JFrog Artifactory is actively being exploited. OpenAI has issued a stark warning regarding the escalating threat of AI-enabled cyberattacks.

#AnonNews_irc #Cybersecurity #Anonymous #News

##

CVE-2026-73749
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-09-02T15:34:36

8 posts

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.

beyondmachines1 at 2026-09-04T10:01:31.275Z ##

HPE Patches Critical Remote Code Execution Flaw in ArubaOS-CX Switches

HPE patched 34 vulnerabilities in ArubaOS-CX, including a critical buffer overflow (CVE-2026-73749) that allows unauthenticated remote code execution. The update also addresses multiple high-severity flaws enabling command injection, authentication bypass, and unauthorized file writes.

**If you run HPE Aruba CX switches (10000, 6400, 8325, 6000 series), first make sure their management interfaces are not reachable from the internet and only accessible from a dedicated management VLAN on trusted networks. Then update the switches to AOS-CX 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, or 10.10.1181, and change any factory-set passwords while you're there.**

beyondmachines.net/event_detai

##

cyho_ubeg@burnout.cafe at 2026-09-04T07:01:59.000Z ##

HPE korjaa kriittisen ArubaOS-CX RCE -haavoittuvuuden HPE on korjannut CVE-2026-73749:n, kriittisen puskurin ylivuodon ArubaOS-CX:ssä, joka sallii todentamattoman etäkoodin suorittamisen korotetuilla oikeuksilla luotujen pakettien kautta kyseiselle daemonille. ArubaOS-CX-tiedote käsittelee myös 23 muuta haavoittuvuutta, mukaan lukien komentojen suorittamisen

bleepingcomputer.com/news/secu

##

cyberworldops at 2026-09-03T20:10:00.982Z ##

HPE patched CVE-2026-73749, a critical unauthenticated buffer overflow in ArubaOS-CX. Exploitation via crafted packets to a vulnerable daemon can yield privileged remote code execution on enterprise switches, risking full network takeover.

cyberworldops.eu/en/arubaos-cx

##

Analyst207@mastodon.social at 2026-09-03T18:29:06.000Z ##

HPE Fixes Remote Code Execution Flaw in ArubaOS-CX

HPE has patched a critical flaw in ArubaOS-CX that could let hackers run malicious code with elevated privileges - and all they need to do is send specially crafted packets to an affected device. This remote code execution vulnerability, tracked as CVE-2026-73749, is a serious threat that demands immediate attention.

osintsights.com/hpe-fixes-remo

#RemoteCodeExecution #Arubaoscx #Cve202673749 #BufferOverflow #Hpe

##

beyondmachines1@infosec.exchange at 2026-09-04T10:01:31.000Z ##

HPE Patches Critical Remote Code Execution Flaw in ArubaOS-CX Switches

HPE patched 34 vulnerabilities in ArubaOS-CX, including a critical buffer overflow (CVE-2026-73749) that allows unauthenticated remote code execution. The update also addresses multiple high-severity flaws enabling command injection, authentication bypass, and unauthorized file writes.

**If you run HPE Aruba CX switches (10000, 6400, 8325, 6000 series), first make sure their management interfaces are not reachable from the internet and only accessible from a dedicated management VLAN on trusted networks. Then update the switches to AOS-CX 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, or 10.10.1181, and change any factory-set passwords while you're there.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

cyho_ubeg@burnout.cafe at 2026-09-04T07:01:59.000Z ##

HPE korjaa kriittisen ArubaOS-CX RCE -haavoittuvuuden HPE on korjannut CVE-2026-73749:n, kriittisen puskurin ylivuodon ArubaOS-CX:ssä, joka sallii todentamattoman etäkoodin suorittamisen korotetuilla oikeuksilla luotujen pakettien kautta kyseiselle daemonille. ArubaOS-CX-tiedote käsittelee myös 23 muuta haavoittuvuutta, mukaan lukien komentojen suorittamisen

bleepingcomputer.com/news/secu

##

cyberworldops@infosec.exchange at 2026-09-03T20:10:00.000Z ##

HPE patched CVE-2026-73749, a critical unauthenticated buffer overflow in ArubaOS-CX. Exploitation via crafted packets to a vulnerable daemon can yield privileged remote code execution on enterprise switches, risking full network takeover. #HpeAruba #ArubaOS #NetworkSecurity

cyberworldops.eu/en/arubaos-cx

##

DailyCyberSecurity@infosec.exchange at 2026-09-03T01:58:31.000Z ##

CVE-2026-73749: Unauth RCE in HPE Networking AOS-CX Scores 9.8

securityonline.info/hpe-aos-cx

##

CVE-2026-78657
(9.8 CRITICAL)

EPSS: 0.72%

updated 2026-09-02T13:55:27.963000

1 posts

The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted

thehackerwire@mastodon.social at 2026-09-02T07:01:18.000Z ##

🔴 CVE-2026-78657 - Critical (9.8)

The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it po...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84795
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-09-02T12:31:39

1 posts

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

cR0w@infosec.exchange at 2026-09-02T14:03:04.000Z ##

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

Seems like a pretty limited scope but it's still interesting to see that sev:CRIT in the CVE when the advisory says sev:MED:

github.com/craftcms/cms/securi

##

CVE-2026-84699
(9.1 CRITICAL)

EPSS: 0.37%

updated 2026-09-02T12:17:14.410000

1 posts

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

cR0w@infosec.exchange at 2026-09-02T14:01:22.000Z ##

"Just use a password manager."

nvd.nist.gov/vuln/detail/cve-2

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

##

CVE-2026-84485
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-02T11:17:25.947000

1 posts

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.

thehackerwire@mastodon.social at 2026-09-02T08:00:34.000Z ##

🟠 CVE-2026-84485 - High (7.5)

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9055
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-09-02T06:31:24

1 posts

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when t

1 repos

https://github.com/EXEcution-py/CVE-2026-9055

thehackerwire@mastodon.social at 2026-09-02T08:00:24.000Z ##

🔴 CVE-2026-9055 - Critical (9.8)

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the cus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14357
(8.8 HIGH)

EPSS: 0.65%

updated 2026-09-02T06:31:24

1 posts

The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on the wp_ajax_DPDEV_install_themes action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary t

thehackerwire@mastodon.social at 2026-09-02T07:01:30.000Z ##

🟠 CVE-2026-14357 - High (8.8)

The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-46418
(7.6 HIGH)

EPSS: 0.68%

updated 2026-09-02T06:31:19

1 posts

Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

thehackerwire@mastodon.social at 2026-09-02T07:01:42.000Z ##

🟠 CVE-2025-46418 - High (7.6)

Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62911
(8.0 HIGH)

EPSS: 1.32%

updated 2026-09-02T04:18:00.460000

3 posts

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/hypnguyen1209/CVE-2026-62911

cyberveille@mastobot.ping.moi at 2026-09-04T16:30:05.000Z ##

📢 CVE-2026-62911 : vulnérabilité critique d'élévation de privilèges dans Microsoft Exchange avec PoC public

📰 Source : LeMagIT — Article publié le 26 août 2026, relatant une vulnérabilité Exchange divulguée lors du Patch Tuesday de Microsoft du 11 août 2026. 🔍 Contexte : Le Patch Tuesday d'août 2026 de Microsoft est décrit comme le plus…

📖 cyberveille : cyberveille.ch/posts/2026-09-0
🌐 source : lemagit.fr/actualites/36664975
🟡 vérification factuelle moyenne
#MicrosoftExchange #PoCPublic #Cyberveille

##

DailyCyberSecurity@infosec.exchange at 2026-09-03T08:02:34.000Z ##

Nearly 22,000 internet-facing Exchange servers remain unpatched against CVE-2026-62911, an authentication bypass that can hijack every user's mailbox.

