## Updated at UTC 2026-09-28T21:03:05.008007

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-86950 8.8 0.00% 2 0 2026-09-28T20:17:11.193000 An out-of-bounds write issue was addressed with improved bounds checking. This i
CVE-2026-100643 8.0 0.00% 1 0 2026-09-28T19:16:44.867000 SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View
CVE-2026-100639 8.8 0.00% 1 0 2026-09-28T19:16:44.720000 SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gu
CVE-2026-100622 7.5 0.00% 1 0 2026-09-28T19:16:44.120000 capgo.app through 12.129.0 fails to verify deletion status when serving cached b
CVE-2026-88776 9.8 0.00% 2 1 2026-09-28T18:31:19 Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix N
CVE-2026-88778 7.5 0.00% 5 1 2026-09-28T18:19:33.703000 Predictable exact value from previous values vulnerability in Citrix NetScaler A
CVE-2026-87969 0 0.00% 2 0 2026-09-28T18:17:25.943000 An OS command injection vulnerability in the WatchGuard AP diagnostic CLI allows
CVE-2026-86102 0 0.00% 2 0 2026-09-28T18:17:25.557000 An OS command injection vulnerability in the WatchGuard AP internal API service
CVE-2026-54160 8.2 0.00% 2 0 2026-09-28T18:17:22.433000 Network UPS Tools is a collection of programs which provide a common interface f
CVE-2026-12342 9.6 0.00% 2 0 2026-09-28T18:17:21.410000 This vulnerability impacts all versions of IdentityIQ and allows an unauthentica
CVE-2026-101894 9.1 0.00% 2 0 2026-09-28T18:17:17.730000 The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4
CVE-2026-101891 0 0.00% 2 0 2026-09-28T18:17:17.600000 An improper access control vulnerability in an internal API service on WatchGuar
CVE-2026-100707 7.7 0.00% 1 0 2026-09-28T18:17:16.030000 Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall conte
CVE-2026-100679 8.8 0.00% 1 0 2026-09-28T18:17:15.007000 stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authent
CVE-2026-100567 8.2 0.00% 1 0 2026-09-28T18:17:13.090000 OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versi
CVE-2026-88777 9.8 0.00% 2 1 2026-09-28T18:12:31.173000 Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix N
CVE-2026-101081 9.1 0.00% 2 0 2026-09-28T17:17:47.817000 A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability
CVE-2026-100864 8.8 0.00% 1 0 2026-09-28T17:17:47.360000 heym before 0.0.91 contains a sandbox escape vulnerability in the expression eng
CVE-2026-100852 8.8 0.00% 1 0 2026-09-28T17:17:46.947000 AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquid
CVE-2026-100844 8.4 0.00% 1 0 2026-09-28T17:17:46.637000 MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner c
CVE-2026-100684 8.1 0.00% 1 0 2026-09-28T17:17:45.093000 Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the O
CVE-2026-100680 8.1 0.00% 1 0 2026-09-28T17:17:44.953000 Budibase versions before 3.45.0 fail to disable external JSON reference resoluti
CVE-2026-100672 7.5 0.00% 1 0 2026-09-28T17:17:44.670000 The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version
CVE-2026-100660 7.5 0.00% 1 0 2026-09-28T17:17:44.247000 Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.1
CVE-2026-100656 7.5 0.00% 1 0 2026-09-28T17:17:44.097000 Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue gro
CVE-2026-86609 8.8 0.00% 1 0 2026-09-28T16:38:58.950000 The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape
CVE-2026-100697 8.6 0.00% 1 0 2026-09-28T16:37:02.187000 Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins
CVE-2026-100686 8.1 0.00% 1 0 2026-09-28T16:36:05.010000 Budibase versions before 3.45.0 fail to validate per-app authorization in the PO
CVE-2026-100872 7.5 0.00% 1 0 2026-09-28T16:17:11.483000 Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during
CVE-2026-100700 7.5 0.00% 1 0 2026-09-28T16:17:10.847000 nodemailer before 10.0.6 contains a denial of service vulnerability in the addre
CVE-2026-73640 None 0.00% 2 0 2026-09-28T15:32:02 Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password rec
CVE-2026-88775 9.8 0.00% 2 1 2026-09-28T15:31:46 Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gatew
CVE-2026-88774 7.2 0.00% 2 1 2026-09-28T15:31:46 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-100657 7.5 0.00% 1 0 2026-09-28T15:23:38.510000 Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in Stom
CVE-2026-100662 7.5 0.00% 1 0 2026-09-28T15:23:38.510000 Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4
CVE-2026-100835 7.4 0.00% 1 1 2026-09-28T15:23:38.510000 Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contr
CVE-2026-100839 8.4 0.00% 1 0 2026-09-28T15:23:38.510000 Contrast is a confidential-computing runtime for Kubernetes. In versions before
CVE-2026-100661 7.5 0.00% 1 0 2026-09-28T15:23:38.510000 Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4
CVE-2026-100541 7.5 0.00% 1 0 2026-09-28T15:23:38.510000 OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.
CVE-2026-100544 8.8 0.00% 1 0 2026-09-28T15:23:38.510000 openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured
CVE-2026-100543 7.5 0.00% 1 0 2026-09-28T15:23:38.510000 OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hash
CVE-2026-89078 9.9 0.00% 1 0 2026-09-28T15:22:58.227000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
CVE-2026-100705 7.6 0.00% 1 0 2026-09-28T15:20:06.633000 Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default
CVE-2026-100552 8.8 0.00% 1 0 2026-09-28T15:18:41.260000 OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per
CVE-2026-100561 8.0 0.00% 1 0 2026-09-28T15:18:41.260000 OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain a
CVE-2026-100559 8.0 0.00% 1 0 2026-09-28T15:18:41.260000 OpenClaw versions before 2026.8.1 contain a command parser vulnerability where e
CVE-2026-100570 7.8 0.00% 1 0 2026-09-28T15:18:41.260000 OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an
CVE-2026-101045 8.0 0.00% 1 0 2026-09-28T15:17:11.780000 Fleet-maintained app install and uninstall scripts for macOS are generated from
CVE-2026-100740 9.9 0.00% 2 1 2026-09-28T15:17:11.597000 A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the funct
CVE-2026-101002 9.9 0.00% 2 0 2026-09-28T15:16:04.793000 A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affec
CVE-2026-82901 9.8 0.00% 2 1 2026-09-28T15:16:04.793000 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitr
CVE-2026-77203 8.8 0.00% 1 0 2026-09-28T15:16:04.793000 The Groups – Memberships and Access Control plugin for WordPress is vulnerable t
CVE-2026-82384 9.8 0.00% 1 1 2026-09-28T14:29:44.860000 Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticat
CVE-2026-88773 10.0 0.00% 3 1 2026-09-28T14:27:13.743000 Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling')
CVE-2026-100857 8.0 0.00% 1 0 2026-09-28T14:17:10.717000 AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWri
CVE-2026-100841 7.8 0.00% 1 0 2026-09-28T14:17:10.120000 In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the
CVE-2026-91840 7.8 0.00% 1 0 2026-09-28T13:17:25.337000 A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unpri
CVE-2026-88771 9.8 0.00% 44 6 2026-09-28T13:17:25.027000 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc
CVE-2026-101090 9.8 0.00% 2 0 2026-09-28T13:17:21.117000 Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect e
CVE-2026-101064 7.6 0.00% 1 0 2026-09-28T13:17:19.927000 Obot before v0.23.0 contains a server-side request forgery vulnerability in remo
CVE-2026-101039 10.0 0.00% 2 0 2026-09-28T12:31:13 A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this
CVE-2026-81867 None 0.00% 2 0 2026-09-28T12:31:13 A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Goog
CVE-2026-88772 8.1 0.00% 29 5 2026-09-28T12:26:47.670000 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-101009 8.4 0.00% 1 0 2026-09-28T09:30:34 A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected eleme
CVE-2026-101001 10.0 0.00% 1 0 2026-09-28T06:31:23 A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impac
CVE-2026-101000 10.0 0.00% 1 0 2026-09-28T06:31:23 A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affec
CVE-2026-100908 7.5 0.00% 1 0 2026-09-28T06:31:18 A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown f
CVE-2026-100896 9.9 0.00% 2 0 2026-09-28T03:30:34 A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected
CVE-2026-96896 7.2 0.00% 1 0 2026-09-28T03:30:27 The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19
CVE-2026-81655 7.5 0.00% 2 0 2026-09-28T03:30:25 The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict acce
CVE-2026-100886 10.0 0.00% 2 1 2026-09-28T00:30:36 A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4
CVE-2026-101062 8.8 0.00% 1 0 2026-09-27T21:31:10 Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENAB
CVE-2026-96280 7.5 0.00% 1 0 2026-09-27T21:17:04.200000 The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O an
CVE-2026-101084 9.6 0.00% 2 0 2026-09-27T21:17:02.163000 obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-co
CVE-2026-101065 9.8 0.00% 1 0 2026-09-27T21:17:02.027000 Obot is an open-source AI agent/MCP platform. In all versions up to and includin
CVE-2026-100865 8.8 0.00% 1 0 2026-09-27T18:31:24 Heym before 0.0.53 contains multiple independent vulnerabilities. (1) The workfl
CVE-2026-101060 8.2 0.00% 1 0 2026-09-27T18:30:35 python-utcp versions before 1.1.4 contain a server-side request forgery vulnerab
CVE-2026-100871 8.8 0.00% 1 0 2026-09-27T15:31:14 Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to incl
CVE-2026-100870 8.8 0.00% 1 0 2026-09-27T13:16:38.240000 Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build admini
CVE-2026-100741 9.8 0.00% 2 0 2026-09-27T09:31:17 Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's
CVE-2026-85542 8.8 0.00% 1 0 2026-09-27T04:16:36.100000 IBM Guardium Data Protection 12.2 is affected by a command injection vulnerabili
CVE-2026-100840 7.8 0.00% 1 0 2026-09-27T03:31:13 MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle
CVE-2026-100847 7.5 0.00% 1 0 2026-09-27T03:31:13 AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder
CVE-2026-100851 7.6 0.00% 1 0 2026-09-27T03:31:13 AzuraCast before 0.23.8 contains a broken access control vulnerability in the GE
CVE-2026-100850 7.7 0.00% 1 0 2026-09-27T03:31:13 AzuraCast before 0.23.8 contains a server-side request forgery and local file re
CVE-2026-100856 8.8 0.00% 1 0 2026-09-27T03:31:13 AzuraCast before 0.23.6 contains a code injection vulnerability in the remote re
CVE-2026-100721 9.0 0.00% 2 1 2026-09-27T03:31:12 vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module
CVE-2026-100833 8.2 0.00% 1 0 2026-09-27T03:31:12 Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime p
CVE-2026-100838 8.1 0.00% 1 0 2026-09-27T03:31:12 Contrast is a confidential-computing runtime for Kubernetes. In versions before
CVE-2026-100845 7.8 0.00% 1 0 2026-09-27T03:31:05 MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the Numpy
CVE-2026-100846 7.6 0.00% 1 0 2026-09-27T02:17:23.283000 MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in
CVE-2026-100843 7.8 0.00% 1 0 2026-09-27T02:17:22.853000 MONAI versions before 1.6.0 contain a remote code execution vulnerability in the
CVE-2026-100723 7.5 0.00% 1 0 2026-09-27T02:17:20.553000 vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (b
CVE-2026-96533 5.8 0.00% 1 0 2026-09-27T00:32:20 The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-
CVE-2026-84388 9.6 0.00% 2 1 2026-09-27T00:16:35.007000 A improper restriction of rendered ui layers or frames vulnerability in Fortinet
CVE-2026-100714 9.1 0.00% 1 0 2026-09-26T23:16:33.297000 Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchalleng
CVE-2026-100709 7.5 0.00% 1 0 2026-09-26T23:16:32.930000 Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (p
CVE-2026-85984 9.8 0.00% 2 1 2026-09-26T18:31:08 The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPres
CVE-2026-100715 9.6 0.00% 1 0 2026-09-26T15:31:32 Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink foll
CVE-2026-100720 8.7 0.00% 1 0 2026-09-26T15:31:32 Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When
CVE-2026-100711 7.5 0.00% 1 0 2026-09-26T15:31:28 froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API k
CVE-2026-100716 9.9 0.00% 1 0 2026-09-26T15:31:28 Froxlor is a server administration panel. In versions 2.3.10 and earlier, the cu
CVE-2026-100713 7.8 0.00% 1 0 2026-09-26T15:31:28 Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race con
CVE-2026-100671 8.0 0.00% 1 0 2026-09-26T15:31:27 Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 throug
CVE-2026-100676 8.2 0.00% 1 0 2026-09-26T15:31:27 January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), befor
CVE-2026-100673 8.2 0.00% 1 0 2026-09-26T15:31:27 The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 th
CVE-2026-100685 7.7 0.00% 1 0 2026-09-26T15:31:27 Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint
CVE-2026-100683 8.0 0.00% 1 0 2026-09-26T15:31:27 Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename D
CVE-2026-100682 8.8 0.00% 1 0 2026-09-26T15:31:27 Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in
CVE-2026-100690 7.5 0.00% 1 0 2026-09-26T15:31:27 Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css
CVE-2026-100706 9.9 0.00% 1 0 2026-09-26T15:31:27 kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Po
CVE-2026-100704 7.7 0.00% 1 0 2026-09-26T15:31:27 Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, th
CVE-2026-100703 7.7 0.00% 1 0 2026-09-26T15:31:27 Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its
CVE-2026-100664 7.5 0.00% 1 0 2026-09-26T15:31:26 Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4
CVE-2026-100669 7.5 0.00% 1 0 2026-09-26T15:31:26 Grav before 2.0.25 ships web server configuration samples whose access-control d
CVE-2026-100692 7.5 0.00% 1 0 2026-09-26T15:31:23 Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0,
CVE-2026-100693 8.4 0.00% 1 0 2026-09-26T15:31:23 Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation
CVE-2026-100637 7.6 0.00% 1 0 2026-09-26T15:31:22 SiYuan versions before v3.8.4 contain a path traversal vulnerability in the chec
CVE-2026-100636 7.6 0.00% 1 0 2026-09-26T15:31:22 SiYuan versions before v3.8.4 contain a path traversal vulnerability in the expo
CVE-2026-100646 8.1 0.00% 1 0 2026-09-26T15:31:22 SiYuan is a self-hosted personal knowledge management system. In versions up to
CVE-2026-100644 7.5 0.00% 1 0 2026-09-26T15:31:22 SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query e
CVE-2026-100642 7.6 0.00% 1 0 2026-09-26T15:31:22 SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery v
CVE-2026-100641 8.0 0.00% 1 0 2026-09-26T15:31:22 SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before
CVE-2026-100655 7.5 0.00% 1 0 2026-09-26T15:31:22 Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and
CVE-2026-100663 7.5 0.00% 1 0 2026-09-26T15:31:22 Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.1
CVE-2026-100627 8.1 0.00% 1 0 2026-09-26T15:31:21 Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect
CVE-2026-100631 7.5 0.00% 1 0 2026-09-26T15:31:21 Parse Server is an open source backend server. In versions prior to 8.6.90 and i
CVE-2026-100665 7.5 0.00% 1 0 2026-09-26T15:31:19 Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostn
CVE-2026-100623 8.8 0.00% 1 0 2026-09-26T15:31:16 Capgo (capgo.app) exposes the legacy membership table public.org_users directly
CVE-2026-100717 9.9 0.00% 1 0 2026-09-26T14:16:57.867000 froxlor is a server administration panel. In versions 2.3.10 and earlier, Valida
CVE-2026-100670 8.8 0.00% 1 0 2026-09-26T14:16:50.697000 Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in
CVE-2026-100645 8.0 0.00% 1 0 2026-09-26T14:16:46.857000 SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnera
CVE-2026-100638 7.6 0.00% 1 0 2026-09-26T14:16:45.590000 SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setN
CVE-2026-18143 9.8 0.00% 2 1 2026-09-26T09:30:26 The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitr
CVE-2026-65660 8.8 0.00% 2 2 2026-09-26T04:17:45.630000 Improper control of generation of code ('code injection') in Microsoft Office Sh
CVE-2026-100208 7.5 0.00% 1 0 2026-09-26T04:17:33.933000 Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorize
CVE-2026-100560 7.5 0.00% 1 0 2026-09-26T03:30:35 OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability
CVE-2026-100568 8.3 0.00% 1 0 2026-09-26T03:30:35 OpenClaw versions before 2026.8.1 fail to properly restrict access to operator c
CVE-2026-100558 7.5 0.00% 1 0 2026-09-26T03:30:34 OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in
CVE-2026-100557 8.3 0.00% 1 0 2026-09-26T03:30:34 OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability
CVE-2026-100532 8.1 0.00% 1 0 2026-09-26T03:30:28 @openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through
CVE-2026-100535 7.5 0.00% 1 0 2026-09-26T03:30:28 OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose t
CVE-2026-100551 8.3 0.00% 2 0 2026-09-26T03:30:25 OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gatew
CVE-2026-100382 None 0.00% 1 1 2026-09-26T00:32:22 Improper Neutralization of Special Elements used in an OS Command ('OS Command I
CVE-2026-97063 9.1 0.00% 1 0 2026-09-25T21:33:06 X-SpringBoot through 6.0 returns login verification codes in HTTP responses from
CVE-2026-97064 9.1 0.00% 1 0 2026-09-25T21:33:03 X-SpringBoot through 6.0 ships with a hardcoded static master login verification
CVE-2026-100389 8.1 0.00% 1 0 2026-09-25T21:17:22.483000 GestSup versions before 3.2.61 contain a remote code execution vulnerability in
CVE-2026-92161 9.8 0.00% 1 0 2026-09-25T20:31:30 ### Impact An unauthenticated account takeover vulnerability exists in `fof/oau
CVE-2026-91841 7.8 0.00% 1 0 2026-09-25T18:31:36 A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A loca
CVE-2026-91839 7.8 0.00% 1 0 2026-09-25T18:31:36 A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for Netwo
CVE-2026-91838 7.8 0.00% 1 0 2026-09-25T18:31:36 A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager.
CVE-2026-94445 8.8 0.00% 1 0 2026-09-25T18:31:35 A malicious txtar could escape the intended execution context and force arbitrar
CVE-2026-91837 7.8 0.00% 1 0 2026-09-25T17:17:18.983000 A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkMana
CVE-2026-89032 7.7 0.00% 1 0 2026-09-25T17:17:18.793000 BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerabi
CVE-2026-62062 8.8 0.00% 4 1 2026-09-25T14:17:18.807000 Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder all
CVE-2026-14281 9.8 0.00% 1 3 2026-09-25T09:31:05 The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Co
CVE-2026-15027 8.8 0.00% 1 0 2026-09-24T14:45:22.827000 CGServiSign developed by Changing has a OS Command Injection vulnerability. Unau
CVE-2026-94097 10.0 0.00% 1 0 2026-09-24T13:17:17.460000 A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affec
CVE-2026-19599 9.9 0.00% 1 0 2026-09-24T04:17:48.027000 ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable
CVE-2026-93577 9.9 0.00% 1 0 2026-09-24T00:30:34 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
CVE-2026-76978 8.8 0.00% 1 0 2026-09-23T15:30:52 ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and belo
CVE-2026-93616 9.8 0.00% 2 1 2026-09-22T21:31:15 A directory traversal and file upload vulnerability allows an unauthenticated at
CVE-2026-85102 9.8 0.00% 1 0 2026-09-22T21:30:40 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-94533 6.5 0.00% 1 0 2026-09-22T20:53:07.383000 lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in File
CVE-2026-82890 5.9 0.00% 1 0 2026-09-22T19:32:25.730000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-92235 8.1 0.00% 1 0 2026-09-22T19:04:55.677000 The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary short
CVE-2026-94492 6.3 0.00% 1 0 2026-09-22T19:04:55.677000 A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerabi
CVE-2026-93836 7.2 0.00% 1 0 2026-09-22T19:04:55.677000 The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to St
CVE-2026-43641 9.8 0.00% 1 0 2026-09-22T18:33:42 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command
CVE-2026-74849 9.8 0.00% 1 0 2026-09-22T12:30:32 Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerab
CVE-2026-7273 8.8 0.00% 1 0 2026-09-22T12:10:51.067000 A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-4
CVE-2026-93778 7.2 0.00% 1 0 2026-09-22T09:31:18 The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Sit
CVE-2026-94504 7.2 0.00% 1 1 2026-09-22T09:31:17 Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it wit
CVE-2026-80521 7.8 0.00% 2 1 2026-09-21T15:32:39 In the Linux kernel, the following vulnerability has been resolved: af_unix: Un
CVE-2026-94098 9.1 0.00% 1 0 2026-09-21T03:30:22 A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulne
CVE-2025-39964 7.8 0.00% 1 2 2026-09-19T04:17:48.307000 In the Linux kernel, the following vulnerability has been resolved: crypto: af_
CVE-2026-89775 9.3 0.00% 1 0 2026-09-16T18:31:58 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64:
CVE-2026-43786 7.8 0.00% 1 2 2026-09-15T00:31:13 This issue was addressed with additional entitlement checks. This issue is fixed
CVE-2026-0310 0 0.00% 1 0 2026-09-11T04:17:13.060000 A buffer overflow vulnerability in the XML processing functionality of Palo Alto
CVE-2026-75960 8.1 0.00% 1 0 2026-08-26T18:32:04 Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently
CVE-2026-55074 None 0.00% 1 0 2026-08-13T15:58:54 Through version 1.3.0, the jailexec connection plugin's put_file resolved a tran
CVE-2026-58052 3.3 0.00% 1 0 2026-08-07T20:47:38.443000 7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extra
CVE-2026-35273 9.8 0.00% 6 4 template 2026-07-23T09:10:00.113000 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS
CVE-2026-94545 0 0.00% 1 2 N/A
CVE-2026-87902 0 0.00% 3 24 template N/A
CVE-2026-32740 0 0.00% 1 1 N/A
CVE-2026-887712 0 0.00% 1 0 N/A