#CVE202662911 #MicrosoftExchange #AuthenticationBypass #Shadowserver #Patch

meterpreter.org/exchange-cve-2

##

benzogaga33@mamot.fr at 2026-09-02T09:40:03.000Z ##

Exchange Server : près de 22 000 serveurs exposés sont vulnérables à la CVE-2026-62911 it-connect.fr/microsoft-exchan #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #Exchange

##

CVE-2026-84484
(7.5 HIGH)

EPSS: 0.48%

updated 2026-09-02T03:31:18

1 posts

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a truncated SDNV to trigger reads up to nine bytes past buffer boundaries and underflow byte counters.

thehackerwire@mastodon.social at 2026-09-02T05:01:06.000Z ##

🟠 CVE-2026-84484 - High (7.5)

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84715
(8.8 HIGH)

EPSS: 0.32%

updated 2026-09-02T03:31:17

1 posts

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration.

thehackerwire@mastodon.social at 2026-09-02T08:00:43.000Z ##

🟠 CVE-2026-84715 - High (8.8)

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted reques...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14982
(8.1 HIGH)

EPSS: 0.52%

updated 2026-09-02T03:31:14

1 posts

The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

thehackerwire@mastodon.social at 2026-09-02T05:00:54.000Z ##

🟠 CVE-2026-14982 - High (8.1)

The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14957
(7.5 HIGH)

EPSS: 0.56%

updated 2026-09-02T03:31:14

1 posts

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Co

thehackerwire@mastodon.social at 2026-09-02T05:00:43.000Z ##

🟠 CVE-2026-14957 - High (7.5)

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84702
(7.5 HIGH)

EPSS: 0.38%

updated 2026-09-02T03:31:13

1 posts

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at arbitrary locations.

thehackerwire@mastodon.social at 2026-09-02T11:00:46.000Z ##

🟠 CVE-2026-84702 - High (7.5)

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HT...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84700
(8.6 HIGH)

EPSS: 0.35%

updated 2026-09-02T03:31:13

1 posts

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates

thehackerwire@mastodon.social at 2026-09-02T11:00:34.000Z ##

🟠 CVE-2026-84700 - High (8.6)

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84115
(8.3 HIGH)

EPSS: 0.28%

updated 2026-09-01T15:31:23

3 posts

A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 i

rhudaur@flipboard.com at 2026-09-03T17:05:20.000Z ##

CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk
thecyberexpress.com/cve-2026-8

Posted into Cybersecurity Today @cybersecurity-today-rhudaur

##

rhudaur@flipboard.com at 2026-09-03T17:05:20.000Z ##

CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk
thecyberexpress.com/cve-2026-8

Posted into Cybersecurity Today @cybersecurity-today-rhudaur

##

oversecurity@mastodon.social at 2026-09-03T09:40:18.000Z ##

CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk

A critical vulnerability identified as CVE-2026-84115 affects Cleo Harmony versions through 5.8.1.10, with the weakness tied to the platform’s JWT

🔗️ [Thecyberexpress] link.is.it/lkJ3B6

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 1.69%

updated 2026-09-01T04:18:02.160000

2 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/virologi-info/papercut-toolkit

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

security_crawler_carl@infosec.exchange at 2026-09-02T09:44:29.000Z ##

Huntress logged confirmed attacks against at least two customers.

SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.

Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.

Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.

#PaperCut #ZeroDay #CVE #CyberSecurity (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-02T09:44:29.000Z ##

🏆 New Achievement! Print Job: Ownership Complete!

ERROR: Assumed single zero-day. Actual zero-days: two. PaperCut, the print management software, has had CVE-2026-81578 and CVE-2026-82078 exploited in the wild since August 26 — the first a high-severity authentication bypass letting remote, unauthenticated attackers modify system configurations. WatchTowr then found additional patch bypasses, triggering a second emergency patch before the first one was even officially released. (1/2)

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 1.62%

updated 2026-08-31T21:31:56

2 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

2 repos

https://github.com/virologi-info/papercut-toolkit

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

security_crawler_carl@infosec.exchange at 2026-09-02T09:44:29.000Z ##

Huntress logged confirmed attacks against at least two customers.

SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.

Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.

Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.

#PaperCut #ZeroDay #CVE #CyberSecurity (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-02T09:44:29.000Z ##

🏆 New Achievement! Print Job: Ownership Complete!

ERROR: Assumed single zero-day. Actual zero-days: two. PaperCut, the print management software, has had CVE-2026-81578 and CVE-2026-82078 exploited in the wild since August 26 — the first a high-severity authentication bypass letting remote, unauthenticated attackers modify system configurations. WatchTowr then found additional patch bypasses, triggering a second emergency patch before the first one was even officially released. (1/2)

##

CVE-2026-81934
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-31T21:31:55

1 posts

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.

CVE-2026-48710
(6.5 MEDIUM)

EPSS: 36.26%

updated 2026-08-28T18:31:00

6 posts

### Summary In affected versions, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions

Nuclei template

5 repos

https://github.com/CuteeCat/CVE-2026-48710

https://github.com/eris-ths/supply-chain-guard

https://github.com/xtremebeing/starlette-host-header-lab

https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace

https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit

thecybermind at 2026-09-03T18:01:45.438Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-48710 – Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Active CISA KEV exploitation of CVE-2026-48710 exposes Starlette to request smuggling and auth bypass. Review board-ready governance, asset visibility, and mitigation....

thecybermind.co/r67t

##

thecybermind@infosec.exchange at 2026-09-03T18:01:45.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-48710 – Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Active CISA KEV exploitation of CVE-2026-48710 exposes Starlette to request smuggling and auth bypass. Review board-ready governance, asset visibility, and mitigation....

thecybermind.co/r67t

##

thecybermind@infosec.exchange at 2026-09-03T06:55:48.000Z ##

Mitigate CVE-2026-48710 in Starlette. Attackers exploit path injections in request headers to trigger auth bypasses. Access our T-Suite brief for Splunk, Sentinel, and Chronicle detection rules and rapid reverse proxy hardening steps to secure your perimeter today. thecybermind.co/zyul

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:11.000Z ##

CVE ID: CVE-2026-48710
Vendor: Kludex
Product: Starlette
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-19949
(8.8 HIGH)

EPSS: 0.54%

updated 2026-08-25T12:31:24

7 posts

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing q

1 repos

https://github.com/HORKimhab/CVE-2026-19949

cyberveille@mastobot.ping.moi at 2026-09-04T14:00:05.000Z ##

📢 Injection SQL de second ordre non authentifiée dans All-in-One WP Migration and Backup (CVE-2026-19949)

Cet article détaille une vulnérabilité critique découverte le 14 août 2026 dans le plugin WordPress All-in-One WP Migration and Backup, qui compte plus de 5 millions d'installations actives.

📖 cyberveille : cyberveille.ch/posts/2026-09-0
🌐 source : wordfence.com/blog/2026/09/5-m
🟡 vérification factuelle moyenne
#WordPress #RemoteCodeExecution #Cyberveille

##

decio at 2026-09-04T07:19:26.566Z ##

Si vous avez utilisé (et oublié 😅) All-in-One WP Migration and Backup sur votre c'est peut-être le moment d'aller jeter un œil.

Une vulnérabilité assez vilaine, CVE-2026-19949, touche les versions jusqu'à 7.109.

Un attaquant peut déposer du contenu piégé qui reste en attente et devient dangereux lors d'un export/import du site. À la clé, il peut finir par exécuter du code sur le serveur et prendre le contrôle du WordPress.

Le plugin est installé sur plus de 5 millions de sites et environ 3,2 millions seraient encore sur une version vulnérable.

👉 Si vous l'avez utilisé un jour pour migrer un site et qu'il traîne toujours dans vos plugins : vérifiez la version et passez au minimum en 7.110.

⬇️
"5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin"
👇
wordfence.com/blog/2026/09/5-m

##

guru@thecybersecguru.com at 2026-09-03T18:57:21.000Z ##

Critical WordPress vulnerability exposes 3.2 million sites to remote code execution via All-in-One WP Migration

CVE-2026-19949 is a second-order SQL injection in All-in-One WP Migration and Backup that leads to unauthenticated RCE. Full exploit chain and fix

thecybersecguru.com/news/cve-2

##

decio@infosec.exchange at 2026-09-04T07:19:26.000Z ##

Si vous avez utilisé (et oublié 😅) All-in-One WP Migration and Backup sur votre #WordPress c'est peut-être le moment d'aller jeter un œil.

Une vulnérabilité assez vilaine, CVE-2026-19949, touche les versions jusqu'à 7.109.

Un attaquant peut déposer du contenu piégé qui reste en attente et devient dangereux lors d'un export/import du site. À la clé, il peut finir par exécuter du code sur le serveur et prendre le contrôle du WordPress.

Le plugin est installé sur plus de 5 millions de sites et environ 3,2 millions seraient encore sur une version vulnérable.

👉 Si vous l'avez utilisé un jour pour migrer un site et qu'il traîne toujours dans vos plugins : vérifiez la version et passez au minimum en 7.110.