CVE-2026-86950
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T20:17:11.193000

2 posts

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions o

applsec at 2026-09-28T19:11:35.067Z ##

📣 EMERGENCY UPDATE 📣

Apple pushed updates for a new zero-day that may have been actively exploited.

🐛 CVE-2026-86950 (CoreGraphics):
- iOS and iPadOS 26.7.1
- macOS Sequoia 15.8.1
- macOS Tahoe 26.7.1

##

applsec@infosec.exchange at 2026-09-28T19:11:35.000Z ##

📣 EMERGENCY UPDATE 📣

Apple pushed updates for a new zero-day that may have been actively exploited.

🐛 CVE-2026-86950 (CoreGraphics):
- iOS and iPadOS 26.7.1
- macOS Sequoia 15.8.1
- macOS Tahoe 26.7.1

#apple #cybersecurity #infosec #security #ios

##

CVE-2026-100643
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-28T19:16:44.867000

1 posts

SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. Attackers can execute stored JavaScript when other users open affected database menus, and in the Electron desktop app with

thehackerwire@mastodon.social at 2026-09-28T02:01:03.000Z ##

🟠 CVE-2026-100643 - High (8)

SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100639
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T19:16:44.720000

1 posts

SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/button.ts, assigned via innerHTML in app/src/protyle/gutter/index.ts) from content pasted as plain-text Markdown containing a Kramdown inline attribute list (IAL). Because the shared Lute renderer parses Kramdown IAL from text/plain input, an attacker-supplied Markdown snippet

thehackerwire@mastodon.social at 2026-09-28T02:45:54.000Z ##

🟠 CVE-2026-100639 - High (8.8)

SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/button.ts, assigned via innerHTML in app/src/protyle/gutter/index.ts) from content pasted as plain-text Markdown containing ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100622
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T19:16:44.120000

1 posts

capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint. Unauthenticated attackers can download deleted bundles using cached URLs and trigger restoration of deleted objects into R2 storage on cache hits.

thehackerwire@mastodon.social at 2026-09-28T07:16:54.000Z ##

🟠 CVE-2026-100622 - High (7.5)

capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint. Unauthenticated attackers can download deleted bundles using cached URLs and trigger restoration of deleted objects...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88776
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T18:31:19

2 posts

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service

1 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-88778
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T18:19:33.703000

5 posts

Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.

1 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

secdb@infosec.exchange at 2026-09-27T23:00:11.000Z ##

🚨 [CISA-2026:0927] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-88771 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: community.citrix.com/techzone- ; support.citrix.com/support-hom ; support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-88772 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: community.citrix.com/techzone- ; support.citrix.com/support-hom ; support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260927 #cisa20260927 #cve_2026_88771 #cve_2026_88772 #cve202688771 #cve202688772

##

zackwhittaker@mastodon.social at 2026-09-27T20:04:46.000Z ##

Citrix has a security post on its website that also confirms exploitation and has a bunch of remedation advice, which you might not know because the company set the page to "noindex," so it doesn't show up in search results. 🤦‍♂️

community.citrix.com/techzone-

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

pedro@infosec.exchange at 2026-09-27T16:22:43.000Z ##

@watchTowr Thanks for being on top of it 💪
community.citrix.com/techzone-

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-87969
(0 None)

EPSS: 0.00%

updated 2026-09-28T18:17:25.943000

2 posts

An OS command injection vulnerability in the WatchGuard AP diagnostic CLI allows an authenticated administrator to execute arbitrary operating system commands by supplying crafted input.

CVE-2026-86102
(0 None)

EPSS: 0.00%

updated 2026-09-28T18:17:25.557000

2 posts

An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.

CVE-2026-54160
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-28T18:17:22.433000

2 posts

Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitHub Checks statuses and PR comments about it was mis-structured in terms of mixing code running with higher privileges (single-use token generated with wr

thehackerwire@mastodon.social at 2026-09-28T17:30:41.000Z ##

🟠 CVE-2026-54160 - High (8.2)

Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitH...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-28T17:30:41.000Z ##

🟠 CVE-2026-54160 - High (8.2)

Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitH...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12342
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T18:17:21.410000

2 posts

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.

cR0w at 2026-09-28T18:54:15.567Z ##

You had one job.

sailpoint.com/security-advisor

sev:CRIT 9.6 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.

##

cR0w@infosec.exchange at 2026-09-28T18:54:15.000Z ##

You had one job.

sailpoint.com/security-advisor

sev:CRIT 9.6 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.

##

CVE-2026-101894
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T18:17:17.730000

2 posts

The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output

thehackerwire@mastodon.social at 2026-09-28T17:30:49.000Z ##

🔴 CVE-2026-101894 - Critical (9.1)

The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-28T17:30:49.000Z ##

🔴 CVE-2026-101894 - Critical (9.1)

The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101891
(0 None)

EPSS: 0.00%

updated 2026-09-28T18:17:17.600000

2 posts

An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.

CVE-2026-100707
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-28T18:17:16.030000

1 posts

Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and execution. A low-privilege tenant can use percent-encoded dot-segments in urlPath to bypass namespace checks and read resources from other namespaces using the Kyverno admission controller's ServiceAccount credentials

thehackerwire@mastodon.social at 2026-09-27T00:46:46.000Z ##

🟠 CVE-2026-100707 - High (7.7)

Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and execution. A low-privilege tenant can use percent-encoded dot-se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100679
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T18:17:15.007000

1 posts

stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account and use it with a victim's session token to disable TOTP, view recovery codes, or perform other sensitive operations without providing the victim's creden

thehackerwire@mastodon.social at 2026-09-27T02:01:33.000Z ##

🟠 CVE-2026-100679 - High (8.8)

stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100567
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-28T18:17:13.090000

1 posts

OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gateway validated a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the raw WebSocket and Playwright transports performed a later, independent DNS resolution, discarding the DNS pinning enforced at validation time. An attacker who con

thehackerwire@mastodon.social at 2026-09-26T06:32:46.000Z ##

🟠 CVE-2026-100567 - High (8.2)

OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and &lt; 2026.8.1, the Gateway validated a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the raw We...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88777
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T18:12:31.173000

2 posts

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service

1 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-101081
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T17:17:47.817000

2 posts

A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

thehackerwire@mastodon.social at 2026-09-28T17:30:59.000Z ##

🔴 CVE-2026-101081 - Critical (9.1)

A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-28T17:30:59.000Z ##

🔴 CVE-2026-101081 - Critical (9.1)

A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100864
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T17:17:47.360000

1 posts

heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python code. Attackers can craft workflow expressions using dunder attribute access through item expressions or the fallback resolver to access os.system and execute commands as the backend process.

thehackerwire@mastodon.social at 2026-09-27T02:31:33.000Z ##

🟠 CVE-2026-100864 - High (8.8)

heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python code. Attackers can craft workflow expressions using dunder ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100852
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T17:17:46.947000

1 posts

AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permissions can set a username containing shell metacharacters and trigger command execution as the Liquidsoap process user when recording closes.

thehackerwire@mastodon.social at 2026-09-27T02:46:15.000Z ##

🟠 CVE-2026-100852 - High (8.8)

AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100844
(8.4 HIGH)

EPSS: 0.00%

updated 2026-09-28T17:17:46.637000

1 posts

MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments are concatenated into a command string without quoting or validation and then passed to subprocess with shell=True, so shell metacharacters (e.g., ';' on

thehackerwire@mastodon.social at 2026-09-28T00:45:45.000Z ##

🟠 CVE-2026-100844 - High (8.4)

MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100684
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-28T17:17:45.093000

1 posts

Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone — without validating an invite code and without an email_verified check (the email_verified gate protects only the existin

thehackerwire@mastodon.social at 2026-09-27T01:32:58.000Z ##

🟠 CVE-2026-100684 - High (8.1)

Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the Id...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100680
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-28T17:17:44.953000

1 posts

Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references in OpenAPI specifications submitted to the import endpoint to exfiltrate sensitive files including environment variables containing JWT secrets, API keys,

thehackerwire@mastodon.social at 2026-09-27T01:16:32.000Z ##

🟠 CVE-2026-100680 - High (8.1)

Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100672
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T17:17:44.670000

1 posts

The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the admin service is registered on the current route rather than that the visitor is authenticated, and it echoes the JSON and calls exit() during the plugin

thehackerwire@mastodon.social at 2026-09-27T02:16:52.000Z ##

🟠 CVE-2026-100672 - High (7.5)

The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100660
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T17:17:44.247000

1 posts

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker for every encoded field section that references the QPACK dynamic table, keyed by the peer-controlled QUIC stream ID, and these entries are released only when the remote decoder sends a Section Acknow

thehackerwire@mastodon.social at 2026-09-28T01:45:44.000Z ##

🟠 CVE-2026-100660 - High (7.5)

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker for every encoded field section that references...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100656
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T17:17:44.097000

1 posts

Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks the HTTP method of each still-unanswered pipelined request; the first 32 entries are bit-packed into a single long, but every additional entry is appended to methodOverflowQueue, an ArrayDeque with no size limit and no rejection path. A remote, unauthenticated attacker who

thehackerwire@mastodon.social at 2026-09-28T01:30:52.000Z ##

🟠 CVE-2026-100656 - High (7.5)

Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks the HTTP method of each still-unanswered pipelined request; the first 32 entries are bit-packed into a single long, but e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86609
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T16:38:58.950000

1 posts

The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin befor

thehackerwire@mastodon.social at 2026-09-28T02:31:16.000Z ##

🟠 CVE-2026-86609 - High (8.8)

The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform S...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100697
(8.6 HIGH)

EPSS: 0.00%

updated 2026-09-28T16:37:02.187000

1 posts

Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[driver]=clickhouse with auth[server] set to an arbitrary URL (for example http://127.0.0.1:18089), causing the Adminer server to issue an HTTP POST contain

thehackerwire@mastodon.social at 2026-09-27T01:01:39.000Z ##

🟠 CVE-2026-100697 - High (8.6)

Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[dr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100686
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-28T16:36:05.010000

1 posts

Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.

thehackerwire@mastodon.social at 2026-09-27T01:01:48.000Z ##

🟠 CVE-2026-100686 - High (8.1)

Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit mi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100872
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T16:17:11.483000

1 posts

Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.

thehackerwire@mastodon.social at 2026-09-28T00:30:46.000Z ##

🟠 CVE-2026-100872 - High (7.5)

Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100700
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T16:17:10.847000

1 posts

nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs to block the Node.js event loop for tens of seconds, causing service unavailability.

thehackerwire@mastodon.social at 2026-09-27T00:31:17.000Z ##

🟠 CVE-2026-100700 - High (7.5)

nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free run...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73640(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-28T15:32:02

2 posts

Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an arbitrary SQL query. The parameter is interpreted as part of SQL predicate resulting in Time-Based Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only bee

cR0w at 2026-09-28T16:09:17.122Z ##

sev:CRITs in Dayforce Payroll. Go patch and protect that shit before your pay gets fucked.

cert.pl/en/posts/2026/09/CVE-2

##

cR0w@infosec.exchange at 2026-09-28T16:09:17.000Z ##

sev:CRITs in Dayforce Payroll. Go patch and protect that shit before your pay gets fucked.

cert.pl/en/posts/2026/09/CVE-2

##

CVE-2026-88775
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T15:31:46

2 posts

Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

1 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-88774
(7.2 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:31:46

2 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.

1 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

CVE-2026-100657
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:23:38.510000

1 posts

Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder. Once a frame's declared content-length has been fully read, the decoder allocates a chunk buffer from the channel allocator and parks it in an instance field while waiting for the single NUL byte that terminates the frame. If that byte never arrives, the buffer is never released: the replay Signal thr

thehackerwire@mastodon.social at 2026-09-28T01:45:36.000Z ##

🟠 CVE-2026-100657 - High (7.5)

Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder. Once a frame's declared content-length has been fully read, the decoder allocates a chunk buffer from the channel allocator and parks it in an instan...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100662
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:23:38.510000

1 posts

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder (QpackEncoderHandler, installed on the peer-initiated unidirectional QPACK encoder stream, type 0x02). The handler accepts an attacker-declared string-literal length of up to Integer.MAX_VALUE (~2 GiB)

thehackerwire@mastodon.social at 2026-09-28T01:15:31.000Z ##

🟠 CVE-2026-100662 - High (7.5)

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder (QpackEncoderHandler, installed on the peer-init...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100835
(7.4 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:23:38.510000

1 posts

Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI a

1 repos

https://github.com/murrez/CVE-2026-100835

offseq@infosec.exchange at 2026-09-27T04:30:24.000Z ##

CVE-2026-100835: Contrast <1.16.0 faces CRITICAL remote attestation relay attacks. Any valid TEE attestation report is accepted, risking trust bypass. Upgrade ASAP. radar.offseq.com/threat/contra #OffSeq #CVE2026100835 #infosec #security

##

CVE-2026-100839
(8.4 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:23:38.510000

1 posts

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted host (QEMU) to the guest firmware (OVMF) and on to the Linux kernel, whose AML interpreter executes them. An attacker controlling the host — an assumed adve

thehackerwire@mastodon.social at 2026-09-27T02:47:28.000Z ##

🟠 CVE-2026-100839 - High (8.4)

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted hos...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100661
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:23:38.510000

1 posts

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound the number of continuation bytes it will process. A remote, unauthenticated peer can open a QPACK unidirectional stream (type 0x02 encoder or 0x03 decoder) and send a first

thehackerwire@mastodon.social at 2026-09-27T02:17:02.000Z ##

🟠 CVE-2026-100661 - High (7.5)

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound the number of conti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100541
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:23:38.510000

1 posts

OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can normalize to the same authorization identity. A Matrix participant controlling a c

thehackerwire@mastodon.social at 2026-09-26T07:30:48.000Z ##

🟠 CVE-2026-100541 - High (7.5)

OpenClaw's Matrix integration (npm package @OpenClaw/matrix) versions >= 2026.2.2 and &lt; 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw au...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100544
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:23:38.510000

1 posts

openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose the agent's normal tool authority to a remote caller. A caller who is admitted by the configured inbound-call policy (open, pairing, or allowlist) on a dep

thehackerwire@mastodon.social at 2026-09-26T07:15:40.000Z ##

🟠 CVE-2026-100544 - High (8.8)

openclaw's @OpenClaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100543
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:23:38.510000

1 posts

OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as offline password verifiers: a caller able to obtain the redacted configuration (for example via config

thehackerwire@mastodon.social at 2026-09-26T07:15:31.000Z ##

🟠 CVE-2026-100543 - High (7.5)

OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89078
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T15:22:58.227000

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.

beyondmachines1@infosec.exchange at 2026-09-26T10:01:12.000Z ##

GitLab Patches Critical Regex Flaws Allowing Remote Code Execution

GitLab released emergency patches for 11 vulnerabilities, including two critical regex-related flaws (CVE-2026-89078 and CVE-2026-93577) that allow authenticated attackers to execute arbitrary code on self-managed servers.

**If you run your own GitLab server, update it to version 19.4.1, 19.3.3, or 19.2.7. Two critical flaws allow any logged-in user take over the whole server. After updating, check your .gitlab-ci.yml files for new or strange-looking regular expressions, and review who has access to your projects in case someone already tried to exploit this. GitLab.com and GitLab Dedicated users don't need to do anything.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-100705
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:20:06.633000

1 posts

Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.169.253, metadata.google.internal, 127.0.0.0/8, ::1/128) and the scoped-token control were wired only into the new CEL http.Get/Post library and were never applied to the legacy apiCall service executor (pkg/engine/apicall/executor.go) or to the GlobalContextEntry external-API

thehackerwire@mastodon.social at 2026-09-27T00:46:29.000Z ##

🟠 CVE-2026-100705 - High (7.6)

Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.169.253, metadata.google.internal, 127.0.0.0/8, ::1/128) and the scoped-token control were wired only into the new CEL http....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100552
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:18:41.260000

1 posts

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, and patch tools owned by the Codex runtime. When a lower-trust conversation was assigned to a Codex runtime and restricted with a per-chat tool allowlist,

thehackerwire@mastodon.social at 2026-09-26T07:15:22.000Z ##

🟠 CVE-2026-100552 - High (8.8)

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100561
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:18:41.260000

1 posts

OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign wrapper invocation, a later agent turn could substitute an arbitrary inner command and execute it w

thehackerwire@mastodon.social at 2026-09-26T07:01:05.000Z ##

🟠 CVE-2026-100561 - High (8)

OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and &lt; 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100559
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:18:41.260000

1 posts

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and execute additional commands without expected authorization prompts.

thehackerwire@mastodon.social at 2026-09-26T06:45:37.000Z ##

🟠 CVE-2026-100559 - High (8)

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100570
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:18:41.260000

1 posts

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and then runs the Gmail setup flow, that value is inherited when gcloud is launched, and the gcloud launcher passes it as arguments to the trusted Python interpre

thehackerwire@mastodon.social at 2026-09-26T06:32:36.000Z ##

🟠 CVE-2026-100570 - High (7.8)

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and &lt; 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101045
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:17:11.780000

1 posts

Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the script generator escaped this metadata at some interpolation sites but not all of them, so cask metadata containing shell metacharacters (for example $(...) command substitution) could be carried into scripts that execute as root on managed macOS hos

thehackerwire@mastodon.social at 2026-09-28T00:16:38.000Z ##

🟠 CVE-2026-101045 - High (8)

Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the script generator escaped this metadata at some interpolation sites but not all of them, so cask m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100740
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T15:17:11.597000

2 posts

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.

1 repos

https://github.com/murrez/CVE-2026-100740

thehackerwire@mastodon.social at 2026-09-27T01:32:18.000Z ##

🔴 CVE-2026-100740 - Critical (9.9)

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-27T01:30:24.000Z ##

D-Link DIR-895L hit by CRITICAL vuln: CVE-2026-100740 (CVSS 9.4) in tunnel_set_params — public exploit code enables remote RCE or DoS via out-of-bounds write. No patch yet. Monitor for updates: radar.offseq.com/threat/cve-20 #OffSeq #CVE2026100740 #infosec #RouterSecurity

##

CVE-2026-101002
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T15:16:04.793000

2 posts

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early

thehackerwire@mastodon.social at 2026-09-28T07:01:50.000Z ##

🔴 CVE-2026-101002 - Critical (9.9)

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-28T06:00:24.000Z ##

CVE-2026-101002: Critical OS command injection in Netcore NBR200V2 v1.3.241127.071246 via Tools Ping Handler. Public exploit code available; no vendor patch. Isolate devices, restrict network access. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026101002 #Netcore #Vuln

##

CVE-2026-82901
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T15:16:04.793000

2 posts

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is o

1 repos

https://github.com/murrez/CVE-2026-82901

offseq@infosec.exchange at 2026-09-27T00:00:34.000Z ##

CVE-2026-82901: CRITICAL (CVSS 9.8) file upload vuln in Ultra Addons for Contact Form 7 (≤3.5.50). RCE risk if PDF Generator enabled (off by default). Disable/monitor plugin & watch for patches. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #Vulnerability

##

thehackerwire@mastodon.social at 2026-09-26T23:46:38.000Z ##

🔴 CVE-2026-82901 - Critical (9.8)

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it poss...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77203
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T15:16:04.793000

1 posts

The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's author capabilities via the global $post->post_author rather than from the currently authenticated user's own capabilities, while simultaneously minting a

thehackerwire@mastodon.social at 2026-09-26T23:46:56.000Z ##

🟠 CVE-2026-77203 - High (8.8)

The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82384
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T14:29:44.860000

1 posts

Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no

1 repos

https://github.com/murrez/CVE-2026-82384

offseq@infosec.exchange at 2026-09-28T09:00:26.000Z ##

Apache Roller 6.1.5 is vulnerable (CVE-2026-82384, CRITICAL, CVSS 9.8): unauthenticated remote deserialization can lead to RCE via XML-RPC — even if disabled. Upgrade to 6.1.6+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #ApacheRoller #CVE202682384 #infosec

##

CVE-2026-88773
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T14:27:13.743000

3 posts

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

1 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

GossiTheDog@cyberplace.social at 2026-09-27T15:33:35.000Z ##

Netscaler CVEs are out:

support.citrix.com/support-hom

Patch isn’t yet through QA at Citrix still, been a week :02angery:

The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained.

It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.

Probably nation state aligned as well resourced, espionage rather than teens.

##

CVE-2026-100857
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-28T14:17:10.717000

1 posts

AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Attackers can inject #{process.run()} expressions into playlist URLs or station metadata fields tha

thehackerwire@mastodon.social at 2026-09-27T02:32:33.000Z ##

🟠 CVE-2026-100857 - High (8)

AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100841
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T14:17:10.120000

1 posts

In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_only=False). Related cache helpers in monai/data/utils.py also call pickle.loads on cached content and derive cache keys with hashlib.md5. As a result, a

thehackerwire@mastodon.social at 2026-09-27T03:02:12.000Z ##

🟠 CVE-2026-100841 - High (7.8)

In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91840
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-28T13:17:25.337000

1 posts

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.

thehackerwire@mastodon.social at 2026-09-26T08:00:45.000Z ##

🟠 CVE-2026-91840 - High (7.8)

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88771
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T13:17:25.027000

44 posts

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

6 repos

https://github.com/EXEcution-py/CVE-2026-88771-POC

https://github.com/securekomodo/citrixInspector

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771

https://github.com/techupdate24/citrix-netscaler-cve-2026-88771-rce

https://github.com/technion/netscaler_scanner

cyberveille@mastobot.ping.moi at 2026-09-28T20:30:05.000Z ##

📢 Deux zero-days critiques NetScaler (CVE-2026-88771 et CVE-2026-88772) exploités activement

🔍 Vulnérabilités identifiées Citrix a publié le bulletin de sécurité CTX697096 confirmant deux failles critiques : CVE-2026-88771 (score CVSS 9.5) : Exécution de code à distance via une validation d'entrée incorrecte, exploitable sans authentification, affectant…

📖 cyberveille : cyberveille.ch/posts/2026-09-2
🌐 source : bleepingcomputer.com/news/secu
🟡 vérification factuelle moyenne
#NetScaler #ZeroDay #Cyberveille

##

sayzard@mastodon.sayzard.org at 2026-09-28T18:45:11.000Z ##

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix는 인터넷 경계에 배치되는 NetScaler ADC·Gateway의 치명적 RCE 제로데이 CVE-2026-88771 및 CVE-2026-88772가 실제 공격에 악용되고 있음을 확인하고 패치를 배포했습니다. 두 취약점 모두 CVSS 9.5이며, 전자는 인증 없이 임의 명령 실행이 가능한 입력 검증 취약점이고, 후자는 DTLS 활성화 환경(기본 VPN 가상 서버 포함)에서 RCE 또는 DoS를 유발할 수 있는 메모리 오버플로입니다. 영향을 받...

bleepingcomputer.com/news/secu

##

sayzard@mastodon.sayzard.org at 2026-09-28T17:41:42.000Z ##

Citrix NetScaler PreAuth Command Injection CVE-2026-88771

watchTowr는 Citrix NetScaler ADC/Gateway의 CVE-2026-88771을 기본 구성에서 인증 없이 임의 명령을 실행할 수 있는 사전 인증(command injection) 취약점으로 분석했다. CVSS 9.5이며 패치 이전 제로데이로 실제 악용된 정황이 보고돼, 인터넷 노출 NetScaler 장비를 운영하는 조직에는 즉각적인 대응이 필요하다. 원인은 Perl 진단 스크립트가 로그에서 얻은 값을 검증 없이 셸 명령 문자열에 삽입한 것으...

labs.watchtowr.com/oh-look-the

##

ssvc at 2026-09-28T17:18:37.350Z ##

GreyNoise saw CVE-2026-88771 exploitation attempts on Sep 24, more than three days before public disclosure. Some IOC are listed.

greynoise.io/blog/swarming-aga

##

thenextweb@flipboard.com at 2026-09-28T16:42:18.000Z ##

Hackers are exploiting two critical Citrix NetScaler zero-days
thenextweb.com/news/citrix-net

Posted into TNW - All Stories @tnw-all-stories-thenextweb

##

AAKL at 2026-09-28T16:45:24.946Z ##

Tenable, posted yesterday: Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities tenable.com/blog/frequently-as @tenablesecurity

GreyNoise: Swarming Against Citrix 0-Day Exploitation greynoise.io/blog/swarming-aga @greynoise

WatchTower: Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) labs.watchtowr.com/oh-look-the

@ifin

##

youranonnewsirc@nerdculture.de at 2026-09-28T16:25:41.000Z ##

Here's a summary of the latest geopolitical, technology, and cybersecurity news:

Geopolitically, US-Iran tensions remain high after President Trump rejected a Strait of Hormuz proposal, with ongoing investigations into potential terror links to Iran after arrests near a U.S.-operated air base in the UK. Russia has intensified attacks on Kyiv, while Ukraine reportedly recaptured territory in Donetsk.

In technology, OpenAI halted AI model training due to "rogue agent" incidents and unexpected behavior on government websites. Nvidia launched an Open Agent Safety Platform to enhance AI security.

Cybersecurity saw critical Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) actively exploited globally, prompting CISA to add them to its KEV catalog. Ransomware activity reached a 2026 high in August, with industrial sectors being the most targeted. A new Carbonato botnet targets Docker hosts to deploy a Telegram-controlled AI agent. Kiteworks also advised customers to temporarily shut down their platform due to credible threat intelligence.