⬇️
"5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin"
👇
wordfence.com/blog/2026/09/5-m

#CyberVeille

##

guru@thecybersecguru.com at 2026-09-03T18:57:21.000Z ##

Critical WordPress vulnerability exposes 3.2 million sites to remote code execution via All-in-One WP Migration

CVE-2026-19949 is a second-order SQL injection in All-in-One WP Migration and Backup that leads to unauthenticated RCE. Full exploit chain and fix

thecybersecguru.com/news/cve-2

##

cyberworldops@infosec.exchange at 2026-09-03T12:10:00.000Z ##

Second-order SQL injection in All-in-One WP Migration and Backup restore function enables RCE, tracked as CVE-2026-19949. Affects versions up to 7.109, with ~3.2M sites exposed. Patch to 7.110 and audit for anomalous restore activity. #WordPressSecurity #SqlInjection #PatchManagement

cyberworldops.eu/en/wordpress-

##

beyondmachines1@infosec.exchange at 2026-09-03T10:01:29.000Z ##

ServMask Patches Critical SQL Injection in All-in-One WP Migration Plugin

ServMask patched a high-severity SQL injection vulnerability (CVE-2026-19949) in the All-in-One WP Migration and Backup plugin. The flaw allows unauthenticated attackers to leak secret keys and execute remote code when an administrator restores a site archive.

**If you use the All-in-One WP Migration and Backup plugin, update it to version 7.110 or later ASAP. Even if the plugin is currently inactive, since it becomes dangerous the moment someone turns it on for a migration. Until you've patched, don't run any import or export, turn off trackbacks and pings on public posts, and check your comments for suspicious entries.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-19490(CVSS UNKNOWN)

EPSS: 3.37%

updated 2026-08-20T15:34:03

7 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

1 repos

https://github.com/TarPeg007/CVE-2026-19490

undercodenews@mastodon.social at 2026-09-04T20:09:24.000Z ##

Critical Citrix NetScaler Authentication Bypass Is Now Being Exploited: CVE-2026-19490 Raises the Alarm for Exposed Networks + Video

A New Warning for NetScaler Administrators A critical authentication-bypass vulnerability affecting Citrix NetScaler has moved into a far more dangerous phase. CVE-2026-19490, rated 9.3/10 Critical under CVSS 4.0, affects NetScaler ADC and NetScaler Gateway and can allow an unauthenticated attacker to bypass authentication under specific…

undercodenews.com/critical-cit

##

cyberworldops at 2026-09-04T18:20:00.922Z ##

Previdian reports exploitation attempts targeting CVE-2026-19490, a critical authentication bypass in Citrix NetScaler ADC and Gateway. Exposure depends on firmware version and AAA virtual server configuration. Review exposed assets and authentication logs for anomalous access.

cyberworldops.eu/en/citrix-net

##

oversecurity@mastodon.social at 2026-09-04T16:21:08.000Z ##

Critical Citrix NetScaler auth bypass now leveraged in attacks

Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability...

🔗️ [Bleepingcomputer] link.is.it/1ZYTCn

##

undercodenews@mastodon.social at 2026-09-04T15:58:29.000Z ##

Citrix NetScaler Under Attack: Critical CVE-2026-19490 Exploitation Attempts Raise the Alarm + Video

Introduction: Another NetScaler Warning Arrives at a Dangerous Time Citrix NetScaler administrators are facing another serious security warning, and this time the concern is no longer limited to a theoretical vulnerability or laboratory proof of concept. Security researchers have observed what appear to be real-world attempts to exploit CVE-2026-19490, a…

undercodenews.com/citrix-netsc

##

Analyst207@mastodon.social at 2026-09-04T15:29:37.000Z ##

Citrix NetScaler Flaw Exploited in Targeted Attacks

Citrix is urging customers to act fast to protect their NetScaler deployments from a critical flaw, known as CVE-2026-19490, that lets hackers bypass authentication and gain unauthorized access. To stay safe, review the security bulletin, check if your setup is vulnerable, and upgrade to the recommended build ASAP.

osintsights.com/citrix-netscal

#Citrix #Cve202619490 #Netscaler #AuthenticationBypass #RemoteExploitation

##

cyberworldops@infosec.exchange at 2026-09-04T18:20:00.000Z ##

Previdian reports exploitation attempts targeting CVE-2026-19490, a critical authentication bypass in Citrix NetScaler ADC and Gateway. Exposure depends on firmware version and AAA virtual server configuration. Review exposed assets and authentication logs for anomalous access. #CitrixNetScaler #AuthBypass #ThreatIntel

cyberworldops.eu/en/citrix-net

##

oversecurity@mastodon.social at 2026-09-04T16:21:08.000Z ##

Critical Citrix NetScaler auth bypass now leveraged in attacks

Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability...

🔗️ [Bleepingcomputer] link.is.it/1ZYTCn

##

CVE-2026-32475
(9.0 None)

EPSS: 2.37%

updated 2026-08-19T18:32:57

12 posts

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

Nuclei template

4 repos

https://github.com/sahmsec/CVE-2026-32475

https://github.com/absholi7ly/Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE

https://github.com/Boreas37/CVE-2026-32475-PoC

https://github.com/0xBlackash/CVE-2026-32475

DailyCyberSecurity at 2026-09-04T14:06:38.908Z ##

Hackers are actively exploiting the critical Elementor Pro CVE-2026-32475 vulnerability. The flaw allows unauthenticated PHP file uploads and site takeovers.

securityexpress.info/elementor

##

cyberworldops at 2026-09-04T12:10:01.017Z ##

Wordfence reports over 440,000 blocked exploitation attempts against CVE-2026-14894 in Super Forms and CVE-2026-32475 in Elementor Pro. Both allow unauthenticated arbitrary file upload leading to RCE, indicating mass opportunistic targeting of WordPress.

cyberworldops.eu/en/wordpress-

##

guru@thecybersecguru.com at 2026-09-04T10:48:49.000Z ##

Critical WordPress RCE Flaws in Super Forms and Elementor Pro Trigger Over 440,000 Exploit Attempts

Critical WordPress flaws in Super Forms and Elementor Pro are under active attack. Learn about CVE-2026-14894 and CVE-2026-32475, RCE exploits, affected versions and fixes

thecybersecguru.com/news/wordp

##

Analyst207@mastodon.social at 2026-09-04T10:29:18.000Z ##

WordPress Sites Targeted in Mass Exploits of Plugin Flaws

Hackers have launched over 440,000 exploit attempts on WordPress sites, targeting critical flaws in popular plugins Super Forms and Elementor Pro, with attackers seeking to upload malicious files and execute remote code. Two high-severity vulnerabilities, CVE-2026-14894 and CVE-2026-32475, were behind the attacks, and have since been…

osintsights.com/wordpress-site

#Wordpress #SupplyChain #PluginVulnerabilities #Cve202614894 #Cve202632475

##

decio at 2026-09-04T09:52:52.307Z ##

…et si vous utilisez Elementor Pro sur encore une à vérifier rapidement 👀

CVE-2026-32475 CVSS 9.8
Upload arbitraire de fichiers sans authentification → possibilité d'uploader du PHP → RCE / takeover complet du site.

Et ce n’est plus théorique : exploitation active depuis le 19 août, avec déjà >190'000 tentatives bloquées par Wordfence.

Vulnérable jusqu’à Elementor Pro 4.2.1

Corrigé en 4.2.2

Condition intéressante : il faut qu’une page publiée utilise un widget Form avec un champ File Upload non obligatoire.

Si vous êtes concernés : patch rapidemment, puis petit contrôle de /wp-content/uploads/elementor/forms/ — un .php là-dedans mérite clairement votre attention.

👇
wordfence.com/blog/2026/09/att

👇 thehackernews.com/2026/09/over

##

undercodenews@mastodon.social at 2026-09-03T21:42:48.000Z ##

Critical Elementor Pro Vulnerability Is Being Actively Exploited — WordPress Sites Face Webshells, Remote Code Execution, and Full Takeover + Video

A New Warning for Millions of WordPress Sites A critical security problem in Elementor Pro has moved from vulnerability disclosure to real-world exploitation, putting vulnerable WordPress websites directly in the crosshairs of attackers. Tracked as CVE-2026-32475, the flaw allows an unauthenticated attacker to abuse the…

undercodenews.com/critical-ele

##

DailyCyberSecurity@infosec.exchange at 2026-09-04T14:06:38.000Z ##

Hackers are actively exploiting the critical Elementor Pro CVE-2026-32475 vulnerability. The flaw allows unauthenticated PHP file uploads and site takeovers.

#ElementorPro #WordPressSecurity #CVE202632475 #CyberAttack #Malware

securityexpress.info/elementor

##

cyberworldops@infosec.exchange at 2026-09-04T12:10:01.000Z ##

Wordfence reports over 440,000 blocked exploitation attempts against CVE-2026-14894 in Super Forms and CVE-2026-32475 in Elementor Pro. Both allow unauthenticated arbitrary file upload leading to RCE, indicating mass opportunistic targeting of WordPress. #WordPressSecurity #RemoteCodeExecution #ThreatIntel

cyberworldops.eu/en/wordpress-

##

guru@thecybersecguru.com at 2026-09-04T10:48:49.000Z ##

Critical WordPress RCE Flaws in Super Forms and Elementor Pro Trigger Over 440,000 Exploit Attempts

Critical WordPress flaws in Super Forms and Elementor Pro are under active attack. Learn about CVE-2026-14894 and CVE-2026-32475, RCE exploits, affected versions and fixes

thecybersecguru.com/news/wordp

##

decio@infosec.exchange at 2026-09-04T09:52:52.000Z ##

…et si vous utilisez Elementor Pro sur #WordPress encore une à vérifier rapidement 👀

CVE-2026-32475 CVSS 9.8
Upload arbitraire de fichiers sans authentification → possibilité d'uploader du PHP → RCE / takeover complet du site.

Et ce n’est plus théorique : exploitation active depuis le 19 août, avec déjà >190'000 tentatives bloquées par Wordfence.

Vulnérable jusqu’à Elementor Pro 4.2.1

Corrigé en 4.2.2

Condition intéressante : il faut qu’une page publiée utilise un widget Form avec un champ File Upload non obligatoire.

Si vous êtes concernés : patch rapidemment, puis petit contrôle de /wp-content/uploads/elementor/forms/ — un .php là-dedans mérite clairement votre attention.

👇
wordfence.com/blog/2026/09/att

👇 thehackernews.com/2026/09/over

#CyberVeille

##

oversecurity@mastodon.social at 2026-09-03T15:00:44.000Z ##

Critical Elementor Pro flaw exploited to take over WordPress sites

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a...

🔗️ [Bleepingcomputer] link.is.it/zUHe37

##

DailyCyberSecurity@infosec.exchange at 2026-09-02T15:25:26.000Z ##

Attackers exploit a critical Elementor Pro vulnerability (CVE-2026-32475) in the wild. Patch this Elementor Pro vulnerability to prevent site takeover.

#ElementorPro #CVE202632475 #WordPress #Cybersecurity #RCE

securityonline.info/elementor-

##

CVE-2026-6471
(7.2 HIGH)

EPSS: 0.29%

updated 2026-08-13T15:34:37

6 posts

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

1 repos

https://github.com/HORKimhab/CVE-2026-6471

cyberworldops at 2026-09-04T20:10:00.808Z ##

CVE-2026-6471 PostGREShell is an authorization flaw in PostgreSQL allowing REPLICATION users to execute arbitrary code as the server OS user. It affects versions since 2014 and enables escalation to superuser, making exposed replication accounts a critical risk.

cyberworldops.eu/en/postgreshe

##

netsecio@mastodon.social at 2026-09-04T16:50:56.000Z ##

📰 12-Year-Old "PostGREShell" Flaw Threatens PostgreSQL Servers

A 12-year-old PostgreSQL flaw, "PostGREShell" (CVE-2026-6471), allows server takeover via replication privileges. Affects versions since 9.4. Patch immediately and audit all accounts with REPLICATION rights. #PostgreSQL #CyberSecurity #RCE

🔗 cyber.netsecops.io/articles/de

##

Analyst207@mastodon.social at 2026-09-04T16:30:41.000Z ##

PostgreSQL Patches 12-Year-Old Flaw Enabling Code Execution

A 12-year-old flaw in PostgreSQL, just patched, allowed replication users to execute arbitrary code on the database server, posing a significant security risk. The vulnerability, tracked as CVE-2026-6471, was exploitable by accounts with the REPLICATION attribute and has been fixed in releases 18.6, 17.11, 16.15, 15.19, and 14.24.

osintsights.com/postgresql-pat

#Postgresql #Cve20266471 #CodeExecution #LogicalDecoding #DatabaseSecurity

##

beyondmachines1 at 2026-09-04T08:01:31.810Z ##

PostGREShell: Decade-Old PostgreSQL Flaw Turns Backup Accounts into Backdoors

PostgreSQL patched a vulnerability (CVE-2026-6471) that allows attackers with low-privilege replication access to execute arbitrary code and gain full superuser control. The flaw, present since 2014, enables persistent backdoor access across Windows, Linux, and macOS environments.

**If you run PostgreSQL, update immediately to version 18.6, 17.11, 16.15, 15.19, or 14.24 to fix CVE-2026-6471. Then review who has the REPLICATION permission and remove it from anyone who doesn't need it, restrict replication access in `pg_hba.conf` to trusted IP addresses only, and block outbound SMB and NFS traffic from your database servers.**

beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-09-04T20:10:00.000Z ##

CVE-2026-6471 PostGREShell is an authorization flaw in PostgreSQL allowing REPLICATION users to execute arbitrary code as the server OS user. It affects versions since 2014 and enables escalation to superuser, making exposed replication accounts a critical risk. #PostgreSQL #CodeExecution #ThreatIntel

cyberworldops.eu/en/postgreshe

##

beyondmachines1@infosec.exchange at 2026-09-04T08:01:31.000Z ##

PostGREShell: Decade-Old PostgreSQL Flaw Turns Backup Accounts into Backdoors

PostgreSQL patched a vulnerability (CVE-2026-6471) that allows attackers with low-privilege replication access to execute arbitrary code and gain full superuser control. The flaw, present since 2014, enables persistent backdoor access across Windows, Linux, and macOS environments.

**If you run PostgreSQL, update immediately to version 18.6, 17.11, 16.15, 15.19, or 14.24 to fix CVE-2026-6471. Then review who has the REPLICATION permission and remove it from anyone who doesn't need it, restrict replication access in `pg_hba.conf` to trusted IP addresses only, and block outbound SMB and NFS traffic from your database servers.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-66066(CVSS UNKNOWN)

EPSS: 27.86%

updated 2026-07-30T18:23:34

1 posts

### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment. That environment typically holds `secret_key_base` and often credentials for external systems, which may in turn allow escalation to remote code execution or lateral movement to those systems. ##

7 repos

https://github.com/shinthink/CVE-2026-66066

https://github.com/0xsha/KindaRails2Shell

https://github.com/0xBlackash/CVE-2026-66066

https://github.com/rails/rails-forensics-CVE-2026-66066

https://github.com/HackSpeak/CVE-2026-66066

https://github.com/paveg/rails-activestorage-vips-audit

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

sayzard@mastodon.sayzard.org at 2026-09-04T21:45:03.000Z ##

Government Rails Site Hit Hours After CVE Patch

Ruby on Rails 8 이상 Active Storage의 임의 파일 읽기·원격 코드 실행 취약점 CVE-2026-66066(KindaRails2Shell, CVSS 9.5)이 패치 공개 직후 실제 공격 시도에 사용된 사례다. 운영사 Rietta는 7월 29일 긴급 패치를 배포했지만, 공개 PoC가 배포 완료 전 GitHub에 올라왔고 한 정부기관 고객 환경에서는 배포 약 8시간 뒤 악성 BMP 업로드 기반 탐지가 기록됐다고 밝혔다. 이후에는 PNG 위장 파일, 회전 IP, 다양한 User-Agent를 활용한 지속 스캐닝이 관측됐으며, 패치 diff만으로도 공격 체...

rietta.com/blog/ruby-on-rails-

##

CVE-2026-43748
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-07-28T19:32:10.027000

1 posts

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

DailyCyberSecurity@infosec.exchange at 2026-09-03T02:36:01.000Z ##

CVE-2026-43748 (CVSS 9.8) is an Apple ANE kernel OOB write reachable from a sandbox. Full details and macOS/iOS PoC code are now public. Update now.