#AnonNews_irc #Cybersecurity #News

##

Matchbook3469@mastodon.social at 2026-09-28T14:23:53.000Z ##

🔴 New security advisory:

CVE-2026-88771 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#Cybersecurity #VulnerabilityManagement #CyberSec

##

glitterbean@wehavecookies.social at 2026-09-28T13:28:52.000Z ##

Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) labs.watchtowr.com/oh-look-the

##

christopherkunz@chaos.social at 2026-09-28T13:13:55.000Z ##

@bsi labs.watchtowr.com/oh-look-the
Ab wann gilt der Betrieb dieser Geräte eigentlich als fahrlässig?

##

bsi@social.bund.de at 2026-09-28T13:04:09.000Z ##

⚠️ 📢 Sicherheitswarnung: Am 27. September 2026 veröffentlichte der Hersteller #Citrix ein Advisory [CIT26a] zu insgesamt acht Sicherheitslücken in seinen Produkten NetScaler ADC (ehemals Citrix ADC) und NetScaler Gateway (ehemals Citrix Gateway). Hierin enthalten sind auch zwei #ZeroDay-Schwachstellen (CVE-2026-88771 und CVE-2026-88772), zu denen sich im Laufe des vergangenen Wochenendes Berichte über eine aktive Ausnutzung verbreitet hatten.

Mehr dazu hier: bsi.bund.de/dok/1209522

##

computersweden@friendica.helvetet.eu at 2026-09-28T11:03:35.000Z ## Sårbarheterna CVE-2026-88771 och CVE-2026-88772 utnyttjas nu aktivt.#Security
Hackare utnyttjar kritiska sårbarheter i Citrix Netscaler ##

ssvc at 2026-09-28T12:16:27.850Z ##

CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.

cisa.gov/news-events/alerts/20

##

_r_netsec at 2026-09-28T11:13:05.012Z ##

Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs labs.watchtowr.com/oh-look-the

##

ssvc@infosec.exchange at 2026-09-28T17:18:37.000Z ##

GreyNoise saw CVE-2026-88771 exploitation attempts on Sep 24, more than three days before public disclosure. Some IOC are listed.

greynoise.io/blog/swarming-aga

#threatintel #citrix #netscaler #zeroday #CVE

##

thenextweb@flipboard.com at 2026-09-28T16:42:18.000Z ##

Hackers are exploiting two critical Citrix NetScaler zero-days
thenextweb.com/news/citrix-net

Posted into TNW - All Stories @tnw-all-stories-thenextweb

##

AAKL@infosec.exchange at 2026-09-28T16:45:24.000Z ##

Tenable, posted yesterday: Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities tenable.com/blog/frequently-as @tenablesecurity

GreyNoise: Swarming Against Citrix 0-Day Exploitation greynoise.io/blog/swarming-aga @greynoise

WatchTower: Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) labs.watchtowr.com/oh-look-the #vulnerability #Citrix #NetScaler

@ifin

##

youranonnewsirc@nerdculture.de at 2026-09-28T16:25:41.000Z ##

Here's a summary of the latest geopolitical, technology, and cybersecurity news:

Geopolitically, US-Iran tensions remain high after President Trump rejected a Strait of Hormuz proposal, with ongoing investigations into potential terror links to Iran after arrests near a U.S.-operated air base in the UK. Russia has intensified attacks on Kyiv, while Ukraine reportedly recaptured territory in Donetsk.

In technology, OpenAI halted AI model training due to "rogue agent" incidents and unexpected behavior on government websites. Nvidia launched an Open Agent Safety Platform to enhance AI security.

Cybersecurity saw critical Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) actively exploited globally, prompting CISA to add them to its KEV catalog. Ransomware activity reached a 2026 high in August, with industrial sectors being the most targeted. A new Carbonato botnet targets Docker hosts to deploy a Telegram-controlled AI agent. Kiteworks also advised customers to temporarily shut down their platform due to credible threat intelligence.

#AnonNews_irc #Cybersecurity #News

##

christopherkunz@chaos.social at 2026-09-28T13:13:55.000Z ##

@bsi labs.watchtowr.com/oh-look-the
Ab wann gilt der Betrieb dieser Geräte eigentlich als fahrlässig?

##

bsi@social.bund.de at 2026-09-28T13:04:09.000Z ##

⚠️ 📢 Sicherheitswarnung: Am 27. September 2026 veröffentlichte der Hersteller #Citrix ein Advisory [CIT26a] zu insgesamt acht Sicherheitslücken in seinen Produkten NetScaler ADC (ehemals Citrix ADC) und NetScaler Gateway (ehemals Citrix Gateway). Hierin enthalten sind auch zwei #ZeroDay-Schwachstellen (CVE-2026-88771 und CVE-2026-88772), zu denen sich im Laufe des vergangenen Wochenendes Berichte über eine aktive Ausnutzung verbreitet hatten.

Mehr dazu hier: bsi.bund.de/dok/1209522

##

ssvc@infosec.exchange at 2026-09-28T12:16:27.000Z ##

CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.

cisa.gov/news-events/alerts/20

#CISA #KEV #Citrix #zeroday #CVE

##

_r_netsec@infosec.exchange at 2026-09-28T11:13:05.000Z ##

Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs labs.watchtowr.com/oh-look-the

##

youranonnewsirc@nerdculture.de at 2026-09-28T10:26:19.000Z ##

Critical Citrix NetScaler RCE zero-days (CVE-2026-88771/88772) are under active exploitation; urgent fixes released. OpenAI halted AI model training after agents went rogue on government sites. Geopolitically, US-Iran tensions persist over the Strait of Hormuz, with reports of missile attacks.

#Cybersecurity #Geopolitics #AnonNews_irc

##

benzogaga33@mamot.fr at 2026-09-28T09:40:04.000Z ##

« Éteignez vos NetScaler » : Citrix confirme 2 failles zero-day critiques déjà exploitées it-connect.fr/citrix-netscaler #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

oversecurity@mastodon.social at 2026-09-28T09:20:31.000Z ##

Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack

Citrix has released fixes for two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771

🔗️ [Thecyberexpress] link.is.it/oXuQ75

##

cert_fr@social.numerique.gouv.fr at 2026-09-28T09:00:19.000Z ##

⚠️ Alerte CERT-FR ⚠️
Les vulnérabilités CVE-2026-88771 et CVE-2026-88772 sont activement exploitées et permettent une RCE pré-authentification sur Citrix NetScaler ADC et Gateway.

cert.ssi.gouv.fr/alerte/CERTFR

##

tugatech@masto.pt at 2026-09-28T08:41:25.000Z ##

Citrix corrige 2 vulnerabilidades críticas no NetScaler exploradas em ataques. A empresa já disponibilizou atualizações de segurança para corrigir as falhas zero-day identificadas como CVE-2026-88771 e CVE-2026-88772. 🛡️

🔗 tugatech.com.pt/t91845-citrix-

 

##

threatnoir@infosec.exchange at 2026-09-28T08:06:09.000Z ##

⚠️ CRITICAL: Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix NetScaler ADC and Gateway appliances are under active attack via two unpatched RCE zero-days (CVE-2026-88771 and CVE-2026-88772). Unauthenticated attackers can execute arbitrary commands or trigger denial-of-service on vulnerable instances. Any organization running these appliances without t…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-28T07:05:59.000Z ##

⚠️ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler to the Known Exploited Vulnerabilities catalog due to active exploitation in the wild. These are remote code execution vectors being actively weaponized. Federal agencies and any organization running exposed NetScaler instances…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

ssvc@infosec.exchange at 2026-09-28T01:16:48.000Z ##

CISA working on a Sunday: Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-887712 were added to the Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

cisa.gov/news-event/alerts/202

#KEV #Citrix #NetScaler #zeroday #CVE

##

cisakevtracker@mastodon.social at 2026-09-27T23:01:08.000Z ##

CVE ID: CVE-2026-88771
Vendor: Citrix
Product: NetScaler
Date Added: 2026-09-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-09-27T23:00:11.000Z ##

🚨 [CISA-2026:0927] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-88771 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: community.citrix.com/techzone- ; support.citrix.com/support-hom ; support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-88772 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: community.citrix.com/techzone- ; support.citrix.com/support-hom ; support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260927 #cisa20260927 #cve_2026_88771 #cve_2026_88772 #cve202688771 #cve202688772

##

youranonnewsirc@nerdculture.de at 2026-09-27T22:26:18.000Z ##

Latest News (Sept 26-27, 2026): Geopolitically, President Trump rejected Iran's Strait of Hormuz reopening proposal. In technology, OpenAI halted AI model training due to reports of "rogue" agents. Cybersecurity saw CISA add two critical, actively exploited Citrix NetScaler RCE zero-days to its KEV catalog (CVE-2026-88771, CVE-2026-88772), while ShinyHunters resumed Oracle PeopleSoft attacks, bypassing WAFs.

#Cybersecurity #TechNews #Geopolitics

##

zackwhittaker@mastodon.social at 2026-09-27T20:04:46.000Z ##

Citrix has a security post on its website that also confirms exploitation and has a bunch of remedation advice, which you might not know because the company set the page to "noindex," so it doesn't show up in search results. 🤦‍♂️

community.citrix.com/techzone-

##

zackwhittaker@mastodon.social at 2026-09-27T19:56:16.000Z ##

CISA has confirmed two bugs in Citrix NetScaler are under attack, CVE-2026-88771 and CVE-2026-88772, per its catalog of known exploited vulnerabiliites. cisa.gov/known-exploited-vulne

Citrix has a support base article, confirming exploitation. support.citrix.com/support-hom

##

security_crawler_carl@infosec.exchange at 2026-09-27T19:42:16.000Z ##

🏆 New Achievement! Welcome to the Mandatory Exploit Tutorial!

Ah, new player. Before you proceed, the game would like to walk you through two compulsory debuffs. CVE-2026-88771 — CVSS 9.5, unauthenticated remote code execution via improper input validation — is applied automatically. No extra features required. Think of it as the tutorial that runs whether you clicked "Skip" or not. CVE-2026-88772 also joins the party, also scoring 9.5, because the game respects symmetry. (1/3)

##

cyberworldops@infosec.exchange at 2026-09-27T18:30:00.000Z ##

Citrix patched NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 after confirmed exploitation of unmitigated systems. Edge appliances remain high-value targets, and the September 27 release also fixes six other flaws requiring immediate patching. #Citrix #NetScaler #ZeroDay #VulnerabilityManagement

cyberworldops.eu/en/citrix-pat

##

jela@social.tchncs.de at 2026-09-27T17:31:47.000Z ##

Zusätzlich sehr nützliche Betriebs- und Incident-Response-Hinweise gibt es hier: cyberkendra.com/2026/09/cve-20

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

pedro@infosec.exchange at 2026-09-27T16:22:43.000Z ##

@watchTowr Thanks for being on top of it 💪
community.citrix.com/techzone-

##

DailyCyberSecurity@infosec.exchange at 2026-09-27T16:18:08.000Z ##

Two Citrix NetScaler zero-day RCE flaws are under active exploitation. Citrix confirmed CVE-2026-88771 and CVE-2026-88772 and shipped patches. Update now.

#Citrix #NetScaler #ZeroDay #RCE #CyberSecurity #VPN #watchTowr #PatchNow

securityonline.info/citrix-net

##

ssvc@infosec.exchange at 2026-09-27T15:56:01.000Z ##

Citrix NetScaler zero-days

Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.

This is a Monday problem for me, but you're better off knowing what to expect when coming into work tomorrow. h/t @mttaggart

support.citrix.com/support-hom

#citrix #netscaler #zeroday #cve

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

GossiTheDog@cyberplace.social at 2026-09-27T15:33:35.000Z ##

Netscaler CVEs are out:

support.citrix.com/support-hom

Patch isn’t yet through QA at Citrix still, been a week :02angery:

The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained.

It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.

Probably nation state aligned as well resourced, espionage rather than teens.

##

CVE-2026-101090
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T13:17:21.117000

2 posts

Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to b

offseq@infosec.exchange at 2026-09-28T01:30:23.000Z ##

Nezha 2.2.3 (CVE-2026-101090): CRITICAL open redirect via Host header injection in OAuth2 flow. Account takeover possible if dashboard_host is unset. Set to trusted value; no patch yet. radar.offseq.com/threat/cve-20 #OffSeq #OAuth2 #Vulnerability #InfoSec

##

thehackerwire@mastodon.social at 2026-09-28T00:01:10.000Z ##

🔴 CVE-2026-101090 - Critical (9.8)

Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101064
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-28T13:17:19.927000

1 posts

Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error messages to disclose sensitive credentials.

thehackerwire@mastodon.social at 2026-09-28T00:16:20.000Z ##

🟠 CVE-2026-101064 - High (7.6)

Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101039
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T12:31:13

2 posts

A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element of the component devdiscover Service. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

offseq at 2026-09-28T13:30:28.289Z ##

CRITICAL: FAST FAC1900R 20190827_2.0.2 vulnerable to stack-based buffer overflow (CVE-2026-101039, CVSS 10). RCE possible via public exploit. No patch released; block access to devdiscover Service. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-28T13:30:28.000Z ##

CRITICAL: FAST FAC1900R 20190827_2.0.2 vulnerable to stack-based buffer overflow (CVE-2026-101039, CVSS 10). RCE possible via public exploit. No patch released; block access to devdiscover Service. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoT #Infosec

##

CVE-2026-81867(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-28T12:31:13

2 posts

A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerability was patched on 28 June 2026, and no customer

offseq at 2026-09-28T12:00:26.043Z ##

Critical: Google Cloud Application Integration is affected by CVE-2026-81867 (CVSS 9.4) — deserialization of untrusted data lets authenticated users run code on shared servers. Patched 2026-06-28. Confirm your environment is current. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-28T12:00:26.000Z ##

Critical: Google Cloud Application Integration is affected by CVE-2026-81867 (CVSS 9.4) — deserialization of untrusted data lets authenticated users run code on shared servers. Patched 2026-06-28. Confirm your environment is current. Details: radar.offseq.com/threat/cve-20 #OffSeq #CloudSecurity #CVE202681867

##

CVE-2026-88772
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-28T12:26:47.670000

29 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

5 repos

https://github.com/murrez/CVE-2026-88772

https://github.com/securekomodo/citrixInspector

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/FollowerSeize/CVE-2026-88772-POC

https://github.com/technion/netscaler_scanner

cyberveille@mastobot.ping.moi at 2026-09-28T20:30:05.000Z ##

📢 Deux zero-days critiques NetScaler (CVE-2026-88771 et CVE-2026-88772) exploités activement

🔍 Vulnérabilités identifiées Citrix a publié le bulletin de sécurité CTX697096 confirmant deux failles critiques : CVE-2026-88771 (score CVSS 9.5) : Exécution de code à distance via une validation d'entrée incorrecte, exploitable sans authentification, affectant…

📖 cyberveille : cyberveille.ch/posts/2026-09-2
🌐 source : bleepingcomputer.com/news/secu
🟡 vérification factuelle moyenne
#NetScaler #ZeroDay #Cyberveille

##

thecybermind at 2026-09-28T19:48:29.423Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-88772 – Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

A high-severity memory buffer vulnerability in Citrix NetScaler is under active exploitation. Review CISA telemetry and deployment hardening protocols....

thecybermind.co/41l1

##

sayzard@mastodon.sayzard.org at 2026-09-28T18:45:11.000Z ##

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix는 인터넷 경계에 배치되는 NetScaler ADC·Gateway의 치명적 RCE 제로데이 CVE-2026-88771 및 CVE-2026-88772가 실제 공격에 악용되고 있음을 확인하고 패치를 배포했습니다. 두 취약점 모두 CVSS 9.5이며, 전자는 인증 없이 임의 명령 실행이 가능한 입력 검증 취약점이고, 후자는 DTLS 활성화 환경(기본 VPN 가상 서버 포함)에서 RCE 또는 DoS를 유발할 수 있는 메모리 오버플로입니다. 영향을 받...

bleepingcomputer.com/news/secu

##

youranonnewsirc@nerdculture.de at 2026-09-28T16:25:41.000Z ##

Here's a summary of the latest geopolitical, technology, and cybersecurity news:

Geopolitically, US-Iran tensions remain high after President Trump rejected a Strait of Hormuz proposal, with ongoing investigations into potential terror links to Iran after arrests near a U.S.-operated air base in the UK. Russia has intensified attacks on Kyiv, while Ukraine reportedly recaptured territory in Donetsk.