#Apple #CVE202643748 #iOS #macOS #KernelBug #InfoSec #ANE

securityonline.info/apple-ane-

##

CVE-2026-61884
(9.8 CRITICAL)

EPSS: 0.66%

updated 2026-07-25T00:31:53

2 posts

The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, dev

cyberworldops at 2026-09-03T18:20:00.948Z ##

Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover.

cyberworldops.eu/en/tycon-tpdi

##

cyberworldops@infosec.exchange at 2026-09-03T18:20:00.000Z ##

Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement

cyberworldops.eu/en/tycon-tpdi

##

CVE-2026-59822(CVSS UNKNOWN)

EPSS: 0.87%

updated 2026-07-22T22:38:34

6 posts

### Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. The MCP auth handler supported OAuth2 passthrough for upstream MCP servers, but the fallback path could replace failed LiteLLM key validation with an empty `UserAPIKeyAuth()` object. This allowed requests with a fabricated `Authoriza

1 repos

https://github.com/HORKimhab/CVE-2026-59822

thecybermind at 2026-09-03T15:19:58.534Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-59822 – BerriAI LiteLLM Improper Authentication Vulnerability

BerriAI LiteLLM is impacted by CVE-2026-59822, enabling unauthenticated attackers to bypass token validation. Review detection queries, compensating controls, and patching guides....

thecybermind.co/ng9r

##

thecybermind@infosec.exchange at 2026-09-03T15:19:58.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-59822 – BerriAI LiteLLM Improper Authentication Vulnerability

BerriAI LiteLLM is impacted by CVE-2026-59822, enabling unauthenticated attackers to bypass token validation. Review detection queries, compensating controls, and patching guides....

thecybermind.co/ng9r

##

thecybermind@infosec.exchange at 2026-09-03T07:52:48.000Z ##

Mitigate CVE-2026-59822 in BerriAI LiteLLM. Unauthenticated attackers bypass token checks on MCP endpoints. Read our T-Suite brief for Splunk, Sentinel, and Chronicle detection rules, plus vital hardening controls to lock down your AI infrastructure today. thecybermind.co/5vrg

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:00:55.000Z ##

CVE ID: CVE-2026-59822
Vendor: BerriAI
Product: LiteLLM
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-50031
(7.5 HIGH)

EPSS: 0.39%

updated 2026-07-22T19:10:00.120000

2 posts

ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors comma

thehackerwire@mastodon.social at 2026-09-04T07:03:34.000Z ##

🟠 CVE-2026-85505 - High (7.5)

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has differe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T07:03:34.000Z ##

🟠 CVE-2026-85505 - High (7.5)

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has differe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52833
(8.0 HIGH)

EPSS: 0.33%

updated 2026-07-16T19:40:53

1 posts

## Summary Nuclio's Java runtime generates a `build.gradle` file during function builds using Go's `text/template` package. The template renders `runtimeAttributes.repositories[]` values with the `{{ . }}` action, which performs no escaping. An attacker can embed a closing brace (`}`) to break out of the `repositories {}` block and append arbitrary Groovy statements that execute unconditionally d

thehackerwire@mastodon.social at 2026-09-03T07:00:32.000Z ##

🟠 CVE-2026-52833 - High (8)

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttribut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61699
(8.1 HIGH)

EPSS: 0.00%

updated 2026-07-14T20:28:19

2 posts

### Summary nebula-mesh revokes a host by adding its certificate fingerprint to a per-CA blocklist and shipping that list to every other agent on each poll. Slack's Nebula enforces certificate revocation ONLY through the `pki.blocklist` list in `config.yml` (no CRL/OCSP). The project's own code states this: `internal/pki/durations.go:15` — "Revocation via the blocklist remains the immediate secur

thehackerwire@mastodon.social at 2026-09-04T21:00:44.000Z ##

🟠 CVE-2026-61699 - High (8.1)

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any peer's c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T21:00:44.000Z ##

🟠 CVE-2026-61699 - High (8.1)

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any peer's c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-21913
(5.5 MEDIUM)

EPSS: 0.20%

updated 2026-07-14T15:32:25

1 posts

In the Linux kernel, the following vulnerability has been resolved: x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range() Xen doesn't offer MSR_FAM10H_MMIO_CONF_BASE to all guests. This results in the following warning: unchecked MSR access error: RDMSR from 0xc0010058 at rIP: 0xffffffff8101d19f (xen_do_read_msr+0x7f/0xa0) Call Trace: xen_read_msr+0x1e/0x30 amd_get_mmconfig_range+

andersonc0d3@infosec.exchange at 2026-09-02T17:44:44.000Z ##

RE: infosec.exchange/@andersonc0d3

The exception table mechanism in the page fault handler is popular, but maybe the mechanism in the general protection handler isn't so well-known.

When the code is interacting with MSRs, if the MSR index/address is invalid for the architecture, it triggers a #GP and the kernel oopses. This can happen in some scenarios and most of the cases it shouldn't trigger an oops and crash the kernel. That's why there are two MSR access implementations: rdmsr() / rdmsrq() and rdmsr_safe() / rdmsrq_safe(). The rdmsr variants use split 32-bit values for high/low bits, while rdmsrq handles 64-bit quadwords directly.

There is a proposal to retire legacy 32-bit user-space MSR interfaces, but I haven't followed this closely.

Linux Preparing To Retire Its 32-bit MSR Interfaces
phoronix.com/news/Linux-Ending

The safe ones are supposed to not crash/oops the kernel when the #GP is issued. It implements the same exception table mechanism present in the page fault handler. That's why it contains *_safe() in the function name.

This is checked by the general protection fault handler via fixup_exception() at line below:

github.com/torvalds/linux/blob

There was an oops caused by the use of rdmsrl() when running the Linux kernel as a Xen guest and the fix was to replace rdmsrl() with rdmsrl_safe().

CVE-2025-21913: x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()
lore.kernel.org/linux-cve-anno

x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()
git.kernel.org/pub/scm/linux/k

The interface was rdmsrl before being renamed to rdmsrq.

In the case of virtualization, things get more complicated because the hypervisor might have different configurations. That issue in the Linux kernel seems to have been exposed due to a change in Xen regarding MSRs accesses.

xen/pv: support selecting safe/unsafe msr accesses git.kernel.org/pub/scm/linux/k

##

CVE-2026-14894
(9.8 CRITICAL)

EPSS: 5.27%

updated 2026-07-10T06:31:28

7 posts

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separat

Nuclei template

2 repos

https://github.com/shinthink/CVE-2026-14894

https://github.com/1beelze/CVE-2026-14894

cyberworldops at 2026-09-04T12:10:01.017Z ##

Wordfence reports over 440,000 blocked exploitation attempts against CVE-2026-14894 in Super Forms and CVE-2026-32475 in Elementor Pro. Both allow unauthenticated arbitrary file upload leading to RCE, indicating mass opportunistic targeting of WordPress.

cyberworldops.eu/en/wordpress-

##

guru@thecybersecguru.com at 2026-09-04T10:48:49.000Z ##

Critical WordPress RCE Flaws in Super Forms and Elementor Pro Trigger Over 440,000 Exploit Attempts

Critical WordPress flaws in Super Forms and Elementor Pro are under active attack. Learn about CVE-2026-14894 and CVE-2026-32475, RCE exploits, affected versions and fixes

thecybersecguru.com/news/wordp

##

Analyst207@mastodon.social at 2026-09-04T10:29:18.000Z ##

WordPress Sites Targeted in Mass Exploits of Plugin Flaws

Hackers have launched over 440,000 exploit attempts on WordPress sites, targeting critical flaws in popular plugins Super Forms and Elementor Pro, with attackers seeking to upload malicious files and execute remote code. Two high-severity vulnerabilities, CVE-2026-14894 and CVE-2026-32475, were behind the attacks, and have since been…

osintsights.com/wordpress-site

#Wordpress #SupplyChain #PluginVulnerabilities #Cve202614894 #Cve202632475

##

DailyCyberSecurity at 2026-09-04T02:02:52.017Z ##

CVE-2026-14894, a critical Super Forms vulnerability, is exploited in the wild. The 9.8 CVSS file upload flaw enables unauthenticated remote code execution.

securityonline.info/super-form

##

cyberworldops@infosec.exchange at 2026-09-04T12:10:01.000Z ##

Wordfence reports over 440,000 blocked exploitation attempts against CVE-2026-14894 in Super Forms and CVE-2026-32475 in Elementor Pro. Both allow unauthenticated arbitrary file upload leading to RCE, indicating mass opportunistic targeting of WordPress. #WordPressSecurity #RemoteCodeExecution #ThreatIntel

cyberworldops.eu/en/wordpress-

##

guru@thecybersecguru.com at 2026-09-04T10:48:49.000Z ##

Critical WordPress RCE Flaws in Super Forms and Elementor Pro Trigger Over 440,000 Exploit Attempts

Critical WordPress flaws in Super Forms and Elementor Pro are under active attack. Learn about CVE-2026-14894 and CVE-2026-32475, RCE exploits, affected versions and fixes

thecybersecguru.com/news/wordp

##

DailyCyberSecurity@infosec.exchange at 2026-09-04T02:02:52.000Z ##

CVE-2026-14894, a critical Super Forms vulnerability, is exploited in the wild. The 9.8 CVSS file upload flaw enables unauthenticated remote code execution.

#SuperForms #WordPress #CVE202614894 #RCE #FileUpload #WebSecurity #InfoSec #ExploitedInTheWild

securityonline.info/super-form

##

CVE-2026-53932
(8.0 HIGH)

EPSS: 0.00%

updated 2026-07-09T20:52:58

2 posts

## Summary A crafted backup archive can trigger OS command injection during database restore. The restore workflow extracts a ZIP archive, enumerates files under `db-dumps`, converts the dump path to an absolute path, and passes that path into database import commands that are built as shell command strings. The dump filename is not shell-escaped before it is interpolated into commands such as:

thehackerwire@mastodon.social at 2026-09-04T21:02:44.000Z ##

🟠 CVE-2026-53932 - High (8)

laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T21:02:44.000Z ##

🟠 CVE-2026-53932 - High (8)

laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53649
(9.6 CRITICAL)

EPSS: 0.21%

updated 2026-07-08T20:27:04

1 posts

# Unauthenticated Cross-Origin Plugin Upload Leads to RCE (Joro ≤ v1.1.0) **Severity:** Critical **CVSS v3.1:** 9.6 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) **Affected versions:** Joro ≤ v1.1.0, proxy mode (default), Linux/macOS **Reporter:** cstover **Date:** 2026-05-27 --- ## Summary Joro's default proxy mode (in versions <= 1.1.0) exposes a local API on `127.0.0.1:9090` that performs no authen

thehackerwire@mastodon.social at 2026-09-03T00:00:21.000Z ##

🔴 CVE-2026-53649 - Critical (9.6)

Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multip...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49832
(8.0 HIGH)

EPSS: 0.54%

updated 2026-07-08T20:25:04

1 posts

## Overview Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for [COAR Notify/LDN messages](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126679/COAR+Notify). _This vulnerability impacts DSpace versions 8.0 <= 8.3, 9.0 <= 9.2._ The attacker MUST already have DSpace administrator credentials in order to perform the attack. This attack is related to the path travers

thehackerwire@mastodon.social at 2026-09-03T00:00:31.000Z ##

🟠 CVE-2026-49832 - High (8)

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible via Veloci...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52831
(10.0 CRITICAL)

EPSS: 0.32%

updated 2026-07-08T20:24:21

1 posts

## Summary Nuclio controller builds a `curl` invocation string for each cron trigger and stores it as the `args` of a Kubernetes CronJob container (`/bin/sh`, `-c`, `<command>`). Two fields in the trigger specification flow into this string without adequate sanitization: - `event.headers` keys — interpolated verbatim inside double-quoted `--header` arguments (`lazy.go:2150`); any key containing

thehackerwire@mastodon.social at 2026-09-02T18:00:10.000Z ##

🟠 CVE-2026-52831 - High (8)

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52924
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-07-08T15:31:44

4 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfiguration. In this path, the outbound stream scheduler state (stream->out_curr) is expected to be clean, since no user data should have been transmitted yet unless

DarkWebInformer at 2026-09-04T17:05:45.615Z ##

‼️ Exploit disclosed for CVE-2026-52924... 9.8 CVSS Linux Root Privilege Escalation

GitHub: github.com/NebuSec/CyberMeowfi

##

DailyCyberSecurity at 2026-09-04T03:38:03.791Z ##

Security researchers released a Linux CVE-2026-52924 PoC exploit. Check flaw details and patch instructions to secure your systems against root takeovers.

securityonline.info/linux-cve-

##

DarkWebInformer@infosec.exchange at 2026-09-04T17:05:45.000Z ##

‼️ Exploit disclosed for CVE-2026-52924... 9.8 CVSS Linux Root Privilege Escalation

GitHub: github.com/NebuSec/CyberMeowfi

##

DailyCyberSecurity@infosec.exchange at 2026-09-04T03:38:03.000Z ##

Security researchers released a Linux CVE-2026-52924 PoC exploit. Check flaw details and patch instructions to secure your systems against root takeovers.

#Linux #CyberSecurity #CVE202652924 #PoC #PrivilegeEscalation

securityonline.info/linux-cve-

##

CVE-2026-8024
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-06-18T15:32:09

1 posts

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.

certvde@infosec.exchange at 2026-09-02T09:56:27.000Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-051
iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator
CVE-2026-8024

Changes: Added ibaLogic to the affected products and the mitigation for this product.

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: iba.csaf-tp.certvde.com/.well-

#OT #Advisory

##

CVE-2026-0768
(9.8 CRITICAL)

EPSS: 2.26%

updated 2026-06-17T10:11:20.937000

4 posts

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a use

2 repos

https://github.com/rmhowe425/POC-CVE-2026-0768

https://github.com/HORKimhab/CVE-2026-0768

security_crawler_carl at 2026-09-04T08:51:00.446Z ##

🏆 New Achievement! Cursed Component (Soulbound, No Refund)!

Item tooltip: Langflow Custom Component Editor. Rarity: Critical. Effect: Grants unauthenticated remote attackers the ability to execute arbitrary Python code as root via CVE-2026-0768 (CVSS 9.8). Hidden stat: "Code Validator" passive is, in fact, entirely decorative. VulnCheck has confirmed active in-the-wild exploitation is already underway, so the item has been equipped for you. You did not consent to this. (1/2)

##

security_crawler_carl@infosec.exchange at 2026-09-04T08:51:00.000Z ##

🏆 New Achievement! Cursed Component (Soulbound, No Refund)!

Item tooltip: Langflow Custom Component Editor. Rarity: Critical. Effect: Grants unauthenticated remote attackers the ability to execute arbitrary Python code as root via CVE-2026-0768 (CVSS 9.8). Hidden stat: "Code Validator" passive is, in fact, entirely decorative. VulnCheck has confirmed active in-the-wild exploitation is already underway, so the item has been equipped for you. You did not consent to this. (1/2)

##

DailyCyberSecurity@infosec.exchange at 2026-09-03T11:31:50.000Z ##

Attackers exploit Langflow CVE-2026-0768, an unauthenticated root RCE, to harvest OpenAI and AWS keys and admin credentials from exposed AI servers.

#Langflow #CVE20260768 #VulnCheck #OpenAI #AWS

meterpreter.org/langflow-cve-2

##

beyondmachines1@infosec.exchange at 2026-09-02T09:01:31.000Z ##

Hackers Exploit Zero-Day in Langflow AI Platform to Steal Credentials

Langflow's AI platform is under active attack via a zero-day vulnerability (CVE-2026-0768) that allows unauthenticated remote code execution as root. Attackers are using the flaw to steal environment variables, secret keys, and SSH credentials from vulnerable instances.

**If you use Langflow, this is important and urgent. Make sure the server is isolated from the internet and reachable only from trusted internal networks or via VPN. There is no patch for this flaw and attackers are already exploiting it to steal secrets. Treat any internet-exposed instance as potentially compromised and rotate every API key, token and password stored in or used by it.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2024-1234
(6.4 MEDIUM)

EPSS: 1.59%

updated 2026-06-17T07:03:46.833000

2 posts

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an in

1 repos

https://github.com/RoyaRadin/CVE-2024-12345-POC

hugovalters@mastodon.social at 2026-09-04T14:40:03.000Z ##

CVE data pipeline got bloated? Query CVE, vendor, and exploit intel with one call: curl api.valtersit.com/cve/CVE-2024. Metered, no key overhead, built for devs. Docs at valtersit.com/cve/pricing/.

##

hugovalters@mastodon.social at 2026-09-04T12:00:14.000Z ##

Structured CVE data without the scraping grind. Pull vendor, exploit, and CPE fields in one JSON call:

curl -H "Authorization: Bearer $KEY" api.valtersit.com/cve/CVE-2024

Metered pricing, pay for what you use. Docs: valtersit.com/cve/pricing/

##

CVE-2021-42260
(7.5 HIGH)

EPSS: 3.35%

updated 2026-06-17T04:09:31.687000

1 posts

TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.