In technology, OpenAI halted AI model training due to "rogue agent" incidents and unexpected behavior on government websites. Nvidia launched an Open Agent Safety Platform to enhance AI security.

Cybersecurity saw critical Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) actively exploited globally, prompting CISA to add them to its KEV catalog. Ransomware activity reached a 2026 high in August, with industrial sectors being the most targeted. A new Carbonato botnet targets Docker hosts to deploy a Telegram-controlled AI agent. Kiteworks also advised customers to temporarily shut down their platform due to credible threat intelligence.

#AnonNews_irc #Cybersecurity #News

##

GossiTheDog@cyberplace.social at 2026-09-28T15:13:43.000Z ##

There's various proof of concepts doing the rounds on Github for the new Citrix vulns. All the ones I've seen so far are fake AI slop.

E.g. this one is AI generated, it's not a PoC, it doesn't exploit, the fingerprint method it uses doesn't exist and as a checker it doesn't actually work either.

github.com/murrez/CVE-2026-887

##

bsi@social.bund.de at 2026-09-28T13:04:09.000Z ##

⚠️ 📢 Sicherheitswarnung: Am 27. September 2026 veröffentlichte der Hersteller #Citrix ein Advisory [CIT26a] zu insgesamt acht Sicherheitslücken in seinen Produkten NetScaler ADC (ehemals Citrix ADC) und NetScaler Gateway (ehemals Citrix Gateway). Hierin enthalten sind auch zwei #ZeroDay-Schwachstellen (CVE-2026-88771 und CVE-2026-88772), zu denen sich im Laufe des vergangenen Wochenendes Berichte über eine aktive Ausnutzung verbreitet hatten.

Mehr dazu hier: bsi.bund.de/dok/1209522

##

computersweden@friendica.helvetet.eu at 2026-09-28T11:03:35.000Z ## Sårbarheterna CVE-2026-88771 och CVE-2026-88772 utnyttjas nu aktivt.#Security
Hackare utnyttjar kritiska sårbarheter i Citrix Netscaler ##

ssvc at 2026-09-28T12:16:27.850Z ##

CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.

cisa.gov/news-events/alerts/20

##

thecybermind@infosec.exchange at 2026-09-28T19:48:29.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-88772 – Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

A high-severity memory buffer vulnerability in Citrix NetScaler is under active exploitation. Review CISA telemetry and deployment hardening protocols....

thecybermind.co/41l1

##

youranonnewsirc@nerdculture.de at 2026-09-28T16:25:41.000Z ##

Here's a summary of the latest geopolitical, technology, and cybersecurity news:

Geopolitically, US-Iran tensions remain high after President Trump rejected a Strait of Hormuz proposal, with ongoing investigations into potential terror links to Iran after arrests near a U.S.-operated air base in the UK. Russia has intensified attacks on Kyiv, while Ukraine reportedly recaptured territory in Donetsk.

In technology, OpenAI halted AI model training due to "rogue agent" incidents and unexpected behavior on government websites. Nvidia launched an Open Agent Safety Platform to enhance AI security.

Cybersecurity saw critical Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) actively exploited globally, prompting CISA to add them to its KEV catalog. Ransomware activity reached a 2026 high in August, with industrial sectors being the most targeted. A new Carbonato botnet targets Docker hosts to deploy a Telegram-controlled AI agent. Kiteworks also advised customers to temporarily shut down their platform due to credible threat intelligence.

#AnonNews_irc #Cybersecurity #News

##

GossiTheDog@cyberplace.social at 2026-09-28T15:13:43.000Z ##

There's various proof of concepts doing the rounds on Github for the new Citrix vulns. All the ones I've seen so far are fake AI slop.

E.g. this one is AI generated, it's not a PoC, it doesn't exploit, the fingerprint method it uses doesn't exist and as a checker it doesn't actually work either.

github.com/murrez/CVE-2026-887

##

bsi@social.bund.de at 2026-09-28T13:04:09.000Z ##

⚠️ 📢 Sicherheitswarnung: Am 27. September 2026 veröffentlichte der Hersteller #Citrix ein Advisory [CIT26a] zu insgesamt acht Sicherheitslücken in seinen Produkten NetScaler ADC (ehemals Citrix ADC) und NetScaler Gateway (ehemals Citrix Gateway). Hierin enthalten sind auch zwei #ZeroDay-Schwachstellen (CVE-2026-88771 und CVE-2026-88772), zu denen sich im Laufe des vergangenen Wochenendes Berichte über eine aktive Ausnutzung verbreitet hatten.

Mehr dazu hier: bsi.bund.de/dok/1209522

##

ssvc@infosec.exchange at 2026-09-28T12:16:27.000Z ##

CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.

cisa.gov/news-events/alerts/20

#CISA #KEV #Citrix #zeroday #CVE

##

benzogaga33@mamot.fr at 2026-09-28T09:40:04.000Z ##

« Éteignez vos NetScaler » : Citrix confirme 2 failles zero-day critiques déjà exploitées it-connect.fr/citrix-netscaler #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

cert_fr@social.numerique.gouv.fr at 2026-09-28T09:00:19.000Z ##

⚠️ Alerte CERT-FR ⚠️
Les vulnérabilités CVE-2026-88771 et CVE-2026-88772 sont activement exploitées et permettent une RCE pré-authentification sur Citrix NetScaler ADC et Gateway.

cert.ssi.gouv.fr/alerte/CERTFR

##

tugatech@masto.pt at 2026-09-28T08:41:25.000Z ##

Citrix corrige 2 vulnerabilidades críticas no NetScaler exploradas em ataques. A empresa já disponibilizou atualizações de segurança para corrigir as falhas zero-day identificadas como CVE-2026-88771 e CVE-2026-88772. 🛡️

🔗 tugatech.com.pt/t91845-citrix-

 

##

threatnoir@infosec.exchange at 2026-09-28T08:06:09.000Z ##

⚠️ CRITICAL: Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix NetScaler ADC and Gateway appliances are under active attack via two unpatched RCE zero-days (CVE-2026-88771 and CVE-2026-88772). Unauthenticated attackers can execute arbitrary commands or trigger denial-of-service on vulnerable instances. Any organization running these appliances without t…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-28T07:05:59.000Z ##

⚠️ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler to the Known Exploited Vulnerabilities catalog due to active exploitation in the wild. These are remote code execution vectors being actively weaponized. Federal agencies and any organization running exposed NetScaler instances…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

cisakevtracker@mastodon.social at 2026-09-27T23:00:52.000Z ##

CVE ID: CVE-2026-88772
Vendor: Citrix
Product: NetScaler
Date Added: 2026-09-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-09-27T23:00:11.000Z ##

🚨 [CISA-2026:0927] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-88771 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: community.citrix.com/techzone- ; support.citrix.com/support-hom ; support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-88772 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: community.citrix.com/techzone- ; support.citrix.com/support-hom ; support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260927 #cisa20260927 #cve_2026_88771 #cve_2026_88772 #cve202688771 #cve202688772

##

youranonnewsirc@nerdculture.de at 2026-09-27T22:26:18.000Z ##

Latest News (Sept 26-27, 2026): Geopolitically, President Trump rejected Iran's Strait of Hormuz reopening proposal. In technology, OpenAI halted AI model training due to reports of "rogue" agents. Cybersecurity saw CISA add two critical, actively exploited Citrix NetScaler RCE zero-days to its KEV catalog (CVE-2026-88771, CVE-2026-88772), while ShinyHunters resumed Oracle PeopleSoft attacks, bypassing WAFs.

#Cybersecurity #TechNews #Geopolitics

##

zackwhittaker@mastodon.social at 2026-09-27T19:56:16.000Z ##

CISA has confirmed two bugs in Citrix NetScaler are under attack, CVE-2026-88771 and CVE-2026-88772, per its catalog of known exploited vulnerabiliites. cisa.gov/known-exploited-vulne

Citrix has a support base article, confirming exploitation. support.citrix.com/support-hom

##

security_crawler_carl@infosec.exchange at 2026-09-27T19:42:16.000Z ##

🏆 New Achievement! Welcome to the Mandatory Exploit Tutorial!

Ah, new player. Before you proceed, the game would like to walk you through two compulsory debuffs. CVE-2026-88771 — CVSS 9.5, unauthenticated remote code execution via improper input validation — is applied automatically. No extra features required. Think of it as the tutorial that runs whether you clicked "Skip" or not. CVE-2026-88772 also joins the party, also scoring 9.5, because the game respects symmetry. (1/3)

##

cyberworldops@infosec.exchange at 2026-09-27T18:30:00.000Z ##

Citrix patched NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 after confirmed exploitation of unmitigated systems. Edge appliances remain high-value targets, and the September 27 release also fixes six other flaws requiring immediate patching. #Citrix #NetScaler #ZeroDay #VulnerabilityManagement

cyberworldops.eu/en/citrix-pat

##

DarkWebInformer@infosec.exchange at 2026-09-27T17:25:15.000Z ##

‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway.

More info: support.citrix.com/support-hom

CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

##

DailyCyberSecurity@infosec.exchange at 2026-09-27T16:18:08.000Z ##

Two Citrix NetScaler zero-day RCE flaws are under active exploitation. Citrix confirmed CVE-2026-88771 and CVE-2026-88772 and shipped patches. Update now.

#Citrix #NetScaler #ZeroDay #RCE #CyberSecurity #VPN #watchTowr #PatchNow

securityonline.info/citrix-net

##

ssvc@infosec.exchange at 2026-09-27T15:56:01.000Z ##

Citrix NetScaler zero-days

Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.

This is a Monday problem for me, but you're better off knowing what to expect when coming into work tomorrow. h/t @mttaggart

support.citrix.com/support-hom

#citrix #netscaler #zeroday #cve

##

AAKL@infosec.exchange at 2026-09-27T15:50:36.000Z ##

Citrix has finally spoken.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com/support-hom #infosec #Citrix #NetScaler #vulnerability

@mttaggart

##

GossiTheDog@cyberplace.social at 2026-09-27T15:33:35.000Z ##

Netscaler CVEs are out:

support.citrix.com/support-hom

Patch isn’t yet through QA at Citrix still, been a week :02angery:

The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained.

It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.

Probably nation state aligned as well resourced, espionage rather than teens.

##

CVE-2026-101009
(8.4 HIGH)

EPSS: 0.00%

updated 2026-09-28T09:30:34

1 posts

A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendo

offseq@infosec.exchange at 2026-09-28T07:30:26.000Z ##

OS command injection (CVE-2026-101009) in aaPanel BaoTa <=11.8.0: CRITICAL severity. Exploit public, vendor silent. Remote attackers can execute commands via panelTask.bt_task._unzip. Review and mitigate now. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026101009 #infosec

##

CVE-2026-101001
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T06:31:23

1 posts

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about thi

thehackerwire@mastodon.social at 2026-09-28T05:31:27.000Z ##

🔴 CVE-2026-101001 - Critical (10)

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101000
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T06:31:23

1 posts

A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted ear

thehackerwire@mastodon.social at 2026-09-28T05:31:19.000Z ##

🔴 CVE-2026-101000 - Critical (10)

A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100908
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T06:31:18

1 posts

A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Parser. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

thehackerwire@mastodon.social at 2026-09-28T05:31:37.000Z ##

🟠 CVE-2026-100908 - High (7.5)

A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Parser. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100896
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T03:30:34

2 posts

A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

offseq@infosec.exchange at 2026-09-28T03:00:26.000Z ##

TOTOLINK N150RT v3.4.0-B20201030 is vulnerable (CVE-2026-100896, CVSS 9.4): CRITICAL OS command injection in Web UI. Public exploit out, no patch yet. Restrict mgmt access & monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026100896 #infosec #router

##

thehackerwire@mastodon.social at 2026-09-28T02:30:35.000Z ##

🔴 CVE-2026-100896 - Critical (9.9)

A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96896
(7.2 HIGH)

EPSS: 0.00%

updated 2026-09-28T03:30:27

1 posts

The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.

offseq@infosec.exchange at 2026-09-27T07:30:23.000Z ##

CVE-2026-96896: Malcure Malware Shield <19.9.7 has a CRITICAL auth flaw. Subsite admins in WP multisite can write/delete arbitrary files, enabling RCE. Upgrade to 19.9.7+ now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #RCE

##

CVE-2026-81655
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-28T03:30:25

2 posts

The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.

thehackerwire@mastodon.social at 2026-09-28T02:31:25.000Z ##

🟠 CVE-2026-81655 - High (7.5)

The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-27T10:30:24.000Z ##

CVE-2026-81655: CRITICAL code injection in Ad Inserter WP plugin (2.8.12 – 2.8.18). Subscribers can execute PHP or unescaped content. Patch to 2.8.19+ ASAP. More: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #Vuln

##

CVE-2026-100886
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-28T00:30:36

2 posts

A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any wa

1 repos

https://github.com/heapframe/seetong-ts81xxd3x-rce

thehackerwire@mastodon.social at 2026-09-28T00:00:51.000Z ##

🔴 CVE-2026-100886 - Critical (10)

A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-28T00:00:36.000Z ##

Seetong T8108 series (v4.6.1.4-build202604241011) hit by CRITICAL CVE-2026-100886: improper authentication in Debug Service. Exploitable remotely — public exploit code available. No patch. Restrict network access ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026100886 #IoTSecurity #Vuln

##

CVE-2026-101062
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T21:31:10

1 posts

Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the authorization flow auto-completes for an already logged-in user with no consent screen, an attacker who registers a client pointing at their own dom

thehackerwire@mastodon.social at 2026-09-28T00:15:39.000Z ##

🟠 CVE-2026-101062 - High (8.8)

Obot before v0.23.0 (affected versions &lt;= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Beca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96280
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-27T21:17:04.200000

1 posts

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially ac

thehackerwire@mastodon.social at 2026-09-28T00:01:01.000Z ##

🟠 CVE-2026-96280 - High (7.5)

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101084
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-27T21:17:02.163000

2 posts

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.

offseq@infosec.exchange at 2026-09-28T04:30:25.000Z ##

obot-platform obot <0.21.1 suffers a CRITICAL auth bypass (CVE-2026-101084): authenticated users with server IDs can access restricted MCP servers via /mcp-connect. Patch to 0.21.1 now! radar.offseq.com/threat/cve-20 #OffSeq #CVE2026101084 #infosec #vuln

##

thehackerwire@mastodon.social at 2026-09-28T00:15:29.000Z ##

🔴 CVE-2026-101084 - Critical (9.6)

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101065
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-27T21:17:02.027000

1 posts

Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who ca

thehackerwire@mastodon.social at 2026-09-28T00:15:20.000Z ##

🔴 CVE-2026-101065 - Critical (9.8)

Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100865
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T18:31:24

1 posts

Heym before 0.0.53 contains multiple independent vulnerabilities. (1) The workflow condition evaluator uses Python eval() without an effective sandbox, allowing any user who can edit a workflow branch/condition node — or who can import a workflow template containing a malicious condition node — to execute arbitrary Python code as the backend process user when the workflow runs. (2) Slack webhook s

thehackerwire@mastodon.social at 2026-09-27T02:31:42.000Z ##

🟠 CVE-2026-100865 - High (8.8)

Heym before 0.0.53 contains multiple independent vulnerabilities. (1) The workflow condition evaluator uses Python eval() without an effective sandbox, allowing any user who can edit a workflow branch/condition node — or who can import a workflo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101060
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-27T18:30:35

1 posts

python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoint can return a 302 redirect to internal services, allowing the UTCP client to reach cloud metadata endpoints or internal HTTP services and ret

thehackerwire@mastodon.social at 2026-09-28T00:16:29.000Z ##

🟠 CVE-2026-101060 - High (8.2)

python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100871
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T15:31:14

1 posts

Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator's email address and obtain a token that the Admin API resolves to that administrator, granting full administrative access.

thehackerwire@mastodon.social at 2026-09-28T00:30:37.000Z ##

🟠 CVE-2026-100871 - High (8.8)

Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator's emai...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100870
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T13:16:38.240000

1 posts

Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over

thehackerwire@mastodon.social at 2026-09-28T00:30:28.000Z ##

🟠 CVE-2026-100870 - High (8.8)

Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domai...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100741
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-27T09:31:17

2 posts

Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with the privileges of the service account, via a password containing a backslash followed by an apostrophe, sent in any logon (SMTP AUTH, POP3, IMAP) that na

thehackerwire@mastodon.social at 2026-09-28T00:45:28.000Z ##

🔴 CVE-2026-100741 - Critical (9.8)

Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-27T09:00:26.000Z ##

CVE-2026-100741: CRITICAL eval injection in hMailServer (Windows, 6.0.0 – 6.3.3) enables remote code execution via JScript event scripting. Requires non-default config. Disable event scripting/JScript now. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #CyberSec #CVE #hMailServer

##

CVE-2026-85542
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T04:16:36.100000

1 posts

IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated privileges on the Central Manager.