1 repos

https://github.com/vm2mv/tinyxml

cyberworldops@infosec.exchange at 2026-09-02T04:10:01.000Z ##

CISA reports CVE-2021-42260, a DoS vulnerability in Rockwell Automation ControlLogix, CompactLogix and GuardLogix controllers. The CWE-835 infinite loop is triggered by crafted data and results in a Major Non-Recoverable Fault requiring manual recovery, posing high availability risk for OT environments. #RockwellAutomation #ControlLogix #IcsSecurity

cyberworldops.eu/en/rockwell-a

##

CVE-2026-45730
(8.3 HIGH)

EPSS: 0.26%

updated 2026-06-04T15:05:58

1 posts

This vulnerability exists in Nuclio Dashboard's project management API, allowing any authenticated user (without membership in the target project) to bypass OPA authorization checks on write paths (`PUT /api/projects/{id}`, `DELETE /api/projects`) and modify or delete any project along with all its associated resources (functions, API gateways, etc.). CWE classification: CWE-862 (Missing Authoriza

thehackerwire@mastodon.social at 2026-09-03T12:01:20.000Z ##

🟠 CVE-2026-45730 - High (8.3)

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, allowing any authenticated user (without membership in the target project)...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42897
(8.1 HIGH)

EPSS: 71.20%

updated 2026-05-15T18:30:32

1 posts

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

1 repos

https://github.com/atiilla/CVE-2026-42897

cyberveille@mastobot.ping.moi at 2026-09-04T16:30:05.000Z ##

📢 CVE-2026-42897 : TA488 exploite une XSS stockée dans Exchange OWA via l'implant OWAReaper

Cet article constitue une analyse technique approfondie de la vulnérabilité CVE-2026-42897 et de la campagne d'exploitation associée menée par le groupe TA488 (également connu sous les noms Void Blizzard et Laundry Bear), acteur étatique russe.

📖 cyberveille : cyberveille.ch/posts/2026-09-0
🌐 source : resecurity.com/blog/article/in
🟢 vérification factuelle haute
#ExchangeOWA #OWAReaper #Cyberveille

##

CVE-2021-44228
(10.0 CRITICAL)

EPSS: 100.00%

updated 2025-10-22T19:13:26

2 posts

# Summary Log4j versions prior to 2.16.0 are subject to a remote code execution vulnerability via the ldap JNDI parser. As per [Apache's Log4j security guide](https://logging.apache.org/log4j/2.x/security.html): Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who

Nuclei template

100 repos

https://github.com/CERTCC/CVE-2021-44228_scanner

https://github.com/justakazh/Log4j-CVE-2021-44228

https://github.com/pedrohavay/exploit-CVE-2021-44228

https://github.com/DragonSurvivalEU/RCE

https://github.com/CrackerCat/CVE-2021-44228-Log4j-Payloads

https://github.com/corelight/cve-2021-44228

https://github.com/fireeye/CVE-2021-44228

https://github.com/sec13b/CVE-2021-44228-POC

https://github.com/CodeShield-Security/Log4JShell-Bytecode-Detector

https://github.com/puzzlepeaches/Log4jUnifi

https://github.com/wortell/log4j

https://github.com/jas502n/Log4j2-CVE-2021-44228

https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes

https://github.com/dtact/divd-2021-00038--log4j-scanner

https://github.com/Diverto/nse-log4shell

https://github.com/yahoo/check-log4j

https://github.com/marcourbano/CVE-2021-44228

https://github.com/MalwareTech/Log4jTools

https://github.com/mr-r3b00t/CVE-2021-44228

https://github.com/tippexs/nginx-njs-waf-cve2021-44228

https://github.com/cisagov/log4j-scanner

https://github.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit

https://github.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell

https://github.com/NCSC-NL/log4shell

https://github.com/fox-it/log4j-finder

https://github.com/HynekPetrak/log4shell-finder

https://github.com/simonis/Log4jPatch

https://github.com/corretto/hotpatch-for-apache-log4j2

https://github.com/takito1812/log4j-detect

https://github.com/darkarnium/Log4j-CVE-Detect

https://github.com/roxas-tan/CVE-2021-44228

https://github.com/claranet/ansible-role-log4shell

https://github.com/KosmX/CVE-2021-44228-example

https://github.com/momos1337/Log4j-RCE

https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept

https://github.com/alexandre-lavoie/python-log4rce

https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes

https://github.com/LiveOverflow/log4shell

https://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228

https://github.com/lfama/log4j_checker

https://github.com/cyberxml/log4j-poc

https://github.com/blake-fm/vcenter-log4j

https://github.com/qingtengyun/cve-2021-44228-qingteng-online-patch

https://github.com/0xInfection/LogMePwn

https://github.com/stripe/log4j-remediation-tools

https://github.com/alexbakker/log4shell-tools

https://github.com/nu11secur1ty/CVE-2021-44228-VULN-APP

https://github.com/mzlogin/CVE-2021-44228-Demo

https://github.com/thecyberneh/Log4j-RCE-Exploiter

https://github.com/sunnyvale-it/CVE-2021-44228-PoC

https://github.com/mr-vill4in/log4j-fuzzer

https://github.com/future-client/CVE-2021-44228

https://github.com/infiniroot/nginx-mitigate-log4shell

https://github.com/0xDexter0us/Log4J-Scanner

https://github.com/Adikso/minecraft-log4j-honeypot

https://github.com/NS-Sp4ce/Vm4J

https://github.com/fullhunt/log4j-scan

https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words

https://github.com/nccgroup/log4j-jndi-be-gone

https://github.com/dwisiswant0/look4jar

https://github.com/hackinghippo/log4shell_ioc_ips

https://github.com/Jeromeyoung/log4j2burpscanner

https://github.com/1lann/log4shelldetect

https://github.com/Nanitor/log4fix

https://github.com/puzzlepeaches/Log4jHorizon

https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs

https://github.com/Kadantte/CVE-2021-44228-poc

https://github.com/leonjza/log4jpwn

https://github.com/boundaryx/cloudrasp-log4j2

https://github.com/kubearmor/log4j-CVE-2021-44228

https://github.com/giterlizzi/nmap-log4shell

https://github.com/ssl/scan4log4j

https://github.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228

https://github.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent

https://github.com/logpresso/CVE-2021-44228-Scanner

https://github.com/mergebase/log4j-detector

https://github.com/mufeedvh/log4jail

https://github.com/lucab85/log4j-cve-2021-44228

https://github.com/BinaryDefense/log4j-honeypot-flask

https://github.com/greymd/CVE-2021-44228

https://github.com/bigsizeme/Log4j-check

https://github.com/thomaspatzke/Log4Pot

https://github.com/puzzlepeaches/Log4jCenter

https://github.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab

https://github.com/toramanemre/log4j-rce-detect-waf-bypass

https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce

https://github.com/AlexandreHeroux/Fix-CVE-2021-44228

https://github.com/NorthwaveSecurity/log4jcheck

https://github.com/toramanemre/apache-solr-log4j-CVE-2021-44228

https://github.com/redhuntlabs/Log4JHunt

https://github.com/CreeperHost/Log4jPatcher

https://github.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228

https://github.com/rubo77/log4j_checker_beta

https://github.com/f0ng/log4j2burpscanner

https://github.com/kozmer/log4j-shell-poc

https://github.com/christophetd/log4shell-vulnerable-app

https://github.com/qingtengyun/cve-2021-44228-qingteng-patch

https://github.com/Labout/log4shell-rmi-poc

https://github.com/back2root/log4shell-rex

https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator

thehackerwire@mastodon.social at 2026-09-04T22:00:31.000Z ##

🟠 CVE-2026-85656 - High (7.8)

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T22:00:31.000Z ##

🟠 CVE-2026-85656 - High (7.8)

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2021-31886
(9.8 CRITICAL)

EPSS: 3.05%

updated 2023-01-30T05:05:55

1 posts

A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions), APOGEE PXC Compact (P2 Ethernet) (All versions), APOGEE PXC Modular (BACnet) (All versions), APOGEE PXC Modular (P2 Ethernet) (All versions

cyberworldops@infosec.exchange at 2026-09-02T08:20:01.000Z ##

Forescout Research demonstrated porting a pre-auth RCE exploit for CVE-2021-31886 to a different WAGO PLC model using Anthropic Claude, achieving unauthenticated ARM shellcode execution on physical hardware. It shows how LLMs can accelerate exploit adaptation across OT variants, expanding exposure for unpatched systems. #Cve202131886 #OtSecurity #PlcSecurity

cyberworldops.eu/en/claude-ada

##

CVE-2026-59346
(0 None)

EPSS: 0.00%

5 posts

N/A

cyberworldops at 2026-09-04T22:20:00.887Z ##

Broadcom patched two VM escape flaws in VMware Workstation and Fusion. CVE-2026-59346 is an integer overflow in VMXNET3 (CVSS 9.3) allowing host code execution from a privileged VM guest. High risk for dev and lab environments relying on VM isolation.

cyberworldops.eu/en/vmware-wor

##

beyondmachines1 at 2026-09-03T20:01:31.308Z ##

Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion

Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.

**If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.**

beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-09-04T22:20:00.000Z ##

Broadcom patched two VM escape flaws in VMware Workstation and Fusion. CVE-2026-59346 is an integer overflow in VMXNET3 (CVSS 9.3) allowing host code execution from a privileged VM guest. High risk for dev and lab environments relying on VM isolation. #VmEscape #InfoSec #Virtualization

cyberworldops.eu/en/vmware-wor

##

beyondmachines1@infosec.exchange at 2026-09-03T20:01:31.000Z ##

Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion

Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.

**If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-09-03T09:23:36.000Z ##

CVE-2026-59346, a critical VMware Workstation vulnerability, lets an attacker escape a guest VM and execute code on the host. Broadcom rates it 9.3 CVSS.

#VMware #Workstation #Fusion #CVE202659346 #VMXNET3 #Broadcom #InfoSec #PatchNow

securityonline.info/vmware-cve

##

CVE-2026-63464
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-04T21:00:54.000Z ##

🟠 CVE-2026-63464 - High (7.7)

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-sub...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T21:00:54.000Z ##

🟠 CVE-2026-63464 - High (7.7)

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-sub...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85786
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-04T21:00:34.000Z ##

🟠 CVE-2026-85786 - High (7.5)

Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insuff...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-04T21:00:34.000Z ##

🟠 CVE-2026-85786 - High (7.5)

Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insuff...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44506
(0 None)

EPSS: 0.21%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-04T20:20:02.000Z ##

CVE-2026-44506: Medplum 4.1.10–5.1.6 leaks OAuth client_secrets via /oauth2/register. High severity (CVSS 8.2). Patched in 5.1.7—update now if you use defaultOAuthClients. Details: valtersit.com/cve/CVE-2026-445 #CVE #infosec #Medplum

##

CVE-2026-85781
(0 None)

EPSS: 0.00%

4 posts

N/A

thehackerwire@mastodon.social at 2026-09-04T20:00:00.000Z ##

🟠 CVE-2026-85781 - High (8.7)

Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of direct...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

awssecurityfeed at 2026-09-04T19:15:01.122Z ##

CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver

Bulletin ID: 2026-099-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 11:45 AM PDT
Description:
The Amazon EFS CSI Driver is an open-source Kubernetes Container Storage Interface (CSI) dr...

aws.amazon.com/security/securi

##

thehackerwire@mastodon.social at 2026-09-04T20:00:00.000Z ##

🟠 CVE-2026-85781 - High (8.7)

Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of direct...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

awssecurityfeed@infosec.exchange at 2026-09-04T19:15:01.000Z ##

CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver

Bulletin ID: 2026-099-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 11:45 AM PDT
Description:
The Amazon EFS CSI Driver is an open-source Kubernetes Container Storage Interface (CSI) dr...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-67399
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-09-04T01:46:22.600Z ##

A critical WHMCS security update fixes CVE-2026-67399 and CVE-2026-67398. Apply the patch now to prevent remote code execution and data leaks.

securityonline.info/whmcs-secu

##

DailyCyberSecurity@infosec.exchange at 2026-09-04T01:46:22.000Z ##

A critical WHMCS security update fixes CVE-2026-67399 and CVE-2026-67398. Apply the patch now to prevent remote code execution and data leaks.

#WHMCS #CyberSecurity #CVE202667399 #CVE202667398 #InfoSec

securityonline.info/whmcs-secu

##

CVE-2026-85012
(0 None)

EPSS: 1.06%

3 posts

N/A

hugovalters@mastodon.social at 2026-09-04T01:14:26.000Z ##

CVE-2026-85012 - Command Injection in AWS codecatalyst-blueprints. Arbitrary command execution via crafted .ownership-file. CVSS 8.0. Update to v0.3.156 now. #CVE #AWS #infosec

valtersit.com/cve/CVE-2026-850

##

thehackerwire@mastodon.social at 2026-09-03T19:00:08.000Z ##

🟠 CVE-2026-85012 - High (8)

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T19:00:08.000Z ##

🟠 CVE-2026-85012 - High (8)

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59347
(0 None)

EPSS: 0.00%

2 posts

N/A

beyondmachines1 at 2026-09-03T20:01:31.308Z ##

Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion

Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.

**If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-03T20:01:31.000Z ##

Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion

Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.

**If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-58400
(0 None)

EPSS: 1.19%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-03T19:00:30.000Z ##

🔴 CVE-2026-58400 - Critical (9.1)

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-03T19:00:30.000Z ##

🔴 CVE-2026-58400 - Critical (9.1)

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49869
(0 None)

EPSS: 1.92%

6 posts

N/A

1 repos

https://github.com/Ap0dexMe0/CVE-2026-49869

thecybermind at 2026-09-03T16:09:09.994Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-49869 – Kestra OSS OS Command Injection Vulnerability

Active CISA KEV exploitation of CVE-2026-49869 exposes Kestra OSS to remote OS command injection. Explore board-ready governance, asset enumeration, and risk mitigation....

thecybermind.co/f58i

##

thecybermind@infosec.exchange at 2026-09-03T16:09:09.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-49869 – Kestra OSS OS Command Injection Vulnerability

Active CISA KEV exploitation of CVE-2026-49869 exposes Kestra OSS to remote OS command injection. Explore board-ready governance, asset enumeration, and risk mitigation....

thecybermind.co/f58i

##

thecybermind@infosec.exchange at 2026-09-03T06:18:00.000Z ##

Critical vulnerability CVE-2026-49869 strikes Kestra OSS with active CISA KEV exploitation. Unauthenticated attackers can execute arbitrary OS commands. Read our strategic T-Suite brief for telemetry analysis, CrowdStrike detection queries, and rapid perimeter hardening steps. thecybermind.co/23yx

##

AAKL@infosec.exchange at 2026-09-02T19:01:22.000Z ##

Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.

- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-02T19:00:11.000Z ##

🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48710 (secdb.nttzen.cloud/cve/detail/)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/Kludex/starlette/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-49869 (secdb.nttzen.cloud/cve/detail/)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/kestra-io/kestra/se ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-59822 (secdb.nttzen.cloud/cve/detail/)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: github.com/BerriAI/litellm/sec ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-82329 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83548 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-83549 (secdb.nttzen.cloud/cve/detail/)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: psirt.global.sonicwall.com/vul ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9586 (secdb.nttzen.cloud/cve/detail/)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: sangomakb.atlassian.net/wiki/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586

##

cisakevtracker@mastodon.social at 2026-09-02T18:01:26.000Z ##

CVE ID: CVE-2026-49869
Vendor: Kestra
Product: Kestra OSS
Date Added: 2026-09-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-73299
(0 None)

EPSS: 1.21%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-09-03T14:45:57.000Z ##

A critical Prompty vulnerability (CVE-2026-73299, CVSS 10) let a crafted .prompty file escape the template engine and run arbitrary JavaScript in Node.js.

#Prompty #Microsoft #SSTI #RCE #CVE202673299

meterpreter.org/prompty-cve-20

##

CVE-2026-53635
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-03T12:01:10.000Z ##

🟠 CVE-2026-53635 - High (7.6)

Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is decorated only with @login_r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84394
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-03T07:00:21.000Z ##

🟠 CVE-2026-84394 - High (7.5)

fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as an IP literal nor canonicaliz...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84851
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-03T07:00:10.000Z ##

🟠 CVE-2026-84851 - High (7.5)

An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84382
(0 None)

EPSS: 0.35%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-02T23:02:23.000Z ##

🟠 CVE-2026-84382 - High (7.5)

HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bounded piec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84381
(0 None)

EPSS: 0.08%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-02T23:02:13.000Z ##

🟠 CVE-2026-84381 - High (8.1)

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55221
(0 None)

EPSS: 0.27%

1 posts

N/A

offseq@infosec.exchange at 2026-09-02T21:03:29.000Z ##

CVE-2026-55221 | malach-it boruta-server (MEDIUM): Versions before 0.10.0 log OAuth/OpenID tokens in business event logs. Credentials at risk if logs are accessed. Patch to v0.10.0. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #OAuth #LogSecurity

##

Visit counter For Websites