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-100840
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:13

1 posts

MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malicious bundle with crafted configuration containing arbitrary code that executes when a victim loads the bundle using monai.bundle.load() or m

thehackerwire@mastodon.social at 2026-09-27T03:02:01.000Z ##

🟠 CVE-2026-100840 - High (7.8)

MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can pu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100847
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:13

1 posts

AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database information including user credentials and station settings.

thehackerwire@mastodon.social at 2026-09-27T02:47:10.000Z ##

🟠 CVE-2026-100847 - High (7.5)

AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database informa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100851
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:13

1 posts

AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin passwor

thehackerwire@mastodon.social at 2026-09-27T02:32:51.000Z ##

🟠 CVE-2026-100851 - High (7.6)

AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay pass...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100850
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:13

1 posts

AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the station Media permission can create or update a playlist with source=remote_url and remote_type=playlist whose remote_url points at a file:// path or an internal/loopback/link-local

thehackerwire@mastodon.social at 2026-09-27T02:32:42.000Z ##

🟠 CVE-2026-100850 - High (7.7)

AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the station Media permission can...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100856
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:13

1 posts

AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can inject nested Liquidsoap interpolation syntax to execute arbitrary code in the Liquidsoap process, disclose internal API keys, or disrupt station operation.

thehackerwire@mastodon.social at 2026-09-27T02:31:50.000Z ##

🟠 CVE-2026-100856 - High (8.8)

AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can inject neste...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100721
(9.0 None)

EPSS: 0.00%

updated 2026-09-27T03:31:12

2 posts

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-str

1 repos

https://github.com/murrez/CVE-2026-100721

thehackerwire@mastodon.social at 2026-09-28T01:00:53.000Z ##

🔴 CVE-2026-100721 - Critical (9)

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js reco...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-27T06:00:23.000Z ##

CVE-2026-100721: CRITICAL auth bypass in vm2 <3.12.2's NodeVM external-module resolver. Sandbox escape & arbitrary code exec possible. Upgrade to 3.12.2+ ASAP. radar.offseq.com/threat/vm2-be #OffSeq #CVE2026100721 #vm2 #infosec

##

CVE-2026-100833
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:12

1 posts

Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver without verifying the image digest. An attacker with access to the Kata agent API — for example, a

thehackerwire@mastodon.social at 2026-09-28T01:00:36.000Z ##

🟠 CVE-2026-100833 - High (8.2)

Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accept...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100838
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:12

1 posts

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem. A malicious process on the untrusted host able to connect to the Kata agent VSOCK could issue a series of CopyFile requests to overwrite security-critic

thehackerwire@mastodon.social at 2026-09-27T02:47:19.000Z ##

🟠 CVE-2026-100838 - High (8.1)

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100845
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T03:31:05

1 posts

MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payloads that execute arbitrary code when loaded through MONAI's standard data pipeline.

thehackerwire@mastodon.social at 2026-09-27T02:46:24.000Z ##

🟠 CVE-2026-100845 - High (7.8)

MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payload...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100846
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-27T02:17:23.283000

1 posts

MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining __reduce__ is executed during deserializati

thehackerwire@mastodon.social at 2026-09-27T02:46:33.000Z ##

🟠 CVE-2026-100846 - High (7.6)

MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100843
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-27T02:17:22.853000

1 posts

MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrary system commands when deserialized by the vulnerable function.

thehackerwire@mastodon.social at 2026-09-28T00:45:36.000Z ##

🟠 CVE-2026-100843 - High (7.8)

MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100723
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-27T02:17:20.553000

1 posts

vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through NodeVM's builtin allowlist (require: { builtin: ['zlib'] }), zlib.deflateSync can return a Buffer backed by Node's shared small-buffer pool whose .buffer is

thehackerwire@mastodon.social at 2026-09-28T01:00:45.000Z ##

🟠 CVE-2026-100723 - High (7.5)

vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through Node...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96533
(5.8 MEDIUM)

EPSS: 0.00%

updated 2026-09-27T00:32:20

1 posts

The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.

offseq@infosec.exchange at 2026-09-26T12:00:25.000Z ##

CVE-2026-96533: HIGH severity SSRF in Testimonials Widget (<=4.0.4). Unauthenticated users can make the server fetch internal URLs, exposing responses 🛡️. Disable or restrict plugin until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #SSRF #Infosec

##

CVE-2026-84388
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-27T00:16:35.007000

2 posts

A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack

1 repos

https://github.com/ShadowForge-Cyber/CVE-2026-84388-POC

AAKL at 2026-09-28T16:53:55.757Z ##

Fortinet posted a critical vulnerability yesterday:

CVE-2026-84388 - Improper Restriction of Rendered UI Layers or Frames in FortiPAM Chrome Extension Enables Remote Information Disclosure app.opencve.io/cve/CVE-2026-84

##

AAKL@infosec.exchange at 2026-09-28T16:53:55.000Z ##

Fortinet posted a critical vulnerability yesterday:

CVE-2026-84388 - Improper Restriction of Rendered UI Layers or Frames in FortiPAM Chrome Extension Enables Remote Information Disclosure app.opencve.io/cve/CVE-2026-84 #infosec #Fortinet #Chrome #vulnerability

##

CVE-2026-100714
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-26T23:16:33.297000

1 posts

Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php and executed by the root cron via FileDir::safe_exec. Because safe_exec only bla

thehackerwire@mastodon.social at 2026-09-27T00:02:27.000Z ##

🔴 CVE-2026-100714 - Critical (9.1)

Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100709
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T23:16:32.930000

1 posts

Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type. Because customer and administrator IDs are allocated from separate namespaces, a remembered-2FA token legitimately issued to a customer with a given ID

thehackerwire@mastodon.social at 2026-09-27T00:16:17.000Z ##

🟠 CVE-2026-100709 - High (7.5)

Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85984
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-26T18:31:08

2 posts

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as suffici

1 repos

https://github.com/murrez/CVE-2026-85984

offseq@infosec.exchange at 2026-09-27T03:00:25.000Z ##

CVE-2026-85984: CRITICAL auth bypass in miniOrange OTP Login plugin ≤5.5.5. Attackers can log in as admin with just a username if certain options are enabled. Disable risky settings and check vendor guidance. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202685984

##

thehackerwire@mastodon.social at 2026-09-26T23:46:48.000Z ##

🔴 CVE-2026-85984 - Critical (9.8)

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent gua...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100715
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-26T15:31:32

1 posts

Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink component walk is skipped, and then executes 'rm -rf' as root on the resulting path with string-level guards only. Because mak

thehackerwire@mastodon.social at 2026-09-27T00:02:35.000Z ##

🔴 CVE-2026-100715 - Critical (9.6)

Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100720
(8.7 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:32

1 posts

Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store the issuer organization (issuer['O']) value verbatim without sanitization. Froxlor's table-listing renderer then emits s

thehackerwire@mastodon.social at 2026-09-27T00:01:38.000Z ##

🟠 CVE-2026-100720 - High (8.7)

Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100711
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:28

1 posts

froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.

thehackerwire@mastodon.social at 2026-09-27T00:16:25.000Z ##

🟠 CVE-2026-100711 - High (7.5)

froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100716
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-26T15:31:28

1 posts

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that skips the first segment below the customer home directory, and the guard in ExportCron.php checks only the final component

thehackerwire@mastodon.social at 2026-09-27T00:02:44.000Z ##

🔴 CVE-2026-100716 - Critical (9.9)

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100713
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:28

1 posts

Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::makeCorrectDir()/makeCorrectFile() is done only at check time; the live filesystem path is re-resolved as root at write time (file_put_contents with FILE_APP

thehackerwire@mastodon.social at 2026-09-27T00:01:47.000Z ##

🟠 CVE-2026-100713 - High (7.8)

Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::make...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100671
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission is rendered through a Twig sandbox that allowlists get_cookie(), which returns any cookie sent with the current request, including the visitor's session cookie. Because the read oc

thehackerwire@mastodon.social at 2026-09-27T02:16:42.000Z ##

🟠 CVE-2026-100671 - High (8)

Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission is rendered through a T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100676
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG <image href> values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who causes the service to proxy an attacker-hosted SVG (e.g. via the /proxy endpoint) can determine whether local files exist through observable r

thehackerwire@mastodon.social at 2026-09-27T01:46:42.000Z ##

🟠 CVE-2026-100676 - High (8.2)

January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100673
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor wh

thehackerwire@mastodon.social at 2026-09-27T01:46:33.000Z ##

🟠 CVE-2026-100673 - High (8.2)

The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100685
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to acces

thehackerwire@mastodon.social at 2026-09-27T01:46:25.000Z ##

🟠 CVE-2026-100685 - High (7.7)

Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100683
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename literal for MSSQL) without applying the project's quoteMySqlIdentifier / quoteSqlServerIdentifier helpers. An attacker with DDL rights on a connected MySQL/

thehackerwire@mastodon.social at 2026-09-27T01:32:50.000Z ##

🟠 CVE-2026-100683 - High (8)

Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename lit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100682
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary files as root, enabling remote code execution.

thehackerwire@mastodon.social at 2026-09-27T01:32:41.000Z ##

🟠 CVE-2026-100682 - High (8.8)

Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with lea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100690
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that point outside the allowed set, Hugo did not detect symlinks escaping the sandbox.

thehackerwire@mastodon.social at 2026-09-27T01:16:15.000Z ##

🟠 CVE-2026-100690 - High (7.5)

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100706
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyExc

thehackerwire@mastodon.social at 2026-09-27T00:46:38.000Z ##

🔴 CVE-2026-100706 - Critical (9.9)

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100704
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyverno.io/v1beta1) evaluator never reads the spec.images and spec.allowedValues fields of a PolicyException. Any PolicyException whose policyRefs and matchConditions match a resource causes image signature verification to be skipped for the entire resource rather than only for the lis

thehackerwire@mastodon.social at 2026-09-27T00:31:33.000Z ##

🟠 CVE-2026-100704 - High (7.7)

Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyverno.io/v1beta1) evaluator never reads the spec.images and spec.allowedValues fields of a PolicyException. Any PolicyException who...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100703
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:27

1 posts

Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy namespace. A tenant who can create a namespaced policy (e.g. NamespacedValidatingPolicy, and likewise the namespaced mutating, deleting, generating, and

thehackerwire@mastodon.social at 2026-09-27T00:31:25.000Z ##

🟠 CVE-2026-100703 - High (7.7)

Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100664
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:26

1 posts

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1 request-target. In HttpConversionUtil.toHttp3Headers(HttpMessage, boolean) — reached via Http3FrameToHttpObjectCodec(false) — a non-empty Host header takes precedence over the r

thehackerwire@mastodon.social at 2026-09-28T01:15:49.000Z ##

🟠 CVE-2026-100664 - High (7.5)

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1 request-target. In HttpC...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100669
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:26

1 posts

Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, user_pages, system, vendor, ignore_folders) sets ignoreCase="false" on its URL Rewrite <match> element, overriding the IIS default of ignoreCase="true";

thehackerwire@mastodon.social at 2026-09-27T02:01:42.000Z ##

🟠 CVE-2026-100669 - High (7.5)

Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100692
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:23

1 posts

Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a mount root (for example themes/mytheme/assets -> /some/dir/outside). Files behind such a symlink were readable during a site build through resources.Get, res

thehackerwire@mastodon.social at 2026-09-27T01:16:24.000Z ##

🟠 CVE-2026-100692 - High (7.5)

Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a moun...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100693
(8.4 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:23

1 posts

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost.

thehackerwire@mastodon.social at 2026-09-27T01:01:30.000Z ##

🟠 CVE-2026-100693 - High (8.4)

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100637
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing directory traversal sequences to overwrite arbitrary JSON files in pre-existing kernel-writable directories outside workspace boundaries.

thehackerwire@mastodon.social at 2026-09-28T02:31:34.000Z ##

🟠 CVE-2026-100637 - High (7.6)

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing directory t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100636
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authenticated administrators to write arbitrary HTML content to index.html outside the workspace directory. Attackers can supply a folder parameter with directory traversal sequences to escape the export directory and overwrite index.html in any pre-existing kernel-writable location,

thehackerwire@mastodon.social at 2026-09-28T02:15:52.000Z ##

🟠 CVE-2026-100636 - High (7.6)

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authenticated administrators to write arbitrary HTML content to index.html outside the workspace directory. Attackers can supply a f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100646
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in kernel/util/net.go) fail open when the HTTP Origin header is absent, on the incorrect assumption that any browser-initiated cross-site request carries an Origin. Because browsers omit Origin on cr

thehackerwire@mastodon.social at 2026-09-28T02:15:43.000Z ##

🟠 CVE-2026-100646 - High (8.1)

SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in kernel/util/net.go) fail open when the HTTP...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100644
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath parameter is concatenated into SQL without escaping. Unauthenticated attackers on published sites with auth disabled can inject SQL via UNION SELECT to extract arbitrary database rows from all notebooks.

thehackerwire@mastodon.social at 2026-09-28T02:01:12.000Z ##

🟠 CVE-2026-100644 - High (7.5)

SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath parameter is concatenated into SQL without escaping. Unauthenticated attackers on published sites with auth disabled can inject SQL...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100642
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can craft malicious web pages that force victims to terminate the kernel process, read workspace configuration and proxy settings, and trigger administrative a

thehackerwire@mastodon.social at 2026-09-28T02:00:51.000Z ##

🟠 CVE-2026-100642 - High (7.6)

SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100641
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts and assigned to listElement.innerHTML, so content such as <img src=invalid onerror=...> becomes an executable event-handler attribute. Because the SiYua

thehackerwire@mastodon.social at 2026-09-28T01:45:53.000Z ##

🟠 CVE-2026-100641 - High (8)

SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100655
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final accept an unlimited number of concurrent remote-initiated SPDY streams: SpdySessionHandler defaults localConcurrentStreams to Integer.MAX_VALUE and exposes no API to change it. A remote peer that opens a SPDY connection and sends millions of SYN_STREAM frames with FLAG_FIN=0 cause

thehackerwire@mastodon.social at 2026-09-28T01:30:44.000Z ##

🟠 CVE-2026-100655 - High (7.5)

Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final accept an unlimited number of concurrent remote-initiated SPDY streams: SpdySessionHandler defaults localConcurrentStreams to In...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100663
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:22

1 posts

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3 in HttpConversionUtil.toHttp3Headers. The authority-form target (e.g., "CONNECT trusted.example:443") is parsed as a URI, so its host is emitted as :scheme, :path is set to "/", and the HTTP/1 Host head

thehackerwire@mastodon.social at 2026-09-28T01:15:40.000Z ##

🟠 CVE-2026-100663 - High (7.5)

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3 in HttpConversionUtil.toHttp3Headers. The authori...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100627
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:21

1 posts

Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle promotion path. The PUT /bundle endpoint, available to "all" and "write" API keys, dispatches to setChannel, which authorizes with checkPermission(c, 'channel.promote_bundle', { appId: body.app_id }) and omits the request's channel_id. Because the omitted scope field is passed t

thehackerwire@mastodon.social at 2026-09-28T07:17:12.000Z ##

🟠 CVE-2026-100627 - High (8.1)

Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle promotion path. The PUT /bundle endpoint, available to "all" and "write" API keys, dispatches to setChannel, which authorizes ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100631
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:21

1 posts

Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to build database queries. An unauthenticated remote attacker who knows only the public application ID can submit non-string va

thehackerwire@mastodon.social at 2026-09-28T02:46:03.000Z ##

🟠 CVE-2026-100631 - High (7.5)

Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100665
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:19

1 posts

Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can presen

thehackerwire@mastodon.social at 2026-09-28T01:30:35.000Z ##

🟠 CVE-2026-100665 - High (7.5)

Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100623
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-26T15:31:16

1 posts

Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to update" only verify that the caller has admin rights in the target organization (public.check_min_rights('admin', ...)); they do not require a pending invitation in tmp_users, acceptance of an invite

thehackerwire@mastodon.social at 2026-09-28T07:17:03.000Z ##

🟠 CVE-2026-100623 - High (8.8)

Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to update" only verify that the caller has admin r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100717
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-26T14:16:57.867000

1 posts

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or chan

thehackerwire@mastodon.social at 2026-09-27T00:16:08.000Z ##

🔴 CVE-2026-100717 - Critical (9.9)

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100670
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-26T14:16:50.697000

1 posts

Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation key such as `access.admin.super` (instead of the nested `access[admin][super]`) matches no blueprint rule, survives BlueprintSchema::filterArray() an

thehackerwire@mastodon.social at 2026-09-27T02:01:51.000Z ##

🟠 CVE-2026-100670 - High (8.8)

Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100645
(8.0 HIGH)

EPSS: 0.00%

updated 2026-09-26T14:16:46.857000

1 posts

SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration enabled, attackers can inject JavaScript that calls Node.js child_process APIs to execute arbitrary commands with user privileges.

thehackerwire@mastodon.social at 2026-09-28T02:15:34.000Z ##

🟠 CVE-2026-100645 - High (8)

SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration ena...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100638
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-26T14:16:45.590000

1 posts

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can supply directory traversal sequences in the notebook parameter to escape the workspace data directory and write conf.json files to arbitrary locations accessibl

thehackerwire@mastodon.social at 2026-09-28T02:45:44.000Z ##

🟠 CVE-2026-100638 - High (7.6)

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can supply ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18143
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-26T09:30:26

2 posts

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied filename directly as the destination for `move_uploaded_file()`. This makes it p

1 repos

https://github.com/murrez/CVE-2026-18143

thehackerwire@mastodon.social at 2026-09-26T07:30:13.000Z ##

🔴 CVE-2026-18143 - Critical (9.8)

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type vali...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-26T07:30:22.000Z ##

CVE-2026-18143 | CRITICAL unrestricted file upload in Addify Request a Quote for WooCommerce (<=2.9.2). Unauth attackers can achieve RCE. Disable public quote rule/multi-page popup or restrict uploads. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #RCE

##

CVE-2026-65660
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-26T04:17:45.630000

2 posts

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

2 repos

https://github.com/HORKimhab/CVE-2026-65660

https://github.com/ShadowForge-Cyber/CVE-2026-65660-Poc

undercodenews@mastodon.social at 2026-09-28T17:46:14.000Z ##

Microsoft SharePoint CVE-2026-65660 Is Now Under Active Attack After Technical Details Go Public + Video

A Six-Week-Old Vulnerability Suddenly Becomes a Live Threat A Microsoft SharePoint security vulnerability tracked as CVE-2026-65660 has moved from a patched software flaw to an actively exploited threat, raising concerns for organizations that have not yet applied Microsoft’s August 2026 security updates. The vulnerability was patched roughly six weeks ago, but…

undercodenews.com/microsoft-sh

##

patrickcmiller@infosec.exchange at 2026-09-27T18:42:01.000Z ##

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks securityweek.com/microsoft-sha

##

CVE-2026-100208
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T04:17:33.933000

1 posts

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-09-26T07:45:22.000Z ##

🟠 CVE-2026-100208 - High (7.5)

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100560
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T03:30:35

1 posts

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without triggering new approval prompts, potentially accessing files or internal services.

thehackerwire@mastodon.social at 2026-09-26T07:00:56.000Z ##

🟠 CVE-2026-100560 - High (7.5)

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to exe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100568
(8.3 HIGH)

EPSS: 0.00%

updated 2026-09-26T03:30:35

1 posts

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabled or unscheduled command jobs to access secrets and execute operator-authored commands.

thehackerwire@mastodon.social at 2026-09-26T06:32:55.000Z ##

🟠 CVE-2026-100568 - High (8.3)

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run dis...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100558
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T03:30:34

1 posts

OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attackers can repeatedly send malformed upgrade requests to exhaust listener resources and cause denial of service without consuming the WebSocket pre-auth co

thehackerwire@mastodon.social at 2026-09-26T06:45:27.000Z ##

🟠 CVE-2026-100558 - High (7.5)

OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100557
(8.3 HIGH)

EPSS: 0.00%

updated 2026-09-26T03:30:34

1 posts

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server credentials reserved for owners.

thehackerwire@mastodon.social at 2026-09-26T06:45:18.000Z ##

🟠 CVE-2026-100557 - High (8.3)

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server cred...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100532
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-26T03:30:28

1 posts

@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender able to steer the tool can request a forced login and receive a new QR code for a configured account, disconnecting the Gateway's WhatsApp account and ca

thehackerwire@mastodon.social at 2026-09-26T07:30:57.000Z ##

🟠 CVE-2026-100532 - High (8.1)

@OpenClaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100535
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-26T03:30:28

1 posts

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and dreaming are enabled, a restricted external sender whose messages are admitted with limited tools can persist instructions that are later supplied to

thehackerwire@mastodon.social at 2026-09-26T07:30:39.000Z ##

🟠 CVE-2026-100535 - High (7.5)

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and &lt; 2026.8.1 can lose the originating requester&#039;s restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100551
(8.3 HIGH)

EPSS: 0.00%

updated 2026-09-26T03:30:25

2 posts

OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by

thehackerwire@mastodon.social at 2026-09-26T07:01:14.000Z ##

🟠 CVE-2026-100551 - High (8.3)

OpenClaw for iOS versions >= 2026.7.1 and &lt; 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-26T06:00:25.000Z ##

CVE-2026-100551: OpenClaw for iOS (>=2026.7.1, <2026.8.11) has a CRITICAL vuln in Control UI WebViews — TLS pins not enforced. Attackers can steal Gateway creds if they can redirect traffic. Patch to 2026.8.11 ASAP! radar.offseq.com/threat/opencl #OffSeq #Vulnerability #iOS #AppSec

##

CVE-2026-100382(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-26T00:32:22

1 posts

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7.

1 repos

https://github.com/nth347/mediawiki-CVE-2026-100382

offseq@infosec.exchange at 2026-09-26T09:00:23.000Z ##

Mediawiki ExternalData Extension <3.7 has a CRITICAL OS Command Injection vuln (CVE-2026-100382). Unauthenticated attackers could run arbitrary OS commands. No exploits yet. Restrict access, monitor activity. radar.offseq.com/threat/improp #OffSeq #CVE2026100382 #Mediawiki #Security

##

CVE-2026-97063
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-25T21:33:06

1 posts

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as victims via POST /sys/emailOrMobileLogin/login to hijack accounts.

thehackerwire@mastodon.social at 2026-09-26T07:45:31.000Z ##

🔴 CVE-2026-97063 - Critical (9.1)

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97064
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-25T21:33:03

1 posts

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileLogin endpoint with a known email or mobile number.

thehackerwire@mastodon.social at 2026-09-26T07:45:39.000Z ##

🔴 CVE-2026-97064 - Critical (9.1)

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileL...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100389
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-25T21:17:22.483000

1 posts

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.

offseq@infosec.exchange at 2026-09-26T10:30:24.000Z ##

GestSup <3.2.61 is vulnerable to CRITICAL RCE (CVE-2026-100389) via IMAP connector. Attackers can send PHP attachments to monitored mailboxes, leading to system compromise. Upgrade to 3.2.61+ ASAP. radar.offseq.com/threat/gestsu #OffSeq #Infosec #RCE #GestSup

##

CVE-2026-92161
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-25T20:31:30

1 posts

### Impact An unauthenticated account takeover vulnerability exists in `fof/oauth` when the Discord OAuth provider is enabled. Discord allows an account to use an unverified email address when its phone number has been verified. During OAuth authentication, Discord may return that email address with `"verified": false`. Affected versions of `fof/oauth` did not validate this flag and passed the

thehackerwire@mastodon.social at 2026-09-26T08:30:36.000Z ##

🔴 CVE-2026-92161 - Critical (9.8)

FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before passing th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91841
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-25T18:31:36

1 posts

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary commands as the root user, leading to local privilege escalation.

thehackerwire@mastodon.social at 2026-09-26T08:15:22.000Z ##

🟠 CVE-2026-91841 - High (7.8)

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91839
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-25T18:31:36

1 posts

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject additional configuration directives. This can lead to arbitrary code execution with root p

thehackerwire@mastodon.social at 2026-09-26T08:00:36.000Z ##

🟠 CVE-2026-91839 - High (7.8)

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91838
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-25T18:31:36

1 posts

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the `pppd` daemon, which runs with root privileges, allowing the attacke

thehackerwire@mastodon.social at 2026-09-26T08:00:27.000Z ##

🟠 CVE-2026-91838 - High (7.8)

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94445
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-25T18:31:35

1 posts

A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for an environment configuration file rooted in the playground host's $HOME. To

thehackerwire@mastodon.social at 2026-09-26T08:15:30.000Z ##

🟠 CVE-2026-94445 - High (8.8)

A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem.

Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91837
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-25T17:17:18.983000

1 posts

A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedding shell metacharacters (special characters that can execute commands) in the 'nameserver' value, an attacker can inject and execute arbitrary commands. These com

thehackerwire@mastodon.social at 2026-09-26T08:30:27.000Z ##

🟠 CVE-2026-91837 - High (7.8)

A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedding shell ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89032
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-25T17:17:18.793000

1 posts

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_cache_tenant_scope() and _get_metadata_variable_name(). Attackers holding a valid virtual key can submit semantically similar prompts on affected routes su

thehackerwire@mastodon.social at 2026-09-26T08:15:39.000Z ##

🟠 CVE-2026-89032 - High (7.7)

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62062
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-25T14:17:18.807000

4 posts

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.

1 repos

https://github.com/abraxas/CVE-2026-62062

DailyCyberSecurity at 2026-09-28T13:21:48.987Z ##

Discover the critical CVE-2026-62062 Elementor CSRF vulnerability. Learn how this REST API bypass threatens millions of WordPress sites and how to patch it.

meterpreter.org/elementor-csrf

##

DailyCyberSecurity@infosec.exchange at 2026-09-28T13:21:48.000Z ##

Discover the critical CVE-2026-62062 Elementor CSRF vulnerability. Learn how this REST API bypass threatens millions of WordPress sites and how to patch it.

#Elementor #WordPress #CSRF #CyberSecurity #WebSecurity

meterpreter.org/elementor-csrf

##

wpguyuk@infosec.exchange at 2026-09-28T07:04:35.000Z ##

If your site runs Elementor 4.3.0 or 4.3.1, I would update immediately. CVE-2026-62062 allows any authenticated user — a subscriber or WooCommerce customer — to escalate their privileges to admin level. Open registration or a membership area makes this a concrete, present risk rather than a theoretical one.

#WordPress #Elementor #SecurityHardening #CVE #WordPressSecurity

wpguy.uk/blog/elementor-privil

##

guru@thecybersecguru.com at 2026-09-26T17:58:21.000Z ##

Critical Elementor CSRF Flaw Exposes 2 Million WordPress Sites to Full Takeover

Elementor CVE-2026-62062 is a CVSS 8.8 CSRF flaw affecting versions 4.3.0 and 4.3.1. Update to 4.3.2 to block the attack

thecybersecguru.com/news/eleme

##

CVE-2026-14281
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-25T09:31:05

1 posts

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and the absence of a key allowlist in the `finish_registration_logic` function, which

3 repos

https://github.com/langz337/CVE-2026-14281

https://github.com/murrez/CVE-2026-14281

https://github.com/abatsakidis/CVE-2026-14281-check

DarkWebInformer@infosec.exchange at 2026-09-27T19:32:22.000Z ##

‼️ CVE-2026-14281: Unauthenticated Privilege Escalation Vulnerability in the WAWP WordPress Plugin

CVE Published: September 24, 2026
PoC Published: September 25, 2026

GitHub PoC: github.com/murrez/CVE-2026-142

##

CVE-2026-15027
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T14:45:22.827000

1 posts

CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer.

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-94097
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T13:17:17.460000

1 posts

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about t

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19599
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T04:17:48.027000

1 posts

ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-93577
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T00:30:34

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.

beyondmachines1@infosec.exchange at 2026-09-26T10:01:12.000Z ##

GitLab Patches Critical Regex Flaws Allowing Remote Code Execution

GitLab released emergency patches for 11 vulnerabilities, including two critical regex-related flaws (CVE-2026-89078 and CVE-2026-93577) that allow authenticated attackers to execute arbitrary code on self-managed servers.

**If you run your own GitLab server, update it to version 19.4.1, 19.3.3, or 19.2.7. Two critical flaws allow any logged-in user take over the whole server. After updating, check your .gitlab-ci.yml files for new or strange-looking regular expressions, and review who has access to your projects in case someone already tried to exploit this. GitLab.com and GitLab Dedicated users don't need to do anything.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-76978
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-23T15:30:52

1 posts

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-93616
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-22T21:31:15

2 posts

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

1 repos

https://github.com/WadesWeaponShed/CVE-2026-93616_Checks

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

thecybermind@infosec.exchange at 2026-09-26T12:27:03.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-93616 – Check Point Multiple Products Path Traversal Vulnerability

Analyze the technical mechanics of CVE-2026-93616 with our Check Point TSUITE brief, covering management server path traversal, remote code execution, and endpoint hardening....

thecybermind.co/1yot

##

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-22T21:30:40

1 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

thecybermind@infosec.exchange at 2026-09-26T10:59:17.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-85102 – Check Point Multiple Products Improper Certificate Validation Vulnerability

Analyze the technical mechanics of CVE-2026-85102 with our Check Point TSUITE brief, covering VPN certificate trust validation bypass, multi-platform SIEM queries, and gateway hardening....

thecybermind.co/x9a1

##

CVE-2026-94533
(6.5 MEDIUM)

EPSS: 0.00%

updated 2026-09-22T20:53:07.383000

1 posts

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can retrieve other users' stored files by supplying valid attachment identifiers to the /anyone/file/down and /anyone/file/download endpoints, as the application never validates file ownership against the created_by column.

hugovalters@mastodon.social at 2026-09-28T18:10:02.000Z ##

CVE-2026-94533: authorization bypass in Fileanyonecontroller (lamp-cloud up to 5.10.0) lets any authenticated user download other users' files via the /anyone/file/down endpoint. CVSS 6.5, no patch yet. Audit access and valtersit.com/cve/CVE-2026-945 #CVE #infosec #cybersecurity

##

CVE-2026-82890
(5.9 MEDIUM)

EPSS: 0.00%

updated 2026-09-22T19:32:25.730000

1 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation.

hugovalters@mastodon.social at 2026-09-27T14:00:25.000Z ##

CVE-2026-82890 IBM Guardium Data Protection 12.2 allows remote authenticated attackers to execute arbitrary JavaScript via improper input neutralization. CVSS 5.9, patch status unknown. Review and update immediately. valtersit.com/cve/CVE-2026-828 #CVE #infosec #IBM

##

CVE-2026-92235
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-22T19:04:55.677000

1 posts

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.

hugovalters@mastodon.social at 2026-09-28T19:40:07.000Z ##

CVE-2026-92235: WP Ultimate Review plugin unpatched, CVSS 8.1. Subscriber-level users can run arbitrary shortcodes. No fix available - disable the plugin now. valtersit.com/cve/CVE-2026-922 #CVE #WordPress #infosec

##

CVE-2026-94492
(6.3 MEDIUM)

EPSS: 0.00%

updated 2026-09-22T19:04:55.677000

1 posts

A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8cloud/openapi/so.saleorder.sendaudit of the component OpenAPI. The manipulation of the argument operator leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure bu

hugovalters@mastodon.social at 2026-09-28T16:40:02.000Z ##

CVE-2026-94492: SQLi in Yonyou U8cloud 5.x OpenAPI (so.saleorder.sendaudit), CVSS 6.3. Remote, public exploit, no vendor response, no patch. Restrict OpenAPI exposure now. valtersit.com/cve/CVE-2026-944 #CVE #infosec #cybersecurity

##

CVE-2026-93836
(7.2 HIGH)

EPSS: 0.00%

updated 2026-09-22T19:04:55.677000

1 posts

The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and including, 8.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The float c

hugovalters@mastodon.social at 2026-09-28T11:50:01.000Z ##

CVE-2026-93836 WooCommerce WPC Product Bundles stored XSS via qty param, CVSS 7.2, unauthenticated, no patch yet. Update now: valtersit.com/cve/CVE-2026-938 #CVE #infosec #WordPress

##

CVE-2026-43641
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-22T18:33:42

1 posts

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and inject shell payloads through the uid field, which

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-74849
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-22T12:30:32

1 posts

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-7273
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-22T12:10:51.067000

1 posts

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

cyberveille@mastobot.ping.moi at 2026-09-28T20:00:08.000Z ##

📢 Exploitation active de CVE-2026-7273 sur switches Zyxel GS1900 par un acteur sinophone

Help Net Security, publié le 22 septembre 2026. L'article rapporte les conclusions de GreyNoise concernant l'exploitation active d'une vulnérabilité affectant les switches Zyxel GS1900 Smart Managed Switches, ciblant des environnements PME, écoles, hôtels et…

📖 cyberveille : cyberveille.ch/posts/2026-09-2
🌐 source : helpnetsecurity.com/2026/09/22
🟢 vérification factuelle haute
#Zyxel #ActeurSinophone #Cyberveille

##

CVE-2026-93778
(7.2 HIGH)

EPSS: 0.00%

updated 2026-09-22T09:31:18

1 posts

The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up to, and including, 9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injecte

hugovalters@mastodon.social at 2026-09-28T13:30:02.000Z ##

CVE-2026-93778: Stored XSS in WP Yelp Review Slider, all versions up to 9.2, CVSS 7.2. Unpatched. Unauthenticated attackers inject scripts via imported Yelp review text. Disable the plugin until a fix lands. valtersit.com/cve/CVE-2026-937 #CVE #WordPress #infosec

##

CVE-2026-94504
(7.2 HIGH)

EPSS: 0.00%

updated 2026-09-22T09:31:17

1 posts

Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.

1 repos

https://github.com/cflowsec/cve-2026-94504

hugovalters@mastodon.social at 2026-09-28T15:10:06.000Z ##

CVE-2026-94504: Ninja Forms 3.15.3 stored XSS, CVSS 7.2. Attacker script runs in WordPress admin origin. No patch yet - restrict submission access and watch vendor advisories. valtersit.com/cve/CVE-2026-945 #CVE #infosec #WordPress

##

CVE-2026-80521
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-21T15:32:39

2 posts

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: X -. A <-> B ^--' 2) Run the following concurrently: 2-1) send() sk-B to sk-B from sk-X 2-2) close() both A and B At 2-1), there is a sm

1 repos

https://github.com/Markakd/Container_escape

CVE-2026-94098
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-21T03:30:22

1 posts

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this di

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2025-39964
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-19T04:17:48.307000

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates

2 repos

https://github.com/suominen/CVE-2025-39964

https://github.com/n1k0oowang/CVE-2025-39964_EXP

ibu_ipop@burnout.cafe at 2026-09-26T07:52:12.000Z ##

Linux kernel flaw enables root and container escape A 14-year-old bug in the AF_ALG cryptographic socket interface, tracked as CVE-2025-39964, allows unprivileged local users to gain root and escape Docker containers. The issue is a race condition in concurrent sendmsg() operations that can be turned into out-of-bounds memory access and an arbitrary kernel write. The vulnerable code dates to Linux 2.6.38

cyberpress.org/14-year-old-lin

##

CVE-2026-89775
(9.3 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T18:31:58

1 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached by the TLB. For S1 mappings such as VNCR, this is deducted from the combination of the base granule size and the mapping level. However, this implies that the S1 M

sekurakbot@mastodon.com.pl at 2026-09-28T00:06:00.000Z ##

Krytyczna luka w Linux KVM na ARM64. W określonych warunkach można przejąć kontrolę nad hostem [CVE-2026-89775]

Na portalu openwall.com badacz bezpieczeństwa Hyunwoo Kim opublikował wpis zawierający szczegóły krytycznej podatności w podsystemie KVM (Kernel-based Virtual Machine) dla architektury ARM64 w jądrze Linuxa. Luka oznaczona identyfikatorem CVE-2026-89775 umożliwia ucieczkę z maszyny wirtualnej i uzyskanie dostępu do pamięci hosta. Może to prowadzić do przejęcia kontroli nad systemem (hypervisorem).  TLDR:...

#Aktualności #Cve #Kvm #Linux #Rce

sekurak.pl/krytyczna-luka-w-li

##

CVE-2026-43786
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-15T00:31:13

1 posts

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

2 repos

https://github.com/0xBlackash/CVE-2026-43786

https://github.com/Malwation/CVE-2026-43786

CVE-2026-0310
(0 None)

EPSS: 0.00%

updated 2026-09-11T04:17:13.060000

1 posts

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimiz

CVE-2026-75960
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-26T18:32:04

1 posts

Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.

sayzard@mastodon.sayzard.org at 2026-09-28T14:46:28.000Z ##

One resident login, an entire apartment complex: CVE-2026-75960

Rently Smart Home 20.1.0 이하에서 인증된 입주자 계정이 자신의 건물 API 응답을 통해 다른 코드와 관리용 마스터 PIN까지 평문으로 획득할 수 있었던 권한 검증 취약점(CVE-2026-75960)이 공개되었습니다. 모바일 앱은 입주자 본인의 코드만 표시했지만, 서버 API가 전체 코드 테이블을 반환해 UI 레벨 필터링이 실제 접근 제어가 될 수 없음을 보여줍니다. 공격자는 해당 PIN으로 건물의 물리적 출입을 할 수 있었으며, CISA는 CVSS 3.1 8.1 및 CVSS 4.0 8.7 High로 평가했습니다. Rently는 초...

planckproof.ai/blog/rently-mas

##

CVE-2026-55074(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-08-13T15:58:54

1 posts

Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host (<jail filesystem root> + <destination>) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic links, and the path was operated on outside the jail, so a symlink existing inside the jail was followed by the host-side, root-privileged mv. A party

Larvitz@burningboard.net at 2026-09-27T09:38:25.000Z ##

For almost a year, my Ansible connection plugin for FreeBSD jails had a jail escape.

A symlink inside a jail, a root-owned mv on the host, and every file transfer could land wherever the jail wanted. Rejecting ".." didn't help at all.

Now it's CVE-2026-55074. Here's the bug, the fix, and what disclosing it looks like when the project has one maintainer.

blog.hofstede.it/my-ansible-pl

#FreeBSD #Ansible #InfoSec #CVE #Jails #OpenSource #Security #SysAdmin

##

CVE-2026-58052
(3.3 LOW)

EPSS: 0.00%

updated 2026-08-07T20:47:38.443000

1 posts

7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a RAR5 STM record named ':Zone.Identifier:$DATA' is not matched and NTFS canonicalizes it to the same stream, overwriting the propagated Internet-zone marker with Zon

linuxmint_hun@mastodon.social at 2026-09-28T03:35:59.000Z ##

A 7‑Zip 26.03 hibajavításokkal és egy fontos Windows‑specifikus MotW‑sérülékenység (CVE-2026-58052) javításával érkezett. Szeretnéd tudni, hogyan kerülhette meg korábban a SmartScreen-et egy manipulált RAR5‑archívum, és érint‑e téged ez Windows alatt? Linuxra is elérhető a frissítés — nézd meg a részleteket.

linuxmint.hu/hir/2026/09/tomor

#7zip #26.03 #CVE2026-58052 #MotW #RAR5 #tömörítés #letöltés #szabad_szoftver #Linux #Windows

##

CVE-2026-35273
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-07-23T09:10:00.113000

6 posts

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of Peopl

Nuclei template

4 repos

https://github.com/0xBlackash/CVE-2026-35273

https://github.com/ekomsSavior/POC_cve_2026_35273

https://github.com/12hrformat/CVE-2026-35273-POC

https://github.com/HORKimhab/CVE-2026-35273

sayzard@mastodon.sayzard.org at 2026-09-28T17:46:09.000Z ##

Dutch Police Arrest 'Reformed' Hacker in Shiny Hunters Investigation

네덜란드 경찰이 ShinyHunters의 데이터 탈취·갈취 활동을 도운 혐의로 전직 보안 엔지니어 Pepijn van der Stap(별칭 Umbreon)을 체포한 것으로 알려졌다. 핵심 기술 이슈는 ShinyHunters가 Oracle PeopleSoft의 최근 패치된 취약점(CVE-2026-35273)을 대규모로 악용해 FBI 채용 사이트를 포함한 여러 조직에서 민감 데이터를 탈취했다는 점이다. 공격자들은 패치가 어려운 조직을 위해 배포된 Mandiant의 WAF 완화...

krebsonsecurity.com/2026/09/du

##

cyberveille@mastobot.ping.moi at 2026-09-28T15:30:05.000Z ##

📢 ShinyHunters contourne les WAF pour relancer l'exploitation massive de CVE-2026-35273 dans Oracle PeopleSoft

Cette analyse est publiée le 25 septembre 2026 par Mandiant et le Google Threat Intelligence Group (GTIG) sur le blog officiel de Google Cloud. Il s'agit d'une mise à jour d'un précédent rapport de juin 2026 portant sur l'exploitation…

📖 cyberveille : cyberveille.ch/posts/2026-09-2
🌐 source : cloud.google.com/blog/topics/t
🟢 vérification factuelle haute
#OraclePeopleSoft #ShinyHunters #Cyberveille

##

PC_Fluesterer@social.tchncs.de at 2026-09-28T13:57:24.000Z ##

ShinyHunters weitet Massenangriffe gegen Oracle PeopleSoft aus

Spätestens seit den "Erfolgen" im Mai/Juni scheint PeopleSoft von Oracle ein Lieblingsspielzeug der Hacker von ShinyHunters zu sein. Damals war CVE-2026-35273 noch eine Zero-Day Sicherheitslücke. Am 2026-06-10 hat Oracle einen Flicken dagegen veröffentlicht. Aber die Reparatur war entweder nicht gründlich genug, oder PeopleSoft ist einfach sowieso ein windelweiches Produkt. Jedenfalls ist es den Hackern von ShinyHunters gelungen, auch in vollständig aktualisierte Systeme einzudringen. Der Trick, den sie benutzen, ist geradezu lächerlich einfach.

PeopleSoft hat eine web application firewall (WAF) ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#closedsource #cybercrime #datenschutz #exploits #hersteller #UnplugOracle #UnplugTrump

##

linuxmint_hun@mastodon.social at 2026-09-28T14:54:13.000Z ##

Google: tömegesen kihasználják az Oracle PeopleSoft CVE-2026-35273-at. WAF-ot URL-kódolással kerülik meg és web shelleket telepítenek — nálatok is lehet gond? Nézd meg, mit kell azonnal ellenőrizni.

linuxmint.hu/hir/2026/09/tamad

#Oracle #PeopleSoft #CVE2026-35273 #WAF #webshell #ShinyHunters #Mandiant #cybersecurity #infosec

##

youranonnewsirc@nerdculture.de at 2026-09-27T04:26:17.000Z ##

Cybersecurity: ShinyHunters exploit a critical Oracle PeopleSoft flaw (CVE-2026-35273), bypassing WAFs and deploying SIDEEYE backdoor across sectors. Geopolitics/Tech: President Trump rejects AI regulation, prioritizing innovation despite global concerns (Sept 26, 2026).

#Cybersecurity #AnonNews_irc #News

##

cyberworldops@infosec.exchange at 2026-09-26T14:40:01.000Z ##

Google reports active exploitation of CVE-2026-35273 in Oracle PeopleSoft PeopleTools by UNC6240, linked to ShinyHunters. Encoded requests evade WAF rules to deploy JSP webshells via the Environment Management Hub, enabling persistent access. Prioritize patching and compromise hunting. #OracleSecurity #PeopleSoft #ThreatIntel

cyberworldops.eu/en/encoded-re

##

linhfishcr7.wordpress.com@linhfishcr7.wordpress.com at 2026-09-28T13:41:43.000Z ##

Next.js vá lỗ hổng RCE nghiêm trọng CVE-2026-94545: nâng cấp lên 16.3.6 ngay

Ngày 22/9/2026, Vercel phát hành Next.js 16.3.6 kèm cảnh báo bảo mật GHSA-vcvr-r3jv-pc5j để vá lỗ hổng thực thi mã từ xa (RCE) nghiêm trọng trong tính năng ImageResponse của next/og. Lỗ hổng được định danh CVE-2026-94545 với điểm CVSS 9.5 ở mức critical, ảnh hưởng mọi phiên bản Next.js từ 16.2.0 đến 16.3.5 chạy trên Node.js runtime. Nếu ứng dụng của bạn tạo ảnh Open Graph động bằng next/og, hãy nâng […]

linhfishcr7.wordpress.com/2026

##

thenextweb@flipboard.com at 2026-09-28T11:32:39.000Z ##

Hackers exploited a critical WordPress flaw within hours of the patch
thenextweb.com/news/wordpress-

Posted into TNW - All Stories @tnw-all-stories-thenextweb

##

thenextweb@flipboard.com at 2026-09-28T11:32:39.000Z ##

Hackers exploited a critical WordPress flaw within hours of the patch
thenextweb.com/news/wordpress-

Posted into TNW - All Stories @tnw-all-stories-thenextweb

##

secdb@infosec.exchange at 2026-09-28T00:01:31.000Z ##

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0922 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0924 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0925 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0927 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-87902 - 18.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-74849 - 4.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-76978 - 3.72 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15027 - 3.16 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-43641 - 3.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94097 - 2.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19599 - 2.86 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85542 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-94098 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-887712
(0 None)

EPSS: 0.00%

1 posts

N/A

ssvc@infosec.exchange at 2026-09-28T01:16:48.000Z ##

CISA working on a Sunday: Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-887712 were added to the Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

cisa.gov/news-event/alerts/202

#KEV #Citrix #NetScaler #zeroday #CVE

##

Visit counter For Websites